Skip to main content

Service

ITSM and IT infrastructure

Active Directory, Citrix, Windows Server, networking, access concepts: the side of IT that runs fine until it suddenly does not. I clean up, document access rights nobody can explain anymore, and bring Windows environments back to a state a second administrator can understand.

Network switch with patched cables in a server cabinet
Photo: Dimitri Karastelev / Unsplash

The problem

What I commonly find: an Active Directory structure that grew over ten years. Security groups named things like 'Group2_old_copy', nested permissions nobody can explain anymore, group policies that override each other.

Citrix environments with several hundred to a thousand users often run on configurations from the last major rollout, only ever added to, never cleaned up. Monitoring either reports too much (nobody reads the alerts anymore) or too little (the outage reaches the user before it reaches the dashboard).

The reflex is often to bolt on a new tool instead of understanding the existing structure and cleaning it up deliberately. That just moves the problem into an extra layer.

The solution

I start with an inventory: which permissions actually exist, which group policies apply where, which Citrix configuration is active and which is dead weight from an old rollout. Cleanup happens after that, not before, and never as a blind rebuild.

Access concepts get re-documented on a least-privilege basis, security groups structured by function instead of historically grown names. The same applies to Windows Server and networking (firewalls, VLANs, routing, DNS/DHCP, PKI/certificate management): understand what is actually needed first, then simplify.

Deliverables: a documented access structure, cleaned-up group policies, a monitoring setup (Nagios/Zabbix/PRTG class) that reports what is actually relevant, and a backup/disaster recovery concept that is tested, not just claimed.

Typical use cases

  • Cleaning up an Active Directory and access structure grown over years
  • Citrix rollout or consolidation in the hundreds-to-thousands user range
  • Windows Server administration and group policy cleanup
  • Building or sharpening monitoring (Nagios/Zabbix/PRTG class) that reports real issues instead of noise
  • Backup and disaster recovery concepts that actually get tested
  • PKI/certificate management for internal infrastructure

Concrete benefits

  • Access rights are documented and traceable, no longer just historically grown
  • Less alert noise, more genuine early warning in monitoring
  • Citrix and server environments are understandable for a second administrator within a reasonable time
  • A tested, not just claimed, backup and disaster recovery concept
  • Less dependency on one person who keeps the structure in their head
Row of three server racks with structured cabling and blinking status LEDs in a data center
Photo: Taylor Vick / Unsplash

How we work together

  1. Inventory (1-3 days)

    Which permissions, group policies, and configurations actually exist? Output is a prioritized list of risks and cleanup work.

  2. Cleanup in manageable steps

    Access structure, group policies, network configuration. Every step gets checked against live operations before the next one starts.

  3. Monitoring and backup concept

    Alerts that are actually relevant, and a backup/disaster recovery plan that gets a real dry run, not just a document.

  4. Handover with documentation

    README with access logic, network plan, maintenance notes. Walkthrough with your internal IT team.

Frequently asked questions

Do you work on our infrastructure remotely?

For analysis, documentation, and much of the configuration work, yes, via VPN or jump host per your security requirements. For physical work or especially sensitive environments, on-site in the Rhine-Neckar region, elsewhere in Germany by arrangement.

What does an inventory cost?

An inventory of Active Directory, permissions, and Citrix configuration typically runs €1,000 to €3,000 at €100/h, depending on environment size. You get a real range for the follow-on cleanup after that.

Are you certified (Microsoft, Citrix)?

No formal certificates, but 18 years of hands-on experience, several of them in an environment with several thousand users. Where a certificate is contractually required, I say so upfront and honestly.

Do you also take over day-to-day administration?

Selectively via a retainer, yes. For a permanent full-time administrator role I am the wrong fit, a direct hire or a staffing agency serves that better.

What if our environment mixes Windows and Linux?

My focus is the Windows/Microsoft side (Active Directory, Citrix, Windows Server, Exchange/SharePoint). I connect Linux servers as part of an infrastructure, but deep Linux administration is not my core field, and I say so upfront.

/ Next step

Get a grown IT infrastructure cleaned up?

Briefly describe environment size and your biggest concern (permissions, Citrix, monitoring, backup). You get an honest read on where to start.