Complete modernization of server infrastructure, identity, and remote access into a consistent Zero Trust architecture — from hyperconverged storage to hardened server and client baselines to secure remote work without a single publicly reachable device.
Arrange a call
Access exclusively through identity-based secure access instead of open network paths
Ten times the bandwidth for storage and backup workloads — the foundation for the hyperconverged cluster
Our client operated an aging server and storage landscape without hardware-level redundancy, a 1G network that no longer sufficed for modern storage and backup workloads, and a classic Active Directory environment with static passwords and permanently privileged accounts — a favorite target for credential-based attacks and lateral movement. Service accounts ran on classic, never-rotating passwords, administrative access happened directly from user endpoints, and backups were reachable from the production network and therefore an attack target themselves in a real incident. Remote work lacked a consistent Zero Trust strategy: access was governed by open network paths rather than identity and device posture, individual systems were directly reachable from the internet, and endpoints and servers followed no uniform security baseline. The goal: a highly available, hybrid infrastructure that implements Zero Trust from the ground up — hardened at every layer, without a single publicly reachable device, and with an identity strategy that structurally rules out classic attack paths.
We designed and implemented a hyperconverged cluster based on Storage Spaces Direct (S2D) with NVMe storage — Azure Local-compatible for a later hybrid cloud connection. In parallel, we modernized the network to 10G and consistently segmented it: the server environment no longer has direct internet access, and access is routed based on identity rather than over open network paths. For the backup architecture, we implemented Veeam Backup & Replication with immutable on-premises storage: even with administrative rights, backed-up data cannot be deleted or encrypted within the retention period — an effective safeguard against ransomware, which specifically targets backups first. We placed the biggest lever for identity security in Active Directory: through Fine-Grained Password Policies, the underlying passwords rotate automatically every day at 128 characters — nobody knows their own password anymore. For everyday sign-in on managed devices, we use Windows Hello for Business, device-bound via biometrics or PIN; for access that must not be tied to a single device — privileged sign-in or roaming workplaces, for example — we use YubiKeys as a portable, hardware-based factor. Where services support it, service accounts run on Group Managed Service Accounts (gMSA) instead of static, manually managed passwords. Privileged access happens exclusively through a dedicated PIM/PAM solution with a jump host — no standing admin rights, no direct administrative sign-in from user endpoints. Microsoft Defender for Identity continuously monitors the Active Directory environment for lateral movement, pass-the-hash, and other identity-based attack patterns. Clients consistently follow CIS Benchmark Level 1, while the jump host and critical servers follow the stricter Level 2 — standard practice for systems where security clearly outweighs convenience. As an additional detection layer, Microsoft Defender for Endpoint runs with Defender Antivirus in passive mode and EDR in block mode enabled, alongside CrowdStrike Falcon Complete as the primary EDR — a second, independent layer of post-breach detection for threats the primary agent misses. For secure remote work, we hardened Entra ID and Intune to current baselines and implemented Global Secure Access as an identity-based replacement for classic VPN — access is decided by identity, device posture, and context, no longer primarily by network location. With Azure Virtual Desktop as the central access point, there is no longer any need to make endpoints or servers directly reachable from the internet: remote work today is fully secured through hardened, identity-based access paths, without a single publicly exposed system.
The result: a consistent Zero Trust architecture from the data center to the remote workplace — hyperconverged, ransomware-resistant, free of standing admin rights, and without a single publicly reachable device.
„Zero Trust is not a product you buy — it is the sum of hardened identity, hardened endpoints, and a network that no longer automatically trusts anyone.“
Zero Trust Infrastructure Without a Single Publicly Reachable Device
The infrastructure now runs in production — hyperconverged, highly available, and secured end-to-end according to Zero Trust principles: hardened clients and servers, privileged access exclusively through a jump host and PIM/PAM, two independent detection layers, and identity-based secure access instead of classic VPN. Thanks to the Azure Local-compatible cluster architecture, nothing stands in the way of a gradual hybrid cloud connection without having to rebuild the existing infrastructure.
Service: Infrastructure & Private Cloud
Let's make your next project a success together. Contact us for a non-binding initial consultation.