Cloud & Identity
Azure architecture, hybrid identity, resilience and cost governance across subscriptions.
- Microsoft Azure
- Azure IaaS / PaaS
- Microsoft Entra ID
- Azure Backup
- Azure Site Recovery
- Azure Files
- Blob Storage
- Microsoft 365
- Cost Optimization
HADI KHAN
Security & Infrastructure Engineer — Dubai, UAE
CORE
The background of this page is a decorative, scroll-driven 3D visualisation of a hybrid enterprise infrastructure — a central core connected to cloud services, security gateways, network sites, identity services, virtualized compute and backup layers. It carries no information that is not also written on this page.
System onlineHybrid infrastructureDubai, UAE
Designing, securing and scaling hybrid cloud and on-premises infrastructure.
7+ years engineering resilient enterprise environments across cloud, networks, security, identity and virtualization.
Security and infrastructure engineer with 7+ years designing, deploying and hardening hybrid environments that span Microsoft Azure and on-premises data centres.
The work sits where cloud meets the building: Azure subscriptions and Entra ID on one side, domain controllers, hypervisors, firewalls and switch fabric on the other — and a secure, measured path between them.
Delivery runs end to end. Greenfield design, migration, hardening against CIS benchmarks, backup and recovery engineering, and the documentation and SOPs that let a team actually operate what was built.
Hands-on across
Point at a platform to illuminate it in the architecture.
Years experience
Enterprise infrastructure, security and cloud engineering.
Service availability
Maintained across supported production infrastructure.
Microsoft Azure architecture, identity, resilience and cost governance.
Cloud estates rarely fail on capability — they drift on cost and ownership. The work is deciding what actually belongs in Azure, connecting it back to the data centre deliberately, and keeping the bill matched to what the business is using.
Right-sizing & cost governance
Estimated Azure spend reduction
Right-sizing and cost governance across Azure workloads.
Reduced manual operational effort
Through PowerShell automation of recurring administration.
Users migrated to Microsoft 365
Full mailbox and data migration from G Suite.
Above: cloud resources reorganise as the chapter plays — oversized capacity is reclaimed and the architecture settles into a cleaner shape.
Not a product bolted on at the end — a layer designed at the same time as the switch fabric, the domain and the cloud.
Traffic between cloud and on-premises passes through a gateway that decides, every time, whether it should. Multiple gateways report into one management plane so policy is written once and verified everywhere.
Inspect
Policy evaluated at the gateway, per session.
Permit
Authorised traffic continues to its destination.
Deny
Everything else stops at the boundary.
Log
Retained centrally for analysis and compliance.
Designing segmented, resilient and centrally managed networks across distributed environments.
A flat network is convenient once and expensive forever. Segmentation decided at design time — which traffic classes exist, what they may reach, and how each site connects back — is what keeps a distributed estate manageable as it grows.
Segmentation model
Corporate
User and endpoint traffic, tied to directory groups.
Infrastructure
Management, hypervisors and storage, isolated from users.
Restricted
Access granted explicitly, never inherited.
9-site hub-and-spoke FortiGate deployment
Nine FortiGate firewalls, each configured and maintained independently, brought under a single FortiManager control plane with a documented operating procedure behind it.
Sites
1 management plane
One directory, replicated where the people are — and joined to cloud identity rather than duplicated alongside it.
Building Windows Server infrastructure from scratch means designing the directory before anything depends on it: domain structure, a replication topology that matches the physical sites, and DNS and DHCP that agree with both.
Replication topology
On-premises identity
Cloud identity · Microsoft Entra ID
Directory groups drive access on both sides of the boundary, and SAML federation carries that identity out to cloud-delivered services.
Configuration drifts quietly. Benchmarks give you something to measure against, and a defensible reason for every control you apply.
The sequence is always the same: establish the baseline, find where the estate has moved away from it, apply controls in an order that does not break the services people use, then verify what actually landed.
Regional hospitality group operating in four UAE emirates
CIS Benchmark controls applied across infrastructure servers, and Active Directory domain hardening carried out across the hotel sites of a regional hospitality group operating in four UAE emirates.
Project 04
Firewall configurations assessed across the multiple sites of a government entity, with findings turned into a structured set of hardening recommendations.
Client: Multi-site government entity
Assess
Review firewall configuration across every site.
Identify
Surface deviations from hardening guidance.
Prioritise
Rank findings by security impact and operational risk.
Harden
Hand over a structured remediation path.
Consolidating physical hosts onto hypervisor clusters with shared storage — fewer machines to power, patch and replace, and far more room to move workloads.
At Mace Engineering Technologies a VMware virtualization initiative reduced the physical server footprint by 77%, turning a rack of single-purpose machines into a cluster that could be maintained without taking services down.
Reduction in physical server footprint
VMware virtualization initiative consolidating physical hosts.
Before
Physical infrastructure
After
Virtualized infrastructure
Same workloads, a fraction of the hardware — and a platform where high availability finally becomes possible.
Availability is a design decision made long before the outage — and a recovery path is only real once someone has actually walked it.
Protection is layered so that no single failure removes every copy: clustering handles host loss, Veeam handles the data, and Azure keeps a copy somewhere the building cannot affect.
Primary infrastructure
The workloads the business runs on.
High availability
Failover clustering and VMware HA inside the site.
On-premises backup
Veeam Backup & Replication against local storage.
Cloud backup
Azure Backup, Azure Files and Blob Storage off-site.
Recovery
Site Recovery and a rehearsed restore procedure.
Service availability
Maintained across supported production infrastructure.
Disaster recovery time
48h
Before
5h
After
Redesigned backup and recovery processes at Mace Engineering Technologies reduced disaster recovery time from 48 hours to five.
Each pillar maps to a part of the estate behind this text. Point at one to see which systems it touches.
Azure architecture, hybrid identity, resilience and cost governance across subscriptions.
Fortinet security fabric — perimeter, secure access, centralised management and analytics.
Hypervisor clusters, shared storage and failover design that survives host loss.
Windows Server estates, multi-site directory replication and core network services.
Segmented, centrally managed switching and routing across distributed sites.
Benchmark-driven configuration control, audit and prioritised remediation.
Ten engagements across security, cloud, networking, identity, virtualization and resilience. Open a module for the challenge, the approach and what it produced.
Scroll the rail — 10 modules
All projectsFrom supporting infrastructure to owning it — each role covering more of the stack than the last.
Pakistan
IT Support Specialist
Infrastructure support and modernisation — virtualization, cloud migration and a rebuilt backup and recovery process.
Dubai, UAE
IT Support Engineer
End-user and infrastructure support across Microsoft 365, endpoint services and network services for a Dubai real estate business.
Dubai, UAE
Azure Cloud & Network Administrator
Operating and extending a hybrid estate across Microsoft Azure and on-premises data centre infrastructure, with security, identity and resilience owned end to end.
10 certifications across Microsoft Azure, security, networking and cloud architecture, with 2 currently in progress.
Microsoft · Cloud administration
Compute, storage, networking, identity and governance across Azure subscriptions.
Microsoft · Cloud networking
Hybrid connectivity, routing, private access and network security in Azure.
Microsoft · End-user compute
Planning, delivering and managing virtualized desktop infrastructure on Azure.
Microsoft · Identity
Entra ID, authentication, access governance and identity lifecycle.
Microsoft · AI platform
Designing and deploying Azure AI solutions and services.
Microsoft · AI fundamentals
Core AI workloads and services on the Azure platform.
Security · Network security
Fortinet security fabric — firewall policy, secure access and management.
Security · Cybersecurity
Security principles, access control, network security and operations.
Networking · Enterprise networking
Routing, switching, IP services, security fundamentals and automation.
Cloud · Cloud architecture
Designing resilient, cost-aware architectures on AWS.
Currently in progress
In Progress · Cloud security
Identity protection, platform protection, security operations and data security.
In Progress · Security operations
Threat mitigation using Microsoft Defender and Microsoft Sentinel.
Education
B.S. Computer Science
Lahore Garrison University · Lahore, Pakistan · 2017
16 — One connected system
Hadi Khan
Security & Infrastructure Engineer
Dubai, UAE
Available for conversations around cloud, security, infrastructure, networking and enterprise technology.