1. Home
  2. Projects
  3. Enterprise AWS Modernization

Enterprise AWS Modernization

Landing zone, server migration, virtual desktops, file services and disaster recovery

  • Lead AWS Engineer
  • AWS
  • Control Tower
  • Organizations
  • EC2
  • MGN
  • FSx
  • WorkSpaces
  • IAM Identity Center
On this page

Overview

A life-insurance organization needed a secure AWS foundation for a server estate, file services, a virtual-desktop environment and disaster recovery. The work combined foundation design, implementation, migration support, troubleshooting, testing and handover.

Challenge

The environment required a multi-account foundation, integration with existing identity and network services, replacement of legacy virtual desktops, migration of Windows workloads and file data, and a tested recovery capability. Connectivity and group-policy behavior also had to be resolved before migration and desktop adoption could proceed.

My role

I led the AWS technical delivery. I ran landing-zone discovery, wrote and updated the design, implemented the foundation, deployed domain-controller infrastructure, configured identity and migration prerequisites, built the virtual-desktop proof of concept, supported migration waves, led recovery drills and contributed to the final as-built documentation and knowledge transfer.

Architecture & approach

Simplified view of the engagement scope. Confidential details omitted.

Key components: AWS Control Tower, AWS Organizations, Amazon EC2, AWS Application Migration Service, Amazon FSx for Windows, Amazon WorkSpaces, AWS IAM Identity Center, Entra ID SAML, AWS WAF, AWS Elastic Disaster Recovery, Terraform.

What I implemented

  • Built the multi-account landing zone and core security and governance services.
  • Deployed EC2 domain controllers and worked through VPN routing and group-policy issues with AWS Support.
  • Configured IAM Identity Center, MGN private endpoints, Amazon FSx for Windows, Amazon S3 and AWS WAF.
  • Built an Amazon WorkSpaces proof of concept using AD Connector, FSx-hosted FSLogix profiles, Entra ID SAML single sign-on and custom images.
  • Supported application and infrastructure migration waves and investigated file-service throughput constraints.
  • Ran disaster-recovery proof-of-concept sessions, failover drills and knowledge transfer.

Key decisions

  • Used a multi-account foundation to separate governance, security and workloads.
  • Kept directory, profile and virtual-desktop design aligned so the WorkSpaces proof of concept could be tested as a complete user journey.
  • Escalated intermittent network behavior with evidence through an AWS Support case rather than masking it with application changes.

Security & reliability

The solution used centralized identity and security controls, private migration endpoints, managed file services, web application protection and documented disaster-recovery procedures. Recovery was validated through live failover exercises rather than treated as a design-only deliverable.

Technologies

  • Control Tower
  • Organizations
  • EC2
  • MGN
  • FSx
  • WorkSpaces
  • IAM Identity Center
  • Entra ID
  • AWS WAF
  • DRS
  • Terraform

Outcome

The engagement delivered the AWS foundation, core infrastructure, a functioning WorkSpaces proof of concept, migration support, disaster-recovery exercises, knowledge transfer and operational documentation.

Lessons & takeaways

Key takeaway

Cross-service dependencies mattered more than any single component. Identity, routing, directory services, profiles, migration endpoints and recovery procedures had to be validated as one operating environment.