On this page
Overview
A life-insurance organization needed a secure AWS foundation for a server estate, file services, a virtual-desktop environment and disaster recovery. The work combined foundation design, implementation, migration support, troubleshooting, testing and handover.
Challenge
The environment required a multi-account foundation, integration with existing identity and network services, replacement of legacy virtual desktops, migration of Windows workloads and file data, and a tested recovery capability. Connectivity and group-policy behavior also had to be resolved before migration and desktop adoption could proceed.
My role
I led the AWS technical delivery. I ran landing-zone discovery, wrote and updated the design, implemented the foundation, deployed domain-controller infrastructure, configured identity and migration prerequisites, built the virtual-desktop proof of concept, supported migration waves, led recovery drills and contributed to the final as-built documentation and knowledge transfer.
Architecture & approach
Key components: AWS Control Tower, AWS Organizations, Amazon EC2, AWS Application Migration Service, Amazon FSx for Windows, Amazon WorkSpaces, AWS IAM Identity Center, Entra ID SAML, AWS WAF, AWS Elastic Disaster Recovery, Terraform.
What I implemented
- Built the multi-account landing zone and core security and governance services.
- Deployed EC2 domain controllers and worked through VPN routing and group-policy issues with AWS Support.
- Configured IAM Identity Center, MGN private endpoints, Amazon FSx for Windows, Amazon S3 and AWS WAF.
- Built an Amazon WorkSpaces proof of concept using AD Connector, FSx-hosted FSLogix profiles, Entra ID SAML single sign-on and custom images.
- Supported application and infrastructure migration waves and investigated file-service throughput constraints.
- Ran disaster-recovery proof-of-concept sessions, failover drills and knowledge transfer.
Key decisions
- Used a multi-account foundation to separate governance, security and workloads.
- Kept directory, profile and virtual-desktop design aligned so the WorkSpaces proof of concept could be tested as a complete user journey.
- Escalated intermittent network behavior with evidence through an AWS Support case rather than masking it with application changes.
Security & reliability
The solution used centralized identity and security controls, private migration endpoints, managed file services, web application protection and documented disaster-recovery procedures. Recovery was validated through live failover exercises rather than treated as a design-only deliverable.
Technologies
Outcome
The engagement delivered the AWS foundation, core infrastructure, a functioning WorkSpaces proof of concept, migration support, disaster-recovery exercises, knowledge transfer and operational documentation.
Lessons & takeaways
Key takeaway
Cross-service dependencies mattered more than any single component. Identity, routing, directory services, profiles, migration endpoints and recovery procedures had to be validated as one operating environment.