Curriculum Vitae

Work at Kamstrup



Onboarded November 2019 as a Senior Specialist, specializing mostly in all things Microsoft in the logical infrastructure and supporting integrations to primary platforms like Vmware vCenter, Azure Entra ID etc.

Tasked primarily with updating the Active Directory to a supported level (2012R2) and getting ip services stabilized (DNS, DHCP), plus renovating all domain controllers, abroad and domestic for Kamstrup Corporate.
Heading a virtual team, AD Team, for building up a cross organizational team for fleshing out a beginning road map for Active Directory alignment and modernization, including prepping for RBAC. In this capacity, assigned ownership of primary AD, DNS, DHCP and Certificates (The core Active Directory services).

Sparring for Incident management in IT Operations and stepping in as interim Owner of Azure tenant and Entra ID for the corporate side of Kamstrup.

In addtition, an active participant and driver for low level automations, internal education, espec. in PowerShell, AD, networking services and facilitating social events like a yearly trip to the Poolhall and other events.

On a frequent basis 3rd or 4th line on most things Windows, including DFS and file services, IP Services, as well as networking integrations to On-Premises and Azure resources, Vmware vCenter and the odd 3rd party solution in need of sparring or help.

Advocating architecture for some time, facilitating an informal task force of people trying to add a more architectual approach and awareness on a Systems architecture level. After the last reorganization, architecture has found it's way on the Roadmap for Kamstrup in general, overtaking this work in some degree.


Primary tools

As a specialist, my PowerShell console is never far from sight. We are onboarding GitLab as GIT repository. The Azure Portal along with any product specific MMC is readily at hand as well.

We employ Service Now for servicing the business and requesting service or support in general. Our Standard Operating Procedures reside in Service Now as well. Jira for some project tasks and Confluence for documentation and knowledge gathering, and some architecture work as well.


Examples of projects and initiatives

Building a virtual Active Directory team
As Kamstrup keep a strict seperation between corporate systems and customer facing systems, especially Kamstrup hosted customer solutions, it became evident immediately, we needed to build a bridge between our operations teams and our setup for managing both the corporate and the commercial primary ADs.
Spear heading this as part of my onboarding, a virtual team was made with a primary stakeholder (Admins) from each segment, securing both a feedback loop for relevant teams as well as a firm access into each AD. AD Team has survived all reorganizations since, though with varying intensity as need demand it.

Stabilizing and upgrading Active Directory
A somewhat afflicted AD with a lot of hardcoded couplings needed to be stabilized and brought up to a current level.

Build up internal competences
Hosting a series of internal training and technical deep dives for especially our Support and Operations teams, as well as part of onboarding trainees and colleagues, depending on level of competences.

Restructure and migrate DHCP
With a mushroomed DHCP setup, residing on domain controllers, a complete map of networks, abroad and at HQ, were done and ported into a new DHCP setup, with a few central hubs with dedicated Microsoft DHCP servers (main factories) and some DHCP services delegated to Cisco ASA and now Cisco Firepower devices at the smaller network locations, typically sales offices. This as a temporary, but very capable and stabile, solution, granting sufficient time to do a proper analysis and vendor selection.
Phase 2 is a full blown IPAM solution, that right now is in Proof of Concept.

Introducing Role Based Access Controls
RBAC and IAM weren't topics in Kamstrup, and a considerable amount of sprawl in both identities and access were an issue. We tried leverage the introduction to RBAC in AD Team, and have had some succes in setting up a Auth/Role paradigm in on-premises systems. The key challenge remain legacy systems.
In Entra, en early adoption of Privileged Access Groups, coupled with Administrative Units, are now a goto solution, alongside PIM, and awareness of seperation is relatively high. It helps, when we are able to enforce this directly - this is what you get, when you order a service... But still, a majority of the stakeholders see the point now.
The aim is to employ frameworks like Zero Trust and Microsoft's view of modern identity management, which we feature as principles on our modernization track, ensuring we do projects that work towards this, eg. our Windows 11 roll out project.

Introducing Quick Stepper
I brought with me the thoughts of a centralized app, I built for support and operations in Aarhus Vand, and build this in Kamstrup as well.
As before, the app provide shortcuts to trivial tasks like resetting a password, including sending an SMS, unlocking accounts etc. Also, it hold some shortcuts to vital systems, granting you quicker access through the credentials, you logged into the app, eg. RDP to a central jumphost. A select few functions also automate registration in Service Now, however, not as tightly knit as the app in Aarhus Vand.

Cloud cost reduction
Starting up a cloud cost initiative, targeting rampant costs in our cloud consumption. This work is now handed over to a dedicated task force, that also look into our customer facing systems and applications.

Windows 11 roll out
This project is owned by another team, but I participate as interim architect and sparring on identities, integrations etc. as well as crash test dummy. The project is mainly carried by 3rd party consultants, overseen by product owner and to some extend me.
We opt for a fully modern managed setup, working towards a setup more in lieu with Zero Trust.