Tiering fails as a diagram and succeeds as an enforcement mechanism. This is the dependency order that decides which one you end up with.
Based in Doha, Qatar
Palani KumarAnnamalai
Microsoft Cloud, Infrastructure, Identity & Security Architect
Microsoft Certified TrainerCISSPFormer Microsoft Cloud Solution Architect
I design, secure and troubleshoot Microsoft environments spanning Azure, Microsoft 365, Microsoft Entra ID, Windows Server, Active Directory, Exchange, Microsoft Defender, Sentinel, Purview and hybrid infrastructure. My work connects architecture with implementation, validation and operations.

- Professional scope
- Enterprise Microsoft infrastructure, cloud, identity and security
- Previously
- Microsoft Cloud Solution Architect, Security
- Credentials
- CISSP and Microsoft Certified Trainer
- International experience
- India, the UAE, Ireland and Qatar
What I work on
Connecting Microsoft infrastructure, cloud, identity and security
Modern Microsoft environments rarely fit within one product boundary. Identity, messaging, infrastructure, security and governance depend on one another. I work across those connections to reduce exposure and modernise established environments while maintaining operational control.
Free community tool · Public beta
Assess Microsoft security across cloud and on-premises systems
AdminSecOps is a free, read-only assessment tool covering Microsoft Entra ID, Microsoft 365, Exchange Online, Intune, Azure, Active Directory, AD CS, Group Policy and Windows.
Evidence is evaluated on the user’s device. The browser application has no server-side evidence upload, telemetry, analytics or remote logging.
From design to operations
Architecture must continue working after implementation
A technically correct design can still fail if ownership, monitoring, recovery and operational dependencies are unclear.
My work examines the required capability, its dependencies, how access is controlled, what happens when a component fails, how the result is validated and who owns the service afterwards.
- Windows NT and Exchange 5.5Where it started
- Windows Server and Active DirectoryDirectory, domains and server generations
- Exchange generationsOn-premises messaging, then hybrid and Exchange Online
- System Center, virtualisation and clusteringEnterprise management and availability
- Storage Spaces Direct and Azure LocalSoftware-defined infrastructure; Azure Local was Azure Stack HCI until November 2024
- Azure and Microsoft 365Cloud platform and productivity services
- Identity, security and governanceEntra ID, Defender, Sentinel and Purview across every layer
AutomationPowerShell · Microsoft Graph
Current focus
Five areas I work in today
These are the areas where established infrastructure and current cloud services meet, and where my writing, labs and training are focused.
Infrastructure and hybrid cloud
Windows Server estates, clusters and software-defined storage, and how they extend into Azure and Azure Local.
- Windows Server
- Active Directory
- Failover Clustering
- Storage Spaces Direct
- Azure
- Azure Local
Identity and access
From Active Directory to Microsoft Entra ID: hybrid identity, authentication, Conditional Access and privileged access.
- Microsoft Entra ID
- Hybrid identity
- Conditional Access
- Identity governance
- Privileged Identity Management
Messaging and collaboration
Exchange since 5.5: on-premises generations, Exchange hybrid, Exchange Online and the Microsoft 365 around it.
- Exchange Server
- Exchange hybrid
- Exchange Online
- Microsoft 365
- Teams
Security and governance
Security operations, identity security and data governance, built on Zero Trust principles rather than bolted on.
- Microsoft Defender
- Microsoft Sentinel
- Microsoft Purview
- Zero Trust
Automation and technical enablement
PowerShell and Microsoft Graph for the repeatable work, and labs, scripts and training so others can do it too.
- PowerShell
- Microsoft Graph
- Labs and scripts
- Training
Technical writing
Practical guidance, documented in depth
I write on LinkedIn about Microsoft identity, security, messaging, governance and infrastructure. This site is the permanent home for the deeper engineering pieces: the problem, the evidence, the mechanism and the fix, with the versions tested.
Namespace, zone storage and forwarder choices are made once and inherited for twenty years. These are the ones that are expensive to reverse, and the ones that are not.
Forest recovery is not restoring a domain controller. It is rebuilding the authentication layer that every other recovery plan quietly assumes is already working.
Training and community
Practical training grounded in experience
As a Microsoft Certified Trainer, I provide practical sessions across Azure, Microsoft 365, identity, security, Windows Server and hybrid infrastructure.
No sessions scheduled yet. Dates are published on the training page once confirmed.
Selected credentials
Credentials aligned to my work
These selected credentials support my work across security, architecture, cloud and identity. The broader certification record is available on Credly.
Technical training and presentations
Microsoft Certified Trainer
Recorded AZ-900, AZ-104 and SC-200 training series, and technical presentations. Training
Professional certification
- CISSPCertified Information Systems Security Professional
Expert certifications
- SecurityMicrosoft Certified: Cybersecurity Architect Expert
- CloudMicrosoft Certified: Azure Solutions Architect Expert
- Microsoft 365Microsoft 365 Certified: Administrator Expert
As of September 2026
- active Microsoft certifications
- 18
- passed Microsoft exams
- 32
- Microsoft Applied Skills
- 2
Contact
Connect
I’m open to senior architecture, technical leadership, speaking and Microsoft training opportunities. For professional enquiries or questions about material published here, email is the best way to reach me. I also share shorter technical notes on LinkedIn.
