Automation of IT infrastructure

Tech Case Study: Automation of the IT Infrastructure

Lines of programmed code
> 0
Compliance with audit requirements
0 %
Process automation
0 %
Project

Our client, a leading global pharmaceutical company, approached Datalynx with a requirement to automate their Active Directory Domain Controller infrastructure (terminology see below) mit Hilfe moderner Azure-Technologien zu automatisieren. Durch die Durchführung des Projekts konnte der Kunde die Automatisierung und die Sicherheit der wichtigsten IT-Infrastruktur-Serverrollen gewährleisten und sicherstellen, dass die Konfiguration mit den Audit-Anforderungen übereinstimmt, was für das Geschäft des Kunden entscheidend ist. Der Einsatz der Lösung trägt ausserdem dazu bei, manuelle IT-Operationen zu reduzieren, was zu Kosteneinsparungen führt.

Challenge

The requirements for the IT infrastructure

  • Use DSC code (Desired State Configuration) and describe each configuration (avoid GPO as far as possible).
  • Enable tracking of code changes and control over releases
  • Ensure that the configuration settings on key infrastructure servers match the requirements of internal and external auditors
  • Manage the patch management lifecycle of domain controllers (no System Center Configuration Manager - SCCM)
  • The existing «System Center Configuration Manager» infrastructure cannot be used and must be replaced.
  • The domain administrator's password must not be stored outside the local Privilege Access Management (PAM) solution and must be retrieved from there in a secure manner.

The biggest challenges:

  • Convince stakeholders to participate in the development of the solution
  • Environments in which the solution was implemented were identified as inconsistent
  • Training the technical team on how the solution works and how to maintain and operate it
  • Technical definition of the process and customization of the domain admin password in a secure manner
  • Replacing SCCM with another solution and sensitizing the stakeholders of the security agent team
  • Identification of process gaps during the implementation of the change
Solution

Recommendation after detailed analysis

After careful analysis, Datalynx was able to recommend the following technologies for setting up the infrastructure, all of which met the requirements:

  • Azure automation service
  • Azure Log Analytics workspace
  • Azure Express Route
  • Azure Key Vault
  • DSC code written in PowerShell
  • Azure DevOps and its pipeline and repo
  • Windows Update Management Service
  • Chocolatey and NuGet

After determining the possible solutions, a few more tasks and activities had to be completed.


What had to be considered during implementation:

The first step was to define and gather the requirements of the various stakeholders in the company to ensure that the proposed solution would fit their needs. In a next step, we focused on understanding the existing DC deployment process, modifying and adapting the new solution accordingly. The following phase involved the development and customization of the DSC code. The final code was more than 10,000 lines!

Implementation

Close cooperation with the parties involved

In parallel to the steps mentioned above, another important milestone in this project was working with the stakeholders to implement the solution in all environments (test, pre-production, production). In order to test the concept, implementation in several environments was chosen. This also allowed detailed documentation to be prepared for the technical teams who would later take over the entire solution.

Every single infrastructure-related project requires a network. So does this one. As expected, configuration changes such as firewall exceptions (port opening) and Azure Express Route configuration were required. A very important step was also the selection of the right Azure region that supports Express Route and meets the company's criteria. Last but not least, the process for capturing the password through the Privileged Access Management System had to be set up in order to perform the «dcpromo» (Domain Controller Promotion) operation on the Domain Controller.

Domain controller provisioning process - technical implementation:

One challenge was that the software agents installed on the servers had been installed by SCCM. To ensure that the agents could be installed via the new solution, they all had to be uninstalled first. Then SCCM itself had to be uninstalled. The new solution then had to set up the software agents during the Azure onboarding process. Another challenge was to create custom NuGet packages based on existing packages. In addition, a SCOM agent (System Center Operations Manager agent) was deployed on the servers. The Microsoft Monitoring Agent (MMA) had to be installed, reporting to the Azure Log Analytics Workspace, and the MMA agent had to be extended to report to Azure and SCOM as a single agent after installation!

  • The Active Directory operations team, acting as a stakeholder, asked the infrastructure team to create a new virtual machine that would later be used as a domain controller.
  • The DevOps pipeline was executed to integrate the server into the solution.
  • Once the server was integrated with Azure, the DSC code was applied and all security settings and configurations were implemented, including the installation of the software agent. There was no longer a need to use Active Directory group policies. With this configuration, the server was automatically integrated with Azure Update Management to ensure that all patches were installed regularly.
  • If the server is compliant (based on the compliance report from the security tool), it is promoted to the domain controller - Another DevOps pipeline is executed. This triggers the DC promo operation. The domain controller is deployed according to the configurations in the code.
Success

Wide range of benefits

  • Automation of the most important infrastructure server roles
  • Ensuring safety
  • Ensuring that the configuration complies with the audit requirements (compliance)
  • Cost savings through the reduction of manual IT operations
Terminology:
  • Microsoft Active Directory Domain Services (AD DS): form the basis for distributed networks that are operated on the Windows 2000 Server, Windows Server 2003 and Windows Server 2008 operating systems and use domain controllers. AD DS provides secure, structured and hierarchical data storage for network objects such as users, computers, printers and services. They also enable the search for and interaction with these objects in the network.
  • Desired State Configuration (DSC): DSC is a Microsoft technology that makes it possible to manage computer configurations (such as servers) in a declarative manner. DSC code describes the desired system configuration, which can be defined and automatically applied via PowerShell scripts.
  • Group Policy Object (GPO): GPOs are central management tools in Windows networks that allow administrators to define and enforce security policies, user and computer configurations and settings for different systems within an Active Directory network.
  • System Center Configuration Manager (SCCM): SCCM is a comprehensive solution from Microsoft for managing networks, which makes it possible to centrally manage software updates, operating system deployments, software distribution, monitoring and inventory of systems in large IT environments.
  • Privilege Access Management (PAM): PAM is a security solution specifically designed to manage, monitor and protect access to sensitive systems and data within an organization. PAM solutions aim to control privileged user accounts and their access rights in order to minimize the risk of misuse and cyberattacks.
  • Chocolatey and NuGet: are package managers for Windows that make it easier to install, manage and update software and libraries.
Would you like to know more?
Get in touch with me.
Foto des Primtetrack CEO Stephan Fredrich
Stephan Fredrich, Head of Digital Solutions &
Group CMO/CSO & Primetrack CEO

+41 61 385 93 00
stephan.fredrich@datalynx.ch

icon_datalynxgroup_colored-1png
Supplementary services of the Datalynx Group