Operate, modernize and evolve your Microsoft Cloud securely.
I support companies and public sector organizations with demanding Microsoft Cloud and Modern Workplace projects, with a particular focus on Microsoft 365, Azure, Microsoft Intune, Entra ID and Conditional Access.
From initial design through technical implementation to stable day-to-day operations: hands-on, structured and backed by more than ten years of project experience, including regulated and security-critical IT environments such as critical infrastructure and settings that handle classified information.
Technically sound. Securely designed. Built for everyday use.
Microsoft Cloud platforms are now a central part of modern corporate IT. At the same time, the demands on identity protection, device management, access control, governance and reliable operations keep growing.
My focus is on designing, implementing, securing and evolving modern Microsoft environments. I treat Microsoft 365, Azure, Entra ID and endpoint management not as isolated products but as one connected platform.
The goal: an environment that is secure, standardized, manageable and sustainable to operate.
Focus areas
Microsoft 365
Design, administration and further development of complex Microsoft 365 environments, from day-to-day operations to the structured optimization of existing platforms.
- Microsoft 365 administration and operations
- Exchange Online
- Microsoft Teams
- SharePoint Online
- Microsoft Entra ID
- Role and permission models
- Security and governance
- Migrations and rollouts
- Automation of administrative processes
- Standardization of existing environments
Microsoft Intune & Endpoint Management
Modern device management has to combine security, standardization and a good user experience. I support organizations in building, optimizing and operating Microsoft Intune and cloud-based endpoint management.
- Microsoft Intune
- Windows 10 and Windows 11
- Windows Autopilot
- Configuration profiles
- Compliance policies
- Application delivery
- Win32 app deployment
- Update management
- Endpoint security
- Device configuration
- Automated rollouts
- Standardization of client environments
Entra ID & Conditional Access
Securing identities and access with intent
A particular focus of my work is Microsoft Entra ID and Conditional Access. I design and refine access and security concepts that effectively protect users, devices and cloud resources without making everyday work unnecessarily difficult.
- Conditional Access strategies
- Multi-factor authentication
- Microsoft Entra ID
- Identity Protection
- Risk-based access control
- Device compliance
- Access by user, device, location and risk
- Privileged roles
- Administrative access models
- Least-privilege approaches
- Security baselines
- Protection of administrative accounts
What matters here is not the sheer number of individual policies, but a security concept that is comprehensible, maintainable and tailored to the organization.
Microsoft Azure
Support with operating, securing and evolving Azure environments, and with integrating cloud services into existing corporate structures.
- Azure administration
- Identity and access management
- Role and permission models
- Governance
- Network and access structures
- Azure resources and services
- Security requirements
- Integration with Microsoft 365 and Entra ID
- Automation
Security has to be built into the technical architecture.
In regulated and security-critical organizations, IT systems that simply work are not enough. Technical solutions must also meet requirements for information security, access protection, governance, auditability and operations.
I bring project experience from environments with elevated protection requirements. This includes critical infrastructure, known in Germany as KRITIS, and environments that handle classified information at the German VS-NfD level, which corresponds to RESTRICTED. As a result, I am familiar with situations in which technical decisions cannot be made on grounds of convenience or efficiency alone.
- Identity and access management
- Conditional Access
- MFA and risk-based access control
- Privileged access
- Role and permission models
- Endpoint security
- Device compliance
- Governance and security policies
- Technical documentation
- Standardization and auditability
- Collaboration with information security and data protection teams
- Projects in critical infrastructure environments
- Projects involving classified information
My focus is on the technical implementation of these requirements and on integrating them into IT operations that remain workable in practice.
From requirement to stable operations
Solutions have to keep working after the project ends.
For me, a successful implementation does not end at technical go-live. I accompany projects from the first analysis through to handover into stable, well-documented operations.
Analysis & design
Understand existing structures, assess requirements and develop a technically sound target architecture.
Technical implementation
Configuration, integration, migration and rollout. Hands-on directly in the production environment where needed.
Security & governance
Account for security requirements, identities, roles, access and organizational policies from the very beginning.
Rollout & adoption
Introduce technical changes into the organization in a controlled way, considering the impact on users and operations.
Documentation & standardization
Document and standardize configurations, decision paths and operational processes so they remain traceable.
Handover & ongoing operations
Transfer solutions into operations so that internal IT teams can work with them reliably and independently afterwards.
Enterprise experience beyond the Microsoft platform
My technological focus is on Microsoft 365, Azure, Intune and identity security. At the same time, I bring experience from complex IT landscapes in which Microsoft technologies interact with numerous other systems, processes and organizational requirements.
- ITSM and service management
- ERP integration
- Network and infrastructure topics
- Information security
- Interfaces and automation
- Vendor and service provider management
- Technical rollouts
- Operational handovers
- Collaboration with business departments
- Data protection and governance
This allows me not only to implement Microsoft Cloud topics technically, but also to position them within existing enterprise structures and operational processes.
Experience from mid-sized businesses to enterprise environments
For more than ten years I have worked in demanding IT environments and on projects of very different sizes. My experience ranges from mid-sized companies to large enterprise and public sector organizations, including environments with high requirements for availability, information security, governance and documentation.
In these settings I take on hands-on technical work as well as coordination between internal IT teams, business departments, service providers and management.
Proven expertise from Azure to identity security
AZ-104Microsoft Azure AdministratorAZ-305Designing Microsoft Azure Infrastructure SolutionsAZ-500Microsoft Azure Security TechnologiesSC-100Microsoft Cybersecurity ArchitectSC-300Identity and Access AdministratorSC-400Information Protection AdministratorSC-401Information Security AdministratorMD-102Endpoint AdministratorMS-102Microsoft 365 AdministratorMS-500Microsoft 365 Security AdministrationMS-700Managing Microsoft TeamsMS-720Microsoft Teams Voice EngineerPL-200Power Platform Functional ConsultantMS-4014Extend Microsoft 365 CopilotMS-900Microsoft 365 FundamentalsMS-100Microsoft 365 Identity and ServicesComplemented by methodological certifications for structured project work:
Senior IT consulting with technical depth
I am Valentin Weber, an independent senior IT consultant based in Wiesbaden, Germany. For more than ten years I have supported companies and organizations with demanding IT projects. My professional focus is on Microsoft 365, Azure, Microsoft Intune and Microsoft Entra ID, and in particular on Conditional Access and identity security.
My strength lies in combining technical depth with a solid understanding of wider IT structures. I do not just develop concepts; I work directly in the technical environments and implement solutions in practice.
I am equally comfortable at the interfaces between IT operations, information security, business departments, service providers and management, including in regulated and security-critical organizations.
My standard: results you can rely on, not slide decks. Solutions should not only work on paper. They have to be implemented cleanly, documented in a way people can follow, and integrated into operations so that internal teams can confidently continue to work with them.
Typical engagements
Support is available on a project basis as well as for temporarily reinforcing existing IT teams. Typical engagements include:
- Building or optimizing a Microsoft Intune environment
- Introducing or restructuring Conditional Access
- Security review of existing Conditional Access policies
- Hardening Microsoft 365 and Entra ID
- Modernizing endpoint management
- Windows 11 and Autopilot rollouts
- Optimizing existing Microsoft 365 structures
- Microsoft Cloud migrations
- Identity and access management
- Role, permission and governance models
- Support with security and governance projects
- Microsoft projects in regulated IT environments
- Projects with elevated critical infrastructure or classification requirements
- Stabilizing and evolving existing platforms
- Temporary reinforcement of IT operations and project teams
Do you have a Microsoft Cloud challenge?
Whether it is Microsoft 365, Azure, Intune, Entra ID, Conditional Access or a complex Modern Workplace project: tell me briefly about your current situation and the kind of support you are looking for. I will get back to you personally so we can clarify whether and how I can support your project.
Note: if you contact me by email, your details will be processed in order to handle your enquiry. Further information can be found in the privacy policy.