Architecture & Topology

Architecture Diagram

Figure 1.0: The final hybrid architecture. Scaling instantly with Azure while maintaining a secure, redundant physical footprint on-site.

SAIT Campus

Cloud Migration: Calgary Call Centre

Role: Project Lead

I directed the technical rescue of a 100-user organization running on borrowed time. Their infrastructure was built on End-of-Life Windows Server 2012 R2 and a consumer-grade SOHO router that couldn't handle the traffic.

The consequences were real: they had been hit by ransomware twice in one year and suffered a DNS poisoning attack that took their services offline. My team beat out competitors with a $472k proposal to modernize them into a hybrid Azure environment, securing their perimeter with Palo Alto firewalls and guaranteeing 99.99% uptime.

Cloud Diagram

The Challenge & The Solution

The Security Gap

The client was operating on significant "Technical Debt." Their flat network topology meant that once a hacker got past the SOHO router, they had unrestricted lateral movement. The DNS poisoning incident proved their internal resolution was compromised, and their backups were not air-gapped.

The Hybrid Fix

We moved from "hope" to "Zero Trust." Here is the new edge architecture:

  • Perimeter: Replaced the home router with a Palo Alto PA-450 to inspect Layer 7 traffic and block DNS attacks.
  • Patch Management: Decommissioned the broken WSUS server and implemented Azure Update Management for automated, cloud-controlled patching.
  • Identity: Deployed Azure AD Connect to sync their new Windows Server 2022 Domain Controller with the cloud.

Execution Strategy

A Zero-Downtime Rollout

Phase 1: Weeks 1-4

Recon & Architecture

We didn't just rush in. I spent the first month mapping inventory and dependencies to ensure our cost analysis held firm. We built the Azure "Landing Zone" (VNets, Subnets) to mimic their on-prem topology and established the VPN tunnel.

Crucially, we prioritized services to move during off-peak hours, ensuring the call center agents never faced a service interruption during the prep work.

VPN Gateway Cost Analysis VNet Design
Phase 2: Weeks 4-8

The Heavy Lift (Migration)

This was the critical move. We utilized Azure Migrate and AzCopy to shift 10TB of unstructured data to Azure Blob Storage.

We synchronized identities using Azure AD Connect but made a strategic call to keep a local DHCP server running. This created a resilient hybrid environment—ensuring that even if the fiber uplink fails, the local LAN remains functional for internal tasks.

Azure Migrate AzCopy Azure AD Connect Blob Storage
Phase 3: Weeks 8-12

Hardening & Handover

Cutover wasn't the end. We stress-tested DNS resolution and latency to ensure VoIP traffic was stable. Then, we locked the doors: enabling Microsoft Defender for Cloud and Azure Sentinel for real-time threat detection.

Finally, we conducted user training and decommissioned the legacy hardware, leaving the client with a fully redundant, cloud-native infrastructure.

Microsoft Sentinel Defender for Cloud MFA Enforcement

> MISSION_DEBRIEF

We didn't just patch a leak; we built a fortress. The legacy infrastructure is gone, replaced by a self-healing, cloud-native environment.

99.99%

Uptime SLA

Guaranteed availability via Azure Availability Zones.

$472k

Delivered On-Budget

Executed the full transformation without exceeding the RFP cap.

0

Incidents

Zero ransomware events or breaches since deployment.

© Copyright 2026 Slaterbytes.com - All Rights Reserved