top of page
HTTPS listener on both server.jpg

Hybrid Infrastructure Modernization for NewVue Health

Objective: Transform a static on-premises IT environment into a dynamic hybrid cloud infrastructure capable of supporting a modern healthcare organization.

Approach:

  • Virtualization: Oracle VirtualBox, Windows Server 2022 VMs, NAT networking

  • Identity & Access: Redundant AD DS, FSMO role distribution, hierarchical OU structure.

  • Network Services: DHCP failover (load-balanced), AD-integrated DNS, internal web hosting (IIS).

  • Data & Storage: FSRM quotas & file screening, Storage Replica synchronous replication.

  • Cloud Integration: Azure AD Connect (password hash sync), Hybrid Azure AD Join, Intune MDM.

Outcome: A fully documented, production-ready hybrid environment that demonstrates enterprise-grade reliability, security, and manageability.

Implementation: Two-Phase Transformation
Phase 1: Building the On-Premises Foundation
Phase 2: Hybrid Cloud Integration

1. The Virtual Core: Architecting the Foundation

I engineered a complete virtual ecosystem using Oracle VirtualBox, establishing four production grade VMs connected via a secure NAT network (10.0.2.0/24). This included meticulous resource allocation, 2 vCPU/4GB RAM per server, and strategic OS deployment. Each machine served a distinct purpose: NV-DC1 as the primary domain controller, NV-DC2 for redundancy, NV-FS1 for centralized storage, and NV-CL1 as the validation endpoint. The network was carefully segmented with static IPs for infrastructure servers and DHCP for dynamic clients, creating a secure, isolated environment that mirrored real-world healthcare IT requirements.

2. Identity Architecture: Designing a Resilient Active Directory

I constructed a fault-tolerant identity backbone by deploying Windows Server 2022 domain controllers with strategic FSMO role distribution. NV-DC1 hosted the Schema Master, Domain Naming Master, RID Master, and PDC Emulator, while NV-DC2 managed the Infrastructure Master role a best-practice separation from the Global Catalog. I implemented a hierarchical OU structure aligned with NewVue Health's organizational departments, creating nested security groups for role-based access control. Automated AD replication between controllers ensured continuous authentication services, eliminating single points of failure in the identity layer.

3. Network Fortification: Engineering High-Availability Services

I built a resilient network core with redundant DNS and load-balanced DHCP failover. Both domain controllers hosted AD-integrated DNS zones for newvue.local, with synchronized forward and reverse lookup records. The DHCP failover relationship between NV-DC1 and NV-DC2 operated in load-balancing mode with a 50/50 distribution, ensuring continuous IP address availability. I configured DNS records for internal services (including www.newvue.local pointing to the intranet server) and validated that clients automatically received both DNS servers via DHCP, creating a self-healing network infrastructure.

4. Data & Storage Engineering: Securing Corporate Assets

I architected a comprehensive storage solution featuring departmental file shares with advanced management controls. Using File Server Resource Manager, I implemented 10GB storage quotas per department and file screening to block unauthorized file types (.exe, .mp4, .avi). A DFS Namespace provided unified access paths (\newvuehealth.local\Shares) abstracting physical server locations. Most critically, I configured synchronous Storage Replica between NV-FS1 and NV-DC1, establishing block-level real-time replication with zero data loss tolerance a crucial capability for healthcare data protection and business continuity.

5. Cloud Identity Bridge: Synchroni

I engineered the hybrid identity bridge by deploying Azure AD Connect on NV-DC1 with custom configuration for NewVue Health's specific needs. After preparing the on-premises directory using IdFix for attribute remediation and PowerShell scripts for bulk UPN updates, I configured password hash synchronization with a 30-minute delta sync cadence. The synchronization scope was precisely targeted to include only essential departmental OUs (Administration, Clinical Services, HR, IT, Finance), maintaining clean cloud directory hygiene while ensuring all critical identities were available in Azure Entra ID.

6. Modern Management Layer: Transforming Device Governance

I implemented a comprehensive modern management framework by configuring Hybrid Azure AD Join with automatic Intune enrollment. Through Group Policy, I ensured domain-joined devices automatically registered with both on-premises AD and Azure AD, creating a dual-state identity. In Intune, I deployed security baselines enforcing BitLocker encryption, password complexity, and firewall settings. I validated the management chain by successfully deploying Microsoft 365 Apps to NV-CL1 and executing remote device actions demonstrating true cloud-based endpoint management while maintaining on-premises compatibility.

7. Productivity Platform Integration: Unifying User Experience

I provisioned and configured a Microsoft 365 E5 tenant with custom company branding, creating a seamless authentication experience across cloud services. I validated access to Exchange Online, SharePoint, and Teams using synchronized identities, confirming that password hash synchronization enabled single sign-on capabilities. The implementation maintained on-premises Active Directory as the authoritative source while extending authentication to Microsoft 365 services, creating a unified productivity platform that spanned both environments without requiring separate credentials.

8. Validation & Health Monitoring: Ensuring Hybrid Harmony

I established comprehensive monitoring and validation processes using multiple verification methodologies. The Synchronization Service Manager showed successful import/sync/export operations with zero errors, while Entra Admin Center displayed synchronized users with "Windows Server AD" as source authority. I conducted authentication testing with both synchronized and cloud-native users, troubleshooting initial credential synchronization timing issues. Device compliance reporting in Intune provided real-time visibility into policy application, and PowerShell queries using Microsoft.Entra modules confirmed directory object visibility and synchronization health across the hybrid environment.

Infrastructure Modernization Portfolio

A comprehensive showcase of the NewVue Health hybrid infrastructure transformation project, demonstrating enterprise-grade IT architecture, cloud integration, and healthcare-specific solutions. This portfolio highlights technical implementation, problem-solving capabilities, and strategic thinking through documented evidence and measurable outcomes.

1b.png

NewVue Health: Hybrid Infrastructure Transformation

This project transformed legacy IT systems into a resilient hybrid cloud infrastructure for a simulated healthcare organization. Through meticulous planning and execution, I designed and deployed a complete enterprise environment featuring redundant Active Directory services, high-availability networking, real-time data replication, and seamless Microsoft 365/Azure integration all documented comprehensively on GitHub with 47-page technical report and configuration evidence.

  • LinkedIn
  • GitHub
  • Medium

©2025 Vivian J. Goshashy. Proudly created with Wix.com

bottom of page