Skip to content

Latest commit

Β 

History

17 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

TechNova Enterprise Infrastructure Banner

TechNova Enterprise Infrastructure

Production-Grade Windows Server 2019 Enterprise Infrastructure
Built with Active Directory, PowerShell, Ansible, Vagrant, and Infrastructure as Code.

Windows Server PowerShell Ansible Vagrant GitHub


πŸ“– Overview

TechNova Enterprise Infrastructure is a production-style Microsoft Windows Server 2019 infrastructure project designed to demonstrate enterprise system administration, infrastructure automation, cybersecurity, and Infrastructure as Code (IaC) best practices.

Unlike traditional homelab projects, this repository follows real enterprise design principles with professional documentation, automation, security hardening, validation procedures, and operational guides.

This project is intended to simulate the IT infrastructure of a medium-sized enterprise and showcase skills expected from a:

  • Windows Server Administrator
  • Microsoft Infrastructure Engineer
  • System Administrator
  • DevOps Engineer
  • Infrastructure Engineer
  • Cybersecurity Engineer

🎯 Project Objectives

  • Design a production-style enterprise infrastructure
  • Deploy using Infrastructure as Code
  • Automate server configuration
  • Implement enterprise security best practices
  • Document every configuration
  • Create reusable PowerShell automation
  • Configure Windows using Ansible
  • Validate infrastructure health automatically

πŸš€ Quick Navigation

Category Link
πŸ“ Enterprise Architecture Open
🌐 Network Design Open
🏒 Active Directory Open
πŸ” Security Hardening Open
βš™οΈ PowerShell Automation Open
πŸ€– Ansible Automation Open
πŸ“– Operations Manual Open
πŸ›  Troubleshooting Open

🏒 Enterprise Architecture

The environment simulates a company with approximately 250 employees.

The infrastructure includes:

  • Two Active Directory Forests
  • Forest Trust Relationship
  • Centralized Authentication
  • DNS
  • DHCP
  • Group Policy
  • File Services
  • IIS
  • WSUS
  • Windows Deployment Services
  • RRAS VPN
  • Network Policy Server (RADIUS)
  • PowerShell Automation
  • Ansible Automation
  • Infrastructure as Code

Enterprise Architecture Diagram

TechNova Enterprise Architecture


πŸ–₯ Virtual Infrastructure

Machine Operating System Roles
DC01 Windows Server 2019 Active Directory, DNS, DHCP, WSUS
DC02 Windows Server 2019 Active Directory, DNS, WDS
SRV01 Windows Server 2019 File Server, IIS, RRAS VPN, NPS
CLIENT01 Windows 11 Administration & Testing

βš™ Technology Stack

Microsoft Technologies

  • Windows Server 2019
  • Windows 11
  • Active Directory Domain Services
  • DNS
  • DHCP
  • Group Policy
  • File Services
  • NTFS Permissions
  • IIS
  • WSUS
  • Windows Deployment Services
  • RRAS VPN
  • Network Policy Server (NPS)

Automation

  • PowerShell
  • PowerShell DSC
  • Ansible
  • WinRM
  • Vagrant

DevOps

  • Git
  • GitHub
  • Markdown
  • Draw.io

✨ Features

  • Enterprise Active Directory Design
  • Multi-Forest Architecture
  • Forest Trust Configuration
  • Organizational Units
  • Security Groups
  • User Management
  • Password Policies
  • Group Policy Management
  • DNS Infrastructure
  • DHCP Management
  • File Server with NTFS Permissions
  • IIS Web Server
  • Windows Update Services
  • Windows Deployment Services
  • Secure VPN Access
  • RADIUS Authentication
  • PowerShell Automation
  • Infrastructure Validation
  • Health Monitoring
  • Security Hardening
  • Enterprise Documentation

πŸ“ Repository Structure

technova-enterprise-infrastructure/

β”œβ”€β”€ assets/
β”‚   └── images/
β”‚
β”œβ”€β”€ docs/
β”‚   β”œβ”€β”€ architecture/
β”‚   β”œβ”€β”€ active-directory/
β”‚   β”œβ”€β”€ dns/
β”‚   β”œβ”€β”€ dhcp/
β”‚   β”œβ”€β”€ gpo/
β”‚   β”œβ”€β”€ file-services/
β”‚   β”œβ”€β”€ iis/
β”‚   β”œβ”€β”€ wsus/
β”‚   β”œβ”€β”€ wds/
β”‚   β”œβ”€β”€ vpn/
β”‚   β”œβ”€β”€ nps/
β”‚   β”œβ”€β”€ security/
β”‚   β”œβ”€β”€ operations/
β”‚   β”œβ”€β”€ troubleshooting/
β”‚   └── testing/
β”‚
β”œβ”€β”€ automation/
β”‚   β”œβ”€β”€ powershell/
β”‚   β”œβ”€β”€ ansible/
β”‚   └── vagrant/
β”‚
β”œβ”€β”€ diagrams/
β”‚
β”œβ”€β”€ screenshots/
β”‚
β”œβ”€β”€ reports/
β”‚
β”œβ”€β”€ scripts/
β”‚
β”œβ”€β”€ backup/
β”‚
β”œβ”€β”€ testing/
β”‚
β”œβ”€β”€ CHANGELOG.md
β”œβ”€β”€ CONTRIBUTING.md
β”œβ”€β”€ LICENSE
└── README.md

πŸš€ Deployment Workflow

Clone Repository
        β”‚
        β–Ό
Vagrant Provisioning
        β”‚
        β–Ό
PowerShell Bootstrap
        β”‚
        β–Ό
Enable WinRM
        β”‚
        β–Ό
Ansible Configuration
        β”‚
        β–Ό
PowerShell Automation
        β”‚
        β–Ό
Validation Scripts
        β”‚
        β–Ό
Health Reports

πŸ“š Documentation

The project documentation is organized into dedicated chapters that cover the complete lifecycle of designing, deploying, securing, automating, and maintaining a Microsoft enterprise infrastructure.

Chapter Description Status
Enterprise Architecture Business requirements, infrastructure overview, VM design, security principles and architecture decisions. βœ…
Network Design Enterprise network topology, IP addressing, routing, VLANs, DNS flow and firewall design. 🚧
Active Directory Forests, domains, trust relationships, Organizational Units, users, groups and delegation. 🚧
DNS DNS zones, forwarding, conditional forwarding, records and troubleshooting. 🚧
DHCP DHCP scopes, reservations, options, failover and lease management. 🚧
Group Policy Group Policy Objects, security baselines, software deployment and administration. 🚧
File Services Shared folders, NTFS permissions, access-based enumeration and DFS Namespace. 🚧
IIS Web Server IIS installation, website deployment, SSL configuration and logging. 🚧
Windows Server Update Services (WSUS) Centralized Windows updates, synchronization, approvals and reporting. 🚧
Windows Deployment Services (WDS) PXE boot, deployment images, unattended installation and client deployment. 🚧
VPN (RRAS) Secure remote access, VPN configuration and routing. 🚧
Network Policy Server (NPS) RADIUS authentication, policies and VPN integration. 🚧
PowerShell Automation Infrastructure automation, provisioning scripts and reporting. 🚧
Ansible Automation Windows configuration management using WinRM and Ansible roles. 🚧
Infrastructure Validation Health checks, verification procedures and automated testing. 🚧
Security Hardening Least privilege, LAPS, auditing, firewall, password policies and security baselines. 🚧
Backup & Disaster Recovery Backup strategy, Active Directory recovery and disaster recovery planning. 🚧
Operations Manual Daily administration tasks, user management, maintenance and monitoring. 🚧
Troubleshooting Guide Common issues, diagnostics, PowerShell commands and resolutions. 🚧
Project Reports Validation reports, inventories and infrastructure health reports. 🚧

πŸ“Š Infrastructure Statistics

Item Value
Virtual Machines 4
Active Directory Forests 2
Windows Servers 3
Windows Clients 1
Server Roles 10+
PowerShell Scripts 40+ (Planned)
Ansible Roles 10+ (Planned)
Enterprise Documents 20+ (Planned)

πŸ“· Screenshots

The completed project will include screenshots of:

  • Active Directory
  • DNS
  • DHCP
  • Group Policy
  • IIS
  • File Server
  • VPN
  • WSUS
  • WDS
  • PowerShell Automation
  • Ansible Deployment
  • Infrastructure Validation
  • Enterprise Reports

πŸ›£ Project Roadmap

Phase 1

  • Repository Initialization
  • Enterprise Architecture
  • Network Design
  • Active Directory
  • DNS
  • DHCP

Phase 2

  • Group Policy
  • File Services
  • IIS
  • WSUS
  • WDS

Phase 3

  • RRAS VPN
  • NPS
  • PowerShell Automation
  • Ansible Automation

Phase 4

  • Security Hardening
  • Monitoring
  • Validation
  • Backup
  • Disaster Recovery
  • Operations Guide
  • Troubleshooting Guide

πŸ”’ Security

The project follows Microsoft security best practices including:

  • Least Privilege
  • Account Lockout Policies
  • Password Policies
  • Windows Firewall
  • Secure RDP
  • Audit Policies
  • LAPS
  • NTFS Permissions
  • VPN Security
  • Administrative Separation

🀝 Contributing

Contributions, suggestions, and improvements are welcome.

Please read the CONTRIBUTING.md file before submitting changes.


πŸ“„ License

This project is licensed under the MIT License.

See the LICENSE file for more information.


πŸ‘¨β€πŸ’» Author

Wael Balhoudi

Master's Student β€” Windows Administration, Linux, Security & Cloud Computing

GitHub: https://github.com/WaelBalhoudi

LinkedIn: https://www.linkedin.com/in/wael-balhoudi-a89045275/


⭐ If you found this project interesting, consider starring the repository.

About

Production-grade Windows Server 2019 enterprise infrastructure built with Active Directory, PowerShell, Ansible, Vagrant, and Infrastructure as Code.

Topics

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors