Active Directory Experts in Germany
matched in minutes from over 15,000 CVs with the power of AI.Hire experts who design, harden, and troubleshoot Active Directory, build clean OU and GPO structures, and support domain services across hybrid Microsoft environments. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used Active Directory
Markus Halbedel
Last position:
Senior M365 Consultant at BITMARCK GmbH
Creation of concepts for M365 implementation, especially Tenants, EntraID, EntraConnect and ExchangeOnline, taking BAS standards into account (mandatory baseline security requirements) in the project "Concept M365" with the aim of transferring the concepts to the M365 environments of Bitmarck and then handing them over to the customer.
- Creation of a current-state analysis of the existing M365 environments as well as the on-premises environments and the BAS standards.
- Creation of concepts for the topics Tenants, EntraID, EntraConnect and ExchangeOnline taking the BAS standards into account
- Design and implementation of an automated solution for creating standardized M365 tenants based on Microsoft M365 DSC (Desired State Configuration)
- Transfer of the concepts into the M365 environments
- Creation of detailed technical documentation
Ornel Franck Wora Yeno
Last position:
Purchasing Manager, Logistics & IT Manager at Onlinehandler
Proactive support of management in business field development & innovation management
New development of a suite of business applications for analyzing valuation, P&L, and market price risk data
Automation of all internal and external business and work processes
Development of AI-based and AI-supported ETL processes as well as data analysis
Business use-case development
Business and work process optimization
Enterprise architecture management
Sales data analysis and forecasting as well as capture
Inventory management & reordering
Supplier management and communication
Customs processing & clearance
Shipping handling & warehouse coordination
Interface management
Technologies used: Microsoft Office 365, Microsoft Teams, JTL-Wawi, JTL-WMS, OTTO Partner Connect (OPC), Amazon Seller Central, DHL Global Forwarding, Jira, Draw.IO, Java (8,17,21,25), Jenkins, SonarQube, Git, Gitea, Spring Boot, Spring Batch, Vaadin, H2, PostgreSQL, Docker, Local LLMs, Postman, JasperSoft Studio, JasperReports
Yusuf Demirci
Last position:
Senior Project Management Transformation & Data at BG-PREVENT
Nationwide service provider for occupational medicine, occupational safety, and health management with a focus on prevention, health, and digital transformation.
- Role: Responsible for building and further developing professional project portfolio management in the area of Digital Transformation & Data. Steering and supporting strategic IT and transformation projects as well as supporting the introduction and establishment of project management standards, methods, and governance structures.
Focus areas:
- Build-up and further development of IT project portfolio management
- Analysis and structuring of business and technical requirements
- Steering and coordination of cross-functional IT initiatives
- Stakeholder management at business, management, and service provider level
- Introduction and further development of project management methods and tools (including Jira, Confluence, MS Planner)
- Preparation of decision bases, target visions, and implementation concepts in the context of digital transformation
- Steering and coordination of transformation, digitalization, and organizational projects
- Preparation of decision papers and management documents for steering committees
- Running workshops and stakeholder management with business units and IT teams
- Definition of requirements for dashboards, reporting, and KPI steering
- Support in the project Wissenskompass (requirements analysis and MVP concept)
- Analysis and evaluation of AI support options in knowledge management
- Investigation of AI use cases to improve knowledge provision and use
- Consideration of AI requirements as part of the Wissenskompass concept
- Coordination with strategic business units on the further development of project management standards
- Introduction, configuration, and training of Microsoft Planner to support project and task management
- Conducting user training and supporting employees in the introduction of new ways of working and tools
Christian R
Last position:
Project Manager Outlook and Teams Rollout at BWI
- Gathering information
- Creating wave concepts for the rollout
- Coordinating employees
- Monitoring and steering measures
- Project management including analyses & reporting to the board
- Creating instructions and requirement specifications
- Training floorwalkers
- On-site rollout support
- VIP support
- Introducing SharePoint
Burhan Dinler
Last position:
Enterprise Architect & Solution Architect at DB Netz AG
With project PRIZMA, DB will modernize its infrastructure on the one hand, and develop a fail-safe IT landscape on the other hand, which can be restored quickly and securely in case of a disaster.
- Capture current architectures of existing systems as well as methodical consulting and development of target architectures
- Deepen and maintain the building plan / target IT landscape
- Implement technical architecture concepts & architecture descriptions
- Implement migration concepts for updating and further developing the platform and information systems
- Assess submitted improvement suggestions as part of the project
- Capability management: identify capability gaps, develop target visions, and support transformation planning within the enterprise architecture.
- Create a compatibility matrix of the components in use and compare dependencies of specific versions
- Create an IT concept for extending the platform with the following topics: hardware and software requirements, security, licensing, high availability, load balancing, backup & recovery, update strategy, monitoring integration, etc.
- Coordinate with business architects as well as technical architects from the cross-functional architecture area of the PRISMA program for the topics (backup, Active Directory, monitoring, Citrix, and business applications ...)
- Status meetings and alignment of project planning with the Release Train Engineer / Project Manager
- Advise the Release Train Engineer / Project Manager in identifying project risks
- Advise the System Architect Engineers in steering the implementation of the concept
- Implement the IT concept
- Document the infrastructure
Label: MS Project, LINUX, Windows, ORACLE, Java, REST, SharePoint, Microsoft Exchange, UML, Enterprise Architect, BPMN, AZURE, AWS, V-MODEL, Micro Service, VisualStudio, SAP S/4HANA, SCRUM(SAFE), ESB (TIBCO), Python, Innovator, LeanIX (TOGAF), Ansible, Ansible Tower, Ansible Automation, ROBOT, SpringBoot
Markus Blohm
Last position:
Consultant, Technical Project Manager at Lanxess
- Project: ESU Windows and SQL Server consolidation / Configuration Management in ServiceNow
- Creation of an as-is analysis of all servers worldwide
- Creation of an as-is analysis of all SQL servers worldwide
- Creation of requirements analyses for SQL and server migrations
- Coordination of requirements with partners for migrations to Hyper-V (on-premises) or Azure Cloud
- Moderation of jour fixe meetings
- Creation of roadmaps and solution models for server migrations
- Setup of test scenarios
- Moderation of workshops for the introduction of a Global Admin Team
- Creation of data models (CMDB) in ServiceNow
- Conducting workshops for the CMDB data model
- Creation of solution models for the CMDB
- Creation of seamless configuration and work documentation for the CMDB
- Creation of reports for license management
- Creation of KPIs for data quality in ServiceNow
- Creation of a service catalog
- Moderation of workshops for creating service requests
- Interface between needs analysis and ServiceNow development team
- Systems used: Windows 7, Windows 10, Microsoft Office 365/2010, Windows Server 20xx, SQL Server 20xx, SharePoint, Azure Cloud, Hyper-V, ServiceNow, various tools
Halil Oeztoprak
Last position:
Senior Cloud Operations & DevSecOps Engineer (Azure / Terraform / CI-CD) at KfW Bankengruppe
Regulated environment within a German banking group (approx. 8,500 employees, hybrid cloud strategy).
Responsible for operating, provisioning, and continuously securing business-critical platforms – including a GenAI chat application, a big data/AI platform, and data science workspaces based on Azure Virtual Desktops and VMs. Ownership of Azure DevOps projects for ShaiHulud and React2Shell, as well as BSI alerts – Security Operations improvements across the SDLC.
Deployment responsibility for the GenAI chat application, big data/AI platform (BDAI), and data science workspaces (AVD/VM-based) in the respective landing zones.
Deployment & release management: end-to-end responsibility for deploying portal and service applications across multiple Azure landing zones, including technical approvals, compliance with development team deployment guidelines, and ensuring ITIL-based change and release processes via ServiceNow.
Azure landing zones & network architecture: design, provisioning, and operation of Azure landing zones for 3-tier web applications with enhanced network segmentation, VNet peering, hub-and-spoke architectures, private endpoints, and firewall integration across separate subscriptions and tenants.
Azure DevOps governance & operations: ownership of the Azure DevOps organization, including projects, repositories, and CI/CD pipelines; implementation of governance requirements such as branch policies, approval gates, permission models, and audit-ready operating structures.
Infrastructure as Code (Terraform): design, implementation, and operation of a modular Terraform architecture for standardized cloud infrastructure deployment, including state management, provider versioning, reusability, and policy-as-code approaches.
CI/CD pipeline engineering: design, operation, and optimization of complex YAML-based CI/CD pipelines with multi-stage deployments, template standardization, self-hosted agents, integrated secret management, and automated quality and security checks.
Git migration & platform consolidation: planning and execution of repository and pipeline migration from Azure DevOps to GitLab CI/CD, including automated scripts, full Git history transfer, pipeline porting, and platform consolidation.
Container & platform operations (AKS): operation and security assessment of containerized workloads on Azure Kubernetes Service, centralization of on-premises container registries for ACR.
OpenShift (OCP) security reviews: security assessment of code baselines, build pipelines, and deployment processes for on-premises OpenShift clusters with critical applications, and derivation of specific hardening recommendations.
Shift-left security & DevSecOps transformation: introduction of a company-wide shift-left approach for early security integration in development and deployment processes, enabling developers to perform self-led security checks and sustainably reduce vulnerabilities before production (IDE integrations, pre-commit hooks, local scanners).
Software supply chain security: analysis and mitigation of supply chain risks in NPM- and Yarn-based applications through dependency audits, CI/CD pipeline hardening, token rotation, and restriction of risky build and lifecycle mechanisms.
Frontend & framework security (React / Next.js): security assessment and coordination of critical vulnerability remediation across platform applications and web frameworks, including coordination and complementary technical mitigations with all teams following BSI alerts.
Software composition analysis (SCA): introduction and operation of automated vulnerability scans for container images, pipelines/artifacts, and third-party dependencies, including SBOM exports within CI/CD pipelines.
SAST/DAST integration: design and piloting of static and dynamic application security tests in close collaboration with security architecture and development teams, for continuous improvement of code and runtime security, and establishing operational acceptance tests.
Artifact & registry consolidation: analysis and consolidation of all package and container repositories for service applications and AKS workloads, aiming for a centralized, secured registry strategy with centralized vulnerability scanning and governance.
Dependency-Track & SBOM strategy: advising the compliance board on introducing a central SBOM and vulnerability management platform to increase enterprise-wide dependency transparency and accelerate CVE response capability.
CI/CD pipeline hardening: security analysis and cleanup of the existing pipeline landscape by removing unused pipelines, improving secrets hygiene, implementing least-privilege principles, and isolating build agent environments.
Azure Web Application Firewall (WAF) optimization: analysis and tuning of existing Azure WAF rules (OWASP Top 10 Core Rule Set, DSR/SDC, custom rules) to defend against known vulnerabilities and exploit patterns, including reducing false positives and improving threat detection.
Documentation & stakeholder communication: creating and maintaining technical documentation, runbooks, and architecture overviews in Jira and Confluence, as well as active knowledge transfer between operations, development, security, and compliance stakeholders.
Vicenco Kenk
Last position:
ITSM Project Manager (self-employed)
Unified ITSM framework
- Definition of a company-wide ITSM target picture
- Introduction of a uniform service structure across all business units
SLA and OLA management
- Building a standardized SLA framework
- Definition of service classes (Business Critical, Standard, Low Priority)
- Introduction of OLAs between internal teams
- Building meaningful SLA reporting
- Definition of KPI and service dashboards for business units
Service portfolio management
- Definition of service descriptions
- If needed, preparing possible cost and service billing
Ticketing & processes
- Incident management
- Uniform ticket categories
- Standardized prioritization
- Escalation matrix
- Automations
- Self-service optimization
Request fulfillment
- Service catalog across all business units
- Approval workflows
Problem management
- Introduction of root cause analysis
- Known error database
- Problem review process
Complete asset management concept
- Hardware lifecycle management
- Software lifecycle management
- Leasing lifecycle
- Mobile device lifecycle
- Monitor lifecycle
- Phone lifecycle
Processes
- Procurement
- Goods receipt
- Inventory
- Assignment
- Return
- Disposal
- Leasing return Goal: single source of truth for all assets
CMDB design
- Definition of all configuration items:
- Workplace
- Notebooks
- Monitors
- Mobile phones
- Printers
Infrastructure
- Servers
- Firewalls
- Switches
- WLAN
- Storage
- Backup systems
Cloud
- Azure resources
- Microsoft 365
- SaaS services
Relationships
- User ↔ Asset
- Asset ↔ Service
- Service ↔ Infrastructure
- Location ↔ Asset
- Goal: make all service dependencies visible
Software asset & license management
- License management concept
- License balancing
- Compliance reporting
- Microsoft license management
- Adobe license management
- SaaS management
- Contract management
- Renewal management
Interfaces & automation Existing systems
- Workday
- Joiner
- Mover
- Leaver
TESMA
- Leasing data
- Contract data
Matrix42
- Asset synchronization
- User synchronization
Active Directory / Entra ID
- User management
Microsoft 365
- License assignment
- Group management
Dormakaba
Access processes
Lifecycle services
Monitoring platforms
- PRTG
- Palo Alto
- Cisco
Reporting & KPI framework
- Definition of a management dashboard
- KPIs
- Ticket volume
- SLA fulfillment
- MTTR
- First resolution rate
- Asset accuracy
- License compliance
- Change success rate
- Service availability
- Degree of automation
Network redesign support
- Governance
- Support of the network redesign from an ITSM point of view
- Definition of affected services
- Change management structure
- Communication concept
CMDB integration
- Recording of all network components
- Service mapping
- Dependency analysis
Validation of documentation and knowledge base articles
- Network documentation
- Operations documentation
- Standard changes
Monitoring & event management
- Target picture
- Central monitoring concept
- Event management process
- Alerting strategy
- Escalation model
Systems
Cisco
Palo Alto
Fortinet
Rubrik
Veeam
Matrix42
Azure
Microsoft 365 Automation
Ticket creation from monitoring
Escalations
Standard actions
Audit, compliance & information security
- ISO 27001 consulting
- TISAX consulting
- NIS2 preparation - consulting
- Audit-ready processes
- Documentation structure
- Evidence tracking in Matrix42
Roadmap
- 12-month roadmap
- Prioritization of all measures
- Quick wins
- Medium-term projects
- Long-term target picture
- Documentation
Sumalatha Bhuchupalle
Last position:
Copilot Cloud Security Chatbot | AI / LLM at Banyan Cloud
Conversational AI assistant for cloud infrastructure and security queries
- Designed FastAPI backend with multi-turn conversation handler, token budgeting, and context window management.
- Integrated Amazon Bedrock (Claude 3 Sonnet/Haiku); built RAG pipeline with MongoDB chat history and semantic search.
- Implemented Factory Pattern for modular LLM provider switching; reduced model onboarding effort by 60%.
- Reduced LLM inference cost by 35% through model tiering (Haiku vs Sonnet) and prompt/entity consolidation.
Tech: Python, FastAPI, Amazon Bedrock, MongoDB, Streamlit, Pydantic.
Agelis Wassilios
Last position:
Senior Application & IT Service Management at AW-Datentechnik
- Focus on acquiring new enterprise IT projects as well as further developing the IT service and application management profile
- Available for new projects in application management, IT service management, and application operations
Artyom Narimanyan
Last position:
AI Automation Engineer & Solution Architect at Technology Research Project
Designed and developed an AI-powered automation platform using n8n to analyze social media niches, identify target audiences, and automate marketing strategy generation. The solution combined AI agents, workflow orchestration, and data analysis to automate research processes and generate data-driven insights.
- Designed and implemented complex automation workflows using n8n
- Developed AI-powered analysis agents for market and audience research
- Integrated multiple APIs and AI services into automated workflows
- Built automated market, competitor, and target audience analysis pipelines
- Leveraged Large Language Models (LLMs) for information summarization, classification, and prioritization
- Containerized and deployed the platform using Docker
Technologies: n8n, AI Agents, OpenAI APIs, Prompt Engineering, LLMs, Docker, Linux, REST APIs, Webhooks
Matthias Batz
Last position:
Windows Administrator at Telair GmbH
Windows Administrator, software deployment, user support, Azure / Entra administrator, hardware support, software packaging, defining and introducing processes
Tasks performed:
- Handling incidents, service requests & changes in the Matrix42 ticket system
- Handling / resolving incidents
- User creation / permissions
- Installation and patch management for Windows
- Permissions and license management in Entra
- Process improvement and documentation
Tools and methods used: Windows Server 2016 / 2019, Active Directory, Windows 11, Office 365, Azure / Entra, Ivanti, VMWare & ESX, Dell & Kyocera Minolta & Zeus hardware support
Syed Abdul
Last position:
Senior Software Engineer at Giant Eagle
- Designed and developed AI-powered document processing solutions using Python, OCR, NLP, and Large Language Models (LLMs) to automate extraction, validation, and classification of financial documents, reducing processing time by 75%.
- Built intelligent multi-stage workflow automation pipelines integrating AI services, machine learning models, and enterprise systems to streamline financial operations and improve data quality.
- Developed reusable AI-driven transformation frameworks capable of processing structured and unstructured document formats (XML, CSV, JSON, TXT, DAT) and normalizing them into unified business schemas.
- Designed and developed Python-based REST APIs and backend services supporting enterprise finance applications and high-volume data processing workloads.
- Built scalable data synchronization pipelines between Oracle CFIN and SQL databases, incorporating machine learning models for cash-flow forecasting and AP/AR anomaly detection.
- Architected and deployed Apache Airflow workflows to orchestrate AI-powered data pipelines, automating end-to-end processing from document ingestion through financial system integration.
- Led the migration of critical enterprise integrations from MuleSoft to Python-based services, improving maintainability, performance, and operational flexibility while preserving complete data integrity.
- Managed the full API lifecycle including solution design, implementation, documentation, deployment, monitoring, and production support for mission-critical financial systems.
- Collaborated directly with finance stakeholders to identify business challenges, define solution requirements, and deliver measurable operational improvements through automation and AI-driven workflows.
- Worked closely with cross-functional engineering and business teams to rapidly iterate on features, improve processes, and drive successful adoption of AI-enabled solutions.
- Provided technical leadership through architecture reviews, technology decisions, code reviews, and engineering best practices across integration and automation initiatives.
- Mentored developers, established coding standards, and contributed to improving software quality, maintainability, and delivery effectiveness across projects.
- Provided production support during critical month-end and quarter-close financial processes, performing root-cause analysis and implementing rapid fixes to ensure system reliability and data accuracy.
Alexander Alawi
Last position:
Onsite Support Administrator at Sana Kliniken AG
- Processing and coordination of IT tickets (Helix, Omnitracker) incl. VIP support and remote support (Microsoft Teams, RDP, FastViewer)
- Onsite support at the main location as well as support for modern conference and meeting room technology (e.g. MeetingBoard 75 Pro)
- User and rights management in Active Directory (Active Roles), Azure AD, Exchange and MDM
- VDI support and monitoring with Citrix Director and Aruba Networking
- Endpoint management and policy administration via Ivanti
- Deployment, configuration and lifecycle management of clients (Dell notebooks, iPhones, iPads)
- Hardware rollouts for new employees incl. shipping across Germany
- Asset and license management as well as organization of site migrations
Jan Miltner
Last position:
Managing Director at Nexcent GmbH
- IT consulting
- Power Platform & Databricks
- AI software development (custom software)
- Commercial responsibility for the company
Discover over 15,000 top freelancers
Statistics of experts using Active Directory
Aggregated from the professional profiles of matched freelancers.
Experience
19 years
Position duration
3 years
Positions per freelancer
14
Top business areas
Information Technology, Operations, Project Management
Top industries
Information Technology, Banking and Finance, Manufacturing
Certification focus areas
Information Technology, Project Management, Operations
Bachelor's degree or higher
69%
Master's degree or higher
36%
Doctorate
5%
Certifications per freelancer
4
Most common languages
German, English, French
Speak two or more languages
97%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using Active Directory
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What it is
Active Directory is Microsoft’s directory service for identity and access in Windows environments. It stores users, groups, computers, and policies in one central place, so companies can control who can sign in, what they can reach, and how devices behave.
Where it fits
It is used for domain services, authentication, authorization, and policy management across on-premises and hybrid setups. Many teams also refer to it as AD or Microsoft Active Directory, especially when they mean Windows Server Active Directory.
Typical work
- Domain design and trust relationships
- Organizational units and group policy structure
- User, group, and computer lifecycle management
- DNS and replication troubleshooting
- Hybrid identity integration with Microsoft 365 and Entra ID
When specialists help
Companies bring in freelance experts when a domain is unstable, a migration is planned, or access control has become hard to manage. In Germany, this often comes up in enterprise IT, manufacturing, finance, and public-sector environments that still rely on Windows-based identity services.
What strong experts do
Strong professionals think in dependencies, not just settings. They understand replication, DNS, Kerberos, Group Policy, delegated administration, and security boundaries, and they can explain why a change affects authentication or device login.
Ecosystem and tools
- Windows Server and domain controller administration
- Group Policy Management, RSAT, and PowerShell
- Sites and Services, FSMO roles, and backup recovery
- Azure AD Connect, Entra ID, and hybrid sign-in flows
- Security hardening, audit readiness, and incident recovery
Frequently asked questions
Quick answers to the questions that come up most around Active Directory.
Active Directory is used to manage identities, access, and policy in Windows-based networks. It helps companies centralize logins, permissions, device rules, and group membership across many systems.
Bring in a specialist when a domain is failing, a migration is coming up, or your structure has become difficult to maintain. Active Directory projects often need outside help for cleanups, security hardening, and hybrid identity changes.
Active Directory handles traditional domain services for Windows networks, while Entra ID is built for modern cloud identity. Many companies use both together, so a good expert should understand hybrid sign-in, sync, and access flows.
A strong Active Directory professional usually knows DNS, Kerberos, Group Policy, PowerShell, and Windows Server administration. For hybrid work, knowledge of Azure AD Connect and Entra ID is also important.
Simple account and group tasks need less depth, but domain design, recovery, and migration work require a specialist who has handled production systems. Active Directory mistakes can affect logon, permissions, and service access across the company.
Many Active Directory tasks can be done remotely, including policy review, troubleshooting, and most migration planning. On-site access can still help when a company needs hands-on work with domain controllers, network segments, or restricted environments.
Look for clear explanations, careful change planning, and experience with recovery as well as setup. A strong Active Directory expert should be able to describe replication, permissions, and rollback steps before making changes.
Active Directory specialists often fix authentication failures, broken Group Policy, replication issues, DNS problems, and messy permission structures. They also help with domain consolidation, security reviews, and moves toward hybrid identity.
The average hourly rate of freelancers in Germany who have used Active Directory in their recent projects is 96 €, which corresponds to a daily rate of about 766 € based on an 8-hour working day.
Of the freelancers in Germany who have used Active Directory in their recent projects, 69% hold at least a Bachelor's degree, 36% hold at least a Master's degree, and 5% hold a doctorate.
On average, freelancers in Germany who have used Active Directory in their recent projects have 19 years of professional experience, with a single engagement typically lasting around 3 years.
The most common languages among freelancers in Germany who have used Active Directory in their recent projects are German (99%), English (96%), and French (17%).
The most common industries among freelancers in Germany who have used Active Directory in their recent projects are Information Technology (97%), Banking and Finance (54%), and Manufacturing (53%).
The most common business areas among freelancers in Germany who have used Active Directory in their recent projects are Information Technology (99%), Operations (76%), and Project Management (72%).
Main locations of FRATCH Experts, who have recently used Active Directory
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Hamburg
Munich
Cologne
Frankfurt
Dusseldorf
Essen
Nuremberg