Group Policy Experts in Munich
matched in minutes from vetted specialists with the power of AIHire experts who manage Group Policy Objects, Active Directory policy design, and Windows security baselines for offices and hybrid environments. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Munich, who have recently used Group Policy
Alexander Alawi
Last position:
Onsite Support Administrator at Sana Kliniken AG
- Processing and coordination of IT tickets (Helix, Omnitracker) incl. VIP support and remote support (Microsoft Teams, RDP, FastViewer)
- Onsite support at the main location as well as support for modern conference and meeting room technology (e.g. MeetingBoard 75 Pro)
- User and rights management in Active Directory (Active Roles), Azure AD, Exchange and MDM
- VDI support and monitoring with Citrix Director and Aruba Networking
- Endpoint management and policy administration via Ivanti
- Deployment, configuration and lifecycle management of clients (Dell notebooks, iPhones, iPads)
- Hardware rollouts for new employees incl. shipping across Germany
- Asset and license management as well as organization of site migrations
Mohamad Dib-Skhni
Last position:
Project Engineer at BMW Group AG
- Designed and implemented Azure Kubernetes Clusters, and managed DNS and Firewall solutions, enhancing network security and reliability.
- Led projects using Agile Scrum methodologies to streamline development cycles and improve project efficiency.
- Fostered and maintained relationships with suppliers to ensure timely project deliverables and resource availability.
- Managed continuous integration and delivery (CI/CD) pipelines using Jenkins, Sonar, GitHub, Bitbucket, and Terraform within the BMW Azure Cloud environment.
- Utilized Fortify SSC and Contrast AST for robust application security testing.
- Directed DevOps engineering initiatives on the SAP Business Technology Platform (BTP), focusing on streamlining development and deployment processes.
- Service Now governance, risk und compliance (GRC&IRM).
Konstantinos Metaxas
Last position:
IT-Fly Specialist – Global Rollout at Lufthansa Group
Plan & Prepare (Site Design & Readiness): Inventory & Design: Dell PowerEdge R-Series, Aruba switches (L2/L3), notebooks/peripherals; serials/asset tags, IPv4/IPv6 addressing, VLAN-/DHCP-/DNS plan
Runbooks/MOPs: site rollout runbook, backout strategy (<15–30 min), risk register, communication matrix; approvals via CAB/change
Images/Packages: Golden Image (Win10/11), driver packs, BIOS/UEFI baseline; O365/Teams/OneDrive KFM; BitLocker policies; MECM/SCCM, Intune/Autopilot, MDT/WinPE
Logistics: shipping/customs clearance, RMA/DOA, on-site spares; tools (barcode scanner, label printer), "Go-Bag" (cables, SFPs, console cables)
Deliver (on-site implementation): End devices: swap & migration (USMT/OneDrive KFM), peripherals (ATB/BT printers, scanners, boarding gate hardware); domain join, compliance checks, O365 activation, printers/queues, network drives
Acceptance: functional tests for DCS/CUTE/CUPPS/CUSS stations, ticketing/check-in workflows, boarding gates
Server (R-Series): rack & stack, cabling (PDU redundancy, fiber/copper), labeling/naming; firmware/RAID (PERC), Lifecycle Controller, iDRAC network; Windows Server 2022/2025 + CIS/BSI hardening; agents (backup/AV/EDR/monitoring), time service/NTP auth, Syslog/SNMPv3
Network (Aruba): VLANs, LACP trunks, MSTP root; PortFast + BPDU Guard at the edge; QoS (EF/AF); dual stack (v4/v6), DHCP relay. NAC/802.1X with ClearPass/Radius/TACACS+, roles + MAB fallback; guest isolation, ACLs (Guest→Mgmt deny). Telemetry: sFlow, SNMPv3, Syslog→SIEM; LLDP→inventory/CMDB
Airport specifics: CUTE/CUPPS/CUSS terminals; DCS/Amadeus/SITA connectivity; FIDS (read-only); bag tag/boarding pass printing; changes in off-peak/night windows
Stabilize (hypercare): first-day support, KPI tracking (login times, ticket volume, error classes), QoS fine-tuning
Troubleshooting: Wireshark/iperf, event logs, switch counters, sFlow flows; fast incident handling as SPOC
Knowledge transfer: short training sessions for station teams, mini-runbooks (fault/recovery)
Close (documentation & handover): docs & CMDB: final configs (switch/server), topology/patch plans, IP tables, serial/asset lists, before/after photos
Acceptance & sign-off: UAT protocols, functional evidence (use cases), return/reuse of old hardware
Lessons learned: risks, standard packages, driver freeze, "known issues"
Interfaces/communication: station IT, airport IT, SOC/NOC, ground ops/ramp/check-in, provider (SITA/Amadeus). ITSM: ServiceNow (Inc/Req/Change/KB), handover to BAU
Tobias Walther
Last position:
External Contractor at Government Agency
- Project support for VMware/Active Directory
- Operational support for administration, process execution
- Creation and review of documentation
- Active Directory, Powershell, VMware VSphere 7, Confluence, Jira
- Windows Server 2016/2019/2022/2025 GUI/Core
- Concept and rollout of Windows Update Services (approx. 500 client/server systems) and takeover of a central WSUS gateway company-wide
- Takeover and redesign KMS/RDS systems company-wide
Torsten Waldeck
Last position:
Product Owner at Beyonnex
Initial technical analysis of the requirements for the two applications
Creating a system concept for the interim solution and for the final solution
Creating the product vision, customer journey, and story map for the interim solution in close cooperation with subject matter experts
Building a development team
Managing dependencies and interfaces with the other applications according to Domain Driven Design principles
Creating EPICs and user stories, and maintaining the product backlog in coordination with subject matter experts and developers
Running sprint reviews with relevant stakeholders such as subject matter experts and management
Analyzing the requirements for the final solution
The interim solution was built within 8 months and was successfully used for the 2022 heating cost billing
The interim solution has since been further developed to increase automation
A technical concept for the final solution was created
Handover to two internal Product Owners is currently in progress
Marco Fischer
Last position:
System Engineer–Vmware, Veeam at DCSO
- About 800 different server VMs, operation and lifecycle/asset management of about 40 ESXi hosts (Lenovo)
- Upgrade of all clusters to ESXi/VCSA 7.0U3 and 8. Planning patch management for all hosts
- Cleaning up the AD – many different domains that all needed to be migrated into the main environment. Planning/execution
- Veeam – check the configuration and migrate to a newer, partly virtual infrastructure to make the setup leaner and faster
- VMware – upgrades/updates, general maintenance
- Proxmox POC – evaluate if an alternative to VMware
- Documentation for Veeam/VMware/storage
- Implementation of the uniflow cloud solution
- NetApp migration to new storage, CIFS maintenance and administration of SVMs
Alexander Schwartz
Last position:
Full-Stack Developer (Java/Kotlin/Angular) at Hypoport (Vergleich.de)
Further development of the vergleich.de website
Development of new and improvement of existing backend services as microservices
Deployment via TeamCity and GitHub Actions
Development of monitoring tools
Development of REST APIs
Database migration from Oracle to PostgreSQL
Java and Kotlin (including Spring, Spring Boot, JPA, Hibernate)
Angular (TypeScript) and JavaScript
IntelliJ IDEA and WebStorm
Apache Maven
Oracle DB (and SQL Developer), MongoDB, PostgreSQL DB
Git (GitLab, GitHub, BitBucket)
TeamCity
Jira
Docker
JUnit, Mockito, jasmin
Bernhard Tauchmann
Last position:
Project Manager at Law Firms / Tax Consultants
- Gathering requirements
- Planning and monitoring budgets
- Scheduling and tracking progress
- Revising the authorization concept
- Managing external service providers
- Quality assurance
- Handover to operations
Philipp Schmidt
Last position:
MS365 Consultant/Solution Architect at Self-employed
- Setup and configuration of an M365 tenant on a hybrid basis
- SSO integration of the existing app infrastructure like Metamost, Huhu, etc.
- License consulting, Entra ID initial configuration, MFA, Conditional Access, Privileged Identity Management
- Intune: initial configuration, Windows 11 Autopilot, iPhone AES
- Takeover of the tenant and preparation of a security audit
- Rollout of iPhones with AES (formerly DEP) as COPE (Corporate Owned, Business Enabled)
- Connecting external customers with enhanced security through Conditional Access
- Consulting on cloud-first strategy and migration to a cloud-only business
- Connecting various apps via SSO/SCIM (e.g. Atlassian, Personio, Adobe)
- On-premises AD: security audit and project management for replacing the local AD (migration of file servers, Navision2016, user clients joined to Entra ID)
- Copilot rollout with connection to external data sources and configuration via Intune
- Support for TISAX and ISO27001 preparation
- Setup and hardening of Entra ID, switching MFA to phishing resistant via Conditional Access
- Intune management for Windows and Apple clients, web enrollment switch to AES, introduction of Autopilot, app management, integration of Microsoft Defender
- Building a device baseline for Windows (COBO) and iOS/Android (BYOD)
- Teams/SharePoint Online: access concepts and integration into Teams
- Maintenance and backup of Entra ID and Intune tenants (drift management)
- M365 backup with Veeam
- Extending Conditional Access policies, introduction of Privileged Identity Management with hardware tokens and an on-premises admin tier concept
- Revision of existing GPOs regarding structure, security, and compliance
- Security audit and hardening of on-premises Active Directory and cloud tenant, SAML VPN, PIM introduction
- Support for the HR department in introducing a booking portal and general system engineering administration & security
- Introduction of Conditional Access and passwordless MFA, platform SSO, Defender for macOS/iOS, macOS compliance with Intune, Code2 signature configuration
Sebastian Fohler
Last position:
Managing Director System Administration & DevOps at Far Galaxy Networks
- Windows application migration using Windows Server 2022/2025, DHCP, Active Directory, directory trust and setup, GPO management
- Cloud service automation, firewall and network management, debugging
Discover over 15,000 top freelancers
Statistics of experts using Group Policy
Aggregated from the professional profiles of matched freelancers.
Experience
18 years (Germany: 20 years)
Position duration
1.2 years (Germany: 3.8 years)
Positions per freelancer
14 (Germany: 13)
Top business areas
Information Technology, Project Management, Operations
Top industries
Information Technology, Banking and Finance, Manufacturing
Certification focus areas
Information Technology, Project Management, Business Intelligence
Bachelor's degree or higher
67% (Germany: 57%)
Master's degree or higher
50% (Germany: 40%)
Doctorate
17% (Germany: 11%)
Certifications per freelancer
4 (Germany: 5)
Most common languages
German, English, Italian
Speak two or more languages
100% (Germany: 97%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Munich are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Munich using Group Policy
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What it covers
Group Policy is the Windows mechanism for controlling user and computer settings across an Active Directory environment. It is used to enforce security baselines, desktop behavior, software restrictions, drive mappings, scripts, and access rules. Companies bring in specialists when they need predictable Windows control at scale.
Where it matters
- Active Directory design and domain policy structure
- Security hardening for Windows endpoints
- Software deployment and update control
- Login scripts, printers, and shared resources
- Policy cleanup after mergers, moves, or audits
This work is common in larger office networks, regulated environments, and mixed on-site and remote setups. In Munich, it often touches IT teams that need stable workstation standards across several locations and language settings.
Ecosystem and tools
Strong specialists know Group Policy Management Console, the Local Group Policy Editor, Resultant Set of Policy tools, and PowerShell. They also understand how GPO inheritance, filtering, loopback processing, and OU design interact. Good work depends on clean AD structure and careful testing.
When to bring in help
Companies usually look for freelance expertise when policies become messy, logon issues spread, or a rollout needs tighter control. A specialist can trace conflicting settings, separate legacy GPOs, and document what should stay, what should be merged, and what should be retired. That saves time during migrations and audits.
What strong experts do
A strong professional does more than change a setting. They review the impact of every policy, test in staging, and keep changes small and reversible. They also write clear notes so internal teams can maintain the environment after the project ends.
Signs you need one
- Users receive different settings on different devices
- New security rules break normal work
- Policy processing is slow or hard to explain
- Old GPOs keep causing side effects
- You need a safe migration to a cleaner setup
In Munich, this is often easiest when the specialist can work remotely with local IT and join on-site only for troubleshooting that needs direct access to the network.
Frequently asked questions
Need clarity? These are the questions we hear most often about Group Policy.
Group Policy is used to control Windows settings from a central place in Active Directory. It helps teams enforce security rules, manage desktop behavior, push scripts, and keep user and computer settings consistent across the domain.
GPO is the common short form for a Group Policy Object, which is the unit used to deliver settings in Active Directory Group Policy. In practice, people often use the terms together when they talk about domain-based Windows policy control.
Group Policy support makes sense when policies conflict, logons become slow, or a Windows rollout needs a cleaner structure. It is also useful during mergers, domain reorganizations, security hardening, and cleanup of old settings that no one fully understands anymore.
A strong Group Policy specialist usually knows Active Directory, Windows Server, PowerShell, DNS, and basic security hardening. Good troubleshooting also depends on understanding OU design, permissions, login scripts, and how policy inheritance behaves across different devices.
Group Policy is best known for domain-joined Windows management inside Active Directory, while Intune and other MDM tools focus more on cloud-managed devices. Many companies use both, but a specialist should know when each tool fits and where overlap can create conflicts.
Group Policy projects range from simple settings cleanup to deep policy redesign. A small issue may only need a focused review, while a migration or security baseline project needs someone who can map dependencies, test changes safely, and explain the result clearly.
Group Policy work is often remote-friendly because most analysis, design, and testing can be done from anywhere. On-site time in Munich is only needed when a specialist must inspect local network behavior, join sensitive troubleshooting sessions, or work with restricted systems.
A strong Group Policy expert documents the current state before changing anything, explains trade-offs in plain words, and tests every change in a safe scope first. Look for clear thinking around inheritance, filtering, loopback processing, and rollback, not just familiarity with the GPMC.
The average hourly rate of freelancers in Munich, Germany who have used Group Policy in their recent projects is 97 €, which corresponds to a daily rate of about 775 € based on an 8-hour working day.
Of the freelancers in Munich, Germany who have used Group Policy in their recent projects, 67% hold at least a Bachelor's degree, 50% hold at least a Master's degree, and 17% hold a doctorate.
On average, freelancers in Munich, Germany who have used Group Policy in their recent projects have 18 years of professional experience, with a single engagement typically lasting around 1.2 years.
The most common languages among freelancers in Munich, Germany who have used Group Policy in their recent projects are German (100%), English (100%), and Italian (20%).
The most common industries among freelancers in Munich, Germany who have used Group Policy in their recent projects are Information Technology (100%), Banking and Finance (80%), and Manufacturing (70%).
The most common business areas among freelancers in Munich, Germany who have used Group Policy in their recent projects are Information Technology (100%), Project Management (90%), and Operations (80%).
Main locations of FRATCH Experts, who have recently used Group Policy
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Frankfurt