The Microsoft Cloud Transformation - a comprehensive guide

Lesedauer 6 Minuten

"5 reasons why you should get rid of your Active Directory."

"On-premise infrastructure is so 90s – the future belongs to the cloud!"

"If the excavator cuts your line, no one can work anymore."

If a company still relies on on-premises infrastructure, consulting relevant IT guides or social media often leaves the impression that it is a dinosaur. The perception is that you are using outdated technology, facing a much heavier administrative burden, and—in any case—unable to protect yourself against attacks or system failures. The suggested solution? Simply move everything to the cloud, and everything will be fine.

Quite a few companies have trusted this promise—only to regret it later due to significantly higher costs.
Does this mean the cloud is inherently bad or always more expensive? Not necessarily! It simply highlights the need to carefully consider *what* you move to the cloud, *how* you do it, and—above all—*why* you are doing it (or should be doing it).

To explore this, let’s first look at some typical arguments for switching to the cloud and how the reality often (though not always) plays out.

One point upfront: this article series is not intended to provide an exhaustive set of arguments for or against the use of cloud services. Instead, it aims to serve as a resource for those who are interested in the topic but feel daunted by the sheer volume of available services and the pace of upcoming innovations.

The argument: reduced maintenance requirements

One of the main arguments for the cloud is the potential to reduce operational maintenance efforts. On one hand, this is true: there is no longer a need to manage underlying infrastructure such as servers, power supply, cooling, physical access security, and so on.

On the other hand, new or different types of effort arise. Since the cloud is subject to constant change, one must keep a close eye on these developments:

  • New features are continually being added, while others are discontinued.
  • Services are periodically revised, modernized, or completely redeveloped.
  • Cloud services are subject to different—and often more restrictive—security requirements (for instance, certificate validity periods, which have been drastically shortened).

Likewise, the knowledge required for operations must first be built up and then constantly maintained. While this also applies to local infrastructure, things there typically do not change quite as rapidly.

Conclusion

Using cloud services can reduce maintenance efforts. However, as a rule, the workload merely shifts to other areas. In addition, the use of cloud services creates a need for training, and new positions often have to be created for this purpose.

The argument: a better response to security threats

The threat landscape has intensified significantly, particularly in recent years. Gone are the days when infrastructure and systems required only infrequent updates. On the contrary, organizations must now respond immediately and continuously to new threats, as attackers constantly devise novel and creative ways to cause damage.

Consequently, there is a growing need for systems designed to defend against—or at least contain—such attacks. Operating and managing each of these systems requires specialized knowledge. While comprehensive solutions do exist, they typically fall short of achieving 100% coverage.

Cloud-based services face this same fundamental challenge, though generally to a lesser extent. Platforms like Microsoft Azure consolidate a wide range of offerings under a single umbrella, enabling the centralized aggregation of data from all these systems (for instance, using Microsoft Sentinel or Defender XDR, depending on the service tier). However, it is important to note that this approach effectively places you in the hands of a service provider, requiring a certain level of trust in them from the outset.

Conclusion

The cloud offers a wide range of services to protect one's own infrastructure—including on-premises systems—against threats and to detect attacks at an early stage. However, this requires trusting the cloud provider to effectively manage its own services and close security gaps as quickly as possible. On-premises solutions of this kind are often expensive to acquire and can entail significant additional maintenance overhead.

The argument: better user experience

The working world has undergone a profound transformation, particularly since the onset of the COVID-19 pandemic. While working from home once seemed unusual or was a privilege reserved for senior management, it has now become an indispensable component of hybrid corporate structures.

This shift presented companies with significant, immediate challenges. Existing infrastructures were not originally designed to handle large-scale remote access, necessitating substantial investment in modernization and expansion. Furthermore, new software solutions were required to facilitate seamless collaboration across the organization.

This served as a catalyst for the adoption of solutions such as Microsoft 365 (specifically Teams) and Microsoft Azure. Teams was designed with collaboration at its core and has undergone numerous improvements and revisions over the years. Similarly, Microsoft Azure has expanded its service portfolio over time to enable the gradual replacement of on-premises services—for example:

  • Azure Update Manager replacing Windows Server Update Services
  • Azure File Shares replacing traditional Windows Server file shares
  • Azure Automation replacing scheduled tasks on Windows Server

These services can also improve the experience for administrators, as they primarily require configuration rather than the complex setup and ongoing maintenance associated with the underlying systems.

Conclusion

Whether the user experience actually improves through the use of cloud services depends heavily on how such services are implemented and how users are introduced to using them. However, the cloud undoubtedly offers immense potential for enhancing the user experience, particularly due to the diverse opportunities for collaboration.

The practice: restraint

While Microsoft 365 and Entra ID have become widely adopted and are heavily used, the situation is somewhat different for Microsoft Azure (as well as platforms like Amazon Web Services and Google Cloud Platform). Companies are often hesitant here, tending to use the platform primarily for development environments. These platforms offer significant advantages over traditional infrastructure, particularly for developers:

  • Services can be flexibly tested for a specific period and then cancelled (so-called "throwaway IT")
  • Services can be scaled flexibly
  • Provisioning is much faster than with on-premises infrastructure (where complex request and deployment processes can cause delays)

For these reasons, the adoption of such platforms is often driven by developers. However, it is relatively rare for an IT department to consider how to supplement or replace traditional infrastructure with Azure services. The reasons for this are obvious:

  • On-premises infrastructure is already in place and paid for
  • Services are running as intended and meeting requirements
  • Expertise regarding infrastructure operation and monitoring is already established

At first glance, therefore, a move to the cloud offers no apparent advantages:

  • Additional costs arise for provisioning the necessary cloud services
  • One must constantly anticipate changes that could impact operations
  • New expertise must be developed for operating and monitoring cloud services

This is certainly understandable. However, a comprehensive IT strategy must encompass all aspects and possibilities to ensure an appropriate response to new requirements at all times.

Why a cloud transformation?

That is why this post kicks off a new article series on the topic of "cloud transformation." The aim is to clearly illustrate:

  • the opportunities the cloud offers,
  • how cloud services can effectively complement or even replace traditional infrastructure,
  • the pros and cons of specific services compared to traditional infrastructure,
  • how a company can evolve—step by step—toward a pure cloud infrastructure.

Hopefully, this will help alleviate some of the overwhelm caused by the sheer volume of available services. And perhaps you’ll even have a personal "aha" moment or two, realizing that Azure isn't actually all that bad. 😉

One more thing: these posts are all based on practical experience from my client projects. You won't find any generic fluff here—just real-world implementations, warts and all. And let’s be honest: not everything that glitters is gold. But with the right support, these challenges can certainly be mastered!



About the articles (planned; topics are subject to change!):

Part 1: Getting Started: Provisioning an Azure Subscription

Part 2: Only I shall see my resources – with private network access

Part 3: IP addresses are so 90s—DNS names are the way to go!

Part 4: User VPN, made easy – with Entra-based authentication

Part 5: When Teams isn't the right fit – cloud-based file shares

Part 6: Cloud scripts belong in the cloud!

Part 7: Workgroup servers are a hassle – Azure Arc makes things better

Part 8: Goodbye WSUS – hello Azure Update Manager!

Part 9: Are all our servers actually hardened? Let’s find out!

Part 10: The Defender platform does more than just endpoints

Part 11: Real-world example: how a company underwent a complete transformation



Liked this article? Share it!