Profile

Kjetil Furås

Principal Consultant · Azure Solutions Architect · 16 years across infrastructure, security, and automation.

Kjetil Furås

I started on the support phones in 2010, taking first-line calls for customers on Citrix. Since then I have worked every layer: on-site operations, physical data centers, VMware clusters, Cisco networks, and from 2017 onwards mostly Microsoft Azure. The last few years I have built and migrated Azure platforms for Norwegian enterprises and public sector clients, much of it as infrastructure as code.

The core of what I do sits where infrastructure meets security and automation: identity, networking, platform hardening, and moving manual operations into code. Outside consulting I keep my lab work on GitHub and write on this blog.

Experience

Principal Consultant · Basepark (Iteam group)

2025 —

Azure infrastructure as code for enterprise clients. Bicep, Azure Verified Modules, GitHub Actions with OIDC.

Senior Consultant · Crayon

2022 — 2025

Cloud architecture and senior operations for cloud and hybrid environments. Landing zones, Defender for Cloud, Sentinel, platform engineering.

Cloud Solution Architect · Visolit / Advania

2020 — 2022

Solution architect for Azure migrations. Planning, design, and hands-on execution of on-prem to cloud moves.

Senior Consultant · Netscenario / Visolit

2018 — 2020

Operations for customer infrastructure in Norwegian colocation data centers. Microsoft 365 and Azure tenants, SCCM, data center migrations.

Senior Systems Engineer · Global Maritime

2012 — 2018

Ran the company's infrastructure end to end: VMware clusters, Cisco networking, CheckPoint firewalls, hybrid AD, Azure IaaS, backup.

Consultant · Telecomputing / Alcom

2010 — 2012

Support and on-site operations for customers in Citrix environments. Servers, networking, Exchange.

Selected work

Client names are left out on purpose. The full project list is available on request.

Azure platform engineeringEnergy sector

2025 —

Infrastructure as code with Bicep and Azure Verified Modules: automated Windows Server provisioning, NSGs, Azure Monitor and Log Analytics with Data Collection Rules, Key Vault integration, and CI/CD via GitHub Actions with OIDC.

Information protectionData center operator

2024 — 2025

Ran the Microsoft Purview / Information Protection implementation: sensitivity labels, data classification, DLP policies, plus Privileged Identity Management improvements in Entra ID.

Cloud securityPublic sector institution

2024

Completed a Defender for Cloud rollout: onboarded the on-prem fleet to Azure Arc, held workshops on Azure Policy, and mapped recommendations to NIST and NSM security baselines.

Cloud platform teamGovernment agency

2023

Part of the team running the full Azure platform as code. Implemented Microsoft Sentinel with UEBA via Bicep, Azure custom policies for compliance enforcement, Defender for Cloud, and network zoning with microsegmentation: NSGs, ASGs, route tables, S2S/P2S VPN.

Azure platform developmentSoftware company

2023 —

Built and extended the client's Azure platform with Bicep and Azure Pipelines: Microsoft Sentinel with data connectors, Application Gateway, Recovery Vault, and SQL Server VMs with private endpoints — all deployed as code.

PKI designCounty municipality

2022 —

Designed a new Public Key Infrastructure: requirements workshops, assessment of the existing environment, and a proposed architecture with drawings and documentation.

Disaster recovery for Azure Virtual DesktopSoftware company

2022

Proof of concept for cross-region DR: hub-and-spoke network, AVD host pools across two Azure regions, FSLogix Cloud Cache profile replication. The entire solution written in Terraform.

Azure region migrationSoftware company

2022

Moved a client's Azure workloads from the EU region to Norway: VNets, VMs, Azure SQL, Application Gateway, Key Vaults, and Web Apps. The move improved performance, and cost optimization along the way cut the client's Azure spend noticeably.

Senior Microsoft resourceMunicipal IT provider

2022 —

Stepped in when the client lost a key person, acting as the most senior resource on Microsoft technology: PKI, Active Directory, Group Policy, Exchange Online, Intune, and SCCM. Ran an Intune proof of concept with Always-On VPN.

Cloud migrationsPublic sector

2022

Migrated a full server estate from on-prem hosting to Azure: landing zones deployed via Azure Pipelines, automated server provisioning, backup, and custom routing. Worked with the SOC team to prepare the servers for Rapid7 security auditing.

Toolbox

Cloud & IaC

Microsoft Azure, Bicep, Terraform, OpenTofu, Ansible, Azure Verified Modules, GitHub Actions, Azure DevOps, landing zones, Azure Policy

Security & identity

Microsoft Entra ID, Conditional Access, Defender for Cloud, Defender for Endpoint, Microsoft Sentinel, Purview / Information Protection, PKI, Key Vault

Microsoft platform

Microsoft 365, Intune, Active Directory, Group Policy, Exchange Online, Windows Server, SCCM, Azure Virtual Desktop, FSLogix

Data center & network

VMware vSphere, Hyper-V, Cisco, CheckPoint, iSCSI SAN, Veeam, DNS, DHCP, VPN (IPsec, BGP), microsegmentation

Automation & dev

PowerShell, Bash, Python, TypeScript, Next.js, Docker, n8n, Claude Code, AI agents

Products & projects

Certifications

Education

Certified System Specialist, Utbildning Nord (2009 — 2010)