Profile
Kjetil Furås
Principal Consultant · Azure Solutions Architect · 16 years across infrastructure, security, and automation.
I started on the support phones in 2010, taking first-line calls for customers on Citrix. Since then I have worked every layer: on-site operations, physical data centers, VMware clusters, Cisco networks, and from 2017 onwards mostly Microsoft Azure. The last few years I have built and migrated Azure platforms for Norwegian enterprises and public sector clients, much of it as infrastructure as code.
The core of what I do sits where infrastructure meets security and automation: identity, networking, platform hardening, and moving manual operations into code. Outside consulting I keep my lab work on GitHub and write on this blog.
Experience
Principal Consultant · Basepark (Iteam group)
2025 —
Azure infrastructure as code for enterprise clients. Bicep, Azure Verified Modules, GitHub Actions with OIDC.
Senior Consultant · Crayon
2022 — 2025
Cloud architecture and senior operations for cloud and hybrid environments. Landing zones, Defender for Cloud, Sentinel, platform engineering.
Cloud Solution Architect · Visolit / Advania
2020 — 2022
Solution architect for Azure migrations. Planning, design, and hands-on execution of on-prem to cloud moves.
Senior Consultant · Netscenario / Visolit
2018 — 2020
Operations for customer infrastructure in Norwegian colocation data centers. Microsoft 365 and Azure tenants, SCCM, data center migrations.
Senior Systems Engineer · Global Maritime
2012 — 2018
Ran the company's infrastructure end to end: VMware clusters, Cisco networking, CheckPoint firewalls, hybrid AD, Azure IaaS, backup.
Consultant · Telecomputing / Alcom
2010 — 2012
Support and on-site operations for customers in Citrix environments. Servers, networking, Exchange.
Selected work
Client names are left out on purpose. The full project list is available on request.
Azure platform engineeringEnergy sector
2025 —
Infrastructure as code with Bicep and Azure Verified Modules: automated Windows Server provisioning, NSGs, Azure Monitor and Log Analytics with Data Collection Rules, Key Vault integration, and CI/CD via GitHub Actions with OIDC.
Information protectionData center operator
2024 — 2025
Ran the Microsoft Purview / Information Protection implementation: sensitivity labels, data classification, DLP policies, plus Privileged Identity Management improvements in Entra ID.
Cloud securityPublic sector institution
2024
Completed a Defender for Cloud rollout: onboarded the on-prem fleet to Azure Arc, held workshops on Azure Policy, and mapped recommendations to NIST and NSM security baselines.
Cloud platform teamGovernment agency
2023
Part of the team running the full Azure platform as code. Implemented Microsoft Sentinel with UEBA via Bicep, Azure custom policies for compliance enforcement, Defender for Cloud, and network zoning with microsegmentation: NSGs, ASGs, route tables, S2S/P2S VPN.
Azure platform developmentSoftware company
2023 —
Built and extended the client's Azure platform with Bicep and Azure Pipelines: Microsoft Sentinel with data connectors, Application Gateway, Recovery Vault, and SQL Server VMs with private endpoints — all deployed as code.
PKI designCounty municipality
2022 —
Designed a new Public Key Infrastructure: requirements workshops, assessment of the existing environment, and a proposed architecture with drawings and documentation.
Disaster recovery for Azure Virtual DesktopSoftware company
2022
Proof of concept for cross-region DR: hub-and-spoke network, AVD host pools across two Azure regions, FSLogix Cloud Cache profile replication. The entire solution written in Terraform.
Azure region migrationSoftware company
2022
Moved a client's Azure workloads from the EU region to Norway: VNets, VMs, Azure SQL, Application Gateway, Key Vaults, and Web Apps. The move improved performance, and cost optimization along the way cut the client's Azure spend noticeably.
Senior Microsoft resourceMunicipal IT provider
2022 —
Stepped in when the client lost a key person, acting as the most senior resource on Microsoft technology: PKI, Active Directory, Group Policy, Exchange Online, Intune, and SCCM. Ran an Intune proof of concept with Always-On VPN.
Cloud migrationsPublic sector
2022
Migrated a full server estate from on-prem hosting to Azure: landing zones deployed via Azure Pipelines, automated server provisioning, backup, and custom routing. Worked with the SOC team to prepare the servers for Rapid7 security auditing.
Toolbox
Cloud & IaC
Microsoft Azure, Bicep, Terraform, OpenTofu, Ansible, Azure Verified Modules, GitHub Actions, Azure DevOps, landing zones, Azure Policy
Security & identity
Microsoft Entra ID, Conditional Access, Defender for Cloud, Defender for Endpoint, Microsoft Sentinel, Purview / Information Protection, PKI, Key Vault
Microsoft platform
Microsoft 365, Intune, Active Directory, Group Policy, Exchange Online, Windows Server, SCCM, Azure Virtual Desktop, FSLogix
Data center & network
VMware vSphere, Hyper-V, Cisco, CheckPoint, iSCSI SAN, Veeam, DNS, DHCP, VPN (IPsec, BGP), microsegmentation
Automation & dev
PowerShell, Bash, Python, TypeScript, Next.js, Docker, n8n, Claude Code, AI agents
Products & projects
Certifications
Education
Certified System Specialist, Utbildning Nord (2009 — 2010)