About

I’m Kumar.

Formally, Palanikumar Annamalai. I am a Microsoft Cloud, Infrastructure, Identity & Security Architect based in Doha, Qatar, a Microsoft Certified Trainer, and a former Microsoft Cloud Solution Architect (2021–2024).

My work with Microsoft infrastructure began with Windows NT and Exchange 5.5. Since then I have worked through successive generations of it: implementing, migrating, upgrading and troubleshooting each one, and carrying what it taught me into the next.

Portrait of Palanikumar Annamalai

Technology progression

Each generation built on the last

The products changed names and architectures; the work did not. The stages below are in order, they overlap, and they are not dated.

  1. Windows NT
  2. Active Directory
  3. Exchange
  4. System Center
  5. Clustering
  6. Storage Spaces Direct
  7. Hybrid
  8. Azure
  9. Azure Local
  10. Microsoft 365
  11. Identity
  12. Security
  13. AI-era security
  1. Windows NT and Exchange 5.5

    Where my experience began: Windows NT servers and domains, and Exchange 5.5. It predates my certification record, which starts in the Windows 2000 era.

    • Implementation
    • Operations
  2. Windows Server and Active Directory

    The move from NT domains to Active Directory, then successive Windows Server releases. Each generation brought upgrades, domain migrations, and the work of finding everything that depended on the old one.

    • Migration
    • Upgrades
  3. Exchange generations and messaging

    Exchange from 5.5 onwards: upgrades and mailbox migrations from version to version, and the coexistence problems of running two generations at once.

    • Messaging
    • Migration
  4. System Center and enterprise management

    Managing estates at scale with System Center: deployment, configuration and monitoring, and the operational discipline that has to come with them.

    • Operations
    • Automation
  5. Virtualisation and failover clustering

    Moving workloads from physical servers to virtual machines and clustering them for availability: quorum, witnesses, and what survives a node failure.

    • Transition
    • Architecture
  6. Storage Spaces Direct and software-defined infrastructure

    Clustered Windows Server with local disks pooled into resilient storage: resiliency choices, capacity planning, and reading what the cluster reports when a disk or node fails.

    • Infrastructure
    • Troubleshooting
  7. Hybrid infrastructure and cloud

    Connecting on-premises estates to cloud services: hybrid identity, Exchange hybrid, and the decisions about what moves and what stays.

    • Architecture
    • Transition
  8. Azure

    Azure infrastructure alongside what still runs on-premises, and an operating model that has to work across both.

    • Architecture
    • Operations
  9. Azure Local

    Storage Spaces DirectAzure Stack HCIAzure Local

    At Dell (2020–21) and then at Microsoft as a Cloud Solution Architect (2021–24), my hands-on work was Azure Stack HCI and Windows Server with Storage Spaces Direct. Microsoft renamed Azure Stack HCI to Azure Local on 19 November 2024; the clustering and storage underneath are still where much of the troubleshooting happens.

    • Implementation
    • Troubleshooting
  10. Microsoft 365

    Exchange Online, Teams and the Microsoft 365 services that replaced much of what used to run on-premises, and the administration and migration work that comes with them.

    • Messaging
    • Transition
  11. Microsoft identity and access

    Microsoft Entra ID and hybrid identity: authentication, Conditional Access, identity governance and Privileged Identity Management.

    • Identity
    • Security
  12. Microsoft security and governance

    Microsoft Defender, Sentinel and Purview: security operations, and data and security governance built on Zero Trust principles.

    • Security
    • Architecture
  13. Identity and security in the AI era

    Where the work is now: passkey-first authentication, retiring legacy protocols before they are switched off, and applying identity, data and access controls to AI agents.

    • Identity
    • Security
    • Automation
Palanikumar speaks into a microphone from a lectern during a technical presentation.
Presenting to a technical audience.

What it taught me

Lessons from repeated transitions

Every generation brought a new product. The engineering lessons kept repeating.

  1. Every migration is a dependency hunt

    The plan is only as good as the inventory of what depends on the old system. The dependency nobody listed is the one that fails on cutover night.

  2. The old layer never really leaves

    Azure Local still runs on clustering and storage. Entra ID still meets Active Directory in hybrid identity. Knowing the layer underneath is most of the troubleshooting.

  3. Coexistence is where the risk sits

    Running two generations side by side, sometimes for months, is harder than either the old estate or the new one.

  4. Names change faster than architectures

    Knowing what a product used to be called is often how you find the right documentation, the right log and the right fix.

  5. Identity is the control plane

    From NT domains to Entra ID, whoever controls identity controls everything else. Security work starts there.

  6. Automate the second time

    The first run teaches the process. The script makes it repeatable, reviewable and teachable.

The work that recurs

  • Implementation
  • Migration
  • Upgrades
  • Transitions
  • Architecture
  • Troubleshooting
  • Operational ownership
  • Identity
  • Messaging
  • Infrastructure
  • Security
  • Automation

Current focus

Five areas I work in today

Plenty of people write about Azure Local or Entra ID today. Fewer have run the generations underneath them. That is the perspective I write and teach from.

  1. Infrastructure and hybrid cloud

    Windows Server estates, clusters and software-defined storage, and how they extend into Azure and Azure Local.

    • Windows Server
    • Active Directory
    • Failover Clustering
    • Storage Spaces Direct
    • Azure
    • Azure Local
  2. Identity and access

    From Active Directory to Microsoft Entra ID: hybrid identity, authentication, Conditional Access and privileged access.

    • Microsoft Entra ID
    • Hybrid identity
    • Conditional Access
    • Identity governance
    • Privileged Identity Management
  3. Messaging and collaboration

    Exchange since 5.5: on-premises generations, Exchange hybrid, Exchange Online and the Microsoft 365 around it.

    • Exchange Server
    • Exchange hybrid
    • Exchange Online
    • Microsoft 365
    • Teams
  4. Security and governance

    Security operations, identity security and data governance, built on Zero Trust principles rather than bolted on.

    • Microsoft Defender
    • Microsoft Sentinel
    • Microsoft Purview
    • Zero Trust
  5. Automation and technical enablement

    PowerShell and Microsoft Graph for the repeatable work, and labs, scripts and training so others can do it too.

    • PowerShell
    • Microsoft Graph
    • Labs and scripts
    • Training

Selected credentials

Current credentials

Certifications validate parts of the engineering story; they are not the story. These are the current ones most relevant to the work. The full record is verifiable on Credly.

Current, 2026

Microsoft Certified Trainer

Recorded AZ-900, AZ-104 and SC-200 training series, and technical presentations. Training

Expert certifications

  • SecurityMicrosoft Certified: Cybersecurity Architect Expert
  • CloudMicrosoft Certified: Azure Solutions Architect Expert
  • Microsoft 365Microsoft 365 Certified: Administrator Expert

Associate certifications

  • IdentityMicrosoft Certified: Identity and Access Administrator Associate
  • SecurityMicrosoft Certified: Azure Security Engineer Associate
  • Security operationsMicrosoft Certified: Security Operations Analyst Associate
  • CloudMicrosoft Certified: Azure Administrator Associate

Microsoft Applied Skills

  • Configure SIEM security operations using Microsoft Sentinel
  • Secure Azure services and workloads with Microsoft Defender for Cloud regulatory compliance controls

As of September 2026

active Microsoft certifications
18
passed Microsoft exams
32
Microsoft Applied Skills
2

Verify credentials on Credly (external site)

Certification history

A record across generations

Selected technology areas from my Microsoft exam history, from the Windows 2000 era to today. The work itself started earlier, with Windows NT and Exchange 5.5.

  1. Windows 2000
  2. Windows 2000 Directory Services
  3. Exchange Server 5.5
  4. Proxy Server
  5. Active Directory
  6. Windows Server
  7. Exchange Server 2010
  8. System Center
  9. Lync
  10. Windows Server infrastructure architecture
  11. Azure
  12. Microsoft 365
  13. Identity
  14. Security operations
  15. Cybersecurity architecture

Community

Training

I am a Microsoft Certified Trainer, current for 2026, and I treat teaching as part of the engineering work: if I cannot explain it clearly, I do not understand it well enough.

I have recorded 19 training sessions across AZ-900, AZ-104 and SC-200. Selected recordings will be added after review.

Training and upcoming sessions

Standards

How I publish

  • Versions and dates. Every article and lab states the product versions it was tested on, and carries a last-reviewed date as well as a published date.
  • Limitations stated. Labs and resources say what they do not cover, and where they will give you a wrong answer.
  • Case studies anonymised. Employer and customer details are removed, and nothing is published without approval.
  • Names as they were. Microsoft renames products often. I use the name that applied at the time of the work.

Contact

Connect

Senior architecture roles, training, or a technical question about something on this site: email is the best way to reach me. LinkedIn is where I share shorter technical notes.