You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Charles-Antoine GourdonCG

Charles-Antoine Gourdon

Microsoft System Engineer

€600/day
Nantes, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Charles-Antoine

Microsoft System Engineer with 10 years of experience, specializing in identity (Active Directory / Entra ID), AD security, Microsoft 365 migrations, company integrations (Carve-in/Carve-out), and Microsoft infrastructure modernization.

My missions include:
🔹 AD / Entra ID Audits (hardening, legacy protocols, PingCastle analysis)
🔹 AD & Tiering Model Security (design, deployment, remediation)
🔹 AD / M365 / Azure Migrations (tenant-to-tenant, ADMT, BitTitan)
🔹 Carve-in / Carve-out for mergers/acquisitions
🔹 Azure Hybridization (AADC / Cloud Sync)
🔹 PowerShell Automation (governance, provisioning, hardening)
🔹 Architecture Scoping & Documentation (DAT)

My experience covers multi-site, multi-tenant environments, up to several thousand users, with a high level of autonomy and technical expertise.

🎯 Objective: to support companies in their AD / Security / M365 / Azure projects, with a rigorous and results-oriented approach.
  • French

    Native or bilingual

  • English

    Conversational

Can work on-site
Nantes (up to 50km)

Experience

  • Bessé
    AD Technical Expert / N3 System Engineer
    BANKING AND INSURANCE
    November 2024 - Today (1 year and 7 months)
    Nantes, France
    Besse — AD Technical Expert / N3 System Engineer

    Context:
    Taking over a multi-domain Microsoft On-Prem infrastructure (~400 servers) with high technical debt and numerous internal applications. Objectives: modernize tools, secure Active Directory, manage strategic projects, and support a highly customized critical IS.

    Achievements:

    RUN / Production
    • Integration into the N3 System team to manage a complete environment: AD DS, Exchange On-Prem, SharePoint On-Prem, Entra ID, PKI, SSO, JBOSS 5, JBOSS 7.
    • Management of a large number of internal business applications: analysis, operational maintenance, workarounds, compatibility, and patches.
    • Monitoring of sensitive network and multi-domain environments (prod / testing / dev).

    Modernization / Projects
    • Participation in AD remediation: security, structure, protocols, and rights.
    • Updating Microsoft components: servers, workstations, and middleware.
    • Obsolescence management: version upgrades and removal of unsupported components.
    • Updating critical vulnerabilities in collaboration with the SOC and CISO.
    • Redesign of the internal deployment system: MDT + WDS + scripts + dedicated storage.
    • Contribution to the Intune project to modernize park management:
    • Progressive migration MDT → Intune
    • Application packaging and configuration strategies (policies, security, compliance)
    • Workstation automation and standardization

    Support & Governance
    • N3 Support AD / Windows Server / System.
    • Training and skill development for N1 & N2 teams.
    • Participation in cross-functional IT projects and environment documentation (DAT, procedures, architecture).

    Technologies: AD DS, Exchange On-Prem, SharePoint On-Prem, Entra ID, SSO, MDT/WDS, PKI, GPO, Hyper-V/VMware, Veeam, Windows Server
    Active Directory Microsoft Exchange Veeam Windows Server Jboss
  • Kersia
    AD Consultant / PowerShell
    CHEMICAL
    August 2024 - August 2024
    Nantes, France
    Kersia — Deployment of a strong password policy (PowerShell)

    Context:
    Intervention on a legacy Active Directory lacking a robust password policy, with the need to deploy and control this policy centrally and automatically for all accounts.

    Achievements:
    • Development of PowerShell scripts to automate the implementation of the policy.
    • Testing and validation on different environments to ensure compliance and reliability.
    • Integration into existing AD policies to secure all user accounts.

    Technologies: PowerShell, AD DS
    Active Directory Powershell Scripting Windows Server IAM
  • Groupe Seb
    AD Architect
    TECH
    July 2024 - September 2024 (2 months)
    Lyon, France
    Groupe SEB — Active Directory Security Audit & Global Remediation (International Mission)

    Context:
    International mission on a global Active Directory, with a data center per continent and multiple local teams, to meet a high cyber insurer requirement. The objective was to secure all domain controllers and eliminate non-compliant protocols.

    Achievements:

    • Splunk analysis to identify obsolete AD protocols still in use (NTLMv1, SMBv1, unencrypted LDAP…).
    • Complete AD configuration audit.
    • Analysis of insecure traffic between international sites (Europe, Americas, Asia).
    • Coordination with IT teams from several countries to migrate to encrypted traffic.
    • Technical recommendations: LDAPS, SMB signing, disabling legacy protocols, AD hardening.
    • Support for the progressive deactivation of non-compliant protocols in global production.

    Technologies: Splunk, Windows Server, AD DS, GPO, LDAP/LDAPS, RBAC, Microsoft security hardening
    Splunk Kerberos Active Directory Protocole Remédiation

Recommendations

Be the first to recommend Charles-Antoine

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Microsoft Certified: Azure Fundamentals Sophos Certified Engineer CCNA Discovery
    Microsoft Certified: Azure Fundamentals Sophos Certified Engineer CCNA Discovery
  • Certified: Azure AI Fundamentals
    Microsoft
    Certified: Azure AI Fundamentals

Skill set

Categories