PROJECT OVERVIEW
Built a small cloud-based IT environment using Cloudflare and Microsoft 365, with a custom domain supporting email, identity, DNS, and web services.
The project was designed as a practical exercise in domain management, DNS, Microsoft 365 administration, email authentication, identity security, and cloud hosting.
ARCHITECTURE
PLATFORM STACK
- Domain registrar: Cloudflare
- DNS provider: Cloudflare
- Email: Microsoft Exchange Online
- Identity: Microsoft Entra ID
- Web hosting: Cloudflare Pages
01 — DOMAIN & DNS
The project domain was registered through Cloudflare, which also provides authoritative DNS for the domain.
- Registered the project domain through Cloudflare.
- Configured Cloudflare as the authoritative DNS provider.
- Created DNS records for Microsoft 365 services.
- Created DNS records for web hosting.
- Verified DNS resolution after configuration changes.
Microsoft 365 domain ownership was verified using the required DNS verification record.
02 — MICROSOFT 365
A Microsoft 365 tenant was configured and connected to the custom domain.
- Created the Microsoft 365 organization.
- Configured the custom domain.
- Verified domain ownership through DNS.
- Configured Microsoft Entra ID.
- Assigned Exchange Online licensing.
03 — EXCHANGE ONLINE
Exchange Online was configured to provide hosted email using the project's custom domain.
- Configured the custom mail domain.
- Created the primary mailbox.
- Configured a role-based email alias.
- Configured MX records through Cloudflare DNS.
- Tested inbound mail delivery.
- Tested outbound mail delivery.
No self-hosted SMTP server is used. Exchange Online handles mail hosting and delivery.
04 — EMAIL AUTHENTICATION
SPF, DKIM, and DMARC were configured to improve email authentication and domain reputation.
- SPF: Authorized Microsoft 365 as a sending service.
- DKIM: Enabled cryptographic message signing.
- DMARC: Added policy and aggregate reporting.
All three authentication mechanisms were tested using outbound email and verified for successful results.
05 — IDENTITY & SECURITY
Administrative access was secured through Microsoft Entra ID and modern authentication controls.
- Enabled Microsoft Security Defaults.
- Configured Microsoft Authenticator.
- Configured a passkey.
- Tested multi-factor authentication.
- Verified protected administrative sign-in.
06 — CLOUDFLARE PAGES
The public website was built using static HTML and CSS and deployed through Cloudflare Pages.
- Created the HTML structure.
- Created the CSS stylesheet.
- Tested the site locally.
- Deployed the site through Cloudflare Pages.
- Connected the custom domain.
- Configured the
wwwhostname. - Verified HTTPS access.
VALIDATION
VERIFIED
- Domain ownership verification
- Cloudflare DNS resolution
- Microsoft 365 domain configuration
- Inbound email delivery
- Outbound email delivery
- SPF authentication
- DKIM authentication
- DMARC authentication
- MFA authentication
- Cloudflare Pages deployment
- Custom-domain HTTPS
wwwhostname access
SECURITY BOUNDARY
Documentation describes the architecture without exposing information required to access the environment.
- No passwords or credentials.
- No API keys or access tokens.
- No recovery codes.
- No private IP addresses.
- No tenant identifiers.
- No DNS verification secrets.
RESULT
The completed environment provides a functioning cloud-based infrastructure stack combining Cloudflare, Microsoft 365, Exchange Online, Entra ID, email authentication, and static web hosting.
The project demonstrates the complete process of establishing a domain, configuring DNS, connecting cloud services, securing identity, authenticating email, deploying a website, and validating the result.
NEXT ITERATION
PLANNED
- Setting up a helpdesk and ticketing system.
- Adding additional project summaries.
- Loading helpful tips and tricks