Siemens Gamesa Moves From Microsoft IIS FTP to Files.com Without Moving Data Out of Azure
Siemens Gamesa Renewable Energy, part of Siemens Energy, designs, manufactures, installs, and services wind turbines for utilities, industrial customers, and governments worldwide. Infosys, the global IT services and consulting firm, manages IT infrastructure on Siemens Gamesa’s behalf.
An operation that size trades files with the outside world constantly. Banks and vendors send files in and take files out, and project teams share files with external counterparties at different levels of access. For years, that external exchange ran through on-premises Windows infrastructure.
Replacing it was not a lift-and-shift. Data at rest had to remain inside Siemens Gamesa’s own Azure tenancy. The service needed a Siemens-named domain on dedicated IP addresses rather than a vendor’s broad public range. Every user had to come from Entra ID, with multi-factor authentication enforced there and no locally created accounts. Administration also had to be delegable to the teams that owned each project.
External Exchange on a Server Security Had Already Ruled Out
The Microsoft IIS server provided FTP alongside a web interface, while an on-premises SFTP server received files from banks and other vendors. Roughly 500 user accounts had accumulated on the IIS server, most of them no longer active, and every one had been created locally on the box.
That local identity was the problem. Siemens Gamesa’s own cybersecurity function did not accept locally created accounts as compliant. The standing requirement was that every user authenticate through Entra ID, with a second factor enforced, and the IIS platform could provide neither.
The setup also concentrated all administration in one place. Every partner connection had to be configured and tested by hand, and user administration could not be delegated to the project owners who actually knew who needed access. Every routine access change therefore flowed through central IT.
The diagnosis was plain. The platform carrying Siemens Gamesa’s exchange with banks and vendors was one the company’s own security standards no longer permitted, and it could not be brought into line because local identity and manual administration were how it was built. As the organisation moved off legacy on-premises infrastructure into Azure, Siemens Gamesa began moving those workloads out.
Working with Infosys, Siemens Gamesa selected Files.com to provide the governed front door.
“We had the ability to have group administrators, so we could delegate user administration.”
A Files.com Front Door on Storage Siemens Gamesa Already Owns
Files.com became an exchange layer with no data of its own. Using a Files.com Remote Server Mount, the company’s Azure Files share sits behind the platform, so every file a bank or vendor sends over SFTP lands directly in Siemens Gamesa’s Azure tenancy and stays there. The Azure storage account’s firewall is restricted to Files.com addresses, and the design uses no on-premises server or agent.
Identity moved entirely to the directory. Users sign in through Entra ID over SAML, while SCIM provisions and deactivates their Files.com accounts as the directory changes. Those accounts are directory-managed rather than created locally. Multi-factor authentication is enforced through Entra, and folder permissions follow directory groups mirrored in Files.com.
Each external counterparty gets its own folder, with access granted only to that vendor’s named users and SSH key pairs generated on the platform for their connections. The site runs on a Siemens-named subdomain pointed at two dedicated public IP addresses, with certificates managed automatically.
Because Infosys delivers the service, Infosys administers a Files.com parent site while Siemens Gamesa operates on its own child site. This keeps the integrator’s administration separate from the client’s day-to-day environment.
Implementation covered the custom domain, Azure Files connectivity, and identity integration. From site activation in August 2025 to completed onboarding in October took roughly eight weeks, across change-approval processes spanning the Siemens Azure, Entra ID, and network teams, Infosys, and Siemens Gamesa’s engineering contacts.
Test folders and groups were built in Files.com while IIS remained in place. Partner SFTP connections were then scheduled to move in batches, with the remaining on-premises use cases planned to follow over several months.
A Repeatable Operating Model for External Access
For workloads moved to Files.com, local user administration is gone as a compliance exposure. Accounts and group membership follow Entra ID, and every login carries the second factor cybersecurity requires. When someone leaves, access ends where the directory says it does.
Routine access changes no longer route through central IT. Group administrators manage the users in their own groups, so the project owners who know who needs access are the ones who grant it.
Onboarding the next counterparty is also repeatable rather than bespoke: a folder, a permission set, and an SSH key, designed for a partner estate expected to span between 50 and 100 SFTP connections.
“It is kind of striking a very good balance between versatility and simplicity, which is really what can be difficult to do.”
The Mandate Met Without Moving the Data
In the legacy model, an access change was a request to a central IT team, executed by hand against a server the company’s own security function had already ruled out. In the new model, the group administrator who owns a project grants it, the directory decides who can log in at all, and the file a bank sends lands in Azure storage Siemens Gamesa already owned.
Files.com gave the company a way to satisfy every line of its security mandate: no local accounts, a second factor on every login, data at rest in its own cloud, and a named domain on dedicated addresses. None of it required rebuilding the exchange or relocating a byte of data. It required putting something governable in front of storage the company already had.
Related Customer Stories
Manufacturing
Coherent Replaced Zipped Email Attachments With Files.com Inboxes Tied to Salesforce Cases in Days
When an overnight security mandate closed the standard route for customer diagnostics, Coherent built an account-free, case-keyed intake path that kept its global service organization moving.
Read story →

Manufacturing
Finning Retired Two Regional FTP Servers and Closed a Near-20-Hour Telemetry Blind Spot With Files.com—Without Reconfiguring a Truck
More than 1,900 fixed-function machines kept dialing the same addresses while Files.com added the controls and arrival monitoring needed to protect telemetry that onboard storage could otherwise overwrite.
Read story →

Manufacturing
u-blox Retired Its Legacy FTP Platforms—and Three Years Later, Files.com Remains Its Only External Sharing Channel
Keeping the old servers off required more than modern protocols: u-blox moved directory identity, delegated administration, and transit-only retention into Files.com.
Read story →