Senior End User Computing Engineer

Legacy endpoint estates, re-architected cloud-native.

I take multi-thousand-endpoint environments off on-prem SCCM and KACE and rebuild them as cloud-native, self-healing platforms — Autopilot provisioning, Conditional Access across Windows and macOS, and remediation that closes tickets before they open.

Fitchburg, Wisconsin
About

Five years turning helpdesk chaos into automated platforms.

I build the systems that fix things before a ticket is ever opened — then hand the team the tools to run them. Every environment I touch leaves manual and returns cloud-managed, self-healing, and documented.

8,000+
Endpoints re-architected
2
Legacy stacks retired
9
Sites
600+
Apps packaged to standard
What I do

One common thread: fewer manual steps.

Endpoint Management

Cloud-managed device fleets

Intune, Autopilot, Entra ID, Jamf. Zero-touch enrollment, compliance policy design, and lifecycle automation for Windows and macOS at scale.

Identity & access

Conditional Access, PIM, MAM

Zero trust access built on device compliance: numbered Conditional Access baselines, just-in-time admin through PIM, app-level protection for BYOD, and passwordless sign-in.

Automation

PowerShell, Graph, runbooks

Azure Automation, Power Automate, and Microsoft Graph. Building the systems that fix things without a ticket ever being opened.

Internal tooling

SPFx, React, Power Platform

Self-service catalogs, approval flows, and internal apps that replace ticket queues with buttons employees can press themselves.

Infrastructure

Hybrid identity, Azure, Linux

On-prem Active Directory and internal PKI synchronized to Entra ID, plus Docker, DNS, Tailscale, reverse proxies, and Azure Automation. If it runs on Linux or in Azure, I've broken and rebuilt it in my own lab.

Where I've been

Every step has demanded more — and rewarded more.

2026 — Present
Senior EUC Engineer
Enterprise manufacturer · Wisconsin
Managing 3,500 endpoints across nine sites and retiring an on-prem KACE appliance for cloud-native Intune. Replaced day-long, error-prone imaging with Autopilot zero-touch (now live), and turned multi-week software requests into a self-service catalog that delivers in under an hour. Rebuilt the access layer on top of it — a sixteen-policy Conditional Access baseline, app protection for BYOD, and just-in-time admin through PIM. Plus an Azure Automation “prevention fleet” runbook that auto-remediates proactive detections. Both are written up below.
IntuneAutopilotConditional AccessPIMIntune MAMKACE decommissionSPFx / ReactAzure AutomationGraph API
2022 — 2026
EUC Engineer
Enterprise manufacturer · Wisconsin
Four years and four promotions from helpdesk to lead engineer. Built the Intune platform from zero across 4,500 devices and ran it co-managed alongside an existing SCCM estate — moving workloads over gradually until Intune could stand on its own. Packaged 600+ Win32 apps to a repeatable standard and led the EUC team across endpoints, SharePoint, and applications. The SCCM co-management story is below.
Intune from zeroSCCM co-managementAutopilotJamfADCSPowerShell
Earlier
Helpdesk
Where the fundamentals were learned
The years that made the rest possible. Tickets, imaging benches, GPO rabbit holes, and the pattern-recognition that comes from seeing a thousand endpoints break in a thousand different ways.
Selected work

Outcome first, tech underneath.

Also shipped

Personal hybrid identity lab

A full hybrid environment I own end-to-end — on-prem Active Directory with a domain controller and an internal ADCS certificate authority, synchronized to a live Microsoft 365 tenant (Entra ID P1, Intune, SharePoint, Exchange, Azure) through Entra Connect. It gives me a real hybrid identity plane to prototype and validate directory sync, certificate deployment, PowerShell automation, and Intune policy before any of it touches production. Also serves as a sandbox for peers and adjacent teams to safely build hands-on skills.

Active Directory · ADCS · Entra Connect · Intune · Azure · M365

Passwordless sign-in rollout

Windows Hello for Business, passkeys in Microsoft Authenticator, and a passphrase policy that replaced forced expiry — packaged as a SharePoint site with enrollment walkthroughs per platform, ahead of the retirement of SMS and voice as MFA methods.

Entra ID · Windows Hello · Passkeys · SharePoint

Self-service software catalog

Replaced a ticket-driven software request process with a SharePoint-native React catalog. Employees browse titles, request installs, and license groups auto-assign on approval. Tenant-agnostic and portable across sites.

SPFx · React · TypeScript · Power Automate · Graph

Proactive remediation “prevention fleet”

An Azure Automation runbook wired to a SharePoint flags list. Two-pass architecture: trigger on-demand Intune remediations at scale, then harvest results. Fleet-level self-healing without human-in-the-loop.

Azure Automation · Graph API · PowerShell · SharePoint

ITSM service catalog web part

A config-driven IT Service Catalog rendered from SharePoint lists, so non-developers edit every tier, panel, and UI string without touching code. Per-row show/hide toggles and a two-column layout, deployed as a versioned companion package.

SPFx · React · TypeScript · SharePoint lists
Certifications

Where the paper says the same thing the work does.

AZ-104In Progress
CCFECertified
CMFECertified
Network+Certified
A+Certified
CompTIA CSISCertified
CompTIA CIOSCertified
LPI Linux EssentialsCertified
Get in touch

Let's talk.

I'm open to Principal Cloud / EUC Architect conversations, and to work at organizations building things that matter — infrastructure, security, or the mission itself.