I take multi-thousand-endpoint environments off on-prem SCCM and KACE and rebuild them as cloud-native, self-healing platforms — Autopilot provisioning, Conditional Access across Windows and macOS, and remediation that closes tickets before they open.
Five years turning helpdesk chaos into automated platforms.
I build the systems that fix things before a ticket is ever opened — then hand the team the tools to run them. Every environment I touch leaves manual and returns cloud-managed, self-healing, and documented.
Intune, Autopilot, Entra ID, Jamf. Zero-touch enrollment, compliance policy design, and lifecycle automation for Windows and macOS at scale.
Zero trust access built on device compliance: numbered Conditional Access baselines, just-in-time admin through PIM, app-level protection for BYOD, and passwordless sign-in.
Azure Automation, Power Automate, and Microsoft Graph. Building the systems that fix things without a ticket ever being opened.
Self-service catalogs, approval flows, and internal apps that replace ticket queues with buttons employees can press themselves.
On-prem Active Directory and internal PKI synchronized to Entra ID, plus Docker, DNS, Tailscale, reverse proxies, and Azure Automation. If it runs on Linux or in Azure, I've broken and rebuilt it in my own lab.
The same destination twice — SCCM at one employer, KACE at another — with a migration strategy chosen for each estate: gradual co-management in one, clean replacement in the other.
Automated Device Enrollment from Apple Business Manager to a compliant, self-service Mac — and folded macOS into the same Conditional Access posture as Windows.
A sixteen-policy Conditional Access baseline gated on device compliance, app-level protection for personal phones, and admin rights that expire on their own.
A full hybrid environment I own end-to-end — on-prem Active Directory with a domain controller and an internal ADCS certificate authority, synchronized to a live Microsoft 365 tenant (Entra ID P1, Intune, SharePoint, Exchange, Azure) through Entra Connect. It gives me a real hybrid identity plane to prototype and validate directory sync, certificate deployment, PowerShell automation, and Intune policy before any of it touches production. Also serves as a sandbox for peers and adjacent teams to safely build hands-on skills.
Windows Hello for Business, passkeys in Microsoft Authenticator, and a passphrase policy that replaced forced expiry — packaged as a SharePoint site with enrollment walkthroughs per platform, ahead of the retirement of SMS and voice as MFA methods.
Replaced a ticket-driven software request process with a SharePoint-native React catalog. Employees browse titles, request installs, and license groups auto-assign on approval. Tenant-agnostic and portable across sites.
An Azure Automation runbook wired to a SharePoint flags list. Two-pass architecture: trigger on-demand Intune remediations at scale, then harvest results. Fleet-level self-healing without human-in-the-loop.
A config-driven IT Service Catalog rendered from SharePoint lists, so non-developers edit every tier, panel, and UI string without touching code. Per-row show/hide toggles and a two-column layout, deployed as a versioned companion package.
I'm open to Principal Cloud / EUC Architect conversations, and to work at organizations building things that matter — infrastructure, security, or the mission itself.