System Administrator
Cloud infrastructure and security engineer with hands-on experience designing and administering Azure, Microsoft Entra ID and Microsoft 365 end to end: hybrid-to-cloud identity migrations, Conditional Access and MFA rollouts, automated user lifecycle management, and multi-region enterprise storage architecture, grounded in ISMS (ISO 27001) and ITIL-aligned operations.
What I actually enjoy is the moment a messy environment starts making sense: a fleet of devices still tangled in on-prem AD dependency, a file share that's fast in one region and painful in another, an onboarding process held together by tickets and memory. Untangling that, deciding what the identity model should be rather than just patching around it, and watching the fix hold up months later. That's the part of this job I'd do for free.
Outside of work hours, I'm usually solving a different kind of problem in a very different kind of environment. Rock climbing has the same appeal as a good architecture decision: read the terrain, commit to a line, adjust when it's wrong. Bushcraft scratches a similar itch: no dashboard, no rollback, just first principles and whatever's actually in front of you. I write when I need to think something through properly, and lately I've been deep in vibe coding, building things fast and scrappily with an AI pair, which honestly isn't that different from architecting cloud infrastructure: you're still the one who has to know why it works.
Migrated the managed device fleet from Hybrid Azure AD Join to Entra ID Join, removing on-premises Active Directory dependency for authentication on migrated machines while preserving user state during transition.
Legacy hybrid-join / on-prem AD dependency vs. implemented Entra ID-only, cloud-only auth.
Designed a distributed storage architecture giving both AU and US-based engineering staff local-speed file access against a single centralised SolidWorks data source, spanning two genuinely different identity/authentication models depending on the underlying storage service.
Two identity models under one storage project, evaluated per workload.
Regional cache VMs, Azure File Sync, and logon-time latency-based auto-routing.
Client-side local caching via a sequential Intune Win32 dependency chain.
Built an end-to-end onboarding and offboarding pipeline driven entirely by a single HR CSV source of truth, removing manual ticket-driven account provisioning.
HR CSV source of truth, boolean-driven branching, dual delta-sync propagation.
Replaced a flat, blanket-policy deployment model with department-scoped application and profile delivery, so devices only carry the software relevant to their team.
Entra ID group segmentation through to department-scoped application delivery.
Designed and rolled out Conditional Access policies enforcing MFA based on user risk, location and device compliance signals, alongside Self-Service Password Reset with password writeback to on-premises Active Directory, implemented to Microsoft security best practices and contributing to a measurable improvement in the organisation's Microsoft Secure Score.
Registered and configured Enterprise Applications in Azure for Single Sign-On, published through MyApps, so users authenticate once with their Entra ID credentials instead of managing separate application logins, improving both user experience and credential security.
IT System and Cloud Administrator
IT System Administrator
IT Support
Open to conversations about cloud infrastructure, identity architecture, and security engineering roles, and I'm happy to walk through any of the projects above in more depth.