The best way to contact me is via LinkedIn. For technical inquiries regarding my labs, feel free to open an issue.
This repository contains a comprehensive, three-part technical lab series simulating a real-world enterprise IT environment. The project moves from raw infrastructure deployment to advanced Identity and Access Management (IAM), concluding with a hands-on Help Desk ticketing simulation.
The Goal: To build, secure, and manage a corporate network from the ground up, demonstrating proficiency in systems administration, network security, and technical support workflows.
- Operating Systems: Windows Server 2025 (Datacenter), Windows 11 Enterprise
- Directory Services: Active Directory Domain Services (AD DS)
- Networking: DNS, DHCP, Static IPv4 Addressing, NAT Networking
- Security & Policy: Group Policy Objects (GPO), RBAC (Role-Based Access Control), Least Privilege, Account Lockout Policies
- Virtualization: Oracle VirtualBox (Type-2 Hypervisor)
- IT Operations: Disaster Recovery (Snapshots), Documentation, Troubleshooting
- Scripting: PowerShell
Focus: The Foundation.
- Architected an isolated virtual network environment.
- Deployed Windows Server 2025 as a Primary Domain Controller.
- Provisioned a Windows 11 managed endpoint.
- Key Outcome: A fully functional, stable environment with verified internal/external connectivity and disaster recovery fail-safes.
Focus: Security & Governance.
- Designed a scalable Organizational Unit (OU) hierarchy.
- Implemented Role-Based Access Control (RBAC) for HR, Finance, and IT departments.
- Deployed Group Policy Objects (GPOs) to harden endpoints (restricting CMD/Control Panel) and enforce corporate compliance.
- Automated User Provisioning at Scale: Built a PowerShell-driven onboarding process to create and assign 100 user accounts from a CSV file.
- Validated Security & System Integrity: Conducted end-to-end testing (permissions, GPOs, resource limits), ensuring policies work as intended.
- Key Outcome: A fully automated and policy-driven domain where user access, security controls, and resource provisioning are consistently enforced, reducing manual IT workload and significantly reducing the attack surface, and ensuring every employee is set up correctly from day one.
Focus: Cloud Identity & Mobility.
- Established a Hybrid Identity infrastructure by deploying Microsoft Entra Connect Sync, bridging the on-premises Active Directory to a Microsoft 365 Enterprise environment.
- Engineered Single Sign-On (SSO) capabilities by resolving non-routable
.localdomain constraints and implementing alternative UPN suffixes for over 100 users. - Configured Hybrid Microsoft Entra Join via GPO and enrolled client endpoints into Microsoft Intune for over-the-air Mobile Device Management (MDM).
- Modernized policy enforcement by translating local Group Policies into Intune Configuration Profiles, pushing customized browser settings and security policies via the cloud.
- Conducted advanced troubleshooting and root cause analysis, resolving critical host-machine storage failures (
VERR_DISK_FULL), licensing attribute errors, and GPO conflicts during MDM enrollment. - Key Outcome: A fully synchronized, cloud-integrated environment that extends local infrastructure to the web. Users benefit from seamless SSO, while IT can securely provision licenses, enforce compliance, and push software to remote devices over the internet, enabling a secure "work-from-anywhere" infrastructure.
Part 4: Help Desk Operations & Ticketing (In Progress)
Focus: The User Experience.
- Simulating real-world L1/L2 support scenarios.
- Resolving common issues: Password resets, software deployment, and policy troubleshooting.
- Utilizing ticketing workflows to document and track "Break/Fix" incidents.
- Key Outcome: Demonstrating the ability to translate technical knowledge into professional end-user support.
- Hybrid Directory Synchronization: Deployed Microsoft Entra Connect Sync to bridge the on-premises Windows Server 2025 environment with Microsoft 365, successfully synchronizing 100+ Active Directory users and security groups to the cloud.
- Seamless Single Sign-On (SSO): Resolved non-routable domain (
lab.local) limitations by configuring alternative UPN suffixes (@pbitsupport.onmicrosoft.com) across all local accounts, establishing a unified login for local file shares, Entra ID, and M365 email.
- Intune Device Enrollment: Configured Hybrid Microsoft Entra Join via Group Policy and Entra Connect, successfully enrolling Windows 11 client devices into Microsoft Intune for cloud-based Mobile Device Management.
- Cloud Policy Deployment: Transitioned local GPOs to Intune Configuration Profiles (Settings Catalog), deploying targeted web browser configurations based on synced Entra ID security groups (Finance vs. HR).
- Enterprise License Management: Managed M365 E5 Developer licenses within the Microsoft 365 Admin Center, strategically provisioning access and managing "Usage Location" attributes to maintain regional compliance.
- Bulk User Provisioning: Automated the creation and security group assignment of 100+ user accounts using a custom PowerShell script, reducing a multi-hour onboarding task to just minutes and eliminating manual errors.
- Access Control: Deployed automated security policies to enforce Principle of Least Privilege (PoLP), ensuring that standard users cannot access system-level tools, while "IT Support" users maintain the access needed to perform their duties.
- Zero-Touch Setup: Deployed Group Policies to automatically map departmental network drives (S:) and deploy shared printers, providing employees with instant access to essential tools upon login.
- Data Governance: Implemented FSRM to enforce storage quotas and block unauthorized file types (e.g., audio/video), preventing waste and ensuring critical disk space remains available for business operations.
Throughout this lab series, I resolved critical conflicts, including:
- Proactive Vulnerability Management: Researched Server 2025 DirSync known issues prior to cloud migration, confirming KB5068861 was installed to prevent directory synchronization failures.
- Identity & Routing Resolution: Solved Entra Sync errors caused by a private local domain by bulk-mapping accounts to a public UPN suffix, ensuring cloud-authentication functionality.
- Licensing & Compliance Errors: Rectified an "Invalid Usage Location" error during M365 license assignment by updating regional compliance data for synced cloud profiles.
- Policy Conflict Resolution: Bypassed a local "Disable Settings" GPO that blocked MDM enrollment by utilizing an IT Support admin account, proving the effectiveness of previously established Least Privilege architectures.
- Hypervisor Optimization: Solved "Black Screen" boot errors by managing Hyper-V/Core Isolation conflicts, and resolved a critical VirtualBox
VERR_DISK_FULLcrash during a cumulative OS update by performing host-level storage remediation. - Permission Misconfiguration: Identified and corrected inherited NTFS/share permission conflicts that unintentionally granted Finance access to all departments.
- GPO & Print Deployment Failure: Troubleshot a failed network printer deployment caused by incorrect GPO pathing and client security restrictions; rebuilt the printer using a compatible driver and corrected the FQDN to restore functionality.
- Network Logic: Rectified authentication errors caused by VM mismatches, proving a methodical approach to the OSI model.
Each phase of this project includes a detailed Implementation Log. I treat these logs as professional internal documentation, ensuring that every configuration change is auditable and repeatable, a vital skill in any enterprise IT team.
While 100% of the technical implementation and verification within this environment was conducted by the author, Generative AI was employed to assist in structuring the final report and ensuring professional terminology standards were met throughout the documentation.







