01
Azure Landing Zones
ALZ-Bicep foundations, hub-and-spoke topologies, Azure Firewall Premium, Azure Policy, AMBA-aligned monitoring and management group governance.
AZURE · M365 · IDENTITY & ENDPOINT
I design and deliver Azure landing zones, identity and endpoint security, and Microsoft 365 migrations for organisations operating across multiple sites and thousands of devices.
CAPABILITIES
01
ALZ-Bicep foundations, hub-and-spoke topologies, Azure Firewall Premium, Azure Policy, AMBA-aligned monitoring and management group governance.
02
Entra ID, Conditional Access policy-as-code, break-glass and CA-exclusion patterns, Intune device baselines, Defender for Endpoint, zero-trust controls.
03
Multi-site Azure IaaS migrations, SD-WAN integration, Google Workspace to Microsoft 365 transitions, tenant-to-tenant consolidation, AVD and remote access.
04
SCCM and Intune co-management, in-place OS upgrade campaigns at thousands-of-devices scale, distributed collection design, Autopilot and modern provisioning.
05
PowerShell tooling, Azure Automation runbooks, Azure Monitor and Log Analytics, KQL analytics and Workbook dashboards, AI-assisted operations tooling.
06
Architecture review aligned to the Well-Architected Framework, M365 licensing strategy (E3/E5, Purview), CSP commercial structures, technical pre-sales.
SELECTED ENGAGEMENTS
Enterprise-grade security baseline for Contoso Ltd across six phases: identity & access control (PIM, Conditional Access), email protection (Defender for Office 365), endpoint security & EDR (Defender for Endpoint, Intune), data governance (DLP, sensitivity labels), and compliance audit. Aligned to Zero Trust principles using M365 E3 + Security P2 licensing.
Migrated the full IT estate of an elder-care provider into Azure. Deployed an ALZ-Bicep foundation, integrated all 16 sites via SD-WAN to a central Azure hub, centralised DHCP, wireless controllers and domain services, and rolled out Azure Virtual Desktop using the AVD Accelerator.
Led an in-place Windows 10 1607 to 22H2 upgrade for a global testing and assessment provider with 10,500+ devices across roughly 650 test centres and four regional subdomains. Delivered in under six months against prior vendor estimates of over a year.
Tenant-wide migration from Google Workspace to Microsoft 365 for 3,000+ user accounts using BitTitan. Scope covered mail, Drive to OneDrive migration, and the design and provisioning of more than 300 SharePoint sites.
Designed and delivered a Conditional Access policy baseline (11 policies including break-glass and CA-exclusion patterns) and an Intune security group structure used as the repeatable starting point for subsequent tenant deployments.
PROOFS OF CONCEPT
Modular Azure Landing Zone implementation using Bicep with hub-and-spoke topology, Azure Firewall Premium, and centralized logging.
Policy-as-code framework for deploying and testing Conditional Access policies at scale with built-in validation and compliance checks.
Repeatable Intune configuration baseline covering compliance policies, device configuration profiles, and app protection policies.
KQL-based analytics dashboards for Azure security posture, Defender for Endpoint threat intelligence, and operational metrics.
Automated tenant provisioning and configuration orchestration across multiple M365 environments with tenant-switching utilities.
Enterprise-grade security baseline with 6 phases: Identity & Access (PIM, Conditional Access), Email Protection (Defender for Office 365), Endpoint Security (Intune + EDR), Data Governance (DLP, sensitivity labels), and Compliance Audit. Full Zero Trust implementation with policy-as-code.
AI-ASSISTED DELIVERY
I use modern AI tooling, including Claude, to accelerate secure engineering workflows, generate higher-quality automation faster, and improve consistency across large Microsoft estates. The outcome is practical: faster delivery, stronger validation, and cleaner reporting at scale.
01
AI-enhanced workflows for Conditional Access, Intune, and M365 baseline deployments: policy drafting, script scaffolding, validation checks, and implementation runbooks aligned to Zero Trust controls.
02
Automated collection pipelines across 4,000+ EPA devices to capture endpoint performance signals, normalize telemetry, and generate structured health and trend reports for decision-making.
03
Repeatable reporting flows that turn raw platform data into executive-ready summaries: compliance posture, endpoint health, policy drift, and delivery progress without manual spreadsheet cycles.
04
Reusable automation for tenant onboarding, baseline enforcement, and environment checks across multiple clients, reducing deployment variance and improving governance consistency.
LEAD ARCHITECT
Azure Solutions Architect · Cloud Engineer · Costa Rica
Microsoft Certified: Azure Solutions Architect Expert. CSP audit expertise in Azure infrastructure and data migration. Microsoft alumnus — former Customer Success Architect across LATAM and North America (contracted via Persistent Systems), promoted to managing the regional CSA team of 9–12 architects.
Currently delivering Azure and M365 engagements for North American MSP and CSP partners, with hands-on migration work using Bicep, the Well-Architected Framework, and the Cloud Adoption Framework.
DOCUMENTATION & RESOURCES
Complete deployment guide for enterprise-grade Microsoft 365 security across 6 phases: Identity & Access, Email Protection, Endpoint Security, Data Governance, and Compliance. Includes phase details, prerequisites, admin workstation setup, and timeline.
NEXT STEPS
A 30-minute alignment call to walk through your environment, discuss fit, and identify a starting point — whether that's a project, staff augmentation, or a managed service.
Based in La Guรกcima, Alajuela, Costa Rica · +506 8851 7574