AZURE · M365 · IDENTITY & ENDPOINT

Azure platforms and Microsoft 365 estates, delivered at scale.

I design and deliver Azure landing zones, identity and endpoint security, and Microsoft 365 migrations for organisations operating across multiple sites and thousands of devices.

  • 10K+Devices managed at enterprise scale
  • 8K+Users supported across enterprise
  • 16Sites onboarded in a single Azure migration

CAPABILITIES

Full-stack Microsoft delivery, end to end.

01

Azure Landing Zones

ALZ-Bicep foundations, hub-and-spoke topologies, Azure Firewall Premium, Azure Policy, AMBA-aligned monitoring and management group governance.

02

Identity & Endpoint Security

Entra ID, Conditional Access policy-as-code, break-glass and CA-exclusion patterns, Intune device baselines, Defender for Endpoint, zero-trust controls.

03

Migrations at Scale

Multi-site Azure IaaS migrations, SD-WAN integration, Google Workspace to Microsoft 365 transitions, tenant-to-tenant consolidation, AVD and remote access.

04

Endpoint Management

SCCM and Intune co-management, in-place OS upgrade campaigns at thousands-of-devices scale, distributed collection design, Autopilot and modern provisioning.

05

Automation & Observability

PowerShell tooling, Azure Automation runbooks, Azure Monitor and Log Analytics, KQL analytics and Workbook dashboards, AI-assisted operations tooling.

06

Advisory & Customer Success

Architecture review aligned to the Well-Architected Framework, M365 licensing strategy (E3/E5, Purview), CSP commercial structures, technical pre-sales.

SELECTED ENGAGEMENTS

Recent delivery, anonymised.

PROOFS OF CONCEPT

Technical experiments & rapid prototyping.

๐Ÿ—๏ธ

ALZ-Bicep Hub & Spoke

Modular Azure Landing Zone implementation using Bicep with hub-and-spoke topology, Azure Firewall Premium, and centralized logging.

Bicep Infrastructure Azure
๐Ÿ”

Conditional Access Policy Engine

Policy-as-code framework for deploying and testing Conditional Access policies at scale with built-in validation and compliance checks.

PowerShell Microsoft Graph Identity
๐Ÿ’พ

Intune Baseline Deployment

Repeatable Intune configuration baseline covering compliance policies, device configuration profiles, and app protection policies.

PowerShell Intune Endpoint
๐Ÿ“Š

Azure Monitor Analytics Workbooks

KQL-based analytics dashboards for Azure security posture, Defender for Endpoint threat intelligence, and operational metrics.

KQL Azure Monitor Analytics
๐Ÿ”„

Multi-Tenant M365 Provisioning

Automated tenant provisioning and configuration orchestration across multiple M365 environments with tenant-switching utilities.

PowerShell M365 Automation
๐Ÿ›ก๏ธ

M365 Baseline Security

Enterprise-grade security baseline with 6 phases: Identity & Access (PIM, Conditional Access), Email Protection (Defender for Office 365), Endpoint Security (Intune + EDR), Data Governance (DLP, sensitivity labels), and Compliance Audit. Full Zero Trust implementation with policy-as-code.

PowerShell M365 Security

AI-ASSISTED DELIVERY

Operational AI and automation built for real enterprise environments.

I use modern AI tooling, including Claude, to accelerate secure engineering workflows, generate higher-quality automation faster, and improve consistency across large Microsoft estates. The outcome is practical: faster delivery, stronger validation, and cleaner reporting at scale.

01

AI-Assisted Security Engineering

AI-enhanced workflows for Conditional Access, Intune, and M365 baseline deployments: policy drafting, script scaffolding, validation checks, and implementation runbooks aligned to Zero Trust controls.

Claude Policy-as-Code Security Baselines

02

4,000+ Endpoint Performance Automation

Automated collection pipelines across 4,000+ EPA devices to capture endpoint performance signals, normalize telemetry, and generate structured health and trend reports for decision-making.

4,000+ Devices Telemetry Performance Analytics

03

Automated Reporting Pipelines

Repeatable reporting flows that turn raw platform data into executive-ready summaries: compliance posture, endpoint health, policy drift, and delivery progress without manual spreadsheet cycles.

PowerShell KQL Executive Reporting

04

Cross-Tenant Operations Automation

Reusable automation for tenant onboarding, baseline enforcement, and environment checks across multiple clients, reducing deployment variance and improving governance consistency.

M365 Azure Multi-Tenant
  • 4,000+EPA devices monitored through automated performance pipelines
  • Faster Delivery cycles through AI-assisted scripting and validation
  • Repeatable Automation patterns across identity, endpoint, and reporting workloads

LEAD ARCHITECT

Manuel Arce

Azure Solutions Architect · Cloud Engineer · Costa Rica

Microsoft Certified: Azure Solutions Architect Expert. CSP audit expertise in Azure infrastructure and data migration. Microsoft alumnus — former Customer Success Architect across LATAM and North America (contracted via Persistent Systems), promoted to managing the regional CSA team of 9–12 architects.

Currently delivering Azure and M365 engagements for North American MSP and CSP partners, with hands-on migration work using Bicep, the Well-Architected Framework, and the Cloud Adoption Framework.

DOCUMENTATION & RESOURCES

Explore project details and deployment guides.

NEXT STEPS

Let's scope your engagement.

A 30-minute alignment call to walk through your environment, discuss fit, and identify a starting point — whether that's a project, staff augmentation, or a managed service.

Based in La Guรกcima, Alajuela, Costa Rica · +506 8851 7574