Expertise

Skills, knowledge and experience

Twenty years specialising in identity, built on a longer engineering career across infrastructure, networks, platforms and online services - a grounding that shapes how I design: for how systems actually behave in production, not how the datasheet says they should.

The depth is the Microsoft identity estate, hands-on from directory internals and PKI through to Entra ID Governance, Conditional Access and the emerging discipline of AI and agent identity. The breadth is deliberately vendor-agnostic: the architectural patterns beneath Okta, Ping, SailPoint, Saviynt and their peers transcend any single product, which is exactly what objective platform evaluation and multi-vendor identity fabric design demand.

The range runs from board-level strategy and design authority governance at global scale down to the high and low level designs engineers build from - and the thread colleagues and managers cite most consistently across two decades of references is the documentation and diagramming: designs precise enough to survive handover, audit and the passage of time.

Microsoft Identity Stack

Entra IDActive Directory (ADDS)Entra ID Connect & Cloud SyncEntra ID GovernanceConditional AccessEntra External IDIntune / Autopilot / MDM / MAMGroup Policy (ADGP / AGPM)Tiered AdministrationADFS & WAPMicrosoft Identity Manager (MIM)Access Packages & ReviewsPrivileged Identity Mgmt (PIM)Azure AD B2CEntra ID B2BEntra Agent IDCertificate Services (ADCS) / PKILAPS & PAW patternsDNSSEC & AD-DNS

Architecture practice & leadership

Identity fabric designHLD / LLD / conceptual / logical designRoadmaps & strategyBusiness cases & solution proposalsTechnical writing & diagrammingStakeholder & vendor managementTeam leadership & mentoringArchiMate & TOGAFArchitecture decision recordsTDA & EARB chairingDesign authority governanceM&A integration architectureC-suite & board engagement

Identity governance & access control

IGA architectureJoiner-mover-leaver automationRBAC / ABAC / PBACAccess reviews & certificationLeast privilege & separation of dutiesEntitlement managementServiceNow integrationWorkday integrationClearSkye IGAPrivileged access designJust-in-time / just-enough admin

Microsoft cloud & platform

Azure architectureMicrosoft 365 / Office 365Azure Application ProxyAzure Landing Zones & CAFExpressRoute & networking (NSGs)Azure IaaS / PaaSLoad Balancers & Traffic ManagerAzure DevOpsExchange OnlineSharePoint & SharePoint OnlineTeams & Skype for BusinessPower BI & reportingDynamics CRM

Protocols & standards

OAuth 2.0 / OpenID ConnectSAML 2.0Kerberos / NTLM (legacy)SCIM provisioningPDP / PEP / PIP / PAP modelsPasswordless / FIDO2NIST SP 800-207WS-FederationXACML conceptsOWASP LLM Top 10MITRE ATLAS

Infrastructure foundations

Data centre design & migrationWindows Server (all versions)VMware vSphere / SRMHyper-VCitrix XenApp / XenDesktopSAN / storage (HP 3PAR, NetApp, EMC)DFS / NLB / failover clusteringIIS & web platformsSQL Server & MySQLLinux (RHEL / CentOS / Ubuntu)MDT & OS deploymentAlways-on / active-active designHardware platforms (HP / Dell / IBM / Cisco)

Security & Zero-Trust

Zero-Trust identity frameworksAI security architectureMicrosoft DefenderIdentity Protection & risk policiesSecurity hardening & baselinesAttack path mitigationMicrosoft SentinelZscaler ZIA / ZPA / ZDXAzure Information ProtectionClearSwift Secure GatewayEndpoint protection (Symantec / Sophos)DDoS protection & WAF concepts

Networking

Firewalls & network zoningNetwork separation & segmentationDNS / DHCPMPLS / SD-WAN / WAN / LANCisco routing & switchingCisco Nexus data centre coresCisco ISE / Dot1xLoad balancing (Radware Alteon)GSLB / LSLBWireless infrastructure

Vendor landscape (design & evaluation)

MicrosoftGoogle IdentityVendor selection & RFPsOktaPing IdentitySailPointSaviyntWSO2ClearSkyeJumpCloudZscalerServiceNowWorkdayCiscoVMwareCitrixRadwareNetAppClearswiftHPE / Dell

Scripting, tooling & ways of working

PowerShellBashVBScript / batchHTML / CSSDocumentation standardsAgile & Waterfall deliveryChange & incident managementC# / .NET basicsSolarWinds & KS-HostmonitorDell OpenManage / HP InsightITIL service managementProcurement & licensing (Microsoft)
Credentials

Licences and certifications

Formal certifications alongside a continuous-learning habit - full credential details are on LinkedIn.

Certifications

  • Implementing Microsoft Azure Infrastructure Solutions (70-533)Microsoft · 2017 · Credential ID G238-6643
  • Managing Office 365 Identities and Requirements (70-346)Microsoft · 2018
  • M50412 Implementing Active Directory Federation Services 2.0Microsoft · 2015
  • Windows Server 2012 R2 Implementing a Basic PKIMicrosoft · 2014
  • Windows Server 2012 DirectAccess TrainingMicrosoft · 2014
  • Clearswift Certified EngineerClearswift · 2011

LinkedIn Learning

Focused identity and platform course series:

Windows as a Service: Planning DeploymentWindows Server 2016: Implementing Group PolicyWindows Server 2016: DNSWindows Server 2016: Active Directory Certificate ServicesOffice 365: Manage Identities using Azure AD ConnectOffice 365: Implement Identities for SSOOffice 365: Manage Cloud IdentitiesOffice 365: Provision Office 365Office 365: Implement Networking and SecurityOffice 365: Troubleshoot Availability and Usage

Have an identity challenge worth solving?

I take a small number of freelance and contract engagements each year.

Start a conversation