Identity & Access Management Engineer specializing in Microsoft Entra ID, enterprise directory services, and privileged access governance. Below is my capstone implementation of a complete zero-trust identity architecture for a simulated enterprise (Nexus Cloud Solutions).
A production-grade 5-phase deployment bridging on-premises Active Directory with Microsoft Entra ID, covering lifecycle automation, zero-trust perimeter defense, SaaS federation, and privileged governance.
Windows Server 2022 • PowerShell • Entra Connect
Manual account creation across departments causes significant onboarding latency, inconsistent group assignments, and critical orphan-account risks during offboarding.
Authored a modular PowerShell automation script ingesting raw HR CSV data, dynamically routing users to distinct OUs, and establishing delta synchronization to Entra ID via Entra Connect.
Cut identity provisioning time to seconds, enforced uniform directory structures, and verified real-time cloud object sync.
Microsoft Entra ID • Conditional Access Policies
Basic authentication protocols (IMAP/POP3) cannot respond to MFA challenges, serving as a primary target for password spray attacks.
Configured tenant-wide Conditional Access Policies explicitly terminating legacy protocol authentication while scoping emergency break-glass exemptions and modern MFA controls.
Eliminated legacy auth vectors; verified access denial and audit telemetry using the Entra ID 'What If' simulation engine.
Identity Governance • Access Reviews • Dynamic Groups
External contractor and vendor identities regularly persist indefinitely post-contract, generating unmonitored vendor sprawl and audit failures.
Created dynamic B2B guest assignment groups coupled to recurring monthly Access Reviews requiring mandatory user self-attestation.
Automated account revocation for unresponsive contractors after 14 days, maintaining strict compliance with least-privilege principles.
SAML 2.0 • SCIM • Enterprise Applications
Fragmented credentials across third-party SaaS services increase credential theft exposure and result in manual offboarding backlogs.
Configured SAML 2.0 federation between Entra ID and SaaS apps; enabled SCIM endpoints with attribute mappings for automated provisioning and suspension.
Centralized authentication logs into Entra ID, enabled one-click credential revocation, and inspected SAML assertion tokens via browser tracer tools.
Privileged Identity Management (PIM) • Just-In-Time Access
Permanent Global Administrator assignments expose cloud environments to total takeover in the event of workstation compromise or credential theft.
Stripped permanent admin rights via Entra ID PIM, structuring high-privilege roles as Eligible with MFA enforcement, ticket justification, and 2-hour limits.
Zero standing admin privileges across the tenant, complete JIT elevation audit logs, and strict adherence to zero-trust standards.
Actively seeking IAM Analyst and Identity Engineering roles. Ready to discuss how identity architecture, automation, and zero-trust controls secure enterprise boundaries.