Automation & Applied AI
Repeatable workflows and AI integrations for operations, documentation, and knowledge management, with permissions, validation, and human review.
Infrastructure · Security · Automation · Applied AI
I'm Diogo Wermann, an IT Infrastructure & Security Analyst focused on Windows automation, Microsoft Intune, hybrid identity, and the safe integration of AI into operations, documentation, and internal systems.
Automation and agents should be observable, reversible, and explicit about the decisions they refuse to make.
WHAT I WORK ON
I operate across the layers where identity, endpoints, automation, knowledge, and business continuity meet.
Repeatable workflows and AI integrations for operations, documentation, and knowledge management, with permissions, validation, and human review.
Microsoft Intune packaging, deployment, detection, policy validation, and reliable device-side execution.
Active Directory, Microsoft Entra ID, synchronization, device identity correlation, and access-aware operations.
Backups, logs, dashboards, service health, recovery procedures, and evidence for operational decisions.
SELECTED PROJECTS
Each project starts with an operational constraint and is designed around safety, maintainability, and clear documentation.
A safety-first lifecycle engine for inactive hybrid Windows devices across Active Directory, Entra ID, and Intune.
A read-only FastAPI extension that exposes lifecycle reports and logs without extending the privileged control plane.
A Windows agent for validated, versioned wallpaper delivery with privilege separation and safe content promotion.
A complete Win32 deployment package for installing, configuring, detecting, and removing RustDesk through Intune.
A security-conscious PowerShell pipeline for deployment-specific Windows answer files, delegated domain join, Hybrid Microsoft Entra join, cleanup, state, and validation.
FEATURED CASE STUDY
A private modular platform for support, assets, dashboards, scheduling, integrations, and an AI-ready knowledge base. The source remains private; its architecture and decisions can still be documented responsibly.
Private system · Sanitized engineering case study
TECHNICAL WRITING
Long-form articles explain the constraints, architecture, safeguards, and tradeoffs behind the systems I build.
How a PowerShell agent uses Intune, privilege separation, SHA-256 validation, atomic promotion, and per-user application to manage Windows wallpapers safely.
An engineering case study on converting a working Windows unattended installation into a reusable PowerShell provisioning pipeline without publishing operational secrets.
How a RustDesk MSI became a configured and verifiable Microsoft Intune Win32 application with multi-context configuration, logs, service checks, and custom detection.
ABOUT
I work across infrastructure, support, automation, endpoints, observability, security, and applied AI. I turn operational knowledge into systems that are easier to understand, audit, and maintain.
CONTACT
For professional conversations, technical collaboration, or questions about my public projects, use the channels below.