Building practical systems in Brazil

Infrastructure · Endpoint Management · Identity Security

I design reliable infrastructure and security automation for real environments.

I'm Diogo Wermann, an IT Infrastructure & Security Analyst focused on Windows automation, Microsoft Intune, hybrid identity, observability, and operational resilience.

CURRENT FOCUS dw://portfolio

Operational systems that remain safe under uncertainty.

Automation should be observable, reversible, and explicit about the decisions it refuses to make.

Identity AD → Entra ID Correlated
Endpoints Intune → Windows Managed
Automation PowerShell + Python Auditable
Fail closedLeast privilegeRecovery first

WHAT I WORK ON

Infrastructure work with a security engineering mindset.

I operate across the layers where identity, endpoints, automation, and business continuity meet.

01

Infrastructure Automation

Repeatable PowerShell and Python workflows for Windows, servers, inventories, reporting, and operational maintenance.

02

Endpoint Management

Microsoft Intune packaging, deployment, detection, policy validation, and reliable device-side execution.

03

Hybrid Identity

Active Directory, Microsoft Entra ID, synchronization, device identity correlation, and access-aware operations.

04

Resilience & Observability

Backups, logs, dashboards, service health, recovery procedures, and evidence for operational decisions.

SELECTED PROJECTS

Public tools built from production problems.

Each project starts with an operational constraint and is designed around safety, maintainability, and clear documentation.

View all projects
Flagship Active

DeviceLifecycle

A safety-first lifecycle engine for inactive hybrid Windows devices across Active Directory, Entra ID, and Intune.

PowerShellMicrosoft GraphActive Directory
View project
Open source Active

DeviceLifecycle-API

A read-only FastAPI extension that exposes lifecycle reports and logs without extending the privileged control plane.

PythonFastAPIAPI Security
View project
Open source Active

WallpaperAgent

A Windows agent for validated, versioned wallpaper delivery with privilege separation and safe content promotion.

PowerShellIntuneSHA-256
View project
Open source Active

RustDeskIntuneDeployment

A complete Win32 deployment package for installing, configuring, detecting, and removing RustDesk through Intune.

PowerShellIntuneEndpoint Management
View project

FEATURED CASE STUDY

An enterprise operations portal built around real internal workflows.

A private, modular platform for support, assets, operational dashboards, scheduling, access control, and service integrations. The source remains private; the architecture and engineering decisions can still be documented responsibly.

Multiple operational modules in one controlled interface
Role-aware access and network-aware exposure
Database migrations, integrations, logs, and reporting

Private system · Sanitized engineering case study

Multi-module
operational platform
Private
source and business data
Public
engineering lessons
Read the case study → Architecture, decisions, and outcomes

TECHNICAL WRITING

Detailed implementation notes, not generic tutorials.

Long-form articles explain the constraints, architecture, safeguards, and tradeoffs behind the systems I build.

Browse all writing

ABOUT

Hands-on infrastructure experience, documented with engineering discipline.

I work across infrastructure, user support, automation, endpoint management, backups, monitoring, and security. My focus is turning operational knowledge into systems that are easier to understand, audit, and maintain.

Production-minded automation
Microsoft hybrid environments
Clear technical documentation
More about my work

CONTACT

Let's discuss infrastructure, automation, or security engineering.

For professional conversations, technical collaboration, or questions about my public projects, use the channels below.