Infrastructure Automation
Repeatable PowerShell and Python workflows for Windows, servers, inventories, reporting, and operational maintenance.
Infrastructure · Endpoint Management · Identity Security
I'm Diogo Wermann, an IT Infrastructure & Security Analyst focused on Windows automation, Microsoft Intune, hybrid identity, observability, and operational resilience.
Automation should be observable, reversible, and explicit about the decisions it refuses to make.
WHAT I WORK ON
I operate across the layers where identity, endpoints, automation, and business continuity meet.
Repeatable PowerShell and Python workflows for Windows, servers, inventories, reporting, and operational maintenance.
Microsoft Intune packaging, deployment, detection, policy validation, and reliable device-side execution.
Active Directory, Microsoft Entra ID, synchronization, device identity correlation, and access-aware operations.
Backups, logs, dashboards, service health, recovery procedures, and evidence for operational decisions.
SELECTED PROJECTS
Each project starts with an operational constraint and is designed around safety, maintainability, and clear documentation.
A safety-first lifecycle engine for inactive hybrid Windows devices across Active Directory, Entra ID, and Intune.
A read-only FastAPI extension that exposes lifecycle reports and logs without extending the privileged control plane.
A Windows agent for validated, versioned wallpaper delivery with privilege separation and safe content promotion.
A complete Win32 deployment package for installing, configuring, detecting, and removing RustDesk through Intune.
FEATURED CASE STUDY
A private, modular platform for support, assets, operational dashboards, scheduling, access control, and service integrations. The source remains private; the architecture and engineering decisions can still be documented responsibly.
Private system · Sanitized engineering case study
TECHNICAL WRITING
Long-form articles explain the constraints, architecture, safeguards, and tradeoffs behind the systems I build.
How a RustDesk MSI became a configured and verifiable Microsoft Intune Win32 application with multi-context configuration, logs, service checks, and custom detection.
A technical case study on fail-closed lifecycle automation for hybrid Windows devices, including identity correlation, staged enforcement, recovery, and a read-only API.
How a layered recovery design combines user-data protection, shared-folder backups, PostgreSQL-aware recovery, Proxmox backups, secondary storage, and an offsite copy.
ABOUT
I work across infrastructure, user support, automation, endpoint management, backups, monitoring, and security. My focus is turning operational knowledge into systems that are easier to understand, audit, and maintain.
CONTACT
For professional conversations, technical collaboration, or questions about my public projects, use the channels below.