Modernizing a Legacy Knowledge Base with Markdown, Mermaid, and AI
A sanitized case study on incrementally evolving the knowledge base of a HESK-based portal with legacy HTML compatibility, Markdown authoring, Mermaid diagrams, secure rendering, and an explicit contract for AI-agent collaboration.
- Existing HTML articles remained available without a mandatory migration
- New articles gained Markdown as their editable canonical source
- Preview and published reading began sharing the same visual pipeline
Designing a Failure-Safe Device & Asset Integration Control Plane
Sanitized case study of a production integration that reconciles device identity, Microsoft Intune, Microsoft Entra ID, Snipe-IT, and an internal portal through explicit authority boundaries, human-reviewed operations, idempotency, and fail-closed safety gates.
- Logical device identity, physical assets, and possession were separated into explicit sources of authority instead of being synchronized bidirectionally.
- Mutating workflows gained preview, live preflight, human confirmation, idempotency, persisted write intent, verification, and kill-switch controls.
- Intune Primary User became a projection of confirmed possession rather than an independent patrimonial source of truth.
Enterprise Operations Portal
A sanitized case study of a private modular platform that consolidates support, assets, service workflows, scheduling, dashboards, and internal integrations without forcing every domain into one monolithic application.
- Multiple operational workflows consolidated behind one controlled entry point
- Independent modules retained explicit permissions and persistence boundaries
- Versioned deployment and database-change procedures replaced manual server edits
From On-Premises Active Directory to Microsoft 365: Identity, Email, and Endpoints in Four Months
Sanitized case study of a four-month modernization: Active Directory cleanup, identity consolidation, Exchange Online migration, and the transition to modern endpoint management with Intune and Defender.
- In four months, the environment moved from primarily on-premises identity and email to an architecture integrated with Microsoft 365.
- Active Directory was cleaned up and reorganized under a predictable corporate hierarchy before broad cloud consolidation.
- Mail flow was migrated to Exchange Online with minimal operational disruption for end users.
Android Enterprise with Intune in Practice: Fully Managed, Defender, and the Limits of Automation
Sanitized case study of corporate Android management with Android Enterprise, Microsoft Intune, and Defender, covering Fully Managed enrollment, application delivery, compliance, and real-world vendor and application limitations.
- The Corporate-owned, fully managed model was validated for individually assigned corporate devices.
- Applications, restrictions, and user experience could be delivered centrally through Intune.
- Microsoft Defender was integrated into the mobile security flow, with signals intended for compliance and Outlook access decisions.