Eight technical areas, one consultant, and the solution design and scoping that turn them into one plan. Most problems touch more than one of them, which is exactly the point. Where a job needs a deeper specialist than me, I say so and help you bring the right one in.
svc_01
Identity and Zero Trust
Entra ID, hybrid AD, and Conditional Access designed so the right people get in and everyone else does not. Phishing-resistant MFA, just-in-time admin, and a Zero Trust model built pillar by pillar.
Tenants that are secure by default, governed, and sized for what you actually use. Reviews, baselines, landing zones, and cleanup of what grew on its own.
On-prem and cloud working as one platform. Servers, sites, and services connected cleanly, Azure Local (formerly Azure Stack HCI) clusters managed from Azure through Arc, and a clear map of what talks to what.
A network is more than routing. Segmentation, network access control, and firewalls that are understood, documented, and hardened, with ZTNA where classic VPN no longer fits.
VMware, Proxmox, and Hyper-V platforms planned for performance and failure. Hyper-V failover clusters and Storage Spaces Direct (S2D) hyperconverged clusters, from design and build to day-2 operations. Storage that is fast, sized right, and ready to grow.
Practical AI for operations and the business: agents and automation, MCP integrations into your own systems, private models on your own hardware, and Microsoft 365 Copilot made ready, with clear rules for what data goes where.
Scope documents, statements of work, IT proposals, and solution designs for enterprise setups. Clear about what is delivered, what is not, and who owns what, with estimates that hold when the work starts.
Zero Trust is a design model, not a product. Identity comes first, every request is verified, access is the least that works, and the design assumes someone is already inside.
Identity first
Verify every request
Least privilege
Assume breach
P1Identity
Phishing-resistant sign-in and access that adapts to risk.
Conditional Access / Passkeys / FIDO2 / PIM
P2Devices
Only known, healthy devices get in.
Intune compliance / Defender for Endpoint / ISE posture
P3Networks
Segmented, so one breach cannot reach everything.
Cisco ISE / 802.1X / Segmentation / ZTNA
P4Applications
Published one app at a time, behind identity.
Entra Private Access / Cloudflare Access / SSO
P5Data
Know where it lives, and make sure you can get it back.
Classification / Encryption / Immutable backup
> how I start: assess the five pillars > identity first > devices and apps > segment the network > measure and review
ZTNA is one option among many. The order is set by your biggest risk, not by a product roadmap.
01 // AI
Practical AI, without the hype
AI is a tool, not a strategy. I use it every day in my own engineering, and I help teams put it to work where it pays off, with the data rules decided first.
ai.agents
Agents and automation
AI agents and workflows built on n8n, APIs, and PowerShell, with a human approving anything that changes production.
ai.mcp
MCP servers and integrations
Model Context Protocol (MCP) endpoints that give AI agents controlled access to your APIs, databases, and documents. Scoped, logged, and brokered, so agents never hold the keys.
ai.local
Local and private models
Open models running on your own hardware, for data that must not leave the network.
ai.copilot
Copilot readiness
Before Microsoft 365 Copilot goes live: permissions, sensitivity labels, and oversharing cleaned up. Copilot finds whatever a user can already open.
ai.engineering
AI in daily engineering
Claude, Codex, and open-source agents as coding and ops assistants, in multi-agent workflows where one agent reviews the work of another. A human approves before it runs.
ai.knowledge
Knowledge, memory, and RAG
Embeddings and search over your own documents (RAG), so answers come with sources. Agents keep a memory per project instead of starting from zero every time.
ai.security
AI security and red teaming
Chatbots and agents tested for prompt injection and jailbreaks, MCP tools scanned for poisoning, and a gateway that strips sensitive data before a prompt reaches any model.
ai.governance
Governance and safe use
What data may go to which AI service, written down as a short policy people can actually follow.