Infrastructure Automation
Repeatable PowerShell and Python workflows for Windows, servers, inventories, reporting, and operational maintenance.
Infrastructure · Endpoint Management · Identity Security
I'm Diogo Wermann, an IT Infrastructure & Security Analyst focused on Windows automation, Microsoft Intune, hybrid identity, observability, and operational resilience.
Automation should be observable, reversible, and explicit about the decisions it refuses to make.
WHAT I WORK ON
I operate across the layers where identity, endpoints, automation, and business continuity meet.
Repeatable PowerShell and Python workflows for Windows, servers, inventories, reporting, and operational maintenance.
Microsoft Intune packaging, deployment, detection, policy validation, and reliable device-side execution.
Active Directory, Microsoft Entra ID, synchronization, device identity correlation, and access-aware operations.
Backups, logs, dashboards, service health, recovery procedures, and evidence for operational decisions.
SELECTED PROJECTS
Each project starts with an operational constraint and is designed around safety, maintainability, and clear documentation.
A safety-first lifecycle engine for inactive hybrid Windows devices across Active Directory, Entra ID, and Intune.
A read-only FastAPI extension that exposes lifecycle reports and logs without extending the privileged control plane.
A Windows agent for validated, versioned wallpaper delivery with privilege separation and safe content promotion.
A complete Win32 deployment package for installing, configuring, detecting, and removing RustDesk through Intune.
A security-conscious PowerShell pipeline for deployment-specific Windows answer files, delegated domain join, Hybrid Microsoft Entra join, cleanup, state, and validation.
FEATURED CASE STUDY
A private, modular platform for support, assets, operational dashboards, scheduling, access control, and service integrations. The source remains private; the architecture and engineering decisions can still be documented responsibly.
Private system · Sanitized engineering case study
TECHNICAL WRITING
Long-form articles explain the constraints, architecture, safeguards, and tradeoffs behind the systems I build.
How a PowerShell agent uses Intune, privilege separation, SHA-256 validation, atomic promotion, and per-user application to manage Windows wallpapers safely.
An engineering case study on converting a working Windows unattended installation into a reusable PowerShell provisioning pipeline without publishing operational secrets.
How a RustDesk MSI became a configured and verifiable Microsoft Intune Win32 application with multi-context configuration, logs, service checks, and custom detection.
ABOUT
I work across infrastructure, user support, automation, endpoint management, backups, monitoring, and security. My focus is turning operational knowledge into systems that are easier to understand, audit, and maintain.
CONTACT
For professional conversations, technical collaboration, or questions about my public projects, use the channels below.