================================= Systems Engineer Final Report ================================= 1. Summary ============= During my internship at Mohawk Northeast, Inc., a Department of Defense subcontractor, I served as the sole IT administrator responsible for managing approximately 125 users across a hybrid on-premises and cloud environment (Mohawk.local domain and mohawknortheast.com tenant). Over the course of the internship, I built significant portions of the company's IT environment largely from scratch, including a help desk platform, a company intranet portal, a centralized logging/SIEM solution, and modern device management infrastructure, while also handling day-to-day systems administration and supporting the organization's CMMC compliance efforts across three company locations. This work spanned identity and device management (Intune/Autopilot, Entra ID, Active Directory), IT service management (ManageEngine ServiceDesk Plus), security monitoring (ManageEngine Log360), internal web application development (a Power Pages/Power Apps/Dataverse-based intranet), server administration, and vendor evaluation. Based on this work, company leadership has expressed intent to bring me on full-time after graduation. 2. Key Points and Projects ========================= Work Connect - Company Intranet Portal --------------------------------------- - Built and migrated a Power Pages intranet portal (workconnect.mohawknortheast.com) from a development environment to production. - Developed Power Automate flows for time-off approvals, a company events calendar, and user synchronization via the Microsoft Graph API. - Configured Dataverse table permissions and Entra ID authentication with custom web roles; managed ALM solution export/import between environments. - Diagnosed and resolved managed solution locks, hardcoded file references, expired client secrets, and missing production runtime solutions. - Built core features from scratch: a FullCalendar-based company events calendar (Power Automate HTTP flow → Dataverse), a passcode-gated HR section, a three-tier permission model (Public / company-code / Entra ID), and a Dataverse-backed Announcements system with image attachments via the Dataverse Web API. - Managed the full user lifecycle for the portal: External Identity records, web roles, and Entra ID identity provider configuration; troubleshot invite redemption issues. - Built a Power Apps canvas app (Onboarding Canvas App) to manage new-employee records in Dataverse, including gallery selection architecture and multi-select Choice column handling. - Authored management-facing documentation: site architecture, permission model, a company intranet access guide, and the WorkConnect launch announcement. Device Management - Intune/Autopilot/M365 Licensing ------------------------------------------------------- - Led extended troubleshooting of Hybrid Entra Join, including ODJ Connector configuration on a member server, dynamic Entra group rules, and the Enrollment Status Page. - Deployed applications via Intune, including Chrome, Microsoft 365 Apps, CrowdStrike Falcon, Duo, and Zoho Desk. - Identified missing Entra ID P1 licensing as the key blocker preventing automatic MDM enrollment. - Evaluated Microsoft 365 Business Premium against Office 365 E3 for ~125 seats as a cost-effective path to close licensing gaps for Autopilot, Conditional Access, and MDM enrollment. - Deployed an Edge startup URL policy via the Intune Settings Catalog, resolving ADMX Central Store access issues. - Delivered the initial Intune rollout: Company Portal branding, PowerShell/Win32-based printer deployment, Windows Update rings, and MDM/GPO conflict resolution. SIEM Research and Deployment ------------------------------------- - Deployed and configured ManageEngine Log360 (both cloud and on-premises) across ESXi hosts, Meraki firewalls, Synology NAS devices, and network switches. - Troubleshot syslog forwarding and ongoing agent health monitoring. - Worked with CrowdStrike's next gen SIEM across the entire environment ServiceDesk Plus - IT Help Desk Platform ------------------------------------------ - Stood up ManageEngine ServiceDesk Plus with Microsoft 365 OAuth/Graph email integration. - Configured Entra app registrations for inbound/outbound mail, resolved SMTP AUTH tenant restrictions, and evaluated SDP Cloud. - Built automation so the HR new-employee request form auto-generates a second request to the CUI manager for training/certification when a CUI checkbox is selected. Systems Administration & IT Operations ----------------------------------------- - Administered Active Directory: resolved Exchange ActiveSync child object deletion issues, wrote Python/ldap3 scripts to audit inactive accounts, and managed the AD user/computer object lifecycle. - Stood up a Windows Server 2025 RDS terminal server for HeavyJob (HCSS construction management software); used Procmon to trace a missing network drive mapping and resolved it with Group Policy Preference drive mappings. - Resolved a range of operational issues: BSOD/hardware failures (including a MACHINE_CHECK_EXCEPTION), NVMe SSD data recovery guidance, OWA Error 440, DHCP/networking issues on domain-joined machines, and remote wallpaper deployment via PowerShell Remoting. - Migrated a virtual machine from VMware to Hyper-V, diagnosing and resolving an inaccessible boot device error on a Gen 1 Windows Server 2016 guest (IDE controller placement and Hyper-V storage driver fixes). - Authored a vendor comparison proposal evaluating Mimecast, Barracuda, and KnowBe4. - Prepared a formal business justification and market data to support a pay-rate adjustment request to HR, reflecting a transition from intern to part-time technical contributor. 3. Skills to Add to Resume =============================== Identity & Device Management ------------------------------- - Microsoft Intune & Windows Autopilot — app deployment, Settings Catalog policies, Enrollment Status Page, MDM licensing analysis - Microsoft Entra ID — Hybrid Entra Join, dynamic groups, Conditional Access licensing, identity providers - Active Directory administration — user/computer lifecycle management, Group Policy (GPO/GPP), scripting-based auditing - Microsoft 365 administration — licensing strategy (E3 vs. Business Premium), Exchange, OWA troubleshooting Systems & infrastructure --------------------------- - Windows Server administration — Server 2016/2025, Remote Desktop Services (RDS) - Virtualization — VMware to Hyper-V migration, storage/boot troubleshooting - Networking & diagnostics — DHCP, syslog, Procmon-based root cause analysis - PowerShell scripting — PSRemoting, Group Policy automation - Python scripting — LDAP automation (ldap3) for account auditing Application & Platform Development ------------------------------------ - Microsoft Power Platform — Power Pages, Power Apps (canvas apps), Power Automate, Dataverse - Microsoft Graph API integration — user sync, OAuth-based email integration - Web application permissions & authentication design — tiered access models, Entra ID-based auth Security & IT Service Management ----------------------------------- - SIEM deployment — ManageEngine Log360 across servers, firewalls, NAS, and network switches - IT Service Management (ITSM) — ManageEngine ServiceDesk Plus deployment and workflow automation - Security vendor evaluation — email security/anti-phishing platform comparison (Mimecast, Barracuda, KnowBe4) - CMMC compliance support — remediation work across multiple company locations Professional Skills ---------------------- - CO IT ownership — One of two administrators for a ~125-user hybrid environment - Technical documentation — architecture guides, access policies, business justification writing - Vendor & business analysis — cost/licensing comparisons, proposal writing - OSHA 10 Construction