Systems Engineer Final Report

1. Summary

During my internship at Mohawk Northeast, Inc., a Department of Defense subcontractor, I served as the sole IT administrator responsible for managing approximately 125 users across a hybrid on-premises and cloud environment (Mohawk.local domain and mohawknortheast.com tenant). Over the course of the internship, I built significant portions of the company’s IT environment largely from scratch, including a help desk platform, a company intranet portal, a centralized logging/SIEM solution, and modern device management infrastructure, while also handling day-to-day systems administration and supporting the organization’s CMMC compliance efforts across three company locations.

This work spanned identity and device management (Intune/Autopilot, Entra ID, Active Directory), IT service management (ManageEngine ServiceDesk Plus), security monitoring (ManageEngine Log360), internal web application development (a Power Pages/Power Apps/Dataverse-based intranet), server administration, and vendor evaluation. Based on this work, company leadership has expressed intent to bring me on full-time after graduation.

2. Key Points and Projects

Work Connect - Company Intranet Portal

  • Built and migrated a Power Pages intranet portal (workconnect.mohawknortheast.com) from a development environment to production.

  • Developed Power Automate flows for time-off approvals, a company events calendar, and user synchronization via the Microsoft Graph API.

  • Configured Dataverse table permissions and Entra ID authentication with custom web roles; managed ALM solution export/import between environments.

  • Diagnosed and resolved managed solution locks, hardcoded file references, expired client secrets, and missing production runtime solutions.

  • Built core features from scratch: a FullCalendar-based company events calendar (Power Automate HTTP flow → Dataverse), a passcode-gated HR section, a three-tier permission model (Public / company-code / Entra ID), and a Dataverse-backed Announcements system with image attachments via the Dataverse Web API.

  • Managed the full user lifecycle for the portal: External Identity records, web roles, and Entra ID identity provider configuration; troubleshot invite redemption issues.

  • Built a Power Apps canvas app (Onboarding Canvas App) to manage new-employee records in Dataverse, including gallery selection architecture and multi-select Choice column handling.

  • Authored management-facing documentation: site architecture, permission model, a company intranet access guide, and the WorkConnect launch announcement.

Device Management - Intune/Autopilot/M365 Licensing

  • Led extended troubleshooting of Hybrid Entra Join, including ODJ Connector configuration on a member server, dynamic Entra group rules, and the Enrollment Status Page.

  • Deployed applications via Intune, including Chrome, Microsoft 365 Apps, CrowdStrike Falcon, Duo, and Zoho Desk.

  • Identified missing Entra ID P1 licensing as the key blocker preventing automatic MDM enrollment.

  • Evaluated Microsoft 365 Business Premium against Office 365 E3 for ~125 seats as a cost-effective path to close licensing gaps for Autopilot, Conditional Access, and MDM enrollment.

  • Deployed an Edge startup URL policy via the Intune Settings Catalog, resolving ADMX Central Store access issues.

  • Delivered the initial Intune rollout: Company Portal branding, PowerShell/Win32-based printer deployment, Windows Update rings, and MDM/GPO conflict resolution.

SIEM Research and Deployment

  • Deployed and configured ManageEngine Log360 (both cloud and on-premises) across ESXi hosts, Meraki firewalls, Synology NAS devices, and network switches.

  • Troubleshot syslog forwarding and ongoing agent health monitoring.

  • Worked with CrowdStrike’s next gen SIEM across the entire environment

ServiceDesk Plus - IT Help Desk Platform

  • Stood up ManageEngine ServiceDesk Plus with Microsoft 365 OAuth/Graph email integration.

  • Configured Entra app registrations for inbound/outbound mail, resolved SMTP AUTH tenant restrictions, and evaluated SDP Cloud.

  • Built automation so the HR new-employee request form auto-generates a second request to the CUI manager for training/certification when a CUI checkbox is selected.

Systems Administration & IT Operations

  • Administered Active Directory: resolved Exchange ActiveSync child object deletion issues, wrote Python/ldap3 scripts to audit inactive accounts, and managed the AD user/computer object lifecycle.

  • Stood up a Windows Server 2025 RDS terminal server for HeavyJob (HCSS construction management software); used Procmon to trace a missing network drive mapping and resolved it with Group Policy Preference drive mappings.

  • Resolved a range of operational issues: BSOD/hardware failures (including a MACHINE_CHECK_EXCEPTION), NVMe SSD data recovery guidance, OWA Error 440, DHCP/networking issues on domain-joined machines, and remote wallpaper deployment via PowerShell Remoting.

  • Migrated a virtual machine from VMware to Hyper-V, diagnosing and resolving an inaccessible boot device error on a Gen 1 Windows Server 2016 guest (IDE controller placement and Hyper-V storage driver fixes).

  • Authored a vendor comparison proposal evaluating Mimecast, Barracuda, and KnowBe4.

  • Prepared a formal business justification and market data to support a pay-rate adjustment request to HR, reflecting a transition from intern to part-time technical contributor.

3. Skills to Add to Resume

Identity & Device Management

  • Microsoft Intune & Windows Autopilot — app deployment, Settings Catalog policies, Enrollment Status Page, MDM licensing analysis

  • Microsoft Entra ID — Hybrid Entra Join, dynamic groups, Conditional Access licensing, identity providers

  • Active Directory administration — user/computer lifecycle management, Group Policy (GPO/GPP), scripting-based auditing

  • Microsoft 365 administration — licensing strategy (E3 vs. Business Premium), Exchange, OWA troubleshooting

Systems & infrastructure

  • Windows Server administration — Server 2016/2025, Remote Desktop Services (RDS)

  • Virtualization — VMware to Hyper-V migration, storage/boot troubleshooting

  • Networking & diagnostics — DHCP, syslog, Procmon-based root cause analysis

  • PowerShell scripting — PSRemoting, Group Policy automation

  • Python scripting — LDAP automation (ldap3) for account auditing

Application & Platform Development

  • Microsoft Power Platform — Power Pages, Power Apps (canvas apps), Power Automate, Dataverse

  • Microsoft Graph API integration — user sync, OAuth-based email integration

  • Web application permissions & authentication design — tiered access models, Entra ID-based auth

Security & IT Service Management

  • SIEM deployment — ManageEngine Log360 across servers, firewalls, NAS, and network switches

  • IT Service Management (ITSM) — ManageEngine ServiceDesk Plus deployment and workflow automation

  • Security vendor evaluation — email security/anti-phishing platform comparison (Mimecast, Barracuda, KnowBe4)

  • CMMC compliance support — remediation work across multiple company locations

Professional Skills

  • CO IT ownership — One of two administrators for a ~125-user hybrid environment

  • Technical documentation — architecture guides, access policies, business justification writing

  • Vendor & business analysis — cost/licensing comparisons, proposal writing

  • OSHA 10 Construction