London & Europe · 16+ Years Experience

Cross-Domain Technical Architect

Microsoft 365 Platform Architect · Technical Services Lead · Senior Technical Consultant

Multi-disciplined architect progressing from hands-on service desk, desktop, infrastructure and operations roles into senior architecture, technical leadership and enterprise delivery. Strongest across Microsoft 365, Azure, Entra, Intune, Purview, Defender, EUC, infrastructure, cyber, automation and cloud.

Microsoft 365EntraIntunePurviewDefender TeamsExchangeSharePointCopilotAzure

Professional Profile

Architecture that connects engineering, governance and operations.

I bridge enterprise architecture, security governance, technical delivery and service operations; translating business requirements into pragmatic designs, target-state roadmaps, standards and operating models while remaining hands-on across Microsoft cloud and automation technologies.

My delivery spans projects and BAU, discovery and definition, remediation and transformation. I produce HLDs, LLDs, standards, governance frameworks, options appraisals, RAID packs, CRQs, rollback plans, runbooks, migration strategies, roadmaps, ARB/TDA material and service-transition documentation.

01 // CROSS-DOMAIN LENS

Cross-Domain Technical Architecture

Architecture leadership across Microsoft 365, Azure, EUC, infrastructure, identity, security, automation, Wintel, datacentre, service operations and cloud transformation.

Architecture GovernanceEUCInfrastructureSecurityCloudOperations

Core Capabilities

Nine connected architecture domains.

Broad enough to work across the estate, with specialist depth across Microsoft platform architecture, security, compliance, AI governance and modern workplace.

01

Architecture, Governance & Leadership

Discovery, options analysis, target-state architecture, governance, technical planning, documentation, stakeholder leadership and service transition.

HLD/LLD · TDA/ARB · TOGAF · ITIL · ISO 27001 · NIST · CIS
View depth
  • HLDs, LLDs, KBA/SOP/CR artefacts, SoWs, solution proposals, KDDs, runbooks, roadmaps and option appraisals.
  • Planning and visual design using Microsoft Planner, Jira, Monday, Lucidchart, Miro and Visio.
  • GDPR, ISO 27001:2022, SOC 2, Cyber Essentials, NIST CSF 2.0, CIS, SDLC and Government IL0–IL3 alignment.
  • Line management, mentoring, C-suite engagement, vendor/MSP/SI governance and cross-functional technical leadership.
02

Microsoft Entra — Identity & Access

Identity and access governance across Entra ID, Conditional Access, privileged administration, application access, lifecycle controls and Zero Trust-aligned security.

Entra ID · CA · MFA · PIM/JIT · SSO · App Governance · Identity Governance
View depth
  • Users, groups, administrative units, enterprise applications, app registrations, service principals and managed identities.
  • Conditional Access, MFA, SSPR, authentication methods, named locations, Identity Protection and risk-based access.
  • SAML, OAuth/OIDC, SSO, delegated/application permissions, app roles and cross-tenant access.
  • RBAC, PIM, JIT, privileged groups, administrative segregation, lifecycle workflows, access reviews, entitlement management and custom security attributes.
03

Microsoft Intune — Endpoint Management

Cloud-managed endpoint architecture across Windows, iOS and Android, covering provisioning, security, compliance, applications and frontline/shared device patterns.

Intune · Autopilot · Windows 11 · iOS · Android · MDM/MAM · MECM
View depth
  • Autopilot, enrolment profiles, ESP, provisioning strategies and deployment governance.
  • Configuration profiles, Settings Catalog, administrative templates, scripts and remediation policies.
  • Compliance policies, security baselines, endpoint security and Conditional Access integration.
  • Microsoft 365, Win32 and mobile application packaging, deployment, assignment and lifecycle management.
  • Kiosk, shared-device and purpose-built endpoint architectures across Windows, iOS and Android; Workspace ONE and MECM/SCCM coexistence experience.
04

Microsoft Purview — Compliance & AI Governance

Information protection, compliance, data risk and AI governance across Microsoft 365, Copilot and AI-enabled workloads.

Sensitivity Labels · DLP · Retention · eDiscovery · DSPM for AI · Insider Risk
View depth
  • Sensitivity labels, publishing policies, auto-labelling, encryption, IRM and Microsoft/custom Sensitive Information Types.
  • DLP across Endpoint, Teams, Exchange Online, SharePoint Online, OneDrive, Copilot and AI-governance scenarios.
  • Retention, Data Lifecycle Management, records management, disposition review and regulatory governance.
  • Audit, eDiscovery, Content Search, cases, legal holds, Communication Compliance, Insider Risk, Compliance Manager and Information Barriers.
  • DSPM for AI, Copilot governance, ChatGPT Enterprise governance, Activity Explorer, oversharing assessment and sensitive-data exposure analysis.
05

Microsoft Defender — XDR & Security

Endpoint protection, threat detection, exposure management and XDR visibility across Microsoft Defender security services and Zero Trust security architectures.

MDE · XDR · DVM · MDI · MDO · MDCA · KQL · ASR
View depth
  • Defender for Endpoint onboarding, AV/EDR, ASR, device control, security baselines and endpoint security controls.
  • Defender Vulnerability Management, exposure management, Secure Score, recommendations, remediation planning and attack-path analysis.
  • Advanced Hunting, KQL investigation, incident triage, alert correlation and cross-workload XDR visibility.
  • Defender for Identity, Defender for Office 365 and Defender for Cloud Apps governance and investigation patterns.
06

Microsoft 365 — Collaboration, Voice & Content

Tenant and service governance across Teams, Exchange Online, SharePoint Online, OneDrive and collaboration operating models.

Teams · Teams Phone · Teams Rooms · Exchange · SharePoint · OneDrive
View depth
  • Microsoft 365 tenant administration, licensing, service ownership, operational governance, reporting and dependency mapping.
  • Teams lifecycle, channels, guest/external access, meetings, webinars/town halls, Teams Phone, Direct Routing, Operator Connect, Teams Rooms and adoption.
  • Exchange Online mail flow, connectors, transport rules, mailbox/resource governance, SPF/DKIM/DMARC, EOP and compliance alignment.
  • SharePoint/OneDrive information architecture, site governance, permissions, external sharing, libraries, content lifecycle and Copilot-readiness remediation.
07

Azure, Automation, DevOps & Power Platform

Cloud platform architecture, governance and automation using Azure, Graph, PowerShell, DevOps, Infrastructure as Code and Power Platform services.

Landing Zones · Graph · PowerShell · Functions · Logic Apps · IaC · Power Platform
View depth
  • Landing Zones, management groups, subscriptions, resource groups, RBAC/IAM, Azure Policy, tagging and managed identities.
  • Key Vault, App Configuration, Storage, Functions, Automation Accounts, Logic Apps, Azure Monitor, Log Analytics and Application Insights.
  • Microsoft Graph API, REST APIs, PowerShell, PowerShell Universal, runbook-driven collection and workflow orchestration.
  • Azure DevOps, GitHub, CI/CD, Terraform, Packer, Infrastructure as Code and deployment governance.
  • Power Apps, Power Automate, Copilot Studio, DLP policies, environment strategy, ALM principles and maker guardrails.
08

Infrastructure, Wintel, Network & Datacentre

Traditional infrastructure depth across Active Directory, Windows Server, virtualisation, networking, compute, storage and datacentre transformation.

AD DS · Wintel · VMware · Hyper-V · Cisco · Fortinet · SAN/NAS
View depth
  • AD DS, OUs, GPOs, DNS, DHCP, certificates, NPS, KMS, file/storage services, WSUS, MDT/WDS and SCCM/MECM.
  • Windows Server 2003–2022, VMware ESXi/vCenter, Hyper-V, AVD, Horizon and Citrix XenDesktop.
  • Cisco Meraki, Fortinet, WatchGuard, DrayTek: routing, firewall policies, switching, VLANs, wireless, S2S VPN and HA.
  • HPE ProLiant, Cisco UCS, Dell PowerEdge; Synology, IBM Storwize, HPE Nimble/MSA; SAN, NAS, iSCSI and NFS.
09

Service Operations, Monitoring & Resilience

Operational governance across monitoring, ITSM/CMDB, RMM/PSA, backup, disaster recovery, reporting, support models and BAU readiness.

LogicMonitor · SolarWinds · ServiceNow · ITSM/CMDB · Veeam · Rubrik
View depth
  • LogicMonitor, SolarWinds Orion, Lansweeper and Mutiny monitoring/reporting experience.
  • ServiceNow, Remedy, Freshservice, TopDesk, SysAid, Spiceworks and Landesk ITSM/ITAM/CMDB exposure.
  • Pulseway, Atera, BeyondTrust/Bomgar and Workspace ONE Assist remote operations tooling.
  • Rubrik, Veeam, Acronis and Microsoft DPM for backup validation, restore testing, DR planning and operational continuity.
  • Incident, problem, change, service ownership, alerting, support models, handover and operational-readiness governance.

Architecture Portfolio

Microsoft platform depth with cross-domain delivery behind it.

Representative programmes and technical problem-spaces drawn across both architecture profiles, covering identity, endpoint, compliance, security, collaboration, Azure, infrastructure and operational transformation.

01

Identity · Governance · Zero Trust

Entra identity governance and privileged access

Identity architecture covering Conditional Access, MFA, SSPR, PIM/JIT, RBAC, application access, cross-tenant patterns, lifecycle workflows, access reviews, service principals and managed identities.

Entra IDPIMConditional AccessSSO
02

Endpoint · Modern Workplace

Intune, Autopilot and endpoint architecture

Architecture and remediation across Intune, Windows Autopilot, enrolment, ESP, compliance, configuration, applications, security baselines, Hybrid Entra Join and shared/kiosk endpoint patterns.

IntuneAutopilotWindowsMECM
03

Information Protection · Compliance

Purview information protection, DLP and lifecycle governance

Sensitivity labelling, publishing and auto-labelling, encryption, Sensitive Information Types, DLP, retention, records, audit, eDiscovery, Communication Compliance, Insider Risk and information barriers.

PurviewDLPLabelseDiscovery
04

Security · XDR · Exposure

Defender XDR and endpoint security baseline design

Defender for Endpoint, XDR incident visibility, ASR and endpoint controls, vulnerability/exposure management, KQL hunting and alignment across identity, Office 365 and cloud-app security.

Defender XDRMDEDVMKQL
05

AI · Data Security · Governance

Copilot, DSPM for AI and enterprise AI governance

Governance and risk controls for Microsoft 365 Copilot and ChatGPT Enterprise using Purview DLP, sensitivity labels, SIT detection, Audit/Activity Explorer, DSPM for AI, oversharing reviews and sensitive-data exposure analysis.

CopilotDSPM for AIChatGPT EnterprisePurview
06

Collaboration · Messaging · Content

Teams, Exchange and SharePoint governance

Collaboration operating models, Teams lifecycle/voice/rooms, Exchange mail governance and security, SharePoint/OneDrive information architecture, external sharing and Copilot-readiness controls.

TeamsExchangeSharePointOneDrive
07

Cloud Platform · Automation

Azure Landing Zone, automation and evidence frameworks

Azure governance across management groups, subscriptions, policy, RBAC and tagging; platform services using Key Vault, Functions, Automation, Logic Apps, Storage and observability, with Graph/PowerShell-led automation and CI/CD.

AzureLanding ZonesGraphPowerShell
08

EUC · Virtualisation · Migration

MECM, VDI/DaaS and modern workplace transformation

MECM/SCCM platform design, Workspace ONE coexistence, VMware Horizon-to-AVD migration, legacy GPO-to-CSP transition, global Intune/Autopilot rollout and service-readiness planning.

MECMWorkspace ONEHorizonAVD
09

Infrastructure · Datacentre · Network

Infrastructure modernisation and legacy remediation

Server/SAN implementation, VMware architecture, firewall and VPN delivery, Active Directory/GPO remediation, Windows Server decommissioning, reverse-proxy/SaaS transition and datacentre migration activity.

WintelVMwareNetworkStorage
10

Monitoring · ITSM · BAU

Monitoring uplift, operational governance and service transition

SolarWinds-to-LogicMonitor uplift, SSO/RBAC governance, alert tuning, business services, operational baselines, dashboards, RACI ownership, change/rollback planning, documentation and BAU handover.

LogicMonitorSolarWindsRBACService Transition
View additional delivery portfolio
Single Sign-On and role-based access control implementation using Entra ID and Workspace ONE Access.
Infrastructure and EUC audit, remediation and mitigation programmes.
IaaS/PaaS-to-SaaS solution design including reverse proxy for legacy web applications.
WatchGuard and FortiGate firewall implementations plus hub-and-spoke VPN delivery.
HPE/Dell server and SAN implementations and VMware ESXi/vCenter architecture.
Cross-platform kiosk/shared-device architecture across Windows, iOS and Android.
Workspace ONE UEM global design and modern-management coexistence.
Windows Server 2008/2012/2016 estate decommissioning and legacy GPO remediation.
Cyber Essentials/GDPR implementation with Cyber Essentials Plus and ISO 27001 readiness.
JML automation across users, groups, applications and endpoints.
BitLocker Enterprise/MBAM decommission and migration into Microsoft cloud management.
End-to-end office relocation covering technical services for 1,000+ users.
Poly AV/VC and Microsoft Teams Room design and delivery.

Experience

Technical depth built from support through architecture leadership.

One career, two useful views: broad cross-domain architecture and deep Microsoft platform architecture.

Jul 2025 — Sep 2025

Cloud & Infrastructure SME

WWT / Amasol

Led SolarWinds-to-LogicMonitor uplift and operational governance, reducing alert noise and strengthening SSO/RBAC, role separation, monitoring baselines, dashboards and BAU ownership.

Technical depth

Thresholds, alert rules, escalations, automations and Business Services across Meraki, Arista, Silver Peak SD-WAN, Cisco ISE, VitalQIP and Ivanti Pulse, supported by RACI, KB/process documentation, backup validation, event correlation, cutover and rollback planning.

Sep 2024 — Jun 2025

Technical Solutions Architect — EUC Domain

Hitachi Rail

Managed architecture/engineering resources and delivered enterprise endpoint transformation across MECM, endpoint security, VDI/AVD and Microsoft 365/modern workplace governance.

Technical depth

Architected a new MECM/SCCM platform, led global Trellix ePO rollout, delivered VMware Horizon-to-AVD transformation and established operational triage, escalation, configuration and BAU support standards.

Apr 2024 — Sep 2024

Technical Solutions Architect — Infrastructure, EUC & Security

Tracsis

Served on group TDA/ARB with architecture oversight across business units, acting as technical authority and final escalation across Microsoft 365, cloud, EUC, infrastructure and security.

Technical depth

Bridged business stakeholders, internal IT and the incumbent MSP, supporting complex incidents, design decisions, service improvement and transition toward an in-house operating model through capability assessment and future-state support design.

Sep 2023 — Mar 2024

Microsoft Modern Workplace Architect

Charles Taylor (InsureTech)

Led workplace/EUC transformation, managed and matured the Desktop Team, and delivered AVD, Intune, Conditional Access, Autopilot and CSP-based modern workplace services.

Technical depth

Also led an end-to-end office move for 1,000+ users covering endpoint readiness, business continuity, access control, meeting-room AV/VC, site technology and wider workplace services.

Mar 2023 — Aug 2023

European Infrastructure & EUC Lead Consultant

Lipton (Teas & Infusion)

Led European EUC and modern workplace deployment across UK&I, France, Poland, Netherlands, Italy, Germany and Sweden, aligning technical rollout with adoption and operational readiness.

Technical depth

Assessed endpoint capability and dependencies, developed phased rollout strategies and coordinated vendors, contracts, SLAs, communications and transition into BAU support.

May 2022 — Feb 2023

Head of IT & Technical Solutions Architect

IntelliQ

Owned IT operations and enterprise architecture across Microsoft 365, Azure, EUC, infrastructure, cloud, security and service management, including strategy, roadmap, governance and delivery.

Technical depth

Built EUC/infrastructure/security functions, implemented ITSM/ITAM/change/JML platforms, and delivered secure workplace, datacentre and cloud transformation across Azure, M365, VMware, Wintel, SAN, WatchGuard, Intune, Workspace ONE, IAM, RBAC, SSO, monitoring, BC/DR and ISO 27001/Cyber Essentials readiness.

EARLY CAREER

Technical Solutions Architect — Infrastructure & EUCRoyal Papworth Hospital NHS FT · 2021–2022
Microsoft 365 Security Endpoint ConsultantMicrosoft · 2021
Technical Solutions Architect / EUC Technical ManagerRoyal Orthopedic Hospital NHS FT · 2020–2021
National Third Line / Infrastructure RolesServer · Storage · Network · 2015–2020
National First & Second Line RolesService Desk · Desktop · 2010–2015

Contact

Discuss architecture, consulting or technical leadership work.

Available for conversations across Microsoft 365, Azure, identity, security, compliance, endpoint, AI governance, automation, EUC and infrastructure architecture.