01 // CROSS-DOMAIN LENS
Cross-Domain Technical Architecture
Architecture leadership across Microsoft 365, Azure, EUC, infrastructure, identity, security, automation, Wintel, datacentre, service operations and cloud transformation.
London & Europe · 16+ Years Experience
Microsoft 365 Platform Architect · Technical Services Lead · Senior Technical Consultant
Multi-disciplined architect progressing from hands-on service desk, desktop, infrastructure and operations roles into senior architecture, technical leadership and enterprise delivery. Strongest across Microsoft 365, Azure, Entra, Intune, Purview, Defender, EUC, infrastructure, cyber, automation and cloud.
Professional Profile
I bridge enterprise architecture, security governance, technical delivery and service operations; translating business requirements into pragmatic designs, target-state roadmaps, standards and operating models while remaining hands-on across Microsoft cloud and automation technologies.
My delivery spans projects and BAU, discovery and definition, remediation and transformation. I produce HLDs, LLDs, standards, governance frameworks, options appraisals, RAID packs, CRQs, rollback plans, runbooks, migration strategies, roadmaps, ARB/TDA material and service-transition documentation.
01 // CROSS-DOMAIN LENS
Architecture leadership across Microsoft 365, Azure, EUC, infrastructure, identity, security, automation, Wintel, datacentre, service operations and cloud transformation.
02 // MICROSOFT PLATFORM LENS
Deep Microsoft platform focus across Entra, Intune, Purview, Defender, Teams, Exchange, SharePoint, OneDrive, Copilot, Azure automation and security, compliance & AI governance.
Core Capabilities
Broad enough to work across the estate, with specialist depth across Microsoft platform architecture, security, compliance, AI governance and modern workplace.
Discovery, options analysis, target-state architecture, governance, technical planning, documentation, stakeholder leadership and service transition.
Identity and access governance across Entra ID, Conditional Access, privileged administration, application access, lifecycle controls and Zero Trust-aligned security.
Cloud-managed endpoint architecture across Windows, iOS and Android, covering provisioning, security, compliance, applications and frontline/shared device patterns.
Information protection, compliance, data risk and AI governance across Microsoft 365, Copilot and AI-enabled workloads.
Endpoint protection, threat detection, exposure management and XDR visibility across Microsoft Defender security services and Zero Trust security architectures.
Tenant and service governance across Teams, Exchange Online, SharePoint Online, OneDrive and collaboration operating models.
Cloud platform architecture, governance and automation using Azure, Graph, PowerShell, DevOps, Infrastructure as Code and Power Platform services.
Traditional infrastructure depth across Active Directory, Windows Server, virtualisation, networking, compute, storage and datacentre transformation.
Operational governance across monitoring, ITSM/CMDB, RMM/PSA, backup, disaster recovery, reporting, support models and BAU readiness.
Architecture Portfolio
Representative programmes and technical problem-spaces drawn across both architecture profiles, covering identity, endpoint, compliance, security, collaboration, Azure, infrastructure and operational transformation.
Identity · Governance · Zero Trust
Identity architecture covering Conditional Access, MFA, SSPR, PIM/JIT, RBAC, application access, cross-tenant patterns, lifecycle workflows, access reviews, service principals and managed identities.
Endpoint · Modern Workplace
Architecture and remediation across Intune, Windows Autopilot, enrolment, ESP, compliance, configuration, applications, security baselines, Hybrid Entra Join and shared/kiosk endpoint patterns.
Information Protection · Compliance
Sensitivity labelling, publishing and auto-labelling, encryption, Sensitive Information Types, DLP, retention, records, audit, eDiscovery, Communication Compliance, Insider Risk and information barriers.
Security · XDR · Exposure
Defender for Endpoint, XDR incident visibility, ASR and endpoint controls, vulnerability/exposure management, KQL hunting and alignment across identity, Office 365 and cloud-app security.
AI · Data Security · Governance
Governance and risk controls for Microsoft 365 Copilot and ChatGPT Enterprise using Purview DLP, sensitivity labels, SIT detection, Audit/Activity Explorer, DSPM for AI, oversharing reviews and sensitive-data exposure analysis.
Collaboration · Messaging · Content
Collaboration operating models, Teams lifecycle/voice/rooms, Exchange mail governance and security, SharePoint/OneDrive information architecture, external sharing and Copilot-readiness controls.
Cloud Platform · Automation
Azure governance across management groups, subscriptions, policy, RBAC and tagging; platform services using Key Vault, Functions, Automation, Logic Apps, Storage and observability, with Graph/PowerShell-led automation and CI/CD.
EUC · Virtualisation · Migration
MECM/SCCM platform design, Workspace ONE coexistence, VMware Horizon-to-AVD migration, legacy GPO-to-CSP transition, global Intune/Autopilot rollout and service-readiness planning.
Infrastructure · Datacentre · Network
Server/SAN implementation, VMware architecture, firewall and VPN delivery, Active Directory/GPO remediation, Windows Server decommissioning, reverse-proxy/SaaS transition and datacentre migration activity.
Monitoring · ITSM · BAU
SolarWinds-to-LogicMonitor uplift, SSO/RBAC governance, alert tuning, business services, operational baselines, dashboards, RACI ownership, change/rollback planning, documentation and BAU handover.
Experience
One career, two useful views: broad cross-domain architecture and deep Microsoft platform architecture.
UK Government Local Authority
Cross-domain troubleshooting also covers AD DS, Group Policy, PKCS/SCEP certificate services, NPS/Wi-Fi authentication, Entra device registration, endpoint readiness including TPM/Secure Boot, Landing Zone patterns, Azure Policy, Key Vault, Storage, Functions, Automation Accounts, Logic Apps, Log Analytics and Application Insights. Delivery is supported by HLD/LLD, standards, CRQs, option appraisals, RAID/dependency analysis, rollback plans, runbooks and BAU transition.
WWT / Amasol
Led SolarWinds-to-LogicMonitor uplift and operational governance, reducing alert noise and strengthening SSO/RBAC, role separation, monitoring baselines, dashboards and BAU ownership.
Thresholds, alert rules, escalations, automations and Business Services across Meraki, Arista, Silver Peak SD-WAN, Cisco ISE, VitalQIP and Ivanti Pulse, supported by RACI, KB/process documentation, backup validation, event correlation, cutover and rollback planning.
Hitachi Rail
Managed architecture/engineering resources and delivered enterprise endpoint transformation across MECM, endpoint security, VDI/AVD and Microsoft 365/modern workplace governance.
Architected a new MECM/SCCM platform, led global Trellix ePO rollout, delivered VMware Horizon-to-AVD transformation and established operational triage, escalation, configuration and BAU support standards.
Tracsis
Served on group TDA/ARB with architecture oversight across business units, acting as technical authority and final escalation across Microsoft 365, cloud, EUC, infrastructure and security.
Bridged business stakeholders, internal IT and the incumbent MSP, supporting complex incidents, design decisions, service improvement and transition toward an in-house operating model through capability assessment and future-state support design.
Charles Taylor (InsureTech)
Led workplace/EUC transformation, managed and matured the Desktop Team, and delivered AVD, Intune, Conditional Access, Autopilot and CSP-based modern workplace services.
Also led an end-to-end office move for 1,000+ users covering endpoint readiness, business continuity, access control, meeting-room AV/VC, site technology and wider workplace services.
Lipton (Teas & Infusion)
Led European EUC and modern workplace deployment across UK&I, France, Poland, Netherlands, Italy, Germany and Sweden, aligning technical rollout with adoption and operational readiness.
Assessed endpoint capability and dependencies, developed phased rollout strategies and coordinated vendors, contracts, SLAs, communications and transition into BAU support.
IntelliQ
Owned IT operations and enterprise architecture across Microsoft 365, Azure, EUC, infrastructure, cloud, security and service management, including strategy, roadmap, governance and delivery.
Built EUC/infrastructure/security functions, implemented ITSM/ITAM/change/JML platforms, and delivered secure workplace, datacentre and cloud transformation across Azure, M365, VMware, Wintel, SAN, WatchGuard, Intune, Workspace ONE, IAM, RBAC, SSO, monitoring, BC/DR and ISO 27001/Cyber Essentials readiness.
EARLY CAREER
Contact
Available for conversations across Microsoft 365, Azure, identity, security, compliance, endpoint, AI governance, automation, EUC and infrastructure architecture.