Alexander Frank

Freelance · Remote · DACH

Identity & Endpoint Management

I help companies control access to their business data: Microsoft Entra ID, Conditional Access and modern endpoint management through Intune. Alongside that, Okta as a second platform in the workforce identity space.

  • Microsoft Entra ID
  • Intune
  • Conditional Access
  • Okta
  • Microsoft Graph
  • Android Enterprise
User, device and application are connected to the identity layer. From there exactly one path leads to company data, and a policy sits on that path.UserDeviceApplicationIdentityPolicyData
User, application and device meet in the identity layer. That is where it is decided who gets in.

Identity-first

Only verified users and compliant devices get access to company resources.

Identity is the layer that connects users, applications and devices. When it is set up cleanly, the rest of the security architecture becomes something you can steer.

When it is not, you spend your time managing symptoms.

Starting point

Problems I solve

Most environments were not planned badly — they simply grew over years. These are the points where I usually start.

  • Identity environments that grew without a clear structure

    Groups, roles and policies accumulated over years. Nobody can say any more which of them still does anything.

  • Active Directory and cloud identity side by side

    Two directories, two truths. Synchronisation exists, but ownership of any given attribute is unclear.

  • Manual onboarding and offboarding

    Every arrival is a checklist sent by email. Every departure is a hope that nobody skipped a step.

  • Inconsistently configured endpoints

    Devices arrive from different sources with different baselines. Compliance is a claim, not a measurement.

  • Too many administrative permissions, too little control

    Permanently assigned admin roles, grown historically, with no expiry, no approval and no audit trail.

  • No overview of who may access what

    It can be answered, but only with several days of manual work, and with no guarantee of completeness.

Services

What I work with

Five areas, deliverable in clearly scoped packages. What I can do in each field is stated as a capability, not as a war story.

  • 01

    Identity & Access Management

    The core: a directory structure you can explain, and access decisions you can retrace. From user and group structure through authentication methods to privileged roles.

    In hybrid environments I work inside the existing synchronisation between Active Directory and Entra ID. Building or migrating Entra Connect itself is not something I have owned so far.

  • 02

    Endpoint Management

    Devices are the second half of every access decision. Enrollment, baseline, compliance and apps across all four platforms, corporate-owned and personal alike.

  • 03

    Okta

    Okta is my second platform in the workforce identity space. It makes sense where Okta is the leading directory, or runs alongside Entra ID.

  • 04

    Automation

    Whatever is repeatable belongs in a script. Above all the lifecycle: joining, moving, leaving: traceable, logged and without forgotten steps.

  • 05

    Documentation and handover

    The part that most often gets left behind in projects. An environment is only finished when somebody else can keep running it without me.

How I work

How a project runs with me

Four steps I go through in every package, whatever its size.

User, device and context feed into one Conditional Access policy as signals. What comes out is either access or a block.SIGNALSUser and riskDevice complianceLocation and appConditional AccessEvaluate conditionGrant accessBlock
Conditional Access as the decision point: signals in, one decision out.
  1. 01Understand

    Take stock of the identity, access and device environment. What exists, what simply grew, and what was actually intended.

  2. 02Design

    A target picture that fits the organisation, and a route towards it that works while the business keeps running.

  3. 03Implement

    Configure, automate, integrate, in clearly scoped packages rather than one big push.

  4. 04Hand over

    Harden, document, hand over to operations. An environment the internal team can carry on by itself.

Work

Labs and projects

I build my identity practice in my own lab environments and document it publicly. What is a lab is labelled a lab here. What was a client project is labelled a client project.

Hands-on labAugust 2026

JML Lab: joiner/mover/leaver automation with Microsoft Graph PowerShell

The complete identity lifecycle in Microsoft Entra ID through the Graph PowerShell SDK: onboarding with user creation, group and licence assignment, department change, offboarding with disable and delete. Documented with scripts, screenshots from a real tenant and the obstacles that came up while building it.

github.com/alexander-frank-identity/JML-Lab
Hands-on lab2026

Intune and Entra labs

Device enrollment and access control across all four platforms: Windows, macOS, Android and iOS. Compliance policies as a measurable condition, Conditional Access as the decision point on top of it, and BYOD through App Protection Policies where the device is not managed.

Write-up in progress

Client project2024

Blank Baukompetenz — access migration and permission model

Took over a client after an access conflict with their previous provider, who refused them control over their own website. Domain transfer out of the old contract, migration to a system they could administer themselves, and a role and permission model (admin / editor) with defined areas of access. Outcome: full ownership with the client instead of dependency on an outside party.

Verified

Five certifications. Credentials are linked under “About”, each with its issuer.

  • Okta Certified AdministratorOkta · September 2026
  • Okta Certified ProfessionalOkta · August 2026
  • Microsoft Certified: Identity and Access Administrator AssociateMicrosoft · July 2026
  • Microsoft 365 Certified: Endpoint Administrator AssociateMicrosoft · June 2026
  • Android Enterprise Certified ExpertGoogle · January 2026

Where I stand

There are two things I can't yet point to: an Okta customer tenant I built myself, and a hybrid migration I saw through from the start. In both areas my practice comes from lab environments of my own, which I document publicly.

I put this here so you don't have to find it out in conversation. What I'm looking for is scoped implementation work and collaboration with system integrators, MSPs and partners. Inside a project I'm equally direct about what I know and what I'll have to work out.

Notes

Written up from practice

Concrete obstacles, concepts and decisions from my labs, in the form I would have wanted to read them myself.

A question about identity or endpoint management?

Write me a line about what it is about. I usually reply within one working day.

info@alexander-frank.org

Remote, German business hours. Project-based, not employment.