Alexander Frank

Services

Services

Identity, endpoint and the automation in between, in packages that can be scoped.

The points below describe what I can configure, build and hand over. They are phrased as capabilities, not as accounts of past engagements.

01

Identity & Access Management

The core: a directory structure you can explain, and access decisions you can retrace. From user and group structure through authentication methods to privileged roles.

In hybrid environments I work inside the existing synchronisation between Active Directory and Entra ID. Building or migrating Entra Connect itself is not something I have owned so far.

  • Microsoft Entra ID
  • Users, groups, roles, administrative units
  • Conditional Access
  • Multi-factor authentication and authentication methods including FIDO2, passwordless, Temporary Access Pass
  • Self-service password reset
  • Identity Protection
  • Privileged Identity Management
  • Access reviews and entitlement management
  • Break-glass concepts
02

Endpoint Management

Devices are the second half of every access decision. Enrollment, baseline, compliance and apps across all four platforms, corporate-owned and personal alike.

  • Microsoft Intune
  • Device enrollment for Windows 11, macOS, iOS and Android Enterprise
  • Compliance policies
  • Configuration profiles
  • App deployment
  • BYOD through App Protection Policies (MAM)
  • Android Enterprise including Samsung Knox
03

Okta

Okta is my second platform in the workforce identity space. It makes sense where Okta is the leading directory, or runs alongside Entra ID.

  • Okta Workforce Identity
  • Universal Directory
  • Single sign-on over SAML 2.0 and OIDC
  • Group rules
  • Lifecycle management and provisioning over SCIM
  • Authentication and session policies
  • Administration and operations
04

Automation

Whatever is repeatable belongs in a script. Above all the lifecycle: joining, moving, leaving: traceable, logged and without forgotten steps.

  • PowerShell and Microsoft Graph through the Graph PowerShell SDK
  • Joiner-mover-leaver workflows
  • Provisioning and deprovisioning
  • Bulk operations from CSV
  • API-driven identity workflows
05

Documentation and handover

The part that most often gets left behind in projects. An environment is only finished when somebody else can keep running it without me.

  • Configuration baseline
  • Runbooks
  • Integration data sheets per application
  • Decision and change log

A question about identity or endpoint management?

Write me a line about what it is about. I usually reply within one working day.

info@alexander-frank.org

Remote, German business hours. Project-based, not employment.