Enterprise IT Support · Service Delivery · Technical Leadership

When the Obvious Fix Fails,
That's Where I Start.

My name is Mace Cole Davis. I've spent more than seven years in enterprise IT support, working through escalations, identity issues, onboarding, and the problems that keep people out of production. I also train technicians and help teams streamline how they provide support. Whether it's a printer that refuses to cooperate or a problem buried in a legacy on-premises system, I'm happy to dig in.

Experience at a Glance
7+Years in Enterprise IT
50 - 100Tickets Managed Weekly at GreenSky and Genpact
388Users Onboarded in BPO Rollout
40%Reduction in Onboarding Technician Labor
Portrait of Mace Cole Davis
About Me

How I Work

I like the complicated tickets. I also like making sure the next technician doesn't have to solve the same problem from scratch. That means documenting what worked, explaining why it worked, and sharing it with the team.

Most of my background is in Microsoft environments, including Entra ID, Active Directory, Microsoft 365, endpoints, and virtual desktops. I've also spent a lot of time handling escalations, coordinating onboarding, and helping newer technicians find their footing.

Professional Background

Enterprise IT Experience

I've spent more than seven years troubleshooting enterprise IT issues, handling escalations, training technicians, and helping keep daily support operations on track.

Technical Support Analyst II (Acting Team Lead)

July 2026 – Present

Genpact

  • Support day-to-day IT operations, including user onboarding, account provisioning, access troubleshooting, service desk coverage, and operational reporting.
  • Coordinate new-hire account readiness, application access, system setup, and issue resolution.
  • Train technicians on troubleshooting procedures, escalation paths, service standards, and team expectations.
  • Work with internal stakeholders to resolve employee-data and account-access issues affecting provisioning and service delivery.
  • Support knowledge transfer and BPO operational transition efforts, focusing on clear handoffs and continuity for users and technicians.

Technical Support Analyst II (Acting Team Lead)

March 2019 – June 2026

GreenSky LLC

  • Served as day-to-day acting lead for a support team of approximately ten analysts supporting an enterprise environment of more than 1,600 users.
  • Coordinated ticket distribution, escalation priorities, SLAs, and support continuity.
  • Acted as a primary escalation resource for complex Microsoft 365, endpoint, hardware/software, identity, access, and authentication problems.
  • Managed 50–100 tickets per week and regularly contributed approximately 25% of the team's ticket workload.
  • Trained and onboarded technicians; improved shared troubleshooting procedures, escalation practices, and internal knowledge articles.
  • Supported cloud desktops, vendor coordination, technical rollouts, user communications, and post-release troubleshooting.
Working With Other People

Training and Team Support

I enjoy helping technicians get comfortable with unfamiliar problems. I try to explain the reasoning, not just give someone the answer. Good documentation and clear handoffs make everyone's job easier.

01 / Align

BPO Transition Coordination

Work with other teams to sort out ownership, account readiness, support processes, and handoffs during transitions.

02 / Enable

Technician Training and Mentorship

Help newer technicians learn how to investigate issues, recognize when to escalate, and become confident working on their own.

03 / Document

Knowledge Transfer and SOPs

Turn the fixes and processes we learn into instructions the rest of the team can actually use.

04 / Sustain

Service Continuity and Accountability

Keep people informed about priorities, realistic timelines, and who owns the next step when things change.

What I Bring to a Team

Making the Next Ticket Easier

Solving the problem matters, but so does what happens next. If I can document a fix, teach someone how to spot the issue, or improve the escalation process, the whole team benefits the next time it comes up.

  • Comfortable guiding teammates through unfamiliar technical issues
  • Focused on clear expectations and practical, repeatable handoffs
  • Experienced balancing ticket volume with coaching and daily operations
  • Share what I learn so other technicians can use it
Technical and Operational Capabilities

A Broader Technical Toolkit

Not just products I've touched, but the responsibilities and practices I've used to support real enterprise environments.

01 / IDENTITY

Identity and Access Management

User access, authentication troubleshooting, secure provisioning, and account lifecycle support.

Entra IDActive DirectoryConditional AccessAccount Provisioning
02 / AUTHENTICATION

Multifactor Authentication

Helping users regain secure access and resolving authentication issues with enterprise sign-in tools.

MFAFIDO2YubiKeyTemporary Access Pass
03 / PRODUCTIVITY

Microsoft 365 and Messaging

Application and service support across enterprise collaboration and email environments.

Microsoft 365ExchangeOutlookTeams
04 / ENDPOINTS

Endpoint and Desktop Support

Resolving Windows, desktop, software, and managed-device issues across distributed teams.

WindowsIntuneCompany PortalSCCM
05 / CLOUD

Virtual Desktops and Remote Support

Working through cloud desktop, user access, VPN, and remote connectivity issues.

Windows 365Cloud PCVPN SupportRemote Troubleshooting
06 / SECURITY

Endpoint Security and Compliance

Supporting security tools, secure access workflows, and issue resolution with specialized teams.

Defender for EndpointNetskopeRapid7Security Coordination
07 / OPERATIONS

Incident and Escalation Management

Ticket triage, issue prioritization, ownership, escalations, and follow-through against service expectations.

JiraSLAsTicket TriageEscalation Workflows
08 / PEOPLE

Team Leadership and Mentorship

Daily lead responsibilities, coaching, technician training, and thoughtful support of new teammates.

Acting Team LeadTrainingCoachingTeam Support
09 / TRANSITIONS

BPO Operations and Transitions

Coordinating account readiness, operational handoffs, new-hire enablement, and support continuity.

BPO CoordinationTransition SupportReadinessHandoffs
10 / LEARNING

Documentation and Knowledge Transfer

Creating and refining practical support procedures and sharing troubleshooting approaches.

SOPsKnowledge ArticlesProcess Improvement
11 / COLLABORATION

Cross-Functional Problem Solving

Partnering with internal technical teams and vendors to remove blockers and resolve recurring issues.

Vendor CoordinationCross-Team IncidentsProject Rollouts
12 / DELIVERY

Onboarding and Service Reporting

Provisioning and new-hire workflows, operations tracking, service desk coverage, and clear communications.

User OnboardingAccess ReadinessOperational Reporting
Enterprise Troubleshooting · Real-World Escalations

Technical Troubleshooting Case Studies

These are technical problems I worked on directly. I've removed company-specific details and added public documentation where it helps explain the technology.

Case Study 01 · Identity / Virtual Desktop Infrastructure

Resolving FIDO2 Passkey Errors in a Legacy Virtual Desktop Environment

Users couldn't complete biometric passkey sign-ins from a legacy virtual desktop. I ruled out a Conditional Access block, narrowed the issue to the remote session, and documented a six-digit code workaround using Yubico Authenticator.

Microsoft Entra IDAzure Virtual DesktopFIDO2 / WebAuthnYubico AuthenticatorOATH One-Time CodesWindows 365 Comparison

01 / Symptoms and Scope

Users attempting biometric security-key authentication from the legacy Azure Virtual Desktop environment encountered this sign-in failure:

“We couldn't sign you in. Something went wrong when trying to sign in with a passkey. Please try again.”

Microsoft Entra Conditional Access permitted FIDO2 authentication, so the failure could not be explained simply as a policy forbidding the method. The issue was tied to the authentication experience inside the affected virtual desktop connection path.

02 / What Distinguished the Problem

The same behavior was not observed on Microsoft Windows 365 Cloud PCs in the supported environment. That contrast made it important to investigate how the older virtual desktop session handled the locally connected biometric authenticator, rather than treating the passkey message as a generic account or Conditional Access problem.

Observed comparison: legacy AVD session: passkey error; Windows 365 Cloud PC: no matching failure observed. This is a firsthand comparison, not a claim that one platform universally supports a feature the other never supports.

03 / Investigation and Diagnostic Reasoning

  1. Separated authentication policy from authentication transport. Confirmed that FIDO2 authentication was an allowed sign-in method. An approved method can still fail if the remote session cannot properly complete a device-based challenge.
  2. Focused on the redirection boundary. The failure was associated with using a local biometric key through the legacy virtual desktop environment. This indicated a compatibility problem in the session's device/authenticator redirection path, rather than a demonstrated Conditional Access denial.
  3. Compared a different Microsoft desktop platform. Windows 365 Cloud PCs did not exhibit the reported behavior, supporting a configuration- or connection-path-specific diagnosis.
  4. Selected a sanctioned alternative authentication method. Instead of relying on the failing passkey flow, developed a Yubico Authenticator workflow that let affected users complete MFA with a six-digit one-time code.

Technical clarification: Microsoft documents WebAuthn redirection for both Azure Virtual Desktop and Windows 365. This is a higher-level protocol pathway and should not be conflated with ordinary low-level USB passthrough. The precise setting, client version, and device-driver interaction that caused the original failure were not retained, so the case does not claim a more specific root cause than the observed compatibility boundary.

04 / Resolution

Documented and implemented an approved alternate software-assisted MFA flow using Yubico Authenticator. Users entered a six-digit code displayed by the application instead of completing the failing in-session biometric FIDO2 passkey challenge.

This is correctly described as an OATH one-time-password (OTP) authentication method, not OAuth and not the original FIDO2 passkey operation. It bypassed the problematic device-based sign-in path rather than repairing WebAuthn redirection itself.

05 / Outcome and Security Considerations

The alternate workflow restored authentication for the affected users without requiring an organizational policy change to prohibit or broadly weaken FIDO2 sign-in. The Cloud PC comparison helped limit the scope of the investigation to the affected virtual desktop experience.

Tradeoff: A typed one-time code is a different authentication mechanism from a phishing-resistant FIDO2 security-key challenge. The method must be enabled and approved by the identity/security team and should not be presented as an equivalent replacement for phishing-resistant authentication.

06 / Technical Context and Documentation Limits

Microsoft's support model: FIDO2 in remote sessions relies on supported clients and WebAuthn redirection settings. Windows 365 enables WebAuthn redirection in its default documented configuration, while Azure Virtual Desktop redirection also depends on session-host policy and host-pool settings. Those differences provide potential avenues for investigation, but do not independently prove which setting caused this incident.

Yubico's device distinction: Yubico Authenticator can display six-digit OATH TOTP codes with supported OATH-capable keys. Yubico's published compatibility matrix lists YubiKey Bio FIDO Edition as lacking OATH-code capability. Because the exact model and OTP credential storage details were not preserved, this case documents the successful app-displayed code flow.

Documentation method: Incident behavior, platform comparison, and workaround are reconstructed from firsthand experience; protocol explanations and vendor capabilities are sourced from public documentation. No production tenant settings, employee records, internal URLs, identifiers, or proprietary procedures are reproduced.

Case Study 02 · Identity Governance / Enterprise SSO

Resolving False Inactivity Flags for Active Consulting Accounts

Consulting accounts were being disabled even though people were still using them. I traced the problem to an authentication path our inactivity checks couldn't see, then worked with the Enterprise Tools team to make Microsoft SSO available to the affected users.

Hybrid IdentityMicrosoft Entra IDEnterprise SSOActive DirectoryAccount Lifecycle ControlsCross-Team Remediation

01 / The Problem

Consulting personnel regularly accessed authorized business applications through an independent third-party single sign-on provider. Nevertheless, their directory accounts were being automatically disabled as inactive by an existing account-lifecycle process.

The automated control served a legitimate security objective: limiting residual access for accounts that were no longer being used. The problem was that some genuinely active users were invisible to the activity signal being evaluated.

02 / Root-Cause Analysis

These users could authenticate to their applications through the external SSO provider without traversing the Microsoft authentication path observed by the environment's inactivity process. Successful application use therefore did not reliably register as activity for that control.

Key distinction: An application login can succeed while a separate identity platform has no corresponding sign-in event. Authentication success and lifecycle visibility are different things.

This was not evidence that the inactivity automation itself had malfunctioned. Its input signal was incomplete for the affected authentication path.

03 / Investigation and Escalation

  1. Correlated symptoms with identity usage. Established that users were still performing work in approved applications, despite being classified as inactive by the automated account process.
  2. Compared the sign-in paths. Identified that application access through the independent SSO provider did not generate the Microsoft-observed activity that the control expected.
  3. Examined directory evidence. Used account sign-in history and on-premises Active Directory logon timestamps as diagnostic clues, rather than treating a single timestamp as the complete source of truth.
  4. Engaged the Enterprise Tools team. Presented the issue and coordinated a remediation that fit an already-planned transition toward Microsoft-based enterprise SSO.

04 / The Resolution

Worked with the Enterprise Tools team to introduce a parallel Microsoft Entra-based SSO configuration for affected applications, available through Microsoft My Apps. The existing external SSO path remained available while affected consulting users were migrated to the Microsoft-backed route.

The change accelerated a planned platform transition for the users most affected by the false inactivity determination; it did not require weakening or disabling the inactivity safeguard.

05 / Verification: Three Checks

  • Initial signal: After the affected users switched authentication paths, their on-premises AD logon timestamp was observed updating. This was the first indication that the activity path had changed.
  • Next scheduled run: Confirmed that the accounts stayed enabled after the following morning's automated inactivity-processing cycle.
  • Continued monitoring: Took responsibility for administering the affected consulting accounts and monitored them for two additional weeks. No repeat automatic disablements were observed during that period.

06 / Technical Interpretation and Lessons Learned

Why the change mattered: A security control is only as reliable as the activity it can observe. When applications authenticate through different identity providers, an inactivity decision built around one provider's sign-in signals may not reflect real application use. Aligning the affected application's authentication path with the monitored identity platform corrected that gap in this environment.

Important limitation: Opening an application from My Apps does not by itself guarantee Microsoft handles authentication. Microsoft supports linked applications that simply redirect to another provider. The implemented configuration used Microsoft-backed SSO; the underlying integration details are intentionally not published. Likewise, an Entra sign-in does not inherently update an on-premises AD lastLogonTimestamp in every hybrid configuration. The observed timestamp change is presented as incident evidence, not a universal protocol guarantee.

Transferable skills: Hybrid identity troubleshooting, evaluating lifecycle-control inputs, authentication-path analysis, cross-functional collaboration, staged SSO migration, and time-based post-change verification.

Disclosure: This account is reconstructed from firsthand experience and publicly available platform documentation. Company names, internal application names, configurations, threshold values, automation logic, identities, and tenant details are intentionally omitted.

PowerShell · Active Directory · Exchange Online

PowerShell Automation and Directory Administration

These are scripts I've used for directory lookups, bulk reporting, email address administration, and access checks. Three are highlighted below, and the full set of eleven is available to browse and download.

The examples use fictional account names and environment details. I've kept the scripts focused on the administrative tasks they were written for.

Download All 11 Scripts ↓
01 / Messaging Administration

Bulk SMTP Proxy Address Updates

This utility reads account and alias values from a CSV and updates Active Directory proxyAddresses in bulk. The public version preserves existing non-SMTP aliases, handles the primary/secondary SMTP distinction, and lets you review changes before applying them.

CSV ImportsproxyAddressesBulk UpdatesChange Control

Technical approach: Look up each account, compare existing aliases with the requested primary and secondary addresses, then prepare a corrected proxy-address set.

Change behavior: Read-only preview by default; -Apply enables explicitly confirmable updates. Follow the organization's Exchange or hybrid attribute ownership rules.

View Script
# CSV columns: UserID, PrimarySMTP, SecondarySMTP
# PrimarySMTP is the email address, without the SMTP: prefix.
# Coordinate with Exchange if email address policies or sync own the attributes.
[CmdletBinding(SupportsShouldProcess=$true, ConfirmImpact='High')]
param(
    [Parameter(Mandatory)][string]$CsvPath,
    [string]$DomainController,
    [switch]$Apply
)
Import-Module ActiveDirectory -ErrorAction Stop
$adOptions = @{ ErrorAction = 'Stop' }
if ($DomainController) { $adOptions.Server = $DomainController }

foreach ($row in @(Import-Csv -Path $CsvPath -ErrorAction Stop)) {
    $account = [string]$row.UserID
    $primary = ([string]$row.PrimarySMTP -replace '^(?i:SMTP:)', '').Trim()
    $secondary = ([string]$row.SecondarySMTP -replace '^(?i:SMTP:)', '').Trim()
    if ([string]::IsNullOrWhiteSpace($account) -or $primary -notmatch '^[^@\s]+@[^@\s]+$') {
        Write-Warning "Skipping invalid account or primary SMTP for '$account'."
        continue
    }
    if ($secondary -and $secondary -notmatch '^[^@\s]+@[^@\s]+$') {
        Write-Warning "Skipping invalid secondary SMTP for '$account'."
        continue
    }

    try {
        $user = Get-ADUser -Identity $account -Properties proxyAddresses @adOptions
        $existing = @($user.proxyAddresses)
        $nonSmtp = @($existing | Where-Object { $_ -notmatch '^(?i:smtp:)' })
        $smtpAddresses = @($existing | Where-Object { $_ -match '^(?i:smtp:)' } |
            ForEach-Object { $_.Substring(5) })
        if ($secondary) { $smtpAddresses += $secondary }
        # Retain the previous primary as an alias, unless the organization removes it separately.
        $unique = @($smtpAddresses | Where-Object { $_ } | Sort-Object -Unique)
        $newProxy = @($nonSmtp) + @("SMTP:$primary") + @(
            $unique | Where-Object { $_ -ine $primary } | ForEach-Object { "smtp:$_" }
        )
        $changed = (@($existing | Sort-Object) -join '|') -cne (@($newProxy | Sort-Object) -join '|')
        [PSCustomObject]@{
            UserID = $account; PrimarySMTP = $primary
            SecondarySMTP = $secondary
            Action = if (-not $changed) { 'No change' } elseif ($Apply) { 'Update requested' } else { 'Preview only' }
        }
        if ($changed -and $Apply -and $PSCmdlet.ShouldProcess($account, 'Replace proxyAddresses')) {
            Set-ADUser -Identity $user -Replace @{ proxyAddresses = $newProxy } @adOptions
        }
    }
    catch { Write-Warning "Unable to update '$account': $($_.Exception.Message)" }
}
02 / Access Validation

Recursive Security Group Verification

I used this approach to check whether a list of users had the expected AD group membership, including membership inherited through nested groups. It lets me run one group query and then check each account against the result.

Security GroupsNested GroupsAccess ChecksRead-Only

Technical approach: Get recursive group members once, compare account distinguished names, and produce a clear membership result for each user.

Change behavior: No directory changes. Requires Active Directory access and appropriate read permissions.

View Script
[CmdletBinding()]
param(
    [string]$GroupName = 'Example-Security-Group',
    [string[]]$UserIds = @('example.user1', 'example.user2')
)
Import-Module ActiveDirectory -ErrorAction Stop

# Pull members once for speed (Recursive includes nested groups).
$groupMembers = @(Get-ADGroupMember -Identity $GroupName -Recursive -ErrorAction Stop |
    Where-Object { $_.objectClass -eq 'user' })
$memberDns = @{}
foreach ($member in $groupMembers) { $memberDns[$member.DistinguishedName] = $true }

foreach ($userId in $UserIds) {
    try {
        $user = Get-ADUser -Identity $userId -ErrorAction Stop
        [PSCustomObject]@{
            UserID = $userId; Group = $GroupName
            IsMember = $memberDns.ContainsKey($user.DistinguishedName)
            Status = 'Found'
        }
    }
    catch {
        [PSCustomObject]@{
            UserID = $userId; Group = $GroupName
            IsMember = $false; Status = 'Lookup failed'
        }
    }
}
03 / Messaging Audit

Primary SMTP Address Lookup

This lookup checks users for the uppercase SMTP: proxy address that represents the primary email address in standard Exchange proxy-address conventions.

AD QueriesSMTP AddressesUser LookupRead-Only

Technical approach: Find each named account, inspect its proxyAddresses, and distinguish the actual primary SMTP entry from secondary aliases and the separate mail attribute.

Change behavior: No directory changes. Reports missing and ambiguous matches instead of silently choosing an account.

View Script
Import-Module ActiveDirectory -ErrorAction Stop

$names = @('Example User One', 'Example User Two')
foreach ($name in $names) {
    $escaped = $name.Replace("'", "''")
    try {
        $matches = @(Get-ADUser -Filter "Name -eq '$escaped'" `
            -Properties proxyAddresses, mail -ErrorAction Stop)
        if ($matches.Count -ne 1) {
            [PSCustomObject]@{
                Name = $name; PrimarySMTP = ''
                Status = if ($matches.Count -gt 1) { 'Multiple matches' } else { 'Not found' }
            }
            continue
        }
        $primary = @($matches[0].proxyAddresses | Where-Object { $_ -clike 'SMTP:*' })
        [PSCustomObject]@{
            Name = $name
            PrimarySMTP = if ($primary.Count -eq 1) { $primary[0].Substring(5) } else { '' }
            Status = if ($primary.Count -eq 1) { 'Found' } else { 'No unique primary proxy found' }
        }
    }
    catch {
        [PSCustomObject]@{ Name = $name; PrimarySMTP = ''; Status = 'Lookup failed' }
    }
}
# For an Exchange mailbox, Get-Mailbox -Identity <user> can also return PrimarySmtpAddress.
Full script collection: Eleven sanitized PowerShell utilities, including CSV exports, parent and child group lookups, direct and recursive membership checks, email lookups, SMTP updates, and an Exchange Online mail-flow rule. The public versions have placeholder values and review steps where changes could affect accounts or email routing.

More PowerShell Utilities

Display Name CSV Export

Resolves sAMAccountName values from a CSV into display names and exports a report.

Download .ps1 ↓

Direct Parent Group Lookup

Lists groups that directly contain a specified Active Directory group.

Download .ps1 ↓

Bulk Display Name to User ID Lookup

Looks up sAMAccountName values from multiple AD display names, with an ambiguity check.

Download .ps1 ↓

User Group Membership Lookup

Reports the direct AD groups assigned to a user, with optional domain controller selection.

Download .ps1 ↓

Bulk Email Address Lookup

Resolves names to AD mail addresses with UPN fallback; skips ambiguous matches instead of guessing.

Download .ps1 ↓

UPN and User ID Bulk Export

Retrieves sAMAccountName, UPN, and email for a name list from a specified domain controller and exports a CSV.

Download .ps1 ↓

Exchange Online Bulk Mail Redirect

Creates a mail flow rule to redirect messages from multiple senders; previews by default.

Download .ps1 ↓

Nested Child Security Groups

Lists the direct group objects contained within a security group, without confusing children with parents.

Download .ps1 ↓

Hands-On Learning

Projects Outside Work

Outside work, I spend a lot of time tinkering with computers, networking, and other projects. I usually end up taking notes on what broke, what I tried, and what finally worked. These are my own projects, not employer work.

PERSONAL LAB / 01

Home Networking and Systems

Configuring and troubleshooting personal network connectivity, shared resources, and wired infrastructure.

Focus: topology, connectivity validation, file shares, and practical diagnostics.
HARDWARE / 02

PC Hardware and Diagnostics

I built both of my desktop workstations and regularly work on compatibility, storage upgrades, component replacement, and extending the useful life of older systems.

Focus: isolating faults, economical repairs, upgrade planning, and system validation.
DEVELOPMENT / 03

Continued Technical Education

Studying IT and cybersecurity at Northern Kentucky University while extending my knowledge through hands-on projects.

Focus: cybersecurity foundations, Python fundamentals, and practical systems concepts.
OPERATIONS / 04

Documentation and Mentorship

Translating complicated technical processes into approachable guidance for other people.

Focus: standard procedures, knowledge sharing, effective coaching, and better handoffs.
My Personal Infrastructure

Hardware and Home Lab

I built both of the desktop workstations below. The 6 TB Windows Server NAS is also deployed and has hosted Minecraft Java Edition and Palworld. These are systems I actually use at home, not hypothetical builds.

How It Started

How I Got Into IT

Most of my professional experience is in software and support. Hardware is what got me into IT, though, and it's still the part I love most.

Money was tight when I was a kid. I remember my grandfather swapping PC components, troubleshooting whatever broke, and even taping box fans to computer cases. Wires and cables stretched across the room. While my friends were running Windows 7, we were still using XP and Vista. We didn't always have the newest equipment, so we figured out how to make what we had work.

That stuck with me. I built both of the desktop workstations below, and I care a lot about repairing, reusing, and giving hardware a second life. Reducing e-waste matters to me. Every computer is a modern marvel of engineering and ingenuity, with somebody's time, effort, blood, sweat, and tears behind it. To me, being an enthusiast isn't just about buying newer parts. It's about understanding what you have and making the most of it.

02 / Infrastructure

6 TB NAS and Windows Server Home Lab

I repurposed this Lenovo desktop into a working 6 TB NAS running Windows Server 2022. I've also used it to host Minecraft Java Edition and Palworld servers.

CPU
Intel Pentium G4400 · 2 Cores / 2 Threads
RAM
16 GB DDR4
Storage
6 TB NAS storage · 256 GB SSD
Platform
Lenovo Desktop Platform
OS
Windows Server 2022
Status: Operational 6 TB NAS · Minecraft Java Edition and Palworld hosting completed · Read the NAS and Lab Notes →
03 / Secondary Workstation

Secondary Workstation

Built by Me

I built this desktop for general-purpose computing, additional testing, and hardware troubleshooting.

CPU
Intel Core i7-8700 · 6 Cores / 12 Threads
GPU
NVIDIA GeForce RTX 2070
RAM
32 GB DDR4
Board
ASUS Z390 Platform
OS
Windows 11 Home
Project Focus: Windows troubleshooting, spare capacity, and comparative testing
04 / Ubuntu System

Streaming Server

A dedicated Ubuntu system intended for streaming-related roles and lightweight Linux administration practice.

CPU
Intel Core i5-8300H · 4 Cores / 8 Threads
GPU
NVIDIA GeForce GTX 1050 Ti
RAM
16 GB
Platform
Acer Nitro Laptop Hardware
OS
Ubuntu
Project Focus: Ubuntu administration, media and streaming support, and Linux troubleshooting
05 / Portable System

Personal Notebook

A portable Ubuntu system for personal computing, Linux use, and mobile troubleshooting work.

CPU
AMD Ryzen 7 5800H · 8 Cores / 16 Threads
GPU
NVIDIA GeForce RTX 3070 Laptop GPU
RAM
16 GB
Platform
Lenovo Legion 5 Pro 16ACH6H
OS
Ubuntu
Project Focus: Portable Linux workflows, diagnostics, and flexible compute capacity
06 / Networking

Home Network Router

The router anchoring my home network, supporting wired and wireless connectivity for personal systems and future demonstrations.

Model
Netgear Nighthawk R6400v2
Class
AC1750 Dual-Band Router
Role
Home Networking Core
Focus
Connectivity, coverage, and troubleshooting
Project Focus: Home networking, routing, wireless reliability, and connectivity diagnostics
Infrastructure Design · Home Lab Project

6 TB Windows Server NAS and Home Lab

I built and deployed this 6 TB Windows Server NAS using a repurposed Lenovo desktop. File storage is working, and I've already hosted Minecraft Java Edition and Palworld on it. The DNS, DHCP, and Wake-on-LAN sections below are optional technical reference examples, not unfinished parts of the build.

DEPLOYED NAS / GAME SERVER

Why Repurpose Existing Hardware?

Instead of buying enterprise hardware, I reused a compact Lenovo desktop built around an Intel Pentium G4400 and 16 GB RAM. It serves as a 6 TB Windows Server NAS, and I've already used it to host Minecraft Java Edition and Palworld. Reusing the hardware kept costs down and gave me an actual Windows Server environment to administer. The tradeoffs are its two-core processor and limited expandability. It's my personal server, not an enterprise production environment.

01 / BUILTRepurposed Lenovo desktop hardware
02 / DEPLOYEDWindows Server 2022 and 6 TB NAS storage
03 / HOSTEDMinecraft Java Edition server
04 / HOSTEDPalworld server
01 / Requirements

What I Built and Used

My 6 TB Windows Server NAS is built and in use for network storage. I've also hosted Minecraft Java Edition and Palworld servers on the same hardware. I prefer getting useful work out of equipment I already own over chasing benchmark scores.

  • Network storage: working 6 TB NAS accessible on my home network.
  • Minecraft Java Edition: server hosting completed using this Windows Server machine.
  • Palworld: server hosting completed on the same system.
  • Administration: a real Windows Server environment for managing storage and game-server workloads.
  • Data safety: backup and recovery planning remain important operational practices; mirrored storage alone is not a backup.
02 / Platform Choice

Why This Motherboard and System?

The Lenovo platform was selected primarily because it was already available: a low-cost way to reuse working hardware rather than start with an expensive new enclosure and power supply. A key selection criterion is its Wake-on-LAN capability, useful for waking a server on demand instead of leaving it powered on unnecessarily.

Important distinction: Wake-on-LAN must still be verified on this exact firmware, Ethernet adapter, and power-state configuration. A supported checkbox is not proof a remote magic packet successfully wakes the system.

  • Inspect available 3.5-inch bays, SATA ports, PSU connectors, and airflow before expanding drives.
  • Check BIOS/UEFI options for PCIe / network wake and the NIC driver’s Wake on Magic Packet support.
  • Validate wired sleep/shutdown wake behavior separately; S5 wake support varies by platform.
  • Measure idle electricity draw and compare against the cost of keeping the host running.
03 / Example Topology

Plan Addressing Before Changing the Network

This illustrative private subnet is not a disclosure of the household’s real IP addressing. It deliberately shows one gateway, one fixed server address, a reserved static segment, and a non-overlapping DHCP pool.

ComponentExample ValueRationale
Subnet192.168.50.0/24Isolated documentation example
Router / gateway192.168.50.1Default route to the Internet
Windows Server192.168.50.10Manual/static address outside DHCP scope
Infrastructure / reservations192.168.50.20–49Printers and predictable hosts
DHCP scope192.168.50.100–199Dynamic client leases
DNS zonelab.example.testDocumentation-only namespace

Keep the router’s DHCP service enabled for household clients until the replacement server and leases have been tested in an isolated network. Only one authoritative, non-overlapping DHCP plan should serve a given subnet. If the lab is turned off, household clients still need a working DHCP/DNS fallback.

04 / Installation

Windows Server 2022 Deployment and Reference Checklist

Windows Server 2022 is already installed and has been used for NAS storage and game hosting. This checklist documents common installation and administration considerations; it is not a list of work still required to make my NAS functional. DNS and DHCP are optional examples, not claimed running roles.

  1. Back up existing data, confirm driver compatibility and licensing, then create bootable installation media for a supported Windows Server release.
  2. Install Windows Server onto the SSD, keeping storage disks separate where possible; choose Desktop Experience for easier initial labs or Server Core for a leaner deployment.
  3. Set an administrator credential, apply updates, configure the local firewall, confirm Ethernet connectivity, and rename the host internally (without publishing the hostname).
  4. Configure a fixed IPv4 address, gateway and DNS plan before adding DNS or DHCP roles.
  5. Use Server Manager or elevated PowerShell to install File Server, DNS, and DHCP roles only as required by the selected scope.
# Reference only. These are not all claimed as installed roles.
Install-WindowsFeature -Name File-Services,FS-FileServer,DNS,DHCP -IncludeManagementTools
Get-WindowsFeature File-Services,FS-FileServer,DNS,DHCP
Get-NetAdapter | Format-Table Name,Status,LinkSpeed
Get-NetIPConfiguration

Windows Server 2022 is installed on the NAS. The role-installation commands are reference examples, not a live configuration export; use an appropriately licensed Windows Server installation.

05 / Fixed Address

Assign the Server a Static IPv4 Address

Infrastructure services must be reachable consistently. A statically configured server address avoids dependence on DHCP during startup and reduces ambiguity about which machine hosts DNS or SMB shares.

# Example only: replace adapter and addresses with your actual lab plan.
New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 192.168.50.10 -PrefixLength 24 -DefaultGateway 192.168.50.1
Set-DnsClientServerAddress -InterfaceAlias "Ethernet" -ServerAddresses 127.0.0.1
Get-NetIPAddress -InterfaceAlias "Ethernet" -AddressFamily IPv4

Use Get-NetAdapter to check the actual interface alias. Plan the change locally: applying an incorrect remote IP may immediately disconnect a remote administration session. This example presumes DNS will ultimately run locally; verify resolution and upstream forwarders once the DNS role is active.

06 / Name Resolution

Configure DNS Zones and Forwarders

DNS maps names to addresses. A forward lookup zone provides readable lab names for local resources, while forwarders send queries for external domains upstream. An Active Directory domain would require its own AD-integrated DNS design; this example is a standalone test zone, not a completed domain deployment.

Add-DnsServerPrimaryZone -Name "lab.example.test" -ZoneFile "lab.example.test.dns"
Add-DnsServerResourceRecordA -ZoneName "lab.example.test" -Name "nas" -IPv4Address "192.168.50.10"
Set-DnsServerForwarder -IPAddress 1.1.1.1,9.9.9.9
Resolve-DnsName nas.lab.example.test -Server 192.168.50.10

Confirm local A-record resolution from a separate client, then verify unrelated public names still resolve. Configure DNS recursion and firewall rules only for intended internal clients; do not expose this resolver to the public Internet.

07 / Client Addressing

Configure DHCP Carefully

DHCP automatically distributes IP leases and can advertise the gateway and DNS resolver. This setup is potentially disruptive if performed on the existing household LAN without coordination.

  1. Start on a physically or logically isolated test network; audit the router’s existing pool.
  2. Install DHCP, define a non-overlapping IPv4 scope, and set option 003 (router), 006 (DNS), and 015 (DNS domain).
  3. In an Active Directory domain, authorize the server in AD DS. A workgroup lab does not use that authorization step.
  4. Activate only after confirming there is no second competing DHCP service for the same clients.
  5. Renew a lab client’s lease, inspect gateway/DNS options, test Internet access and local name resolution.
# First disable DHCP on the router if this server will become authoritative.
# Do not run while another DHCP server leases the same subnet.
Add-DhcpServerv4Scope -Name "Lab Clients" -StartRange 192.168.50.100 -EndRange 192.168.50.199 -SubnetMask 255.255.255.0 -State InActive
Set-DhcpServerv4OptionValue -ScopeId 192.168.50.0 -Router 192.168.50.1 -DnsServer 192.168.50.10 -DnsDomain "lab.example.test"
Get-DhcpServerv4Scope
# Activate only after isolation / conflict checks.
Set-DhcpServerv4Scope -ScopeId 192.168.50.0 -State Active

The sample scope is created inactive first. Do not copy and run the activation command on your live home network until the previous DHCP service is disabled or the test network is isolated.

08 / Storage

Working 6 TB Network Storage

The 6 TB NAS storage is already installed and working on my network. These notes cover ongoing storage administration, access control, and recovery practices, not steps needed to finish the NAS. Windows file sharing and NTFS permissions should be managed together, with access limited to the people who need it.

  • For any future storage changes, assess standalone disks, Storage Spaces resiliency, or a mirror according to the hardware and required usable capacity.
  • Use an offline or independent backup destination and test file restoration before trusting important data to the system.
  • Enable SMB signing as appropriate, maintain OS updates, and do not expose SMB ports to the Internet.
  • Measure transfer speeds using wired connections and capture disk/CPU utilization during large transfers.

Further portfolio evidence: sanitized screenshots of existing storage access, drive-health output, share permissions, and a documented restore test would show more of the administration work without exposing private files or network details.

09 / Operations

Wake-on-LAN, Power and Performance

Wake-on-LAN uses a magic packet directed at the target NIC’s MAC address. The benefit is potential energy savings when the NAS is used intermittently, but idle-vs-sleep savings must be weighed against availability of game servers and DNS/DHCP.

  • Enable relevant BIOS/UEFI wake options; disable any low-power mode that suppresses standby NIC power if required by the hardware.
  • Configure the Ethernet driver’s magic-packet wake setting; test from another LAN computer while monitoring link state.
  • Validate wake from sleep and full shutdown separately, record failures, and avoid promising S5 wake until tested.
  • Architectural tradeoff: if DNS/DHCP runs on a sleeping server, clients may lose renewals/name resolution. Keep essential network services on an always-on device or run the server continuously.
10 / Acceptance Tests

Operational Work and Reference Checks

The NAS is deployed with working storage, and I've hosted Minecraft Java Edition and Palworld on it. These generic commands show ways to document connectivity and optional Windows Server roles; they are not a prerequisite for the NAS or game-hosting deployments I've already completed.

ipconfig /all
nslookup nas.lab.example.test 192.168.50.10
ping 192.168.50.10
Test-NetConnection 192.168.50.10 -Port 445
Get-SmbSession
Get-DhcpServerv4Lease -ScopeId 192.168.50.0

For the optional DNS/DHCP examples, I would check client lease behavior, name resolution, and service isolation. For ongoing NAS maintenance, useful evidence includes permission checks, restore tests, and storage monitoring. None of those optional examples changes the fact that the NAS and both game-server workloads have already been used successfully.

Reference Documentation: Microsoft Learn: Install and Configure DHCP · Microsoft Learn: Install and Configure DNS · Microsoft Learn: DHCP Scope Design. The 6 TB NAS is operational and has already hosted Minecraft Java Edition and Palworld. The DNS/DHCP and Wake-on-LAN examples above are reference material and are not claims that those optional services are enabled.
Upcoming Hands-On Portfolio

Technical Demos

I'm putting together demos using my own equipment. Each one will show the setup, the problem, what I tested, and the result.

01 · Networking · Demo Planned

Home Network and Connectivity

Netgear R6400v2 router, multiple wired devices, and Windows network shares.

  • Map physical and logical connections
  • Show connectivity and throughput tests
  • Explain network-share troubleshooting
02 · Workstation · Demo Planned

Desktop Workstation and Hardware

MSI MAG X670E TOMAHAWK WIFI workstation, multi-display configuration, and dedicated PCIe Ethernet adapter.

  • Document physical components and layout
  • Explain fault isolation and hardware choices
  • Show adapter and driver validation
03 · Storage · System Deployed

Deployed NAS and Storage Administration

My existing 6 TB Windows Server NAS is already serving files and has hosted Minecraft Java Edition and Palworld. This demo would document that working setup.

  • Show the deployed storage hardware and network access
  • Explain hardware reuse and drive layout
  • Document drive-health and backup-recovery checks
04 · Diagnostics · Demo Planned

Windows Diagnostics and Scripting

Repeatable local PowerShell diagnostics using personal Windows systems.

  • Collect troubleshooting information
  • Investigate connectivity problems
  • Share sanitized scripts and results
05 · Linux · Demo Planned

Ubuntu Streaming and Portable Systems

Two Ubuntu installations on repurposed and portable hardware.

  • Demonstrate basic Linux administration and diagnostics
  • Document streaming services and configuration after validation
  • Show sanitized logs and repeatable troubleshooting methods
Evidence-First: Demo recordings and additional test evidence are separate from the systems themselves. The 6 TB NAS and Minecraft Java Edition/Palworld hosting are completed work; other demos remain labeled as planned until documented. No private credentials, employer data, network addresses, device serial numbers, or confidential configurations will be published.
At a Glance or In Full

Resume and Qualifications

A searchable overview of my professional experience and credentials, based on my current resume. Download the one-page version for your records.

Professional Summary

IT support and operations professional with 7+ years of experience supporting enterprise Microsoft environments, identity and access management, and high-volume end-user operations. Experienced in technical escalations, team leadership, onboarding, training, reporting, and SLA-focused service delivery.

Professional Experience

Genpact · July 2026 – Present

Technical Support Analyst II (Acting Team Lead)

  • Daily IT operations, user onboarding, access provisioning, support, reporting, and phone coverage
  • New-hire account readiness, system setup, and troubleshooting
  • Training technicians on support processes and escalation workflows
  • Cross-team coordination to resolve provisioning and access issues

GreenSky LLC · March 2019 – June 2026

Technical Support Analyst II (Acting Team Lead)

  • Helped lead a team of approximately ten analysts supporting more than 1,600 enterprise users
  • Primary escalation support across Microsoft 365, identity, authentication, endpoints, and hardware/software issues
  • 50–100 tickets managed weekly, frequently representing about 25% of team workload
  • Technician onboarding, SOPs, knowledge articles, vendor coordination, and project rollouts

Core Competencies

Microsoft 365, Entra ID, Active Directory, Exchange, Conditional Access, MFA, FIDO2/YubiKey, Temporary Access Pass, Windows 365 / Cloud PC, Intune, SCCM, VPN, Jira, Microsoft Defender for Endpoint, Netskope, Rapid7, escalation management, SLA coordination, training, onboarding, operational reporting, and SOP development.

Education

Northern Kentucky University · 2024 – Present
Information Technology (Cybersecurity Track)

Certifications

  • CompTIA A+ (Hardware & Software)
  • Microsoft Office Certifications (Word, Excel, PowerPoint)
  • Business Writing Certification
Beyond the Resume

About Me and Technical Hobbies

Outside work, I spend plenty of time tinkering with PCs, Linux, home networking, and lava lamps. Figuring out why something broke and how to fix it is not part of the fun, it is the fun!

Featured Hobby Project

Lava Lamp Restoration and Custom Builds

I restore and modify lava lamps for fun. I've rewired bases, worked on the fluid and wax, resealed globes, and learned quite a bit about heat, buoyancy, and surface tension along the way.

  • Electrical Repair: rewiring lamp bases, identifying hot and neutral conductors, replacing cords, and checking socket safety.
  • Troubleshooting: diagnosing cloudiness, overheating, wax separation, bubble formation, and cap-sealing failures.
  • Chemistry and Flow: understanding master fluid, wax density, buoyancy, surfactants, viscosity, and how heat affects motion.
  • Documentation: keeping track of what changed, what improved, and what failed so the next iteration is better.

I'll add more photos, before-and-after examples, and notes as I keep working on them. Read the Detailed Restoration Case Study →

What It Demonstrates

What I Get Out of It

These are different kinds of problems, but I use the same troubleshooting habits I rely on at work.

  • Systematic Troubleshooting: isolating variables and testing changes one step at a time.
  • Comfort With Hardware: working hands-on with electrical components, mechanical assemblies, and repurposed equipment.
  • Knowledge Transfer: translating technical terminology into plain language and writing practical guides.
  • Resourcefulness: reusing affordable hardware and improving it instead of defaulting to expensive replacements.

Other Ongoing Interests: home networking, PC hardware, storage planning, Linux systems, retro gaming setups, and small-scale homelab work.

LAVA® Lamp FAQ · Lava Lab Creations Restoration Guide · Basic Cord and Plug Safety Reference

Hands-On Repair Case Study

Lava Lamp Restoration: Electrical, Thermal, and Fluid Systems

A collection of real restoration experiments involving failed wiring, fluid behavior, glass sealing, and custom lamp design. The aim is to document diagnostic reasoning rather than just show a finished object.

01 / ELECTRICAL REPAIR

Rewiring and Electrical Troubleshooting

I have repaired dozens of lamp bases with different connection methods:screw-terminal socket assembly, soldered assemblys, crimped assemblies, you name it! The work involved examining cord identification, identifying socket contacts, correcting conductors, insulating connections, and functional verification.

Terminology: line/hot conductor, neutral conductor, polarized lamp cord, Edison screw shell, center terminal, continuity, strain relief, mechanical termination, insulation and heat shrink.

Electrical principle: In properly polarized Edison-screw fixtures, the switched hot conductor goes to the recessed center contact and neutral to the threaded shell. A lamp lighting up does not alone prove correct polarity or mechanical safety.

Adding Dimmers for Heat Control: I also put my lava lamps on compatible dimmers so I can adjust the heat instead of relying on a bulb running at full power all the time. A small change can make the difference between sluggish wax and a lamp that is running too hot. I adjust one lamp at a time and watch how it behaves through a full warm-up cycle before making another change.

Dimmer Safety: The dimmer has to be rated for the bulb type and electrical load. It is a way to control heat, not a substitute for correct wiring, proper insulation, or using a bulb within the lamp's rated limits.

Safety: Unplug before opening or testing a fixture; inspect cords, insulation, strain relief, and socket ratings; verify de-energized state before handling. Do not rely on a switch being off. Replacement components and any modifications should be checked against applicable electrical requirements.

02 / FLUID CHEMISTRY

Master Fluid, Wax, and Surfactant Behavior

Lava motion depends on a temperature-driven density cycle. Wax heats, expands, becomes buoyant relative to the surrounding master fluid, rises, cools, then sinks. Surface tension and interactions with the glass influence blob shape and motion.

Terminology: master fluid (the continuous liquid phase), wax phase, buoyancy, density differential, thermal expansion, viscosity, surface tension, surfactant, wetting, adhesion, emulsion, and thermal cycling.

I experimented with distilled-water refills, fluid and wax colorants, surface-active additives, and repeated heat/cool cycles. The changes produced different blob counts and movement patterns, giving me a way to distinguish adjustment effects from thermal conditions.

Surfactant vs. Magic Surf: Manufacturer guidance distinguishes regular SURF (also used to coat clean glass) from Magic Surf (a fluid-only flow modifier intended for compatible modern wax). Adding more does not always improve flow; overdosing may produce microblobs or cloudiness. Compatibility depends on the wax formula.

03 / TROUBLESHOOTING

Diagnosing Unstable Flow

Symptom: weak motion. Evaluate warm-up state, lamp/bulb rating, room conditions, and whether the wax has reached operating temperature before changing the chemistry.

Symptom: too many tiny blobs or cloudy fluid. Consider excess surfactant or incompatible additives. I learned the value of changing one variable at a time, allowing equilibration, and recording the result. Lava Lab Creations recommends cooling and partially replacing master fluid with distilled water if surfactant limits were exceeded; the product's instructions and wax compatibility remain important.

Symptom: overheating. Rapid small droplets and unusual behavior can indicate a thermal problem. Switch off and let the lamp cool undisturbed rather than trying to fix hot glass.

Process: document the symptom → isolate electrical, thermal, or fluid causes → make a controlled adjustment → run a new thermal cycle → compare behavior.

04 / MECHANICAL RESTORATION

Resealing, Repainting, and Custom Design

My restorations included removing adhesive and old finishes, sanding and preparing lamp bases, experimenting with resealing bottle-style caps, and checking for leaks. One globe broke during an unsuccessful cap-fitting attempt, a useful lesson about glass fragility, force control, and choosing suitable tools.

After changing the technique, I successfully resealed four lamps. I also investigated a larger custom round-bottom borosilicate flask and stand concept, including stability, heating, and maintaining adequate clearances. This larger design remains a concept rather than a validated appliance.

Terminology: crimp seal, thermal expansion, heat cycling, glass stress, strain relief, convection, heat transfer, and mechanical tolerance.

Safety: Never heat a sealed vessel on a stove or microwave lamp wax; never apply uncontrolled force to glass or operate a cracked globe. Any custom heated electrical appliance requires appropriate temperature protection and electrical engineering validation before use.

Research and Technical References

Distinguishing firsthand project notes from external technical guidance:

LAVA® Lamp FAQ: buoyancy and operating principles · Lava Lab Creations: restoration and flow troubleshooting · Magic Surf: use and compatibility · iFixit: cord polarity and safety

Photos, measured temperatures, electrical test results, and comparison videos can be added as evidence when available; no measurements are invented here.

Let's Connect

Let's Make IT Work Better

I'm looking for IT support, operations, escalation, and team lead roles where I can dig into tough problems and help the people around me. I'm based in Northern Kentucky and open to opportunities around Greater Cincinnati.

One More Thing

Ticket Invaders

You made it to the bottom. Here's a little game about the one thing IT never runs out of: tickets. Try to clear the queue before it gets out of hand.

Resolved 0Missed 0 / 5Best 0Coffee Ready

The queue is filling up.

Move left and right, shoot the incoming tickets, and don't let five reach the bottom.

Keyboard: ← / → or A / D to move, Space to fire, Enter for coffee, P to pause

Just for fun. Everything runs in your browser. No sign-in, tracking, or high scores sent anywhere.