Work

Microsoft 365 & Identity Engineer

+15 years in IT. Microsoft 365 and identity engineer from Barcelona, Spain. I run the Microsoft 365 platform end to end, Entra ID, Exchange, SharePoint, Intune and Purview, for a multinational tenant, and automate what repeats.

Experience

  1. 2026 — Present

    Microsoft 365 & Identity Engineer

    Synlab Group

    Identity and collaboration for a multinational, multi-country tenant: Entra ID, licensing, Exchange Online and SharePoint. Automation in PowerShell, Microsoft Graph and Logic Apps.

  2. 2023 — 2026

    Workplace Technical Lead

    IESE Business School

    Led the Workplace team and the endpoint estate: Windows, macOS, iOS and Android in Intune, with enrollment profiles redesigned per device role (staff, classrooms, meeting rooms). Defender for Endpoint, CrowdStrike and Purview; the SOC-to-Workplace remediation process; vendors and licences. Part of achieving ISO 27001 certification in my first year, and of keeping it in the following ones.

  3. 2021 — 2023

    Modern Workplace & Microsoft Mobility Consultant

    Clevertask IT Solutions

    Modern-workplace deployments and identity integration for several enterprise clients; tier-2 support in regulated environments (Active Directory, Microsoft 365, Citrix, SCCM, XenMobile).

  4. 2017 — 2021

    L2 IT Technician & Asset Management Specialist

    Accenture, for Almirall

    Tier-2 support in a regulated pharmaceutical environment; CMDB and IT asset lifecycle, leading a small operational team; mobility and infrastructure projects.

What I look after

Microsoft 365 platforms I look afterMicrosoft 365 tenantone tenant · many countriesEntra IDusers · service principalsConditional Accessgroups · roles · PIMExchange Onlinemailboxes · roomsmail flow · rulesgroups · listsIntuneAutopilot · enrollmentcompliance · baselinesapps · remediationsAutomationPowerShell · GraphLogic Apps · runbooksscheduled reportsMicrosoft DefenderEndpoint · Office 365incidents · alertssecure scoreSharePoint · OneDrivesites · permissionsstorage · quotasexternal sharingActive Directoryon-premises · forestsEntra Connect syncprivileged groupsPurviewsensitivity labelsDLP · retentionaudit · eDiscovery

Day to day I look after the whole Microsoft 365 stack from its admin consoles: identity in Entra ID, mail in Exchange Online, devices in Intune, the automation that ties them together (PowerShell and Graph, Logic Apps, runbooks), files and sites in SharePoint and OneDrive, data protection in Purview, with on-premises Active Directory and Entra Connect underneath.

Anything I have to do twice becomes a script, filed under the platform it belongs to. The ones that are not specific to one tenant are published in the open: every script that changes state says so, and none does anything without -Execute.

Projects

Things I built and what came of them. Each has a short write-up.

All projects