Skip to content
View guyleonchen's full-sized avatar
  • Sydney

Block or report guyleonchen

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Guyleonchen/README.md

Guy Cheneval

IT Support | Microsoft 365 | Endpoint Management | Identity & Security

Sydney-based IT support professional with hands-on experience supporting Windows, macOS and iPadOS environments and administering Microsoft 365, Active Directory, Microsoft Entra ID and Teams Phone. I am progressing toward Microsoft 365, endpoint and identity administration roles, combining practical workplace experience with independently built Intune, Conditional Access, PIM and endpoint-security labs.

LinkedIn · Email · Sydney, Australia


Current Technical Experience

My workplace experience includes:

  • Provide Level 1 and Level 2 technical support across Windows, macOS and iPadOS environments, resolving hardware, software, account, printing, network and classroom-technology issues.
  • Administer Microsoft 365 services, including user access, shared mailboxes, distribution groups, Outlook, Teams, OneDrive and SharePoint support.
  • Perform identity and access administration across Active Directory and Microsoft Entra ID, including account management, password resets, security-group membership and access troubleshooting.
  • Diagnose Adobe licensing, application-access and printing issues by comparing user accounts and Active Directory group memberships, then assigning the appropriate licensing or printer-access groups.
  • Administer Microsoft Teams Phone configuration, including telephone-number assignments, tenant dial plans and voice-routing policies for domestic and external calling.
  • Investigate email-delivery issues using Exchange Online message trace, including analysing a bulk distribution of approximately 900 messages and identifying unsuccessful deliveries.
  • Prepare and deploy Windows devices through imaging, Active Directory domain joining, application installation and post-deployment validation.
  • Enrol and support Apple devices through Jamf, resolving configuration-profile, certificate, Keychain, Wi-Fi and application issues.
  • Troubleshoot network connectivity using testing equipment, VLAN and switch-port information, patch-panel tracing and structured cabling.
  • Monitor and investigate security alerts using Microsoft Defender, Proofpoint, escalating confirmed or suspicious activity to the appropriate teams.
  • Built a Microsoft Power Automate workflow that captured Microsoft Forms submissions, mapped the submitted information and automatically created help-desk tickets, streamlining the walk-in support process.
  • Document technical procedures and troubleshooting outcomes as reusable knowledge-base articles, support guides and operational checklists covering device imaging, Microsoft Teams administration, networking, Outlook and Apple device support.

Workplace experience and personal lab work are presented separately. The projects below were built in an independent lab environment and do not contain employer information.

Core Skills

Area Technologies and capabilities Experience basis
Microsoft 365 Microsoft 365 administration and support, Exchange Online message trace, Teams administration, Teams Phone, Outlook, OneDrive and SharePoint Workplace
Identity and access Active Directory and Microsoft Entra ID account administration, security-group membership and access troubleshooting; MFA, Conditional Access, RBAC and PIM Workplace administration + independent labs
Endpoint management Windows deployment and Jamf support; Microsoft Intune enrolment, compliance policies, Win32 application deployment, Autopilot, BYOD and MAM Workplace support + independent labs
Endpoint security Microsoft Defender alert investigation; Intune-managed Attack Surface Reduction and Defender Firewall policies with security validation Workplace investigation + independent labs
Automation and scripting Microsoft Power Automate workflow development; foundational PowerShell and Microsoft Teams PowerShell Workplace automation + foundational scripting
Technical support Windows, macOS and iPadOS support, Jamf, ticketing, Event Viewer, network troubleshooting and technical documentation Workplace

Featured Microsoft Lab Projects

Zero Trust Local Administrator Access with Entra PIM and Intune

Designed and validated a least-privilege solution that provides temporary local administrator access only on approved devices. The design uses PIM-eligible group membership, MFA, approval, justification, a one-hour activation window and an Intune Account Protection policy.

View project repository

Microsoft Entra PIM Just-in-Time Administration

Configured eligible rather than permanent Global Administrator access. Required MFA, justification and approval; applied time-bound activation; enabled notifications; and validated the full request, approval, activation and automatic-expiry lifecycle.

View project repository

Zero Trust BYOD with MAM and Conditional Access

Protected organisational data in Outlook on an unmanaged iPhone using Intune App Protection Policies and Conditional Access. Validated managed-app access, PIN enforcement, browser blocking and restrictions on copy/paste and data transfer.

View project repository

Conditional Access: Location and Session Controls

Built Microsoft Entra Conditional Access policies for location-based access, MFA and sign-in frequency. Tested access from a US VPN endpoint and verified the result using Entra sign-in logs and policy evaluation.

View project repository

Microsoft Intune Win32 Application Deployment

Packaged Google Chrome Enterprise as an .intunewin application, configured silent installation, requirements and MSI detection rules, assigned it to managed devices and validated the deployment through Intune reporting and endpoint checks.

View project repository

Microsoft Defender Attack Surface Reduction

Configured ASR rules through Intune Endpoint Security to reduce credential theft and Office-based attack paths. Verified policy deployment using PowerShell and Defender telemetry, then tested credential-dumping protection using Sysinternals ProcDump.

View project repository


Additional Lab Coverage

  • Microsoft 365 tenant configuration, user creation, licensing, MFA and least-privilege roles
  • Intune enrolment and Windows compliance policies
  • Windows Autopilot and Windows Hello for Business
  • Active Directory Domain Services, DNS, Group Policy and user lifecycle management
  • Microsoft Defender Firewall configuration
  • Intune compliance integrated with Conditional Access
  • Ticketing, Event Viewer, networking and remote-support scenarios

Browse my GitHub repositories

Certifications and Development

  • CompTIA Security+ (SY0-701)
  • Google Cybersecurity Professional Certificate
  • Cisco Junior Cybersecurity Analyst Career Path
  • Currently developing toward Microsoft Certified: Endpoint Administrator Associate (MD-102)
  • Planned next focus: Microsoft Identity and Access Administrator (SC-300)

Career Direction

I am building on my IT support foundation toward Microsoft 365 and endpoint administration roles, with a longer-term focus on identity and access management. I am developing deeper capability across Exchange Online, Microsoft Teams, Entra ID, Intune, Conditional Access and automation through workplace experience and independent labs, with an emphasis on secure administration, least privilege and clear technical documentation.

Pinned Loading

  1. Entra-PIM-Intune-Local-Admin-Access Entra-PIM-Intune-Local-Admin-Access Public

    Zero Trust local administrator access using Microsoft Entra PIM and Intune Account Protection with approval, device scoping and automatic expiry.

  2. Entra-PIM-Just-in-Time-Administration Entra-PIM-Just-in-Time-Administration Public

    Microsoft Entra PIM lab replacing permanent Global Administrator access with eligible, approved, time-bound activation and automatic expiry.

  3. Zero-Trust-BYOD-MAM-Conditional-Access Zero-Trust-BYOD-MAM-Conditional-Access Public

    Zero Trust BYOD lab protecting Microsoft 365 data on unmanaged iOS devices using Intune App Protection and Entra Conditional Access.

  4. Conditional-Access-Location-Session-Control Conditional-Access-Location-Session-Control Public

    Microsoft Entra Conditional Access lab enforcing location restrictions, MFA and session reauthentication with VPN and sign-in-log validation.

  5. Intune-Win32-Application-Deployment Intune-Win32-Application-Deployment Public

    End-to-end Win32 application packaging and silent deployment through Microsoft Intune, including requirements, detection rules and reporting.

  6. Intune-Defender-Attack-Surface-Reduction Intune-Defender-Attack-Surface-Reduction Public

    Microsoft Defender Attack Surface Reduction deployment through Intune, with PowerShell, Defender telemetry and credential-theft validation.