Michael Lawrence

IT Systems & Automation Engineer

I run IT solo for a 100+ employee HIPAA-regulated healthcare organization - and I automate everything that gets done twice. M365 · Entra ID · Windows Server · PowerShell · Power Platform · Docker.

The short version

Numbers first - the case studies below show how.

100+employees supported, solo, across multiple locations
65 → 120headcount growth absorbed with zero added IT staff
HIPAAregulated environment - GPO, MFA, least privilege by design
~45 minzero-touch machine builds, down from half a day of manual setup

Case studies

Real systems, running in production. Sanitized source and full write-ups on GitHub.

Onboarding errors eliminated

Identity automation: attributes in, access out

Manual account creation and hand-managed security groups don't survive 85% headcount growth - every typo became a day-one access problem.

  • One PowerShell command creates the account, stamps HR attributes, provisions the mailbox
  • Entra ID dynamic membership rules derive every security group from those attributes
  • Transfers are one attribute edit; offboarding drops all access instantly
ad-onboarding-automation · entra-dynamic-groups
HR intakename · dept · role New-Employee.ps1account + attributes Dynamic group rulesdept / role / location SharePoint · shares · apps · licenses
Evaluations run themselves

Power Platform: employee evaluation system

Annual evaluations lived on paper and memory - missed anniversaries, wrong forms, no audit trail.

  • Model-driven Power App on Dataverse; anniversary flows key off employeeHireDate in Entra
  • Role-based evaluation tracks driven by a mapping table HR edits - config as data, not code
  • Send / first-open / completion timestamps on every record; PDF export to HR
  • Packaged with environment variables so the whole solution redeploys to a new tenant from a settings file
  • Promoted to production through a staged Dev → Sandbox → Production cutover with a validated rollback path
powerapps-employee-evaluations · powerplatform-alm
Entra IDemployeeHireDate Daily flowanniversary scan Dataverseeval records Model-driven approle-scoped forms notifications · escalations · PDF → HR audit trail: sent · opened · completed
A staging environment that didn't exist

Hyper-V lab: a Server 2025 domain that mirrors production

There's no test environment at work, and "try it in production" isn't a plan. So I built one - 5 VMs on a host I assembled myself (Ryzen 7 7700X, 32 GB DDR5).

  • Two virtual switches on separate NICs - one for internet-facing VMs, one for an isolated lab segment, so the lab's DNS and PXE/DHCP can never collide with the home network
  • Role-separated: domain controller (AD DS / DNS / DHCP), print + database + directory-sync server, RDS host, MDT imaging server, and a domain-joined Windows 11 client to verify against
  • RemoteApp publishing the clinical EMR over a certificate issued by an internal CA - no per-workstation client installs, plus a fallback access path
  • Checkpoints throughout, so a change can be applied, observed, and rolled back in seconds
  • Catches GPO scoping errors, imaging task-sequence failures, and print-driver behavior before they reach real users
hyperv-ad-lab
Home gatewayinternet WAN-Switchpatching / updates LAN-Switchisolated · DNS · PXE DC - Server 2025AD DS · DNS · DHCP Print / DB / Synchybrid identity RDS - RemoteAppinternal CA cert 5 VMs · self-built host · mirrors production OU structure
Recovered from real disk failure

Homelab: self-healing media infrastructure

A multi-container Docker platform serving Plex and Jellyfin across 13 drives. Then Windows dynamic disks failed and drive letters reshuffled under the whole stack.

  • Diagnosed it as a pointer problem, not data loss: the large majority of 200+ dead library entries recovered with zero data movement
  • Edited the Plex library DB directly when the API silently no-op'd; re-mounted and re-rooted every service
  • Health check every 30 min now auto-restarts stopped containers and watches drive mounts, space, and server reachability
  • Dedup tooling freed ~379 GB, with runtime-delta guards so alternate cuts never get deleted as "duplicates"
homelab-media-stack (incl. the full disaster-recovery write-up)
Docker hostone concern per container Support servicesstats · requests · live TV 13 NTFS drivesper-drive mounts Plex · Jellyfintunnel-only remote access Health check · 30 minauto-restart stopped containersper-drive space thresholdsserver reachabilityrolling log + state JSON
Security awareness, measured

In-house phishing simulation program

Awareness training needs evidence, and commercial phishing-sim platforms are overkill for a 100-person org.

  • Power Automate flows randomly target rolling cohorts with tracked simulation emails
  • Clicks and reports-to-IT logged to SharePoint - report rate is the culture metric
  • Department rollups for leadership; individual results drive follow-up training
  • Zero licensing cost - built entirely on tooling the org already owned
powerautomate-phishing-sim
Scheduled flowcampaign kickoff Random targetsexcl. recent cohorts Lure emailtracked link SharePoint campaign logclick rate ↓ · report rate ↑ leadership dashboard · targeted training
Founder · in staging ahead of production

AutomateComply: compliance automation as a product

Small businesses on Microsoft 365 need the same HR and security-compliance workflows a big company has, without a big company's IT team. So I built the systems I run at work into something reproducible they can drop into their own tenant.

  • Reusable Power Automate flows and Power Apps: phishing-awareness training, performance reviews, time-off and overtime approvals
  • Packaged to deploy into a client's own M365 tenant with environment variables, not rebuilds
  • Full small-business cloud build behind it: M365 tenant, authenticated outbound email (SPF/DKIM/DMARC), Bookings scheduling, marketing site on Cloudflare Pages with DNS and SSL
  • Initial setup complete; currently in staging ahead of production, not yet live with clients
automatecomply.com
Reusable templatesflows + Power Apps Client M365 tenantenv vars, no rebuild Compliance workflows livephishing · reviews · time-off · overtime compliant without a large IT team M365 tenant ·SPF/DKIM/DMARC

Stack

Daily drivers, in production.

Microsoft 365Entra IDActive Directory Exchange OnlineWindows ServerHyper-V IntunePowerShellPower Apps Power AutomateDataverseMDT GPOSharePointDocker RDS / RemoteAppAD Certificate ServicesPXE / WDS n8nTCP/IP · DNS · DHCP · VPNDuo MFA Power Platform ALMSPF · DKIM · DMARCathenahealth MEL

About

I'm the sole IT operation for a HIPAA-regulated healthcare organization in New Jersey - escalation support, identity, infrastructure, security, and everything between, across multiple locations. The through-line in my work: if a process gets done twice, it gets automated - and the automation gets documented, monitored, and made repeatable.

I build and validate automation in partnership with AI tools, with every AI-drafted component verified before it reaches production. It is a force multiplier, not an autopilot.

B.A. in Information Technology & Informatics, Rutgers University. TestOut Security Pro (certified, 2024). Rutgers Cybersecurity Bootcamp (2023). athenahealth EMR workflow scripting and customization (MEL). Currently studying for the CCNA.

Off hours I run the labs above on hardware I built myself, write n8n pipelines, and keep a Letterboxd watchlist longer than I will ever finish.