matt-taylor.tech
← Back to experience

IT role

IT Manager, then IT Director · National food brokerage

Oct 2022 to Present · Charlotte, NC · Hybrid

Standardization has been one intentional program since I joined. The company was assembled from regional businesses with their own laptops, networks, phone systems, vendors, support paths, and operating habits. I own the technology standards and the hands-on platform moving those regions toward one operating model across identity, Dell business endpoints, Meraki and Aruba office networks, Teams Phone, Freshservice, vendors, documentation, and acquisition integration.

Hired as IT Manager in October 2022 and promoted to IT Director in May 2024. I own strategy, budget, vendor sourcing, the roadmap, and acquisition integration, while continuing to write the scripts, draw the architecture, and run the migrations. The direction is company-wide, but adoption still means working through the resistance that comes when selling owners and regional teams give up familiar systems and local technology control. Less variation means fewer support paths, less technician training, easier troubleshooting, more reliable onboarding, and a stable base for automation and repeatable acquisitions.

Responsibilities

  • Technology standards and operating model across nine regional estates: Dell business laptops, shared identity and endpoint policy, Meraki and Aruba office networks, Teams Phone, Freshservice, MTS Office MFP service, common vendors, documentation, and an acquisition landing zone
  • Hybrid Azure + Microsoft 365 architecture and administration across 80+ sites (tenant-wide): 1,026 employees, and roughly 4,800 total directory identities once external B2B guests are counted; network, endpoint, and telephony across the 51 offices under internal IT
  • Internal automation estate: four git-tracked PowerShell and Python script libraries (Microsoft 365 administration, Intune fleet, endpoint operations, finance data processing), used for monthly compliance reviews and day-to-day operations
  • Full user lifecycle automation (joiner, mover, leaver): HR submissions flow through Power Apps and Power Automate into Entra ID, normalizing records from three upstream HR platforms, with IT verifying and approving rather than performing the steps
  • Technical escalation point for teams beyond IT: the BI team on Fabric, semantic models, and row-level security; the data team on Snowflake SQL and query optimization; and Power Platform developers building AI-assisted apps
  • Enterprise data platform: Microsoft Fabric F64 capacity and Power BI workspace governance, row-level security on customer-facing datasets, external sharing with food-manufacturer partners, and a Snowflake reporting environment
  • ITIL service management on Freshservice: incident, problem, change, request, asset, knowledge, and service catalog
  • Identity and endpoint security: Conditional Access, Defender for Endpoint/Identity/Cloud Apps, Intune, Purview, PIM; external B2B guest governance and lifecycle review for several hundred active partner identities
  • Cisco Meraki firewall estate and site-to-site VPN topology across the internally supported offices, on standardized Meraki MX plus HPE Aruba Instant On switching and Wi-Fi
  • Company telephony on Microsoft Teams Phone with SBC-based PSTN connectivity, including number porting through acquisitions and office relocations
  • Multi-site Remote Desktop Services platform (dual session-host collections, HTML5 fallback for remote contractors) hosting the line-of-business accounting application, with automated TLS certificate lifecycle management
  • M&A IT integration for acquired companies: tenant discovery, migration, coexistence patterns, and cutover
  • Enterprise AI program: company-wide AI policy and governance, GitHub Copilot Pro+ and Claude for Teams rollouts, Copilot Studio agent builds, and the admin configuration kept under version control
  • Internal documentation and knowledge management: a 13-domain IT documentation library generated from live system introspection, an operations runbook library, and the Freshservice knowledge base
  • IT cost allocation across regional P&Ls; vendor management, budgeting, and board-level strategy presentation

Selected systems and tools

A three-person team supporting 850 users across 51 offices

AI-augmented IT operations platform

Internal platform tying the IT team's source systems (Freshservice, Microsoft Graph, ScreenConnect, Meraki, Bitdefender, Action1) into one Supabase Postgres store. Governed Cowork plugins for the team plus a conversational @claude ticket-note agent: whole-ticket reasoning, a Haiku→Sonnet→Opus confidence cascade, confirm-gated actions. Live in production.

PythonSupabaseAzure FunctionsMicrosoft Graph
Read write-up →

Five systems, one governed connector

IT Ops MCP server

A Model Context Protocol server exposing Freshservice, ScreenConnect, Meraki, Dell warranty, and Microsoft Graph to Claude as one connector. Read-heavy, with governed writes whose trust boundary sits at the identity layer, so every action is scoped and attributed to the individual technician rather than a shared account.

PythonFastMCPAzure Container AppsEntra OAuth (OBO)
Read write-up →

Documentation generated from live systems, not by hand

IT documentation library, generated from live systems

Thirteen domains covering identity, cloud, network, servers, ITSM, line-of-business applications, security, procedures, and standards. Generated from live introspection through the MCP server, then exposed back to the ticket agent as its standards source.

PythonMCP serverMicrosoft GraphAzure Cost Management
Read write-up →

The accounting platform, delivered to 850 users

Multi-site Remote Desktop Services platform

Split-role deployment with a DMZ-isolated gateway and two session-host collections at the primary site, one dedicated to the accounting line-of-business app, plus a regional single-server deployment with an HTML5 fallback for contractors on networks that block persistent RDP tunnels. TLS auto-renews via Let's Encrypt and Cloudflare DNS-01.

Windows Server 2022Remote Desktop ServicesRD Gateway / Broker / Web Access / LicensingCertify The Web
Read write-up →

Monthly compliance reviews, automated across the tenant

Microsoft 365 PowerShell Admin Library

PowerShell library for monthly compliance reviews. Licensing, mailbox sizing, external forwarding, audit logs, MFA status, privileged roles, Conditional Access inventory, Defender reporting, Cloud App Security, Power Platform DLP, and more.

PowerShellMicrosoft GraphExchange OnlineAzure AD / Entra ID
Read write-up →

The documented baseline every policy and automation builds on

Microsoft 365 tenant architecture and governance

The documented reference layer every identity, security, and automation decision builds on: Entra ID identity governance, Conditional Access policy design, app and SaaS integration inventory, a SKU-mapped licensing model, and workload configuration across Exchange Online, Teams, SharePoint, and OneDrive.

Microsoft Entra IDConditional AccessPrivileged Identity ManagementMicrosoft 365
Read write-up →
Enterprise browser extension for a vendor portal

Edge/Chrome MV3 extension automating a monthly irreversible bulk-email process in a partner's legacy contract portal. Runs entirely in the operator's authenticated session, so no credentials are stored or relayed. Dry-run and supervised-batch guardrails throughout, distributed as a signed .crx force-installed through Intune.

Intune fleet management and proactive remediations

Endpoint fleet automation across 51 offices: scheduled proactive remediations, app packaging, batch antivirus removal, per-division serial-based device renaming, and winget and Chocolatey update orchestration.

Client Services activity report (serverless)

Monthly Microsoft 365 activity report (email, Teams, SharePoint, OneDrive) for Client Services and Reconciliation staff, migrated from an on-prem scheduled task to a serverless Azure Automation runbook. Authenticates with a system-assigned managed identity via Microsoft Graph: no server, no certificates, no stored secrets. Scoping the Mail.Send permission to one mailbox is a tracked open item.

Client Manager distribution list automation

CRM nightly data drives two things: Exchange Online distribution lists and the Entra ID security groups gating Microsoft Fabric workspace access. Rebuilt off an on-prem scheduled task onto an Azure Automation runbook on a managed identity, closing a stored-credential dependency and an unsafe parser found in a fleet-wide automation audit.

Service catalog and onboarding/offboarding automation

Structured service-catalog items with forms, approvals, and routing. HR Onboarding Teams App + Power Automate flows propagating new-hire records to Freshservice, the MSP, and the CRM. Provisioning time compressed from hours to minutes across the company's full onboarding and offboarding volume.

HRIS integration via Entra ID SCIM

SCIM-based integration via the Microsoft Entra SCIM connector, making a centralized HRIS the system of record for lifecycle events already automated across three upstream HR platforms. In UAT.

Employee SMS broadcast platform

MS Forms + Power Automate + Microsoft Graph + Twilio with Teams approval routing. Dynamic Entra ID group targeting; Twilio toll-free A2P compliant. Costs next to nothing per company-wide blast.

Cross-platform data sync

Snowflake-native Python stored procedure: 15 extension attributes, manager resolution, MERGE for incremental updates, soft-delete tracking. Runs entirely inside Snowflake via EXTERNAL ACCESS INTEGRATION, with nothing to host or schedule. Same pattern extended to CRM-driven distribution lists and the HRIS over SCIM.

HPSCAT vendor data ingestion pipeline

PowerShell and Graph pipeline replacing manual monthly manufacturer reporting. Static-IP whitelisted, with single-vendor, multi-vendor, date-range, and backfill modes. Re-hosted under a domain service account with DPAPI-encrypted credentials during a fleet-wide hardening pass.

Freshservice reporting infrastructure

Power BI connected directly to the Freshservice REST API, published to a workspace with scheduled refresh. No intermediate warehouse and no pipeline to operate. Years in continuous service; workspace later moved onto the Fabric F64 capacity.

M&A IT Integration Toolkit

Reusable cross-tenant migration toolkit with PowerShell runners for tenant discovery, mailbox + OneDrive migration, SharePoint, and device export. Operating playbook generated from a Node.js + docx builder, backed by a full task-level work inventory. Five completed acquisitions.

Security operations and incident response

A sustained account-compromise caseload run to a documented procedure: containment, Unified Audit Log forensics to establish scope of access, remediation, then structured communication. Standing activity-audit discipline alongside it. Platform control stack across Defender XDR, risk-based Conditional Access, PIM, and Windows LAPS. Point security tools consolidated into the platform layer on a metrics-backed case.

6 more projects from this role →

Programs and governance

Enterprise AI rollout, policy, and governance

Own the company-wide AI program across roughly 1,000 employees: a three-tier governance framework (company AI policy, development policy, developer handbook and repo template) plus a managed developer platform, wired into the existing identity and information-protection stack.

IT operating-model standardization

The defining technology program: turning nine separately operated regional estates into one operating model across identity, Dell endpoints, Meraki and Aruba office networks, Teams Phone, Freshservice, vendors, documentation, and acquisition integration. A national-scale continuation of the standardization model first built across three offices and brands.

Dependency-sequenced IT roadmap

Nine single-topic initiative documents plus a sequencing README ordering them by what blocks what, each citing live inventories and ratios rather than assertion. Grown out of an annual State of IT assessment whose reconciliation names what didn't move as clearly as what did. Docs-as-code applied at the planning layer.

Support channel centralization on Freshservice

Heading a program to bring every support team (CRM, application, mobile app, data, and IT) onto one Freshservice ticketing platform, replacing today's mix of email, shared mailboxes, and disparate per-team tools. One front door, per-team queues, shared SLAs and reporting.

Freshservice implementation

Selected and rolled out Freshservice, replacing inherited spreadsheets and ad-hoc ticketing. Thousands of tickets a year, a live asset inventory covering the company fleet, and a knowledge base spanning every IT domain. Power BI reporting for executives built directly on the Freshservice REST API.

IT operations runbook library

A library of operational runbooks standardizing how the IT team runs day to day: onboarding and offboarding, password resets, computer deployment, macOS enrollment, server patching, backup and recovery, purchasing, and endpoint escalation. Written as repeatable procedures so any team member, a new hire included, can execute them consistently.

Skills & tools

PowerShell Python Microsoft Azure Microsoft 365 Entra ID / Azure AD Intune Cisco Meraki Freshservice · ITIL Microsoft Graph API Microsoft Fabric Power BI Snowflake Supabase Azure Functions Claude API Power Automate Twilio HRIS · SCIM Defender for Endpoint Conditional Access · PIM Microsoft Purview CISA ScubaGear AdminDroid Bitwarden Astro TypeScript Cloudflare GitHub Actions