Active Directory hygiene: GPO repair
GPO and ACL audit and repair in a ~23,000-account forest, phased, with a rollback path at every step
What was built
Seven domains, roughly 23,000 active accounts, and policies different people had been editing for decades. I wrote 17 PowerShell scripts: find the broken ones, restore Security Filtering after a mass downgrade to Authenticated Users, clear out dead NetLogon ACEs. Every run starts with a pre-flight, then three phases, with a backup and a rollback path at each step. Hundreds of GPOs. Not one blind change.
Stack
PowerShellActive DirectoryGroup PolicyGPOZaurrNetLogon ACLSecurity Filtering
Other work
- Single source of truth for infrastructure
- 2FA / SSO for mail on Keycloak + ANGIE
- Enterprise infrastructure from scratch
- Managed corporate access client
- Internal certificate authority with ACME
- Report access gateway on directory groups
- Workplace self-service: software and VDI
- Active Directory modernization
- Zabbix + Grafana and automation
- Office-to-DC networking
- Virtualization and vCenter
- Distributed Veeam and DRP
- Infrastructure Q&A agent over MCP
- Multi-agent workflow for solo development
- LLM call analysis and BI/CRM pipeline