Experience

Experience

How I work, the companies that have backed the channel, and the jobs that add up to 25 years in IT. Linux for homelabs, sysadmins, and the rest of us.

How the day job shows up in the lab

The current role is senior identity and access work: Microsoft Entra, federation, Conditional Access, and tenant-wide administration for a hybrid directory. Before that I led desktop and infrastructure support, and before that I was the person who opened the chassis, kept the repair notes, and escalated the cases that did not fit a script. The blog is not a dump of ticket comments. It is the same habit applied to Linux I run at home.

When I write a CoreOS Quadlet, I am doing what I do at work with a service account. One job, a unit file, a restart policy, and a firewall that defaults to closed. When I write an Omarchy install guide, I am doing what I do with a workstation image. Document the first boot, the update path, and the three ways it fails, so the next person, usually a future version of me, does not rediscover them from a black screen.

Identity work also explains the tone. I care about who can reach a port, which password unlocks a disk, and what happens when a laptop leaves the building. Encryption on by default, BitLocker turned off before a dual-boot shrink, and an admin UI that is not bound to the world are the homelab version of that. They are not aesthetic preferences.

What goes into a guide

I install the thing. I keep the commands that worked. I write down the command that looked right and was wrong. I do not publish frame-rate tables I did not measure on the machine in front of me. If a number matters, it is a version, a port, a timer, or a checksum from the upstream release, and the post names that release.

Videos on the channel are the companion. The post is the page you can search. A description box is a bad place to keep a kernel parameter. If you watched an Omarchy 4 episode and you want the steps, the first-week guide is the page to keep. The comparison posts are for the decision, before the USB is flashed.

I would rather link a narrow article than paste the same procedure into three roundups. The nomodeset ISO rebuild, the Resolve AUR workaround, the Silverblue virtualization layer, and the Quadlet firewall each earned their own URL. The experience of maintaining this site is mostly deciding which URL a sentence belongs on.

The machines, on purpose

The desk is a daily-driver Linux desktop. Lately that is Omarchy when I want a Hyprland session without building it from the wiki. Fedora is the release I leave alone for a month: a jumphost, a mutable workstation, or an XFCE spin on older hardware. Fedora CoreOS is the appliance. DNS, a Quadlet, Ignition, and no compositor. Alpine is the tiny host, an old laptop running Docker for Pi-hole or Jellyfin.

That split is how I keep the lights on, and it is how the tags are organized. A search for Omarchy should not dump you into a Pi-hole unit file. A search for Podman should. The about page is the longer biography. This page is the method, then the sponsors, then the resume.

Corrections, tutorial questions, and business notes go to thelinuxitguy@gmail.com.

Partnerships

Sponsors and Brand Partners

Trusted companies and software tools that have supported The Linux IT Guy channel and content.

Career

Career and Professional History

Over 25 years of enterprise systems administration, identity architecture, and infrastructure management.

  • Sr. Identity & Access Management Engineer / Global Administrator for Entra

    Lead for Microsoft Entra ID (Azure AD), Active Directory Federation Services (ADFS), and enterprise Identity & Access Management (IAM).

    • Global Administrator for Entra ID: Served as Global Administrator managing tenant-wide identity governance, Entra ID security posture, Conditional Access policies, Privileged Identity Management (PIM), Multi-Factor Authentication (MFA), Azure AD Connect directory synchronization, and RBAC across enterprise cloud environments. Architected Enterprise Application SSO integrations, app registrations, and lifecycle workflows.
    • Identity & Access Management (IAM): Designed and enforced IAM security controls, user lifecycle management, authentication protocols (OAuth 2.0, OpenID Connect, SAML 2.0), and zero-trust identity architecture across hybrid infrastructure.
    • Active Directory & Identity Federation: Led enterprise ADFS upgrades (2.0 to 3.0 to Server 2016) and seamless migration from legacy ADFS relying party trusts to Entra ID Enterprise Applications. Implemented ADFS Extranet Smart Lockout, custom forms-based authentication UI, domain local groups, OUs, and security GPOs.
    • Citrix & Virtualization: Administered Citrix Cloud (Azure/AWS), XenDesktop 7.6, StoreFront, NetScaler, and ControlUp monitoring for 2,500+ users. Automated VM provisioning with PVS/MCS and managed VMware host upgrades (5.5 to 6.0).
  • IT Team Lead (Desktop & Infrastructure)

    Led desktop and infrastructure support operations across corporate sites.

    • Infrastructure & Systems: Monitored datacenter servers and switches, installed WAN upgrades, configured RAID arrays, and managed network shared shares and AD group rights.
    • Tools & Automation: Developed custom VB.NET utilities, batch tools, local admin grant/revoke tools, and a TFTP server imaging solution that eliminated bootable installation media.
  • Sr. Desktop Engineer & Escalation Specialist

    Provided desktop engineering, datacenter server maintenance, and level-1/2 escalation support.

    • Systems Engineering: Maintained site servers, blade chassis, network routers, and switches. Managed AD LDAP users, RSA VPN tokens, PGP disk encryption, and Microsoft SQL 2008 databases.
    • Escalation Support: Served as liaison for mobile hardware repair depot and customer issues, managed executive reporting, and headed an on-site vendor pilot program.
  • Computer Repair Technician

    Hardware and software diagnostic evaluation, repair, and failure analysis.

    • Diagnosed unit failures, tested component efficiency/reliability, and documented detailed repair records in customer database.