Microsoft 365 Fundamentals
MS-900
I’m Niroj Bhandari, a Desktop Support Technician at Digital nGenuity. I specialize in Microsoft 365 administration, identity and access management, endpoint management and network security, helping organizations keep their systems secure, reliable and well supported.
Front-line support experience combined with end-to-end project delivery.
A helpdesk background means systems are configured around how people actually work, reducing support requests.
SSO, Intune and Microsoft 365 migrations, planned, tested, deployed and documented.
Experience with Cisco Duo MFA and Conditional Access, currently pursuing SC-300.
Select a project to view the problem, approach and outcome.
Staff kept separate passwords for each business app, and access was managed app by app.
Configured the apps as enterprise applications in Entra ID, assigned access by group, and tested with a pilot group before rollout.
Users sign in once with their Microsoft account, and access is granted or removed in one place.
Email lived on an older platform with limited security and admin tools.
Planned the cutover, migrated mailboxes in batches, lowered TTLs ahead of time, then switched MX and set up SPF, DKIM and DMARC.
Mail was migrated to Exchange Online with authentication records in place.
The company had Intune available but no policies in place, so device settings and security weren’t enforced.
Designed and built the Intune policies from the ground up, including compliance policies and configuration profiles, then tested them before assigning to users and devices.
Security and device settings are now defined in one place and applied consistently.
Duo MFA was connected to Entra ID through custom controls, a method Microsoft is retiring.
Removed the custom controls, set up Cisco Duo as the authentication method in Entra ID, updated the Conditional Access policies and tested sign-ins.
MFA runs through Duo on a supported setup, with no gap in protection for users.
Repeat tasks were done by hand in admin portals, one click at a time.
Wrote and tested PowerShell scripts for common Microsoft 365 and Windows admin tasks.
Tasks run the same way every time and take a fraction of the time.
Branch staff used a slow remote-desktop workaround to reach files.
Built an IPsec tunnel between two WatchGuard Fireboxes with tight policies.
Direct drive access; workaround retired.
One flat network; call quality dropped at busy times.
Created VLANs, tagged trunk and access ports, set firewall interfaces.
Guests isolated and dropped calls stopped.
Desktop Support Technician with a helpdesk background and hands-on project experience.
I began my career on the helpdesk at Digital nGenuity and now work as a Desktop Support Technician, supporting Microsoft 365, identity and access management, and endpoint management. My experience also includes Active Directory, Windows Server, network infrastructure and SQL Server, with PowerShell used to automate routine administration.
Education and professional roles.
Centennial College, Scarborough, Ontario. Networking, systems and support fundamentals.
Digital nGenuity. First point of contact for accounts, email, devices and remote support.
Digital nGenuity. Escalations and projects across Microsoft 365, identity, cloud and networking.
Microsoft and CompTIA certifications, with identity administration in progress.
MS-900
AZ-900
Core 1 & Core 2
SC-300 · Entra ID, Conditional Access, PIM
Technologies and platforms I support.
For opportunities or enquiries, email is the best way to reach me.