MICHAEL HALL
**** ********** **. *** *** Dallas, Tx 75287 · 214-***-****
**************@*****.*** · www.linkedin.com/in/michael-hall-13874271
Identity & Access Management professional with enterprise-level experience supporting global environments of 100,000+ users. Proven background delivering secure authentication and authorization solutions at organizations including Microsoft, Dell, IBM, and JP Morgan. Deep expertise in Azure AD, Active Directory, LDAP, SSO (ADFS), MFA, PIM, and modern federation protocols including OAuth, OIDC, and SAML. Strong understanding of REST APIs and automation using PowerShell, HTML, and XML. I have recently completed advanced study across Azure infrastructure, security operations, AI fundamentals, and cloud architecture to further strengthen cloud-first IAM capabilities.
SKILLS
Multi-Factor Authentication (MFA)
Adaptive Authentication
Single Sign-On (SSO)
Federated Identity Management
Token-Based Authentication
OAuth 2.0
OpenID Connect (OIDC)
SAML 2.0
Kerberos
LDAP / Active Directory Integration
Role-Based Access Control (RBAC)
Privileged Identity Management (PIM)
Separation of Duties (SoD)
Principle of Least Privilege (PoLP)
Okta
Ping Identity
CyberArk
ForgeRock
API Key Management
Defense-in-Depth Strategy
User Behavior Analytics (UBA)
SCIM (System for Cross-domain Identity Management)
FIDO2 / Passwordless Authentication
JWT (JSON Web Tokens)
X.509 Certificates
PKI Management
Azure AD / Microsoft Entra ID
AWS Identity and Access Management (AWS IAM)
Google Cloud Identity
Cross-Account Access Management
IAM Roles & Policies
Managed Identities
Secrets Management
Just-In-Time (JIT) Access
Microsoft Active Directory
SIEM Integration
Compliance Reporting (SOX, HIPAA, GDPR)
Conditional Access Policies
Identity Lifecycle Management
Identity Threat Detection & Response (ITDR)
EXPERIENCE
MAY 2023 – TO PRESENT
AZURE B2C ENGINEER, IAM, Ford Motor company – Tek Systems
I took a job doing CIAM. Its customer identity and access management. Ford has a big Microsoft Azure B2C solution. I'm helping with this effort. I started on 5/4. Its through Tek Systems.
JANUARY 2023 – TO JUNE 2023
ADFS ENGINEER, DOD AAFES – Virtual Tech Gurus
I took a job at AAFES. Its with the DoD. Its a military job. Its the Army Air Force Exchange Service. I do ADFS support. 4 ADFS 2012 servers, 2 locations a headquarters and a colo.
JANUARY 2023 – TO APRIL 2023
FORGEROCK TO B2C MIGRATION, sperician – Kubota
I helped setup IBM WebSphere to speak SAML to Azure B2C. I also helped setup a claims provider trust to let B2C talk OIDC to an Azure Active Directory. I did a whole bunch of work with custom Azure B2C policies, Claims Providers, Building Blocks, Claim Transformations, Orchestrations steps, B2C Content definitions, Predicates, Technical Profiles, User Journeys, and Relying Parties. I supported a migration from Forgerock to Azure B2C. We had a SAML app, android/iPhone app, web app and SalesForce. We had Visual Studio Code to manage the B2C starter pack, we had the b2c-extension-app, 500-600 lines of code in our B2C TrustFrameWorkExtension.xml file. We had multiple B2C environments, staging, dev, UAT, prod, etc.
FEBURARY 2021 – TO AUGUST 2022
ADFS SUPPORT, Microsoft - Insight Global
I was on the Active Directory Federation Services team. I supported ADFS and Web Application Proxies. My support included SAML, WS*, OAuth, and OIDC protocols. My support included ADFS upgrades, ADFS certificate rollover, troubleshooting ADFS errors, enabling ADFS Auditing, ADFS installation, configuring ADFS claims, federating Azure with ADFS, ADFS smart lockout, editing the onload.js ADFS landing page. Support included configuring ADFS to work with access tokens, id tokens and REST APIs. Support included signature verification and encryption of the tokens.
SEPTEMBER 2018 – DECEMBER 2020
SAML TEAM, AIC Talent - JPMC
I supported a migration of 2,000+ web applications from SailPoint to Active Directory Federation Services. I lead multiple dev ops team in coding their web applications to achieve SSO with ADFS using the SAML protocol. I lead the dev teams into coding their web apps to consume claims issued in tokens by ADFS, to do signature verification, to do encryption, to do just in time provisioning, single log out and SCIM. Support included Oauth, OIDC and REST APIs.
SEPTEMBER 2017 – MAY 2018
AZURE SUPPORT, Microsoft - Aditi Staffing -
I supported Azure Active Directory Authentication. Support included Azure Device Registration, Conditional Access Policies, B2B, Azure AD Connect, Privileged Access Management, PowerShell, Azure Key Vault, Azure MFA, Azure Enterprise Applications, Azure App Registrations, Azure SSO, B2C, Azure Virtual Machines, Azure Network Security Groups, Azure RBAC, Azure licensing, Azure Application Proxy, Intune MDM, Azure SSPR, and Azure Subscription administration.
OCTOBER 2016 – NOVERBER 2016
NETWORK ENGINEER, THE CSI COMPANIES
Replaced 162 Cisco switches at a Regional Hospital with new Cisco Catalyst 3650s. Connected stack cables, mounted switches in rack, removed legacy switches. Installed Cisco Nexus 5k's. Configured vPC, etherchannel, port channels and vlans.
JUNE 2016 – JULY 2016
NETWORK ADMINISTRATOR, VERIZON - CROSSFIRE CONSULTING
Verizon Terramark - Remediated vulnerabilities detected with Qualys, Retina and Nesuss scans. Ensured regulatory compliance based on HIPAA, FISMA, FedRAMP and PCI controls for Verizon's clients.
SEPTEMBER 2014 – AUGUST 2015
CISCO UCS ADMINISTRATOR/SAN ADMINISTRATOR, Norwin Technologies
I supported upgrading Vblocks. It is basically a data center in a cabinet. I would unbox and install a Cisco server. It’s a big container called a Cisco UCS Chassis and the servers are called blades. Then we connect the Cisco blades to Cisco Nexus 1000v virtual switches and then connect the switches to EMC SAN storage. I would install VM Ware as the OS on the servers.
Unbox and install EMC VNX and VMAX SANs. Install and configure Cisco UCS, VMWare, Cisco Nexus 1000v switches, EMC PowerPath. Configure Cisco Nexus Fabric Interconnect zoning. Configure EMC VNX and VMAX storage processors, boot LUNS, storage groups, storage pools, initiators and masks. Install, configure and maintain Cisco Nexus switches, Cisco 3560 Catalyst Switches, Cisco 6248 Fabric Interconnect, and EMC Powerpath
APRIL 2016 – JUNE 2016
NETWORK ENGINEER, ROBERT HALF TECHNOLOGY – GREXO TECHNOLOGY GROUP
SEPTERMBER 2015 – MARCH 2016
MICROSOFT TIER III WINDOWS SERVER SUPPORT, CONVERGYS – MICROSOFT
SEPTEMBER 2014 – AUGUST 2015
FIELD ENGINEER, NORWIN TECHNOLGOIES
SEPTEMBER 2014 – JUNE 2015
POS CONVERSION, GO2IT GROUP
OCTOBER 2014 – NOVEMBER 2014
SYSTEM ADMINISTRATOR – TABLET REFRESH PROJECT - DISD, KFORCE
JUL 2014 – SEPTEMBER 2014
NETWORK ENGINEER WIFI DEPLOYMENT PARKLAND HOSPITAL, NETSYNC NETWORK SOLUTIONS
MAY 2014 – JULY 2014
CELL TOWER TECHNICIAN, AT&T
MAY 2014 – MAY 2014
TELLCOMMUNICATIONS ENGINEER, GUGGENHEIM
APRIL 2014 – MAY 2014
NETWORK ENGINEER, FUJITSU
FEBURARY 2014 – FEBURARY 2014
DATA CENTER ENGINEER, WALMART
SEPTEMBER 2013 – FEBURARY 2014
SENIOR FIELD ENGINEER, INTELINET SYSTEMS
SEPTERMBER 2013 – OCTOBER 2013
I.T. CONSULTANT, UT SOUTHWESTERN MEDICAL CENTER
MAY 2013 – SEPTEMBER 2013
TELECOMMUNICATIONS SPECIALIST, STS INTERNATIONAL INC
DEC 2012 – FEBURARY 2013
INSTRUCTOR, MEDIA TECH
NOVEMBER 2012 – DECEMBER 2012
TIER III TECHNICAL SUPPORT, MICROSOFT
DECEMBER 2011 – SEPTEMBER 2012
HELP DESK ANALYST, BLUESOURCE
NOVEMBER 2010 – DECEMBER 2011
TIER III FIELD ENGINEER, CMC NETWORK SOLUTIONS
MARCH 2011 – APRIL 2011
MICROSOFT EXCHANGE ENGINEER, ONCOR ELECTRIC DELIVERY
FEBURARY 2010 – NOVEMBER 2010
TELECOMMUNICATIONS TECHNICIAN, CLEARWIRE
OCTOBER 2009 – JANUARY 2010
DEPLOYMENT TECHNICIAN, DALLAS ISD
SEPTEMBER 2009 – OCTOBER 2009
DEPLOYMENT SPECIALIST, JP MORGAN CHASE
DEC 2008 – SEPTEMBER 2009
NETWORK CONSULTANT, ZAC SOLUTIONS
NOVEMBER 2007 – OCTOBER 2008
HELPDESK ANALYST, CHIP PC
MAY 2007 – NOVEMBER 2007
TIER 1 TECHNICAL SUPPORT, CINGULAR
AUGUST 2006 – APRIL 2007
NETWORK ADMINISTRATOR, SUNL GROUP INC
OCT 2005 – AUGUST 2006
DEPLOYMENT ENGINEER, IBM
FEB 2005 – AUGUST 2005
TIER 1 TELECOMMUNICATIONS TECHNICIAN, XO COMMUNICATIONS
OCT 2004 – FEBURARY 2005
TIER 1 TECHNICAL SUPPORT, TELVISTA INC.
MARCH 2004 – OCTOBER 2004
INDEPENDENT CONSULTANT, INDEPENDENT CONSULTANT
DECEMBER 2003 – JANUARY 2004
DESKTOP SUPPORT TECHNICIAN, SIEMENS
SEPTEMBER 2003 – DECEMBER 2003
DEPLOYMENT ENGINEER, NMCI SERVICES
AUGUST 2003 – AUGUST 2003
NETWORK ENGINEER, AQUAFORM
NOVEMBER 2002 – JUN 2003
TIER 1 TECHNICAL SUPPORT, TELVISTA
MAY 2002 – MAY 2002
TIER 1 TECHNICAL SUPPORT, MICROSOFT
JANUARY 2002– MAY 2002
TIER 1 TECHNICAL SUPPORT, STREAM GLOBAL SERVICES
SEPTEMBER 2001 – DECEMBER 2001
NETWORK ADMINISTRATOR, GUARANTY BANK
MAY 2001 – SEPTEMBER 2001
NETWORK ADMINISTRATOR, CUNNINGHAM LINDSEY
JANUARY 2000 – JANUARY 2001
TIER 1 TECHNICAL SUPPORT, STREAM GLOBAL SERVICES
SEPTEMBER 1998 – SEPTEMBER 1999
TIER 1 TECHNICAL SUPPORT, MICROSOFT
EDUCATION
MAY 2002
STUDIED FOR LAN ADMINISTRATION ASSOCIATES DEGREE, DCCCD Brookhaven
I have 48 hours towards a 2-year degree in LAN Administration. Studied Visual Basic, C++, Java, C# and Networking.
ACTIVITIES
I have 5 certifications. Microsoft Exchange 2010, Citrix Xen Desktop 2.0, Veeam Backup, EMC Data Domain and Enterprise Vault 9.0. I studied for CCNA, CCNP, MCSE, VM Ware Certified Professional and multiple EMC SANs.