Syed Tabrez Azmath
Chicago, IL *****
****************@*****.***
https://www.linkedin.com/in/syed-azmath-4956284b/
Senior Endpoint Engineer Modern Workplace Engineer Intune & MECM/SCCM Specialist Windows Autopilot Windows 11 Enterprise Microsoft Entra ID Endpoint Security PowerShell Automation PROFESSIONAL SUMMARY
• Senior Endpoint Engineer with 13+ years of experience designing, engineering, securing, and supporting enterprise endpoint environments across healthcare, financial services, and corporate organisations.
• Certifications: Microsoft Certified Solutions Expert (MCSE) – 2016 Cisco Certified Network Associate (CCNA) Microsoft Certified: Endpoint Administrator Associate (MD-102) Microsoft Certified: Azure Administrator Associate (AZ-104) Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
• Expertise in Microsoft Intune, MECM/SCCM, Windows Autopilot, Windows 11 Enterprise, Microsoft Entra ID, Microsoft Defender for Endpoint, and modern workplace endpoint management solutions.
• Experienced in enterprise device lifecycle management including Windows 10/11 migrations, zero-touch deployments, application packaging, software distribution, patch management, endpoint compliance, security hardening, and device modernisation initiatives.
• Skilled in PowerShell automation, Microsoft Graph PowerShell, Intune Remediations, Conditional Access, Zero Trust security, and proactive endpoint management to improve security, compliance, and operational efficiency.
• Proven experience supporting large-scale enterprise environments through modern endpoint transformation, cloud-based device management, automation, and secure digital workplace solutions. CORE COMPETENCIES
Modern Endpoint Management Microsoft Intune MECM/SCCM Windows Autopilot Windows 11 Enterprise Microsoft Entra ID Microsoft Endpoint Manager Endpoint Security Microsoft Defender for Endpoint Zero Trust Security Application Packaging Win32 Application Deployment Software Distribution Windows Migration Device Lifecycle Management Patch Management PowerShell Automation Microsoft Graph PowerShell Intune Remediations Proactive Remediation Conditional Access Compliance Management Azure Virtual Desktop (AVD) Windows 365 Cloud PC FSLogix EUC Engineering Desktop Engineering Incident Management Change Management ServiceNow ITSM. TECHNICAL SKILLS
Modern Endpoint Management & UEM: Microsoft Intune, Microsoft Endpoint Manager, Unified Endpoint Management (UEM), Enterprise Device Management, Device Enrollment, Windows Autopilot, Autopilot Deployment Profiles, Enrollment Status Page
(ESP), Entra Join, Hybrid Azure AD Join, Hybrid Join, Configuration Profiles, Compliance Policies, Intune Filters, Company Portal, Endpoint Analytics, Intune Remediations, Proactive Remediations, Device Compliance Management. Windows Desktop Engineering: Windows 11 Enterprise, Windows 10 Enterprise, Enterprise Workstation Management, End User Computing (EUC), Desktop Engineering, Device Lifecycle Management, Windows Deployment, Zero Touch Deployment, Hardware Refresh, Windows Imaging, Golden Image Management, Driver Management, User State Migration (USMT), User Profile Management, Desktop Troubleshooting.
Application Deployment & Packaging: Win32 Application Deployment, Intune Application Deployment, MECM/SCCM Application Models, MSI/MSIX Packaging, Application Packaging, Software Distribution, Application Lifecycle Management, Microsoft 365 Apps Deployment, Office 365 Click-to-Run, Application Testing, Detection Methods, Application Supersedence. MECM/SCCM Administration: Microsoft Endpoint Configuration Manager (MECM), SCCM Current Branch, Co-Management, Task Sequences, Operating System Deployment (OSD), Collections, Device Collections, User Collections, Boundaries, Distribution Points, Software Update Point (SUP), Configuration Baselines, Inventory Management, Compliance Monitoring, SCCM Reporting, SSRS Reports.
Identity & Access Management: Microsoft Entra ID (Azure AD), Active Directory, Hybrid Identity, Azure AD Connect, Group Policy
(GPO), Organisational Units (OU), Role-Based Access Control (RBAC), Conditional Access, Multi-Factor Authentication (MFA), Device Authentication, Access Control.
Endpoint Security: Microsoft Defender for Endpoint, Microsoft Defender XDR, Endpoint Detection and Response (EDR), Defender Vulnerability Management, Endpoint Security Policies, Security Baselines, BitLocker Encryption, Attack Surface Reduction (ASR), Zero Trust Security, Endpoint Privilege Management, Threat Protection, Vulnerability Remediation. Automation & Scripting: PowerShell Automation, PowerShell Remediation Scripts, Microsoft Graph PowerShell, Microsoft Graph API, Intune Automation, Windows Automation, Task Automation, Reporting Automation. Microsoft Cloud & Modern Workplace: Microsoft Azure, Microsoft 365, Exchange Online, Microsoft Teams, SharePoint Online, OneDrive for Business, Azure Monitor, Log Analytics, Cloud Services Administration. Virtual Desktop & Cloud Workspace: Azure Virtual Desktop (AVD), AVD Host Pools, Session Hosts, FSLogix Profile Containers, Windows 365 Cloud PC, VMware Horizon, VMware vSphere, Remote Desktop Services (RDS), Virtual Desktop Infrastructure (VDI). Patch Management & IT Operations: Enterprise Patch Management, Windows Update for Business (WUfB), Intune Update Rings, Windows Autopatch, Software Updates, Vulnerability Remediation, Endpoint Health Monitoring, Incident Management, Change Management, Problem Management, ServiceNow ITSM.
Reporting & Monitoring: Microsoft Intune Reporting, Endpoint Analytics, Device Health Monitoring, Compliance Reporting, Power BI Reporting, Inventory Management, Operational Dashboards, SCOM, SolarWinds, Azure Monitor. Networking & Infrastructure: TCP/IP, DNS, DHCP, VPN, LAN/WAN, Wireless Troubleshooting, Network Connectivity Analysis, Remote Desktop Support, Hardware Troubleshooting.
PROFESSIONAL EXPERIENCE
WORTH PRIME TAX Glastonbury, CT Jun 2024 – Present Senior Desktop Engineer Endpoint Management Engineer Modern Workplace Engineer.
Engineered and managed enterprise endpoint environments supporting 5,000+ Windows devices using Microsoft Intune, MECM/SCCM Co-management, and Windows Autopilot, improving device provisioning efficiency and endpoint reliability
Automated endpoint compliance validation and remediation using PowerShell and Microsoft Graph, significantly reducing manual administration effort and improving compliance consistency.
Implemented Windows Autopilot Zero-Touch Deployment, streamlining enterprise device provisioning and reducing deployment time for new Windows endpoints
Improved endpoint security posture through Intune compliance policies, Defender for Endpoint integration, and Zero Trust security controls.
Managed the complete lifecycle of 5,000+ enterprise Windows endpoints, maintaining high compliance, security, and operational availability across distributed environments.
Implemented Windows Autopilot deployment solutions including Entra Join, Hybrid Join, Enrollment Status Page (ESP), deployment profiles, and automated device provisioning workflows.
Administered Microsoft Intune policies including configuration profiles, compliance policies, endpoint security policies, application assignments, update rings, and proactive remediation workflows.
Developed and deployed enterprise applications using Win32 application packaging, MSI/MSIX packages, Microsoft 365 Apps deployment, Intune, and MECM/SCCM software distribution.
Created PowerShell automation scripts and Microsoft Graph PowerShell solutions to automate endpoint management tasks, compliance checks, reporting, and remediation activities.
Implemented endpoint security solutions using Microsoft Defender for Endpoint, Microsoft Defender XDR, BitLocker encryption, Security Baselines, Attack Surface Reduction (ASR), Conditional Access, and Zero Trust security practices.
Managed identity-based device access using Microsoft Entra ID, Active Directory, RBAC, MFA, and Conditional Access policies to maintain secure endpoint authentication.
Supported Azure Virtual Desktop (AVD), Windows 365 Cloud PC, and FSLogix profile management to enhance remote workspace performance and user experience.
Served as the Tier 3 escalation engineer, resolving complex endpoint, Intune, MECM, Windows 11, and Microsoft 365 issues while consistently meeting enterprise SLA targets. Technology Environment: Windows 11 Enterprise, Microsoft Intune Suite, Microsoft Endpoint Manager, MECM/SCCM Co- management, Windows Autopilot, Microsoft Entra ID, Microsoft 365, Defender for Endpoint, Defender XDR, Azure Virtual Desktop, Windows 365 Cloud PC, FSLogix, PowerShell, Microsoft Graph API, ServiceNow, Zero Trust Endpoint Security. Novartis (Client) Wipro Deerfield, IL Jan 2019 – Jun 2023 Endpoint Management Engineer Desktop Engineer MECM/SCCM Administrator
Supported enterprise endpoint environments within a regulated healthcare organisation, ensuring secure, reliable, and compliant Windows desktop operations.
Administered Microsoft Endpoint Configuration Manager (MECM/SCCM) Current Branch for enterprise software distribution, operating system deployment, device inventory, compliance monitoring, and endpoint lifecycle management.
Created and maintained SCCM task sequences, operating system images, driver packages, boot media, and deployment workflows supporting Windows workstation refresh and migration initiatives.
Supported Windows 10 to Windows 11 migration projects including hardware readiness assessment, application compatibility testing, pilot deployments, user transition support, and post-deployment troubleshooting.
Designed and deployed enterprise applications using SCCM Application Models, MSI/MSIX packaging, Win32 applications, software distribution, detection methods, and application testing processes.
Managed endpoint patching activities using SCCM Software Updates, Windows Update technologies, and enterprise patch management processes to improve device compliance and reduce security risks.
Supported Microsoft Intune and MECM co-management initiatives to transition traditional endpoint management toward modern cloud-based device management.
Performed advanced troubleshooting for Windows operating systems, Microsoft 365 applications, VPN connectivity, endpoint configuration issues, and enterprise application incidents.
Supported Active Directory administration including computer objects, Group Policy troubleshooting, organisational units
(OU), security groups, and endpoint access management.
Assisted with endpoint security initiatives using Microsoft Defender for Endpoint, BitLocker encryption, vulnerability remediation, security baselines, and compliance policies.
Provided Tier 3 escalation support, collaborated with infrastructure and application teams, and resolved complex incidents using ServiceNow ITSM processes.
Technology Environment: Windows 10/11 Enterprise, MECM/SCCM Current Branch, Microsoft Intune, Microsoft Endpoint Manager, Active Directory, Group Policy, Microsoft 365, Defender for Endpoint, PowerShell, Application Packaging, Software Distribution, Patch Management, ServiceNow, VMware. Global Networks India Oct 2012 – Oct 2019
Senior Desktop Support Engineer Windows Systems Support Engineer EUC Support Engineer.
Delivered enterprise-level End User Computing (EUC) support for Windows-based corporate environments, ensuring workstation reliability, user productivity, and operational stability.
Installed, configured, maintained, and supported Windows desktop operating systems, laptops, workstations, peripherals, and enterprise business applications.
Provided Tier 2 technical support for Windows OS issues, hardware failures, application incidents, printing problems, user access issues, and desktop configuration challenges.
Administered Active Directory environments including user accounts, computer objects, security groups, password resets, access permissions, and account troubleshooting.
Supported Group Policy administration including desktop configurations, security settings, software restrictions, and workstation policy troubleshooting.
Performed workstation deployments, operating system upgrades, software installations, hardware replacements, and endpoint lifecycle management activities.
Supported enterprise connectivity troubleshooting including LAN/WAN, TCP/IP, DNS, DHCP, VPN access, and network-related desktop issues.
Supported Microsoft Office applications, enterprise productivity tools, email clients, and business-critical applications across user environments.
Assisted with IT asset management activities including hardware inventory, device tracking, software licensing, asset lifecycle management, and equipment replacement coordination.
Created technical documentation, knowledge articles, and troubleshooting guides to improve support efficiency and reduce recurring incidents.
Technology Environment: Windows 7/8/10, Windows Server, Active Directory, Group Policy, Microsoft Office Suite, LAN/WAN, DNS, DHCP, VPN, Remote Desktop Support, Hardware Troubleshooting, IT Asset Management. CAT Technologies Ltd India 2010 – 2012
Desktop Support Engineer
• Provided Level 1 and Level 2 technical support for enterprise users, resolving desktop, laptop, operating system, application, and hardware-related incidents.
• Installed, configured, and maintained Windows-based workstations, laptops, printers, peripherals, and standard business applications for end users.
• Performed Windows operating system installations, workstation configurations, software deployments, user setups, and desktop provisioning activities.
• Troubleshot hardware failures, driver issues, application errors, printing problems, and basic network connectivity issues to restore user productivity.
• Supported user onboarding activities including workstation preparation, account setup assistance, access requests, and basic Active Directory administration.
• Managed desktop asset activities including hardware inventory, equipment tracking, replacement coordination, and endpoint lifecycle support.
• Provided remote and onsite technical assistance while documenting incidents, troubleshooting steps, and resolutions through IT support processes.
• Assisted senior infrastructure teams with desktop maintenance activities including security updates, antivirus management, system health checks, and workstation optimisation. Technology Environment: Windows XP/7, Active Directory, Microsoft Office Suite, Desktop Hardware, Printers, LAN Support, Remote Support Tools, Antivirus, User Administration. EDUCATION:
Bachelor of Science in Computer Science, Osmania University, Hyderabad, Mar 2007 – Apr 2010 CERTIFICATIONS:
Microsoft Certified Solutions Expert (MCSE) – 2016
Cisco Certified Network Associate (CCNA)
Microsoft Certified: Endpoint Administrator Associate (MD-102)
Microsoft Certified: Azure Administrator Associate (AZ-104)
Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)