reiderer
Hi, I'm Juan Rodríguez
Microsoft Systems · Cloud · Endpoint · Entra ID · Intune · Azure
I manage and secure Microsoft infrastructure: identity with Entra ID, endpoint management with Intune, Microsoft 365 and Azure, with PowerShell automation. I build labs close to real environments and document every step.
About me
I’m Juan Rodríguez Castellano, a systems administrator specialized in the Microsoft stack: identity with Entra ID, endpoint management with Intune, Microsoft 365 and Azure.
I come from systems administration (ASIR) and it’s where I feel at home: Windows Server and Active Directory, networking, virtualization and cloud. Building the infrastructure, understanding how it fits together and keeping it running and secure is what drives me.
My edge is security: I come from a SOC and Blue Team, so I don’t just deploy systems, I secure them. MFA, Conditional Access and identity and endpoint protection are part of how I work, not an add-on.
I use reiderer to build labs close to real environments, document what I learn and share the journey. Right now my focus is going deeper into Azure (AZ-104) and automation with PowerShell.
And if there’s one thing I’m sure of, it’s that this isn’t about piling up tools, alerts or dashboards, but about understanding things well and telling signal from noise.
Projects & Labs
What I build, close to a real environment and not as a demo: Microsoft systems administration —identity, endpoint and cloud— with security as the common thread.
Microsoft 365 deployment at scale
Real migration of 230+ endpoints with Windows Autopilot, Entra ID and Intune in a corporate environment, with compliance and endpoint security policies.
View on GitHub →Automation toolkit (PowerShell + Graph)
PowerShell module for onboarding/offboarding users in Entra ID, M365 license assignment and reporting (MFA, licenses, devices) via Microsoft Graph.
Hybrid identity lab
On-prem Active Directory synced with Entra ID (Entra Connect), Conditional Access, MFA and endpoint management with Intune. The hybrid environment companies ask for.
High Availability Cluster
High-availability cluster with Pacemaker and Corosync on Linux, with MariaDB load balancing and automatic failover.
View documentation →Microsoft Sentinel Lab
Cloud-native lab in Azure: log ingestion, KQL analytic rules mapped to MITRE ATT&CK, identity hunting and automated response. Where my two worlds meet: cloud and security.
Wazuh SIEM Lab
Full Wazuh lab with a monitored Metasploitable3 and Kali as the offensive box. MITRE ATT&CK detection, 22 CVEs with CVSS prioritization, custom XML rules and VirusTotal API integration.
View on GitHub →DarkHole: 1
Web enumeration, SQL injection and privilege escalation via SUID binaries, with internal service analysis.
View write-up →Psycho: 1
Thorough enumeration, LFI exploitation, log analysis and privilege escalation through scripts with special permissions.
View write-up →Road to OSCP
Offensive knowledge that makes me a better defender and admin. A parallel goal, no rush.
Blog
reiderer is, above all, a log. Here I post what I learn, what I build and what I think about systems and security.
Automating the repetitive stuff: my PowerShell module for Microsoft 365
I got tired of onboarding and offboarding users by hand during a Microsoft 365 migration, so I built a PowerShell module. Here is what I learned along the way.
Blue TeamCase study: building a SOC with Microsoft Sentinel
A Microsoft Sentinel lab in Azure from end to end: identity threat detection with KQL, MITRE ATT&CK mapping and automated response with Logic Apps.
SecurityQubesOS: is it really the most secure operating system?
What makes QubesOS different, why Snowden uses it, and what "the most secure OS" really means.
SystemsFrom VirtualBox to Proxmox: what they don't teach you in school
In class I virtualized with VirtualBox and VMware. Out in the real world I found Proxmox everywhere. Here is what I learned about the difference.
How I work
I work the same way building a system as investigating an alert: understand first, prioritize and document everything well.
Understand before touching
Before launching anything, I try to understand what the system exposes, how it’s built and the context around it.
Prioritize, don’t pile up
I don’t obsess over having more rules or more sources. I prefer fewer things, but understood in depth.
Correlate over time
An isolated alert is usually a medium signal. The real value is how several signals fit together.
Document the process
I care about leaving work well documented: reviewable, reproducible and easy to explain.
Connect systems and security
I understand how infrastructure is built and how it’s defended. That full context is my biggest advantage.
Experience
Certifications
I certify what I learn. Right now the focus is Microsoft systems administration and Azure.
MD-102
On the horizon: AZ-104 (Azure Administrator) and AZ-500. Plus a security foundation (Security+, eJPTv2), ethical hacking and malware analysis.
Recommendations
From the start of ASIR, Juan showed great interest in cybersecurity. He always went a step further, learning on his own. Very dynamic, with a constant drive to improve.
Juan stood out for his interest and curiosity in cybersecurity. Always learning on his own, beyond class. Very proactive and eager to keep improving.
Let's talk systems and security
reiderer is my place to share what I do and what I learn. If you want to comment, propose a collaboration or just connect, here I am.