About Projects Blog Experience Contact
Personal log · Microsoft Systems & Cloud

reiderer

Hi, I'm Juan Rodríguez

Microsoft Systems · Cloud · Endpoint · Entra ID · Intune · Azure

I manage and secure Microsoft infrastructure: identity with Entra ID, endpoint management with Intune, Microsoft 365 and Azure, with PowerShell automation. I build labs close to real environments and document every step.

Microsoft 365Entra ID · IntuneAzurePowerShellEndpoint security
Juan Rodríguez Castellano
Juan Rodríguez Castellano
Córdoba, Andalusia · ES

About me

I’m Juan Rodríguez Castellano, a systems administrator specialized in the Microsoft stack: identity with Entra ID, endpoint management with Intune, Microsoft 365 and Azure.

I come from systems administration (ASIR) and it’s where I feel at home: Windows Server and Active Directory, networking, virtualization and cloud. Building the infrastructure, understanding how it fits together and keeping it running and secure is what drives me.

My edge is security: I come from a SOC and Blue Team, so I don’t just deploy systems, I secure them. MFA, Conditional Access and identity and endpoint protection are part of how I work, not an add-on.

I use reiderer to build labs close to real environments, document what I learn and share the journey. Right now my focus is going deeper into Azure (AZ-104) and automation with PowerShell.

And if there’s one thing I’m sure of, it’s that this isn’t about piling up tools, alerts or dashboards, but about understanding things well and telling signal from noise.

Microsoft 365Entra IDIntuneWindows ServerActive DirectoryAzurePowerShellVirtualizationNetworking / TCP-IPIdentity securityMicrosoft SentinelLinux

Projects & Labs

What I build, close to a real environment and not as a demo: Microsoft systems administration —identity, endpoint and cloud— with security as the common thread.

MICROSOFT SYSTEMS — identity, endpoint and cloud
Featured

Microsoft 365 deployment at scale

Real migration of 230+ endpoints with Windows Autopilot, Entra ID and Intune in a corporate environment, with compliance and endpoint security policies.

#Autopilot#EntraID#Intune#M365
View on GitHub →
In progress

Automation toolkit (PowerShell + Graph)

PowerShell module for onboarding/offboarding users in Entra ID, M365 license assignment and reporting (MFA, licenses, devices) via Microsoft Graph.

#PowerShell#MicrosoftGraph#Automation
In progress

Hybrid identity lab

On-prem Active Directory synced with Entra ID (Entra Connect), Conditional Access, MFA and endpoint management with Intune. The hybrid environment companies ask for.

#ActiveDirectory#EntraID#Intune#Hybrid

High Availability Cluster

High-availability cluster with Pacemaker and Corosync on Linux, with MariaDB load balancing and automatic failover.

#Pacemaker#Corosync#HA#Linux
View documentation →
CLOUD & SECURITY — Azure and detection
In progress

Microsoft Sentinel Lab

Cloud-native lab in Azure: log ingestion, KQL analytic rules mapped to MITRE ATT&CK, identity hunting and automated response. Where my two worlds meet: cloud and security.

#Sentinel#KQL#Azure
Full lab

Wazuh SIEM Lab

Full Wazuh lab with a monitored Metasploitable3 and Kali as the offensive box. MITRE ATT&CK detection, 22 CVEs with CVSS prioritization, custom XML rules and VirusTotal API integration.

#Wazuh#MITREATTACK#VirusTotal
View on GitHub →
EXTRA — Red Team & CTF
Medium

DarkHole: 1

Web enumeration, SQL injection and privilege escalation via SUID binaries, with internal service analysis.

#SQLi#SUID#PrivEsc
View write-up →
Medium

Psycho: 1

Thorough enumeration, LFI exploitation, log analysis and privilege escalation through scripts with special permissions.

#LFI#LogAnalysis#PrivEsc
View write-up →
Future

Road to OSCP

Offensive knowledge that makes me a better defender and admin. A parallel goal, no rush.

#RedTeam#OSCP#OffSec

How I work

I work the same way building a system as investigating an alert: understand first, prioritize and document everything well.

01

Understand before touching

Before launching anything, I try to understand what the system exposes, how it’s built and the context around it.

02

Prioritize, don’t pile up

I don’t obsess over having more rules or more sources. I prefer fewer things, but understood in depth.

03

Correlate over time

An isolated alert is usually a medium signal. The real value is how several signals fit together.

04

Document the process

I care about leaving work well documented: reviewable, reproducible and easy to explain.

05

Connect systems and security

I understand how infrastructure is built and how it’s defended. That full context is my biggest advantage.

Experience

Mar 2026 — May 2026 · Córdoba · On-site
IT Support Technician — Microsoft 365 Migration
ECOINTEGRAL INGENIERÍA, SL (via GI Group)
Deployment and migration of 230+ Windows endpoints to Microsoft 365, within the integration into Bureau Veritas. Windows Autopilot, identities in Entra ID, compliance policies and user support.Windows 11 · Autopilot · Entra ID · Microsoft 365 · Intune
Oct 2025 — Dec 2025 · Córdoba · On-site
IT Technician
Fersoft Informática
Support and rollout of business management software in SMBs (Verifactu project). SQL Server, billing software and on-site and remote user support.Windows · SQL Server · Remote support
Mar 2025 — Jun 2025 · Córdoba · Hybrid
Cybersecurity Analyst — SOC N1
IaaS365 · Internship
24/7 multi-client SOC: monitoring, triage and alert escalation. SIEM (LogPoint, Wazuh) and EDR/XDR (Vision One, Cynet), IOCs and MITRE ATT&CK, Nessus/OpenVAS scans, GoPhish phishing and ENS audits.LogPoint · Wazuh · Vision One · Cynet · MITRE ATT&CK · ENS

Certifications

I certify what I learn. Right now the focus is Microsoft systems administration and Azure.

Microsoft

MD-102

Endpoint Administrator · in progress
CompTIA · SY0-701

Security+ (ce)

Nov 2025 → Nov 2028
Verify credential ↗
eLearnSecurity · INE

eJPTv2

Junior Penetration Tester · Dec 2025
Verify credential ↗
Google · Coursera

Google Cybersecurity

Professional Certificate
Verify credential ↗

On the horizon: AZ-104 (Azure Administrator) and AZ-500. Plus a security foundation (Security+, eJPTv2), ethical hacking and malware analysis.

Recommendations

From the start of ASIR, Juan showed great interest in cybersecurity. He always went a step further, learning on his own. Very dynamic, with a constant drive to improve.

Gonzalo Cabada AñónSystems Technician · ASIR classmate

Juan stood out for his interest and curiosity in cybersecurity. Always learning on his own, beyond class. Very proactive and eager to keep improving.

Irene Aragonés SánchezASIR Technician · ASIR classmate

Let's talk systems and security

reiderer is my place to share what I do and what I learn. If you want to comment, propose a collaboration or just connect, here I am.

cd