Hands-on enterprise IT support portfolio demonstrating troubleshooting across ServiceNow, Microsoft 365, Microsoft Entra ID, Microsoft Intune, Conditional Access, SharePoint Online, Windows 11, networking, security, and PowerShell.
The project simulates a multi-department business environment and documents 10 end-to-end support incidents, from initial user report through investigation, root-cause analysis, remediation, verification, and ServiceNow resolution.
- 10 documented enterprise support incidents
- 8 technical documentation guides
- 109 screenshots of troubleshooting and verification
- Microsoft Entra ID identity administration
- Microsoft 365 licensing and application support
- Microsoft Intune endpoint management
- Conditional Access troubleshooting
- MFA and Microsoft Authenticator
- SharePoint permissions
- DNS and VPN troubleshooting
- Windows Defender Firewall and compliance
- Security sign-in investigation
- PowerShell diagnostics and remediation
- ServiceNow incident lifecycle documentation
The goal of this capstone is to demonstrate how common Help Desk and IT Support issues are investigated across multiple enterprise systems.
Instead of treating technologies as isolated tools, the project connects:
User
↓
ServiceNow
↓
Identity
↓
Endpoint
↓
Network
↓
Security
↓
Microsoft 365
↓
Verification
The focus is on identifying the actual root cause, applying the smallest appropriate remediation, and proving that the user's original issue is resolved.
| Area | Technology |
|---|---|
| ITSM | ServiceNow |
| Identity | Microsoft Entra ID |
| Productivity | Microsoft 365 |
| Messaging | Outlook / Microsoft 365 |
| Collaboration | SharePoint Online |
| Endpoint Management | Microsoft Intune |
| Access Control | Conditional Access |
| Authentication | MFA / Microsoft Authenticator |
| Endpoint | Windows 11 |
| Virtualization | VirtualBox |
| Administration | PowerShell |
| Networking | TCP/IP, DNS, HTTPS, VPN |
| Endpoint Security | Windows Defender Firewall |
| Investigation | Entra Sign-In Logs, Audit Logs, Windows Logs |
flowchart TD
User["Enterprise User"]
ServiceNow["ServiceNow"]
Entra["Microsoft Entra ID"]
M365["Microsoft 365"]
SharePoint["SharePoint Online"]
CA["Conditional Access"]
Intune["Microsoft Intune"]
Windows["INTUNE-WIN-01 - Windows 11"]
PowerShell["PowerShell"]
Authenticator["Microsoft Authenticator"]
User --> ServiceNow
User --> Windows
ServiceNow --> Entra
Entra --> M365
Entra --> CA
Entra --> Authenticator
M365 --> SharePoint
CA --> Intune
Intune --> Windows
Windows --> PowerShell
flowchart LR
A["User Reports Issue"] --> B["ServiceNow Incident"]
B --> C["Triage"]
C --> D["Collect Evidence"]
D --> E["Identify Root Cause"]
E --> F["Targeted Remediation"]
F --> G["Retest"]
G --> H["Verify Resolution"]
H --> I["Document & Close"]
Scenario: Human Resources user unable to access Microsoft cloud services after losing access to the existing password.
Technologies:
- Microsoft Entra ID
- Microsoft 365
- ServiceNow
- Audit Logs
Troubleshooting demonstrated:
- Account-state validation
- Password administration
- Temporary password workflow
- Authentication verification
- Audit verification
Outcome: Password access restored and successful authentication confirmed.
Scenario: Sales user unable to sign in despite attempting valid credentials.
Key evidence:
Microsoft Entra Error: 50057
User account is disabled
Troubleshooting demonstrated:
- Microsoft Entra account state
- Sign-in logs
- Error-code analysis
- Account re-enablement
- Fresh sign-in verification
Outcome: Account was re-enabled and authentication succeeded without an unnecessary password reset.
Scenario: Finance user reports loss of network access.
The endpoint retained direct IP connectivity while DNS resolution failed.
Failure configuration:
DNS Server: 192.0.2.53
Evidence:
Test-NetConnection 1.1.1.1 -Port 443Direct TCP connectivity succeeded.
Resolve-DnsName microsoft.comDNS resolution failed.
Troubleshooting demonstrated:
- TCP/IP
- DNS
Resolve-DnsNamenslookupTest-NetConnection- Root-cause isolation
Outcome: Correct DNS configuration was restored and successful name resolution and HTTPS access were verified.
Scenario: Remote Sales user unable to connect to the simulated corporate VPN.
VPN profile:
Northstar-VPN
Incorrect endpoint:
192.0.2.10
Correct documented endpoint:
vpn.northstar.local
Troubleshooting demonstrated:
- Internet baseline testing
- DNS verification
- TCP endpoint testing
- VPN profile analysis
- Configuration correction
Outcome: The incorrect VPN endpoint was identified and corrected.
This lab did not deploy a live VPN concentrator, so it does not claim that a production VPN tunnel was established.
Scenario: Human Resources user can authenticate but cannot access Outlook.
Application error:
OwaUserHasNoMailboxAndNoLicenseAssignedException
Root cause:
Microsoft 365 Business Basic licensing had been removed.
Troubleshooting demonstrated:
- Microsoft 365 user administration
- License validation
- Outlook access troubleshooting
- Microsoft Entra identity validation
- Application error analysis
Outcome: Microsoft 365 Business Basic was reassigned and Outlook access was successfully restored.
Scenario: Operations user can authenticate to Microsoft 365 but cannot access the Company Intranet.
Account state:
- Enabled
- Licensed
- Authentication successful
Root cause:
Missing SharePoint site membership
Troubleshooting demonstrated:
- Authentication vs authorization
- SharePoint membership
- Microsoft 365 access
- Resource permissions
Outcome: User was added to the appropriate SharePoint membership and access was verified.
Scenario: Managed Windows endpoint becomes noncompliant after a security configuration failure.
Endpoint:
INTUNE-WIN-01
Compliance policy:
Northstar Windows Security Compliance
Windows Defender Firewall was intentionally disabled:
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled FalseIntune later reported:
Firewall — Not compliant
Troubleshooting demonstrated:
- Microsoft Intune
- Device compliance
- Windows Defender Firewall
- PowerShell
- Endpoint remediation
- Cloud synchronization
Remediation:
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled TrueOutcome: Firewall security was restored and the endpoint returned to compliant status.
Scenario: User cannot complete expected MFA authentication because no usable authentication method is available.
Affected user:
Emily Brown
Microsoft Entra Authentication Methods showed:
No usable methods
Troubleshooting demonstrated:
- Microsoft Entra Authentication Methods
- MFA
- Microsoft Authenticator
- Sign-in logs
- Authentication verification
Outcome: Microsoft Authenticator was registered and a successful MFA-protected sign-in was verified.
Scenario: Suspicious failed authentication activity requires investigation.
Affected user:
Gayla Geimer
Microsoft Entra error:
50126
Invalid username or password
Sign-in information reviewed:
Location: Minneapolis, Minnesota, United States
IP Address: 24.7.210.28
ASN: 7922
Investigation included:
- Failed sign-in analysis
- Successful sign-in comparison
- IP address review
- Geographic location review
- MFA validation
- Credential remediation
- Session revocation
- Microsoft Entra audit logs
Containment actions:
- Password updated
- Microsoft Authenticator configured
- MFA verified
- Sessions revoked
Audit activity included:
Update StsRefreshTokenValidFrom Timestamp
Status: Success
Conclusion:
Suspicious failed authentication activity investigated.
No confirmed account compromise established from available evidence.
Outcome: Fresh MFA-protected authentication succeeded after containment.
Scenario: Microsoft 365 access is blocked because a managed Windows endpoint does not satisfy a Conditional Access compliance requirement.
Affected user:
Naomi Caetano
Endpoint:
INTUNE-WIN-01
Conditional Access policy:
INC-010 Require Compliant Device
Grant control:
Require device to be marked as compliant
Windows Defender Firewall Disabled
↓
Intune Compliance Failure
↓
Device Noncompliant
↓
Conditional Access Requirement Not Satisfied
↓
Microsoft 365 Access Blocked
Microsoft Entra recorded:
Error: 53000
Conditional Access showed:
Policy: INC-010 Require Compliant Device
Result: Failure
Grant Control: Require compliant device
Result: Not satisfied
Windows Defender Firewall was restored.
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled TrueAdditional troubleshooting included:
- Windows Security
- Windows services
dsregcmd /status- Intune enrollment
- EnterpriseMgmt scheduled tasks
- OMA-DM
- Microsoft Intune MDM certificate
- Windows Device Management event logs
The existing enrollment was investigated before attempting destructive re-enrollment.
Microsoft Intune eventually reported:
Northstar Windows Security Compliance — Compliant
Firewall — Compliant
A fresh authentication then showed:
INC-010 Require Compliant Device
Result: Success
Microsoft 365 access succeeded.
Root cause:
Windows Defender Firewall was disabled, causing Intune noncompliance.
Conditional Access correctly blocked Microsoft 365 access because the
endpoint did not satisfy the required compliance state.
| Incident | Issue | Root Cause | Technologies |
|---|---|---|---|
| INC-001 | Password access | Password reset required | Entra ID, M365 |
| INC-002 | Sign-in blocked | Account disabled | Entra ID, Sign-In Logs |
| INC-003 | DNS failure | Incorrect DNS server | Windows, DNS, PowerShell |
| | INC-004 | VPN timeout | Incorrect VPN endpoint | Windows, VPN | | INC-005 | Outlook inaccessible | Missing M365 license | Microsoft 365, Outlook | | INC-006 | SharePoint denied | Missing site membership | SharePoint, Entra ID | | INC-007 | Device noncompliant | Firewall disabled | Intune, Windows | | INC-008 | MFA failure | No usable MFA method | Entra ID, Authenticator | | INC-009 | Suspicious sign-in | Failed credentials investigated | Entra ID, MFA, Audit Logs | | INC-010 | M365 blocked | Device noncompliance | Intune, Entra ID, Conditional Access |
The repository contains eight technical documentation guides that explain the environment and troubleshooting methodology in greater depth.
Architecture, platforms, users, devices, technology relationships, and capstone design.
Microsoft Entra ID, authentication, MFA, Conditional Access, sign-in logs, audit logs, and authorization.
Microsoft Intune, Windows 11, compliance policies, MDM enrollment, endpoint security, certificates, OMA-DM, and device troubleshooting.
TCP/IP, DNS, VPN, HTTPS connectivity, PowerShell networking tools, and layered network troubleshooting.
Microsoft 365 administration, licensing, Outlook, SharePoint, authentication, authorization, and cloud access.
Suspicious sign-in investigations, MFA, session revocation, Conditional Access, endpoint security, and evidence-based security analysis.
PowerShell diagnostics, Windows administration, networking commands, endpoint checks, MDM troubleshooting, and repeatable technical verification.
ServiceNow incident lifecycle, triage, work notes, root-cause analysis, resolution, escalation awareness, and verification.
The project follows a consistent troubleshooting process.
1. Identify the user and reported symptom
2. Determine affected device / service
3. Establish a known-good baseline
4. Reproduce the issue
5. Collect technical evidence
6. Review logs and configuration
7. Isolate the failing technical layer
8. Identify the root cause
9. Apply targeted remediation
10. Retest the original failure
11. Verify administrative state
12. Verify user access
13. Document work notes
14. Record root cause and resolution
15. Resolve the incident
The project distinguishes between a symptom and the actual cause.
User symptom:
"I can't access Outlook."
Root cause:
Microsoft 365 Business Basic license was missing.
User symptom:
"I can't access SharePoint."
Root cause:
User lacked required site membership.
User symptom:
"Microsoft 365 says my device must comply."
Root cause:
Windows Defender Firewall was disabled, causing Intune noncompliance
and triggering the Conditional Access compliant-device requirement.
The capstone demonstrates that successful authentication does not automatically grant access to every resource.
Authentication
Who are you?
vs.
Authorization
What are you allowed to access?
INC-006 demonstrates a user who could authenticate successfully but lacked SharePoint authorization.
Endpoint troubleshooting also demonstrated that local Windows state and cloud management state may update at different times.
Example:
Windows Firewall Restored
↓
Windows Security Healthy
↓
Intune Still Temporarily Reports Noncompliant
↓
MDM Processing
↓
Intune Compliance Updates
↓
Conditional Access Receives New State
↓
Access Restored
This was a major troubleshooting component of INC-010.
The project uses evidence-based security conclusions.
A failed authentication attempt is not automatically treated as proof that an account was compromised.
Investigation includes:
- Failed sign-ins
- Successful sign-ins
- Error codes
- IP address
- Geographic location
- MFA
- Audit logs
- Session activity
The principle demonstrated is:
Suspicious activity ≠ confirmed compromise
PowerShell was used throughout the project for diagnostics and remediation.
Examples include:
Get-NetFirewallProfile | Select-Object Name,EnabledSet-NetFirewallProfile -Profile Domain,Private,Public -Enabled TrueGet-NetIPConfigurationResolve-DnsName microsoft.comTest-NetConnection 1.1.1.1 -Port 443Get-Service MpsSvc,wscsvc,SecurityHealthService |
Select-Object Name,Status,StartTypedsregcmd /statusGet-ScheduledTask |
Where-Object {$_.TaskPath -like "\Microsoft\Windows\EnterpriseMgmt\*"} |
Select-Object TaskPath,TaskName,StateGet-WinEvent `
-LogName
"Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin"
`
-MaxEvents 25Every incident follows an enterprise-style ITSM process.
Incident Created
↓
User / Service Identified
↓
Impact Reviewed
↓
Troubleshooting Performed
↓
Work Notes Added
↓
Root Cause Identified
↓
Remediation Applied
↓
Resolution Verified
↓
Resolution Notes Added
↓
Incident Closed
The repository contains 109 screenshots organized by technology.
Screenshots/
├── Entra-ID/
├── Intune/
├── Microsoft-365/
├── Networking/
├── PowerShell/
├── ServiceNow/
└── SharePoint/
Evidence includes:
- ServiceNow tickets
- Failed authentication
- Sign-in logs
- Audit logs
- Microsoft 365 errors
- SharePoint permissions
- Intune compliance
- Conditional Access
- Windows Security
- PowerShell diagnostics
- Network testing
- Post-remediation verification
Enterprise-IT-Support-Capstone/
│
├── README.md
│
├── .gitignore
│
├── Documentation/
│ ├── 01-Environment-Overview.md
│ ├── 02-Identity-and-Access.md
│ ├── 03-Endpoint-Management.md
│ ├── 04-Network-Infrastructure.md
│ ├── 05-Microsoft-365.md
│ ├── 06-Security-Operations.md
│ ├── 07-Automation.md
│ └── 08-Incident-Management.md
│
├── Help-Desk-Tickets/
│ ├── INC-001-Password-Reset.md
│ ├── INC-002-Account-Lockout.md
│ ├── INC-003-DNS-Failure.md
│ ├── INC-004-VPN-Failure.md
│ ├── INC-005-M365-License.md
│ ├── INC-006-SharePoint-Access.md
│ ├── INC-007-Device-Compliance.md
│ ├── INC-008-MFA-Failure.md
│ ├── INC-009-Suspicious-Sign-In.md
│ └── INC-010-Conditional-Access-Compliance.md
│
└── Screenshots/
├── Entra-ID/
├── Intune/
├── Microsoft-365/
├── Networking/
├── PowerShell/
├── ServiceNow/
└── SharePoint/
- Help Desk Support
- Technical Support
- Incident Management
- Troubleshooting
- Root-Cause Analysis
- User Support
- Technical Documentation
- Escalation Awareness
- Microsoft 365
- Microsoft Entra ID
- Microsoft Intune
- SharePoint Online
- Microsoft Authenticator
- Conditional Access
- IAM
- User Administration
- Password Resets
- Account Enablement
- MFA
- Authentication Methods
- Sign-In Logs
- Audit Logs
- Session Revocation
- Authorization Troubleshooting
- Windows 11
- Microsoft Intune
- Device Enrollment
- Device Compliance
- Windows Defender Firewall
- Windows Security
- MDM
- OMA-DM
- Endpoint Troubleshooting
- TCP/IP
- DNS
- VPN
- HTTPS
- TCP Port Testing
- Name Resolution
- Connectivity Troubleshooting
- PowerShell
- Windows Services
- Scheduled Tasks
- Windows Registry
- Certificates
- Event Logs
A password reset is not the correct fix for every authentication problem.
Error codes, logs, endpoint status, and application behavior should guide troubleshooting.
Avoid unrelated changes when the root cause has already been identified.
If Conditional Access correctly blocks a noncompliant endpoint, repair the endpoint rather than weakening the policy.
A successful administrative change is not enough.
The user's original workflow must succeed again.
A complete support incident should answer:
What happened?
What was tested?
What was found?
What caused it?
What was changed?
How was the fix verified?
This capstone demonstrates practical enterprise-style support across:
ServiceNow
+
Microsoft 365
+
Microsoft Entra ID
+
Microsoft Intune
+
SharePoint
+
Windows 11
+
PowerShell
+
Networking
+
MFA
+
Conditional Access
+
Security Operations
Across 10 documented incidents, 8 technical guides, and 109 screenshots, the project demonstrates the ability to:
- Triage user issues
- Troubleshoot across multiple platforms
- Interpret logs and error codes
- Isolate technical failures
- Identify root causes
- Apply targeted remediation
- Verify service restoration
- Document incidents through an ITSM workflow
This repository is a personal simulated enterprise IT support lab created for hands-on learning and portfolio demonstration.
The organization, users, incidents, and support scenarios are fictional.
The project does not represent production administration of a real company environment or real customer data.