I build secure and practical systems where enterprise operations, identity infrastructure and software architecture meet.
My background is in operating and designing business-critical infrastructure, with a strong focus on Active Directory, Identity & Access Management, PKI, authentication and automation. I enjoy turning operational problems into tools, services and architectures that are understandable, maintainable and useful in the real world.
- Identity and Access Management
- Active Directory and Windows infrastructure
- Privileged Access Management
- PKI, certificates and secure authentication
- PowerShell and infrastructure automation
- ASP.NET Core, Blazor and C#
- REST APIs and service-oriented architectures
- Technical product design and architecture
- Enterprise operations and operational resilience
A modern web application for managing temporary privileged access in Active Directory using the PAM optional feature and time-limited group memberships.
The project combines:
- ASP.NET Core and Blazor
- A separated frontend and backend architecture
- Signed commands and certificate-based trust
- Microsoft SQL Server
- Active Directory integration
- Temporary group memberships using TTL
- Secure deployment with IIS and gMSA
- Auditability and controlled privileged access
The goal is to make native Active Directory privileged access easier to operate without hiding the underlying security model.
The project is currently under active development.
I originally developed an ioBroker adapter that connects Ă–koFEN Pelletronic heating systems through their JSON interface.
The project was later transferred to the ioBroker community organization and continues to be maintained there.
I have built reusable PowerShell modules and templates for Windows infrastructure administration, including Microsoft DNS automation and module development.
I am most interested in systems that have to work outside a demo environment:
- secure by design
- understandable for operators
- resilient during incidents
- automated without becoming opaque
- maintainable by teams, not only individuals
I do not see architecture, operations and development as separate worlds. Good solutions connect all three.
Identity & Infrastructure
Development & Automation
Platforms & Operations
I like experimenting with home automation, renewable energy systems, electronics and self-hosted infrastructure. Many of my projects begin with a simple question:
Why does this have to be so complicated?
And sometimes that question turns into software.


