Skip to content
View EvanHYearwood's full-sized avatar

Block or report EvanHYearwood

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
EvanHYearwood/README.md

Evan H. Yearwood

IT Systems & IAM Analst @ IntusCare


Portfolio Note

The projects in this portfolio are intentionally designed to simulate the real workflows of an Identity & Access Management (IAM) professional working in enterprise environments.

Each project focuses on practical security tasks such as identity lifecycle automation, RBAC design, access governance, privileged access management, and integration between systems like Active Directory, Okta, and Microsoft Entra ID.

The goal is to demonstrate how a security engineer designs, automates, and manages identity systems at scale, using scripting, identity platforms, and security best practices to enforce consistent access control across hybrid environments.


Identity & Access Management

Workflow Project Proof Purpose Stack Status
SaaS App Integration w/ Okta (SAML) Video & Screenshots Included This lab serves as a pre-requisite step before all proceeding labs. Okta · SAML Complete
Implementing (RBAC) W/ Okta Video & Screenshots Included This lab demonstrates well designed RBAC. AD · Okta · SAML Complete
Automated JML W/ Cert-Based AuthN Video & Screenshots Included This lab automates the JML lifecycle between Active Directory and Okta using RSA-signed JWTs for secure API communication. AD · Okta PowerShell · OAuth 2.0 · RSA · JWT Complete
Entra ID & AD Configuration Screenshots Only In this project I configure a hybrid environment from scratch and create Operational Runbooks for common issues. This includes CA Policies, 3 Applications 2 different AuthN Protocols(OIDC + PKCE and SAML 2.0). I also do implementation testing with Microsoft Graph API, decoding SAML assertions to resolve issues, decoding JWTs to annotates ID/Access tokens, and testing CA enforcement. Active Directory · Entra ID · Entra Connect · Conditional Access · MFA Complete
SSO & SCIM Automation: SaaS Pro/Deprovisioning We'll be integrating SaaS applications with SSO and automates user provisioning and deprovisioning to maintain consistent identity lifecycle across systems. Entra ID · Okta · SAML · OIDC · SCIM In Progress
Access Reviews: Certification and Audit Workflow Here I Simulate periodic access reviews where permissions are approved or revoked, with audit logs generated for compliance and governance. Entra ID · Access Reviews · Audit Logs · CSV Queued
Privileged Access: Just-in-time Role Elevation (PIM) Now I implement a workflow for requesting and granting temporary elevated access with approval and automatic expiration. Entra ID · PIM · Approval Workflow · JIT Queued
Identity Monitoring: Risky Sign-Ins and Incident Response Finally I'll be Detecting and investigating suspicious login activity using identity logs and automated response mechanisms. Entra ID · Sign-In Logs · Sentinel · KQL Queued

Focus area: Managing identity across hybrid environments. Bridging on-premises Active Directory and cloud platforms like Okta and Microsoft Entra ID. Projects cover the full IAM lifecycle: provisioning, access reviews, privileged access, and offboarding, with PowerShell automation at each stage to reduce manual effort and enforce consistent policy at scale.


2 · IT Support Projects

Help Desk (osTicket)

Project Notes
Prerequisites & Installation ▶ Video included
Post-Installation Configuration ▶ Video included
Ticket Lifecycle & SLAs ▶ Video included

Microsoft Azure / Active Directory

Project Notes
Configuring On-Premises Active Directory within Azure VMs ▶ Video included
Network Security Groups (NSGs) & Network Protocol Analysis Wireshark
Basic DNS Configuration & Testing Azure

03 · Security Projects

Project Focus
Internal Security Audit — Botium Toys Risk assessment · audit evidence · mitigation
Python Algorithm — User Access Management Scripted RBAC logic
SQL Security Investigation — Login & Machine Access Patterns Threat analysis · access logs
Linux — Enforcing Least Privilege via File Permissions Hardening · principle of least privilege

04 · Certifications

Earned

MS-900 View

Google Cyber

SBT

HTB

In Progress

AZ-900

Queued

AZ-800 SC-900 SC-300 Okta Pro Sec+ Postman


Connect on LinkedIn

Pinned Loading

  1. EvanHYearwood EvanHYearwood Public

    3 2

  2. configure-ad configure-ad Public

    3

  3. osticket-prereqs osticket-prereqs Public

    1 2