New York, NY · Open to remote
Brandon Sardelli
Go Live Engineer | Modern Work & Post-Sales Enablement
5+ years in Microsoft cloud and endpoint engineering. Own go-live delivery from deal close through enablement and handoff. Focused on Intune-centered partner onboarding, post-sales training, and internal tooling that improves partner readiness and growth.
200+ partner calls and 50+ go-live projects in my first 6 months at Nerdio.

Platforms I work with
Microsoft
Azure
Microsoft Intune
Microsoft Entra ID
Microsoft Defender
Nerdio
What I do
Go-Live & Partner Enablement
Own engagements from deal close through support handoff. Lead discovery, workshops, and Intune-focused education for engineers and leadership.
- Discovery
- Playbooks
- Workshops
- Solution Baselines
- Field feedback
Microsoft Cloud & Endpoint
Intune, Nerdio Manager, Autopilot, Entra ID, Azure Virtual Desktop, Defender for Endpoint, and Microsoft Tunnel across multi-tenant MSP environments.
- Intune
- NMM
- Autopilot
- Entra ID
- AVD
- Defender
- Graph API

Security & Compliance
CIS Level 1/2 benchmark policies, Conditional Access, Secure Score, CMMC mapping, and policy drift management with Nerdio Policy Management.
- Conditional Access
- CIS L1/L2
- Secure Score
- Policy Management
- Power Automate
- PowerShell
Projects
Partner enablement, platform optimization, onboarding, and integration work across multi-tenant Microsoft 365 and Nerdio Manager for MSP environments. Partner details anonymized; outcomes reflect confirmed delivery only.
Brownfield MSP evaluating NMM for Modern Work
Baseline & Onboarding
Stood up Entra and Defender baselines and a repeatable tenant onboarding path for a brownfield MSP.
- NMM
- Entra ID
- Defender for Office 365
- Solution Baselines
- +3 more
View case study →
MSP partner · ongoing optimization engagement
Drift Governance
Operationalized cross-tenant drift monitoring and alerting so an MSP could catch config regressions centrally.
- NMM
- Global Views
- Drift Management
- Conditional Access
- +3 more
View case study →
Multi-tenant Intune MSP · platform optimization
UAM App Standardization
Centralized version-controlled app deployment across Intune tenants with a backup management path.
- NMM
- UAM
- Intune
- Winget
- +3 more
View case study →
Platform optimization · partner-facing enablement content
Decision Enablement
Built source-backed comparison and baseline explainer assets to accelerate partner platform decisions.
- NMM
- Competitive Analysis
- Solution Baselines
- Documentation
- +1 more
View case study →
Internal enablement platform · tooling and automation
Knowledge MCP
Built an internal knowledge server that turns scattered inputs into structured, reusable enablement answers.
- MCP Server
- Knowledge Base
- Automation
- NMM
- +2 more
View case study →
Internal platform for Nerdio's Go-Live Engineers
GLE Utility Belt
Internal platform where a GLE generates a customer onboarding plan and shares it as a single secure link — no login, no attachment.
- TypeScript
- React
- Hono
- Azure App Service
- +3 more
View case study →
Experience

Go Live Engineer (Modern Work focus) at Nerdio
- Own go-live projects from deal close; align scope with Sales, PSMs, and Partners; run structured engagements from kickoff through support handoff.
- Deliver Intune-focused partner education for Senior Systems Engineers, C-level suites, technical engineers, and post-sales technical staff; lead workshops on baselines, policies, and operational execution.
- Onboard MSP partners to Nerdio Manager across multi-tenant environments; configure tenant integrations (Intune, Defender, Exchange, SharePoint), prerequisites, and API permissions.
- Run kickoff and communication workflow: create project collaboration channels, share meeting links and documentation, capture call summaries, and maintain active feedback loops with PSMs and partners.
- Lead discovery using standardized qualification questions on RMM/EDR stack, Microsoft licensing, Intune maturity, onboarding workflows, and security baseline readiness.
- Guide policy rollout using Solution Baselines and Nerdio Policy Management: report-only staging, drift review, allow processing, enforcement planning, version control, and drift detection.
- Deploy CIS Level 1 and Level 2 Intune benchmark policies and support baseline standardization across partner tenants.
- Build enablement assets including Empower Your Helpdesk, First 30 Days with NMM (12-module guide), and M365 Partner Enablement Checklist; design a 10-module go-live playbook.
- Build GLE Engagement Plan tool (session selector, HubSpot booking, scope/quote PDFs) and pilot engagement plans with partners to map call topics and onboarding sequence.
- Power Automate flows for Microsoft Teams: provision channels, post messages, and partner communications—templated automation scaled to thousands of MSP partners.
- Configure RBAC roles, Graph API permissions, and Defender/Secure Score integrations with least-privilege access.
- Build recipe-based engagements for Autopilot V2, LAPS, Conditional Access, Update Rings, Unified Catalog, and Scripted Actions to support greenfield and brownfield deployments.
- Launch release-campaign cadence for major platform updates with internal planning, partner training, Teams announcements, PSM alignment, and go-live meeting triggers.
- Host 200+ partner calls in first 6 months and guide 50+ projects to completion.
Network Administrator at Centerview Partners · Huntington, NY
- Short-term fill-in supporting infrastructure at a financial services firm with seven offices connected over MPLS/WAN.
- Assisted with endpoint patch cycles and maintenance windows across a mixed on-premises and multi-cloud environment.
- Documented Microsoft Tunnel and Intune configuration patterns for secure hybrid access to on-premises resources.
- Shadowed CCIE-level engineers and the CIO on Azure networking, BGP routing, and WAN/MPLS design across multiple sites.
- Monitored network and endpoint health with WhatsUp Gold; assisted with Cisco updates and endpoint troubleshooting during change windows.
Systems Engineer at Site2
- Managed Intune across 15 multi-tenant customers: device registration (Entra Joined, Hybrid Joined, Registered), Windows Autopilot (V2, device preparation, enrollment restrictions, dynamic groups), Configuration Profiles (Settings Catalog, ADMX), compliance policies, remediation scripts, scope tags.
- Configured Endpoint Security baselines—Defender Antivirus, disk encryption, firewall, Attack Surface Reduction, Endpoint Detection and Response; deployed Conditional Access, Account Protection, Microsoft Tunnel (MAM) on iOS/Android; enabled Remote Help and Endpoint Analytics (audit logs, Log Analytics).
- Deployed Win32, Microsoft Store, LOB, and WinGet applications; authored App Protection Policies; administered Windows Update for Business, Autopatch, and Defender Update Controls across tenants.
- Built and supported Azure Virtual Desktop (single- and multi-session)—VM sizing, image management, Intune integration; executed weekly node updates and patching; migrated 15 customers to Azure data center including AVD and Windows Server upgrades.
- Managed help desk ticket queue and escalations; performed Remote Actions (sync, wipe, retire); troubleshot MDE onboarding (Client Analyzer), device registration (DSREGCMD), ESP; operated ConnectWise RMM (ScreenConnect), 1Password, M365 admin.
- Designed Azure hub-and-spoke with Microsoft engineers—VNets, peering, Azure Firewall, CIS benchmark policies—across 15 customers; configured Entra Connect sync, co-management, Intune connector; administered Cisco CDO, Meraki, FortiGate.
Systems Engineer at Ivionics · Hauppauge, NY
- Supported MSP delivery for legal-industry clients with strict confidentiality, audit, and uptime requirements across Hauppauge and remote offices.
- Deployed Intune and Entra Connect; configured compliance policies, Configuration Profiles, and Conditional Access for hybrid identity and endpoint governance.
- Led AWS-to-Azure migrations using server migration tools and virtual network builds with planned zero-downtime cutovers.
- Executed O365 and cloud mail migrations with endpoint compliance integration across multiple client tenants.
- Administered firewalls, switches, and Meraki wireless with MFA and encryption; owned escalations, SLAs, and backup/DR across hardware, software, and cloud platforms.
Systems Engineer at Arbor Realty Trust · Uniondale, NY
- Led Microsoft Intune MDM and OneDrive rollout at a real estate investment firm—enrolled 700+ devices with white-glove, executive-level end-user support.
- Pushed applications, integrated endpoint posture with Entra ID and Conditional Access, and maintained on-premises device inventory alongside cloud enrollment.
- Optimized Azure Virtual Desktop images and session performance; built Windows images and deployed AVD access on macOS for hybrid workers.
- Resolved MFA resets, OneDrive sync issues, and recurring access problems during a company-wide security hygiene push.
- Monitored Azure Sentinel alerts—verified user location and activity as part of threat detection and response workflows.
Endpoint & MDM Engineer at US Ecology · Great River, NY
- Operated ManageEngine MDM for 1,600+ employees across corporate HQ, field sites, and off-site offices in a regulated environmental services organization.
- Enrolled and supported Windows, iOS, and Android devices; resolved enrollment failures, policy conflicts, and SSO/access issues tied to MDM workflows.
- Contributed to Okta migration planning and execution; aligned mobile device policies with new identity provider requirements.
- Imaged workstations and supported large-scale endpoint transitions with minimal disruption to plant and corporate operations.
- Provided Tier 2 support across Office 365, Citrix VPN, VoIP, printing, and endpoint hardware; documented repeatable workflows for the help desk team.
Contact
Open to Go Live Engineer, partner enablement, and Modern Work roles. Reach out by email or LinkedIn — I typically respond within one business day.