ABD ABD Labs

Microsoft enterprise lab and technical portfolio

ABD Labs

A public evidence record for Windows administration, identity, Microsoft 365 automation and infrastructure operations work. The lab is being built from documented, repeatable steps, with only sanitized outputs published here.

Current ABD Labs architecture showing the public portfolio on this VPS, a future separate lab compute host, and a later Microsoft cloud lab.

Verified Foundation

The public route is live, the safety boundaries are documented, and lab infrastructure remains unprovisioned until compute and private access are selected.

Live HTTPS portfolio route

`abdlabs.org` serves this static portfolio over TLS, with `www` redirected to the canonical domain.

Documented Architecture boundary

The current VPS hosts public pages only. Windows lab compute is planned for a separate private environment.

Documented Security rules

No public RDP, SMB, LDAP, WinRM, DNS, Kerberos or hypervisor consoles. Published material must be sanitized.

Next Compute decision

The next operational choice is external lab compute, private admin access and storage quota.

Case Study Pipeline

Each case study will include the objective, implementation steps, troubleshooting notes, security decisions and sanitized evidence.

Ready

Portfolio Routing

DNS, nginx, TLS, redirects and renewal checks for the public `abdlabs.org` route.

  • Canonical HTTPS route live.
  • Certificate renewal dry-run completed.
  • Existing mailbox MX records preserved.
Planned

Lab V1 Foundation

External compute selection, private admin path, snapshots and resource quotas before any Windows workloads are created.

Planned

Active Directory Build

DC01, a Windows 11 workstation, OU layout, groups, synthetic users and a first verified GPO.

Planned

PowerShell Automation

Idempotent OU, group, user import and offboarding workflows with dry-run behavior where practical.

Planned

Microsoft 365 And Graph

Cloud identity administration, Graph queries and tenant evidence after licensing and tenant boundaries are approved.

Planned

Tickly Integration

Read-only discovery against synthetic lab data once the lab can produce stable identity and lifecycle signals.

Build Roadmap

The lab is deliberately staged so experiments do not affect current VPS services, SSH access, nginx, PostgreSQL, KONAI or Tickly.

  1. Choose compute and private access. Select external host, local lab host, Azure-first slice or a mixed path before installing a hypervisor.
  2. Provision the first isolated lab network. Create the private subnet, console access, snapshots and resource limits on the approved lab host.
  3. Build Windows Lab V1. Deploy DC01 and WIN11-01, join the domain and validate the first graphical administration workflow.
  4. Automate and document. Recreate OU, group and user setup with PowerShell, then publish sanitized evidence here.

Public And Private Boundaries

The public site should prove work without exposing management paths, production data or tenant material.

Public Safe to publish
  • Sanitized architecture notes and diagrams.
  • Synthetic user and device datasets.
  • Command outputs with secrets and identifiers removed.
  • Lessons learned and troubleshooting narratives.
Private Never public by default
  • !RDP, SMB, LDAP, Kerberos, DNS, WinRM or hypervisor consoles.
  • !Passwords, tokens, private keys or activation material.
  • !Real tenant IDs, customer exports or personal production data.
  • !Raw admin screenshots that reveal sensitive identifiers.