Field Notes & Lab

Notes from
the climb

Each of these started as something I wanted to understand better: a DNS record, a network segment, a gap in my own documentation. Every note covers what I set out to solve, what I did, the technology involved, and what it taught me.

Microsoft 365 Domain & DNS Configuration
Note 01

Microsoft 365 Domain & DNS Configuration

Problem
I wanted to understand exactly how a custom domain connects to Microsoft 365, not by following a setup wizard, but by knowing what each DNS record actually does.
Approach
Set up MX, SPF, DKIM, CNAME and TXT records by hand, watched propagation across resolvers, and traced a mail-flow issue back to a missing autodiscover record.
Technology Used
Microsoft 365DNSCloudflareExchange Online
Outcome
Mail now flows cleanly, and I can explain, record by record, why a Microsoft 365 domain setup works the way it does.
What I Learned
DNS problems are rarely about DNS itself. They are about understanding what each record is telling the next system in line.
UniFi Network Segmentation
Note 02

UniFi Network Segmentation

Problem
My home network had every device on one flat subnet, trusted laptops, guest devices and IoT gear all able to see each other.
Approach
Rebuilt the network in UniFi with separate VLANs for trusted devices, guests and IoT, added firewall rules between them, and configured DHCP and routing per segment.
Technology Used
UniFiVLANsDHCPFirewall Rules
Outcome
Guest and IoT traffic is isolated from anything that matters, and I can see exactly which device sits on which segment.
What I Learned
Segmentation is not just a security setting. It forces you to actually understand how your own network is structured.
Entra ID Access Review
Note 03

Entra ID Access Review

Problem
It is easy to lose track of which accounts, groups and licenses are actually still in use once a Microsoft 365 tenant grows.
Approach
Built a PowerShell and Microsoft Graph script that pulls account status, group membership and license assignment into one list, flagging anything that looks stale.
Technology Used
PowerShellMicrosoft GraphEntra IDMicrosoft 365
Outcome
Cleanup became a short review instead of digging through the admin center one account at a time.
What I Learned
A script is only useful if its output tells you what to do next, not just what exists.
Troubleshooting Runbooks
Note 04

Troubleshooting Runbooks

Problem
I kept re-solving the same DNS and connectivity issues because the fix only existed in my memory from the last time.
Approach
Started writing short runbooks organised by symptom, what to check first, what each result means, and where to look next, covering DNS, UniFi and Microsoft 365 issues.
Technology Used
Technical DocumentationDNSUniFiMicrosoft 365
Outcome
The next time a similar issue shows up, the diagnosis takes minutes instead of starting from scratch.
What I Learned
Writing the runbook down is part of actually solving the problem, not something to do after.
Building a Personal RMM
Note 05

Building a Personal RMM

Problem
Existing remote monitoring tools show a lot of data, but not always the data that matters when something is actually broken.
Approach
Built my own RMM from the ground up, focused on surfacing device status, connectivity and system health in a way that matches how I actually troubleshoot.
Technology Used
RMM DevelopmentPowerShellSystem MonitoringAutomation
Outcome
A monitoring tool shaped around the questions I actually ask when triaging an issue, not a generic dashboard.
What I Learned
Good tooling is less about collecting data and more about deciding what an administrator needs to see first.
UniFi Protect & DNS Filtering Lab
Note 06

UniFi Protect & DNS Filtering Lab

Problem
Device visibility and domain-level control are often treated as the same problem, when they are really answering two different questions.
Approach
Set up UniFi Protect for device adoption, recording and visibility, and layered DNS filtering policy on top to control and categorize domain resolution separately.
Technology Used
UniFi ProtectDNS FilteringDevice VisibilityNetwork Policy
Outcome
A clearer line between what Protect shows me about the network and what DNS filtering controls about it.
What I Learned
DNS filtering is policy, not surveillance. Keeping the two concepts separate makes both easier to configure correctly.
The Lab

Where the next route gets tested

Unfinished, in-progress and deliberately experimental work. The lab is where a technology stops being something I have read about.

Ongoing

Windows & UniFi Home Lab

A home network built around UniFi gear and a small Windows Server domain with joined clients, DNS, DHCP and deliberately broken configurations to learn exactly how each piece depends on the others.

Active

PowerShell Script Shelf

A growing set of small PowerShell scripts for Microsoft 365 reporting, account checks and the repetitive tasks that turned out to be worth automating.

In Progress

Cloudflare & DNS Testing

Testing DNS record changes, propagation behaviour and mail-related records in Cloudflare before anything touches a live Microsoft 365 domain.

Ongoing

Building an RMM

Designing and building my own remote monitoring and management tool from scratch, thinking through what an administrator actually needs to see and how to surface it without noise.

In Progress

UniFi Protect & DNS Filtering

Testing UniFi Protect device adoption and recording alongside DNS-based filtering policy, to understand where network visibility and domain-level control actually overlap.

Wide basecamp ridge valley at dusk
Next Ascent

Curious how one of these was built?

I am glad to talk through the scripts, the DNS setups or the documentation behind any of this work.