Muhammad Afzaal.

Azure cloud & infrastructure · Brooklyn, NY

I build the network, then break it to find out why.

IT professional working across Azure networking, compute, storage and identity. Three infrastructure builds documented end to end — including the failures and what fixed them.

vnet-hub · 10.0.0.0/16 vnet-spoke · 10.1.0.0/16 LB web bastion nsg peer api db nat gw monitor inbound

Segmented network build: peered virtual networks, tiered subnets, load balancer, Bastion and NAT Gateway.

About

I came into IT through an associate degree in IT support, then a B.S. in Information Technology while working through certifications on my own time. Most of what I know about Azure I learned by building things, watching them fail, and working out why.

That's not a figure of speech. On one build, an App Service deployment kept failing with nothing useful in the error output. I went through PowerShell debug logs until I found it was hitting a regional tier quota — then fixed it and wrote it down. The failures are in the repositories alongside the working configurations, because that's the part that actually taught me something.

Alongside the lab work, I've run real client infrastructure: provisioning Azure VMs for a live workload, setting up snapshots and a recovery VM, hosting a site on App Service, and handling domains, DNS and business email — while being the only technical person my client had to call.

Currently
Preparing for AZ-104,
Azure Administrator
Looking for
Cloud support, systems administration, junior cloud engineering
Based in
Brooklyn, New York
Certified
AZ-900 · AWS CCP
A+ · Network+ · Security+

Infrastructure builds

Three Azure environments built from scratch and documented on GitHub — configurations, troubleshooting steps, and what went wrong along the way.

Segmented network infrastructure

Two peered virtual networks with private Ubuntu VMs across separate web, API and database subnets, subnet-level NSGs, Azure Bastion for secure access, a Standard public Load Balancer, Private DNS and NAT Gateway.

Diagnosed NSG priority conflicts, user-defined route misconfiguration and VNet peering failures using Network Watcher, curl and nc — tracing where traffic was actually being dropped rather than guessing.

  • VNet peering
  • NSGs
  • UDRs
  • Bastion
  • Load Balancer
  • Private DNS
  • NAT Gateway
  • Network Watcher
View repository

Multi-OS compute infrastructure

Ubuntu Linux and Windows Server virtual machines running Nginx and IIS, with managed disks, snapshots and Azure Monitor alerting for health and availability.

Configured persistent Linux storage with UUID and fstab so volumes remount correctly across reboots, and tested snapshot recovery rather than assuming it would work.

  • Virtual Machines
  • Managed disks
  • Snapshots
  • Azure Monitor
  • Nginx
  • IIS
  • Windows Server
  • Ubuntu
View repository

Storage and PowerShell automation

Blob Storage and Azure Files configured with enforced TLS, secure transfer and lifecycle management policies, plus PowerShell automation that generates short-lived user delegation SAS tokens for time-limited access.

Traced an App Service deployment failure through debug output and deployment logs to a regional F1 tier quota limit, then resolved it — the troubleshooting is documented in the repository.

  • Blob Storage
  • Azure Files
  • SAS tokens
  • TLS enforcement
  • Lifecycle policies
  • Azure PowerShell
  • App Service
View repository

Technical skills

What I've actually configured, scripted or troubleshot — not a keyword list.

Azure

  • Virtual Machines
  • VNets, subnets, peering
  • NSGs and route tables
  • Load Balancer, Bastion
  • Private DNS, NAT Gateway
  • Network Watcher
  • Blob Storage, Azure Files
  • Managed disks, snapshots
  • App Service
  • Entra ID, SAS tokens
  • Azure Monitor

Systems & scripting

  • Windows Server
  • Windows 10 / 11 support
  • Ubuntu Linux
  • PowerShell automation
  • Azure CLI
  • Bash
  • Nginx, IIS
  • MariaDB
  • Git and GitHub

Networking

  • TCP/IP
  • DNS and DHCP
  • CIDR and subnetting
  • Routing
  • Ports and protocols
  • Connectivity troubleshooting

Support

  • Client-facing technical support
  • DNS records and nameservers
  • Domain transfers
  • Business email administration
  • Web hosting
  • Technical documentation

Experience

2024 — Present

Freelance IT & Cloud Support Specialist

Self-employed · Brooklyn, NY

  • Provisioned and configured an Azure Windows virtual machine for a client business workload, sizing compute and storage against their actual performance and capacity needs.
  • Built a data protection setup using VM snapshots and a secondary virtual machine for recovery.
  • Deployed and hosted a client website on Azure App Service, keeping it publicly available and troubleshooting availability issues as they came up.
  • Managed web hosting, domain transfers, DNS records, nameservers and business email administration — including account access and permissions.
  • Worked directly with clients to gather requirements, resolve technical and account issues, and explain what was happening in language that made sense to them.
  • Set up and managed Google Ads campaigns, including account configuration and ongoing optimisation.

Credentials

Certifications

  • Azure Fundamentals (AZ-900)Microsoft
  • Azure Administrator (AZ-104)In progress
  • AWS Certified Cloud PractitionerAWS
  • CompTIA Security+CompTIA
  • CompTIA Network+CompTIA
  • CompTIA A+CompTIA
  • ITIL FoundationITIL

Education

B.S. Information Technology

Western Governors University · 2026

A.A.S. Computer Information Systems
(IT Support)

Oakland Community College · 2024

Get in touch

I'm looking for roles in cloud support, infrastructure support, systems administration and junior cloud engineering — in New York or remote.