Cláudio Gonçalves
PT
← Back to Expertise

Automating SCCM Patching Across a 500-User Active Directory

PowerShell automation from the 2013–2018 Server Administrator years standardized SCCM patching and reportedly cut manual work by about 30% — this record states that figure exactly as hedged as its only source.

Automation & DevSecOpsAutomationDevSecOps

Context

As Server Administrator at Angola LNG (2013–2018), I managed Active Directory for 500-plus users, alongside security controls, SCCM patch management, SAP application-server support, and DNS and external domain services — all supporting operations that run around the clock.

Responsibility

Patch compliance and the manual workload across that estate sat with me. The same role also carried the Windows Server 2008/2008 R2 → 2016 migration in 2017 — a large program that had to touch everything at once without stopping a plant that runs 24/7.

Method

I built PowerShell automation to standardize SCCM patching across the AD estate rather than running it system by system — work from the same five-year stretch that also included the full server migration programme.

Constraint

The efficiency figure is one of the only numbers on record from this period, and it's hedged for a reason: I haven't pinned it to a specific year inside the five-year run, and 2014 through 2016 are still one undifferentiated block rather than three confirmed stories. This record states the figure exactly as hedged as the Chronicle itself — automation that reportedly cut manual work by about 30 percent, not a confirmed one.

Result

The same practice — automating technical work rather than repeating it by hand — is what the Automation & DevSecOps pillar names directly today, formalized years later by the SANS Institute's Cloud Security and DevSecOps Automation credential, completed June 2025.

Every detail here already appears, in the same words or close to them, in the Chronicle (the 2014–2017 chapters) and the published CV — nothing new or confidential is added. The efficiency figure carries the same hedge as its only source: "reportedly," not pinned to a specific year.