League Desk

A working operations notebook for a part-time league service role, built on a home Windows domain that syncs to Microsoft Entra ID and is managed by Intune. It tracks league schedules, a work queue, follow-ups and a time clock, and doubles as hands-on proof of Active Directory, SQL Server, ServiceNow, Entra ID and Intune skills.

Status Built, Personal Use

Every milestone verified live. Time with the tool is still being recorded, so no time saving is claimed.

Build Type Solo

Design, lab build, app, integrations, identity tenant, reporting and testing.

Primary Focus

Windows infrastructure, identity and device management, SQL Server, and a service desk integration.

Project Overview

Purpose: League Desk runs on a home Windows domain that syncs to Microsoft Entra ID and is managed by Intune. It keeps each league's schedule, the work due before its next night, the questions that come up each week and the hours spent, in one place.

What was builtSix parts, from the lab servers up to the reporting layer.
PartWhat it is
Hyper-V labFour servers (domain controller, SQL Server, application server, kiosk) on one isolated lab network, built and rebuilt from PowerShell scripts with Pester tests.
Node and Express appRuns as a Windows service, reads and writes SQL Server over Kerberos with a least-privilege account, and holds 15 league schedules, a work queue, follow-ups and a time clock.
ServiceNow integrationAn Escalate action creates an incident through the Table API, retries safely and reads the state back. A five-article knowledge base is published.
Microsoft 365 tenantCloud Sync from Active Directory, Intune compliance on Windows, macOS and iOS (three devices enrolled and verified Compliant), and the app reached from a phone through Entra Application Proxy behind MFA.
Power BI dashboardBuilt on five read-only SQL views that show league aliases instead of names.
Quality gates278 Node tests, 449 Pester tests and a repository verifier, all green, plus a live check for every milestone.

Baseline: A baseline of 6 hours 45 minutes a week is recorded. Any effect on that time is measured later and is not claimed here.

Architecture

A phone request signs in to Entra and meets MFA, passes the Application Proxy, and reaches the app server through the connector, which reads SQL Server with Kerberos. A MacBook reached the same app through a WireGuard tunnel to the host, and ServiceNow is called only when an escalation is made. Power BI Desktop on the host reads five read-only views of the same SQL Server through a read-only Windows account.

A phone request passes Entra and MFA before it reaches the lab Three columns. Devices: an iPhone and a MacBook Air. Cloud services: Entra ID with Conditional Access, Application Proxy, a ServiceNow instance and Intune. Home lab on Hyper-V: a domain controller, the app server, the database server and a kiosk. A phone request passes Entra and MFA before it reaches the lab Devices Cloud services Home lab (Hyper-V) iPhone Enrolled, MFA MacBook Air Enrolled, WireGuard Entra ID Conditional Access: MFA Application Proxy Pre-auth, one group ServiceNow instance Table API over HTTPS Intune Compliance policies Domain controller AD, DNS, sync agent App server Node app, proxy connector Database server SQL Server 2022, SSRS Kiosk Hybrid joined Cloud Sync connector enrol enrol
Devices on the left, Microsoft cloud services and ServiceNow in the middle, the Hyper-V lab on the right. The app server is highlighted.

Skills Demonstrated

Every row points to something that was checked: a script, a test run or a captured screenshot.

Skills and evidenceWhat was done in each area, and how it was verified.
Skill areaWhat was doneEvidence
Active Directory and Group PolicyBuilt a domain with OUs, groups, delegated password reset and kiosk lockdown GPOs; later added a UPN suffix and a GPO for Intune enrolment.Live state check passes; delegated reset and lockdown tested; GPO values read back.
PowerShell automationScripted VM builds, directory setup, backups, a credential store, firewall rules and a Graph report, all with a preview mode and exit codes.449 Pester tests whose stubs enforce real parameter sets; a repository verifier.
SQL Server and SSRSPinned schema, stored procedures, Agent jobs, a least-privilege role and a Weekly Recap report.Verifier scripts (14, 21 and 46 checks); backup and restore drill.
Windows services and app hostingNode app as a Windows service with delayed start, crash recovery, a scoped firewall rule and Kerberos to SQL.Crash recovery under 12 seconds; survives a restart with nobody signed in.
ServiceNow administration and RESTDeveloper instance, integration user, scoped app, a Table API client with timeouts, a circuit breaker and idempotent retries, and a knowledge base.Live incident created, retried and read back; five published articles.
Entra ID and Cloud SyncVerified a subdomain with one DNS record, synced by OU, kept admins out of the cloud and added device sync.Agent healthy; provision-on-demand results; scoping filters captured.
IntuneApple MDM push certificate, compliance policies for Windows, macOS and iOS, and enrolment of three devices.All three devices showed Compliant in the Intune device list.
Conditional Access and Application ProxyPublished the app through a connector, restricted it to one group and required MFA.Phone sign-in on cellular; the sign-in log listed the policy with Success.
Microsoft GraphA read-only device health report with delegated consent and minimal scopes.Two clean live runs; report with no personal identifiers.
Power BI and reportingFive read-only SQL views that show league aliases instead of names and carry no free text or contacts, read by Power BI Desktop through a least-privilege Windows identity; a one-page dashboard.26 live checks passed; the dashboard export was checked for league names before it was used.

Usage

How the app is used week to week.

  • Nightly work. After a league bowls, a nightly job creates the work due before its next night: enter, print (with each league's copy count), email or verify.
  • One Work Queue. All open work sits on one list, overdue first, with the days late written out. Anything unfinished stays on the list.
  • Follow-ups. Questions that come up, such as bad handwriting, missing sheets or rule queries, are logged and tracked until resolved. One can be escalated to ServiceNow with a single button.
  • Time clock. A clock records when work starts and ends. Weekly totals sit beside the 6 hour 45 minute baseline.
  • Access. The app is reached from a laptop over a private tunnel, or from a phone through the published address behind MFA.
  • Dashboard. A read-only Power BI dashboard shows weekly hours, open work, follow-ups and printing workload.

Preview

One-page Power BI dashboard: weekly hours as columns with a line at the 6 hour 45 minute baseline, counts of open work, follow-up counts, and printing workload by league alias
The dashboard, with league names replaced by aliases. The baseline weeks are shown against the 6 hour 45 minute average; later weeks are still accumulating, so no saving is shown.

Usage figures from the tool (hours a week, items closed, days late) will be added once there are enough weeks of clock-ins.

Context: The Problem and the Goals

The work is real and weekly: roughly 6 hours 45 minutes a week (a three-week average from September 2026) spent preparing score sheets and standings, chasing follow-ups and tracking which league needs what before its next night. The same project is also the hands-on evidence for the skills job applications ask about.

GoalsWhat the tool had to do, and what the build had to prove.
GoalIncludes
What the tool must do
  • Give each league a schedule (day, start time, bye weeks) and show the work due before its next night.
  • Log weekly questions and follow them until resolved, with a safe path to escalate to a manager or IT.
  • Run from a phone, over a path that is reachable and protected.
What the build must prove
  • Active Directory and Group Policy, PowerShell automation with tests, SQL Server and SSRS.
  • ServiceNow administration and REST integration.
  • Entra ID, Intune, Conditional Access and Application Proxy in a working tenant.

Data boundary: The system stores only the owner's own schedules, notes, tasks, follow-ups, timers and officer contacts. It holds no participant names, scores or exports from any scoring service.

Tools + Build

Hyper-VWindows Server 2025Active DirectoryGroup PolicyPowerShellPesterSQL Server 2022SSRSNode.jsExpressKerberosWindows ServicesMicrosoft Entra IDEntra Cloud SyncIntuneConditional AccessApplication ProxyMicrosoft GraphServiceNow Table APIPower BIWireGuard

More projects like this

← Back to all projects