SME - Active Directory Azure Entra ID Microsoft 365
About Role - We are seeking a highly experienced L4 Engineer responsible for designing, managing, and supporting enterprise identity infrastructure across on-prem Active Directory, Microsoft Entra ID, and Microsoft 365. This role involves escalation handling, architecture input,
automation, and security hardening.
Key Responsibilities:
Active Directory (On-Premises)
- Design, deploy, and manage complex Active Directory environments (multi-domain/forest)
- Handle advanced troubleshooting (replication, DNS, Kerberos, Group Policy issues)
- Implement and maintain GPOs, OU structure, and AD delegation models.
- Perform AD health checks, audits, and performance tuning.
- Manage AD disaster recovery, backup, and restore strategies.
Azure Entra ID (Azure AD)
- Manage and configure Microsoft Entra ID
- Configure: Conditional Access Policies, Identity Protection, MFA & Passwordless authentication
- Integrate applications using SSO (SAML/OAuth)
- Troubleshoot sync issues with Azure AD Connect / Entra Connect
Microsoft 365 (O365)
- Administer **Microsoft 365 services: Exchange Online, SharePoint Online, Teams
- Handle complex mail flow, hybrid configurations, and migrations.
- Manage security & compliance - DLP, Retention policies, eDiscovery
- Resolve escalations related to user access, licensing, and service issues
Automation & Scripting
- Automate user provisioning, reporting, and operational tasks Security & Compliance
- Implement Zero Trust principles.
- Monitor identity risks and respond to security incidents.
- Conduct access reviews and privileged identity management (PIM)
L4 / Escalation Responsibilities
- Act as final escalation point (L3/L4) for critical incidents.
- Perform root cause analysis (RCA) and provide permanent fixes.
- Work with Microsoft support for complex issues.
- Mentor L2/L3 engineers and review technical solutions.
Preferred candidate profile
Deep expertise in:
- Active Directory (AD DS, DNS, GPO)
- Microsoft Entra ID
- Microsoft 365
Strong knowledge of:
- Hybrid identity (AD Connect)
- Authentication protocols (Kerberos, OAuth, SAML)
Experience in migrations
- (AD to cloud / O365 tenant migrations)