Microsoft 365 & Azure Administrator (L2)

Gargash Group

Dubai

On-site

AED 150,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Gargash Group is seeking an experienced cloud administrator to oversee day-to-day Microsoft 365 and Azure operations. The role ensures secure by default configuration, proper licensing, and thorough documentation aligned with security and compliance standards.

You will manage Exchange Online, SharePoint/OneDrive, Teams, Intune, Entra ID, and Azure resources while collaborating with Cybersecurity and Governance teams to maintain identity hygiene and operational resilience.

Qualifications

  • 5+ years hands-on experience administering Microsoft 365 and Azure in a production enterprise environment.
  • Deep practical knowledge of Entra ID (Azure AD), Exchange Online, SharePoint Online, Teams, OneDrive, and Intune / Endpoint Manager.
  • Experience with Azure IaaS, PaaS, networking, storage, Key Vault, Backup, and Monitor.
  • Experience implementing security controls and compliance actions across Microsoft 365/Azure.

Responsibilities

  • Administer the Microsoft 365 tenant day-to-day (Exchange Online mailboxes, distribution lists, mail flow, retention).
  • Manage Intune / Endpoint Manager configuration: device enrollment, policies, deployment, and conditional access integration.
  • Operate Microsoft Purview controls with Cybersecurity and Risk & Governance on DLP, retention, sensitivity, and eDiscovery.
  • Maintain tenant hygiene: unused mailboxes, shared mailbox sprawl, orphaned guest accounts, stale sites.
  • Administer Entra ID: user lifecycle, groups, app registrations, and service principals.
  • Implement and maintain Conditional Access policies and MFA, and sign-in risk policies.
  • Operate PIM for just-in-time elevation and conduct access reviews.
  • Support migration from on-premises AD to Entra ID with hybrid identity sync.
  • Administer Azure subscriptions, resource groups, and governance.
  • Provision and maintain Azure IaaS (VMs, storage, networking) and PaaS per architecture.
  • Manage Azure Key Vault and lifecycle of secrets, keys, certs; integrate with apps.
  • Configure and monitor Azure Backup, Site Recovery, disaster recovery for in-scope workloads.
  • Use Azure Monitor, Log Analytics, and cost-management tools to track health and spend.
  • Administer licences across Microsoft 365/Azure; monitor consumption vs entitlement.
  • Operate Defender consoles in coordination with Cybersecurity; respond to alerts per SLAs.
  • Support ISMS, audits, and incident-response actions with security configurations.
  • Maintain documentation of tenant config, Azure architecture, runbooks, and SOPs.
  • Collaborate with Cybersecurity, Applications, and EA teams; liaison with Microsoft and licensing partners.

Skills

Microsoft 365 administration
Azure administration
Entra ID / Azure AD
Intune / Endpoint Manager
Exchange Online management
SharePoint Online & OneDrive
Teams policies & voice config
Security & Compliance operations
PIM and access reviews
Identity & access management

Tools

Azure IaaS & PaaS
Azure Monitor / Log Analytics
Key Vault
Backup & Site Recovery
Cost management tooling
Microsoft Defender

Job description

About the Role

This is a hands-on technical role responsible for the day-to-day administration, operational stability, and security posture of the Group’s Microsoft 365 tenant and Microsoft Azure environment. The role holder will ensure that the tenant and cloud environment are administered to a professional standard, secure by default, licensed correctly, fully documented, and aligned with Group security and compliance requirements.

Responsibilities
  • Microsoft 365 Administration
  • Administer the Microsoft 365 tenant on a day-to-day basis, including Exchange Online (mailboxes, distribution lists, mail flow, transport rules), SharePoint and OneDrive (sites, sharing policies, retention), and Microsoft Teams (teams, channels, policies, voice configuration where applicable).
  • Manage Intune / Endpoint Manager configuration: device enrolment, compliance policies, configuration profiles, application deployment, and conditional access integration.
  • Operate Microsoft Purview controls in coordination with Cybersecurity and Risk & Governance — data loss prevention, retention labels, sensitivity labels, eDiscovery requests.
  • Maintain tenant hygiene: unused mailboxes, shared mailbox sprawl, orphaned guest accounts, stale Teams and SharePoint sites.
  • Identity & Access Management
  • Administer Entra ID (Azure AD): user lifecycle, group management, application registrations, enterprise applications, service principals.
  • Implement and maintain Conditional Access policies, MFA enforcement, sign-in risk policies, and named locations in line with the Group security baseline.
  • Operate Privileged Identity Management (PIM) for just-in-time elevation of administrative roles; conduct periodic access reviews.
  • Support the migration from on-premises Active Directory to a cloud-native Entra ID environment, including hybrid identity synchronisation and the phased decommissioning of legacy domain controllers.
  • Partner with the Cybersecurity and Applications teams on identity and access management, maintaining identity hygiene across the estate.
  • Administer Azure subscriptions, resource groups, and management groups under the Group’s tenant governance model.
  • Provision, configure, and maintain Azure IaaS (virtual machines, storage, networking) and PaaS services in line with architectural standards set with the Enterprise Architect.
  • Operate Azure Key Vault — secret, key, and certificate lifecycle management, access policies, and integration with application teams.
  • Configure and monitor Azure Backup, Site Recovery, and disaster-recovery components for in-scope workloads, sharing the backup and recovery support load with the Cybersecurity, Applications, and Infrastructure teams.
  • Use Azure Monitor, Log Analytics, and cost-management tooling to track resource health, utilisation, and spend.
  • Licensing & Cost Control
  • Administer licence assignment across the Microsoft 365 / Azure estate, including group-based licensing where appropriate.
  • Maintain an accurate, evergreen view of licence consumption versus entitlement under the EA and any CSP arrangements; flag over- and under-utilisation.
  • Track Azure consumption against budget and reservation commitments; raise variances to the Head of Technology Service Delivery and Enterprise Architect.
  • Support the annual EA true‑up and renewal cycle with data, reconciliation, and recommendations.
  • Security & Compliance Operations
  • Operate Microsoft Defender (Endpoint, Identity, Office 365, Cloud) consoles in coordination with the Cybersecurity team; action alerts within agreed L2 scope and elevate as required.
  • Support the Cybersecurity function with tenant‑side configuration changes required by ISMS, audit, or incident-response activity.
  • Maintain hardening baselines for tenant configuration in line with Microsoft Secure Score and CIS benchmarks; track drift and remediation.
  • Participate in vulnerability remediation, patching, and configuration-change activity affecting Microsoft cloud workloads.
  • Service Operations & Incident Response
  • Act as second-line escalation for service desk tickets relating to Microsoft 365 and Azure services; resolve incidents within agreed SLAs.
  • Participate in problem management — root‑cause analysis for recurring incidents, with documented remediation.
  • Execute changes through the Group change‑management process; produce implementation, test, and rollback plans.
  • Contribute to major incident response on‑call rotation as agreed with the Head of Technology Service Delivery.
  • Documentation & Knowledge
  • Maintain accurate, current documentation of tenant configuration, Azure architecture, runbooks, and standard operating procedures.
  • Produce knowledge‑base articles and self‑service guidance to deflect repeat L1 tickets.
  • Support audit and assurance activity (internal audit, ISMS, OEM and regulatory reviews) with evidence packs on demand.
  • Cross‑Functional Collaboration
  • Work closely with the Cybersecurity, Risk & Governance, Applications, and Enterprise Architecture functions to ensure tenant and cloud changes are reviewed, approved, and aligned to Group standards.
  • Engage directly with Microsoft (account team, FastTrack, support) and the Group’s licensing reseller to maximise value from existing agreements.
  • Coordinate with business units’ technology liaisons on tenant‑affecting changes and major rollouts (Teams Phone, new SharePoint estates, and similar).
Qualifications
  • Minimum 5 years of hands‑on experience administering Microsoft 365 and Microsoft Azure in a production enterprise environment.
  • Deep practical knowledge of Entra ID (Azure AD), Exchange Online, SharePoint Online, Teams, OneDrive, and Intune / Endpoint Manager.
  • Demonstrable Azure administration experience covering IaaS, PaaS, virtual networking, storage, Key Vault, Backup, and Monitor.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Systems Administrator
Systems Administrator

YOSH HOSPITALITY LLC OPC • Abu Dhabi

On-site
AED 120,000 - 180,000
System Administrator
System Administrator

Confidential Company • Dubai

On-site
AED 180,000 - 240,000
Senior Microsoft 365 & Azure Administrator
Senior Microsoft 365 & Azure Administrator

Gargash Group • Dubai

On-site
AED 150,000 - 230,000
Lead Infrastructure & Cloud Engineer at Qode
Lead Infrastructure & Cloud Engineer at Qode

Qode • Dubai

On-site
AED 380,000 - 520,000
Digital Workplace 365 Architect
Digital Workplace 365 Architect

VDart Digital • Abu Dhabi

On-site
AED 350,000 - 550,000
MS Security Specialist
MS Security Specialist

R3 Consultant • Dubai

On-site
Professional development
Azure Cloud Architect
Azure Cloud Architect

Good co India • United Arab Emirates

On-site
AED 350,000 - 700,000
Cloud Security Specialist
Cloud Security Specialist

iConnect IT Business Solutions DMCC • Dubai

On-site
AED 300,000 - 420,000
Cloud Security Engineer
Cloud Security Engineer

Confidential • Dubai

Hybrid
AED 350,000 - 550,000
TECHNICAL LEAD - Wintel Administration
TECHNICAL LEAD - Wintel Administration

Happiest Minds Technologies • Dubai

On-site
AED 180,000 - 240,000