We are seeking a skilled Microsoft Entra ID (IAM) & Microsoft 365 Engineer with hands‑on experience in identity and access management, endpoint management, messaging, collaboration, and Microsoft security solutions. The ideal candidate should have strong expertise in Microsoft Entra ID, Microsoft Intune, Exchange Online, SharePoint Online, Microsoft Defender, along with solid networking fundamentals and an understanding of cloud networking concepts.
Key Responsibilities
- Manage user, group, and device lifecycle.
- Configure and administer SSO, MFA, Conditional Access, Identity Protection, and SSPR.
- Manage Enterprise Applications, App Registrations, and Service Principals.
- Implement RBAC and Privileged Identity Management (PIM).
- Configure Identity Governance, including Access Reviews, Entitlement Management, and Lifecycle Workflows.
- Manage B2B collaboration and External Identities.
- Troubleshoot authentication, authorization, and directory synchronization issues.
- Monitor sign‑in logs, audit logs, and identity‑related security events.
- Support Zero Trust identity initiatives.
- Manage Windows, macOS, Android, and iOS devices.
- Configure compliance, configuration, endpoint security, and update policies.
- Deploy applications, scripts, and certificates.
- Troubleshoot device enrolment and policy issues.
Exchange Online
- Manage mailboxes, distribution groups, and shared mailboxes.
- Configure mail flow, transport rules, connectors, and Exchange Online Protection (EOP).
- Troubleshoot email delivery and mailbox‑related issues.
- Manage mailbox permissions, retention, and compliance settings.
SharePoint Online & OneDrive
- Manage SharePoint sites, permissions, and storage.
- Configure external sharing and collaboration policies.
- Administer OneDrive for Business.
- Support governance, retention, and user access management.
- Configure Endpoint Detection and Response (EDR).
- Investigate alerts and security incidents.
- Configure Attack Surface Reduction (ASR) rules.
- Manage Defender Antivirus and Defender for Office 365 policies.
- Perform basic threat hunting using Advanced Hunting.
Candidates should have a clear understanding of networking concepts, including:
- TCP/IP and the OSI model
- DNS, DHCP, NAT, and subnetting
- Routing and switching fundamentals
- HTTP, HTTPS, SMTP, IMAP, POP3, LDAP, and Kerberos
- Firewalls, proxy servers, VPNs, and load balancers
- SSL/TLS and certificate management
- Network troubleshooting using tools such as Ping, Traceroute, Nslookup, Telnet, and Wireshark
- Understanding of hybrid connectivity and cloud networking concepts
- Ability to troubleshoot authentication and connectivity issues between on‑premises and cloud environments
Required Skills
Identity & Access Management
- Conditional Access
- Single Sign‑On (SSO)
- RBAC
- Privileged Identity Management (PIM)
- Identity Governance
- Microsoft Entra Connect / Cloud Sync
- Device Compliance
Microsoft 365
- Exchange Online
- SharePoint Online
- OneDrive for Business
Security
Networking
- TCP/IP and the OSI model
- DNS, DHCP, NAT, and subnetting
- Routing and switching fundamentals
- HTTP, HTTPS, SMTP, IMAP, POP3, LDAP, and Kerberos
- Firewalls, proxy servers, VPNs, and load balancers
- SSL/TLS and certificate management
- Network troubleshooting using tools such as Ping, Traceroute, Nslookup, Telnet, and Wireshark
- Understanding of hybrid connectivity and cloud networking concepts
- Ability to troubleshoot authentication and connectivity issues between on‑premises and cloud environments
Scripting & Automation
- PowerShell
- Microsoft Graph API (preferred)
Preferred Certifications
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- CompTIA Network+
This JD targets a mid-level Microsoft Identity & M365 Engineer with the following approximate focus:
- 15% Exchange Online
- 10% SharePoint Online & OneDrive
- 5% Networking fundamentals and cloud networking concepts
Qualifications
- B.Tech or equivalent
- 6-10 years of experience