Role & responsibilities
- Serve as the L3 technical escalation and design authority for EUC services.
- Design scalable, secure, supportable, and standardised endpoint-management solutions.
- Engineer and operate Intune, SCCM, Autopilot, Windows servicing, application deployment, and endpoint-security capabilities.
- Diagnose complex incidents and deliver permanent corrective solutions.
- Define technical standards, configuration baselines, test plans, deployment methods, and operating procedures.
- Automate repetitive administration, remediation, reporting, and compliance tasks.
- Lead technical workstreams for migrations, upgrades, service transitions, and modernisation programmes.
- Mentor L1/L2 engineers and improve support-team capability.
- Work closely with security, IAM, network, cloud, service desk, application, and architecture teams.
- Ensure technical documentation and knowledge are complete and current.
Technical Scope
The SME should possess deep expertise in several of the following areas and working knowledge across the wider EUC portfolio:
- Microsoft Intune and Endpoint Manager
- Microsoft Configuration Manager/SCCM
- Windows Autopilot
- Windows 10/11 engineering and lifecycle management
- Application packaging and software distribution
- PowerShell and Microsoft Graph automation
- Microsoft 365 platform services
- Microsoft Entra ID, Conditional Access, MFA, and SSO integration
- Defender for Endpoint and endpoint security controls
- Microsoft Purview, sensitivity labelling, and DLP support
- BitLocker and encryption compliance
- Mobile device and application management
- Virtual desktop platforms
- Active Directory, Group Policy, PKI, and certificates
- Endpoint analytics and user-experience monitoring
- Hardware lifecycle, asset management, CMDB, and software licence data
- ServiceNow and ITIL-aligned operational processes
- Printing, peripherals, remote support, and VIP support dependencies
Key Responsibilities
Solution Design and Engineering
- Translate business and service requirements into technical designs and implementation plans.
- Produce high-level and low-level designs, configuration standards, logical diagrams, build documents, test plans, implementation procedures, and rollback plans.
- Define device-management architecture for corporate, shared, kiosk, privileged, mobile, and BYOD use cases.
- Design co-management, workload migration, or cloud-native endpoint-management approaches.
- Define configuration profiles, compliance policies, security baselines, enrolment restrictions, filters, scope tags, role-based access, and assignment models.
- Design Windows Autopilot profiles and user-driven, pre-provisioned, self-deploying, or shared-device scenarios.
- Define Windows Update for Business rings, feature-update policies, driver-management methods, expedite policies, and deployment controls.
- Ensure designs align with security, IAM, network, application, data-protection, and enterprise-architecture requirements.
These responsibilities align with modern Intune engineering roles covering co-management, Autopilot, compliance profiles, security baselines, update rings, application deployment, and lifecycle management.
Endpoint Management
- Administer and engineer Intune and SCCM environments.
- Manage enrolment, inventory, application delivery, configuration, patching, compliance, reporting, and remediation.
- Design and support collections, queries, boundaries, distribution points, task sequences, deployment types, baselines, and reporting in SCCM.
- Manage MDM, MAM, corporate-owned devices, personally owned devices, and application protection policies.
- Troubleshoot enrolment, synchronisation, policy deployment, application installation, compliance, and Autopilot failures.
- Support tenant, hierarchy, connector, certificate, and integration components.
- Maintain platform health, capacity, role separation, and administrative security.
Windows Engineering
- Design, build, secure, and maintain Windows 10/11 images and provisioning methods.
- Support Autopilot, MDT, DISM, task-sequence, or equivalent deployment approaches where applicable.
- Maintain security hardening, Group Policy, configuration baselines, AppLocker or application-control policies, and local-administrator controls.
- Manage monthly quality updates, feature updates, zero-day remediation, driver updates, and rollback procedures.
- Analyse compatibility and readiness for new Windows versions.
- Support standard, technical, laboratory, manufacturing, kiosk, and shared-device use cases.
- Maintain build, re-image, recovery, and secure-wipe procedures.
Current EUC engineering postings emphasise Windows 11 imaging, Autopilot, MDT, DISM, application packaging, OS patching, endpoint remediation, and compliance.
Application Packaging and Deployment
- Package and deploy Win32, MSI, MSIX, Microsoft Store, line-of-business, and script-based applications.
- Define detection rules, requirement rules, dependencies, supersedence, uninstall methods, return-code handling, and deployment assignments.
- Conduct technical testing for installation, repair, upgrade, rollback, coexistence, and uninstallation.
- Ensure packages support silent installation and removal.
- Assess compatibility with Windows upgrades, security controls, and other enterprise applications.
- Automate packaging and deployment activities where practical.
- Maintain application catalogue, packaging records, deployment versions, and retirement plans.
- Coordinate user acceptance testing and deployment approvals.
Microsoft 365 and Collaboration Services
- Provide engineering and L3 support across Exchange Online, Teams, SharePoint Online, OneDrive, and related Microsoft 365 workloads.
- Support tenant configuration, policy implementation, integration, migration, troubleshooting, and service optimisation.
- Work with IAM teams on Entra ID, authentication, Conditional Access, SSPR, MFA, and hybrid identity.
- Support Microsoft Purview controls, sensitivity labels, DLP, retention, and user-impact troubleshooting.
- Support Microsoft 365 backup and restoration solutions where included in scope.
- Contribute to Microsoft Copilot readiness, data-governance prerequisites, pilot design, and controlled rollout where required.
- Support governance for Power Platform, Microsoft Viva, and related productivity services where applicable.
Current senior EUC architecture roles include Microsoft 365 platform governance, Copilot readiness, Entra ID, Intune, Purview, Power Platform, physical endpoints, mobile platforms, and virtual desktops.
Endpoint Security and Compliance
- Implement and support Defender for Endpoint, antivirus, attack-surface-reduction rules, firewall profiles, web protection, and endpoint-detection controls.
- Configure and maintain BitLocker, recovery-key escrow, encryption reporting, and lost-device evidence.
- Support DLP, Microsoft Purview, secure mail, phishing-related endpoint actions, and related compliance controls.
- Implement Conditional Access device-compliance dependencies.
- Support privileged endpoint management, removal of excessive local-administrator rights, and approved elevation solutions.
- Analyse vulnerabilities and coordinate patching, re-configuration, isolation, or compensating controls.
- Support security incidents, forensic evidence collection, endpoint containment, recovery, and post-incident remediation.
- Ensure technical controls align with Zero Trust principles.
Modern Intune roles increasingly expect Zero Trust-aligned expertise across Entra ID, Conditional Access, Defender for Endpoint, MFA, SSO, passwordless authentication, and endpoint compliance.
Mobile Device Management
- Design and support iOS, Android, corporate-owned, personally owned, fully managed, work-profile, and application-protection scenarios.
- Configure enrolment, compliance, configuration, application, certificate, Wi‑Fi, VPN, and security policies.
- Support selective wipe, full wipe, remote lock, device retirement, and ownership changes.
- Troubleshoot mobile enrolment, application protection, access, synchronisation, and compliance issues.
- Coordinate with telecom providers and OEMs where necessary.
- Support mobile-device audit and compliance reporting.
Virtual Desktop and Remote Access
- Support Azure Virtual Desktop, Windows 365, Citrix, VMware, or equivalent VDI platforms where applicable.
- Design profile, image, application, access, patching, monitoring, and capacity approaches.
- Troubleshoot session, profile, authentication, application, network, and performance issues.
- Support VPN clients, certificates, tokens, remote desktop, and secure remote-access dependencies.
Incident, Problem, and Change Management
- Act as the final technical escalation for complex and high-impact EUC incidents.
- Perform structured diagnosis using logs, traces, telemetry, event data, platform reports, and device analytics.
- Restore service quickly while developing permanent corrective actions.
- Lead technical root-cause analysis and problem-resolution activities.
- Evaluate changes for technical risk, security impact, dependencies, testing, monitoring, and rollback.
- Support major incidents and provide concise technical updates to service leadership.
- Document known errors, workarounds, root causes, and preventive actions.
Automation and Tooling
- Develop and maintain PowerShell scripts, Microsoft Graph automation, proactive remediations, runbooks, and reporting utilities.
- Automate device provisioning, application deployment, compliance correction, inventory validation, stale-object cleanup, and operational reporting.
- Apply secure scripting, logging, error handling, source control, peer review, and release practices.
- Identify repeatable support tasks suitable for self-service or automated remediation.
- Demonstrate measurable reduction in manual effort, resolution time, or error rates.
Advanced PowerShell capability is a recurring requirement in current EUC SME and administrator roles, particularly for configuration, reporting, remediation, and integration automation.
Documentation and Knowledge Management
- Maintain technical designs, configuration documents, SOPs, runbooks, knowledge articles, troubleshooting guides, and support matrices.
- Document platform dependencies, service accounts, certificates, connectors, firewall requirements, and recovery procedures.
- Ensure all production changes are reflected in technical documentation.
- Create training material and conduct knowledge-transfer sessions.
- Improve first-line and second-line resolution through clear documentation and coaching.
Technical Leadership
- Provide technical direction to engineers and project teams.
- Review solution designs, scripts, packages, configurations, and implementation plans.
- Mentor L1 and L2 staff and conduct technical workshops.
- Participate in technical interviews and candidate assessments.
- Support estimation, planning, and technical-risk assessment.
- Maintain awareness of product roadmaps, deprecations, feature releases, and end-of-support dates.
- Recommend technical improvements and innovation opportunities.
Deliverables
- High-level and low-level solution designs
- Platform standards and security baselines
- Build and configuration documents
- Application packages and deployment records
- Automation scripts and operational runbooks
- Test plans, implementation plans, and rollback plans
- Root-cause analyses and problem records
- Patch, compliance, and vulnerability reports
- Technical knowledge articles
- Capacity and platform-health reports
- Upgrade and migration plans
- Proofs of concept and technical recommendations
- Service transition and knowledge-transfer documentation
Required Experience
- Typically 815 years of IT infrastructure or EUC experience.
- At least 5–8 years of hands-on experience in endpoint management, Windows engineering, application deployment, or Microsoft 365.
- At least 3 years of strong hands-on Intune and/or SCCM engineering experience.
- Experience supporting large-scale enterprise environments and global users.
- Demonstrated experience with L3 troubleshooting, solution design