Identity & Microsoft 365 Migration Specialist
We're looking for a hands-on migration specialist to help modernize a large enterprise identity and Microsoft 365 estate. You'll consolidate legacy Active Directory forests, move users, groups and devices to Entra ID and Intune and run tenant-to-tenant migrations for Exchange Online, OneDrive, SharePoint and Teams.
Key Responsibilities
- Identity and directory
- Move users, groups, computers and service accounts from legacy forests into the target forest and manage coexistence (trusts, SID history and directory sync) while both are live.
- Run Entra Connect and Cloud Sync through the migration, including scoping changes and staging-mode cutovers.
- Make sure every migrated user lands on their existing cloud identity. That means managing sourceAnchor and ImmutableID values and using hard-match or soft-match, so nobody ends up with a duplicate account or loses access to their mailbox, files or licences.
- Check that Conditional Access, MFA, RBAC and PIM still behave as expected once users have moved.
- Tidy up afterwards: clear SID history, take down migration trusts and retire the old forests.
- Devices
- Move devices from domain-joined or hybrid-joined to Entra-joined and managed in Intune.
- Rebuild the Group Policy settings that still matter as Intune configuration and compliance.
- Microsoft 365 tenant-to-tenant
- Migrate Exchange Online, OneDrive, SharePoint Online and Teams between tenants, plus public folders where they're in scope.
- Handle the domain and mail-flow cutover, including connectors, MX, SPF, DKIM and DMARC.
- Look after data that's tied to the source tenant, such as sensitivity labels, encrypted content, retention policies and holds and raise design questions with PwC as they come up.
- Tooling, operations and governance
- Use the tool that suits each workload, whether that's Quest, ShareGate, BitTitan MigrationWiz or Microsoft's native options.
- Script the repetitive work and the validation checks in PowerShell, Microsoft Graph PowerShell and the Graph API.
- Look after the Azure VMs running the migration and sync servers: sizing, patching, backups, network access and monitoring.
- Troubleshoot identity and Microsoft 365 issues during and after migration, get to the root cause and put lasting fixes in place.
- Follow the client's change control process for every production change.
- Keep runbooks, SOPs, validation reports and handover documents up to date.
- Join and sometimes run, working sessions with stakeholders in different regions.
Required Experience
- 5+ years working with Microsoft identity and infrastructure, covering Active Directory, Entra ID and Microsoft 365.
- Deep hands-on experience in one of these areas and practical experience in the other:
- Identity migration: AD forest consolidation, hybrid identity and moving devices to Entra ID and Intune
- Microsoft 365 workload migration: tenant-to-tenant moves for Exchange Online, OneDrive, SharePoint and Teams
- At least two migration projects delivered hands-on, covering both areas between them.
- A solid grasp of Active Directory: forests and trusts, Group Policy, DNS, replication, Kerberos and LDAP.
- Experience with Entra Connect or Cloud Sync and a clear understanding of how sourceAnchor and hard-match work.
- Hands-on time with at least one migration tool, such as Quest (Migration Manager for AD or On Demand Migration), ADMT, ShareGate, BitTitan MigrationWiz or Microsoft native tooling.
- Practical knowledge of Exchange Online mail flow, SharePoint and OneDrive permissions, Teams administration and Intune enrolment and policies.
- Strong PowerShell, including the Microsoft Graph PowerShell SDK.
- Clear, confident communication, both in writing and on calls.
Preferred Experience
- Migrations of 5,000+ users across multiple forests or tenants
- Consolidation work following a merger or acquisition
- Exchange hybrid and public folder migrations
- Purview (DLP, sensitivity labels, retention) and Defender, particularly how they affect a migration
- Experience in banking, financial services or another regulated industry
- Certifications such as MS-102, SC-300, AZ-104 or MD-102 (helpful, not required)