Senior Intune & Microsoft Endpoint Administrator
Job Id: Aeries/311/26-27
Experience Range 5 - 7 Years
Qualification Graduate/ Post Graduate
Open
Job Description
About Us
Aeries Technology is a Nasdaq listed global professional services and consulting partner, headquartered in Mumbai, India, with centers in the USA, Mexico, Singapore, and Dubai. We provide mid-size technology companies with the right mix of deep vertical specialty, functional expertise, and the right systems & solutions to scale, optimize and transform their business operations with unique customized engagement models. Aeries is Great Place to Work certified by GPTW India, reflecting our commitment to fostering a positive and inclusive workplace culture for our employees.Read about us at https://aeriestechnology.com
About Business Unit
Roles and Responsibility
Position/Title: Senior Intune & Microsoft EndpointAdministrator
Experience: 5-7+ years
Department: IT
Employment type: Full Time
Shifts (if any): -
About Aeries:
Aeries Technology is a Nasdaq listed (AERT) global professionalservices and consulting partner, with offices in the USA, India, Mexico,Singapore, and UAE. We provide Private Equities, its Portfolio Companies andmid-market companies with the right mix of deep vertical specialty, functionalexpertise, and the right systems & solutions to scale, optimize andtransform their business operations with unique customized engagement models.Aeries is Great Place to Work certified by GPTW Institute, reflecting ourcommitment to fostering a positive and inclusive workplace culture for ouremployees.
- Microsoft Intune & Endpoint Management: Own the design, configuration, administration, monitoring, andcontinuous improvement of Microsoft Intune for Windows endpoints, includingconfiguration profiles, compliance policies, applications, security baselines,certificates, restrictions, reporting, and remediation.
- Windows Device Management: Lead theend-to-end lifecycle of Windows devices covering provisioning, configuration,application deployment, security hardening, compliance, patching,troubleshooting, and retirement.
- MDM / MAM Administration: Administerenterprise Mobile Device Management and, where applicable, Mobile ApplicationManagement policies, enrollment, device restrictions, application protection,compliance, and Conditional Access integration.
- Windows Autopilot: Own Autopilotconfiguration and management, including device registration, deploymentprofiles, Enrollment Status Page, pre-provisioning, user-driven deployment,application assignment, troubleshooting, and lifecycle processes.
- Windows Autopatch & Patch Management: Design and manage Windows Autopatch and Intune patching, includingupdate rings, feature and quality updates, driver/firmware strategies,monitoring, compliance, rollback, and remediation.
- Microsoft Entra ID: Administer users,groups, device identities, administrative roles, RBAC, Conditional Access, SSO,authentication controls, enterprise applications, and identity lifecycleprocesses.
- Azure Resource Management: Manage Azuresubscriptions, resource groups, RBAC, virtual machines, storage, networkingcomponents, monitoring, governance, and cost/consumption controls; supportAzure requirements from engineering and IT teams.
- Windows Server Administration: Administerand troubleshoot Windows Server environments including Active Directory, DNS,DHCP, Group Policy, file services, patching, permissions, performance, andintegration with Entra ID and endpoint management.
- Backup & Recovery: Administer andmonitor Veeam and/or Veritas backup solutions, including backup jobs,repositories, retention, alerts, restoration, recovery testing, and compliancereporting.
- macOS Management: Manage macOS devicesusing Intune, ensuring secure configuration, patching, compliance, andoperational health.
- Security & Compliance: Implementendpoint and identity security controls aligned with organizational policies,audit requirements, and regulatory standards; support remediation and evidencecollection.
- PowerShell & Automation: DevelopPowerShell automation for Intune, Entra ID, Azure, Windows administration,compliance checks, remediation, reporting, and repetitive operational tasks.
- ITSM & Technical Support: Provideadvanced technical support through ServiceDesk Plus, ServiceNow, or similarITSM platforms and own complex incidents, requests, problems, and changes.
- Monitoring, Reporting & Documentation: Produce reports covering device compliance, patch status,enrollment, applications, Azure consumption, backup status, and securityposture; maintain SOPs and technical documentation.
- GenAI & Process Improvement: Useapproved GenAI tools such as Microsoft Copilot to improve productivity,documentation, analysis, troubleshooting, reporting, and automation whilefollowing security policies.
- Collaboration & Projects: Work withInfrastructure, Network, Security, Service Desk, HR, Engineering, and businessteams on endpoint, identity, cloud, security, and infrastructure projects.
Requirements forthe role:
- 5–7+ years of experience inendpoint management, systems administration, infrastructure, or a similar senior IT role.
- Strong hands-on experience withMicrosoft Intune and enterprise Windows endpoint management.
- Strong understanding ofMDM/MAM, device enrollment, compliance, configuration profiles, applicationdeployment, and endpoint security.
- Hands-on experience withWindows Autopilot, including device registration, deployment profiles, ESP,pre-provisioning, and troubleshooting.
- Hands-on experience withWindows Autopatch and/or advanced Intune patch management, including updaterings and feature/quality update policies.
- Strong Microsoft Entra IDadministration experience covering users, groups, device identities, RBAC,Conditional Access, SSO, and enterprise applications.
- Hands-on Azure resourcemanagement experience covering subscriptions, resource groups, RBAC, VMs,storage, monitoring, and governance.
- Strong Windows Serveradministration experience including Active Directory, DNS, DHCP, Group Policy,patching, permissions, and troubleshooting.
- Experience with Veeam and/orVeritas backup, restore, retention, monitoring, and recovery testing.
- Strong PowerShell scripting andautomation skills; Microsoft Graph automation experience is an advantage.
- Experience with Jamf for macOSmanagement is preferred.
- Experience with ServiceDeskPlus, ServiceNow, or comparable ITSM platforms.
- Strong troubleshooting skillsacross endpoint, identity, server, cloud, and application deployment issues.
- Ability to produce technicaldocumentation, SOPs, operational reports, and audit evidence.
Skills/Certifications:
- Microsoft Certified: Identityand Access Administrator Associate (SC-300)
- Microsoft Certified: Security,Compliance, and Identity Fundamentals (SC-900)
- Veeam or Veritas backupcertification
- Jamf certification
Education:
Bachelor’s degree in computerscience, Information Technology, Engineering, or a related discipline, orequivalent practical experience.
Core Competencies:
- · Strong analytical andproblem-solving capability.
- Excellent written and verbalcommunication skills.
- Ability to explain technicalconcepts to technical and non-technical stakeholders.
- Strong ownership andaccountability for production systems.
- Ability to work independentlyand collaborate across cross-functional teams.
- Strong change-management,documentation, and operational discipline.
- Ability to manage multiplepriorities in a fast-paced enterprise IT environment.
Area
Technologies /Platforms
PatchManagement
Identity
Microsoft EntraID, RBAC, Conditional Access, SSO
Cloud
Server
Windows Server,Active Directory, DNS, DHCP, GPO
Backup
macOS
Jamf
Automation
PowerShell,Microsoft Graph
ITSM
GenAI
The Job responsibilities of thecandidate shall include but not limited to the Job Description & to performany other tasks/functions as required by the Company.