Entra Hybrid Authentication, NPS, VPN & VDI Engineer

T7 Intelligent Resources

Kuala Lumpur

On-site

MYR 160,000 - 260,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

T7 Intelligent Resources is seeking an Entra Hybrid Authentication, NPS, VPN & VDI Engineer to design, implement and migrate VPN/VDI authentication away from Falaina to Microsoft Entra MFA NPS Extension. The role focuses on Windows NPS, RADIUS, AD/Kerberos hybrid authentication and enterprise MFA migrations.

Responsibilities include detailing target designs, implementing NPS instances, validating Entra ID communication, and supporting cutover with comprehensive documentation and testing.

Qualifications

  • Degree or diploma in Computer Science, Information Technology, Networking, Cybersecurity or equivalent.
  • Minimum 5 years of relevant infrastructure/security engineering experience with hands-on Windows Server, NPS/RADIUS and remote-access authentication.
  • Mandatory demonstrable production implementation experience with Microsoft Entra MFA NPS Extension for enterprise VPN/VDI authentication.
  • Experience supporting enterprise MFA migration/registration and Active Directory/Kerberos hybrid authentication is required.
  • WHfB exposure and experience with Cisco ASA/AnyConnect/Secure Client are strongly preferred.
  • SC-300 Identity Access Admin Associate and relevant Microsoft Windows Server, Azure or Cisco certifications are preferred.

Responsibilities

  • Assess the current VPN, VDI, RADIUS, Falaina MFA, Active Directory and network authentication architecture and document authentication flows, dependencies and failure points.
  • Prepare the detailed target VPN/VDI authentication design covering Windows NPS, RADIUS, Microsoft Entra MFA NPS Extension, AD, connectivity/firewall requirements and high availability.
  • Install, configure and harden Windows NPS instances and configure RADIUS clients, policies, authentication settings, logging and required certificates/secrets.
  • Install, register and configure Microsoft Entra MFA NPS Extension and validate communication and authentication dependencies with Entra ID.
  • Design and configure NPS/RADIUS high availability, resilience and failure handling and document expected behavior for component, network and cloud‑service failures.
  • Work with network and remote‑access SMEs to integrate the target NPS/RADIUS service with VPN and VDI platforms, including Cisco ASA/AnyConnect/Secure Client where applicable.
  • Identify applications or services among the existing Falaina integrations and wider application estate that rely on RADIUS or related network authentication and support their migration to the approved target authentication architecture where applicable.
  • Support Entra MFA user migration/re‑registration activities for VPN/VDI users, including pilot validation, authentication method readiness, exception handling and troubleshooting.
  • Prepare detailed configuration documentation, implementation procedures, test cases, cutover checklists and rollback procedures for VPN/VDI authentication migration.
  • Conduct technical testing covering successful and failed authentication, MFA challenge, policy enforcement, redundancy/failover, timeout, network failure and relevant negative scenarios.
  • Support UAT and execute/assist production migration of VPN and VDI authentication from Falaina to the target Entra MFA architecture.
  • Troubleshoot NPS, RADIUS, MFA, AD, VPN and VDI authentication issues using NPS/Event Viewer, Entra signin logs, network traces and relevant platform logs.
  • Support final Falaina cutover by validating that VPN/VDI and applicable RADIUS authentication dependencies no longer rely on Falaina.
  • Support Windows Hello for Business (WHfB) infrastructure prerequisites involving AD, Kerberos, domain controllers, device connectivity, DNS and related hybrid authentication dependencies where required.
  • Provide hyper‑care, as‑built/operational documentation and knowledge transfer to BNM infrastructure, network, IAM and support teams.

Skills

Windows Server
NPS/RADIUS
Remote-access auth
Active Directory
Kerberos
MFA
Cisco ASA/AnyConnect

Education

Degree or diploma in CS/IT/Networking/Cybersecurity or equivalent

Tools

Entra MFA NPS Extension
Entra ID
Event Viewer
Cisco ASA/AnyConnect

Job description

Entra Hybrid Authentication, NPS, VPN & VDI Engineer

MAIN FUNCTIONS:
  • Design, configure, test and migrate the Bank's VPN and VDI authentication services from Falaina-based RADIUS/MFA to the approved Microsoft Entra MFA architecture using Windows Network Policy Server (NPS) and Microsoft Entra MFA NPS Extension. The role shall provide hands‑on remote‑access authentication expertise, support user MFA migration and relevant application/RADIUS dependencies, and support hybrid authentication prerequisites for Windows Hello for Business.
RESPONSIBILITIES:
  • Assess the current VPN, VDI, RADIUS, Falaina MFA, Active Directory and network authentication architecture and document authentication flows, dependencies and failure points.
  • Prepare the detailed target VPN/VDI authentication design covering Windows NPS, RADIUS, Microsoft Entra MFA NPS Extension, AD, connectivity/firewall requirements and high availability.
  • Install, configure and harden Windows NPS instances and configure RADIUS clients, policies, authentication settings, logging and required certificates/secrets.
  • Install, register and configure Microsoft Entra MFA NPS Extension and validate communication and authentication dependencies with Entra ID.
  • Design and configure NPS/RADIUS high availability, resilience and failure handling and document expected behavior for component, network and cloud‑service failures.
  • Work with network and remote‑access SMEs to integrate the target NPS/RADIUS service with VPN and VDI platforms, including Cisco ASA/AnyConnect/Secure Client where applicable.
  • Identify applications or services among the existing Falaina integrations and wider application estate that rely on RADIUS or related network authentication and support their migration to the approved target authentication architecture where applicable.
  • Support Entra MFA user migration/re‑registration activities for VPN/VDI users, including pilot validation, authentication method readiness, exception handling and troubleshooting.
  • Prepare detailed configuration documentation, implementation procedures, test cases, cutover checklists and rollback procedures for VPN/VDI authentication migration.
  • Conduct technical testing covering successful and failed authentication, MFA challenge, policy enforcement, redundancy/failover, timeout, network failure and relevant negative scenarios.
  • Support UAT and execute/assist production migration of VPN and VDI authentication from Falaina to the target Entra MFA architecture.
  • Troubleshoot NPS, RADIUS, MFA, AD, VPN and VDI authentication issues using NPS/Event Viewer, Entra signin logs, network traces and relevant platform logs.
  • Support final Falaina cutover by validating that VPN/VDI and applicable RADIUS authentication dependencies no longer rely on Falaina.
  • Support Windows Hello for Business (WHfB) infrastructure prerequisites involving AD, Kerberos, domain controllers, device connectivity, DNS and related hybrid authentication dependencies where required.
  • Provide hyper‑care, as‑built/operational documentation and knowledge transfer to BNM infrastructure, network, IAM and support teams.
REQUIREMENTS:
  • Degree or diploma in Computer Science, Information Technology, Networking, Cybersecurity or equivalent.
  • Minimum 5 years of relevant infrastructure/security engineering experience with strong hands‑on Windows Server, NPS/RADIUS and enterprise remote‑access authentication experience.
  • Mandatory demonstrable production implementation experience with Microsoft Entra MFA NPS Extension for enterprise VPN and/or VDI authentication.
  • Experience supporting enterprise MFA migration/registration and Active Directory/Kerberos hybrid authentication is required.
  • WHfB exposure and experience with Cisco ASA/AnyConnect/Secure Client are strongly preferred.
  • SC-300 Identity Access Admin Associate and relevant Microsoft Windows Server, Azure or Cisco certifications are preferred.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Entra MFA & NPS Hybrid VPN/VDI Engineer
Entra MFA & NPS Hybrid VPN/VDI Engineer

T7 Intelligent Resources • Kuala Lumpur

On-site
MYR 160,000 - 260,000
Entra Hybrid Authentication, NPS, VPN & VDI Engineer
Entra Hybrid Authentication, NPS, VPN & VDI Engineer

OPTIMUM INFOSOLUTIONS (M) SDN BHD • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Certifications support
Professional development
Contract role
Entra Hybrid Authentication, NPS, VPN & VDI Engineer
Entra Hybrid Authentication, NPS, VPN & VDI Engineer

Optimum Infosolutions • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Entra Hybrid Identity & VPN/VDI Engineer
Entra Hybrid Identity & VPN/VDI Engineer

Optimum Infosolutions • Kuala Lumpur

On-site
MYR 180,000 - 240,000
IAM Application Migration & Test Engineer
IAM Application Migration & Test Engineer

Hexamatics Servvcom Sdn Bhd • Kuala Lumpur

On-site
MYR 90,000 - 180,000
IAM Application Migration & Test Engineer
IAM Application Migration & Test Engineer

Hexa Business • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Hybrid Identity & Networking Engineer: Entra, VPN, VDI
Hybrid Identity & Networking Engineer: Entra, VPN, VDI

OPTIMUM INFOSOLUTIONS (M) SDN BHD • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Certifications support
Professional development
Contract role
Senior IT Security
Senior IT Security

Tribe Business Services Sdn Bhd • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Performance bonus
Medical and insurance benefits
Professional certification sponsorship
Senior IT Security
Senior IT Security

Tribe Digital • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Competitive salary
Performance bonus
Medical insurance
+2
Network & Security Specialist Engineer
Network & Security Specialist Engineer

ENOVIX Corporation • Penang

On-site
MYR 90,000 - 130,000