The position is an execution and remediation role. It owns the sustained, high-volume administrative work across Microsoft 365, Intune, Entra ID, and Apple Business Manager, and provides hands‑on support to the legacy directory and file store migration program.
Core Responsibilities
Microsoft 365 Administration — 30%
- Administer Exchange Online, SharePoint Online, OneDrive, and Teams within delegated administrative scopes
- Manage mailbox provisioning, shared mailboxes, distribution groups, and mail flow configuration
- Perform license assignment, reconciliation, and reclamation across the M365 A5 estate; report on unused and orphaned licenses
- Execute service health monitoring and first-line diagnosis of tenant-level service issues
- Maintain administrative runbook documentation for all recurring procedures
Microsoft Intune and Endpoint Management — 25%
- Administer Intune device configuration, compliance, and application deployment policies for company-issued devices only — Intune MDM is never applied to personal devices at Cadence, and this boundary is not subject to local interpretation
- Monitor and remediate device compliance failures across the school and SSC estate
- Package, deploy, and update applications through Intune
- Maintain Windows Update for Business rings and report on patch compliance
- Support the Windows 10 end-of-support refresh program with device readiness reporting
Entra ID Account Lifecycle and Cleanup — 20%
- Execute systematic cleanup of stale, duplicate, orphaned, and disabled Entra ID user and device objects
- Reconcile Entra ID accounts against the UKG HR system of record; identify and elevate discrepancies
- Support joiner/mover/leaver processing, including timely disable and license reclamation on separation
- Maintain group membership hygiene, including dynamic group rule validation
- Produce recurring account hygiene reporting. Report actionable counts — active, enabled, seen within 90 days — as the headline figure. Raw object counts are inflated by stale records across 336+ sites and must not be quoted externally
- Support Conditional Access and phishing-resistant MFA (FIDO2) enrollment operations, including registration troubleshooting and key lifecycle tracking
Legacy Directory and File Store Migration Support — 15%
- Assist the migration of on-premises Active Directory objects and legacy file shares into Entra ID, SharePoint Online, and OneDrive
- Perform pre-migration discovery: share inventory, permission mapping, data volume assessment, and stale-data identification
- Execute assigned migration batches, validate results, and remediate permission and metadata failures
- Document source-to-target mapping and post-migration validation evidence
- Support cutover activities and post-cutover issue resolution
Apple Business Manager and Device Enrollment — 10%
- Administer Apple Business Manager: device assignment, Automated Device Enrollment (ADE) token lifecycle, Managed Apple Account administration, and Apps and Books (VPP) license management
- Maintain the ABM-to-Intune connection, including token renewal before expiry
- Execute device enrollment for new and refreshed hardware; resolve enrollment failures
- Reconcile ABM, Intune, and Entra device inventories; identify and close enrollment gaps — including devices that are Entra-joined but not Intune-enrolled
- Perform device record cleanup, retirement, and wipe processing for returned, lost, and end-of-life hardware
Required Qualifications
Experience
- 4+ years administering Microsoft 365 in a production environment of 1,000+ users
- 2+ years hands‑on Microsoft Intune administration, including device configuration, compliance policy, and application deployment
- 2+ years Entra ID (Azure AD) administration, including account lifecycle, groups, and Conditional Access operations
- Demonstrated experience with Apple Business Manager and Automated Device Enrollment
- Demonstrated experience supporting a directory or file share migration to Microsoft 365 (AD to Entra ID, file shares to SharePoint/OneDrive)
- Experience working in a ticket-driven support environment with documented SLAs
Technical Skills
- PowerShell scripting for administrative automation and reporting (Microsoft Graph PowerShell SDK, Exchange Online Management)
- Microsoft Graph API familiarity for reporting and bulk operations
- Hybrid identity concepts: Entra Connect / Cloud Sync, hybrid join, and coexistence
- Windows 10/11 endpoint administration; macOS and iPadOS endpoint administration
- NTFS and SharePoint permission models, and the translation between them
- Accurate documentation and change-record discipline
Non-Technical Requirements
- Professional written and spoken English sufficient for direct written communication with SSC staff and school directors
- Availability for a night shift in Cebu providing daily overlap with Arizona business hours