Active Directory Specialist
Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed
Job Overview
We are seeking experienced and technically proficient Active Directory Specialists to design, implement, configure, administer, secure and maintain Microsoft Active Directory environments within complex enterprise IT infrastructures.
The successful candidates will be responsible for ensuring the availability, performance, security and integrity of enterprise directory services, authentication systems and identity infrastructure across on-premises and hybrid cloud environments.
This role requires strong hands‑on expertise in Active Directory Domain Services (AD DS), Group Policy management, domain controllers, DNS, authentication protocols, identity synchronisation and enterprise directory security.
The ideal candidates will have proven experience supporting large‑scale Microsoft Active Directory environments, troubleshooting complex directory service issues, implementing security best practices and maintaining reliable identity and authentication services.
Key Responsibilities
Active Directory Administration and Management
- Install, configure, administer and maintain Microsoft Active Directory Domain Services (AD DS).
- Manage Active Directory forests, domains, organisational units (OUs), users, groups and computer objects.
- Configure, maintain and troubleshoot domain controllers and directory replication.
- Implement and manage Group Policy Objects (GPOs) across enterprise environments.
- Administer Active Directory Sites and Services, trusts and domain relationships.
- Maintain directory service availability, performance and operational stability.
- Manage Active Directory permissions, delegation and administrative access.
- Perform routine Active Directory maintenance, monitoring and health checks.
- Investigate and resolve directory service incidents, authentication failures and replication issues.
- Support Active Directory upgrades, migrations and infrastructure modernisation initiatives.
Active Directory Security and Access Control
- Implement and maintain Active Directory security policies and access controls.
- Apply least‑privilege principles and secure administrative account management.
- Review and remediate excessive permissions, privileged group memberships and insecure configurations.
- Implement Active Directory hardening measures aligned with Microsoft security recommendations.
- Secure domain controllers, administrative accounts and critical directory infrastructure.
- Monitor suspicious authentication activity and potential Active Directory security threats.
- Support privileged access management and identity governance initiatives.
- Implement and maintain secure Group Policy configurations.
- Assist with Active Directory security assessments and remediation activities.
- Support the implementation of Zero Trust identity security principles.
Authentication, DNS and Directory Services
- Configure and troubleshoot Kerberos and NTLM authentication.
- Administer Active Directory‑integrated DNS services.
- Support Lightweight Directory Access Protocol (LDAP) and secure LDAP (LDAPS).
- Manage domain trust relationships and authentication dependencies.
- Troubleshoot name resolution, domain connectivity and authentication issues.
- Maintain Active Directory replication and site topology configurations.
- Support enterprise certificate services and directory‑integrated authentication where required.
- Investigate complex authentication and directory integration problems.
Hybrid Identity and Microsoft Entra Integration
- Support integration between on‑premises Active Directory and Microsoft Entra ID.
- Configure, administer and troubleshoot Microsoft Entra Connect synchronisation.
- Support hybrid identity authentication and directory synchronisation.
- Manage identity‑related configurations supporting Microsoft 365 and Azure environments.
- Assist with hybrid identity migrations and cloud identity integration projects.
- Support authentication modernisation and identity security improvements.
- Collaborate with cloud and IAM teams to ensure secure and reliable identity integration.
Automation, Monitoring and Technical Support
- Develop and maintain PowerShell scripts to automate Active Directory administration.
- Automate user provisioning, group management, reporting and routine maintenance tasks.
- Monitor Active Directory health, replication, security events and service performance.
- Maintain Active Directory documentation, configuration records and operational procedures.
- Support backup, recovery and disaster recovery planning for directory services.
- Participate in Active Directory recovery testing and business continuity activities.
- Provide advanced technical support for complex Active Directory incidents.
- Collaborate with infrastructure, networking, cybersecurity and application support teams.
- Recommend improvements to directory service performance, security and operational efficiency.
Minimum Requirements
- Relevant diploma or degree in Information Technology, Computer Science, Information Systems, Network Engineering or a related discipline.
- Typically 3–5 years of relevant experience administering and supporting Microsoft Active Directory environments.
- Proven hands‑on experience with Microsoft Active Directory Domain Services (AD DS) in enterprise environments.
- Strong knowledge of Active Directory forests, domains, organisational units and Group Policy.
- Practical experience administering domain controllers and troubleshooting directory replication.
- Experience configuring and troubleshooting DNS, LDAP, Kerberos and Windows authentication.
- Strong working knowledge of Windows Server administration.
- Experience managing Active Directory user accounts, security groups, permissions and administrative delegation.
- Experience implementing Active Directory security hardening and access control measures.
- Practical PowerShell scripting experience for Active Directory administration and automation.
- Familiarity with Microsoft Entra ID and hybrid identity environments.
- Experience troubleshooting complex Active Directory authentication and infrastructure issues.
- Understanding of backup, recovery and disaster recovery processes for directory services.
- Knowledge of enterprise IT security practices and recognised security frameworks.
- Strong analytical, troubleshooting and technical documentation skills.
Technical Skills and Competencies
Microsoft Active Directory Technologies
- Active Directory Domain Services (AD DS)
- Active Directory forests and domains
- Domain Controllers
- Organisational Units (OUs)
- Group Policy Objects (GPOs)
- Active Directory Sites and Services
- Active Directory replication
- Domain and forest trusts
- Flexible Single Master Operations (FSMO) roles
- Active Directory schema and configuration management
- Active Directory Administrative Center
Windows Server and Infrastructure
- Windows Server 2016, 2019, 2022 or later supported versions
- Windows Server administration and troubleshooting
- Server security hardening
- DNS and DHCP fundamentals
- Network connectivity and name resolution
- Enterprise infrastructure monitoring
- Virtualised Windows Server environments
Authentication and Directory Protocols
- Kerberos
- NTLM
- LDAP and LDAPS
- DNS
- Group Policy processing
- Windows authentication and authorisation
- Enterprise directory integration
- Domain trust authentication
Active Directory Security
- Active Directory security assessments
- Privileged account management
- Least‑privilege administration
- Administrative tiering
- Group Policy security hardening
- Privileged group membership reviews
- Secure administrative delegation
- Active Directory attack surface reduction
- Identity threat detection and remediation
- Microsoft security baselines
Hybrid Identity and Cloud Integration
- Microsoft Entra ID
- Microsoft Entra Connect Sync
- Hybrid identity synchronisation
- Microsoft 365 identity integration
- Microsoft Azure identity services
- Hybrid authentication configurations
- Identity lifecycle management fundamentals
PowerShell and Automation
- Windows PowerShell
- Active Directory PowerShell module
- Automated account provisioning and deprovisioning
- Security group management automation
- Group Policy reporting
- Directory health monitoring scripts
- Identity administration automation
- Technical reporting and audit scripting
Monitoring, Backup and Recovery
- Active Directory health checks
- Replication monitoring and troubleshooting
- Windows Event Viewer
- Directory Services event logs
- Active Directory backup and recovery
- System State backup
- Authoritative and non-authoritative restore concepts
- Active Directory disaster recovery
- Directory service performance monitoring
Security Frameworks and Standards
- Microsoft Active Directory security best practices
- ISO/IEC 27001
- NIST Cybersecurity Framework
- CIS Critical Security Controls
- Zero Trust identity security principles
- Enterprise identity and access management policies
Relevant Certifications (Advantageous)
One or more of the following certifications would be beneficial:
- Microsoft Certified: Windows Server Hybrid Administrator Associate
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- CompTIA Security+
- CompTIA Server+
- Microsoft Applied Skills credentials relevant to Active Directory, Windows Server or hybrid identity
- Relevant Microsoft Windows Server administration certifications
- Relevant Microsoft Entra ID or enterprise identity management certifications
Key Personal Attributes
- Strong technical troubleshooting and analytical abilities.
- Excellent attention to detail and security awareness.
- Ability to investigate and resolve complex Active Directory incidents.
- Strong understanding of enterprise infrastructure and identity security.
- Proactive approach to system monitoring and preventive maintenance.
- Excellent communication and stakeholder engagement skills.
- Ability to collaborate with infrastructure, networking and cybersecurity teams.
- Strong organisational and technical documentation skills.
- Ability to manage multiple technical priorities and incidents.
- High levels of confidentiality, accountability and professional integrity.
Application Requirements
Important: This is a specialist Active Directory opportunity requiring demonstrable hands‑on experience administering and troubleshooting enterprise Microsoft Active Directory environments. General IT support experience without substantial Active Directory expertise will not be sufficient.
Please note: Specific project requirements, remuneration, employment arrangements and working conditions will be confirmed during the recruitment process.