The Active Directory Specialist is responsible for managing, maintaining, and optimizing the organization’s Active Directory (AD) environment. This includes ensuring secure and efficient authentication, authorization, and identity management services across the enterprise.
Active Directory (AD) Specialist’ plays a critical role in ensuring the integrity, security, and efficiency of the organisation’s identity and access management framework. By leveraging expertise in AD architecture, group policy management, and integration with cloud services (e.g., Azure AD), the specialist enables seamless user experiences, enforces robust security practices, and supports the organization’s evolving ICT needs.
Position Outputs
- Ensure a robust and secure Active Directory (AD) infrastructure with up-to-date configurations, patches, and security settings.
- Efficient identity and access controls, including proper user provisioning, group management, and permissions based on organizational policies.
- Properly configured and optimized Group Policies to enforce network security, performance, and compliance standards.
- Real-time directory infrastructure monitoring and optimization to ensure performance, scalability, and availability.
- Seamless integration of on-premises Active Directory with cloud-based services like Azure Active Directory or hybrid identity solutions.
- Implementation of security best practices, such as multi-factor authentication (MFA), password policies, and auditing configurations to reduce vulnerabilities.
- A fully documented and tested disaster recovery and backup plan for Active Directory to ensure business continuity in case of failure.
- Comprehensive and up-to-date documentation of the Active Directory architecture, configurations, policies, and processes.
- Prompt and effective resolution of user-related issues, such as account lockouts, login failures, or permission errors.
- Active Directory is fully compliant with internal and external regulatory standards.
- Proposals and implementation of improvements to the AD environment, such as performance optimizations, feature upgrades, or automation scripts.
- Effective cross-team collaboration with other IT departments to support enterprise initiatives such as migrations, upgrades, or security rollouts
- Manage and maintain the Active Directory environment, including domains, forests, trusts, and organizational units (OUs).
- Ensure proper configuration and maintenance of Group Policy Objects (GPOs) to enforce security policies and streamline system configurations.
- Plan, execute, and monitor the integration of on-premises AD with Azure AD, enabling a hybrid identity model.
- Monitor and troubleshoot authentication and access issues, providing timely resolutions to minimize user impact.
- Manage secure access for users, groups, and service accounts, implementing role- based access control (RBAC) where appropriate.
- Lead Active Directory health checks, performance optimization, and disaster recovery planning.
- Document all AD-related processes, configurations, and standard operating procedures (SOPs).
- Ensure the AD environment complies with industry regulations and organizational security policies.
- Collaborate with IT, cloud, and security teams to align identity services with organizational needs.
Qualifications and Experience
- A Bachelor’s degree in information technology, Computer Science, or a related field
- 6 - 8 years experience in a large ICT environment
- 4 - 5 years in ICT infrastructure managerial/specialist role
- ITIL Foundation Certification an added advantage
Recognition of Competence (ROC)
- NQF Level 5
- 8 - 10 years’ experience in a large ICT environment
- 4 - 5 years in ICT infrastructure managerial/specialist role
Certifications Required For The Position
Having two or more of the following certifications will be advantageous:
- Microsoft Certified: Azure Administrator
- Microsoft Certified: Identity and Access Administrator Associate
- Microsoft Certified: Windows Server Hybrid Administrator Associate
- Microsoft Certified: Security,CompetenciesKnowledge
- Active Directory Expertise: In-depth knowledge of managing and troubleshooting AD environments, including forests, domains, trusts, and replication.
- Azure Active Directory Integration: Proficiency in configuring and managing Azure AD Connect, Azure AD B2B/B2C, and hybrid identity solutions.
- Group Policy Management: Advanced skills in designing, implementing, and troubleshooting GPOs to enforce security policies and streamline configurations.
- Authentication Protocols: Familiarity with protocols such as Kerberos, NTLM, SAML, and OAuth for secure authentication and access.
- Identity and Access Management (IAM): Experience implementing RBAC, MFA, and conditional access policies.
- Monitoring and Automation: Proficiency in tools such as Microsoft Identity Manager (MIM), PowerShell, and associateEquity StatementPreference will be given to suitably qualified Applicants who are members of the designated groups in line with the Employment Equity Plan and Targets of the Organisation/Operating Division.