Nagarro logo
NagarroPosted 3 weeks ago
EXPIRED

Staff Engineer, Microsoft Active Directory

RemoteUnited States or India

Full TimeSenior LevelEnterprise

Job Summary

Design, administer, and optimize enterprise Microsoft Active Directory and Microsoft Entra ID environments, managing Domain Controllers, replication, FSMO roles, and schema. Implement Group Policy frameworks, administer Windows Server, DNS, DHCP, and IIS, while enforcing Conditional Access, MFA, and identity governance policies. Manage Hybrid Identity via Azure AD Connect, administer Microsoft 365 services, and develop PowerShell automation leveraging the Microsoft Graph API. Lead upgrades, migrations, and disaster recovery initiatives, troubleshooting complex authentication issues involving OAuth, SAML, Kerberos, and NTLM. Collaborate with cloud, infrastructure, and security teams to strengthen identity services and ensure compliance.

Required Qualifications

  • Total experience: 5.5+ years.
  • Strong experience in Microsoft Active Directory administration across enterprise, multi-site environments.
  • Must-have expertise in Microsoft Entra ID (Azure AD) administration and Hybrid Identity (Entra Connect/AD Connect).
  • Strong experience in managing Domain Controllers, AD Replication, FSMO Roles, Schema, Trusts, NTDS, DFSR, and AD Sites & Services.
  • Hands-on experience with Windows Server (2012–2022+), DNS, DHCP, IIS, and Group Policy (GPO) administration.
  • Experience designing and implementing Conditional Access, SSO, MFA, RBAC, PIM, and Identity Lifecycle Management.
  • Strong understanding of Microsoft 365 identity services, Exchange Online, and Hybrid Exchange administration.
  • Experience managing mail flow, connectors, SPF, DKIM, DMARC, licensing, and directory synchronization.
  • Hands-on experience troubleshooting OAuth, SAML, Kerberos, and NTLM authentication issues.
  • Strong scripting experience using PowerShell and automation with Microsoft Graph API.
  • Experience with Active Directory migrations, upgrades, consolidations, backup, disaster recovery, and high availability.
  • Good knowledge of identity security, IAM best practices, compliance, and enterprise authentication.
  • Bachelor's or master's degree in computer science, Information Technology, or a related field

Desired Qualifications

  • Experience using Active Directory administration and migration tools such as Quest is preferred.

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Find similar roles