Staff Engineer, Microsoft Active Directory
- Full-time
- Service Region: South Asia
Company Description
👋🏼We're Nagarro.
We are a Digital Product Engineering company that is scaling in a big way! We build products, services, and experiences that inspire, excite, and delight. We work at scale across all devices and digital mediums, and our people exist everywhere in the world (18500+ experts across 40 countries, to be exact). Our work culture is dynamic and non-hierarchical. We're looking for great new colleagues. That's where you come in!
Job Description
REQUIREMENTS:
• Total experience: 5.5+ years.
• Strong experience in Microsoft Active Directory administration across enterprise, multi-site environments.
• Must-have expertise in Microsoft Entra ID (Azure AD) administration and Hybrid Identity (Entra Connect/AD Connect).
• Strong experience in managing Domain Controllers, AD Replication, FSMO Roles, Schema, Trusts, NTDS, DFSR, and AD Sites & Services.
• Hands-on experience with Windows Server (2012–2022+), DNS, DHCP, IIS, and Group Policy (GPO) administration.
• Experience designing and implementing Conditional Access, SSO, MFA, RBAC, PIM, and Identity Lifecycle Management.
• Strong understanding of Microsoft 365 identity services, Exchange Online, and Hybrid Exchange administration.
• Experience managing mail flow, connectors, SPF, DKIM, DMARC, licensing, and directory synchronization.
• Hands-on experience troubleshooting OAuth, SAML, Kerberos, and NTLM authentication issues.
• Strong scripting experience using PowerShell and automation with Microsoft Graph API.
• Experience with Active Directory migrations, upgrades, consolidations, backup, disaster recovery, and high availability.
• Good knowledge of identity security, IAM best practices, compliance, and enterprise authentication.
• Experience using Active Directory administration and migration tools such as Quest is preferred.
• Strong analytical, troubleshooting, communication, and stakeholder management skills.
RESPONSIBILITIES:
• Design, administer, and optimize enterprise Microsoft Active Directory and Microsoft Entra ID environments.
• Manage Domain Controllers, AD replication, FSMO roles, trusts, schema, NTDS, DFSR, and AD Sites & Services.
• Implement, maintain, and secure Group Policy (GPO) frameworks across enterprise environments.
• Administer Windows Server, DNS, DHCP, IIS, and core identity infrastructure services.
• Design and enforce Conditional Access, MFA, SSO, RBAC, PIM, and identity governance policies.
• Manage Hybrid Identity using Microsoft Entra Connect (Azure AD Connect) and ensure seamless directory synchronization.
• Administer Microsoft 365 identity services, Exchange Online, and Hybrid Exchange environments.
• Manage mail flow, connectors, authentication protocols, and compliance-related identity configurations.
• Develop and maintain PowerShell automation scripts and leverage Microsoft Graph API for administration and reporting.
• Lead Active Directory upgrades, migrations, consolidations, backup, recovery, and disaster recovery initiatives.
• Troubleshoot and resolve complex authentication issues involving OAuth, SAML, Kerberos, and NTLM.
• Perform root cause analysis for critical production incidents and implement preventive solutions.
• Collaborate with cloud, infrastructure, and security teams to strengthen enterprise identity services.
• Monitor identity security posture, ensure compliance, and continuously improve identity management processes and automation.
Qualifications
Bachelor’s or master’s degree in computer science, Information Technology, or a related field
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply