Job Summary
L1: This position will lead the design, implementation, governance and continuous improvement of Microsoft Intune and enterprise endpoint management services across corporate, BYOD, co-managed and cloud-native endpoints.
L2: The Intune Architect is expected to possess advanced hands-on expertise in Microsoft Intune administration and architecture, endpoint security, Windows Autopilot, application deployment, compliance policy design, Microsoft Graph based automation, DevOps integration and L3/L4 operational support. The role will work closely with workplace engineering, security, infrastructure, application, operations and customer stakeholders to translate requirements into scalable endpoint management standards and controls.
Key Responsibilities
-
Design, implement and govern enterprise-scale Microsoft Intune solutions for Windows, macOS, iOS/iPadOS and Android Enterprise devices.
-
Define endpoint management strategy including device enrollment, provisioning, configuration, compliance, security baseline, application deployment and lifecycle management standards.
-
Design and govern Windows Autopilot, BYOD, corporate-owned device, unattended enrollment and co-management models with SCCM/MECM where applicable.
-
Configure and govern device configuration profiles, compliance policies, Conditional Access policies, App Protection policies, endpoint security policies and data protection controls.
-
Design and optimize Intune application deployment standards including packaging requirements, assignment models, detection logic, deployment rings, troubleshooting methods and rollback practices.
-
Manage and support Windows Update rings, feature updates, Office 365 updates, evergreen servicing and Autopatch aligned endpoint compliance improvement.
-
Design and support device configurations including Wi-Fi, VPN, certificate-based authentication, LDAP/Active Directory related dependencies, CA integration and required Intune console configurations.
-
Build and maintain automation frameworks using PowerShell, Microsoft Graph API and other scripting approaches for provisioning, compliance checks, reporting, remediation and decommissioning.
-
Develop self-healing and proactive remediation scripts to reduce repetitive operational effort and improve endpoint compliance posture.
-
Implement DevOps practices for endpoint configuration management including Git version control, Azure DevOps/GitHub Actions pipelines and Infrastructure-as-Code approaches such as Terraform or Bicep where suitable.
-
Support Zero Trust endpoint security architecture by defining security baselines, compliance controls, vulnerability remediation inputs and monitoring requirements.
-
Provide L3/L4 technical leadership for complex Intune, Autopilot, application deployment, compliance, enrollment and Windows provisioning issues, including high-severity P1/P2 scenarios.
-
Create and maintain architecture documents, SOPs, technical standards, operational readiness plans, knowledge transfer artefacts and governance frameworks.
-
Collaborate with security, infrastructure, application, workplace engineering and service operations teams to ensure endpoint services remain secure, scalable, supportable and aligned to service levels.
-
Mentor engineers and administrators, conduct technical workshops, support upskilling initiatives and drive continuous service improvement.
Skill Requirements
-
Strong experience in administration, architecture and configuration of Microsoft Intune enterprise environments.
-
Deep knowledge of Microsoft Endpoint Manager, Microsoft Entra ID, Conditional Access, MDM, MAM, Defender for Endpoint and endpoint compliance controls.
-
Hands-on experience with Windows Autopilot, Windows 10/11 provisioning, unattended enrollment, device lifecycle management and troubleshooting.
-
Expertise in PowerShell scripting and Microsoft Graph API based automation for Intune management, reporting and remediation.
-
Working knowledge of Python, Bash, Azure DevOps, GitHub Actions, Git version control and DevOps operating models for endpoint configuration management.
-
Experience with application deployment through Intune, deployment optimization, detection rules, app delivery troubleshooting and software distribution governance.
-
Experience with Windows 11 evergreen support, Windows and Office feature updates, update rings, Autopatch concepts, availability, performance optimization and reporting.
-
Understanding of SCCM/MECM co-management, cloud-native endpoint strategies and migration from legacy endpoint management platforms such as Workspace ONE to Microsoft Intune.
-
Knowledge of endpoint security baselines, compliance posture management, vulnerability remediation planning and integration with tools such as Defender for Endpoint, Qualys, Nexthink, SIEM or equivalent platforms.
-
Ability to manage technical teams and support Intune services either as a technical lead or individual contributor.
-
Experience handling and driving P1/P2 situations from an Intune and Windows device management perspective.
-
Experience in enterprise transformation, operational readiness, release readiness, service recovery, reporting dashboards, AI-assisted automation or Power BI based insights will be an added advantage.
Other Requirements
-
Strong stakeholder management with the ability to lead architecture discussions, technical workshops and governance forums.
-
Ability to translate complex technical topics into clear business, customer and operational language.
-
Customer-focused approach with demonstrable experience delivering services to defined service levels and improving operational stability.
-
Strong analytical thinking, problem-solving ability and capability to drive issues to successful closure.
-
Ability to work effectively in an operational environment alongside technical, security, application and infrastructure teams.
-
Initiative-taking mindset with ability to learn and apply modern technologies, automation practices and endpoint security improvements.
-
Strong written and verbal communication skills, attention to detail and self-motivation.
-
Ability to build positive working relationships with customers and internal stakeholders with a focus on consistent service excellence.
-
Ability to mentor, coach and upskill engineers while building reusable knowledge assets and operational standards.
Required Experience:
-
15+ years of overall experience in Endpoint Management, Workplace Services, IT Infrastructure, Mobility, Modern Workplace or related enterprise technology services.
-
10+ years of hands-on experience with Microsoft Intune and Microsoft Endpoint Management technologies.
-
Experience designing, implementing or governing large-scale enterprise endpoint management solutions.
-
Strong understanding of enterprise security, compliance, cloud transformation and Microsoft 365 environments.
-
Experience leading modernization or migration initiatives, operational transition, endpoint governance or global Windows device management services is preferred.
Preferred Certifications:
-
Microsoft Certified: Endpoint Administrator Associate (MD-102).
-
Microsoft Certified: Azure Administrator Associate (AZ-104).
-
Microsoft Certified: DevOps Engineer Expert (AZ-400).
-
Microsoft Certified: Enterprise Administrator Expert or Cybersecurity Architect Expert.
-
ITIL Foundation certification will be advantageous.
-
Azure AI, Security, Compliance and Identity fundamentals certifications will be an added advantage.
Key Deliverables:
-
Intune Architecture and Governance Framework.
-
Endpoint Security Design and compliance baseline standards.
-
Windows Autopilot and device enrollment strategy.
-
Device Compliance and Conditional Access Framework.
-
Application Deployment Standards and deployment governance model.
-
Automation roadmap for device lifecycle, compliance remediation, reporting and operational efficiency.
-
Modern Workplace Transformation Roadmap.
-
SOPs, technical standards, knowledge transfer and operational readiness documentation.