Job Summary
L1: This position will lead the design, implementation, governance and continuous improvement of Microsoft Intune and enterprise endpoint management services across corporate, BYOD, co-managed and cloud-native endpoints.
L2: The Intune Architect is expected to possess advanced hands-on expertise in Microsoft Intune administration and architecture, endpoint security, Windows Autopilot, application deployment, compliance policy design, Microsoft Graph based automation, DevOps integration and L3/L4 operational support. The role will work closely with workplace engineering, security, infrastructure, application, operations and customer stakeholders to translate requirements into scalable endpoint management standards and controls.
Key Responsibilities
-
Design, implement and govern enterprise-scale Microsoft Intune solutions for Windows, macOS, iOS/iPadOS and Android Enterprise devices.
-
Define endpoint management strategy including device enrollment, provisioning, configuration, compliance, security baseline, application deployment and lifecycle management standards.
-
Design and govern Windows Autopilot, BYOD, corporate-owned device, unattended enrollment and co-management models with SCCM/MECM where applicable.
-
Configure and govern device configuration profiles, compliance policies, Conditional Access policies, App Protection policies, endpoint security policies and data protection controls.
-
Design and optimize Intune application deployment standards including packaging requirements, assignment models, detection logic, deployment rings, troubleshooting methods and rollback practices.
-
Manage and support Windows Update rings, feature updates, Office 365 updates, evergreen servicing and Autopatch aligned endpoint compliance improvement.
-
Design and support device configurations including Wi-Fi, VPN, certificate-based authentication, LDAP/Active Directory related dependencies, CA integration and required Intune console configurations.
-
Build and maintain automation frameworks using PowerShell, Microsoft Graph API and other scripting approaches for provisioning, compliance checks, reporting, remediation and decommissioning.
-
Develop self-healing and proactive remediation scripts to reduce repetitive operational effort and improve endpoint compliance posture.
-
Implement DevOps practices for endpoint configuration management including Git version control, Azure DevOps/GitHub Actions pipelines and Infrastructure-as-Code approaches such as Terraform or Bicep where suitable.
-
Support Zero Trust endpoint security architecture by defining security baselines, compliance controls, vulnerability remediation inputs and monitoring requirements.
-
Provide L3/L4 technical leadership for complex Intune, Autopilot, application deployment, compliance, enrollment and Windows provisioning issues, including high-severity P1/P2 scenarios.
-
Create and maintain architecture documents, SOPs, technical standards, operational readiness plans, knowledge transfer artefacts and governance frameworks.
-
Collaborate with security, infrastructure, application, workplace engineering and service operations teams to ensure endpoint services remain secure, scalable, supportable and aligned to service levels.
-
Mentor engineers and administrators, conduct technical workshops, support upskilling initiatives and drive continuous service improvement.
Skill Requirements
-
Strong experience in administration, architecture and configuration of Microsoft Intune enterprise environments.
-
Deep knowledge of Microsoft Endpoint Manager, Microsoft Entra ID, Conditional Access, MDM, MAM, Defender for Endpoint and endpoint compliance controls.
-
Hands-on experience with Windows Autopilot, Windows 10/11 provisioning, unattended enrollment, device lifecycle management and troubleshooting.
-
Expertise in PowerShell scripting and Microsoft Graph API based automation for Intune management, reporting and remediation.
-
Working knowledge of Python, Bash, Azure DevOps, GitHub Actions, Git version control and DevOps operating models for endpoint configuration management.
-
Experience with application deployment through Intune, deployment optimization, detection rules, app delivery troubleshooting and software distribution governance.
-
Experience with Windows 11 evergreen support, Windows and Office feature updates, update rings, Autopatch concepts, availability, performance optimization and reporting.
-
Understanding of SCCM/MECM co-management, cloud-native endpoint strategies and migration from legacy endpoint management platforms such as Workspace ONE to Microsoft Intune.
-
Knowledge of endpoint security baselines, compliance posture management, vulnerability remediation planning and integration with tools such as Defender for Endpoint, Qualys, Nexthink, SIEM or equivalent platforms.
-
Ability to manage technical teams and support Intune services either as a technical lead or individual contributor.
-
Experience handling and driving P1/P2 situations from an Intune and Windows device management perspective.
-
Experience in enterprise transformation, operational readiness, release readiness, service recovery, reporting dashboards, AI-assisted automation or Power BI based insights will be an added advantage