Job Summary
The L2 Active Directory Engineer will be responsible for supporting and administering enterprise Identity and Access Management (IAM) services, Active Directory, Microsoft Entra ID (Azure AD), user provisioning, access management, authentication services, and directory infrastructure operations.
The role will serve as the escalation point from Service Desk and Deskside teams for identity-related incidents, service requests, and operational activities while ensuring compliance with security standards, audit requirements, and operational service levels.
As defined within the SOW, the engineer will support account management, password management, access provisioning, and directory services operations across the enterprise environment.
Key Responsibilities
Active Directory Administration
Administer and support Microsoft Active Directory infrastructure.
Manage user, group, computer, and organizational unit (OU) administration.
Perform user lifecycle management (Joiner, Mover, Leaver processes).
Create and maintain Group Policies (GPOs).
Manage Active Directory replication and directory health monitoring.
Perform account audits and directory clean-up activities.
Support troubleshooting of authentication and directory-related issues.
Microsoft Entra ID (Azure AD) Administration
Manage Microsoft Entra ID tenant administration.
Support identity synchronization and hybrid identity operations.
Administer Conditional Access Policies.
Manage Azure AD Connect synchronization health.
Support Self-Service Password Reset (SSPR).
Troubleshoot authentication and synchronization failures.
Support identity governance initiatives.
Skill Requirements
Primary Skills
Microsoft Active Directory
Microsoft Entra ID (Azure AD)
Azure AD Connect
Group Policy Administration
LDAP & Authentication Services
DNS & DHCP Fundamentals
Identity & Access Management (IAM)
User Lifecycle Management (JML)
Microsoft Windows Server Administration
Multi-Factor Authentication (MFA)
Other Requirements
Incident & Service Request Management
Provide L2 support for directory and identity-related incidents.
Troubleshoot account lockouts, authentication failures, access issues, and synchronization problems.
Resolve complex user access issues escalated from Service Desk.
Perform root cause analysis for recurring IAM incidents.
Coordinate with infrastructure, security, and application teams for issue resolution.
Support major incident management when identity services are impacted.
Security & Compliance
Support security monitoring and remediation activities.
Maintain compliance with audit and regulatory requirements.
Participate in access reviews and certification exercises.
Support vulnerability remediation and security hardening activities.
Maintain compliance with corporate security standards and governance policies.
Automation & Continuous Improvement
Develop PowerShell scripts for automation of repetitive tasks.
Automate user provisioning and reporting processes.
Improve operational efficiency through workflow optimization.
Identify opportunities to enhance identity management services.
Support self-service and automation initiatives.
Reporting & Documentation
Maintain accurate documentation, SOPs, and knowledge articles.
Produce operational and compliance reports.
Update runbooks and support documentation regularly.
Participate in governance reviews and service improvement initiatives.