Job Summary
AD On‑Prem, Entra ID & DFS Subject Matter Expert (L3) The AD On‑Prem, Entra ID & DFS Subject Matter Expert (L3) is a senior technical authority responsible for end‑to‑end ownership, architecture, and strategic governance of enterprise identity and directory services in a large‑scale hybrid environment. The role provides expert‑level (L3) support across Active Directory (On‑Prem), Microsoft Entra ID, and Windows Distributed File System (DFS), ensuring platform stability, security, scalability, and regulatory compliance. This position acts as the final escalation point for complex and high‑impact incidents, leading major incident resolution, root cause analysis, and long‑term remediation across authentication, hybrid identity, federation, security, and DFS services. The role defines technical standards, reference architectures, and best practices for multi‑domain AD forests, Entra ID integrations, IAM controls, and DFS architecture, while guiding enterprise adoption and secure operation of identity services. In addition to technical leadership, the L3 SME owns security and compliance posture for identity platforms, including MFA, conditional access, identity governance, auditing, and access protection. The role drives service optimization through performance and capacity monitoring, automation using PowerShell, and proactive improvement initiatives. As a senior authority, the role mentors L1/L2 teams, approves operational procedures, supports disaster recovery planning, and acts as a trusted advisor to IT leadership on identity strategy, risk, and transformation initiatives.
Key Responsibilities
Strong working experience and expert knowledge on Active Directory, DNS, DHCP, IIS, Group policy management, Monitoring and Reporting, and Microsoft Entra ID • Strong working experience on AD Administration, Hybrid AD environment, and managing Multi domain forest. • Knowledge on Promotion and Demotion of Domain Controllers, Health Monitoring, and troubleshooting issues related to on-prem DCs. • Group Policy Deployment and troubleshooting using ADGPM. • Configuration and Troubleshooting LDAP and Authentication issues. • Knowledge of PKI certificates. • Provide advanced technical support and troubleshooting for Entra ID, ensuring high availability and performance. • Manage and maintain the Entra ID environment, including configuration, updates, and security compliance. • Conduct root cause analysis for complex technical issues and implement long-term solutions. • Oversee the deployment and management of Entra ID services, including user and group management, application integration, and conditional access policies. • Knowledge of managing identity governance and lifecycle management processes. • Ensure compliance with security policies and best practices. • Assist with issues related to Entra ID, including account access, MFA, and SSO. • Monitor customer feedback and proactively address common issues. • Develop and implement automation scripts using PowerShell to streamline identity management tasks and improve operational efficiency. • Automate routine maintenance tasks, such as user provisioning, deprovisioning, and access reviews. • Create and maintain detailed documentation for all automation scripts and processes. • Handle escalated incidents and work closely with other IT teams to resolve complex issues. • Participate in support for critical issues. • Expert knowledge of Custom domain names in Azure • Expert knowledge of auditing the Microsoft Entra ID Sign in logs and monitoring component. • Strong understanding of IAM concepts, including SSO, MFA, conditional access, and identity governance. • Expert knowledge of Microsoft Entra ID security features • Knowledge on PowerShell Scripting and Automation tasks related to AD. • Perform Root Cause Analysis, Problem Management and Documentation. • Knowledge on Azure SSO Federation (SAML, OAuth), Azure Authentication issues, Sign-in/Audit log reviews • Knowledge on Microsoft Intune Company Portal, troubleshooting enrollment issues and App publishing. • Extensive experience with the deployment, management, and troubleshooting of Entra ID services. • Familiarity with Microsoft Entra ID Connect, Microsoft Entra ID B2B, and Microsoft Entra ID B2C. • Experience with integrating Entra ID with various applications and services. • Proficiency in scripting languages such as PowerShell, with the ability to write, debug, and maintain complex scripts. • Experience with automation tools and frameworks, such as Azure Automation and Microsoft Endpoint Manager. • Knowledge of security best practices and compliance requirements for identity management. • Experience with implementing and managing security measures, such as conditional access policies and identity protection. • Excellent communication skills to interact with users, stakeholders, and team members. • Ability to create clear and concise documentation, including technical guides, user manuals, and training materials. Role and Responsibilities for Windows Distributed File System (DFS) Operational Support • Provide Level 2 operational support for Windows DFS Namespace (DFS N) and DFS Replication (DFS R) services. • Handle incidents, service requests, and standard changes related to DFS within agreed SLAs. • Perform third line troubleshooting for file access
Skill Requirements
Active Directory (On‑Prem) – multi‑domain forests, DNS, DHCP, GPO, AD GPM • Hybrid Identity – AD & Microsoft Entra ID integration • Microsoft Entra ID (Azure AD) – IAM, SSO, MFA, Conditional Access, Identity Governance • Authentication & Federation – LDAP, SAML, OAuth, Azure SSO • Security & Compliance – Entra ID security features, auditing, sign‑in & audit logs, PKI • DFS (DFSN & DFSR) – Namespace management, Replication, troubleshooting, DR • PowerShell Automation – Scripting for AD/Entra administration and lifecycle management • Monitoring & Troubleshooting – RCA, performance, availability, complex incident handling • Application & Device Integration – Entra app integrations, Intune administration • Backup & Recovery – DFS data restore and disaster recovery support
Other Requirements
: Fluent English