At a Glance
- Tasks: Configure and secure Microsoft 365 identity and endpoint management for corporate devices.
- Company: Join AIC, a forward-thinking tech company focused on security and innovation.
- Benefits: Remote work flexibility and a chance to make a real impact in just 20 days.
- Other info: Opportunity to work independently and leave a lasting legacy in a dynamic environment.
- Why this job: Be at the forefront of Microsoft technology and enhance corporate security practices.
- Qualifications: Experience with Microsoft Entra ID, Intune, and Windows Autopilot is essential.
AIC is seeking an experienced Microsoft Entra ID, Microsoft Intune and Windows Autopilot specialist to support the hardening, configuration and operationalisation of our corporate Microsoft 365 identity and endpoint management environment. This is a fixed 20 working day contract engagement, focused on delivering a secure, documented and repeatable baseline for corporate device onboarding, endpoint management, identity access control and administrative governance.
The successful specialist will be expected to work independently, provide clear technical recommendations, configure the required Microsoft 365 services, validate the implementation through pilot devices, and leave AIC with a documented, supportable operating model.
Engagement Overview
- Contract Type: Fixed-term specialist contract
- Duration: 20 working days
- Location: Remote / hybrid by agreement
- Start Date: As soon as practicable
- Client: AIC
- Focus Area: Microsoft 365 security, endpoint management, identity hardening and device onboarding
Core Objective
The objective of this engagement is to design, configure, harden and document AIC’s Microsoft corporate device and identity management environment using Microsoft Entra ID, Microsoft Intune and Windows Autopilot. The engagement should result in a secure and repeatable operating baseline that allows AIC to onboard, manage, monitor and secure corporate Windows devices in a consistent way.
Scope of Work
The specialist will be responsible for reviewing the existing Microsoft 365 environment and implementing a hardened baseline across identity, access, endpoint management and device provisioning. The scope will include, but is not limited to:
- Discovery and Current State Review
- Review AIC’s current Microsoft 365, Entra ID and Intune configuration, including users, groups, roles, licensing, devices, domains, administrative access, security defaults, existing conditional access policies and endpoint management readiness.
- Identify configuration gaps, risks, duplication, misalignment and priority remediation activities.
- Produce a short current-state findings summary with practical recommendations.
- Microsoft Entra ID Configuration and Hardening
- Design and implement a controlled Entra ID group structure using a clear naming convention suitable for ongoing operational use.
- Review and rationalise administrative roles and privileged access.
- Configure or recommend appropriate role-based access controls.
- Review multifactor authentication configuration and enforcement.
- Configure conditional access policies aligned to corporate security requirements.
- Review user access, guest access and external collaboration settings.
- Advise on identity governance improvements where relevant.
- Microsoft Intune Baseline Configuration
- Configure Microsoft Intune to manage corporate Windows endpoints securely and consistently.
- Create device compliance policies.
- Create device configuration profiles.
- Apply Microsoft security baseline policies where appropriate.
- Configure endpoint protection settings.
- Configure BitLocker enforcement and recovery key handling.
- Configure Windows Hello for Business where appropriate.
- Configure local administrator management approach, including recommendations for least privilege and administrative access control.
- Configure update rings and Windows Update for Business policies.
- Define device categories, assignment groups and deployment targeting logic.
- Windows Autopilot Setup
- Configure Windows Autopilot for corporate device provisioning.
- Create and test Autopilot deployment profiles.
- Define the user-driven enrolment experience.
- Configure enrolment status page settings.
- Validate device registration and enrolment flows.
- Support the enrolment of pilot devices.
- Document the Autopilot process for future internal use.
- Application and Policy Deployment
- Configure baseline application deployment where required.
- Support deployment of core corporate applications, security tooling and standard productivity applications.
- Validate policy assignment and application installation behaviour across pilot devices.
- Identify any blockers, licensing constraints or endpoint compatibility issues.
- Security and Governance Alignment
- Ensure the environment is configured in a way that supports a secure corporate operating model.
- Where applicable, align recommendations with recognised good practice, including Microsoft security guidance, Cyber Essentials expectations, NCSC-aligned principles and ISO 27001-style access control and asset management requirements.
- Produce a prioritised security improvement backlog for any items that cannot reasonably be completed within the 20 working day engagement.
- Testing, Validation and Handover
- Test the configuration using one or more pilot devices.
- Validate user onboarding, device enrolment, compliance evaluation, policy application and administrative management.
- Provide clear handover documentation.
- Provide a final walkthrough to AIC covering configuration, ongoing administration, known risks and recommended next steps.
Required Deliverables
By the end of the 20 working day engagement, the specialist will be expected to deliver:
- Current-state review and findings summary.
- Entra ID group and administrative role model.
- Conditional access policy set.
- Intune compliance policy baseline.
- Intune configuration policy baseline.
- Windows security baseline configuration.
- BitLocker and endpoint protection configuration.
- Windows Autopilot deployment profile and tested enrolment process.
- Update ring and patching configuration.
- Application deployment baseline, where agreed.
- Successfully enrolled pilot device or devices.
- Handover documentation and administrative runbook.
- Known issues register.
- Prioritised remediation and improvement backlog.
Required Experience
The successful specialist should have demonstrable hands-on experience with:
- Microsoft Entra ID
- Microsoft Intune
- Windows Autopilot
- Microsoft 365 administration
- Windows 10 and Windows 11 endpoint management
- Conditional Access
- Multifactor authentication
- Device compliance policies
- Endpoint configuration profiles
- Microsoft Defender for Endpoint
- BitLocker
- Windows Hello for Business
- Role-based access control
- PowerShell
- Microsoft security baselines
- Corporate device onboarding and lifecycle management
Desirable Experience
The following experience would be advantageous:
- Cyber Essentials or Cyber Essentials Plus readiness
- NCSC-aligned security configuration
- ISO 27001-aligned access control and asset management
- Microsoft Defender for Cloud Apps
- Microsoft Purview sensitivity labels
- SharePoint and OneDrive security hardening
- Apple Business Manager and iOS/iPadOS device management
- Azure infrastructure awareness
- Secure administration in defence, government or high-assurance environments
Working Approach
We are looking for a practical, delivery-focused specialist who can balance good security practice with operational usability. The successful contractor must be able to work with minimal supervision, explain technical decisions clearly, document their work properly and leave behind a supportable configuration rather than an undocumented one-off build. This engagement is output-focused. The expectation is not simply to advise, but to configure, test, document and hand over a working baseline.
Acceptance Criteria
The engagement will be considered successfully delivered when:
- AIC has a working Entra ID, Intune and Autopilot baseline.
- Pilot Windows devices can be enrolled through Autopilot.
- Corporate devices receive the agreed compliance, configuration, security and update policies.
- Conditional access and multifactor authentication controls are configured and documented.
- Administrative roles and group structures are documented.
- AIC receives clear handover documentation and a practical operating runbook.
- Known gaps, risks and future improvements are documented in a prioritised backlog.
Contract Structure
This is a fixed 20 working day engagement.
Applicants should provide:
- Availability.
- Day rate or fixed price for the 20 working day engagement.
- Relevant Microsoft certifications, if held.
- Summary of similar Intune, Entra ID or Autopilot projects delivered.
- Confirmation of ability to work with sensitive corporate environments.
- References or examples of previous delivery, where available.
How to Apply
Please email us with a short summary of your relevant experience, your availability, your proposed commercial terms and examples of similar Microsoft Entra ID, Intune or Windows Autopilot environments you have configured or hardened. AIC is particularly interested in specialists who can demonstrate practical delivery experience, strong documentation discipline and a security-first approach to corporate endpoint management.
Executive Microsoft Entra ID / Intune / Windows Autopilot Specialist Engineer - 20 Working Day ContractAssistant in Congleton employer: AIC Professional Services UK Ltd
AIC is an exceptional employer that values expertise and offers a collaborative work culture, allowing specialists to thrive in a remote or hybrid environment. With a focus on professional growth, AIC provides opportunities for meaningful contributions to corporate security and endpoint management, ensuring that employees leave behind a robust and documented operating model. Join us to be part of a team that prioritises innovation and security in the ever-evolving landscape of Microsoft 365.
Contact Details:
AIC Professional Services UK Ltd Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Executive Microsoft Entra ID / Intune / Windows Autopilot Specialist Engineer - 20 Working Day ContractAssistant in Congleton
✨Tip Number 1
Network, network, network! Reach out to your connections in the Microsoft ecosystem. Let them know you're on the lookout for opportunities like the Executive Microsoft Entra ID role. You never know who might have a lead or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by brushing up on your technical skills related to Microsoft Entra ID, Intune, and Windows Autopilot. Be ready to discuss your hands-on experience and how you've tackled similar projects in the past. Confidence is key!
✨Tip Number 3
Don’t just apply through job boards; head over to our website and submit your application there. It shows initiative and gives you a better chance of standing out from the crowd. Plus, we love seeing candidates who take that extra step!
✨Tip Number 4
Follow up after interviews with a thank-you note. Mention something specific from your conversation to remind them of your fit for the role. It’s a small gesture that can leave a lasting impression and keep you top of mind.
We think you need these skills to ace Executive Microsoft Entra ID / Intune / Windows Autopilot Specialist Engineer - 20 Working Day ContractAssistant in Congleton
Some tips for your application 🫡
Show Off Your Experience:When you’re writing your application, make sure to highlight your hands-on experience with Microsoft Entra ID, Intune, and Windows Autopilot. We want to see how you've tackled similar projects in the past, so don’t hold back on the details!
Be Clear and Concise:Keep your application straightforward and to the point. We appreciate clarity, so avoid jargon and make sure your technical recommendations are easy to understand. This will help us see your thought process and how you approach challenges.
Document Everything:Since documentation is key for this role, show us your skills by including examples of your previous documentation work. Whether it’s a handover document or a configuration guide, we want to know you can leave behind a solid operating model.
Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to keep track of your application and ensure it gets the attention it deserves. Plus, it makes the whole process smoother for everyone involved.
How to prepare for a job interview at AIC Professional Services UK Ltd
✨Know Your Stuff
Make sure you brush up on Microsoft Entra ID, Intune, and Windows Autopilot. Familiarise yourself with the latest features and best practices, as well as any recent updates. Being able to discuss specific configurations or security measures will show that you're not just knowledgeable but also passionate about the role.
✨Prepare Real-World Examples
Think of specific projects where you've successfully implemented or managed Microsoft 365 environments. Be ready to share how you identified gaps, configured services, and documented processes. This will help demonstrate your hands-on experience and problem-solving skills.
✨Ask Insightful Questions
Prepare a few thoughtful questions about AIC's current Microsoft 365 setup or their goals for this engagement. This shows that you're genuinely interested in the role and helps you understand their needs better, which can guide your responses during the interview.
✨Show Your Documentation Skills
Since documentation is key in this role, be prepared to discuss how you approach documenting configurations and processes. You might even want to bring examples of your previous work to showcase your attention to detail and organisational skills.