At a Glance
- Tasks: Manage and enhance hybrid identity platforms using Active Directory and Entra technologies.
- Company: Join a leading tech consultancy transforming businesses with innovative solutions.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Dynamic work environment with a focus on continuous improvement and innovation.
- Why this job: Be at the forefront of identity management and make a real impact in tech.
- Qualifications: Experience with Active Directory, Entra ID, and strong problem-solving skills.
The predicted salary is between 60000 - 80000 £ per year.
VE3 is a technology and business consultancy focused on delivering end-to-end technology solutions and products. We have successfully serviced enterprises across multiple markets, including the public and private sectors. Our services span all aspects of business, providing a holistic approach to managing an organization. We are committed to providing technical innovations and tools that empower organizations with critical information to facilitate decision-making that results in business transformation through cost savings and increased operational efficiency. Our commitment to quality is adopted throughout the organization and sets the foundation for delivering our full suite of capabilities.
Purpose of the Role
The Active Directory / Entra Specialist is the technical authority for the customer's hybrid identity platform. The role owns the design, operation, security, and continuous improvement of on-premises Active Directory Domain Services, Group Policy, ADFS, Entra ID (P2), Azure AD Connect, B2B and B2C flows, Conditional Access, MFA, Intune, and identity lifecycle automation across all in-scope business programmes. Identity is the foundation of every other workload in the estate. This role therefore underwrites the availability, security and compliance of M365, SharePoint, Power Platform, Dynamics 365, Fabric and Azure services. The post-holder is on the front line for any P1 authentication outage, Conditional Access misconfiguration, or directory replication failure.
Key Technical Responsibilities
- Hybrid Active Directory Operations
- Administer multi-forest on-premises Active Directory Domain Services (modern schema, WS2016+ functional level), including domain controllers, FSMO roles, sites and services, replication topology, DNS, DHCP, time service (NT5DS), and trust relationships.
- Maintain and harden Group Policy Objects across the estate, including baseline security GPOs, audit policies, AppLocker / WDAC, BitLocker, Windows Update for Business, and computer/user configuration drift detection.
- Operate and patch ADFS on legacy Windows Server (where present), administer claims rules, relying party trusts, certificate rotation, and plan migration of relying parties to Entra ID where commercially appropriate.
- Manage Azure AD Connect (auto-updating) including sync rules, source anchor, password hash sync / pass-through authentication, seamless SSO, staging mode validation, and re-permission / re-baseline activities.
- Diagnose and remediate replication failures, lingering objects, USN rollback, tombstone issues, NTLM/Kerberos auth failures, SPN duplication, and time-skew problems using repadmin, dcdiag, klist, KDCDiag, ADReplStatus and Microsoft 365 Connectivity Analyzer.
- Entra ID and Identity Lifecycle
- Administer Entra ID P2 tenants including users, groups, dynamic groups, administrative units, application registrations, enterprise applications, service principals, managed identities, and consent workflows.
- Configure and operate Conditional Access (sign-in risk, user risk, named locations, device compliance, session controls), Multi-Factor Authentication, passwordless sign-in (Windows Hello for Business, FIDO2, Authenticator), and Temporary Access Pass for onboarding.
- Operate Privileged Identity Management (PIM) for just-in-time role activation, approval workflows, access reviews and break-glass account governance; work with the on-premises PAM solution for tier-0 administration.
- Manage Entra ID B2B (guest collaboration) and B2C (custom policies, user flows, identity providers, custom branding, application integrations) for both internal and external-facing tenants.
- Implement Identity Governance: Entitlement Management, Access Packages, Access Reviews, Lifecycle Workflows, and HR-driven inbound provisioning where in scope.
- Endpoint Management with Intune
- Administer Microsoft Intune including device enrolment (Autopilot, Apple ABM, Android Enterprise), configuration profiles, compliance policies, app protection policies (MAM), Conditional Access integration, and Endpoint Privilege Management.
- Define and maintain Windows update rings, feature update profiles, driver update profiles, and Defender for Endpoint baselines via Intune Security Baselines.
- Operate Win32 / LOB / Microsoft Store app deployment, package authoring (intunewin), update rings, and supersedence chains.
- Co-manage devices with Configuration Manager where present, troubleshoot enrolment failures using IME logs, MDM Diagnostics Tool, and the Intune Troubleshooting portal.
- Identity Automation and Tooling
- Author and maintain PowerShell automation using Microsoft Graph PowerShell SDK, Az PowerShell, ExchangeOnlineManagement, MSOnline (legacy), AzureAD (legacy), and ActiveDirectory modules — including JML (Joiner-Mover-Leaver) workflows, group membership reconciliation, stale object cleanup, and licence assignment.
- Build and operate identity-related runbooks in Azure Automation, Logic Apps, or Power Automate where appropriate.
- Use Microsoft Graph (REST + SDK) for advanced reporting, bulk operations, and integration with HR / ITSM platforms.
- Service Operations
- Own L2/L3 incident, problem and change resolution for identity-related tickets, achieving the contractual SLAs: P1 1-hour response / 4-hour resolution, P2 4-hour response / 1 working day resolution, P3 1 working day response / 3 working days resolution.
- Lead root cause analysis (RCA) for P1 identity incidents and produce post-incident review reports within five working days.
- Contribute to monthly service reports with identity KPIs (sign-in success rate, MFA coverage, Conditional Access policy hits, privileged role activations, sync health, AAD Connect latency, certificate expiry watchlist).
- Participate in CAB review, change scheduling, and change risk assessment for identity changes; produce rollback plans and pre/post implementation checks.
Mandatory Technical Skills
- Active Directory Domain Services on Windows Server 2016+ including schema management, sites and services, GPO design, ADFS, AD CS, AD Recycle Bin, and DR/recovery procedures (authoritative restore).
- Entra ID P2 deep configuration: Conditional Access, MFA, PIM, Identity Protection (sign-in risk, user risk, risky users), Identity Governance, Application Proxy, External Identities (B2B, B2C custom policies), and Hybrid Identity (AAD Connect).
- Microsoft Intune end-to-end device and application management, including Autopilot pre-provisioning, compliance, configuration, and Endpoint Security baselines.
- PowerShell scripting (intermediate-to-advanced) using Microsoft Graph SDK, Az, and ActiveDirectory modules; ability to read / debug / extend existing scripts under change control.
- Working knowledge of Microsoft Defender for Identity (formerly Azure ATP) signals and integration with Defender XDR.
- Networking fundamentals: DNS, Kerberos, NTLM, OAuth 2.0, OpenID Connect, SAML 2.0, WS-Federation, certificate-based authentication, TLS/SSL troubleshooting, and modern auth flows.
- Working knowledge of ITIL v4 incident, problem, change and configuration management, and ITSM ticketing (e.g., ServiceNow, Jira Service Management).
Desirable Technical Skills
- Entra Permissions Management (CIEM).
- Microsoft Entra ID Verified ID (decentralised identity) familiarity.
- Group Policy Analytics in Intune for cloud migration.
- Experience operating tier-0 PAM solutions (CyberArk, BeyondTrust, Delinea) on-premises.
- Familiarity with FIDO2 hardware tokens, Windows LAPS (cloud), and Authentication Methods migration.
- Exposure to Azure VPN Gateway, ExpressRoute, and hybrid connectivity for identity authentication paths.
Required Certifications
- Microsoft Certified: Identity and Access Administrator Associate (SC-300) — mandatory.
- Microsoft 365 Certified: Administrator Expert (MS-102) — preferred.
- Microsoft Certified: Cybersecurity Architect Expert (SC-100) — desirable.
Active Directory and Entra Specialist in Maidenhead employer: Data Controller, VE Ltd
Contact Detail:
Data Controller, VE Ltd Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Active Directory and Entra Specialist in Maidenhead
✨Tip Number 1
Network, network, network! Get out there and connect with people in the industry. Attend meetups, webinars, or even just grab a coffee with someone who works at VE3. You never know when a casual chat could lead to your next opportunity.
✨Tip Number 2
Show off your skills! If you’ve got experience with Active Directory or Entra, consider creating a small project or demo that showcases your expertise. Share it on LinkedIn or during interviews to really impress potential employers.
✨Tip Number 3
Don’t just apply and wait! Follow up on your applications. A quick email to express your enthusiasm can set you apart from other candidates. Plus, it shows you’re genuinely interested in the role at VE3.
✨Tip Number 4
Use our website to apply! It’s the best way to ensure your application gets seen by the right people. Plus, you’ll find all the latest job openings and updates about VE3 right there.
We think you need these skills to ace Active Directory and Entra Specialist in Maidenhead
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Active Directory and Entra Specialist role. Highlight relevant experience and skills that match the job description. We want to see how your background aligns with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about this role and how you can contribute to our team. Keep it concise but impactful – we love a good story!
Show Off Your Technical Skills: Don’t hold back on showcasing your technical expertise! Mention specific tools and technologies you've worked with, especially those listed in the job description. We’re keen to see your hands-on experience with Active Directory, Entra ID, and more.
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It helps us keep everything organised and ensures your application gets the attention it deserves. Plus, it’s super easy!
How to prepare for a job interview at Data Controller, VE Ltd
✨Know Your Tech Inside Out
Make sure you’re well-versed in Active Directory, Entra ID, and all the related technologies mentioned in the job description. Brush up on your knowledge of multi-forest AD setups, Group Policy Objects, and Azure AD Connect. Being able to discuss these topics confidently will show that you’re the right fit for the role.
✨Prepare Real-World Examples
Think of specific instances where you've successfully managed identity-related issues or implemented solutions. Whether it’s troubleshooting a P1 authentication outage or configuring Conditional Access, having concrete examples ready will help you demonstrate your expertise and problem-solving skills.
✨Understand the Company’s Needs
Research VE3 and their approach to technology solutions. Understand their focus on business transformation and operational efficiency. Tailor your responses to show how your skills can directly contribute to their goals, especially in managing hybrid identity platforms.
✨Ask Insightful Questions
Prepare thoughtful questions about the team dynamics, ongoing projects, or future challenges they face with identity management. This not only shows your interest in the role but also gives you a chance to assess if the company aligns with your career aspirations.