Active Directory and Entra Specialist in Maidenhead
Active Directory and Entra Specialist

Active Directory and Entra Specialist in Maidenhead

Maidenhead Full-Time 55000 - 65000 £ / year (est.) No home office possible
VE3

At a Glance

  • Tasks: Manage and enhance hybrid identity platforms using Active Directory and Entra technologies.
  • Company: Join a forward-thinking tech company focused on identity security.
  • Benefits: Attractive salary, flexible working options, and opportunities for professional growth.
  • Other info: Dynamic team environment with excellent career advancement potential.
  • Why this job: Be at the forefront of identity management and make a significant impact.
  • Qualifications: Experience with Active Directory, Entra ID, and strong problem-solving skills required.

The predicted salary is between 55000 - 65000 £ per year.

The Active Directory / Entra Specialist is the technical authority for the customer's hybrid identity platform. The role owns the design, operation, security, and continuous improvement of on-premises Active Directory Domain Services, Group Policy, ADFS, Entra ID (P2), Azure AD Connect, B2B and B2C flows, Conditional Access, MFA, Intune, and identity lifecycle automation across all in-scope business programmes.

Identity is the foundation of every other workload in the estate. This role therefore underwrites the availability, security and compliance of M365, SharePoint, Power Platform, Dynamics 365, Fabric and Azure services. The post-holder is on the front line for any P1 authentication outage, Conditional Access misconfiguration, or directory replication failure.

Key Technical Responsibilities

  • Administer multi-forest on-premises Active Directory Domain Services (modern schema, WS2016+ functional level), including domain controllers, FSMO roles, sites and services, replication topology, DNS, DHCP, time service (NT5DS), and trust relationships.
  • Maintain and harden Group Policy Objects across the estate, including baseline security GPOs, audit policies, AppLocker / WDAC, BitLocker, Windows Update for Business, and computer/user configuration drift detection.
  • Operate and patch ADFS on legacy Windows Server (where present), administer claims rules, relying party trusts, certificate rotation, and plan migration of relying parties to Entra ID where commercially appropriate.
  • Manage Azure AD Connect (auto-updating) including sync rules, source anchor, password hash sync / pass-through authentication, seamless SSO, staging mode validation, and re-permission / re-baseline activities.
  • Diagnose and remediate replication failures, lingering objects, USN rollback, tombstone issues, NTLM/Kerberos auth failures, SPN duplication, and time-skew problems using repadmin, dcdiag, klist, KDCDiag, ADReplStatus and Microsoft 365 Connectivity Analyzer.

Entra ID and Identity Lifecycle

  • Administer Entra ID P2 tenants including users, groups, dynamic groups, administrative units, application registrations, enterprise applications, service principals, managed identities, and consent workflows.
  • Configure and operate Conditional Access (sign-in risk, user risk, named locations, device compliance, session controls), Multi-Factor Authentication, passwordless sign-in (Windows Hello for Business, FIDO2, Authenticator), and Temporary Access Pass for onboarding.
  • Operate Privileged Identity Management (PIM) for just-in-time role activation, approval workflows, access reviews and break-glass account governance; work with the on-premises PAM solution for tier-0 administration.
  • Manage Entra ID B2B (guest collaboration) and B2C (custom policies, user flows, identity providers, custom branding, application integrations) for both internal and external-facing tenants.
  • Implement Identity Governance: Entitlement Management, Access Packages, Access Reviews, Lifecycle Workflows, and HR-driven inbound provisioning where in scope.

Endpoint Management with Intune

  • Administer Microsoft Intune including device enrolment (Autopilot, Apple ABM, Android Enterprise), configuration profiles, compliance policies, app protection policies (MAM), Conditional Access integration, and Endpoint Privilege Management.
  • Define and maintain Windows update rings, feature update profiles, driver update profiles, and Defender for Endpoint baselines via Intune Security Baselines.
  • Operate Win32 / LOB / Microsoft Store app deployment, package authoring (intunewin), update rings, and supersedence chains.
  • Co-manage devices with Configuration Manager where present, troubleshoot enrolment failures using IME logs, MDM Diagnostics Tool, and the Intune Troubleshooting portal.

Identity Automation and Tooling

  • Author and maintain PowerShell automation using Microsoft Graph PowerShell SDK, Az PowerShell, ExchangeOnlineManagement, MSOnline (legacy), AzureAD (legacy), and ActiveDirectory modules — including JML (Joiner-Mover-Leaver) workflows, group membership reconciliation, stale object cleanup, and licence assignment.
  • Build and operate identity-related runbooks in Azure Automation, Logic Apps, or Power Automate where appropriate.
  • Use Microsoft Graph (REST + SDK) for advanced reporting, bulk operations, and integration with HR / ITSM platforms.

Service Operations

  • Own L2/L3 incident, problem and change resolution for identity-related tickets, achieving the contractual SLAs: P1 1-hour response / 4-hour resolution, P2 4-hour response / 1 working day resolution, P3 1 working day response / 3 working days resolution.
  • Lead root cause analysis (RCA) for P1 identity incidents and produce post-incident review reports within five working days.
  • Contribute to monthly service reports with identity KPIs (sign-in success rate, MFA coverage, Conditional Access policy hits, privileged role activations, sync health, AAD Connect latency, certificate expiry watchlist).
  • Participate in CAB review, change scheduling, and change risk assessment for identity changes; produce rollback plans and pre/post implementation checks.

Mandatory Technical Skills

  • Active Directory Domain Services on Windows Server 2016+ including schema management, sites and services, GPO design, ADFS, AD CS, AD Recycle Bin, and DR/recovery procedures (authoritative restore).
  • Entra ID P2 deep configuration: Conditional Access, MFA, PIM, Identity Protection (sign-in risk, user risk, risky users), Identity Governance, Application Proxy, External Identities (B2B, B2C custom policies), and Hybrid Identity (AAD Connect).
  • Microsoft Intune end-to-end device and application management, including Autopilot pre-provisioning, compliance, configuration, and Endpoint Security baselines.
  • PowerShell scripting (intermediate-to-advanced) using Microsoft Graph SDK, Az, and ActiveDirectory modules; ability to read / debug / extend existing scripts under change control.
  • Working knowledge of Microsoft Defender for Identity (formerly Azure ATP) signals and integration with Defender XDR.
  • Networking fundamentals: DNS, Kerberos, NTLM, OAuth 2.0, OpenID Connect, SAML 2.0, WS-Federation, certificate-based authentication, TLS/SSL troubleshooting, and modern auth flows.
  • Working knowledge of ITIL v4 incident, problem, change and configuration management, and ITSM ticketing (e.g., ServiceNow, Jira Service Management).

Desirable Technical Skills

  • Entra Permissions Management (CIEM).
  • Microsoft Entra ID Verified ID (decentralised identity) familiarity.
  • Group Policy Analytics in Intune for cloud migration.
  • Experience operating tier-0 PAM solutions (CyberArk, BeyondTrust, Delinea) on-premises.
  • Familiarity with FIDO2 hardware tokens, Windows LAPS (cloud), and Authentication Methods migration.
  • Exposure to Azure VPN Gateway, ExpressRoute, and hybrid connectivity for identity authentication paths.

Required Certifications

  • Microsoft Certified: Identity and Access Administrator Associate (SC-300) — mandatory.
  • Microsoft Certified: Endpoint Administrator Associate (MD-102) — mandatory.
  • Microsoft 365 Certified: Administrator Expert (MS-102) — preferred.
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100) — desirable.
  • ITIL 4 Foundation — preferred.

Active Directory and Entra Specialist in Maidenhead employer: VE3

As an Active Directory and Entra Specialist, you will thrive in a dynamic work environment that prioritises innovation and professional growth. Our company offers comprehensive training programmes, competitive benefits, and a collaborative culture that encourages knowledge sharing and teamwork. Located in a vibrant area, we provide unique opportunities for networking and career advancement, making us an exceptional employer for those seeking meaningful and rewarding employment.
VE3

Contact Detail:

VE3 Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Active Directory and Entra Specialist in Maidenhead

✨Tip Number 1

Network, network, network! Get out there and connect with folks in the industry. Attend meetups, webinars, or even just grab a coffee with someone who works in Active Directory or Entra. You never know who might have a lead on your dream job!

✨Tip Number 2

Show off your skills! Create a personal project or contribute to open-source projects that showcase your expertise in Active Directory and Entra. This not only builds your portfolio but also gives you something tangible to discuss during interviews.

✨Tip Number 3

Prepare for those tricky interview questions! Brush up on your knowledge of hybrid identity platforms, ADFS, and Azure AD Connect. We recommend practicing with a friend or using mock interview platforms to get comfortable with the format.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search!

We think you need these skills to ace Active Directory and Entra Specialist in Maidenhead

Active Directory Domain Services
Group Policy Management
ADFS Administration
Azure AD Connect
Conditional Access Configuration
Multi-Factor Authentication (MFA)
Microsoft Intune Administration
PowerShell Scripting
Identity Lifecycle Management
Troubleshooting Authentication Issues
Incident Management
Root Cause Analysis (RCA)
Networking Fundamentals
ITIL v4 Knowledge

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Active Directory and Entra Specialist role. Highlight your experience with hybrid identity platforms, Azure AD, and any relevant certifications. We want to see how your skills match what we're looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about identity management and how your background makes you a great fit for our team. Keep it concise but impactful – we love a good story!

Show Off Your Technical Skills: Don’t hold back on showcasing your technical expertise! Mention specific tools and technologies you've worked with, like ADFS, Intune, or PowerShell scripting. We’re keen to know how you’ve tackled challenges in previous roles.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining the StudySmarter family!

How to prepare for a job interview at VE3

✨Know Your Tech Inside Out

Make sure you’re well-versed in Active Directory, Entra ID, and all the related technologies mentioned in the job description. Brush up on your knowledge of multi-forest setups, Group Policy Objects, and Azure AD Connect. Being able to discuss these topics confidently will show that you're the right fit for the role.

✨Prepare for Scenario-Based Questions

Expect questions that ask how you would handle specific situations, like a P1 authentication outage or a Conditional Access misconfiguration. Think through potential scenarios and prepare structured responses that highlight your problem-solving skills and technical expertise.

✨Showcase Your Automation Skills

Since PowerShell scripting is crucial for this role, be ready to discuss your experience with automation. Bring examples of scripts you've written or modified, and explain how they improved processes. This will demonstrate your ability to streamline identity management tasks effectively.

✨Understand the Business Impact

Remember that identity management is not just about technology; it’s about ensuring security and compliance across the business. Be prepared to discuss how your work in this area can impact overall business operations and user experience. This shows you understand the bigger picture.

Active Directory and Entra Specialist in Maidenhead
VE3
Location: Maidenhead

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>