Active Directory and Entra Specialist(Freelance/Contract) in Maidenhead
Active Directory and Entra Specialist(Freelance/Contract)

Active Directory and Entra Specialist(Freelance/Contract) in Maidenhead

Maidenhead Freelance 50000 - 70000 £ / year (est.) Home office (partial)
VE3

At a Glance

  • Tasks: Manage and enhance hybrid identity platforms using Active Directory and Entra technologies.
  • Company: Join a forward-thinking tech company focused on identity security.
  • Benefits: Flexible freelance role with competitive pay and opportunities for skill development.
  • Other info: Dynamic work environment with potential for career advancement.
  • Why this job: Be at the forefront of identity management and make a significant impact.
  • Qualifications: Experience with Active Directory, Entra ID, and PowerShell scripting required.

The predicted salary is between 50000 - 70000 £ per year.

The Active Directory / Entra Specialist is the technical authority for the customer's hybrid identity platform. The role owns the design, operation, security, and continuous improvement of on-premises Active Directory Domain Services, Group Policy, ADFS, Entra ID (P2), Azure AD Connect, B2B and B2C flows, Conditional Access, MFA, Intune, and identity lifecycle automation across all in-scope business programmes.

Identity is the foundation of every other workload in the estate. This role therefore underwrites the availability, security and compliance of M365, SharePoint, Power Platform, Dynamics 365, Fabric and Azure services. The post-holder is on the front line for any P1 authentication outage, Conditional Access misconfiguration, or directory replication failure.

Key Technical Responsibilities

  • Administer multi-forest on-premises Active Directory Domain Services (modern schema, WS2016+ functional level), including domain controllers, FSMO roles, sites and services, replication topology, DNS, DHCP, time service (NT5DS), and trust relationships.
  • Maintain and harden Group Policy Objects across the estate, including baseline security GPOs, audit policies, AppLocker / WDAC, BitLocker, Windows Update for Business, and computer/user configuration drift detection.
  • Operate and patch ADFS on legacy Windows Server (where present), administer claims rules, relying party trusts, certificate rotation, and plan migration of relying parties to Entra ID where commercially appropriate.
  • Manage Azure AD Connect (auto-updating) including sync rules, source anchor, password hash sync / pass-through authentication, seamless SSO, staging mode validation, and re-permission / re-baseline activities.
  • Diagnose and remediate replication failures, lingering objects, USN rollback, tombstone issues, NTLM/Kerberos auth failures, SPN duplication, and time-skew problems using repadmin, dcdiag, klist, KDCDiag, ADReplStatus and Microsoft 365 Connectivity Analyzer.

Entra ID and Identity Lifecycle

  • Administer Entra ID P2 tenants including users, groups, dynamic groups, administrative units, application registrations, enterprise applications, service principals, managed identities, and consent workflows.
  • Configure and operate Conditional Access (sign-in risk, user risk, named locations, device compliance, session controls), Multi-Factor Authentication, passwordless sign-in (Windows Hello for Business, FIDO2, Authenticator), and Temporary Access Pass for onboarding.
  • Operate Privileged Identity Management (PIM) for just-in-time role activation, approval workflows, access reviews and break-glass account governance; work with the on-premises PAM solution for tier-0 administration.
  • Manage Entra ID B2B (guest collaboration) and B2C (custom policies, user flows, identity providers, custom branding, application integrations) for both internal and external-facing tenants.
  • Implement Identity Governance: Entitlement Management, Access Packages, Access Reviews, Lifecycle Workflows, and HR-driven inbound provisioning where in scope.

Endpoint Management with Intune

  • Administer Microsoft Intune including device enrolment (Autopilot, Apple ABM, Android Enterprise), configuration profiles, compliance policies, app protection policies (MAM), Conditional Access integration, and Endpoint Privilege Management.
  • Define and maintain Windows update rings, feature update profiles, driver update profiles, and Defender for Endpoint baselines via Intune Security Baselines.
  • Operate Win32 / LOB / Microsoft Store app deployment, package authoring (intunewin), update rings, and supersedence chains.
  • Co-manage devices with Configuration Manager where present, troubleshoot enrolment failures using IME logs, MDM Diagnostics Tool, and the Intune Troubleshooting portal.

Identity Automation and Tooling

  • Author and maintain PowerShell automation using Microsoft Graph PowerShell SDK, Az PowerShell, ExchangeOnlineManagement, MSOnline (legacy), AzureAD (legacy), and ActiveDirectory modules — including JML (Joiner-Mover-Leaver) workflows, group membership reconciliation, stale object cleanup, and licence assignment.
  • Build and operate identity-related runbooks in Azure Automation, Logic Apps, or Power Automate where appropriate.
  • Use Microsoft Graph (REST + SDK) for advanced reporting, bulk operations, and integration with HR / ITSM platforms.

Service Operations

  • Own L2/L3 incident, problem and change resolution for identity-related tickets, achieving the contractual SLAs: P1 1-hour response / 4-hour resolution, P2 4-hour response / 1 working day resolution, P3 1 working day response / 3 working days resolution.
  • Lead root cause analysis (RCA) for P1 identity incidents and produce post-incident review reports within five working days.
  • Contribute to monthly service reports with identity KPIs (sign-in success rate, MFA coverage, Conditional Access policy hits, privileged role activations, sync health, AAD Connect latency, certificate expiry watchlist).
  • Participate in CAB review, change scheduling, and change risk assessment for identity changes; produce rollback plans and pre/post implementation checks.

Mandatory Technical Skills

  • Active Directory Domain Services on Windows Server 2016+ including schema management, sites and services, GPO design, ADFS, AD CS, AD Recycle Bin, and DR/recovery procedures (authoritative restore).
  • Entra ID P2 deep configuration: Conditional Access, MFA, PIM, Identity Protection (sign-in risk, user risk, risky users), Identity Governance, Application Proxy, External Identities (B2B, B2C custom policies), and Hybrid Identity (AAD Connect).
  • Microsoft Intune end-to-end device and application management, including Autopilot pre-provisioning, compliance, configuration, and Endpoint Security baselines.
  • PowerShell scripting (intermediate-to-advanced) using Microsoft Graph SDK, Az, and ActiveDirectory modules; ability to read/debug/extend existing scripts under change control.
  • Working knowledge of Microsoft Defender for Identity (formerly Azure ATP) signals and integration with Defender XDR.
  • Networking fundamentals: DNS, Kerberos, NTLM, OAuth 2.0, OpenID Connect, SAML 2.0, WS-Federation, certificate-based authentication, TLS/SSL troubleshooting, and modern auth flows.
  • Working knowledge of ITIL v4 incident, problem, change and configuration management, and ITSM ticketing (e.g., ServiceNow, Jira Service Management).

Desirable Technical Skills

  • Entra Permissions Management (CIEM).
  • Microsoft Entra ID Verified ID (decentralised identity) familiarity.
  • Group Policy Analytics in Intune for cloud migration.
  • Experience operating tier-0 PAM solutions (CyberArk, BeyondTrust, Delinea) on-premises.
  • Familiarity with FIDO2 hardware tokens, Windows LAPS (cloud), and Authentication Methods migration.
  • Exposure to Azure VPN Gateway, ExpressRoute, and hybrid connectivity for identity authentication paths.

Required Certifications

  • Microsoft Certified: Identity and Access Administrator Associate (SC-300) — mandatory.
  • Microsoft Certified: Endpoint Administrator Associate (MD-102) — mandatory.
  • Microsoft 365 Certified: Administrator Expert (MS-102) — preferred.
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100) — desirable.
  • ITIL 4 Foundation — preferred.

Active Directory and Entra Specialist(Freelance/Contract) in Maidenhead employer: VE3

As an Active Directory and Entra Specialist, you will join a forward-thinking team that prioritises innovation and continuous improvement in a dynamic work environment. Our company fosters a culture of collaboration and professional growth, offering opportunities for skill enhancement and career advancement while working on cutting-edge identity management solutions. Located in a vibrant area, we provide flexible working arrangements and a supportive atmosphere that values your contributions and well-being.
VE3

Contact Detail:

VE3 Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Active Directory and Entra Specialist(Freelance/Contract) in Maidenhead

✨Tip Number 1

Network, network, network! Get out there and connect with folks in the industry. Attend meetups, webinars, or even online forums related to Active Directory and Entra. You never know who might have a lead on your next gig!

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects, scripts, or any automation you've done with PowerShell or Azure. This gives potential clients a taste of what you can do and sets you apart from the crowd.

✨Tip Number 3

Don’t just apply for jobs; tailor your approach! When reaching out to potential clients, mention specific challenges they might face with their identity management and how you can help solve them. This shows you’ve done your homework and are genuinely interested.

✨Tip Number 4

Apply through our website! We’ve got a streamlined process that makes it easy for you to showcase your expertise. Plus, it’s a great way to get noticed by our team directly. Don’t miss out on the chance to land that freelance role!

We think you need these skills to ace Active Directory and Entra Specialist(Freelance/Contract) in Maidenhead

Active Directory Domain Services
Group Policy Management
ADFS Administration
Entra ID P2 Configuration
Azure AD Connect Management
Conditional Access Configuration
Multi-Factor Authentication (MFA)
Microsoft Intune Administration
PowerShell Scripting
Identity Lifecycle Automation
Incident Management
Root Cause Analysis (RCA)
Networking Fundamentals
ITIL v4 Knowledge
Identity Governance

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Active Directory and Entra Specialist role. Highlight your relevant experience with Active Directory, Azure AD, and any specific projects that showcase your skills in identity management.

Show Off Your Skills: Don’t just list your technical skills; demonstrate them! Use examples from your past work where you’ve successfully managed hybrid identity platforms or resolved complex authentication issues. We love seeing real-world applications of your expertise!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Explain why you’re passionate about this role and how your background makes you the perfect fit. Be sure to mention any certifications you hold that are relevant to the position.

Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status directly. Let’s get your journey started with us!

How to prepare for a job interview at VE3

✨Know Your Tech Inside Out

Make sure you’re well-versed in Active Directory, Entra ID, and all the related technologies mentioned in the job description. Brush up on your knowledge of multi-forest setups, Group Policy Objects, and Azure AD Connect. Being able to discuss these topics confidently will show that you're the right fit for the role.

✨Prepare Real-World Scenarios

Think of specific examples from your past experience where you've successfully managed identity-related issues or implemented solutions. Be ready to explain how you diagnosed problems like replication failures or configured Conditional Access policies. This will demonstrate your practical skills and problem-solving abilities.

✨Stay Updated on Best Practices

Familiarise yourself with the latest best practices in identity management and security. Knowing about recent updates in Microsoft technologies, such as MFA and Intune, can give you an edge. It shows that you’re proactive and committed to continuous improvement, which is crucial for this role.

✨Ask Insightful Questions

Prepare thoughtful questions about the company’s current identity management challenges or future projects. This not only shows your interest in the role but also gives you a chance to assess if the company aligns with your career goals. Plus, it opens up a dialogue that can make you more memorable.

Active Directory and Entra Specialist(Freelance/Contract) in Maidenhead
VE3
Location: Maidenhead

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>