Senior Infrastructure Engineer, M365 & Identity
Listed on 2026-09-05
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection, Systems Administrator
Infra Engineer III, M365 & Identity
We are seeking an Infra Engineer III, M365 & Identity to own Forgent's Microsoft identity and productivity platform across all sites. This role is the single point of accountability for Entra , Conditional Access, Privileged Identity Management, and the full suite of Microsoft 365 security and compliance capabilities unlocked by our E5 licensing.
You will be joining at a pivotal moment — Forgent is migrating from a fragmented multi-entity Microsoft 365 environment to a single governed platform with a July 1 go-live deadline. This role will be critical to ensuring that deadline is met, and that identity and access are properly governed across the entire organization from day one.
Key Responsibilities:
- Own and operate Entra (Azure Active Directory) across all Forgent entities — users, groups, roles, and licensing
- Design and enforce Conditional Access policies aligned to Zero Trust principles — risk-based access, phishing-resistant authentication, and named location controls
- Implement and manage Privileged Identity Management — just-in-time role activation, access reviews, and least-privilege enforcement for all admin roles
- Manage Self-Service Password Reset with password writeback in the hybrid Active Directory and Entra t
- Own Entra Connect and hybrid identity sync health — ensure clean, reliable synchronization between on-premises Active Directory and Entra
- Lead Entra — access reviews, entitlement management, and lifecycle workflows across all entities
- Deploy and manage Defender for Identity — sensor deployment on all domain controllers, alert triage, and integration with Defender XDR for unified identity threat detection
- Configure and maintain Microsoft Purview Data Loss Prevention policies — protect sensitive data across Exchange Online, SharePoint, Teams, and endpoints
- Manage Intune compliance and configuration policies — enforce device compliance requirements for Conditional Access integration
- Serve as the identity subject matter expert for security incidents involving compromised accounts, privilege escalation, or unauthorized access
- Own and operate enterprise Single Sign-On across all corporate applications using Entra the identity provider
- Configure and manage SSO integrations — SAML 2.0, OAuth 2.0, and OpenID Connect — for all business-critical applications across all entities
- Onboard new applications to the Entra n gallery and enterprise app catalog, ensuring consistent authentication and access policies
- Implement and manage application-level Conditional Access policies — enforce multi-factor authentication, device compliance, and risk-based controls per application
- Manage application provisioning and de-provisioning using SCIM where supported, ensuring users are automatically granted and revoked access based on role
- Maintain an authoritative inventory of all SSO-integrated applications, their owners, and their access policies
- Serve as the escalation point for authentication failures, SSO configuration issues, and application access problems across the organization
- Own M365 licensing administration — seat allocation, license assignment automation, and renewal planning across all entities
- Manage the M365 Admin Center, including service health monitoring, tenant configuration, and policy enforcement
- Support the broader Microsoft 365 E5 feature rollout — coordinate with the Messaging & Collaboration Engineer on Teams, Exchange Online, and One Drive configurations that depend on identity policies
- Maintain and document tenant configuration standards, Conditional Access runbooks, and identity governance procedures
Qualifications:
Required
- 7–10 years of experience in Microsoft identity and enterprise Microsoft 365 engineering
- Deep hands-on expertise with Entra — user and group management, Conditional Access, hybrid identity, and B2B collaboration
- Proven experience implementing and operating Privileged Identity Management in a production enterprise environment
- Strong understanding of hybrid identity — Entra Connect, password hash sync, pass-through authentication, and Active Directory Federation Services
- Experience with Microsoft Purview, including Data Loss Prevention policy…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).