M365 Admin – IDAM
Listed on 2026-07-09
-
IT/Tech
Cybersecurity, M365, SharePoint & Power Platform, Cloud Computing: Infrastructure & Operations, Systems Administrator
Arbuthnot Latham has been associated with banking since 1833. We combine private and commercial banking, wealth planning and investment management. We believe in traditional relationship and service-led banking powered by modern technology.
Job PurposeThis role is for a Microsoft 365 Specialist with a specialist focus on Identity and Access Management. The role will provide end-to-end administration and maintenance of Microsoft 365 applications, including technical issues and requests for Microsoft 365 related applications with a specific focus on Identity and Access Management across the enterprise estate. The role will also take ownership of the identity lifecycle processes, access governance, and will support compliance and audit requirements across the Microsoft 365 and EntraID estate.
Key Responsibilities- Review, enhance and manage the Role Based Access Management (RBAC) configuration as well as onboarding and deploying enhanced RBAC across the estate.
- Conditional Access policy design & management.
- Privileged Identity Management (PIM) administration and support of our Supporting Zero Trust strategy.
- Provide professional and proactive administration for Microsoft 365 applications.
- Develop and implement changes within the M365 platform.
- Champion Microsoft 365 based solutions embracing new functionality and increasing user adoption.
- Liaise with internal customers to ensure that business requirements of the application are fulfilled.
- Collaborate with other teams to develop system integrations, data migration and automated testing.
- Address machine identity and secrets hygiene as an ongoing implementation activity.
- Establish operational runbooks, monitoring and audit/logging for compliance, risk and incident response.
- Perform secrets and privileged-account discovery, normalization and vaulting. Use discovery to inventory privileged accounts/secrets, define folder/template hierarchy and import/clean accounts before onboarding into the vault.
- Implement automated rotation and lifecycle controls for secrets and machine credentials. Automate credential rotation, integrate with CI/CD and workload platforms, and plan for synchronized rotation where workloads consume credentials in multiple locations.
- Configure access policies, conditional controls and enforce least privilege in the platform. Define role/group templates, conditional/step-up policies and RBAC/approver workflows, minimizing custom code and templating configurations for scalability.
- IT Team in particular the IT Infrastructure and Operations team and service desk.
- Operational Resiliency Team
- All business areas across the Group
- 3rd party suppliers
- Microsoft Account Management Team
- Microsoft 365 certification, with demonstratable experience delivering Microsoft 365 solutions in a fast-paced environment.
- Significant experience of Microsoft 365 Administration, including IDAM, the Microsoft Admin Centre’s, SharePoint and other core apps.
- Understand M365 Teams integration capabilities with M365, SharePoint Online and Third-Party Apps.
- Experience maintaining a thorough understanding of existing and emerging Microsoft 365 core technologies.
- Experience of producing high-quality documentation and user guides for the wider business.
- Experience in undertaking business impact assessments for major M365 updates, as well as analysing complex technical issues and proposing appropriate solutions.
- Experience of working with third party providers e.g. Microsoft technical support, Consultancies etc.
- Experience administering EntraID Conditional Access, PIM, Custom Security Attributes, Access Packages (EPM)
- Experience with identity governance frameworks (e.g., JML workflows, access reviews).
- Experience with Microsoft Graph API.
- Experience of working with Key Cloak identity platform.
- IDAM configuration based on the Microsoft EntraID platform, Microsoft Active Directory as well as other 3rd party providers.
- Experience of working with and gaining ISO
27001 adoption. - Working knowledge and hands‑on platform configuration (PAM/AM/IGA), scripting for integrations, CI/CD/Dev Ops familiarity, secrets/certificate lifecycle knowledge, testing…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: