Infrastructure Engineer, M365 & Identity
Job in
Rochester, Olmsted County, Minnesota, 55905, USA
Listed on 2026-08-26
Listing for:
PwrQ Holdings LLC
Full Time
position Listed on 2026-08-26
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection
Job Description & How to Apply Below
Position Summary
We are seeking a Infra Engineer III, M365 & Identity to own Forgent's Microsoft identity and productivity platform across all sites. This role is the single point of accountability for Entra , Conditional Access, Privileged Identity Management, and the full suite of Microsoft 365 security and compliance capabilities unlocked by our E5 licensing.
Key Responsibilities Identity & Access Governance- Own and operate Entra (Azure Active Directory) across all Forgent entities — users, groups, roles, and licensing
- Design and enforce Conditional Access policies aligned to Zero Trust principles — risk-based access, phishing-resistant authentication, and named location controls
- Implement and manage Privileged Identity Management — just-in-time role activation, access reviews, and least-privilege enforcement for all admin roles
- Manage Self-Service Password Reset with password writeback in the hybrid Active Directory and Entra t
- Own Entra Connect and hybrid identity sync health — ensure clean, reliable synchronization between on-premises Active Directory and Entra
- Lead Entra — access reviews, entitlement management, and lifecycle workflows across all entities
- Deploy and manage Defender for Identity — sensor deployment on all domain controllers, alert triage, and integration with Defender XDR for unified identity threat detection
- Configure and maintain Microsoft Purview Data Loss Prevention policies — protect sensitive data across Exchange Online, SharePoint, Teams, and endpoints
- Manage Intune compliance and configuration policies — enforce device compliance requirements for Conditional Access integration
- Serve as the identity subject matter expert for security incidents involving compromised accounts, privilege escalation, or unauthorized access
- Own and operate enterprise Single Sign-On across all corporate applications using Entra the identity provider
- Configure and manage SSO integrations — SAML 2.0, OAuth 2.0, and OpenID Connect — for all business-critical applications across all entities
- Onboard new applications to the Entra n gallery and enterprise app catalog, ensuring consistent authentication and access policies
- Implement and manage application-level Conditional Access policies — enforce multi-factor authentication, device compliance, and risk-based controls per application
- Manage application provisioning and de-provisioning using SCIM where supported, ensuring users are automatically granted and revoked access based on role
- Maintain an authoritative inventory of all SSO-integrated applications, their owners, and their access policies
- Serve as the escalation point for authentication failures, SSO configuration issues, and application access problems across the organization
- Own M365 licensing administration — seat allocation, license assignment automation, and renewal planning across all entities
- Manage the M365 Admin Center, including service health monitoring, tenant configuration, and policy enforcement
- Support the broader Microsoft 365 E5 feature rollout — coordinate with the Messaging & Collaboration Engineer on Teams, Exchange Online, and One Drive configurations that depend on identity policies
- Maintain and document tenant configuration standards, Conditional Access runbooks, and identity governance procedures
- 710 years of experience in Microsoft identity and enterprise Microsoft 365 engineering
- Deep hands-on expertise with Entra — user and group management, Conditional Access, hybrid identity, and B2B collaboration
- Proven experience implementing and operating Privileged Identity Management in a production enterprise environment
- Strong understanding of hybrid identity — Entra Connect, password hash sync, pass-through authentication, and Active Directory Federation Services
- Experience with Microsoft Purview, including Data Loss Prevention policy design and compliance reporting
- Hands-on experience with Defender for Identity sensor deployment and alert management
- Solid understanding of Intune device compliance and its integration with Conditional Access
- Strong documentation skills —…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×