About this role
This is a remote position.
Microsoft 365 & Identity / Access Management Engineer
Role Overview
We are transitioning our Microsoft 365 environment from a Commercial subscription to a Business tenant and rebuilding identity and access management on top of it.
We need an engineer who has done this before, start to finish, in a live business where downtime is not an option, and who can own the technical execution rather than wait to be handed a plan.
This is hands-on work. You will plan the migration, run it, and stay to make sure the environment is stable, documented, and secure afterward.
What You'll Do
Tenant Migration
- Assess the current Microsoft 365 estate: subscriptions, licensing, domains, and tenant configuration.
- Build the migration plan — scope, sequencing, pilot groups, cutover windows, rollback criteria, and communications.
- Execute mailbox migration in Exchange Online, including shared mailboxes, distribution groups, and coexistence during transition.
- Migrate SharePoint Online, OneDrive for Business, and Teams content with permissions and sharing links preserved.
- Manage domain transfer and DNS cutover (MX, SPF, DKIM, Autodiscover) with minimal mail disruption.
- Validate data integrity post-migration and drive issue resolution to closure.
Active Directory Management
- Administer on-premises Active Directory: domain controllers, organizational units, Group Policy, DNS, and replication health.
- Manage directory synchronization between on-premises AD and Microsoft 365, including UPN alignment and sync error troubleshooting.
- Clean up and rationalize the directory — stale accounts, duplicate objects, inconsistent naming, and orphaned groups.
Rights and Permissions Management
- Design and implement a role-based access model across Microsoft 365 workloads.
- Manage security groups, distribution lists, Microsoft 365 groups, and Teams membership at scale.
- Administer SharePoint Online and OneDrive permissions, external sharing controls, and site governance.
- Apply least-privilege principles to administrative roles.
- Support access reviews and joiner/mover/leaver processes.
Documentation and Handover
- Automate repetitive administration and reporting with PowerShell.
- Produce runbooks, architecture diagrams, and as-built documentation.
- Provide escalation support to the internal helpdesk and hand over cleanly to BAU operations.
What You Need
- 5+ years administering Microsoft 365 in a production business environment, with at least one full tenant or subscription migration you personally executed.
- Strong hands-on Exchange Online experience — mail flow, migration batches, and troubleshooting.
- Solid on-premises Active Directory administration: GPO, OU design, DNS, and replication.
- Working depth in directory synchronization between on-premises AD and Microsoft 365.
- Demonstrated experience designing and enforcing permission models across SharePoint Online, OneDrive, and Teams.
- PowerShell scripting for bulk administration and reporting — not just running scripts others wrote.
- Practical understanding of DNS and email authentication (SPF, DKIM).
- Ability to plan and communicate a cutover to non-technical stakeholders.
- Clear written documentation habits.