On‑Premise Server & VirtualizationAdminister Windows Server (2016/2019/2022) roles—AD DS, DNS, DHCP, GPO, file/print, and PKI/Certificate Services.
Perform patching, upgrades, and vulnerability remediation.
Maintain configuration baselines, capacity plans, and runbooks.
Active Directory & IdentityDesign and maintain Active Directory: domain/forest topology, OU structure, GPOs, replication, and FSMO roles.
Manage Azure Active Directory: Conditional Access, MFA, SSO (SAML/OAuth/OIDC), application registrations, and identity lifecycle.
Enforce least‑privilege access, PAM/PIM controls, and secure join/enrollment processes.
Microsoft 365 AdministrationManage M365 services including Exchange Online, SharePoint Online, OneDrive for Business, Teams, and Microsoft 365 Groups.
Oversee M365 licensing, user provisioning, compliance configurations, retention policies, and DLP/security settings.
Coordinate tenant health, service adoption, productivity improvements, and feature rollouts.
Support integration between M365, Azure AD, Intune, and security tools (Defender suite).
Endpoint Management with Microsoft IntuneOwn Microsoft Intune/Endpoint Manager: device enrollment (Autopilot/ABM), compliance policies, configuration profiles, app lifecycle, and update rings.
Standardize Windows, iOS/iPadOS, and Android posture (encryption, firewall, Defender, BitLocker/FileVault policies) and integrate with Azure AD.
Build zero‑touch provisioning flows, remediation scripts, and hardware lifecycle (procurement to secure decommission).
DevOps & AutomationUse PowerShell/Azure CLI for administrative automation and remediations at scale.
Build and maintain CI/CD using Azure DevOps or GitHub Actions for infrastructure and server configuration (e.g., DSC/Ansible).
Integrate testing, approvals, and change controls aligned to ITIL/DevOps best practices.
Security, Monitoring & ComplianceApply security baselines, patching cadence, Defender for Endpoint/Server integration, and vulnerability remediation.
Support audits with accurate documentation (as‑built, diagrams, SOPs, CMDB/asset references).
Operational SupportProvide Tier 2/3 escalation for cloud, server, identity, and endpoint issues; own problem management and root‑cause analysis.
Collaborate with networking, security, and application teams to ensure end‑to‑end service reliability and performance.