Overview
Skills
Job Details
Role: Azure Active Directory Migration Engineer
Duration: 6-12 months
Location: Atlanta, GA / Windsor, CT
Need candidates who can work onsite from Day 1 (Hybrid basis)
Overview
The Directory Services / Identity Engineer will lead the technical efforts to migrate client domain users, applications, and infrastructure into the client enterprise domain (DSGLOBAL). This role focuses on designing, implementing, and troubleshooting Active Directory (AD), Microsoft Entra ID (formerly Azure AD), and identity integrations to ensure a secure and seamless transition.
Key Responsibilities
- Active Directory Migration
- Plan and execute domain migration activities (user accounts, service accounts, groups, and servers) from IM domain to DSGLOBAL.
- Implement and manage domain trusts, OU structure alignment, and group policy migrations.
- Support dual-domain coexistence during transition (authentication and resource access).
- Identity & Access Management
- Integrate AD and Microsoft Entra ID for hybrid identity synchronization.
- Configure and troubleshoot SSO, federation, and authentication protocols (Kerberos, NTLM, SAML, OAuth2, OpenID Connect, ADFS).
- Work with IAM teams to align group memberships and access policies with enterprise standards.
- Application Integration
- Assess and document application dependencies on AD (LDAP bindings, service accounts, Windows authentication).
- Support application teams in reconfiguring authentication and authorization settings for DSGLOBAL integration.
- Assist in testing and validating dual-domain or migrated application connectivity.
- Automation & Reporting
- Develop and maintain PowerShell scripts for user/group migration, reporting, and cleanup.
- Automate service account provisioning and group membership validation.
- Security & Compliance
- Ensure compliance with security standards and access control policies.
- Support audits and reviews of AD and Entra configurations.
- Documentation & Knowledge Transfer
- Maintain comprehensive documentation of AD architecture, configurations, and migration runbooks.
- Provide technical guidance and mentoring to other engineers and application teams.
Required Skills & Experience
- Technical Expertise
- 5+ years of hands-on experience with Active Directory, DNS, DHCP, Group Policy, and domain trusts.
- Experience with Microsoft Entra ID / Azure AD, AAD Connect, and hybrid identity synchronization.
- Proficient in PowerShell scripting for AD automation and reporting.
- Familiar with IAM tools (SailPoint, Okta, or similar) and SSO/federation configurations.
- Migration Experience
- Proven record of accomplishment with AD domain migrations, user and group consolidations, and cross-domain authentication.
- Experience using tools such as ADMT, Quest Migration Manager, or similar.
- Troubleshooting & Support
- Strong diagnostic skills across authentication, DNS, and network layers.
- Ability to resolve complex directory synchronization and authentication issues.
- Soft Skills
- Excellent communication and documentation skills.
- Strong collaboration with infrastructure, application, and IAM teams.
- Detail-oriented, analytical thinker with solid problem-solving abilities.
Preferred Qualifications
- Microsoft Certified: Identity and Access Administrator Associate or Windows Server Hybrid Administrator Associate
- Experience with Windows Server 2016 2022 environments
- Knowledge of Azure AD Conditional Access, Privileged Identity Management (PIM), and Entra Connect Cloud Sync
- Background in financial services or regulated environments
Tekshapers is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information, or any characteristic protected by law.