Role: Microsoft 365 Identity Support Engineer
Location: Bellevue, WA (Onsite)
Hire Type: Fulltime
Job Description
Role Overview
The Microsoft 365 Identity Support Engineer provides advanced technical support for identity, authentication, licensing, synchronization, and access issues affecting Microsoft 365 first-party applications and services. The role owns customer incidents from initial scoping through resolution, coordinates with Microsoft Entra ID and workload teams when issues cross support boundaries, and delivers a secure, reliable, and customer-focused support experience.
Key Responsibilities
- Administer and troubleshoot user and group licensing, including license-plan and service-plan assignment, removal, updates, billing-blade scenarios, and group-based licensing.
- Investigate Microsoft 365 sign-in and access failures involving Conditional Access, multifactor authentication, self-service password reset, password expiration policies, and first-party application authentication.
- Analyze Microsoft Entra ID sign-in and audit reports to scope incidents, identify authentication patterns, and determine when deeper platform investigation is required.
- Support Microsoft Entra Connect synchronization scenarios, including password hash synchronization, password writeback, group writeback, Exchange extension attributes, directory synchronization, and user, group, or contact synchronization.
- Troubleshoot federated authentication and single sign-on for Microsoft 365, including AD FS token-signing and token-decrypting certificates and certificate-based authentication.
- Diagnose WAM, Token Broker, OneAuth, Pass-through Authentication, Authenticator Lite, and modern authentication issues affecting Microsoft 365 applications.
- Support B2B guest authentication and file-sharing access for Microsoft 365 first-party applications, while distinguishing authentication issues from workload-specific authorization failures.
- Support Microsoft 365 Admin Center identity features, including Copilot prompt availability, Copilot usage reporting, and AI Assistance Adoption Score functionality.
- Collect logs, error codes, timestamps, sign-in details, synchronization evidence, and reproduction steps; document technical findings, troubleshooting actions, root cause, and resolution.
- Own incidents end to end, provide timely customer updates, meet service-level commitments, and escalate confirmed product defects with complete diagnostic evidence.
Cross-Team Collaboration and Support Boundaries
- Collaborate with Microsoft Entra ID Authentication, Authorization, Identity Management, Provisioning, B2B, Account Management, and Developer teams when an issue is outside Microsoft 365 Identity ownership.
- Engage application and workload teams such as Exchange Online, SharePoint Online, Outlook, Intune, Microsoft Defender for Cloud Apps, and other service owners for client defects, authorization failures, app protection policies, service provisioning, or workload-specific functionality.
- Distinguish first-party Microsoft 365 authentication issues from third-party application, device registration, Primary Refresh Token, Windows Hello, FIDO2, OATH token, Temporary Access Pass, custom synchronization rule, and Entra Connect installation or upgrade scenarios.
Required Qualifications
- Three or more years of technical support, systems administration, or cloud identity experience in Microsoft 365 or Microsoft Entra ID environments.
- Strong knowledge of Microsoft 365 Admin Center, Microsoft Entra ID, identity lifecycle management, authentication, authorization, licensing, and hybrid identity.
- Hands-on experience troubleshooting Conditional Access, MFA, SSPR, federation, AD FS, Entra Connect Sync, password hash synchronization, password writeback, and Pass-through Authentication.
- Ability to interpret sign-in logs, audit logs, service health information, synchronization results, and common authentication error codes.
- Working knowledge of PowerShell and Microsoft Graph for identity and licensing administration; ability to determine when a cmdlet or API issue requires developer-team engagement.
- Strong incident ownership, problem-solving, documentation, collaboration, and customer communication skills.
Preferred Qualifications
- Experience in enterprise-level L2 or L3 support and in coordinating complex escalations across identity, security, client, and workload teams.
- Understanding of OAuth 2.0, OpenID Connect, SAML, modern authentication, token flows, device registration, and Primary Refresh Tokens.
- Experience with Microsoft 365 Copilot administration or reporting, B2B guest access, WAM, OneAuth, Authenticator Lite, and Microsoft 365 data-residency concepts.
- Relevant Microsoft certifications, such as Microsoft 365 Administrator, Identity and Access Administrator, or Azure Administrator.
Success Measures
- Accurate scoping and routing of incidents based on product ownership and support boundaries.
- Timely restoration of customer access and identity services, with clear communication and complete case documentation.
- High-quality escalations that include evidence, reproduction details, impact, and troubleshooting already completed.
- Contribution to team readiness through knowledge sharing, technical coaching, support documentation, and reusable troubleshooting guidance.
Working Style
The successful candidate is analytical, customer-focused, collaborative, and comfortable owning ambiguous technical issues. They communicate complex identity concepts clearly, apply structured troubleshooting methods, and balance rapid mitigation with durable root-cause resolution.