Staff Engineer, Microsoft Active Directory

    India
    Full-Time
    Senior (7+ yrs)
    Engineering & Development
    Posted on August 5, 2026

    REQUIREMENTS:

    • Total experience: 5.5+ years.
    • Strong experience in Microsoft Active Directory administration across enterprise, multi-site environments.
    • Must-have expertise in Microsoft Entra ID (Azure AD) administration and Hybrid Identity (Entra Connect/AD Connect).
    • Strong experience in managing Domain Controllers, AD Replication, FSMO Roles, Schema, Trusts, NTDS, DFSR, and AD Sites & Services.
    • Hands-on experience with Windows Server (2012–2022+), DNS, DHCP, IIS, and Group Policy (GPO) administration.
    • Experience designing and implementing Conditional Access, SSO, MFA, RBAC, PIM, and Identity Lifecycle Management.
    • Strong understanding of Microsoft 365 identity services, Exchange Online, and Hybrid Exchange administration.
    • Experience managing mail flow, connectors, SPF, DKIM, DMARC, licensing, and directory synchronization.
    • Hands-on experience troubleshooting OAuth, SAML, Kerberos, and NTLM authentication issues.
    • Strong scripting experience using PowerShell and automation with Microsoft Graph API.
    • Experience with Active Directory migrations, upgrades, consolidations, backup, disaster recovery, and high availability.
    • Good knowledge of identity security, IAM best practices, compliance, and enterprise authentication.
    • Experience using Active Directory administration and migration tools such as Quest is preferred.
    • Strong analytical, troubleshooting, communication, and stakeholder management skills.

    RESPONSIBILITIES:

    • Design, administer, and optimize enterprise Microsoft Active Directory and Microsoft Entra ID environments.
    • Manage Domain Controllers, AD replication, FSMO roles, trusts, schema, NTDS, DFSR, and AD Sites & Services.
    • Implement, maintain, and secure Group Policy (GPO) frameworks across enterprise environments.
    • Administer Windows Server, DNS, DHCP, IIS, and core identity infrastructure services.
    • Design and enforce Conditional Access, MFA, SSO, RBAC, PIM, and identity governance policies.
    • Manage Hybrid Identity using Microsoft Entra Connect (Azure AD Connect) and ensure seamless directory synchronization.
    • Administer Microsoft 365 identity services, Exchange Online, and Hybrid Exchange environments.
    • Manage mail flow, connectors, authentication protocols, and compliance-related identity configurations.
    • Develop and maintain PowerShell automation scripts and leverage Microsoft Graph API for administration and reporting.
    • Lead Active Directory upgrades, migrations, consolidations, backup, recovery, and disaster recovery initiatives.
    • Troubleshoot and resolve complex authentication issues involving OAuth, SAML, Kerberos, and NTLM.
    • Perform root cause analysis for critical production incidents and implement preventive solutions.
    • Collaborate with cloud, infrastructure, and security teams to strengthen enterprise identity services.
    • Monitor identity security posture, ensure compliance, and continuously improve identity management processes and automation.

    Company:  Nagarro

    Provides digital product engineering, AI, cloud, and technology consulting services, helping clients become innovative, digital-first enterprises.
    10001+ employees
    Software & IT Services
    HQ: Germany