Job Description
Active Directory L3
1. Knowledge on AD Architecture & Design
• Define and maintain Active Directory forest/domains.
• Plan and implement domain/forest upgrades and schema extensions.
• Design OU structure, naming conventions, and delegation models for scalability and compliance.
________________________________________
2. Advanced Security & Hardening
• Implement Privileged Access Management (PAM) and Tiered Administration Model.
• Configure Kerberos policies, fine-grained password policies, and authentication mechanisms.
• Perform security audits, detect anomalies, and remediate vulnerabilities.
• Integrate AD with SIEM tools for real-time monitoring.
________________________________________
3. Trusts & Federation
• Configure and maintain domain and forest trusts (internal and external).
• Implement and troubleshoot Active Directory Federation Services (ADFS).
• Manage Single Sign-On (SSO) and OAuth/SAML integrations.
________________________________________
4. Advanced GPO & Policy Strategy
• Implement enterprise-level GPOs for security baselines and compliance.
• Perform impact analysis before deploying new policies.
• Develop policy versioning and rollback strategies.
________________________________________
5. Disaster Recovery & High Availability
• Design and validate AD disaster recovery plans.
• Implement multi-site replication strategies and global catalogue placement.
• Perform authoritative restores and forest recovery in critical scenarios.
________________________________________
6. DNS & DHCP Enterprise Management
• Implement and maintain DNS infrastructure for AD.
• Implement split-brain DNS, conditional forwarders, and secure dynamic updates.
• Troubleshoot complex name resolution issues impacting authentication or replication.
________________________________________
7. Advanced Troubleshooting
• Resolve forest-wide replication failures, FSMO role issues, and schema corruption.
• Handle Kerberos ticketing issues, NTLM fallback, and authentication bottlenecks.
• Diagnose and fix complex hybrid identity sync issues (Azure AD Connect, ADFS).
________________________________________
8. Automation & Optimization
• Develop PowerShell modules for enterprise automation (bulk provisioning, compliance checks).
• Implement scheduled health checks and self-healing scripts.
• Optimize AD performance and reduce replication latency.
________________________________________
9. Hybrid & Cloud Integration
• Manage Azure AD hybrid identity solutions.
• Implement Conditional Access, MFA, and Identity Protection policies.
• Support Entra ID, SSO, and cloud app integrations.
________________________________________
10. Governance, Compliance & Audit
• Define AD governance framework and enforce least privilege principles.
͏
͏
͏
͏
Experience: 5-8 Years .
Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention.