Details:
Job Description
Conditional Access Architect - Microsoft 365 (Label‑Aware Enforcement)
Design and implement label‑aware Conditional Access (CA) and Microsoft Defender for Cloud Apps (MDCA) session controls that protect OneDrive/SharePoint content
by sensitivity, not just device or location. You will translate Client"s priorities into production pilots that let users view low‑risk data while blocking risky actions (e.g., download) on unmanaged devices when content is labeled Confidential/Restricted.
You will work within a hybrid identity environment (Okta MFA federated with Entra ID), with SCCM co‑management, Intune onboarding in progress, and Azure AD Join not yet in use-engineering practical policies that work
now and pave the way for stronger device posture over time.
- 6-8+ years in identity & access with deep Conditional Access design/operations and MDCA session policies (label‑aware controls, app‑enforced restrictions).
- Experience operating in federated identity environments (Okta ↔ Entra) and staged Intune adoption; can design pragmatic interim controls.
- Hands‑on with Purview labeling/auto‑label and how labels drive CA/MDCA decisions; able to read simulation outputs and adjust enforcement.
- Serve as the go-to expert for Microsoft 365 services - including but not limited to SharePoint Online, OneDrive, Teams, Teams Voice, Viva suits, Power Platforms Dynamic 365, Microsoft Purview, Azure AD and etc.
- Evaluate new applications/technologies, conduct proof of concepts (POCs), and make recommendations for integrating innovative solutions to drive efficiency and productivity.
- Provide expert support for designing and troubleshooting issues for complex problems related to Microsoft SharePoint online and OneDrive, including site collections, document library, lists, Organization policies by following organizations security guidelines. Implementing and Administering the Migration strategies.
- Conduct assessments, identify opportunities for optimization, and provide recommendations for enhancing the performance, security, and scalability of the M365 services infrastructure majorly in SPO, OD, MS Teams and other collaboration services along with Power platforms.
- Define best practices, standards, and policies for SharePoint online, OneDrive, Teams, Teams voice, Viva suits and Power platforms, ensuring compliance with industry regulations and security frameworks.
- Monitor system health, performance, and security of SPO, OD, Teams, Teams voice, Viva Suits, Power Platforms, Microsoft Purview components, Azure AD and other M365 services, proactively identifying and addressing any issues or vulnerabilities.
- Collaborate with other IT teams to plan and execute upgrades, migrations, and integrations related to Microsoft 365 service.
- Provide root-cause analysis for recurring or critical problems. Must be able to prepare technical and process documentations.
- Provide guidance and support to other technical team members on Microsoft 365 services, resolving their technical issues, and delivering effective training and documentation as needed.
- Stay updated with the latest trends, features, and best practices in SPO, OD, Teams, viva Suits, Power Platforms, Azure Ad and other M365 services, and apply that knowledge to enhance the organization's systems and processes.
- Strong documentation & stakeholder skills: produce pilot configs, runbooks, governance checklists.
Job Requirements
Details:
Nice to have
- Financial‑services or regulated‑industry background; evidence aligning controls with governance & compliance objectives.
- Familiarity with Endpoint DLP policy interactions and OneDrive sync exfiltration controls (to coordinate cross‑policy behavior).
- PowerShell / Graph API for bulk policy ops; KQL for sign‑in and activity analytics.