MS 365 Migration Expert

Workplace
Remote solely

About this role

This is a remote position.

Microsoft 365 & Identity / Access Management Engineer

Role Overview

We are transitioning our Microsoft 365 environment from a Commercial subscription to a Business tenant and rebuilding identity and access management on top of it.

We need an engineer who has done this before, start to finish, in a live business where downtime is not an option, and who can own the technical execution rather than wait to be handed a plan.

This is hands-on work. You will plan the migration, run it, and stay to make sure the environment is stable, documented, and secure afterward.

What You'll Do

Tenant Migration

  • Assess the current Microsoft 365 estate: subscriptions, licensing, domains, and tenant configuration.

  • Build the migration plan — scope, sequencing, pilot groups, cutover windows, rollback criteria, and communications.

  • Execute mailbox migration in Exchange Online, including shared mailboxes, distribution groups, and coexistence during transition.

  • Migrate SharePoint Online, OneDrive for Business, and Teams content with permissions and sharing links preserved.

  • Manage domain transfer and DNS cutover (MX, SPF, DKIM, Autodiscover) with minimal mail disruption.

  • Validate data integrity post-migration and drive issue resolution to closure.

Active Directory Management

  • Administer on-premises Active Directory: domain controllers, organizational units, Group Policy, DNS, and replication health.

  • Manage directory synchronization between on-premises AD and Microsoft 365, including UPN alignment and sync error troubleshooting.

  • Clean up and rationalize the directory — stale accounts, duplicate objects, inconsistent naming, and orphaned groups.

Rights and Permissions Management

  • Design and implement a role-based access model across Microsoft 365 workloads.

  • Manage security groups, distribution lists, Microsoft 365 groups, and Teams membership at scale.

  • Administer SharePoint Online and OneDrive permissions, external sharing controls, and site governance.

  • Apply least-privilege principles to administrative roles.

  • Support access reviews and joiner/mover/leaver processes.

Documentation and Handover

  • Automate repetitive administration and reporting with PowerShell.

  • Produce runbooks, architecture diagrams, and as-built documentation.

  • Provide escalation support to the internal helpdesk and hand over cleanly to BAU operations.

What You Need

  • 5+ years administering Microsoft 365 in a production business environment, with at least one full tenant or subscription migration you personally executed.

  • Strong hands-on Exchange Online experience — mail flow, migration batches, and troubleshooting.

  • Solid on-premises Active Directory administration: GPO, OU design, DNS, and replication.

  • Working depth in directory synchronization between on-premises AD and Microsoft 365.

  • Demonstrated experience designing and enforcing permission models across SharePoint Online, OneDrive, and Teams.

  • PowerShell scripting for bulk administration and reporting — not just running scripts others wrote.

  • Practical understanding of DNS and email authentication (SPF, DKIM).

  • Ability to plan and communicate a cutover to non-technical stakeholders.

  • Clear written documentation habits.



Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?