About this role
This is a remote position.
Microsoft 365 & Identity / Access Management Engineer
Role Overview
We are transitioning our Microsoft 365 environment from a Commercial subscription to a Business tenant and rebuilding identity and access management on top of it.
We need an engineer who has done this before, start to finish, in a live business where downtime is not an option, and who can own the technical execution rather than wait to be handed a plan.
This is hands-on work. You will plan the migration, run it, and stay to make sure the environment is stable, documented, and secure afterward.
What You'll Do
Tenant Migration
-
Assess the current Microsoft 365 estate: subscriptions, licensing, domains, and tenant configuration.
-
Build the migration plan — scope, sequencing, pilot groups, cutover windows, rollback criteria, and communications.
-
Execute mailbox migration in Exchange Online, including shared mailboxes, distribution groups, and coexistence during transition.
-
Migrate SharePoint Online, OneDrive for Business, and Teams content with permissions and sharing links preserved.
-
Manage domain transfer and DNS cutover (MX, SPF, DKIM, Autodiscover) with minimal mail disruption.
-
Validate data integrity post-migration and drive issue resolution to closure.
Active Directory Management
-
Administer on-premises Active Directory: domain controllers, organizational units, Group Policy, DNS, and replication health.
-
Manage directory synchronization between on-premises AD and Microsoft 365, including UPN alignment and sync error troubleshooting.
-
Clean up and rationalize the directory — stale accounts, duplicate objects, inconsistent naming, and orphaned groups.
Rights and Permissions Management
-
Design and implement a role-based access model across Microsoft 365 workloads.
-
Manage security groups, distribution lists, Microsoft 365 groups, and Teams membership at scale.
-
Administer SharePoint Online and OneDrive permissions, external sharing controls, and site governance.
-
Apply least-privilege principles to administrative roles.
-
Support access reviews and joiner/mover/leaver processes.
Documentation and Handover
-
Automate repetitive administration and reporting with PowerShell.
-
Produce runbooks, architecture diagrams, and as-built documentation.
-
Provide escalation support to the internal helpdesk and hand over cleanly to BAU operations.
What You Need
-
5+ years administering Microsoft 365 in a production business environment, with at least one full tenant or subscription migration you personally executed.
-
Strong hands-on Exchange Online experience — mail flow, migration batches, and troubleshooting.
-
Solid on-premises Active Directory administration: GPO, OU design, DNS, and replication.
-
Working depth in directory synchronization between on-premises AD and Microsoft 365.
-
Demonstrated experience designing and enforcing permission models across SharePoint Online, OneDrive, and Teams.
-
PowerShell scripting for bulk administration and reporting — not just running scripts others wrote.
-
Practical understanding of DNS and email authentication (SPF, DKIM).
-
Ability to plan and communicate a cutover to non-technical stakeholders.
-
Clear written documentation habits.
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?