Desktop/Entra Engineer Support
Posted Updated
Position Summary The IT Technical Associate (Desktop/Entra Engineer Support) at UI Health is a key contributor to maintaining and enhancing the organization's hybrid technology infrastructure. This role demands proficiency in Directory Services, IAM, Microsoft Entra, Security, Collaboration Tools, and Endpoint Management. The ideal candidate should be proactive, adaptable, and dedicated to continuous learning and improvement to support UI Health's evolving technological needs effectively. Duties Responsibilities Directory Services Identity and Access Management (IAM): o Administer Active Directory Domain Services (AD DS), including replication and Group Policy. o Manage Microsoft Entra ID for cloud identity, authentication, security, and Single Sign-On (SSO). o Configure and troubleshoot Conditional Access policies. o Manage MFA, authentication methods, identity protection, and access controls. o Support hybrid identity environments and synchronization between on-premises AD and Entra ID. Security Compliance: o Onboard and manage devices with Microsoft Defender for Endpoint. o Investigate security alerts, threat detections, and endpoint incidents. o Perform containment and remediation of compromised or vulnerable devices. o Configure Microsoft Purview Information Protection and Data Loss Prevention (DLP). o Develop security and compliance policies based on organizational requirements. o Coordinate identity, endpoint, and data-protection controls to reduce security risks. Microsoft 365, Collaboration Content Management: o Administer Microsoft 365, including: Exchange Online, Microsoft Teams, SharePoint Online, Microsoft Edge, OneDrive o Manage Teams collaboration and external-user access. o Configure application deployment and Microsoft 365 service settings. o Manage SharePoint permissions, sharing, and content-access policies. User Data OneDrive: o Monitor OneDrive configuration, synchronization, storage, and usage. o Troubleshoot OneDrive access and synchronization issues. o Implement security controls around user data and file sharing. o Establish appropriate backup and recovery strategies for Microsoft 365 data. o Ensure data-access policies align with organizational security and compliance requirements. Desktop Endpoint Management: o Administer Microsoft Intune across: Windows, macOS, iOS/iPadOS, Android o Create and manage configuration profiles. o Deploy and manage applications. o Configure device-compliance policies. o Implement Windows Autopilot for provisioning and deployment. o Configure mobile application management and App Protection Policies. o Integrate Intune compliance with Entra Conditional Access. o Troubleshoot enrollment, policy, application, and device-compliance issues. Technology Advancement Industry Awareness: o Stay current with Microsoft security, identity, endpoint, and cloud-management technologies. o Monitor Microsoft announcements, security advisories, technical communities, and relevant social-media channels. o Evaluate new Microsoft 365, Entra, Intune, Defender, and Purview capabilities. o Identify opportunities to improve security, automation, user experience, and operational efficiency. o Recommend technology changes based on emerging threats and industry best practices. Perform other related duties and participate in special projects as assigned.