My client is currently seeking a skilled Microsoft Engineer to assist in the process of analyzing current state Active Directory Object Structures, Group Policy Objects, Security Groups, and Directory Services in general.
The candidate for this position must be able to communicate and collaborate with technical and business internal customers, project team members, and vendor consultants to analyze, identify, and provide best practice for directory services. Gathers, interprets and documents business needs and translates them into directory service requirements, operational requirements, use cases, and test cases for testing and implementation.
The work involves:
Analysis and documenting GPOs and provide recommendations for improvements
Organization and restructuring of Active Directory groups and relevant group memberships according to Microsoft best practices, company policies, procedures, and standards
Manual and automated validation of existing data
Manual and automated true-up of data to comply with documented standards
Risked based approach for implementation of enhancements and corrective actions
Close coordination with other Active Directory staff to implement changes in structure, groups, and accounts
Interacting closely with project teams and staff to ensure deployment meets the requirements of the project with minimal impact to current Active Directory design and architecture and no unplanned loss of access to users
Administration and analysis of Active Directory without the use of GUIs.
Advanced scripting capabilities for current state analysis as well as modifications or enhancements implemented
8 years of advanced experience in PowerShell
8 years of experience of Active Directory without the use of a GUI
Experience populating and managing Active Directory groups, group types, entitlements and the capabilities and limitations of each
Experience with native AD integration with Unix Systems
Experience with delegate administration enforcing segregation of duties
Knowledge of Microsoft best practices involving group nesting and permissions inheritance
Knowledge of Microsoft permission types, permission precedents and managing NTFS DACLs
Experience with complete administrative tasks including test, create, change, transfer and delete requests for users, service accounts, and groups
Expert proficiency with Microsoft Office, especially Excel
Experience administering a mid-size or greater, multi-site Active Directory domain
Knowledge and understanding of highly structured IT change management processes
Strong written and verbal communication skills
Education & Certifications:
Bachelors degree in Computer Science or related field, or an equivalent combination of education and experience is required.
MCSA or greater