Active Directory Federation Services (ADFS) Customer EngineerJOB SUMMARY-The ADFS Customer Engineer serves as a trusted advisor to enterprise customers, providing technical guidance, migration support, and operational expertise across Active Directory Federation Services (ADFS), Active Directory, and Microsoft Entra ID. The role focuses on identity modernization, federation services, hybrid identity solutions, and security best practices.
Responsibilities
- Design, deploy, configure, and support ADFS environments.
- Lead ADFS upgrades, migrations, and modernization initiatives, including migrations to Microsoft Entra ID.
- Configure and manage claims-based authentication, Access Control Policies, Relying Party Trusts, MFA integrations, and federation services.
- Troubleshoot authentication, federation, certificate, and identity synchronization issues.
- Support Active Directory architecture, authentication, trust relationships, and Entra Connect synchronization.
- Assess and improve identity security posture through remediation of security findings and implementation of best practices.
- Collaborate with customer infrastructure, security, and architecture teams to deliver secure and compliant identity solutions.
- Deliver technical guidance, knowledge transfer, and operational readiness support.
QualificationsAdvanced (Required)
- Active Directory Federation Services (ADFS)
- ADFS migrations, upgrades, and modernization
- Claims-based authentication and federation
- Access Control Policies and Relying Party Trusts
- Microsoft Entra Connect and Hybrid Identity
- MFA integration and authentication troubleshooting
- Certificate management and federation security
- 5+ years of experience supporting Active Directory and ADFS environments.
- Experience delivering enterprise identity, federation, or hybrid identity projects.
- Strong troubleshooting and problem-solving skills.
- Experience working directly with customers in a consulting, advisory, or support capacity.
Intermediate (Required)
- Active Directory Domain Services (AD DS)
- Multi-domain and multi-forest environments
- Authentication and trust design
- Microsoft Entra ID (Free, P1, P2)
- Identity synchronization and lifecycle management
- Active Directory security assessments and remediation
Preferred
- Microsoft Defender for Identity
- Active Directory Certificate Services (AD CS)
- Entra Password Protection
- Audit policy, event forwarding, and security monitoring
- PowerShell automation
Preferred Certifications
- SC-300: Microsoft Identity and Access Administrator
- AZ-104: Microsoft Azure Administrator
- Microsoft Certified Trainer (MCT)
- MCSE (or equivalent experience)
- CISSP or comparable security certification
#WFH#LI-Remote#ConcentrixCatalyst