Infrastructure Engineer, M365 & Identity

ForgentWaco, TX
Onsite

About The Position

We are seeking a Infra Engineer III, M365 & Identity to own Forgent's Microsoft identity and productivity platform across all sites. This role is the single point of accountability for Entra ID, Conditional Access, Privileged Identity Management, and the full suite of Microsoft 365 security and compliance capabilities unlocked by our E5 licensing. You will be joining at a pivotal moment — Forgent is migrating from a fragmented multi-entity Microsoft 365 environment to a single governed platform with a July 1 go-live deadline. This role will be critical to ensuring that deadline is met, and that identity and access are properly governed across the entire organization from day one.

Requirements

  • 7–10 years of experience in Microsoft identity and enterprise Microsoft 365 engineering
  • Deep hands-on expertise with Entra ID — user and group management, Conditional Access, hybrid identity, and B2B collaboration
  • Proven experience implementing and operating Privileged Identity Management in a production enterprise environment
  • Strong understanding of hybrid identity — Entra Connect, password hash sync, pass-through authentication, and Active Directory Federation Services
  • Experience with Microsoft Purview, including Data Loss Prevention policy design and compliance reporting
  • Hands-on experience with Defender for Identity sensor deployment and alert management
  • Solid understanding of Intune device compliance and its integration with Conditional Access
  • Strong documentation skills — ability to produce runbooks, policy guides, and change management documentation
  • Hands-on experience configuring enterprise Single Sign-On integrations using SAML 2.0, OAuth 2.0, and OpenID Connect
  • Experience managing application provisioning and de-provisioning via SCIM

Nice To Haves

  • Experience with Entra ID Governance — access reviews, entitlement management, and lifecycle workflows
  • Familiarity with Microsoft Sentinel for identity-related log ingestion and alerting
  • Experience supporting a Microsoft 365 E5 deployment or licensing transition
  • Knowledge of multi-entity or post-acquisition Microsoft 365 consolidation
  • Microsoft certifications — SC-300 (Identity and Access Administrator), MS-102 (Microsoft 365 Administrator)

Responsibilities

  • Own and operate Entra ID (Azure Active Directory) across all Forgent entities — users, groups, roles, and licensing
  • Design and enforce Conditional Access policies aligned to Zero Trust principles — risk-based access, phishing-resistant authentication, and named location controls
  • Implement and manage Privileged Identity Management — just-in-time role activation, access reviews, and least-privilege enforcement for all admin roles
  • Manage Self-Service Password Reset with password writeback in the hybrid Active Directory and Entra ID environment
  • Own Entra Connect and hybrid identity sync health — ensure clean, reliable synchronization between on-premises Active Directory and Entra ID
  • Lead Entra ID Governance — access reviews, entitlement management, and lifecycle workflows across all entities
  • Deploy and manage Defender for Identity — sensor deployment on all domain controllers, alert triage, and integration with Defender XDR for unified identity threat detection
  • Configure and maintain Microsoft Purview Data Loss Prevention policies — protect sensitive data across Exchange Online, SharePoint, Teams, and endpoints
  • Manage Intune compliance and configuration policies — enforce device compliance requirements for Conditional Access integration
  • Serve as the identity subject matter expert for security incidents involving compromised accounts, privilege escalation, or unauthorized access
  • Own and operate enterprise Single Sign-On across all corporate applications using Entra ID as the identity provider
  • Configure and manage SSO integrations — SAML 2.0, OAuth 2.0, and OpenID Connect — for all business-critical applications across all entities
  • Onboard new applications to the Entra ID application gallery and enterprise app catalog, ensuring consistent authentication and access policies
  • Implement and manage application-level Conditional Access policies — enforce multi-factor authentication, device compliance, and risk-based controls per application
  • Manage application provisioning and de-provisioning using SCIM where supported, ensuring users are automatically granted and revoked access based on role
  • Maintain an authoritative inventory of all SSO-integrated applications, their owners, and their access policies
  • Serve as the escalation point for authentication failures, SSO configuration issues, and application access problems across the organization
  • Own M365 licensing administration — seat allocation, license assignment automation, and renewal planning across all entities
  • Manage the M365 Admin Center, including service health monitoring, tenant configuration, and policy enforcement
  • Support the broader Microsoft 365 E5 feature rollout — coordinate with the Messaging & Collaboration Engineer on Teams, Exchange Online, and OneDrive configurations that depend on identity policies
  • Maintain and document tenant configuration standards, Conditional Access runbooks, and identity governance procedures

Benefits

  • Competitive compensation
  • benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service