This is a remote position.
We're looking for a hands-on migration specialist to help modernize a large enterprise identity and
Microsoft 365 estate. You'll consolidate legacy Active Directory forests, move users, groups and
devices to Entra ID and Intune and run tenant-to-tenant migrations for Exchange Online, OneDrive,
SharePoint and Teams.
Key Responsibilities
Identity and directory
• Move users, groups, computers and service accounts from legacy forests into the target forest
and manage coexistence (trusts, SID history and directory sync) while both are live.
• Run Entra Connect and Cloud Sync through the migration, including scoping changes and
staging-mode cutovers.
• Make sure every migrated user lands on their existing cloud identity. That means managing
sourceAnchor and ImmutableID values and using hard-match or soft-match, so nobody ends
up with a duplicate account or loses access to their mailbox, files or licences.
• Check that Conditional Access, MFA, RBAC and PIM still behave as expected once users have
moved.
• Tidy up afterwards: clear SID history, take down migration trusts and retire the old forests.
Devices
• Move devices from domain-joined or hybrid-joined to Entra-joined and managed in Intune.
• Rebuild the Group Policy settings that still matter as Intune configuration and compliance
policies.
Microsoft 365 tenant-to-tenant
• Migrate Exchange Online, OneDrive, SharePoint Online and Teams between tenants, plus
public folders where they're in scope.
• Handle the domain and mail-flow cutover, including connectors, MX, SPF, DKIM and DMARC.
• Look after data that's tied to the source tenant, such as sensitivity labels, encrypted content,
retention policies and holds and raise design questions with PwC as they come up.
Tooling, operations and governance
• Use the tool that suits each workload, whether that's Quest, ShareGate, BitTitan MigrationWiz
or Microsoft's native options.
• Script the repetitive work and the validation checks in PowerShell, Microsoft Graph PowerShell
and the Graph API.
• Look after the Azure VMs running the migration and sync servers: sizing, patching, backups,
network access and monitoring.
• Troubleshoot identity and Microsoft 365 issues during and after migration, get to the root
cause and put lasting fixes in place.
• Follow the client's change control process for every production change.
• Keep runbooks, SOPs, validation reports and handover documents up to date.
• Join and sometimes run, working sessions with stakeholders in different regions.
Required Experience
• 5+ years working with Microsoft identity and infrastructure, covering Active Directory, Entra ID
and Microsoft 365.
• Deep hands-on experience in one of these areas and practical experience in the other:
◦ Identity migration: AD forest consolidation, hybrid identity and moving devices to Entra
ID and Intune
◦ Microsoft 365 workload migration: tenant-to-tenant moves for Exchange Online,
OneDrive, SharePoint and Teams
• At least two migration projects delivered hands-on, covering both areas between them.
• A solid grasp of Active Directory: forests and trusts, Group Policy, DNS, replication, Kerberos
and LDAP.
• Experience with Entra Connect or Cloud Sync and a clear understanding of how sourceAnchor
and hard-match work.
• Hands-on time with at least one migration tool, such as Quest (Migration Manager for AD or
On Demand Migration), ADMT, ShareGate, BitTitan MigrationWiz or Microsoft native tooling.
• Practical knowledge of Exchange Online mail flow, SharePoint and OneDrive permissions,
Teams administration and Intune enrolment and policies.
• Strong PowerShell, including the Microsoft Graph PowerShell SDK.
• Clear, confident communication, both in writing and on calls.
Preferred Experience
• Migrations of 5,000+ users across multiple forests or tenants
• Consolidation work following a merger or acquisition
• Exchange hybrid and public folder migrations
• Purview (DLP, sensitivity labels, retention) and Defender, particularly how they affect a
migration
• Azure Automation runbooks
• Experience in banking, financial services or another regulated industry
• Certifications such as MS-102, SC-300, AZ-104 or MD-102 (helpful, not required)