Staff Engineer, Microsoft Active Directory

Remote, in remote Until 10/5/2026 5+ years exp H-1B sponsor history First posted August 6, 2026 Last posted August 6, 2026
Job description

👋🏼We're Nagarro.

We are a Digital Product Engineering company that is scaling in a big way! We build products, services, and experiences that inspire, excite, and delight. We work at scale across all devices and digital mediums, and our people exist everywhere in the world (18500+ experts across 40 countries, to be exact). Our work culture is dynamic and non-hierarchical. We're looking for great new colleagues. That's where you come in!

REQUIREMENTS:

• Total experience: 5.5+ years.
• Strong experience in Microsoft Active Directory administration across enterprise, multi-site environments.
• Must-have expertise in Microsoft Entra ID (Azure AD) administration and Hybrid Identity (Entra Connect/AD Connect).
• Strong experience in managing Domain Controllers, AD Replication, FSMO Roles, Schema, Trusts, NTDS, DFSR, and AD Sites & Services.
• Hands-on experience with Windows Server (2012–2022+), DNS, DHCP, IIS, and Group Policy (GPO) administration.
• Experience designing and implementing Conditional Access, SSO, MFA, RBAC, PIM, and Identity Lifecycle Management.
• Strong understanding of Microsoft 365 identity services, Exchange Online, and Hybrid Exchange administration.
• Experience managing mail flow, connectors, SPF, DKIM, DMARC, licensing, and directory synchronization.
• Hands-on experience troubleshooting OAuth, SAML, Kerberos, and NTLM authentication issues.
• Strong scripting experience using PowerShell and automation with Microsoft Graph API.
• Experience with Active Directory migrations, upgrades, consolidations, backup, disaster recovery, and high availability.
• Good knowledge of identity security, IAM best practices, compliance, and enterprise authentication.
• Experience using Active Directory administration and migration tools such as Quest is preferred.
• Strong analytical, troubleshooting, communication, and stakeholder management skills.

RESPONSIBILITIES:

• Design, administer, and optimize enterprise Microsoft Active Directory and Microsoft Entra ID environments.
• Manage Domain Controllers, AD replication, FSMO roles, trusts, schema, NTDS, DFSR, and AD Sites & Services.
• Implement, maintain, and secure Group Policy (GPO) frameworks across enterprise environments.
• Administer Windows Server, DNS, DHCP, IIS, and core identity infrastructure services.
• Design and enforce Conditional Access, MFA, SSO, RBAC, PIM, and identity governance policies.
• Manage Hybrid Identity using Microsoft Entra Connect (Azure AD Connect) and ensure seamless directory synchronization.
• Administer Microsoft 365 identity services, Exchange Online, and Hybrid Exchange environments.
• Manage mail flow, connectors, authentication protocols, and compliance-related identity configurations.
• Develop and maintain PowerShell automation scripts and leverage Microsoft Graph API for administration and reporting.
• Lead Active Directory upgrades, migrations, consolidations, backup, recovery, and disaster recovery initiatives.
• Troubleshoot and resolve complex authentication issues involving OAuth, SAML, Kerberos, and NTLM.
• Perform root cause analysis for critical production incidents and implement preventive solutions.
• Collaborate with cloud, infrastructure, and security teams to strengthen enterprise identity services.
• Monitor identity security posture, ensure compliance, and continuously improve identity management processes and automation.

Bachelor’s or master’s degree in computer science, Information Technology, or a related field

About this role

Summary

Design, administer, and optimize enterprise Microsoft Active Directory and Entra ID environments, manage identity services and automation.

Job title

Staff Engineer, Microsoft Active Directory

Experience level

5+ years

Minimum experience

5+ years exp

Industry

software

Location requirements

Remote work allowed, candidate in any location

Salary

Not specified

Visa sponsorship

H-1B sponsor history

Management role

No

Skills & keywords

Required skills

Active DirectoryAzure ADPowerShellWindows ServerMicrosoft Graph APIOAuthSAMLKerberosNTLM

Preferred skills

Quest toolsenterprise securitycompliancedisaster recovery

Specializations

Active DirectoryAzure ADIdentity ManagementWindows ServerPowerShell
Locations

Structured locations inferred from the posting.

India

Remote Country