Users, dynamic and assigned groups, administrative units, directory roles, service principals, workload identities
Conditional Access design and rollout: named locations, client app and platform conditions, session controls, sign-in frequency, break-glass exclusions, report-only staging
Authentication methods policy and phishing-resistant factors
Application onboarding over SAML 2.0 (NameID, claims mapping, signing certificate rollover, encrypted assertions) and OIDC / OAuth 2.0 (authorization code with PKCE, client credentials, device code)
App registrations: redirect URIs, permissions, admin consent workflow, secret and certificate lifecycle. – SCIM 2.0 provisioning: attribute mappings, scoping filters, expression transformations, quarantined jobs, drift reconciliation
Tenant consent settings, OAuth grant review, remediation of over-permissioned and stale applications; defensible controls for SaaS without SSO or SCIM support
Joiner-mover-leaver as an automated pipeline: provisioning, group-based licensing, revocation with session and refresh token invalidation
Least privilege for admin access: scoped role assignments, RBAC, PIM, access reviews, entitlement management access packages
Service account and workload identity governance: ownership, credential rotation, permission scoping, decommissioning
Microsoft 365 tenant settings, licensing, admin roles; access and permission issues in Exchange Online, SharePoint Online, Power Platform
Diagnostics from sign-in, audit, and provisioning logs, with diagnostic settings routed to Log Analytics and KQL queries
Cross-tenant access settings and B2B external collaboration
Google Workspace and Cloud Identity: users, groups, organizational units, admin roles and privileges, licensing, 2-Step Verification enforcement, session controls
Third-party SSO profiles with Microsoft Entra ID as SAML IdP, automated provisioning into Cloud Identity, OU- and group-scoped SSO exclusions
Context-Aware Access policies, third-party OAuth app access control, domain-wide delegation, Drive sharing and external access controls. 2
Google Cloud IAM: project and folder membership, predefined and custom roles, allow policies, service accounts and key hygiene, workload identity federation, API enablement, OAuth clients
PowerShell tooling on the Microsoft Graph PowerShell SDK and Graph REST API: lifecycle, licensing, access reporting, recertification
Google-side automation through the Admin SDK Directory API, Cloud Identity API, and gcloud
Scheduled and event-driven workflows in Azure Automation Runbooks, Azure Logic Apps, or Power Automate
Unattended execution on managed identities and narrowly scoped app registrations, with credential rotation, structured logging, error handling, and retries
Automation treated as production code: version control, peer review, documented rollback
3+ years administering Microsoft Entra ID in production as a primary responsibility
Enterprise applications, app registrations, consent and permission models, automated provisioning
Microsoft 365 administration: tenant settings, licensing, admin roles, and access troubleshooting across Exchange Online, SharePoint Online, and Power Platform
Google Workspace and Cloud Identity administration: organizational units, groups, admin roles, SSO profiles, access settings
Google Cloud IAM: projects, roles and policies, service accounts, API access, OAuth credentials
Strong PowerShell with the Microsoft Graph PowerShell SDK and direct REST API work
Azure Automation Runbooks, Azure Logic Apps, Power Automate, or comparable platforms
Least privilege, secure administration, change management, and the discipline to leave configurations documented
Written and spoken English at B2 or higher
Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI