1. Hands-on enterprise Active Directory / Windows Server (2016/2019/2022) administration at L3 level with deep expertise in AD DS design multi-DC forests/domains, OUs, trusts, GPO management, DNS, Kerberos, and AD replication.
2. Proven experience with HA / DR domain controller architecture and AD backup/restore (including krbtgt & DSRM recovery).
3. Working knowledge of PAM and MFA integration and least-privilege / SoD / RBAC enforcement.
Solid PowerShell scripting for automation and reporting.