06 Aug
|
Santan Intellect
|
Chennai
06 Aug
Santan Intellect
Chennai
Hybrid Desktop Solution Architecture
- Define the enterprise reference architecture for the hybrid desktop estate, covering both the AVD/Cloud PC and the Managed Desktop with Zero Trust tiers.
- Build persona and workload segmentation models that determine which users are served by virtual desktops and which by Zero Trust managed endpoints, with explicit entry and exit criteria.
- Produce HLDs, LLDs, technical standards, decision records and Azure landing zone designs supporting both delivery models.
- Develop migration strategies from the legacy Omnissa Horizon VDI estate, any residual Citrix DaaS (Virtual Apps &
- Desktops) footprint, and unmanaged or domain-joined fleets, toward the target hybrid state, with a phased, workload-by-workload cutover plan.
- Provide technical guidance on EUC modernisation, compliance-aligned security requirements, cost models and phased transformation roadmaps for a regulated, enterprise-grade environment.
Azure Virtual Desktop &
- Cloud PC Engineering
- Design, deploy, administer and optimise AVD host pools, session hosts, workspaces, application groups and Windows 365 Cloud PCs.
- Configure autoscaling, session host load balancing, capacity planning and cost optimisation.
- Troubleshoot and resolve complex virtual desktop performance, protocol and brokering issues.
Managed Desktop &
- Zero Trust Endpoint Engineering
- Design and operate the Intune-managed desktop platform: Windows Autopilot provisioning, Entra ID join, configuration profiles, compliance policies and update rings.
- Implement Zero Trust controls across the endpoint estate, including explicit verification, least-privilege access and assume-breach segmentation, applied consistently to both managed endpoints and virtual desktops.
- Configure Microsoft Defender for Endpoint, attack surface reduction, endpoint hardening baselines and device risk signalling into Conditional Access.
- Implement data protection controls: Intune App Protection, BitLocker, Windows LAPS, session lockdown,
clipboard/redirection policy and DLP alignment.
- Design secure remote connectivity for managed endpoints without reliance on traditional VPN backhaul.
Identity, Security &
- Compliance (Common Control Plane)
- Design a unified identity architecture across Microsoft Entra ID and Active Directory serving both desktop models.
- Implement Conditional Access, MFA, PIM and risk-based access policies that treat a Cloud PC session and a managed laptop as equally governed access paths.
- Define a single compliance and audit posture across the hybrid estate, working closely with security and privacy teams on data-protection, access-governance and other regulatory obligations.
Cloud Infrastructure
- Architect and manage the Azure infrastructure underpinning the hybrid desktop estate, including VNets, NSGs, Private Link, ExpressRoute and load balancers.
- Configure Azure Compute, Storage, Backup and Site Recovery for desktop and profile workloads.
- Support hybrid connectivity and multi-region deployments, and optimise Azure consumption and cloud cost.
Profiles, Images &
- Application Delivery
- Design profile and state management using FSLogix for virtual desktops and Enterprise State Roaming / OneDrive Known Folder Move for managed endpoints, delivering a consistent user experience across both.
- Maintain standardised image and configuration baselines shared across virtual and physical estates where possible, and manage app layering and MSIX App Attach.
- Optimise logon times, profile performance and application launch consistency across both tiers.
Automation &
- Infrastructure as Code
- Automate provisioning and configuration using PowerShell, Azure CLI, ARM/Bicep, Terraform and Microsoft Graph API, with IaC and pipeline-driven deployment for host pools, Cloud PCs, Autopilot profiles and Intune policy sets.
- Automate image build and endpoint lifecycle management to support DevOps practices.
Monitoring, Performance &
- FinOps
- Monitor the hybrid estate using Azure Monitor, Log Analytics and Intune Endpoint Analytics (or comparable digital employee experience tooling), tracking DEX metrics comparably across virtual and physical desktops.
- Perform root cause analysis, performance tuning and capacity planning, applying FinOps practices to control Azure and licensing spend.
Resilience, DR &
- Business Continuity
- Design DR and business continuity strategies for both tiers, including multi-region host pool failover for virtual desktops and rapid Autopilot re-provisioning for managed endpoints.
- Configure backup, replication and failover, and maintain runbooks through regular DR testing and validation.
Required Experience
- 7 12 years in IT Infrastructure and End User Computing, including at least 5 years designing and delivering enterprise desktop solutions (virtual desktop and modern managed endpoint platforms) at a scale of 1000+ desktops.
- Demonstrated experience architecting a hybrid estate where AVD/Cloud PC and Intune-managed desktops coexist under a shared identity and security model.
- Practical experience implementing Zero Trust principles for endpoints and remote access.
- Strong solution architecture experience, with enterprise migration and modernisation delivery, ideally including regulated or compliance-sensitive environments subject to data-protection frameworks such as HIPAA, PCI-DSS, SOC 2 or comparable.
- Experience working effectively across a distributed, multi-time-zone team, with proven ability to build stakeholder trust and drive outcomes remotely.
📌 Hybrid Desktop Infrastructure Architect/Engineer-AVD(Immediate Joiner) (Chennai)
🏢 Santan Intellect
📍 Chennai