Role Overview
The L3 Active Directory (AD) & Windows Server Engineer is a senior technical resource responsible for the end-to-end administration, upgrade, migration, and security hardening of enterprise Active Directory, Windows Server and Hyper-V environments. This role combines hands-on experience on complex Hyper-V, Windows server environments, operational ownership with the ability to lead complex AD initiatives including Domain Controller upgrades, migrations, and security hardening programs – and acts as the escalation point for issues beyond L1/L2 capability. The profile is designed to be broadly applicable across AD/Hyper-V/Windows Server engagements, not tied to any single project.
Key Roles & Responsibilities
1. Own end-to-end administration and troubleshooting of enterprise AD environments – DNS, Group Policy, SYSVOL replication, and authentication services (Kerberos/LDAP/NTLM).
2. Lead AD and Windows Server upgrade/migration initiatives – Domain Controller builds, FSMO role transfers, functional level upgrades, and legacy decommissioning.
3. Design and implement security hardening measures – privileged access tiering, service account security, protocol hardening, and alignment with industry best practices.
4. Serve as the L3 escalation point for complex AD/Windows Server incidents – driving root-cause analysis and permanent resolution beyond L1/L2 capability.
5. Support hybrid identity and cloud integration – Microsoft Entra Connect sync, troubleshooting, and coordination with cloud/identity teams.
6. Administer Hyper-V virtualization and cluster infrastructure – host/cluster build and configuration, VM provisioning and lifecycle management, storage and networking, and troubleshooting across the virtualized environment.
7. Maintain documentation, drive change management, and mentor L1/L2 engineers – runbooks, as-built records, and knowledge transfer to strengthen operational maturity.
Technical Skill Set Required
- Windows Server & AD DS:
Solid hands-on experience with Windows Server 2016/2019/2022/2025 and Active Directory Domain Services.
- Windows Server upgrade/migration: 2016 2019/2022/2025 – in-place and migration-based upgrade approaches, compatibility assessment, and rollback planning.
- Domain Controllers: Build, promotion/demotion, and multi-site replication topology.
- FSMO & Functional Levels: FSMO role management, Domain/Forest Functional Level upgrades and dependencies.
- DNS & DHCP: AD-integrated DNS and DHCP administration.
- Group Policy: Design, troubleshooting, and enterprise-scale management.
- SYSVOL/DFSR: Replication configuration and health validation.
- Authentication protocols: Kerberos, LDAP, and NTLM – configuration and troubleshooting.
- Hybrid identity: Microsoft Entra Connect (Azure AD Connect) sync, configuration, and troubleshooting.
- Azure fundamentals (basic): Working knowledge of Entra ID/Azure AD concepts and hybrid identity scenarios – AD/on-prem remains the primary focus, not deep Azure administration.
- Security hardening: Windows LAPS, gMSA, Tier 0/1/2 privileged access model, legacy protocol remediation.
- Hyper-V & Clustering: Host and Failover Cluster build/configuration, VM provisioning and lifecycle management, storage/networking, and general troubleshooting.
- PowerShell: Scripting for automation, auditing, and bulk administration.
- Backup/DR fundamentals: System State backup, restore validation, rollback planning.
- Monitoring & diagnostics: Familiarity with AD health-check and replication diagnostic tools.
- ITSM/ticketing: Working knowledge of ITSM/ticketing platforms for incident and change management.
Preferred Qualifications
- 9+ years of hands-on AD/Hyper-V/Windows Server infrastructure experience.
- Relevant certification (e.g., Microsoft Certified: Windows Server Hybrid Administrator Associate, MCSE, or Azure Fundamentals AZ-900).
- Prior experience with large-scale AD migrations, Migrating to Hyper-V or Domain Controller/Windows Server upgrade projects.
- Strong written and verbal communication skills for client-facing documentation and reporting.
📌 Active Directory Specialist (Pune)
🏢 Shi
📍 Pune