The L3 Endpoint SME is responsible for end-to-end ownership, architecture, and optimization of endpoint management platforms, including Microsoft Endpoint Configuration Manager (SCCM) and Microsoft Intune (MEM).
This role acts as the highest technical escalation point, drives platform stability, automation, and modernization (Intune-first strategy), and ensures secure, compliant, and scalable endpoint management across the enterprise.
Key Responsibilities
Platform Ownership & Architecture
Own the design, architecture, and roadmap for:
SCCM (ConfigMgr)
Microsoft Intune (MDM/MAM)
Co-management (SCCM + Intune)
Drive transition towards cloud-first endpoint management (Intune-first approach)
Define standards for:
Device configuration
Application deployment
Patch management
Compliance & security baselines
Advanced Troubleshooting & Escalation (L3)
Act as final escalation point for complex endpoint issues:
Patch failures across large device groups
Application deployment failures (complex packaging/detection issues)
Co-management conflicts (SCCM vs Intune workloads)
Policy conflicts (GPO, Intune, security baselines)
Perform deep-dive troubleshooting using:
SCCM logs (CAS.log, WUAHandler.log, AppEnforce.log, etc.)
Intune diagnostics & device logs
Engage Microsoft/OEM support with detailed diagnostics
Patch Management Strategy & Governance
Define and govern enterprise patching strategy:
Monthly patch cycles
Emergency patching (zero-day vulnerabilities)
Patch rings and deployment groups
Ensure high compliance (>95–98%) across setting
Align patching with security and audit requirements
Application Packaging Strategy & Engineering
Define standards and frameworks for:
Application packaging (MSI, EXE, Win32 apps)
Detection methods and deployment logic
Review and approve complex application packages
Drive a