21 Aug
|
Tech Mahindra
|
Hyderabad
21 Aug
Tech Mahindra
Hyderabad
Role & responsibilities
Role Summary
The Active Directory & Exchange L3 Engineer is responsible for the design, administration, troubleshooting, and optimization of Active Directory, Exchange Server/Exchange Online, Azure AD, and related Microsoft infrastructure services. The role serves as the highest escalation point for complex incidents, problem management, security, and infrastructure changes.
Key Responsibilities
Active Directory
- Administer Active Directory forests, domains, trusts, and Organizational Units (OUs).
- Manage Domain Controllers, replication, FSMO roles, Sites & Services, and AD health.
- Create and troubleshoot Group Policies (GPOs).
- Manage AD schema updates and directory services.
- Perform AD security hardening and compliance activities.
- Manage AD-integrated DNS and DHCP services.
- Troubleshoot authentication issues, Kerberos, LDAP, and NTLM problems.
- Administer service accounts, privileged accounts, and delegated permissions.
- Support PKI, certificate services, and identity management solutions.
Exchange / Microsoft 365
- Administer Exchange Server 2016/2019 and Exchange Online.
- Manage mailboxes, shared mailboxes, distribution groups, and mail-enabled security groups.
- Troubleshoot mail flow, transport rules, connectors, and hybrid environments.
- Configure and support Exchange Hybrid deployments.
- Manage Exchange DAG, Database maintenance, and backup/recovery.
- Implement email security solutions, SPF, DKIM, and DMARC.
- Troubleshoot Outlook connectivity and Autodiscover issues.
- Support mailbox migration projects and tenant consolidations.
- Manage retention policies, litigation hold, and compliance requirements.
Incident & Problem Management
- Act as L3 escalation point for critical incidents.
- Perform RCA and implement permanent fixes.
- Lead technical bridge calls during P1/P2 incidents.
- Develop preventive maintenance and automation initiatives.
Security & Compliance
- Implement Identity and Access Management (IAM) controls.
- Manage Active Directory auditing and privileged access.
- Monitor security vulnerabilities and remediation activities.
- Support CyberArk, Entra ID (Azure AD), Conditional Access, and MFA.
Automation
- Develop PowerShell scripts for AD and Exchange administration.
- Automate provisioning, reporting, and user lifecycle processes.
- Create operational dashboards and health monitoring reports.
Required Skills
Active Directory
- Forests, Domains, Trusts
- Domain Controllers
- FSMO Roles
- AD Replication
- GPO Design & Troubleshooting
- AD Sites & Services
- DNS & DHCP
- LDAP & Kerberos
- PKI & Certificate Services
- AD Security & Hardening
Exchange
- Exchange 2016/2019
- Exchange Online
- Exchange Hybrid
- DAG
- Mail Flow & Transport Rules
- SMTP
- Autodiscover
- Mailbox Migration
- Exchange Security
Microsoft Cloud
- Microsoft 365
- Entra ID (Azure AD)
- Azure AD Connect
- Conditional Access
- MFA
- Identity Governance
Scripting
- PowerShell
- Exchange Management Shell
- Graph PowerShell
Experience
- 8+ years in Windows Infrastructure.
- 5+ years in Active Directory Administration.
- 5+ years in Exchange Server/Exchange Online Administration.
- Experience supporting enterprise environments with 10,000+ users preferred.
Preferred Certifications
- Microsoft Certified: Identity and Access Administrator
- Microsoft 365 Messaging Administrator
- Microsoft Certified: Azure Administrator
- ITIL Foundation
L3 Interview Must-Have Areas
- AD Replication Troubleshooting
- FSMO Role Failure Scenarios
- Kerberos Authentication Issues
- GPO Processing Troubleshooting
- Exchange Hybrid Mail Flow
- DAG Failover Troubleshooting
- Azure AD Connect Sync Issues
- Mail Routing and Transport Rules
- Exchange Database Recovery
- PowerShell Automation
Preferred candidate profile
Perks and perks
📌 Active Directory & ExchangeEngineer (Hyderabad)
🏢 Tech Mahindra
📍 Hyderabad