25 Sep
|
Accenture
|
Bengaluru
25 Sep
Accenture
Bengaluru
Project Role: Operations Engineer
Project Role Description: Support the operations and/or manage delivery for production systems and services based on operational requirements and service agreement.
Must have skills: Microsoft Endpoint Configuration Manager
Good to have skills : NA
Minimum 7.5 year(s) of experience is required
Educational Qualification: 15 years full time education
Summary:
The Senior Windows Endpoint Engineer owns the Windows client end to end, from the bare-metal build to the experience the user has on the first morning and every morning after. The role is accountable for the image and task sequence architecture in Microsoft Configuration Manager, the Group Policy and configuration estate that governs the desktop, and the Power Shell that automates, hardens and self-heals it.
The role spans both management planes: the on-premises Config Mgr estate that builds the device today, and the Microsoft Intune and cloud-native stack the estate is moving to, provisioning, policy, application delivery and patching from the cloud.
This is a hands-on build engineering role, not console administration: success is a device that provisions predictably, applies its configuration without conflict, performs well on day one, and stays that way through patch, upgrade and refresh cycles, regardless of which plane manages it.
Roles & Responsibilities:
Operating system deployment and task sequence engineering. Own Windows build design across imaging, drivers, WinPE, task sequences, upgrades, state migration, Bit Locker and firmware integration. Troubleshoot deployment failures from logs and make fixes repeatable.
Configuration Manager platform engineering. Engineer and maintain Config Mgr site health, roles, boundaries, distribution points, PXE, boot images, client settings, collections, software updates and reporting. Manage co-management and workload transition to Intune.
Modern endpoint management with Intune and cloud management. Build and manage Intune capabilities for Autopilot, enrollment, Windows policy, compliance, security baselines, scripts and proactive remediations. Migrate GPO and Config Mgr workloads to cloud management with explicit validation.
Cloud patch and update management. Own Windows servicing through Windows Update for Business, Autopatch where adopted, update rings, deferrals, expedited updates, feature updates, driver policy and compliance reporting. Optimize update delivery for remote and bandwidth-constrained sites.
Cloud application delivery. Package and deploy Intune Win32, Microsoft Store, Enterprise App Catalog and Microsoft 365 Apps with reliable detection, requirements, dependencies, supersedence and assignment strategy. Convert Config Mgr applications to cloud-ready equivalents.
Group Policy and configuration management. Own the GPO estate, including OU structure, filtering, precedence, ADMX,
preferences and documented baselines. Rationalize legacy policy, resolve conflicts, and map policies to Intune where appropriate.
Power Shell automation and configuration scripting. Build production-grade Power Shell for provisioning, configuration, detection, remediation, reporting and drift control. Ensure scripts are logged, error-handled, idempotent, signed and source-controlled.
Application packaging and delivery. Own application packaging across MSI, MSIX, App-V where required, and Intune Win32 apps. Standardize silent installs, transforms, uninstall logic, rollback testing, catalog quality and self-service delivery.
Windows platform, identity and backend integration. Engineer endpoint dependencies including Active Directory, Entra ID, domain join, DNS, DHCP, PKI, WSUS, activation, Windows Hello for Business and LAPS. Understand network and content-delivery behavior supporting branch and remote builds.
Security, hardening and patch engineering. Implement Windows security baselines, Bit Locker, ASR, WDAC or App Locker, Credential Guard, exploit protection and local admin controls. Maintain patch compliance, feature update readiness and remediation of non-compliant devices.
End-user experience engineering. Measure and improve provisioning, OOBE, boot, sign-in, policy processing, application reliability and profile performance. Use telemetry, targets and proactive remediation to reduce tickets and technician touch.
Operations, change and technical leadership. Lead change, pilot planning, validation, backout, Tier 3/4 escalation and root-cause analysis. Maintain clear documentation, runbooks, design records, roadmaps and technical debt priorities.
Professional & Technical Skills:
7+ years in Windows endpoint or desktop engineering, with significant ownership of the build and configuration estate in a large or complex environment.
Deep hands-on Microsoft Configuration Manager engineering: site administration, OS deployment, task sequence authoring and debugging, application and update deployment, collections, boundaries and content distribution.
Demonstrable mastery of Windows OS deployment — imaging and image servicing, WinPE and boot image customization, driver management, USMT, and in-place upgrade at scale.
Hands-on Microsoft Intune engineering for Windows: Autopilot provisioning, settings catalog and ADMX-backed policy, compliance policies, platform scripts and proactive remediations, filters and scope tags.
Cloud patch and update management with Windows Update for Business — ring and deferral design, feature update control, expedited updates, and compliance reporting — and familiarity with Windows Autopatch.
Cloud application delivery through Intune Win32 apps, including packaging, detection and requirement rules, supersedence, and assignment strategy.
Advanced Group Policy engineering: policy architecture, filtering, precedence and conflict resolution, ADMX central store, preferences, and systematic rationalization of legacy policy.
Production-grade Power Shell scripting for configuration, automation, detection and remediation, including error handling, logging, code signing and source control.
Strong Windows client internals and troubleshooting: registry, services, WMI, event and setup logs, performance analysis, profile and logon behavior.
Application packaging across MSI, Win32 and MSIX, including detection logic, transforms and supersedence.
Working knowledge of the supporting backend: Active Directory, Entra ID, DNS, DHCP, PKI and certificate autoenrollment, WSUS and update infrastructure, and activation services.
Windows security baseline and hardening experience, including Bit Locker, application control, ASR and patch compliance management.
Enterprise change, incident and problem discipline, high-quality technical documentation, and clear communication to technical and nontechnical audiences.
End-to-end ownership of a Microsoft Configuration Manager environment, design, engineering, and Tier 3/4 support across site architecture, OS deployment, content distribution, and update management, with demonstrable modernization or co-management work alongside Microsoft Intune.
Delivered migration of a workload from Config Mgr to cloud management, provisioning, policy, application delivery or patching, including parity validation and on-premises retirement.
Zero-touch or low-touch provisioning delivery, Autopilot, pre-provisioning, or a hardened Config Mgr sequence replacing technician-built devices.
Large-scale Windows feature update or OS migration programs, including application and driver compatibility remediation.
Advanced automation beyond scripting, policy-as-code, CI/CD for packaging, Graph or WMI-driven reporting, or infrastructure automation.
Global, highly regulated, or large-enterprise environments, including frontline, shared-device or VDI populations.
Additional Information:
- The candidate should have minimum 7.5 years of experience in Microsoft Endpoint Configuration Manager.
- Certifications such as MD-102, MCSE or equivalent Windows Server and client credentials, SC-200 or SC-100, or a scripting or automation certification.
- This position is based at our Bengaluru office.
- A 15 years full time education is required.
📌 Operations Engineer (Bengaluru)
🏢 Accenture
📍 Bengaluru