Workspace Modernization(Intune Developer)
Client Information
The client is a multinational organization operating in a highly dynamic industry, with regional presence across multiple markets. The engagement involves managing complex account relationships, ensuring seamless program delivery, and coordinating with cross-functional teams to support ongoing business operations and strategic initiatives.
Role overview
The Senior Microsoft Intune Engineer will lead and support the endpoint management workstream within the Customer Microsoft 365 Migration Project. The role covers assessment, solution design, migration planning, configuration guidance, deployment support, documentation, and operational transition for the migration of Windows 11 devices from Workspace ONE to Microsoft Intune in a co-managed Microsoft Configuration Manager and Intune environment.
The role will work closely with Customer infrastructure, security, identity, application, service management, and project teams to deliver a secure, scalable, and supportable endpoint management capability across the in-scope Customer entities.
Required skills and experience
- Strong hands-on experience with Microsoft Intune and enterprise endpoint management.
- Experience designing and delivering Windows 11 device management solutions.
- Experience with Workspace ONE to Intune migration or comparable endpoint management platform migrations.
- Experience with Microsoft Configuration Manager and Intune co-management.
- Strong knowledge of Microsoft Entra ID, Conditional Access, device compliance, configuration profiles, application protection policies, Windows update rings, endpoint security, and encryption controls.
- Experience with RBAC, scope tags, dynamic groups, security baselines, Group Policy assessment, and policy migration.
- Experience producing architecture documents, technical designs, migration plans, runbooks, configuration guides, and operational documentation.
- Ability to facilitate technical workshops and work across infrastructure, identity, security, application, service management, and project teams.
- Strong troubleshooting, analytical, documentation, and stakeholder communication skills.
Preferred qualifications
- Microsoft Certified: Endpoint Administrator Associate (MD-102) or an equivalent current Microsoft endpoint management certification.
- Microsoft identity, security, or Microsoft 365 certifications.
- Experience supporting endpoint transformation within financial services or another regulated industry.
- Experience with Microsoft Defender for Endpoint, Windows Hello for Business, PKI, NDES, SCEP, certificate-based authentication, VPN, and Wi-Fi profile deployment.
- Experience supporting large, geographically distributed enterprise environments.
Key deliverables
- Confirmed device volumetrics and documented design decisions.
- Intune high-level design inputs and migration approach.
- Intune policies and best-practice guide tailored to the Customer environment.
- Build guidance, configuration walkthrough inputs, implementation issue log, and updated RAID log.
- Risk and Remediation Action Plan with recommended mitigation actions.
- Go-live, hypercare, and warranty completion reports.
- Updated operational documentation and migration runbooks.
Role boundaries
- The role is primarily focused on advisory support, solution design, configuration documentation, migration guidance, validation, and remediation recommendations.
- Activities outside the agreed endpoint migration scope, including non-Windows endpoint management, network infrastructure changes, hardware procurement or replacement, and broad line-of-business application remediation, should be handled through the appropriate project governance and change-control process.
Success measures
- Approved Intune design and migration approach aligned with the agreed project scope.
- Migration waves are supported with clear prerequisites, validation criteria, risks, and remediation actions.
- In-scope devices are validated against agreed enrollment, configuration, application, and compliance requirements.
- Operational documentation and knowledge transfer are completed for transition to Customer business-as-usual support.
- Open risks, issues, dependencies, and residual actions are clearly documented at workstream closure.
Key responsibilities
Discovery and assessment
- Assess the existing Workspace ONE, Microsoft Configuration Manager, Microsoft Intune, and Windows endpoint management environments.
- Review device inventory, operating system versions, management status, user groupings, application requirements, and existing policy configurations.
- Identify migration prerequisites, technical constraints, dependencies, security gaps, and operational readiness requirements.
- Support workshops to confirm device scope, migration priorities, sequencing, assumptions, and design decisions.
- Develop and maintain risk, issue, dependency, and remediation inputs for the Intune workstream.
Solution architecture and design
- Develop the Intune high-level design and provide detailed design inputs for the target endpoint management solution.
- Design device enrollment, provisioning, configuration, compliance, application deployment, and update management approaches.
- Define Intune role-based access control, scope tags, assignment groups, and dynamic membership rules.
- Design endpoint security settings, encryption standards, security baselines, and policy alignment.
- Collaborate with identity and security teams on Conditional Access, Microsoft Entra ID, Microsoft Defender for Endpoint, and related controls.
- Identify and document conflicts between existing Group Policy Objects and proposed Intune configurations.
Build and configuration guidance
- Configure or provide implementation guidance for Intune tenant settings, enrollment profiles, configuration profiles, compliance policies, update rings, and endpoint security policies.
- Configure or guide the setup of application protection policies, application assignments, VPN profiles, and Wi-Fi profiles within the agreed scope.
- Support the preparation, validation, and attestation of scripts used for migration or configuration activities.
- Provide configuration walkthroughs and troubleshooting support to the Customer technical teams.
- Maintain implementation issue logs and contribute updates to the project RAID log.
Migration, pilot, and deployment support
- Develop the Workspace ONE to Intune migration approach, pilot plan, migration waves, and deployment schedule.
- Support the controlled unenrollment of devices from Workspace ONE and enrollment into Microsoft Intune.
- Support application deployment and configuration assignment to migrated devices.
- Validate enrollment status, policy application, application availability, and device compliance following migration.
- Track migration progress, exceptions, defects, and remediation actions across deployment waves.
- Provide technical support during pilot, rollout, go-live, hypercare, warranty, and transition-to-operations activities.
Documentation and knowledge transfer
- Produce Intune design documents, implementation guidance, configuration standards, operational guides, and migration runbooks.
- Document device compliance policies, update rings, encryption standards, security baselines, RBAC, scope tags, VPN profiles, and Wi-Fi profiles.
- Prepare go-live, hypercare, warranty, risk, and remediation completion reports for the Intune workstream.
- Conduct knowledge transfer sessions for Customer administrators, engineering teams, and support teams.
- Ensure documentation is updated to reflect approved design decisions, implemented configurations, known issues, and operational ownership.
Interested please share your resume
sahana.doddamani@adeccogroup.com
Ref: JN-092026-211354