Job Description — Intune Administrator / L2 Engineer
Job Title: Microsoft Intune Administrator — L2
Department: IT Infrastructure & Endpoint Management
Employment Type: Full-Time
Experience Required: 3–5 Years
Location: Pune, Work from office
About the Role
We are looking for an experienced Microsoft Intune Administrator at the L2 level to manage, configure, and support our enterprise endpoint management environment. The ideal candidate will have hands-on expertise in Microsoft Intune, Microsoft Entra ID, and the broader Microsoft 365 ecosystem, with a strong understanding of device lifecycle management, compliance policies, and security hardening across Windows, macOS, iOS, and Android platforms.
Key Responsibilities
Endpoint Management & Configuration
- Design, deploy, and manage Microsoft Intune policies including Device Configuration Profiles, Compliance Policies, Application Protection Policies (APP), and Conditional Access integration.
- Manage device enrollment across all platforms — Windows Autopilot, Apple DEP/ADE, Android Enterprise — ensuring zero-touch provisioning for end users.
- Configure and maintain Windows Update for Business (WUfB) rings and Feature Update policies to maintain patch compliance across all managed endpoints.
- Manage co-management scenarios between Microsoft Intune and Microsoft Configuration Manager (SCCM/MECM), including workload migration.
- Administer Microsoft Defender for Endpoint integration with Intune for threat and vulnerability management, attack surface reduction rules, and endpoint detection response policies.
Application Management
- Package, deploy, and maintain Win32 applications, Microsoft Store apps, LOB apps, and web clips across Intune-managed devices.
- Configure and manage Microsoft 365 Apps deployment via Intune, including Office Customization Tool (OCT) configurations.
- Implement and manage Application Protection Policies (MAM) for BYOD scenarios on iOS and Android.
- Monitor and troubleshoot application deployment failures using Intune logs, Collect Diagnostics, and CMTrace.
Security & Compliance
- Implement and enforce device compliance policies aligned with organizational security baselines including CIS Benchmarks and Microsoft Security Baselines.
- Configure Conditional Access policies in Microsoft Entra ID to enforce device compliance as a condition for resource access.
- Manage BitLocker encryption policies, recovery key escrow, and disk encryption compliance reporting.
- Administer Windows Hello for Business, FIDO2, and certificate-based authentication through Intune and Entra ID.
- Configure and manage Endpoint Privilege Management (EPM) to control local admin rights without compromising security.
- Implement Microsoft Purview Information Protection policies through Intune for data classification and DLP enforcement on endpoints.
Identity & Entra ID Integration
- Manage Hybrid Azure AD Join and Azure AD Join configurations and troubleshoot device registration issues.
- Administer Entra ID group-based policy targeting including dynamic device groups and assignment filters.
- Configure and troubleshoot Azure AD Connect for hybrid identity synchronization.
- Support Entra ID Conditional Access policy design and review in collaboration with the security team.
L2 Support & Incident Management
- Serve as L2 escalation point for endpoint-related incidents escalated from the L1 helpdesk team — covering Intune enrollment failures, policy conflicts, app deployment issues, and compliance remediation.
- Investigate and resolve complex device management issues using Intune diagnostic logs, Event Viewer, Microsoft Graph Explorer, and PowerShell.
- Document resolutions and root cause analysis in the ITSM ticketing system and contribute to the internal knowledge base.
- Participate in on-call rotation and provide support for P1/P2 endpoint incidents affecting business-critical operations.
- Collaborate with the security operations team during endpoint-related security incidents.
Automation & Reporting
- Develop and maintain PowerShell scripts for bulk device operations, policy assignments, reporting, and remediation tasks via Intune Remediations (Proactive Remediations).
- Generate and distribute regular compliance and inventory reports using Microsoft Endpoint Analytics, Intune Reporting, and Power BI.
- Build and maintain Microsoft Graph API-based automation for Intune operations.
- Configure and manage Intune Remediations to proactively detect and fix endpoint configuration drift.
Documentation & Process
- Maintain up-to-date technical documentation for all Intune configurations, policies, baselines, and operational procedures.
- Contribute to change management processes by authoring change requests and impact assessments for Intune policy changes.
- Support audit and compliance activities by providing Intune reporting evidence for SOC 2, ISO 27001, or other applicable frameworks.
Required Skills & Qualifications
Technical Skills
- Minimum 3–5 years of hands-on experience with Microsoft Intune in an enterprise environment
- Strong understanding of Windows 10/11 device management, MDM protocol, and OMA-URI configurations
- Experience with Windows Autopilot (self-deploying, user-driven, pre-provisioning modes)
- Proficiency in Microsoft Entra ID (Azure AD) — Conditional Access, device registration, dynamic groups
- Solid PowerShell scripting skills for endpoint automation and Intune Graph API interaction
- Experience with Microsoft Defender for Endpoint and its integration with Intune
- Hands-on experience with macOS, iOS, and Android device management via Intune
- Familiarity with SCCM/MECM co-management and workload migration
- Understanding of PKI, certificate deployment via SCEP/PKCS, and Intune Certificate Connector
- Knowledge of Microsoft 365 Apps deployment and Office customization via Intune
Soft Skills
- Strong analytical and problem-solving ability for complex L2 endpoint issues
- Excellent written and verbal communication for technical documentation and stakeholder updates
- Ability to work independently and prioritize multiple incidents and projects simultaneously
- Collaborative mindset for working with security, networking, and helpdesk teams
Preferred Qualifications
- Experience with Microsoft Configuration Manager (MECM/SCCM) in co-management scenarios
- Exposure to Microsoft Endpoint Analytics and Desktop Analytics
- Familiarity with Zero Trust architecture principles and implementation
- Experience with third-party tools like NinjaRMM, ThreatLocker, or similar RMM/EDR platforms
- Knowledge of ITIL framework and experience with ITSM tools
Pay: ₹318,401.20 - ₹1,392,273.24 per year
Benefits:
Work Location: In person