Hope you're doing well!
Please find below JD and let me know your thoughts
Role: System Engineer with Azure AD
Location: Santa Ana, CA
Visa: Any Visa
Experience: 10+years
Most Important Skill.
Azure AD & Tenant Configuration
Active Directory Forest Trust with Entra Connect Sync
Hands on
1. Windows Administration: Expertise in Windows AD, Domains, DNS, DHCP, Forest creation, modification, and integration.
2. Security & Authentication: Knowledge of External DNS, NTLM, Kerberos, Certificate Authority, and SAML SSO.
3. Intune Administration
4. Azure AD & Tenant Configuration
5. O365 Administration: Not an expert-level requirement but should understand and be able to create connectors.
6. Networking Basics: VLAN, VLAN segmentation, Firewalls, Privileged Access Management.
7. Knowledge in SQL Administration – Not an expert level
8. Azure Administration: Experience in deploying Azure resources, managing Resource Groups (RGs), NSGs, tagging, ARM templates, and VPN gateways.
Must-Have Experience in at Least One of the Following Scenarios:
1. Active Directory Forest Trust with Entra Connect Sync
o Establishing a bidirectional forest trust between two AD forests.
o Synchronizing both forests to a single Entra tenant using Microsoft Entra Connect Sync.
o Enabling cross-forest authentication for Entra-integrated and AD-integrated apps.
o Requires TCP/IP network connectivity between domains and domain controllers.
o Ideal for legacy AD-integrated apps that require cross-forest access.
2. Synchronizing Both Forests via a Single Entra Connect
o Using a single Entra Connect server to sync objects from both forests to one tenant, without a forest trust.
o Enabling authentication for Entra-integrated apps but restricting AD-integrated app access between forests.
o Requires network access between the Entra Connect server and both domain controllers.
o Suitable when cross-forest AD app access is not needed.
3. Entra Connect Cloud Sync for a Secondary Forest
o Utilizing Cloud Sync (lightweight agent) for the secondary forest while keeping the primary Entra Connect setup.
o Synchronization without full AD connectivity, ideal for geographically distributed networks.
o Supports hybrid environments, where one forest operates in a cloud-centric model.
o