Skip to main content

Endpoint Administrator (Intune, Defender)

RemoteEU
Published
Role
DevOps
Experience
Mid
Employment
Contract
Salary not disclosed
Check eligibility

Open to Anywhere in EU. Set where you work from to check your eligibility.

No BS summary

Intermediate Endpoint Administrator for Microsoft 365 operations, focused on Intune, Defender, Azure VDI and related Microsoft cloud services. Must be remote from EU countries and an EU citizen. Needs hands-on administration, ticket support, documentation, PowerShell/Graph API automation, security and governance experience.

Core skills

Microsoft IntuneMicrosoft DefenderAzure Virtual Desktop

Required skills

Microsoft 365SharePointOneDriveMicrosoft PurviewMicrosoft CopilotPowerShellAutopilotBYODWin32Microsoft StoreLOB appsWindows UpdateConditional AccessiOSAndroidKQLFSLogixAzure ADEntra IDMFARBACB2BSSOGraph APIITSMGDPR

What you'll do

  • Handle incoming tickets for Microsoft cloud services such as SharePoint, OneDrive, Intune and Defender.
  • Create documentation on the existing infrastructure.
  • Support the Platform Manager in creating governance policies, monitoring, and change management of new features released by Microsoft.
  • Collaborate with administrators of other Microsoft 365 services to ensure smooth platform operations.
  • Efficiently manage and resolve daily support tickets related to Microsoft services, ensuring timely and effective issue resolution.
  • Monitor platform performance and escalate issues when necessary, with Microsoft.
  • Report workload and ongoing tasks within weekly team meetings.
  • Use PowerShell to update system configurations when applicable.
  • Create and maintain documentation of the current infrastructure.
  • Ensure documentation is up-to-date and accessible to relevant stakeholders.
  • Update documentation based on new features released by Microsoft, including material for change management.
  • Provide ongoing technical and operational support to the Platform Managers.
  • Assist in platform migrations and configuration changes.
  • Administer SharePoint, OneDrive, Intune, Defender, Purview and Copilot.
  • Coordinate with administrators of other Microsoft 365 services such as Teams, OneDrive and Exchange to ensure integrated platform support.
  • Participate in cross-functional meetings and contribute to platform-wide initiatives.
  • Handle tickets of other Microsoft services introduced under the responsibility of Digital Workplace service, such as Microsoft Bookings, Viva Insight, Purview or other Microsoft 365 applications.
  • Identify opportunities for automation and process optimisation.
  • Propose improvements to enhance user experience and platform efficiency.
  • Design and implement device enrollment strategies such as Autopilot, BYOD and corporate-owned devices.
  • Create and maintain compliance policies such as encryption, OS version and secure boot.
  • Configure and deploy configuration profiles such as Wi-Fi, VPN, certificates and security baselines.
  • Package and deploy applications such as Win32, Microsoft Store and LOB apps.
  • Implement and manage Windows Update rings and feature update policies.
  • Troubleshoot device compliance, enrollment failures and policy conflicts.
  • Implement Conditional Access integration with Intune compliance.
  • Support mobile device management for iOS/Android including app protection policies.
  • Configure and manage Microsoft Defender for Endpoint policies.
  • Investigate and respond to security incidents and alerts.
  • Perform threat hunting using advanced hunting queries with KQL.
  • Tune detection rules to reduce false positives.
  • Implement and manage attack surface reduction rules.
  • Configure device control policies for USB and removable media.
  • Integrate Defender with Intune and Conditional Access.
  • Produce security reports and recommend improvements.
  • Support vulnerability management and remediation tracking.
  • Design and deploy Azure Virtual Desktop environments.
  • Configure host pools, application groups and workspaces.
  • Optimize session host performance using FSLogix profiles and scaling.
  • Implement image management strategy including golden image and updates.
  • Configure identity integration with Azure AD / Entra ID.
  • Monitor and troubleshoot user sessions and performance issues.
  • Implement cost optimization strategies such as auto-scaling and VM sizing.
  • Secure AVD environment using Defender and Conditional Access.
  • Support end-user connectivity issues and access troubleshooting.
  • Configure and manage Conditional Access policies.
  • Implement MFA and passwordless authentication.
  • Manage role-based access control.
  • Support B2B / guest access scenarios.
  • Integrate applications with Azure AD / Entra ID SSO.
  • Monitor and respond to risky sign-ins and identity alerts.
  • Document solutions and maintain operational runbooks.
  • Automate tasks using PowerShell / Graph API.
  • Participate in service acceptance and transition to operations.
  • Work with stakeholders to translate business requirements into technical solutions.
  • Ensure compliance with security and governance standards.
  • Provide knowledge transfer to internal teams.
  • Adhere to IT Service Management best practices, ensuring consistent, efficient and customer-focused service delivery.
  • Comply with the organisation’s security policies and data protection regulations, including GDPR.
  • Safeguard sensitive information through appropriate handling and confidentiality measures.
  • Apply appropriate access controls to ensure that only authorized personnel can access relevant systems and data.
  • Maintain audit trails for all administrative actions to support accountability and traceability.

What they require

  • Intermediate level profile for daily operational support and administration for Microsoft cloud services such as SharePoint, OneDrive, Intune and Defender.
  • Microsoft 365 administration activities specific expertise.
  • Endpoint Management – Microsoft Intune: ability to design, deploy and troubleshoot modern endpoint management.
  • Security Operations – Microsoft Defender Suite: hands-on experience with endpoint security, threat detection, and response.
  • Virtual Desktop – Azure VDI: ability to deploy and operate scalable virtual desktop environments.
  • Identity & Access: strong understanding of identity as the control plane.
  • Only EU Citizens.
Salary not disclosed