Microsoft 365 Architecture Specialist

Job ID: 40121139

Budget: $750 – $1,500 AUD

Overview

We’re looking for an experienced Microsoft 365 infrastructure specialist to design and correctly configure our Microsoft 365 tenant from the ground up.

This is not a Teams admin or SharePoint content role.

You will be responsible for identity, device management, security, and Cloud PC architecture, ensuring the environment is clean, secure, scalable, and aligned with Zero Trust principles.

If you enjoy doing things properly, locking down environments, and building systems that don’t fall apart later — this role is for you.

What You’ll Be Responsible For
Identity & Access (Foundation)

Microsoft Entra ID tenant hardening

MFA strategy (including break-glass accounts)

Role-based admin access

Disable legacy authentication

Identity-first design

Device Management (Intune)

Microsoft Intune setup (MDM + MAM)

BYOD vs corporate device strategy

Compliance and configuration profiles

App protection policies

iOS, Android, Windows, macOS enrollment flows

Conditional Access & Security

Conditional Access policies (risk-based, device-based)

Geo-aware access (AU / PH)

Cloud PC–only access for privileged roles

Defender for Business baseline policies

Windows 365 / Cloud PC

Cloud PC provisioning policies

Intune integration

Secure isolation (no personal account bleed)

Clipboard, USB, and session controls

Teams & SharePoint (Governance Only)

Clean SharePoint site architecture

Permissions and access boundaries

Proper Teams, SharePoint structure

Retention and audit considerations
(No content creation or site building)


What Success Looks Like

Work is isolated inside Cloud PCs

Personal devices pose minimal risk

Conditional Access blocks non-compliant access automatically

SharePoint and Teams are structured, not chaotic

Environment is future-ready for ISO 27001 / SOC 2

No rework required later

Required Experience

Proven experience with Microsoft 365 Business Premium

Strong hands-on experience with Microsoft Intune

Deep understanding of Conditional Access

Experience with Windows 365 / Cloud PC

Identity & security-first mindset

Ability to explain decisions clearly and simply


Nice to Have (Not Required)

Zero Trust architecture experience

ISO 27001 or SOC 2 exposure

Microsoft certifications (MD-102, SC-300, etc.)

This is a fresh tenant so no messy clean up required.

This Role Is NOT For You If

You mainly build Teams channels or SharePoint sites

Your focus is mailbox management or end-user support

You avoid security or identity topics

You prefer “quick fixes” over proper architecture


Please reply with your experience along with a CV or company track record.