AD SME L3 (Active Directory Subject Matter Expert – Level 3)

People Prime Worldwide

We are looking for an experienced AD SME L3 to provide advanced-level support, administration, troubleshooting, and architecture expertise for enterprise Microsoft Active Directory environments. The role will be responsible for resolving complex AD issues, maintaining a secure and highly available directory infrastructure, and supporting enterprise identity and access requirements.

Key Responsibilities

Provide L3/L4 technical support for Microsoft Active Directory and related services.

Manage and troubleshoot Active Directory Domain Services (AD DS), DNS, DHCP, Group Policy, Sites & Services, and replication.

Troubleshoot complex AD authentication, authorization, replication, and connectivity issues.

Perform AD domain controller installation, configuration, upgrades, migrations, and decommissioning.

Manage Active Directory forests, domains, trusts, OUs, users, groups, and computer objects.

Design, implement, and troubleshoot Group Policy Objects (GPOs).

Monitor and resolve AD replication and SYSVOL issues.

Support AD migrations, domain consolidations, forest-level changes, and hybrid identity environments.

Work with Microsoft Entra ID (Azure AD) and support hybrid identity/integration scenarios.

Implement and maintain AD security best practices, including privileged access, delegation, auditing, and access controls.

Troubleshoot Kerberos, NTLM, LDAP, SSO, and authentication-related issues.

Automate administrative and troubleshooting activities using PowerShell.

Participate in major incident management, problem management, RCA, and change management.

Create and maintain technical documentation, SOPs, architecture diagrams, and knowledge articles.

Collaborate with security, networking, cloud, server, and application teams.

Provide technical guidance to L1/L2 support teams and mentor junior administrators.

Required Skills

8+ years of experience in Microsoft Active Directory administration/support.

Strong expertise in AD DS, DNS, DHCP, GPO, LDAP, Kerberos, and AD replication.

Hands-on experience with Domain Controllers, Forests, Domains, Trusts, Sites & Services, and FSMO roles.

Strong troubleshooting experience in enterprise Windows Server environments.

Excellent knowledge of PowerShell scripting and automation.

Experience with Microsoft Entra ID / Azure AD and hybrid identity.

Knowledge of AD security, authentication, access management, and privileged accounts.

Experience with AD migration, consolidation, and disaster recovery.

Strong knowledge of Windows Server 2016/2019/2022.

Good understanding of networking concepts such as TCP/IP, DNS, DHCP, LDAP, and SSL/TLS.

Strong analytical, communication, and incident-management skills.

Preferred Skills

Microsoft Certified: Identity and Access Administrator Associate (SC-300) or equivalent.

Experience with ADFS, Microsoft Entra Connect, PKI/Certificate Services, and SSO.

Knowledge of Microsoft Defender, IAM/PAM solutions, and security hardening.

Experience working in large-scale enterprise or global environments.

Knowledge of monitoring and troubleshooting tools such as Event Viewer, Repadmin, Dcdiag, and Wireshark.

Education

Bachelor's degree in Computer Science, Information Technology, or a related field preferred.

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.