ERNST YOUNG LLP
Senior Entra ID & MFA Consultant at ERNST YOUNG LLP in Hyderabad
ExperiencedOn-siteHyderabad
Job Description
Job Title
Conditional Access and MFA Management - Senior
Role Summary Execute end-to-end operations for Conditional Access (CA) and Multi-Factor Authentication (MFA), including policy configuration, enforcement monitoring, exception handling, and incident/request management across onboarding and steady-state managed services phases.
Technical Requirements - Must Have - Hands-on expertise in Microsoft Entra ID (Azure AD) with strong focus on Conditional Access policies and MFA controls.
- Experience configuring and managing Conditional Access (CAP) including monitoring enforcement, handling false positives, and tuning policies.
- Strong experience in MFA operations (user onboarding, authentication troubleshooting, lockouts, exception/bypass handling).
- Solid understanding of authentication protocols (SSO, federation), identity risk signals, and device compliance signals.
- Experience handling high-volume L2/L3 IAM tickets (incident, request, change) in a structured ITSM environment.
- Ability to implement and manage time-bound exceptions with audit traceability.
- Experience with policy validation, enforcement monitoring, and post-change verification.
- Experience integrating Conditional Access with device compliance tools (e.g., Intune) and identity risk-based policies.
- Working knowledge of identity security monitoring and SIEM integrations (alerts, sign-in logs, anomaly detection).
- Familiarity with PowerShell scripting for automation of user/admin tasks in Entra ID.
- Experience supporting SSO/federation configurations (SAML, OAuth, OIDC) across enterprise applications.
- Exposure to user awareness, onboarding, and MFA adoption campaigns in enterprise environments.
- Understanding of audit support processes (log extraction, evidence preparation, exception validation).
- Experience in policy tuning and continuous improvement to optimize enforcement and minimize false positives.
- Ability to independently manage high-volume IAM operations with minimal supervision in a structured ITSM model.
- Strong analytical mindset to troubleshoot authentication issues, access failures, and policy enforcement gaps.
- High attention to detail for policy execution, exception handling, and audit traceability requirements.
- Comfortable working within strict client-approved change and approval processes (no independent policy decisions).
- Ability to multi-task across incidents, service requests, and change activities while maintaining SLA adherence.
- Proactive in identifying false positives, enforcement issues, and optimization opportunities.
- Good communication skills to coordinate with service desk, infra teams, and client stakeholders.
- Strong discipline in runbook-driven execution and documentation updates.