Microsoft Intune Policy Audit & Remediation Consultant
DLK Group, City of Cape Town, Western Cape, South Africa
Location : Cape Town
Engagement Type : Contract
Role Purpose : The Consultant will lead a comprehensive audit, analysis, and remediation of Microsoft Intune policies within a complex enterprise environment. This role ensures optimal configuration, improved compliance, and alignment with Microsoft best practices. The ideal candidate is certified (MD-102 or SC-300) and capable of delivering high-impact policy remediation and documentation to enhance the security posture and operational effectiveness of the Intune environment.
Key Responsibilities :
- Perform a full discovery of the current Microsoft Intune (Endpoint Manager) environment : device enrollment, compliance, application deployments, and Conditional Access.
- Assess the effectiveness and alignment of security policies including BitLocker, Microsoft Defender ATP, MDM / MAM, and update ring configurations.
- Review and assess RBAC roles, alerting mechanisms, reporting, and monitoring.
- Identify misconfigurations, redundancies, and risks due to policy conflicts or outdated practices.
- Compile a detailed audit report with risk analysis, policy gaps, and prioritized remediation recommendations.
- Develop and implement a remediation and optimization plan based on audit findings.
- Streamline and standardize policies, enforce naming conventions, and optimize policy layering logic.
- Enhance Conditional Access and RBAC roles to reflect Zero Trust principles.
- Establish or refine monitoring dashboards, reporting metrics, and automated alerts.
- Deliver knowledge transfer sessions, stakeholder briefings, and handover documentation.
Required Skills & Experience :
Certifications : Microsoft Certified : Security Administrator Associate (SC-300) or equivalent.Extensive experience with Microsoft Intune (Endpoint Manager) and Azure AD.Proficiency in MDM, MAM, device compliance, and configuration profiles.Deep understanding of Conditional Access, RBAC, and Zero Trust architecture.Familiarity with Microsoft Defender, BitLocker, update rings, and endpoint security baselines.PowerShell scripting for reporting and policy automation is advantageous.Audit & Governance Skills :
Proven experience in conducting security / configuration audits in enterprise environments.Understanding of NIST, CIS, or Microsoft security baselines.Ability to link technical issues to business risk and recommend prioritized remediation actions.Strong interpersonal, verbal, and written communication skills.Ability to communicate technical concepts to non-technical stakeholders.Capable of producing clear documentation and delivering structured stakeholder presentations.Ability to work independently and deliver within strict deadlines.Engagement Requirements :
Provide own laptop / tools with secure connectivity.Support approximately 100 hours over two project phases.Support remote and in-person sessions as required.Adhere to all confidentiality, data protection, and security policies.#J-18808-Ljbffr