TRCD-26-05259
Active Directory / Entra ID Migration Engineer (AD DS, Quest ODM)
Contract role in Kolkata for a 4–7 years engineer focused on Active Directory domain consolidation and migrations. The engineer will handle AD DS design/troubleshooting (trusts, sites/services, replication, FSMO, GPO), user/group/device/endpoint migrations using Quest ODM (or similar), and hybrid identity work with Entra Connect Sync/Cloud Sync (staging mode, ImmutableID/source anchor, MTO). Strong security and authentication knowledge (Kerberos/NTLM, SPNs, constrained delegation/RBCD), AD-integrated DNS/DHCP integration, privileged access patterns (tiering/PAWs/EAM, LAPS, gMSA), plus strong PowerShell, documentation, testing, rollback and hypercare are required.
Position summary
- Location
- India
- Workplace
- Hybrid
- Employment
- Contract
- Experience
- Minimum 4 years and Maximum 7 years
Role overview
Why This Role Matters.
Contract role in Kolkata for a 4–7 years engineer focused on Active Directory domain consolidation and migrations. The engineer will handle AD DS design/troubleshooting (trusts, sites/services, replication, FSMO, GPO), user/group/device/endpoint migrations using Quest ODM (or similar), and hybrid identity work with Entra Connect Sync/Cloud Sync (staging mode, ImmutableID/source anchor, MTO). Strong security and authentication knowledge (Kerberos/NTLM, SPNs, constrained delegation/RBCD), AD-integrated DNS/DHCP integration, privileged access patterns (tiering/PAWs/EAM, LAPS, gMSA), plus strong PowerShell, documentation, testing, rollback and hypercare are required.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
User, group, device, and endpoint migration using Quest ODM or comparable tools.
Experience with SIDHistory, ReACLing, profile migration, and cutover.
Entra Connect Sync, Cloud Sync, staging mode, ImmutableID, source anchors, and MTO.
Kerberos, NTLM, SPNs, constrained delegation, and resource-based constrained delegation.
AD-integrated DNS, conditional forwarders, split-brain namespaces, and DHCP integration.
Privileged administration using Enterprise Access Model, PAWs, tiering, LAPS, and gMSAs.
Strong PowerShell, troubleshooting, documentation, testing, rollback, and hypercare experience.
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
Active Directory
AD DS
Forest
Domain
Trusts
Sites and Services
Replication
FSMO
GPO
Domain consolidation
Quest ODM
Quest On Demand Migration
SIDHistory
ReACL
Profile migration
Cutover
Microsoft Entra
Azure AD
Entra Connect
Azure AD Connect
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
Active Directory Domain Services (AD DS) administration and troubleshooting
AD trusts, Sites and Services, replication topology, and FSMO roles
Group Policy Objects (GPO) design/troubleshooting
Domain consolidation and migration planning/execution
User/group/device/endpoint migration using Quest ODM (or comparable migration tooling)
SIDHistory concepts and usage during migrations
ReACLing (re-permissioning) and access remediation during migrations
Profile migration and cutover execution
Microsoft Entra Connect Sync and/or Entra Cloud Sync
Staging mode, ImmutableID, source anchor concepts, and MTO (as referenced in TR)
Kerberos and NTLM authentication fundamentals
SPNs management and troubleshooting
Constrained delegation and resource-based constrained delegation (RBCD)
AD-integrated DNS (conditional forwarders, split-brain namespaces)
DHCP integration with AD/DNS
Privileged administration patterns: Enterprise Access Model (tiering), PAWs
LAPS and gMSA usage
PowerShell scripting/automation for AD and migration tasks
Troubleshooting, documentation, testing, rollback planning, and hypercare support
Preferred
Nice to Have
Experience with other AD migration suites (e.g., ADMT) in addition to Quest ODM
Experience with endpoint migration tooling beyond ODM (if applicable)
Advanced DNS design for complex multi-forest environments
Automation frameworks around PowerShell (e.g., DSC)
Experience operating in regulated environments with strict privileged access controls
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Active Directory / Entra ID Migration Engineer (AD DS, Quest ODM)
One page, about two minutes. We only ask for what we actually need to have a first conversation.