The Azure 365 Administrator is responsible for the operational administration of the Azure and Microsoft 365 platform at PACT (Pearson Accelerator Construction Team), a General Partnership of Alberici, Amico, Kenaidan and Obayashi. The primary mission of the role is to enable and assist the development work of the Data & Innovation team by provisioning, securing and maintaining the platform layer on which the program's business intelligence and automation developers build, while carrying tenant administration for IT Operations & Support. The role reports to the IT Operations & Support Coordinator, who owns objectives, priorities, performance management and standards, and holds a dotted-line working relationship with the Manager, Data & Innovation, who sets the practical demand and sequencing for platform enablement work; where the two are in tension, the IT Operations & Support Coordinator arbitrates competing priorities. The role ensures the platform is administered with discipline, repeatability and documented controls.
RESPONSIBILITIES
Microsoft 365 Tenant Administration and Licensing
- Administer tenant configuration and monitor service health across the Microsoft 365 estate
- Administer Exchange Online, Microsoft Teams and OneDrive at the service level, including policies, settings and troubleshooting
- Manage licence assignment, entitlement management and cost tracking across the Microsoft 365 E5 estate and the Copilot add-on
- Operate tenant change control and maintain documented configuration baselines for all administered services
- Reconcile licence position and entitlement records on a defined cadence, with variances documented and resolved
Identity and Access Administration (Entra ID)
- Administer users, groups and roles, including group strategy, naming standards and lifecycle management
- Operate Conditional Access and multi-factor authentication policies, including testing, exclusions and change documentation
- Maintain privileged access and role-assignment hygiene, including periodic review of administrative role assignments
- Operate Privileged Identity Management so administrative role access is granted just in time and time-bound
- Manage the Entra identity object lifecycle for guest and external identities, including invitation, review and removal
- Coordinate with the SharePoint Administrator, who retains resource-level sharing and content recertification for collaboration sites
- Automate joiner, mover and leaver processing driven from the HR system of record
Platform Enablement for Data & Innovation
- Provision and maintain Microsoft Fabric and Power BI workspaces, capacities and data gateways
- Manage service principals, managed identities and service accounts so pipelines are never tied to an individual's credentials
- Administer secret and credential storage in an approved vault, with rotation and controlled access
- Define and operate Power Platform environment strategy, data loss prevention policies and connector governance
- Provision Azure resources, including storage, data services and networking, on which analytics and automation work depends
- Support deployment pipelines and maintain separation of development, test and production environments
Tenant Governance and Analytics Guardrails
- Administer Power BI and Microsoft Fabric tenant settings, including publish-to-web, external sharing, export and workspace-creation controls
- Govern public publishing and external sharing of analytics content through approved tenant settings and a documented exception process
- Monitor and report on tenant setting usage against a defined review cadence
- Monitor capacity utilisation and manage platform cost across Fabric, Power BI and Azure resources
Information Protection, Security and Compliance Operations
- Own and operate the configuration of Microsoft Purview sensitivity labels, label policies, data loss prevention policies and retention policies
- Implement policy requirements defined by the Manager, Security & Compliance, who evidences their operation to external parties
- Operate third-party Microsoft 365 backup, covering schedule, immutability configuration, retention windows and restore testing
- Support the implementation and maintenance of Microsoft security baselines across the tenant
- Maintain audit log collection and retention across in-scope workloads to meet certification and investigative requirements
- Produce control evidence for the ISO 27001 and SOC 2 initiatives and for external audit engagements
- Own Copilot readiness on the platform side through identity, permission and label hygiene, with the AI-use policy held by the Manager, Security & Compliance
Automation, Documentation and Operational Support
- Write and maintain PowerShell and Microsoft Graph scripts for bulk administration, reporting and repeatable provisioning
- Maintain runbooks, configuration documentation and standard operating procedures for all administered services
- Act as the L2 to L3 escalation point for identity, licensing, access and platform incidents raised through the IT helpdesk intake
- Perform root-cause analysis and resolution, feeding fixes back into baselines, runbooks and automation
- Manage vendor and Microsoft support cases through to closure, recording resolutions in service records
- Provide platform support to both office-based and field-based staff for day-to-day operational needs
- Report platform risks and governance exceptions through the IT Operations & Support Coordinator to the IT Steering Committee
WORKING CONDITIONS
The position will be based at our office in Mississauga, Ontario, with visits to the Airport site as required. Your work schedule will be Monday to Friday during regular office or site hours. At times, operational needs may require work outside these hours, with reasonable notice provided. All schedule or on‑call adjustments will comply with applicable employment standards legislation.
It is mandatory for all employees to complete a Criminal Background check and successfully attain a Restricted Access Identity Card (RAIC) upon joining the company.
DESIRED SKILLS, KNOWLEDGE, COMPETENCIES
- Three to five or more years administering Microsoft 365 and Azure in a production environment
- Entra ID administration experience covering groups, roles, Conditional Access and guest identity management
- Three or more years of Power Platform, Microsoft Fabric or Power BI tenant administration experience
- Two or more years of practical experience with service principals, managed identities and vault-based secret management
- Two or more years of PowerShell and Microsoft Graph scripting for bulk administration, reporting and provisioning
- Microsoft licensing administration experience, including assignment, entitlement management and periodic reconciliation of licence position
- Working practice in change and incident management, with documentation discipline evidenced by durable runbooks and configuration records
- Clear written and verbal communication with technical developers and with non-technical business stakeholders
- Post-secondary education in information technology, computer science or a related discipline, or equivalent practical experience
- Microsoft certification such as AZ-104, MS-102, SC-300 or PL-600 preferred or in progress
- Two or more years of Microsoft Fabric capacity and gateway administration experience preferred
- Microsoft Purview and information protection experience, or infrastructure-as-code, Azure DevOps or GitHub Actions exposure, considered an asset
- Construction, engineering or major capital program delivery environment experience considered an asset
- ISO 27001 or SOC 2 exposure, and experience supporting analytics or data-engineering teams, considered an asset
Key Deliverables
- A documented tenant configuration baseline, maintained under change control and reviewed on a defined cadence
- Fabric and Power BI tenant settings governed and monitored, with publish-to-web and external sharing controlled
- A documented Power Platform environment and data loss prevention model, with pipelines running on service principals rather than personal credentials
- Privileged Identity Management in operation, with just-in-time elevation governing administrative role access
- Third-party Microsoft 365 backup in operation, with restore testing performed and evidenced
- A reconciled licence position across the E5 estate and Copilot add-on, with audit-ready identity and access evidence
- A predictable platform provisioning turnaround for the Data & Innovation team, tracked against agreed service targets
PACT is an equal chance employer and is committed to providing employment accommodation in accordance with the Ontario Human Rights Code and the Accessibility for Ontarians with Disabilities Act. We are committed to providing an inclusive and barrier free candidate experience and work environment. If you require accommodation to apply or if selected to participate in an assessment process, please advise Human Resources.
📌 Azure 365 Administrator (Canada)
🏢 PACT
📍 Canada