RESPONSIBILITIES
Microsoft 365 Tenant Administration and Licensing
Administer tenant configuration and monitor service health across the Microsoft 365 estate
Administer Exchange Online, Microsoft Teams and OneDrive at the service level, including policies, settings and troubleshooting
Manage licence assignment, entitlement management and cost tracking across the Microsoft 365 E5 estate and the Copilot add-on
Operate tenant change control and maintain documented configuration baselines for all administered services
Reconcile licence position and entitlement records on a defined cadence, with variances documented and resolved
Identity and Access Administration (Entra ID)
Administer users, groups and roles, including group strategy, naming standards and lifecycle management
Operate Conditional Access and multi-factor authentication policies, including testing, exclusions and change documentation
Maintain privileged access and role-assignment hygiene, including periodic review of administrative role assignments
Operate Privileged Identity Management so administrative role access is granted just in time and time-bound
Manage the Entra identity object lifecycle for guest and external identities, including invitation, review and removal
Coordinate with the SharePoint Administrator, who retains resource-level sharing and content recertification for collaboration sites
Automate joiner, mover and leaver processing driven from the HR system of record
Platform Enablement for Data & Innovation
Provision and maintain Microsoft Fabric and Power BI workspaces, capacities and data gateways
Manage service principals, managed identities and service accounts so pipelines are never tied to an individual's credentials
Administer secret and credential storage in an approved vault, with rotation and controlled access
Define and operate Power Platform environment strategy, data loss prevention policies and connector governance
Provision Azure resources, including storage, data services and networking, on which analytics and automation work depends
Support deployment pipelines and maintain separation of development, test and production environments
Tenant Governance and Analytics Guardrails
Administer Power BI and Microsoft Fabric tenant settings, including publish-to-web, external sharing, export and workspace-creation controls
Govern public publishing and external sharing of analytics content through approved tenant settings and a documented exception process
Monitor and report on tenant setting usage against a defined review cadence
Monitor capacity utilisation and manage platform cost across Fabric, Power BI and Azure resources
Information Protection, Security and Compliance Operations
Own and operate the configuration of Microsoft Purview sensitivity labels,
label policies, data loss prevention policies and retention policies
Implement policy requirements defined by the Manager, Security & Compliance, who evidences their operation to external parties
Operate third-party Microsoft 365 backup, covering schedule, immutability configuration, retention windows and restore testing
Support the implementation and maintenance of Microsoft security baselines across the tenant
Maintain audit log collection and retention across in-scope workloads to meet certification and investigative requirements
Produce control evidence for the ISO 27001 and SOC 2 initiatives and for external audit engagements
Own Copilot readiness on the platform side through identity, permission and label hygiene, with the AI-use policy held by the Manager, Security & Compliance
Automation, Documentation and Operational Support
Write and maintain PowerShell and Microsoft Graph scripts for bulk administration, reporting and repeatable provisioning
Maintain runbooks, configuration documentation and standard operating procedures for all administered services
Act as the L2 to L3 escalation point for identity, licensing, access and platform incidents raised through the IT helpdesk intake
Perform root-cause analysis and resolution, feeding fixes back into baselines, runbooks and automation
Manage vendor and Microsoft support cases through to closure, recording resolutions in service records
Provide platform support to both office-based and field-based staff for day-to-day operational needs
Report platform risks and governance exceptions through the IT Operations & Support Coordinator to the IT Steering Committee
WORKING CONDITIONS
The position will be based at our office in Mississauga, Ontario, with visits to the Airport site as required. Your work schedule will be Monday to Friday during regular office or site hours. At times, operational needs may require work outside these hours, with reasonable notice provided. All schedule or on‑call adjustments will comply with applicable employment standards legislation. It is mandatory for all employees to complete a Criminal Background check and successfully attain a Restricted Access Identity Card (RAIC) upon joining the company.
DESIRED SKILLS, KNOWLEDGE, COMPETENCIES
Three to five or more years administering Microsoft 365 and Azure in a production environment
Entra ID administration experience covering groups, roles,
Conditional Access and guest identity management
Three or more years of Power Platform, Microsoft Fabric or Power BI tenant administration experience
Two or more years of practical experience with service principals, managed identities and vault-based secret management
Two or more years of PowerShell and Microsoft Graph scripting for bulk administration, reporting and provisioning
Microsoft licensing administration experience, including assignment, entitlement management and periodic reconciliation of licence position
Working practice in change and incident management, with documentation discipline evidenced by durable runbooks and configuration records
Clear written and verbal communication with technical developers and with non-technical business stakeholders
Post-secondary education in information technology, computer science or a related discipline, or equivalent practical experience
Microsoft certification such as AZ-104, MS-102, SC-300 or PL-600 preferred or in progress
Two or more years of Microsoft Fabric capacity and gateway administration experience preferred
Microsoft Purview and information protection experience, or infrastructure-as-code, Azure DevOps or GitHub Actions exposure, considered an asset
Construction, engineering or major capital program delivery environment experience considered an asset
ISO 27001 or SOC 2 exposure, and experience supporting analytics or data-engineering teams, considered an asset
Key Deliverables
A documented tenant configuration baseline, maintained under change control and reviewed on a defined cadence
Fabric and Power BI tenant settings governed and monitored, with publish-to-web and external sharing controlled
A documented Power Platform workplace and data loss prevention model, with pipelines running on service principals rather than personal credentials
Privileged Identity Management in operation, with just-in-time elevation governing administrative role access
Third-party Microsoft 365 backup in operation, with restore testing performed and evidenced
A reconciled licence position across the E5 estate and Copilot add-on, with audit-ready identity and access evidence
A predictable platform provisioning turnaround for the Data & Innovation team, tracked against agreed service targets
PACT is an equal prospect employer and is committed to providing employment accommodation in accordance with the Ontario Human Rights Code and the Accessibility for Ontarians with Disabilities Act. We are committed to providing an inclusive and barrier free candidate experience and work environment. If you require accommodation to apply or if selected to participate in an assessment process, please advise Human Resources.
#J-18808-Ljbffr
📌 Azure 365 Administrator (Ontario)
🏢 PACT
📍 Ontario