jobs in T7 Intelligent Resources

T7 Intelligent Resources Hiring! Full Time Entra Hybrid Authentication, NPS, VPN - VDI Engineer in Federal Territory - Ricebowl

Entra Hybrid Authentication, NPS, VPN - VDI Engineer

KL City, Federal Territory

Share
Save

Working Location

  • Kuala Lumpur Federal Territory Malaysia

Job Description

Responsibilities

Entra Hybrid Authentication, NPS, VPN & VDI Engineer



MAIN FUNCTIONS:


  • Design, configure, test and migrate the Bank's VPN and VDI authentication services from Falaina-based RADIUS/MFA to the approved Microsoft Entra MFA architecture using Windows Network Policy Server (NPS) and Microsoft Entra MFA NPS Extension. The role shall provide hands-on remote-access authentication expertise, support user MFA migration and relevant application/RADIUS dependencies, and support hybrid authentication prerequisites for Windows Hello for Business.



RESPONSIBILITIES:


  • Assess the current VPN, VDI, RADIUS, Falaina MFA, Active Directory and network authentication architecture and document authentication flows, dependencies and failure points.
  • Prepare the detailed target VPN/VDI authentication design covering Windows NPS, RADIUS, Microsoft Entra MFA NPS Extension, AD, connectivity/firewall requirements and high availability.
  • Install, configure and harden Windows NPS instances and configure RADIUS clients, policies, authentication settings, logging and required certificates/secrets.
  • Install, register and configure Microsoft Entra MFA NPS Extension and validate communication and authentication dependencies with Entra ID.
  • Design and configure NPS/RADIUS high availability, resilience and failure handling and document expected behaviour for component, network and cloud-service failures.
  • Work with network and remote-access SMEs to integrate the target NPS/RADIUS service with VPN and VDI platforms, including Cisco ASA/AnyConnect/Secure Client where applicable.
  • Identify applications or services among the existing Falaina integrations and wider application estate that rely on RADIUS or related network authentication and support their migration to the approved target authentication architecture where applicable.
  • Support Entra MFA user migration/re-registration activities for VPN/VDI users, including pilot validation, authentication method readiness, exception handling and troubleshooting.
  • Prepare detailed configuration documentation, implementation procedures, test cases, cutover checklists and rollback procedures for VPN/VDI authentication migration.
  • Conduct technical testing covering successful and failed authentication, MFA challenge, policy enforcement, redundancy/failover, timeout, network failure and relevant negative scenarios.
  • Support UAT and execute/assist production migration of VPN and VDI authentication from Falaina to the target Entra MFA architecture.
  • Troubleshoot NPS, RADIUS, MFA, AD, VPN and VDI authentication issues using NPS/Event Viewer, Entra signin logs, network traces and relevant platform logs.
  • Support final Falaina cutover by validating that VPN/VDI and applicable RADIUS authentication dependencies no longer rely on Falaina.
  • Support Windows Hello for Business (WHfB) infrastructure prerequisites involving AD, Kerberos, domain controllers, device connectivity, DNS and related hybrid authentication dependencies where required.
  • Provide hypercare, as-built/operational documentation and knowledge transfer to BNM infrastructure, network, IAM and support teams.



REQUIREMENTS:


  • Degree or diploma in Computer Science, Information Technology, Networking, Cybersecurity or equivalent.
  • Minimum 5 years of relevant infrastructure/security engineering experience with strong hands-on Windows Server, NPS/RADIUS and enterprise remote-access authentication experience.
  • Mandatory demonstrable production implementation experience with Microsoft Entra MFA NPS Extension for enterprise VPN and/or VDI authentication.
  • Experience supporting enterprise MFA migration/registration and Active Directory/Kerberos hybrid authentication is required.
  • WHfB exposure and experience with Cisco ASA/AnyConnect/Secure Client are strongly preferred.
  • SC-300 Identity Access Admin Associate and relevant Microsoft Windows Server, Azure or Cisco certifications are preferred.


Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More