AD, Azure AD and PKI Architect
Workday
- Location
- IND.Pune
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 103 approvals (FY2023)
- Posted
- Aug 17, 2026
Skills
About this role
Your work days are brighter here. We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.
About the Team
The Identity and Access management team manages the identity suite including Okta, Delinea, AD, Entra ID and KeyFactor. Team manages employees, customers and partners identity in IAM system.
About the Role
We are seeking a skilled Active Directory (AD), Microsoft Entra ID (formerly Azure Active Directory), and Public Key Infrastructure (PKI) Architect to design, implement, operate, secure, and continuously improve our enterprise identity and certificate services. This role will own engineering activities across on-premises and cloud identity platforms, with a strong focus on availability, security, automation, governance, and a seamless user experience. The ideal candidate brings deep hands-on expertise in Windows Active Directory, Entra ID, hybrid identity, authentication and authorization protocols, certificate lifecycle management, and identity-related incident resolution. They will partner with infrastructure, security, application, endpoint, and service-management teams to deliver resilient, scalable identity services.
Key Responsibilities
Active Directory and Hybrid Identity Engineering Design, deploy, configure, and maintain enterprise Active Directory Domain Services, including forests, domains, sites, organizational units, trusts, DNS integration, Group Policy, replication, and domain controller lifecycle management. Engineer and support hybrid identity integration between on-premises AD and Microsoft Entra ID, including Microsoft Entra Connect Sync or Cloud Sync, password hash synchronization, pass-through authentication, federation where applicable, and seamless single sign-on. Develop and maintain logical AD designs, delegation models, administrative tiering, privileged access controls, naming standards, and lifecycle processes. Monitor and troubleshoot AD replication, DNS, authentication, domain controller health, Group Policy processing, directory synchronization, and identity-related service degradation. Plan and execute upgrades, migrations, consolidations, domain controller replacements, disaster-recovery testing, and capacity improvements with minimal business disruption. Implement secure configuration baselines and hardening controls aligned to organizational standards and recognized security practices. Microsoft Entra ID / Azure AD Engineering Administer and engineer Microsoft Entra ID capabilities, including users, groups, administrative roles, enterprise applications, app registrations, service principals, managed identities, and directory settings. Design and operate identity access patterns for cloud and hybrid applications using SSO, SAML, OAuth 2.0, OpenID Connect, SCIM provisioning, and modern authentication. Implement and maintain Conditional Access policies, multifactor authentication, passwordless authentication,