Posted on: 16/09/2026
About Sonata Software :
Sonata Software, with over $1.2 Billion in revenue, is a leading AI-first Modernization Engineering company, powered by its unique Platformation framework. With 6,400+ AI Engineers, Sonata helps enterprises transform legacy systems into intelligent business platforms that drive speed, efficiency, innovation, and growth. Sonata provides Modernization Engineering Services across Cloud, Data, AI, Dynamics, Test Automation, and Managed Services. Its AI-led modernization capabilities are supported by proprietary platforms and tools, including the Harmoni.AI Enterprise Platform, AgentBridge, Agent Builder, and Agent Marketplace.
Headquartered in Bengaluru, Sonata has a strong global presence across the US, UK, India, Malaysia, Mexico, Australia, DACH, and Nordics. The company works with Fortune 500 organizations across Banking, Financial Services & Insurance, Healthcare & Lifesciences, Telecom, Media & Technology, Retail, Manufacturing, and Distribution. Sonata has longstanding strategic partnerships with Microsoft, AWS, Salesforce, and Snowflake, including more than 30 years of partnership with Microsoft.
Role Overview :
Sonata Software is looking for an experienced Entra ID Customer Engineer with strong expertise in Microsoft Entra ID, Identity and Access Management, Azure security, authentication, governance, and enterprise identity architecture. As a Customer Engineer, you will work directly with enterprise customers and their technical teams to provide expert technical advisory, architecture guidance, troubleshooting, security recommendations, and implementation support.
The role involves establishing trusted-advisor relationships with customers and helping them assess, improve, secure, and modernize their identity environments. You will leverage structured Microsoft Intellectual Property (MIP) engagements, technical assessments, best practices, and Microsoft security capabilities to help customers achieve a healthy, secure, compliant, and well-governed identity environment.
The ideal candidate should be comfortable operating at a 300400 level of technical depth, communicating with senior technical stakeholders, and translating complex identity and security challenges into practical solutions.
Key Responsibilities :
Customer Advisory & Technical Consulting :
- Act as a trusted technical advisor for enterprise customers on Microsoft Entra ID and identity security.
- Understand customer identity architectures, business requirements, security objectives, and operational challenges.
- Conduct technical discovery sessions, architecture reviews, health assessments, and security assessments.
- Recommend improvements aligned with Microsoft security and identity best practices.
- Help customers establish secure and scalable identity architectures.
- Guide customers through identity modernization and migration initiatives.
- Provide technical workshops, demonstrations, knowledge-transfer sessions, and enablement programs.
- Work closely with customer architects, security teams, infrastructure teams, application owners, and administrators.
Microsoft Entra ID :
- Design, configure, administer, and troubleshoot Microsoft Entra ID environments.
- Provide expertise around Entra ID Role-Based Access Control (RBAC).
- Manage and troubleshoot : User accounts Service principals Managed identities Security groups Microsoft 365 groups Enterprise applications Application registrations.
- Review and optimize identity permissions and access models.
- Identify excessive privileges and recommend appropriate access controls.
- Support enterprise application onboarding and integration with Entra ID.
Authentication & Identity Federation :
- Provide deep technical guidance on enterprise authentication models.
- Work with : Password Hash Synchronization (PHS) Pass-through Authentication (PTA) Federation Single Sign-On (SSO) OAuth 2.0 SAML OpenID Connect (OIDC) Kerberos FIDO2 Passkeys.
- Troubleshoot authentication and federation issues.
- Analyze authentication failures, token-related issues, sign-in errors, and application authentication problems.
- Assist customers in transitioning from legacy authentication mechanisms to modern authentication.
Identity Synchronization :
- Design, implement, monitor, and troubleshoot Microsoft Entra Connect environments.
- Work with Microsoft Entra Cloud Sync.
- Troubleshoot synchronization issues involving : Users Groups Attributes Password hashes Devices Organizational units.
- Analyze synchronization errors and recommend remediation.
- Support hybrid identity architecture and Active Directory integration.
Device Identity & Management :
- Provide technical guidance on device identity and registration.
- Work with: Microsoft Entra Hybrid Join Microsoft Entra Joined devices Azure AD Joined environments Device registration.
- Troubleshoot device authentication and registration issues.
- Support secure identity integration between on-premises Active Directory and cloud environments.
Entra ID Security & Governance :
- Design and troubleshoot Microsoft Entra Conditional Access policies.
- Implement security controls around : MFA Device compliance User risk Sign-in risk Location Application access Authentication strength.
- Review existing Conditional Access policies and identify gaps or conflicts.
- Assist customers with Zero Trust-oriented identity controls.
Identity Protection :
- Configure and troubleshoot Microsoft Entra ID Protection.
- Analyze risky users and risky sign-ins.
- Assist with risk-based Conditional Access policies.
- Investigate suspicious authentication activity.
- Recommend controls to reduce identity-based security risks.
Privileged Identity Management :
- Implement and manage Microsoft Entra Privileged Identity Management (PIM).
- Configure just-in-time privileged access.
- Establish appropriate privileged-role governance.
- Configure approval workflows and access controls.
- Conduct periodic privileged access reviews.
- Support least-privilege security models.
Identity Governance :
- Configure and manage : Access Reviews Entitlement Management Periodic reviews Self-service access Privileged access Compliance controls.
- Help organizations establish identity governance frameworks.
- Support compliance audits and identity-related security assessments.
- Identify dormant, excessive, or inappropriate access.
Self-Service Password Reset :
- Configure and troubleshoot Self-Service Password Reset (SSSP).
- Implement appropriate authentication methods.
- Configure password protection policies.
- Support password policy modernization.
- Troubleshoot user registration and password reset issues.
Active Directory Integration :
- Strong understanding of on-premises Microsoft Active Directory.
- Design and troubleshoot integration between Active Directory and Entra ID.
- Work with: Domains Forests Trusts Organizational Units Group Policy Domain Controllers Service Accounts.
- Troubleshoot hybrid identity issues.
- Support migration from traditional Active Directory-based identity models toward cloud identity.
Microsoft Graph API :
- Demonstrate foundational knowledge of Microsoft Graph API.
- Work with Graph API for identity and access management use cases.
- Understand API-based management of: Users Groups Applications Service principals Directory objects.
- Assist with automation and integration of identity-management processes.
Monitoring & Troubleshooting :
- Analyze identity and authentication logs to identify root causes.
- Troubleshoot complex customer environments and production issues.
- Use relevant Microsoft monitoring and security tools.
- Analyze: Sign-in logs Audit logs Provisioning logs Authentication failures Conditional Access results Identity Protection alerts.
- Provide root-cause analysis and remediation recommendations.
- Document technical findings and recommended corrective actions.
Customer Engagement :
- Conduct technical discussions with enterprise IT and security teams.
- Present architecture recommendations to technical and business stakeholders.
- Lead customer workshops and technical deep dives.
- Explain complex identity concepts in a clear and business-oriented manner.
- Create technical documentation, assessment reports, architecture diagrams, and remediation plans.
- Track customer engagement activities and follow through on agreed technical actions.
- Collaborate with Microsoft, partners, and internal Sonata engineering teams when required.
Optional / Good-to-Have Skills :
- Microsoft Active Directory Federation Services (ADFS) Active Directory Certificate Services (AD CS)
- Azure Monitor Microsoft Sentinel Microsoft Defender for Endpoint Microsoft Intune
- Azure security services
- Zero Trust architecture
- Microsoft 365 security
- PowerShell Identity migration projects
- Enterprise security architecture
Preferred Certifications :
Candidates with one or more of the following certifications will be preferred :
- Microsoft Certified : Identity and Access Administrator Associate
- Microsoft Certified : Cybersecurity Architect Expert
- Microsoft Certified Trainer (MCT) CISSP Certified Information Systems Security Professional Equivalent Microsoft, Azure, or identity/security certifications
Experience & Qualifications :
- 8 - 20 years of overall experience in IT, Cloud, Identity, Infrastructure, Cybersecurity, or related technologies.
- Strong hands-on experience with Microsoft Entra ID and enterprise identity environments.
- Experience working with large enterprise customers is highly desirable.
- Experience in customer-facing consulting, technical advisory, solution architecture, or customer engineering roles. Strong troubleshooting and analytical skills.
- Experience handling complex identity and authentication environments.
- Ability to work independently on technically complex engagements.
- Strong documentation and presentation skills.
- Excellent verbal and written communication skills.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1671773