Active Directory Architecture & Design
Indexed description
Active Directory Architecture & Design
- Design and manage enterprise AD forests, domains, trusts, OU structures, site topology, Tiering Model in AD and Disaster Recovery Plan
- Define and enforce AD naming conventions, delegation models, and role separation aligned with Tiering Model
- Architect high availability and disaster recovery for domain controllers and critical AD services
- Design Group Policy (GPO) strategy aligned to security and operational best practices
- Lead domain controller lifecycle management, patching, and capacity planning
- Oversee DNS, SYSVOL, replication health, and AD performance tuning
- Troubleshoot complex AD issues across multi-domain and multi-forest environments
- Establish monitoring, alerting, and operational runbooks
- Identify and remediate:
- Stale / inactive users and computer objects
- Orphaned and over-privileged accounts
- Legacy and unmanaged service accounts
- Stale / inactive users and computer objects
- Define and enforce account lifecycle and access review processes
- Support service account migration, standardization, and credential hygiene
- Perform AD security posture assessments and remediation planning
- Implement tiered administration, least privilege, and role-based access controls
- Harden AD against common attack vectors (Kerberos abuse, credential theft, lateral movement)
- Support privileged access design and secure admin workstation models
- Define AD governance framework, policies, and technical standards
- Review and approve changes impacting AD architecture and security
- Ensure compliance with internal controls, audits, and regulatory requirements
- Maintain architecture diagrams, design documents, and SOPs
- Support domain consolidation, forest restructuring, and trust rationalization
- Provide technical design inputs for hybrid identity and directory modernization
- Assess AD readiness for integration with cloud identity platforms
- Validate designs and deliverables from system integrators or partner teams
- Act as L4 escalation point for AD-related issues and Mentor AD engineers and operations teams
- Collaborate with security, infrastructure, and application teams
- Present technical findings and recommendations to senior stakeholders
Required Skills & Experience
- 8-12+ years of experience managing large-scale on-prem Active Directory
- Deep expertise in:
- AD DS, DNS, Group Policy, Sites & Services, Replication
- Multi-domain and multi-forest environments
- AD DS, DNS, Group Policy, Sites & Services, Replication
- Strong PowerShell scripting for automation and reporting
- Solid understanding of AD security architecture and threat models
- Proven experience delivering assessments, remediation plans, and architectural designs
About Infosys
Infosys is a global leader in next-generation digital services and consulting. We enable clients in 59 countries to navigate their digital transformation.
With over four decades of experience in managing the systems and workings of global enterprises, we expertly steer clients, in 59 countries, as they navigate their digital transformation powered by cloud and AI. We enable them with an AI-first core, empower the business with agile digital at scale and drive continuous improvement with always-on learning through the transfer of digital skills, expertise, and ideas from our innovation ecosystem. We are deeply committed to being a well-governed, environmentally sustainable organization where diverse talent thrives in an inclusive workplace.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search