Microsoft Cloud Architect
Worldwide
We're a Microsoft-focused managed and co-managed IT services partner serving growing mid-sized businesses (10–200 employees) across pharma and life sciences, manufacturing, nonprofits, food and beverage, architecture and engineering, professional services, commercial real estate, and healthcare. Our clients don't want five vendors pointing at each other — they want one accountable team covering strategy, operations, security, and compliance. We're looking for a Microsoft Cloud Architect to own the technical design behind that promise: the identity model, the endpoint baseline, the security posture, the migration plan, and the documentation that makes all of it repeatable. This is hands-on architecture, not slideware. You will design environments, then stand them up. What you'll own Identity as the foundation Entra ID as the central identity provider: user and group structure, role assignment, directory hygiene, application integration Conditional Access and MFA scoped to a client's actual risk posture and user populations — not a copy-pasted policy set SSPR, Privileged Identity Management with just-in-time elevation, and a real access review cadence for privileged roles Hybrid and federated designs where a non-Microsoft cloud directory or on-prem AD has to stay in the picture for a while License tier calls and their consequences: Business Premium vs. E3 or E5, where Entra ID P1 stops and P2 becomes necessary, what a client actually needs versus what they're paying for Endpoint and MDM Intune across mixed Windows and Apple fleets: enrollment, compliance policies, configuration profiles, app deployment, ongoing policy maintenance Windows Autopilot for zero-touch provisioning; Apple Business Manager including automatic enrollment through the client's reseller channel Hardening baselines covering security configuration, disk encryption, and update enforcement — plus the stricter baselines that NIST, CMMC, or HIPAA scopes demand Live asset inventory from the MDM agent, and a patch cadence for OS, Office, and the supported third-party catalog Security Defender for Endpoint and Defender for Business: deployment, detection and response policy, attack surface reduction rules Email security and anti-spoofing: spam and phishing filtering, sender authentication records, content policies Purview sensitivity labels and DLP across Exchange, SharePoint, OneDrive, and the collaboration workloads Audit logging and retention configured against compliance and legal hold requirements Working alongside our security operations partner — you set the architecture they monitor Email, tenant, and data migrations Tenant provisioning, defederation, and spin-outs from reseller platforms while preserving accounts, aliases, distribution groups, and domain configuration Mailbox migration into Exchange Online with wave-based cutover and reconciliation reporting at the close of each wave Mapping source-platform groups to the right Microsoft construct — distribution group, shared mailbox, or M365 group — and rebuilding forwarding and permissions so nothing breaks Monday morning SMTP relay and line-of-business app reconfiguration, documented and tested before the source platform is decommissioned DNS cutover runbooks covering mail routing, sender authentication, and autodiscover, with rollback procedures SharePoint information architecture, file share and cloud storage migration, and the permission restructuring that moves a client off individual file ownership onto group-based inheritance Hypercare through post-cutover stabilization Azure infrastructure IaaS reference architectures: VMs, managed disks, virtual networking, identity, security, backup Assessing when lift-and-shift is the honest answer and when a PaaS rearchitecture (Azure SQL Managed Instance, App Service) is worth the scope Resilience design, backup and recovery, and consumption modeling with reserved instances — Azure is billed by Microsoft directly, so cost estimates have to hold up Client-facing work and repeatability Discovery and environment audits producing license right-sizing recommendations and a prioritized gap list Solution design documents, baseline environment documentation, and roadmaps that feed the vCIO cadence Scoping and estimating with the sales team, and defending that scope in proposal review Recurring strategic reviews with client leadership on environment health, roadmap progress, and budget Runbooks, configuration baselines, and per-client onboarding and offboarding playbooks other engineers can execute without you Clean time entry, ticket notes, and task updates in our PSA. Documentation quality is part of the job, not overhead attached to it. What we're looking for Deep, current, production experience across Entra ID, Intune, Exchange Online, Defender, and Azure IaaS — in multi-tenant or managed services contexts, or supporting several distinct business units Real migration scars: you've cut mail routing over late on a Friday and know what breaks Working knowledge of at least one compliance framework in practice — FDA, CMMC, HIPAA, SOC 2 or similar Fluent written and spoken English, and the judgment to explain a tradeoff to a non-technical owner without condescending Someone who takes ownership, communicates proactively, and cares about the client outcome as much as the technical solution How we work We're a small, distributed team, built around people with real-world experience running IT inside companies like the ones we serve. Everything lives in client-owned Microsoft tenants rather than proprietary tools. Pricing is transparent and predictable, licensing passes through at list, and there are no long-term contracts to hide behind — which means the work has to be genuinely good. If you want meaningful, hands-on cloud architecture work for real companies without the bureaucracy of a large managed services firm, we'd like to hear from you.
- More than 30 hrs/weekHourly
- 6+ monthsDuration
- ExpertExperience Level
$35.00
-
$70.00
Hourly- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:20 to 50
- Last viewed by client:2 days ago
- Interviewing:3
- Invites sent:13
- Unanswered invites:9
About the client
- USAChicago6:01 AM
- $18K total spent6 hires, 6 active
- 630 hours
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by