Microsoft 365 & CoPilot SME | IDAM SME | SC Cleared | Technical Architect

$ zahin.memon --role="M365 Expert" --specialization="Enterprise Migration"

15+ years transforming enterprise workplaces. Expert in CoPilot implementation, M365 adoption, enterprise migrations (Workspace ONE → Intune), Hybrid/Cloud identity, co-management, and modern device architecture.

Download CV

About

Modern Workplace Solution Architect and Senior Endpoint Management Consultant with 15+ years of experience delivering enterprise-scale digital workspace, endpoint security, identity and access management, and device management solutions across financial services, energy, government, and enterprise environments. Specialist in Microsoft Intune, Microsoft 365, Entra ID / Azure AD, Identity Governance and Administration (IGA), Endpoint Architecture, Windows 11 transformation, security compliance, and Zero Trust strategy.

Proven track record of leading large-scale endpoint modernisation and identity transformation programmes, architecting secure and scalable UEM and IDAM solutions, and driving automation across complex environments supporting tens of thousands of users and devices. Deep expertise in Entra ID governance, Privileged Identity Management (PIM), Conditional Access, and identity lifecycle management — ensuring least-privilege access and compliance across enterprise tenants.

Experienced in delivering cross-platform endpoint management across Windows, macOS, iOS/iPadOS, and Android Enterprise environments, with strong hands-on expertise in Intune, SCCM, Autopilot, Defender for Endpoint, Conditional Access, PowerShell automation, Microsoft Graph API, and enterprise mobility architecture.

Experience

Copilot SME / M365 & Entra ID Consultant

Tata Consultancy Services (Virgin Money / Nationwide Bank)
Sep 2025 – Present
  • Leading Microsoft 365 Copilot adoption and AI enablement initiatives across an enterprise environment of approximately 20,000 users.
  • Providing strategic guidance and architecture on Entra ID identity governance, including Conditional Access policy design, Entra ID Governance configuration, and access review processes for regulated financial services environments.
  • Implementing and advising on Privileged Identity Management (PIM) to enforce just-in-time access, least-privilege principles, and audit-ready access controls across M365 and Azure workloads.
  • Designing identity lifecycle workflows (Joiner/Mover/Leaver) aligned to HR systems via SCIM provisioning and Entra ID automated provisioning, reducing manual identity administration overhead.
  • Managing and resolving complex 3rd line M365 and Intune escalations daily — spanning Exchange Online, Teams, SharePoint, Entra ID, Conditional Access, device compliance, and Autopilot issues.
  • Designing governance, adoption, and evergreen strategies for Microsoft 365 Copilot, including sensitivity label alignment and compliance readiness for AI tooling.
  • Acting as trusted advisor and escalation authority to Technology Leadership on identity, EUX, and modern workplace architecture.

Senior Intune Architect / Entra ID SME

Tata Consultancy Services (EDF Energy)
Jun 2024 – Sep 2025
  • Designed and delivered enterprise-scale Intune endpoint management architecture supporting 30,000+ devices, leading the strategic migration away from legacy SCCM.
  • Architected the Entra ID identity and access management framework for the endpoint estate: Conditional Access policies, device compliance enforcement, Entra ID-joined device design, and hybrid join strategy for legacy workloads.
  • Implemented Privileged Identity Management (PIM) and Entra ID Governance controls, enforcing role-based access, time-limited admin rights, and access reviews across IT and security teams.
  • Designed and deployed SSPR (Self-Service Password Reset), MFA, and Windows Hello for Business (WHfB) as part of a passwordless authentication initiative, reducing helpdesk credential tickets.
  • Defined identity lifecycle management processes integrated with HR provisioning, ensuring automated Joiner/Mover/Leaver workflows through Entra ID and SCIM-compatible connectors.
  • Led Windows 11 transformation programme end-to-end: architecture, Autopilot provisioning, Entra ID join policies, compliance baselines, and phased rollout across all business units.
  • Implemented Zero Trust security model: Defender for Endpoint integration, Conditional Access with device compliance gates, and Cyber Essentials+ alignment.
  • Automated device provisioning, compliance remediation, and identity reporting via PowerShell and Microsoft Graph API.
  • Operated as 3rd/4th line SME and final escalation point for complex endpoint, identity, and Entra ID incidents.

Modern Workplace Architect

boxxe Limited
Aug 2021 – Apr 2024
  • Delivered enterprise endpoint architecture and modern workplace solutions for government and large enterprise customers.
  • Designed Entra ID and Azure AD configurations for client environments, including Conditional Access framework design, B2B guest identity controls, and cross-tenant collaboration policies.
  • Implemented identity governance controls including access packages, entitlement management, and automated access reviews for clients in regulated sectors.
  • Led Workspace ONE to Microsoft Intune migrations including Entra ID join strategy, policy translation, and identity-aligned compliance framework design.
  • Designed multi-platform endpoint management across Windows, macOS, iOS (Apple DEP), and Android Enterprise (Samsung Knox / Google Play Managed).
  • Worked with Microsoft Purview, Defender for Endpoint, and endpoint security baselines to improve customer security and governance posture.
  • Produced HLDs, LLDs, and architecture documentation applying enterprise EUX and identity best practices.

Previous consultancy and engineering roles spanning NHS, Johnson Matthey, Office for National Statistics, Ministry of Housing, Cabinet Office, Taylor Wessing, Tradeweb, Thomson Reuters, and Unilever. Scope included enterprise Windows 10 migrations (up to 120,000 devices), Intune/SCCM architecture, Autopilot deployments, Active Directory / Azure AD management, and EUC transformation programmes across government and regulated industries. Full details available on request.

Additional Enterprise Experience – Senior Modern Workplace / Endpoint Management Consultant

Core Expertise

Modern Workplace & Endpoint Architecture

Microsoft Intune Architecture & Design Unified Endpoint Management (UEM) Windows 10/11 Enterprise Transformation Endpoint Lifecycle Management Microsoft Autopilot & WHfB SCCM / MECM Co-Management & Migration Workspace ONE to Intune Migration BYOD & Corporate Device Strategies Device Compliance & Configuration Governance Hardware & Software Asset Strategy

Identity & Access Management (IDAM / IAM)

Microsoft Entra ID / Azure AD Architecture Identity Governance & Administration (IGA) Privileged Identity Management (PIM) Entra ID Governance & Access Reviews Conditional Access Policy Design Identity Lifecycle Management (Joiner/Mover/Leaver) SSPR, MFA & Passwordless Authentication Entitlement Management & Access Packages B2B / Guest Identity & Cross-Tenant Access SCIM Provisioning & HR-driven Identity Workflows

Security & Compliance

Zero Trust Security Architecture Microsoft Defender for Endpoint Microsoft Purview (Compliance & DLP) Endpoint Security Baselines BitLocker & Device Encryption Secure Access & Compliance Frameworks Cyber Essentials+ Alignment Information Protection & Sensitivity Labels M365 Tenant Security & Governance NCSC Security Standards

Automation, Scripting & Architecture

PowerShell Automation & Scripting Microsoft Graph API Intune Remediation Scripts Application Packaging & Deployment High-Level & Low-Level Designs (HLD/LLD) Technical Solution Architecture Enterprise Architecture Governance Architecture Documentation & Design Assurance

Career Highlights

120k+

Endpoints managed across enterprises

13k+

Employees enabled for CoPilot

1000+

Devices migrated (99%+ success)

20k+

Windows 11 migrations (NCSC)

15+

Years enterprise expertise

89

Technical staff leadership

Certifications

Microsoft 365 Certified: Enterprise Administrator Expert

Microsoft Certified: Endpoint Administrator Associate

Microsoft Certified: Azure Fundamentals (AZ-900)

CompTIA Network+

Certified Ethical Hacker (CEH)

Cisco Certified Academic Instructor

Security Cleared (SC)

Connect

Open to enterprise architecture roles, consulting, and strategic technology initiatives

🔗

Request My CV

To request a copy of my CV, please connect with me on LinkedIn.
I'll send it across directly.

Connect on LinkedIn