Job SummaryThe SCCM Administrator will manage and support enterprise endpoint infrastructure across Microsoft Configuration Manager (SCCM), Group Policy, Microsoft Intune, and third-party patch management tools. This role is responsible for SCCM administration, application and patch deployment, GPO governance, endpoint co-management, reporting, troubleshooting, and maintaining a secure and reliable endpoint environment.
Key ResponsibilitiesSCCM / Configuration Manager- Administer and maintain SCCM infrastructure supporting software distribution, patch management, endpoint security, and inventory.
- Build and maintain packages, applications, collections, and deployments.
- Monitor SCCM client health and troubleshoot agent installation, discovery, policy, and communication issues.
- Administer Software Update Point (SUP)/WSUS, including synchronization troubleshooting and Automatic Deployment Rule (ADR) management.
- Manage monthly Patch Tuesday activities, including third-party patching using Patch My PC.
- Manage Distribution Points, content distribution, boundaries, and boundary groups.
- Support Operating System Deployment (OSD), task sequences, device imaging/re-imaging, and driver package management.
- Use CMPivot for real-time endpoint queries and troubleshooting.
- Configure and maintain maintenance windows and SCCM client settings.
- Monitor platform health and troubleshoot system performance and deployment issues.
- Develop reports for deployment status, patch compliance, hardware inventory, licensing, and compliance.
Group Policy- Design, implement, and maintain Group Policy Objects (GPOs) for security baselines and configuration standards.
- Review and consolidate existing GPOs into standardized policies for core systems, security, browsers, Office, and remote access.
- Troubleshoot GPO conflicts, replication issues, and performance problems using RSoP, GPResult, and Event Viewer.
- Optimize GPO performance through link order, enforcement, WMI filters, and item-level targeting.
- Establish GPO governance, change control, testing, rollback procedures, and documentation.
Microsoft Intune- Configure endpoints for SCCM and Intune co-management.
- Support Windows Autopilot deployments.
- Package, deploy, and monitor applications through Intune.
- Manage and troubleshoot Company Portal and device enrollment.
- Maintain device compliance and configuration policies, including BitLocker and Mobile Application Management (MAM) policies.
- Coordinate with Conditional Access policies to support compliance and access requirements.
Cross-Functional Support- Collaborate with IT teams to integrate SCCM, GPO, Intune, and patch management solutions with broader infrastructure.
- Apply security best practices across endpoint management platforms.
- Serve as a technical resource for SCCM, Group Policy, and Intune-related matters.
- Support software licensing and compliance reporting using SCCM inventory data.
- Maintain technical documentation and stay current with platform updates and industry best practices.
Required Qualifications- Bachelor's degree in Computer Information Systems, Computer Science, Information Technology, Cybersecurity, Engineering, or a related field.
- 5+ years of enterprise SCCM administration experience.
- Hands-on experience designing, managing, and troubleshooting GPOs within multi-domain/multi-OU Active Directory environments.
- Experience using RSoP, GPResult, and Event Viewer to diagnose Group Policy conflicts and performance issues.
- Strong knowledge of Windows Server, Active Directory, and core networking concepts.
- PowerShell scripting experience, particularly for GPO management and reporting.
- SQL Server proficiency for SCCM reporting and troubleshooting.
- Experience with SQL Server Always On Availability Groups in multi-server SCCM environments.
- Experience building and customizing SSRS reports for SCCM.
- Hands-on Microsoft Intune experience, including co-management enrollment, application deployment, and Company Portal support.
- Experience with PKI infrastructure and certificate management.
- Experience with third-party patch management tools such as Patch My PC.
- Proficiency with CMTrace and troubleshooting SCCM client/server logs, Windows Event Logs, IIS logs, and third-party patching logs.
- Strong troubleshooting, communication, and collaboration skills.
- Ability to work independently and manage complex endpoint environments.
Preferred Qualifications- Experience with Group Policy Management Console (GPMC) for modeling, testing, and auditing policy changes.
- Configuration Manager Task Sequences and OSD imaging experience.
- Experience with Power BI.
- Experience with Windows Autopilot.
- Experience with virtualization technologies such as Hyper-V or VMware.
- Familiarity with the ITIL framework.