Conditional Access policies, and passwordless sign‐in aligned to Zero Trust principles. Application integration — migrate or re‐establish SSO for enterprise apps using SAML, OAuth 2.0, and OIDC. Identity governance — stand up Privileged Identity Management (PIM), Entitlement Management (access packages), and Access Reviews as part of the target state. … third-party IdP (Okta, Ping, ForgeRock, etc.). Strong working knowledge of Conditional Access, Zero Trust security models, and modern authentication protocols (SAML 2.0, OAuth 2.0, OIDC). Confident PowerShell scripting for identity lifecycle automation, ideally via the Microsoft Graph PowerShell SDK. Comfortable working independently and communicating migration risk/ ...