Support and maintain identity and federation services, including Active Directory (user and group management, roles, delegation), Entra ID app registrations, service principals, Conditional Access, RBAC, ADFS configuration and integration with internal and external applications. Maintain documentation of identity architectures, PKI designs, AI enablement patterns, and change records for audits and future engineers, and research and propose improvements to identity, PKI, certificate lifecycle, and AI enablement, including automation and governance tooling.