For 1 of our clients, we are looking for an Entra ID (azure) cloud engineer
Full-time
Temporary mission (3 months - but can be extended)
ENG + NL or FR
1 day/week onsite (schaarbeek)
Purpose
You will build and configure an Entra ID External (Azure AD External Identities) environment that meets the requirements of the GWP, SEAGMA, Kazoutopia and Web applications and ensure that authentication, authorization and federation are correctly implemented and tested.
Scope & Deliverables.
Implementation of Entra ID External
Setting up a new Entra ID tenant or configuring within existing tenant
Configure Identity Providers (IDP) support for OAuth2, OpenID Connect, SAML, and LDAP
Integration with external IDPs, such as Itsme and Federal Authentication Service (BOSA FAS/CSAM)
Configuring Security Token Delivery
User & Access Management
Setting up B2B and B2C separation
Volunteers (B2B) → invited by staff
Customers (B2C) → self-service registration
Configuring role-based access management (RBAC)
Link roles and attributes to users
Forwarding claims to applications
Access management based on user roles/attributes
Creating and modifying user flows
Set up Single Sign-On (SSO) for:
B2B users → O365 (SharePoint), SEAGMA, GWP apps
B2C users → Portal, Mobile App (no O365 SSO)
Security & Compliance
Configure Multi-Factor Authentication (MFA)
Activate self-service features (password reset, account recovery)
Set up audit & logging
Configure security analytics for monitoring & alerts
Set up responses to fraudulent events (e.g. block accounts, generate alerts)
Integration with Sailpoint
Customization & User Experience.
Customize branding for GWP, ASBL, Kazoutopia and Web (custom login pages)
Determine User Migration Strategy.
Investigate whether existing accounts can be migrated to Entra ID or whether new registration is required
Dependencies
Coordinate with Security Team on RSL security guidelines
Coordination with development team for application integration & claim mapping
Testing and validation with business stakeholders