Manage Windows endpoint configuration, patching, and compliance through Intune/Endpoint Manager. Administer M365 workloads (Exchange Online, SharePoint Online, Teams, OneDrive), applying security baselines and governance. Implement and monitor endpoint security controls (Defender, BitLocker, conditional access, device compliance policies). Handle complex escalations from the service desk. Act as secondary admin for core identity and Azure resources. Participate in an on-call rotation.