Skip to main content
🇩🇪GDPR-compliant
Hire the best

Azure Conditional Access Experts in Germany

matched in minutes with vetted freelancers and the power of AI

Hire experts who design access policies, MFA rules, device and location controls, and sign-in conditions for Microsoft Entra ID and Azure AD environments. Get support for policy reviews, rollout planning, and secure access changes with fast, precise matching of vetted, available freelancers.

Meet FRATCH Experts in Germany, who have recently used Azure Conditional Access

Verified expert

Peter Fleischer

View profile

Subproject Manager and Solution Architect - Microsoft 365 Transformation

Walpertskirchen
Peter Fleischer

Last position:

Subproject Manager and Solution Architect - Microsoft 365 Transformation at Automotive Industry

  • Integration of highly regulated countries such as China and South Korea into a company-wide M365 tenant.

  • Technical contact for integrating special requirements for the executive board and German subsidiaries that are subject to BaFin compliance requirements.

  • Subproject management.

  • Coordination of requirements within the overall architecture.

  • Design of the use of DLP features from Microsoft Purview.

  • Design of special access restrictions via Entra ID Conditional Access.

  • Support in designing the provisioning of Teams teams and SharePoint sites with higher compliance requirements.

  • Technical support for implementing information classification with sensitivity labels for SharePoint Online and Teams.

  • Technical support for the subproject introducing CoPilot for M365.

  • Skills: M365, Purview, DLP, Entra ID, Sensitivity Labels, CoPilot, Teams, SharePoint Online.

Verified expert

Huy Nguyen

View profile

Modern Workplace & Dynamics 365 Consultant

Hamburg
Huy Nguyen

Last position:

Modern Workplace & Dynamics 365 Consultant at Thinformatics

  • Administration and further development of the M365 environment including Teams, Exchange Online, Intune and SharePoint Online
  • Development of dashboards for performance monitoring using Microsoft Power BI
  • Implementation of user requirements and processes with low-code/no-code technologies (Power Apps, Power Automate)
  • Use of Jira and Azure DevOps to plan and implement user stories in an agile project context
  • Participation in daily stand-ups, sprint planning, sprint reviews and retrospectives as technical point of contact
  • Planning and implementation of security policies using Azure Conditional Access and multi-factor authentication
  • Configuration and deployment of clients and applications via MECM (SCCM) and Baramundi
Verified expert

Victor Omojoye

View profile

Senior Software & Security Engineer · Systems Analysis · Automation Architecture

Berlin
Victor Omojoye

Last position:

AI Training Engineer at Confidential AI Research Client

  • Codebase Evaluation & Problem Design: Designed and stress-tested complex software engineering problems against large open-source Python codebases (including pandas), requiring deep context acquisition and architectural understanding to produce well-scoped, realistic problem statements aligned to strict correctness guidelines.
  • Agent Failure Analysis: Assessed LLM coding agent solutions for correctness and completeness, identifying meaningful failures across edge case handling, dtype behaviour, and multi-column NaN propagation logic; documented findings with precision for downstream evaluation use.
  • Programmatic Test Suite Development: Authored comprehensive pytest suites to programmatically verify agent-generated solutions against defined requirements, with deliberate coverage of boundary conditions and failure modes not caught by naive implementations.
  • Containerised Environment Engineering: Built and debugged Docker environments for reproducible agent execution, including git-based repository provisioning, dependency pinning with npm ci, and multi-stage Dockerfile authoring across Linux-based containers.
Verified expert

Nabil Shahzad

View profile

DevOps Engineer & Cloud Architect

Ober-Ramstadt
Nabil Shahzad

Last position:

DevOps Engineer & Cloud Architect at PTXRE GmbH

  • IaC & Automation: Designed and automated provisioning of about 40 Linux servers and cloud resources using Terraform and Ansible (reducing manual effort by over 80%).
  • Container Orchestration: Built and operated two production Kubernetes clusters with 70+ Docker containers to ensure high availability, scalability, and self-healing.
  • CI/CD Optimization: Developed and maintained 15+ CI/CD pipelines with Jenkins and GitHub Actions (shortening deployment times from several hours to under 15 minutes).
  • OS Hardening & Operations: Automated patch management, OS configuration, and security hardening for 40+ Linux servers with Ansible to improve compliance.
  • Monitoring & Alerting: Implemented centralized monitoring and alerting solutions for proactive issue detection and minimized system downtime.
  • Cross-Functional Collaboration: Worked across Dev, Ops, and Security teams to establish DevOps best practices and infrastructure-as-code standards.
Verified expert

Enrique Gallardo

View profile

Data Security

Hamburg
Enrique Gallardo

Last position:

Security Architect at Capgemini

I implemented a Zero-Trust architecture for robust, military-grade maritime container mini data centers based on VMware & Tanzu to support containerized GIS workloads for ground forces. The main focus was on securing communications, workload protection, and data access in contested electronic battle environments affected by jamming, interception, signal manipulation, and constantly changing operational conditions. I designed and architected use cases so that every element of workload, identity, and system could continue to operate independently and securely even in degraded or disrupted scenarios. In parallel, I defined the enterprise and solution security architecture with LeanIX, Bizzdesign, and HOPEX as enterprise architecture, repository, and governance platforms to maintain architecture inventory, relationships, traceability, target pictures, and security governance in complex environments. For the architectural designs, I used Sparx Enterprise Architect to describe formal architecture views, interfaces, trust boundaries, and system architecture in both IT and OT environments. IriusRisk was used for threat modeling of the solution to identify architecture-driven risks, derive security requirements, and detect countermeasures and design gaps directly from the solution models. Risk and compliance management was supported with Archer. Architecture decisions, control gaps, and operational risks were translated into controlled governance and auditable compliance measures. For documentation, collaboration, and visual design, I used Confluence to maintain Architecture Decision Records, Security Blueprints, and workflows. I used Lucidchart and draw.io to create design artifacts tailored to stakeholders. I also defined OT security concepts with support from electrical and mechanical engineers in the areas of oil, vehicle onboard systems, rail, power plants, pharma, gas turbines, and nuclear technology. I created the end-to-end OT security strategy, starting with global policy, developed into standards and procedures, and finally aligned with Bell-LaPadula, Purdue Model, SABSA, TOGAF ADM, CENELEC 50701, IEC 62443, and NIST standards. In addition, I worked with engineering team leads to identify critical KBP assets and place them under protective measures that segmented SCADA, PLC, and HMI assets. I drove collaboration between Security, IT, and OT teams to create standardized workflows and use cases for the OT security solution catalog, while integrating Defense-in-Depth and Zero-Trust principles into operational environments. A key part of my work was integrating multidisciplinary engineering, security, and operations stakeholders into a unified security blueprinting strategy and ensuring that architecture, threat modeling, governance, and documentation were technically strong and operationally practical.

Verified expert

Markus Ickenroth

View profile

Senior Systems Engineer Microsoft

Ingelheim am Rhein
Markus Ickenroth

Last position:

Senior System Engineer Microsoft at Technidata IT-Service GmbH

  • As part of the project, I was responsible for operating a Citrix farm for 600 users, including optimizing the user experience and ensuring high availability.

  • I managed and optimized the entire application landscape of a major customer, evaluated and implemented application updates, and ensured the compatibility and security of the software in use.

  • I managed user accounts, implemented security policies, and monitored system performance.

  • I administered Azure Entra ID to control identities and access rights, implemented security policies, and synchronized on-premises directories with the cloud.

  • I implemented and managed Microsoft Intune for central management of client devices, including the configuration and management of BitLocker for disk encryption.

  • I managed file servers and NTFS permissions to ensure secure and efficient data access management.

  • I handled change requests and last-level support tickets efficiently to solve complex system issues and improve user satisfaction.

  • I supported and advised the customer team on various topics and projects, identified areas for improvement, and implemented best practices.

Technologies used:

  • Citrix XenApp and XenDesktop
  • Microsoft Windows Server 2012R2 and 2022
  • Exchange 2016 and Exchange Online
  • Entra ID (Azure AD)
  • Entra ID Connect
  • BitLocker
  • PowerShell scripting
  • Microsoft Intune
  • LDAP (Lightweight Directory Access Protocol)
  • DNS services (Domain Name System)
  • Active Directory Certificate Services (AD CS)
Verified expert

Andreas Eckert

View profile

IT Service - Support & Automation

Nortrup
Andreas Eckert

Last position:

IT-Compliance & Security at Bellaseno GmbH

Conducting a gap analysis to assess existing security measures → identifying critical vulnerabilities

Developing a catalog of measures considering risk and cost-effectiveness

Implementing an IT maturity model according to BSI guidelines

Advising management on compliance, governance, and security strategy

Establishing internal processes for a sustainable security organization

Verified expert

Oliver Kretz

View profile

Azure Cloud Engineer

Haßmersheim
Oliver Kretz

Last position:

Azure Cloud Engineer at DVAG-Deutsche Vermögensberatung AG

  • Conceptualization and administration of Azure AD (app registrations, hybrid identities, group concepts)
  • Azure Monitoring
  • Design and building of Azure-based solutions (IaaS / PaaS)
  • Consulting and technical support of internal cloud projects
  • Automations for Azure solutions
Verified expert

Albrecht Noack

View profile

Senior Project Manager IT

Berlin
Albrecht Noack

Last position:

Senior Project Manager IT at HAYS Technology Solutions GmbH

  • Leasing, lifecycle and process management for Apple iPhones, maintenance and expansion of the MDM system, coordination of leasing, device integration into DEP and MDM, followed by a rollout and hardware swap process, plus a BYOD and Android option
  • Migration of the IT ticket system from ManageEngine ServiceDesk Plus to Atlassian Jira Service Management: project management, definition of ticket types, seamless execution according to a detailed timeline, user communication, decommissioning of the old system
  • Project lead: SAP interface in workforce management to automate reading of working hours
  • Sub-project lead for inventory software EZO AssetSonar: demand management, software selection, procurement
Verified expert

René Karges

View profile

Freelancer

Köln
René Karges

Last position:

Freelancer at Freelance work

  • Business analysis
  • Requirements management
  • Project management
  • Stakeholder management
  • Team leadership
Verified expert

Alagi Mansaray

View profile

Senior S/4HANA Project Manager in the Energy Sector

Dreieich
Alagi Mansaray

Last position:

Senior S/4HANA Project Manager in the Energy Sector at RKU Informations- und Telekommunikationsdienste

  • Coordination and monitoring of required tasks and resources
  • Coordination and ensuring the flow of information between involved departments
  • Windows 10/11
  • Time management and project control
  • Integration of S/4HANA solutions in collaboration with business units
  • Microsoft Project
  • Confluence
  • Jira
  • Microsoft Office
  • Microsoft Planner
  • Responsible expert for client management environment services and patch management
  • Coordination of interfaces and integration with existing systems
  • Enable and enforce multi-factor authentication (MFA)
  • Ensuring data migration and quality during the S/4HANA implementation
  • Creation of a project structure plan
  • Optimization of the design and implementation of service and client management processes
  • Azure AD
  • Project management & risk management
  • Regular updates and drafting of decision documents for decision-makers
  • Set up of an additional Linux-based infrastructure for administrative purposes
  • Advising program management on transformation and migration projects
  • PowerShell scripting
  • Enhancement, maintenance and troubleshooting of the existing ERP application
  • Synchronization with on-premises directories (Azure AD Connect)
  • Conducting concept development and planning
  • Procurement, integration, and deployment of MacBooks
  • Autopilot
  • Integration of systems into a client management system (Intune), Microsoft Defender, and Azure AD
  • Implementation of single sign-on for mobile devices & PCs
  • Migration from Active Directory to MS Intune
  • Implementation and integration of SAP S/4HANA solutions
  • Software packaging (MSI)
  • Mobile device management with MS Intune and Mobile Iron
  • Management of servers and services using Ansible
  • MIM (Microsoft Identity Manager)
  • Identity and permission management
  • Access management
Verified expert

Ransford Annan

View profile

IT System & Security Engineer

Nürnberg
Ransford Annan

Last position:

Volunteer IT & Cybersecurity Team Lead at Farm House Organic

  • Led remote IT and cybersecurity operations, including secure device provisioning, app deployment, compliance monitoring, and endpoint security with Microsoft Intune and Defender for Endpoint.
  • Managed Identity and Access Management (IAM) with Microsoft Entra ID, including implementing role-based access control, conditional access, VPN configuration, and multi-factor authentication (MFA).
  • Maintained and secured Cloud PCs, provided technical remote support, and optimized performance within the Microsoft 365 Business environment.
Verified expert

Mohamed Ghassen Brahim

View profile

Founder & CEO

Berlin
Mohamed Ghassen Brahim

Last position:

Lead / Principal Cloud, AI & Security Architect at Freelancer / CC Conceptualise GmbH

Projects:

Project: RWE – Development of a company-wide Zero Trust cybersecurity architecture (CITADEL) Role: Senior Enterprise Cybersecurity Architect / Zero Trust Architect Company: RWE AG Description: Concept and implementation of the strategic CITADEL cybersecurity target architecture at RWE, based on the Zero Trust architecture principle and aligned with regulatory requirements such as NIS2, ISO 27001 and company-wide security governance policies. The goal was to build a measurable, auditable and scalable security architecture with a strong focus on Identity Governance, compliance transparency and operational manageability. Responsibilities & Achievements:

  • Zero Trust architecture design: Developed a company-wide Zero Trust reference architecture (Identity, Device, Network, Application, Data) including trust zones, control points and enforcement mechanisms according to NIS2.
  • Identity & Access Governance (IGA): Designed and introduced IGA governance structures including role models, recertification processes, segregation of duties (SoD) and lifecycle management for identities and access.
  • Security governance & KPIs: Defined and implemented security KPIs and metrics to manage Zero Trust maturity, identity risks and compliance at the management level.
  • Compliance & reporting: Built standardized compliance reports and dashboards to support internal audits, external assessments and regulatory evidence (e.g. NIS2).
  • Architecture & stakeholder alignment: Worked closely with Enterprise Architecture, IT operations and business units to integrate the CITADEL architecture into existing IT and security landscapes.
  • Strategic security consulting: Advised programs and projects on Zero Trust compliance, identity centricity and regulatory requirements in the energy and critical infrastructure (KRITIS) environment. Technologies & Methods: Zero Trust Architecture, NIS2, Identity Governance & Administration (IGA), IAM, RBAC, SoD, Entra ID, SailPoint, Zscaler, Terraform / IaC, Policy as Code, security KPIs, compliance reporting, NIST 2.0, ISO 27001, Enterprise Security Architecture, governance frameworks, risk & control management

Project: Scalable AI Workbench Platform on Microsoft Azure Role: Cloud Architect & Engineer Company: Siemens Energy Description: Design, development and operation of a secure, modular cloud infrastructure to support Data Science, Machine Learning and AI applications for various engineering teams at Siemens Energy. Responsibilities & Achievements:

  • Cloud architecture: Designed and implemented an Infrastructure-as-Code solution (Terraform) for automated provisioning of Azure resources (Resource Groups, Storage Accounts, Cosmos DB, Application Insights, networking, PostgreSQL Flexible Server, Azure Container Apps, Azure Container Registry).
  • Developer portal: Used Backstage with custom frontend and backend plugins (Node.js, TypeScript, React.js, PostgreSQL, Container Apps) to enable self-service and empower developers, data scientists and AI/ML engineers.
  • Role-based access control: Implemented Azure RBAC to grant targeted access (e.g. Storage Blob Data Contributor, Reader) to engineering groups (e.g. AI Engineers) for relevant resources.
  • Data platform engineering: Built and configured a multi-layered storage landscape (Raw, Curated, Vector data), including automated container creation and access control for advanced analytics and AI workloads.
  • DevOps integration: Integrated with Azure DevOps for CI/CD pipelines to automate deployment, monitoring and compliance.
  • Security & compliance: Implemented Private Endpoints, network policies and Managed Identities to ensure data protection and regulatory compliance.
  • Collaboration: Worked closely with cross-functional teams to align the cloud infrastructure with business and technical requirements and drive digital transformation at Siemens Energy. Technologies: Azure, Terraform, Azure DevOps, Cosmos DB, Application Insights, Azure Storage, Private Endpoints, Azure Synapse, Azure Machine Learning, Azure Entra ID, RBAC, Backstage, Node.js, React.js, PostgreSQL, Python (automation), Git
Verified expert

Tom Faulhaber

View profile

Project Manager SOC Service Transition and Implementation of Microsoft Cloud Security Solutions

Berlin
Tom Faulhaber

Last position:

Project Manager SOC Service Transition and Implementation of Microsoft Cloud Security Solutions at Sonovum GmbH

  • Analyzed existing SOC infrastructure and assessed security operations

  • Transitioned to a new operating model including security monitoring, incident response, and threat intelligence

  • Coordinated between internal teams, external partners, and service providers

  • Implemented Microsoft Intune: configuration, compliance policies, and BYOD management

  • Implemented Microsoft Defender: endpoint and network protection, automated threat detection, and incident response

  • Trained IT security teams and end users

  • Deployed Microsoft Sentinel: integration with existing systems, automation of playbooks

  • Introduced Conditional Access: policies, MFA, and creation of reports and dashboards

  • Managed project from initiation to closure including change, risk, and acceptance management

  • Handled project controlling regarding schedule, costs, and quality

  • Managed requirements: gathering, classifying, and evaluating IT security requirements

Discover over 15,000 top freelancers

Statistics of experts using Azure Conditional Access

Aggregated from the professional profiles of matched freelancers.

Experience

18 years

Position duration

2.3 years

Positions per freelancer

13

Top business areas

Information Technology, Operations, Project Management

Top industries

Information Technology, Banking and Finance, Manufacturing

Certification focus areas

Information Technology, Project Management, Business Intelligence

Bachelor's degree or higher

71%

Master's degree or higher

36%

Doctorate

7%

Certifications per freelancer

8

Most common languages

German, English, French

Speak two or more languages

100%

Based on our profile pool as of 30 Aug 2026.

Daily rate distribution

0 2 4 6 8
<€640 €640-​800 €800-​960 €1120+

The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.

Average rates of experts in Germany using Azure Conditional Access

Rates are based on recent contracts and do not include FRATCH margin.

800
600
400
200
Rate comparison chart
Daily rate avg. 765 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

800
600
400
200
Rate comparison chart
Median rate 788 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

About the technology

Access control

Azure Conditional Access is Microsoft’s policy layer for controlling how users sign in to cloud apps and internal resources. It sits in Microsoft Entra ID, formerly Azure AD Conditional Access, and helps companies set clear rules for access by user, device, app, location, and risk.

Typical use

It is used to enforce MFA, block unsafe sign-ins, and require compliant devices for sensitive data.

  • Protect Microsoft 365 and business apps
  • Limit access from unmanaged devices
  • Apply location and group-based policies
  • Support zero trust access rules

Skills needed

Strong professionals know identity design, Entra ID, authentication methods, and policy logic. They also understand how sign-in frequency, session controls, and named locations affect the user experience. Good work here is precise, because one weak policy can lock out the wrong people.

Ecosystem

Azure Conditional Access rarely stands alone. It is usually combined with MFA, device compliance in Intune, identity protection signals, privileged access workflows, and enterprise app registration settings.

  • Microsoft Entra ID and Azure AD
  • Microsoft Intune device compliance
  • MFA and passwordless sign-in
  • Privileged identity controls

When to bring in help

Companies often bring in freelance experts during tenant migrations, security hardening projects, audits, or after policy sprawl has made access rules hard to manage. In Germany, they are also useful when local teams need English-speaking support for global identity projects while keeping collaboration remote and practical.

What strong experts deliver

A strong specialist documents the current setup, maps business access needs, and builds policies that are strict but workable. They test break-glass access, review exclusions, and tune policies so security improves without creating avoidable sign-in problems for users in the office or working remotely.

Published on:
FRATCH GPT

FRATCH GPT delivers freelancer proposals with clear reasoning and transparent pricing in minutes, helping your hiring department quickly and compliantly find the best talent.

Give it a try:

Try FRATCH GPT

Frequently asked questions

The facts hiring teams ask for most often when it comes to Azure Conditional Access.

Azure Conditional Access is used to decide when a person can access Microsoft cloud resources and under what conditions. Companies use it to require MFA, block risky logins, and enforce device or location rules for apps in Microsoft Entra ID.

Azure Conditional Access is the current name people usually mean, while Azure AD Conditional Access is the older term still used in searches and older projects. The feature lives in Microsoft Entra ID, so both names often point to the same policy work.

Azure Conditional Access goes beyond simple MFA prompts because it can combine user, device, app, location, and risk conditions. Basic MFA only checks one part of the access decision, while Conditional Access lets teams build more precise sign-in rules.

A strong Azure Conditional Access specialist should also know Microsoft Entra ID, authentication methods, device compliance, and identity security basics. Experience with Intune, MFA, privileged access, and sign-in troubleshooting is also valuable because these areas usually work together.

Azure Conditional Access work needs a clear view of users, apps, device states, and business-critical sign-in paths. Even a small policy change can affect access across an entire tenant, so the specialist should review current rules, exceptions, and recovery access before making changes.

Yes, Azure Conditional Access projects are often handled remotely because the work is mostly policy design, testing, and tenant review. For teams in Germany, that usually works well as long as there is good access to local stakeholders, security owners, and identity admins when decisions need sign-off.

A good Azure Conditional Access expert explains the policy model clearly, documents every change, and tests for lockout risks before rollout. Look for clean naming, sensible exclusions, break-glass protection, and policies that match business use cases instead of adding unnecessary complexity.

Azure Conditional Access often needs tuning after MFA rollouts, device compliance changes, mergers, or new app launches. It also comes up when users are blocked from trusted devices, when guest access becomes messy, or when security teams need tighter control over high-risk sign-ins.

The average hourly rate of freelancers in Germany who have used Azure Conditional Access in their recent projects is 96 €, which corresponds to a daily rate of about 765 € based on an 8-hour working day.

Of the freelancers in Germany who have used Azure Conditional Access in their recent projects, 71% hold at least a Bachelor's degree, 36% hold at least a Master's degree, and 7% hold a doctorate.

On average, freelancers in Germany who have used Azure Conditional Access in their recent projects have 18 years of professional experience, with a single engagement typically lasting around 2.3 years.

The most common languages among freelancers in Germany who have used Azure Conditional Access in their recent projects are German (100%), English (100%), and French (24%).

The most common industries among freelancers in Germany who have used Azure Conditional Access in their recent projects are Information Technology (100%), Banking and Finance (53%), and Manufacturing (53%).

The most common business areas among freelancers in Germany who have used Azure Conditional Access in their recent projects are Information Technology (100%), Operations (82%), and Project Management (76%).

Main locations of FRATCH Experts, who have recently used Azure Conditional Access

Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.

Berlin Hamburg Munich Cologne Frankfurt Stuttgart Dusseldorf Leipzig Dortmund Essen Bremen Dresden Hanover Nuremberg

Request a free demo

Get in touch with the FRATCH team and we will get back to you within 4 hours.

Contact form

Would you rather directly get in touch?
We always have the time for a call or email!

FRATCH CEO avatar

Philipp Thomaschewski

FRATCH CEO

LinkedInFRATCH