Microsoft Entra ID Experts in Munich
in minutes from over 15,000 CVs with the power of AI.Hire experts who secure access, set up single sign-on, and manage conditional access, app registrations, and tenant governance in Microsoft Entra ID. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Munich, who have recently used Microsoft Entra ID
Vicenco Kenk
Last position:
ITSM Project Manager (self-employed)
Unified ITSM framework
- Definition of a company-wide ITSM target picture
- Introduction of a uniform service structure across all business units
SLA and OLA management
- Building a standardized SLA framework
- Definition of service classes (Business Critical, Standard, Low Priority)
- Introduction of OLAs between internal teams
- Building meaningful SLA reporting
- Definition of KPI and service dashboards for business units
Service portfolio management
- Definition of service descriptions
- If needed, preparing possible cost and service billing
Ticketing & processes
- Incident management
- Uniform ticket categories
- Standardized prioritization
- Escalation matrix
- Automations
- Self-service optimization
Request fulfillment
- Service catalog across all business units
- Approval workflows
Problem management
- Introduction of root cause analysis
- Known error database
- Problem review process
Complete asset management concept
- Hardware lifecycle management
- Software lifecycle management
- Leasing lifecycle
- Mobile device lifecycle
- Monitor lifecycle
- Phone lifecycle
Processes
- Procurement
- Goods receipt
- Inventory
- Assignment
- Return
- Disposal
- Leasing return Goal: single source of truth for all assets
CMDB design
- Definition of all configuration items:
- Workplace
- Notebooks
- Monitors
- Mobile phones
- Printers
Infrastructure
- Servers
- Firewalls
- Switches
- WLAN
- Storage
- Backup systems
Cloud
- Azure resources
- Microsoft 365
- SaaS services
Relationships
- User ↔ Asset
- Asset ↔ Service
- Service ↔ Infrastructure
- Location ↔ Asset
- Goal: make all service dependencies visible
Software asset & license management
- License management concept
- License balancing
- Compliance reporting
- Microsoft license management
- Adobe license management
- SaaS management
- Contract management
- Renewal management
Interfaces & automation Existing systems
- Workday
- Joiner
- Mover
- Leaver
TESMA
- Leasing data
- Contract data
Matrix42
- Asset synchronization
- User synchronization
Active Directory / Entra ID
- User management
Microsoft 365
- License assignment
- Group management
Dormakaba
Access processes
Lifecycle services
Monitoring platforms
- PRTG
- Palo Alto
- Cisco
Reporting & KPI framework
- Definition of a management dashboard
- KPIs
- Ticket volume
- SLA fulfillment
- MTTR
- First resolution rate
- Asset accuracy
- License compliance
- Change success rate
- Service availability
- Degree of automation
Network redesign support
- Governance
- Support of the network redesign from an ITSM point of view
- Definition of affected services
- Change management structure
- Communication concept
CMDB integration
- Recording of all network components
- Service mapping
- Dependency analysis
Validation of documentation and knowledge base articles
- Network documentation
- Operations documentation
- Standard changes
Monitoring & event management
- Target picture
- Central monitoring concept
- Event management process
- Alerting strategy
- Escalation model
Systems
Cisco
Palo Alto
Fortinet
Rubrik
Veeam
Matrix42
Azure
Microsoft 365 Automation
Ticket creation from monitoring
Escalations
Standard actions
Audit, compliance & information security
- ISO 27001 consulting
- TISAX consulting
- NIS2 preparation - consulting
- Audit-ready processes
- Documentation structure
- Evidence tracking in Matrix42
Roadmap
- 12-month roadmap
- Prioritization of all measures
- Quick wins
- Medium-term projects
- Long-term target picture
- Documentation
Alexander Alawi
Last position:
Onsite Support Administrator at Sana Kliniken AG
- Processing and coordination of IT tickets (Helix, Omnitracker) incl. VIP support and remote support (Microsoft Teams, RDP, FastViewer)
- Onsite support at the main location as well as support for modern conference and meeting room technology (e.g. MeetingBoard 75 Pro)
- User and rights management in Active Directory (Active Roles), Azure AD, Exchange and MDM
- VDI support and monitoring with Citrix Director and Aruba Networking
- Endpoint management and policy administration via Ivanti
- Deployment, configuration and lifecycle management of clients (Dell notebooks, iPhones, iPads)
- Hardware rollouts for new employees incl. shipping across Germany
- Asset and license management as well as organization of site migrations
Thomas Hoefkens
Last position:
Senior MLOps, DevOps Engineer at Trianel Energy
- Build and operate an end-to-end MLOps platform on Azure ML and Kubernetes (Kubeflow) for the automated deployment, monitoring, and scaling of forecasting models (including Temporal Fusion Transformer, Informer, Autoformer).
- Implement CI/CD pipelines in Azure DevOps for the full ML lifecycle – from resource provisioning (Terraform), data transformation (Hugging Face Datasets, Pandas, PyTorch, CUDA cluster) through training and evaluation to model registry and endpoint deployment.
- Integrate MLflow for experiment tracking, model versioning, performance monitoring, and automated registration in the Azure Model Registry.
- Develop and containerize PyTorch training jobs (Azure Notebook, Jupyter Notebooks) for price and time series forecasting (PFC models) with automatic rollout via Azure ML Endpoints and REST/gRPC interfaces, Docker containerization, secured with OAuth 2.0.
- Set up monitoring and alerting mechanisms (Prometheus, MLflow Metrics), log centralization, and cost monitoring.
- Automate infrastructure provisioning and model deployment using Terraform, Helm, and Azure CLI; connect to existing market data systems and event pipelines.
- Migrate existing workloads and databases (IONOS → Azure, MongoDB) with integration into central MLOps workflows and internal networks.
- Extend the platform with LLM-based tools (LangChain, LangServe) to integrate GPT-based analysis modules into existing Spring Boot services for market anomaly detection and automated reports.
- Analyze and architect a software solution to process large volumes of data efficiently (>3000 messages/sec.) (market data store).
- Spring Boot / Java 21 container development with RabbitMQ for distributing stock market data via MongoDB (Kubernetes) with fast storage of data in Redis RMaps, deduplication, forwarding messages to Read Model queues, and building Read Models for UI display in MongoDB.
- Integration of RESTHeart to create a REST API for MongoDB.
- Build an Angular frontend to simplify data queries and master data maintenance.
- Agentic coding with remote and local LLMs (Claude Sonnet, Ollama Qwen) and MCP servers.
- Develop Python scripts for transforming and cleaning incoming stock market data (Pandas, scikit-learn).
Omar Ashour
Last position:
Senior Fullstack AI Engineer (Team Lead – B2C Platform) at mama health
- Partner directly with C-level leadership (CEO, CAIO, CTO) on architecture, OKR strategy, and cross-team roadmap prioritization, translating strategic goals into structured engineering requirements.
- Surfaced and mapped technical debt across the entire organization with C-level leadership and co-defined a prioritized remediation strategy, balancing debt paydown against feature delivery.
- Led code reviews and technical standards across the team, fostering a mentor-first environment with two-way feedback dialogue — pairing on complex pipeline work and unblocking junior engineers on async architecture patterns.
- Re-architected the AI companion's core processing pipeline from synchronous to asynchronous with a queue-based worker architecture, enabling horizontal scalability and cutting upload processing time ~4x (from ~22s to 5–10s) while improving response accuracy.
- Designed an AI-driven document intelligence workflow with automatic multi-document classification, per-document summarization, and relevance guardrails for the patient care journey.
- Built a unified patient memory system (short- and long-term context) bridging the document vault and chatbot into a single bidirectional, context-aware platform.
Mohamad Dib-Skhni
Last position:
Project Engineer at BMW Group AG
- Designed and implemented Azure Kubernetes Clusters, and managed DNS and Firewall solutions, enhancing network security and reliability.
- Led projects using Agile Scrum methodologies to streamline development cycles and improve project efficiency.
- Fostered and maintained relationships with suppliers to ensure timely project deliverables and resource availability.
- Managed continuous integration and delivery (CI/CD) pipelines using Jenkins, Sonar, GitHub, Bitbucket, and Terraform within the BMW Azure Cloud environment.
- Utilized Fortify SSC and Contrast AST for robust application security testing.
- Directed DevOps engineering initiatives on the SAP Business Technology Platform (BTP), focusing on streamlining development and deployment processes.
- Service Now governance, risk und compliance (GRC&IRM).
Harald Laschitz
Last position:
Project Management at Loocid LLC
- Conducted a comprehensive due diligence review for a potential acquisition of a Swiss manufacturing company as part of a pre-merger analysis
- Assessed production capacities and technical infrastructure
- Evaluated integration possibilities into existing business processes
- Performed risk assessment and developed recommendations for action
- Documented the findings and presented them to management
Timo Hahn
Last position:
IT Product Owner / IT Project Manager at Schaeffler AG
- Responsible for tool-based project and portfolio management in the group
- Designing, enhancing and operating Jira- and Confluence-based workflows
- Translating management and business requirements into reliable tool concepts
- Integrating Jira into existing tool landscapes (e.g. Planview, ServiceNow, SAP BW)
- Establishing governance, reporting and KPI structures
- Rolling out new workflows including training & key user models
- Using AI features to support planning & analysis
Michael Møller
Last position:
Freelance Senior Consultant & Cloud Architect at Rheinmetall AG
- Specialized in designing and implementing robust, secure cloud solutions for critical client infrastructure.
- Expertise in Microsoft Intune environment with a strong focus on system hardening and comprehensive policy management.
- Architected NIST and ISO/IEC 27000 compliant Mobile Device Management (MDM) infrastructure tailored for an international government defense aerospace project.
- Performed an architectural role for an offline Microsoft Endpoint Configuration Manager (MECM) environment, ensuring NIST compliance while handling complex manufacturing infrastructure.
Ales Loncar
Last position:
Senior DevOps Consultant (Freelance) at European Union Agency (via IBM)
- Worked as freelance Senior DevOps Consultant on-site for IBM at a European Union Agency, operating in a highly secure, air-gapped environment managing classified systems.
- Led automation and DevOps initiatives for a large-scale OpenShift platform (>400 nodes), driving deployment efficiency, GitOps adoption, and operational automation using Ansible, Python, and Bash while ensuring compliance with security requirements.
- Spearheaded automation of release and deployment workflows in a private cloud environment hosting 400+ OpenShift nodes, significantly improving deployment speed and reliability.
- Migrated existing playbooks, roles, and templates from Ansible Tower to Ansible Automation Platform (AAP), ensuring full compliance with fully-qualified collection names (FQCN) and preparing custom Execution Environments (EE) for containerized automation.
- Implemented GitOps Agent for AAP Controller Configuration as Code, enabling automated synchronization (CRUD) of Ansible Controller objects based on repository-stored configuration definitions using GitHub webhooks.
- Designed and automated complex multi-step operational workflows including environment cleanup, Helix cluster component re-creation, Kafka topic management, and OpenShift object lifecycle management across ~100 environments.
- Achieved a reduction of multi-day manual operations to under a few hours through automation improvements spanning multiple AAP clusters and OpenShift environments.
- Integrated Ansible Automation Platform with Thycotic (Delinea) Secret Server via lookup plugin to enhance secure credential management in automated processes.
- Managed deployment tasks, platform troubleshooting, and Istio network configurations while adhering to stringent EU PSC security and compliance standards.
- Collaborated with infrastructure and application teams to refine deployment procedures, develop naming conventions, and continuously improve automation coverage in an air-gapped, classified environment.
Stefan Corsten
Last position:
SSIS Development at Stadtsparkasse München
- Replacement of a Java application and the Oracle DB for loading the internal WerWasWo system using SSIS.
- Development of SSIS packages to load text files into the database (SQL Server)
- Development of a database project for deployment on various servers
- Creation of queries to monitor the loading runs
- Development of a PowerShell script to automate the deployment of the SSDT projects.
- Oracle, SQL Developer, Microsoft SQL Server 2022 on-premises, SQL Server Management Studio v21, Visual Studio 2022, SSIS, SSDT, PowerShell.
Rick Grassmann
Last position:
Interim IT Security Analyst at GLS IT Services GmbH
- Risk Management
- Incident Management
- Security Analysis
- Secure Coding
- Information Security Management System (ISMS)
Maryam Nemati
Last position:
Senior FullStack Developer at Camunda
- Role: Senior FullStack Developer
- Technologies: Google Cloud, Azure, Microsoft Entra, Keycloak, Spring Boot, Java
- Active in production
Philipp Schmidt
Last position:
MS365 Consultant/Solution Architect at Self-employed
- Setup and configuration of an M365 tenant on a hybrid basis
- SSO integration of the existing app infrastructure like Metamost, Huhu, etc.
- License consulting, Entra ID initial configuration, MFA, Conditional Access, Privileged Identity Management
- Intune: initial configuration, Windows 11 Autopilot, iPhone AES
- Takeover of the tenant and preparation of a security audit
- Rollout of iPhones with AES (formerly DEP) as COPE (Corporate Owned, Business Enabled)
- Connecting external customers with enhanced security through Conditional Access
- Consulting on cloud-first strategy and migration to a cloud-only business
- Connecting various apps via SSO/SCIM (e.g. Atlassian, Personio, Adobe)
- On-premises AD: security audit and project management for replacing the local AD (migration of file servers, Navision2016, user clients joined to Entra ID)
- Copilot rollout with connection to external data sources and configuration via Intune
- Support for TISAX and ISO27001 preparation
- Setup and hardening of Entra ID, switching MFA to phishing resistant via Conditional Access
- Intune management for Windows and Apple clients, web enrollment switch to AES, introduction of Autopilot, app management, integration of Microsoft Defender
- Building a device baseline for Windows (COBO) and iOS/Android (BYOD)
- Teams/SharePoint Online: access concepts and integration into Teams
- Maintenance and backup of Entra ID and Intune tenants (drift management)
- M365 backup with Veeam
- Extending Conditional Access policies, introduction of Privileged Identity Management with hardware tokens and an on-premises admin tier concept
- Revision of existing GPOs regarding structure, security, and compliance
- Security audit and hardening of on-premises Active Directory and cloud tenant, SAML VPN, PIM introduction
- Support for the HR department in introducing a booking portal and general system engineering administration & security
- Introduction of Conditional Access and passwordless MFA, platform SSO, Defender for macOS/iOS, macOS compliance with Intune, Code2 signature configuration
Konstantinos Metaxas
Last position:
IT System Engineer at Client belongs to critical infrastructure
- IT infrastructure services
- IT services, networks, Exchange, Office 365 & 2016
- IT documentation
- Collaboration with external partner & managed provider
- Stakeholder management
Christian Trutz
Last position:
JEE Software Engineer, DevOps Engineer at AKDB
- JEE Software Engineer
- DevOps Engineer
- Java, JEE, JBoss/WildFly, Vaadin, CI/CD Pipelines, Jenkins, Maven, Git, Oracle database, MSSQL Server database
Discover over 15,000 top freelancers
Statistics of experts using Microsoft Entra ID
Aggregated from the professional profiles of matched freelancers.
Experience
21 years (Germany: 18 years)
Position duration
1.7 years (Germany: 1.9 years)
Positions per freelancer
13 (Germany: 14)
Top business areas
Information Technology, Operations, Product Development
Top industries
Information Technology, Manufacturing, Healthcare
Certification focus areas
Information Technology, Project Management, Business Intelligence
Bachelor's degree or higher
67% (Germany: 69%)
Master's degree or higher
44% (Germany: 38%)
Doctorate
11% (Germany: 8%)
Certifications per freelancer
3 (Germany: 4)
Most common languages
English, German, French
Speak two or more languages
100% (Germany: 96%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Munich are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Munich using Microsoft Entra ID
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Access control
Microsoft Entra ID is the identity layer for Microsoft 365, Azure, and connected business apps. It is used to manage sign-in, permissions, and secure access across cloud and hybrid systems. Strong specialists turn it into a clean control point instead of a source of friction.
Common work
- Single sign-on for internal and external apps
- Multi-factor authentication and conditional access policies
- App registrations, enterprise applications, and consent flows
- Guest access and external collaboration setup
- Identity hygiene for users, groups, and roles
Where it fits
Entra ID often sits behind finance tools, HR systems, customer portals, and Microsoft 365 environments. In Munich, it is common in companies that need structured access for office teams, partners, and remote specialists. The right setup reduces account sprawl and keeps access rules clear.
Ecosystem skills
A good Microsoft Entra ID specialist understands Azure, Microsoft 365, Intune, MFA, SSO, SCIM provisioning, and PowerShell. They should also know how identity connects to device trust, API permissions, and lifecycle automation. Clean documentation matters as much as configuration.
When to bring help
Companies usually bring in freelance expertise during tenant migrations, security hardening, app onboarding, or identity cleanup. The best professionals can review risky policy combinations, fix broken sign-in paths, and align access design with real business workflows. They work well with security and cloud teams.
What strong specialists do
Strong Microsoft Entra ID professionals design access that users can follow and auditors can understand. They test edge cases, document admin roles, and keep authentication flows stable during change. For complex rollouts, remote work is common, with on-site time in Munich useful for workshops and stakeholder alignment.
Frequently asked questions
Key details about Microsoft Entra ID, drawn from the questions we get asked most.
Microsoft Entra ID is used to control who can sign in to apps, what they can access, and under which conditions. It is central to single sign-on, multi-factor authentication, guest access, and access policy design. Companies use it to reduce password sprawl and keep identity management consistent.
Microsoft Entra ID is the current name for what many teams still call Azure AD or Azure Active Directory. The product changed names, but the core identity functions stayed familiar. When you hire a specialist, make sure they understand both the old and new naming so migrations and documentation stay clear.
Microsoft Entra ID is usually the strongest fit when a company already runs Microsoft 365, Azure, or a large Windows estate. Okta is often weighed for broader cross-vendor identity use, while Google Cloud Identity fits different workspace setups. The right choice depends on the app landscape, security model, and integration depth.
A strong Entra ID specialist usually also knows Azure, Microsoft 365, Intune, conditional access, MFA, and PowerShell. For larger projects, SCIM provisioning, SAML, OAuth, and role-based access design matter too. These skills help when identity touches devices, apps, and user lifecycle automation.
A small Microsoft Entra ID task may only need someone who can set up SSO or adjust access policies. A tenant migration, hybrid identity setup, or security redesign needs deeper hands-on work and careful testing. The more apps and user groups involved, the more important practical rollout experience becomes.
Most Microsoft Entra ID work can be done remotely because it lives in cloud settings, logs, and policy reviews. On-site time in Munich can help for workshops, access reviews, and stakeholder alignment, especially during migration or security projects. Many teams use a mixed setup.
Look for someone who explains trade-offs clearly and documents every change in Microsoft Entra ID. Good specialists test sign-in flows, role assignments, and conditional access before they hand over. They also think about rollback, support handoff, and how the setup will work after the project ends.
A solid Entra ID engagement should leave behind working policies, app registrations, access rules, and clear documentation. Depending on the scope, you may also get migration notes, role definitions, and guidance for support teams. The goal is a setup that stays maintainable after the specialist leaves.
The average hourly rate of freelancers in Munich, Germany who have used Microsoft Entra ID in their recent projects is 96 €, which corresponds to a daily rate of about 765 € based on an 8-hour working day.
Of the freelancers in Munich, Germany who have used Microsoft Entra ID in their recent projects, 67% hold at least a Bachelor's degree, 44% hold at least a Master's degree, and 11% hold a doctorate.
On average, freelancers in Munich, Germany who have used Microsoft Entra ID in their recent projects have 21 years of professional experience, with a single engagement typically lasting around 1.7 years.
The most common languages among freelancers in Munich, Germany who have used Microsoft Entra ID in their recent projects are English (100%), German (89%), and French (22%).
The most common industries among freelancers in Munich, Germany who have used Microsoft Entra ID in their recent projects are Information Technology (94%), Manufacturing (72%), and Healthcare (56%).
The most common business areas among freelancers in Munich, Germany who have used Microsoft Entra ID in their recent projects are Information Technology (100%), Operations (67%), and Product Development (67%).
Main locations of FRATCH Experts, who have recently used Microsoft Entra ID
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Hamburg
Cologne
Frankfurt
Dusseldorf
Essen
Nuremberg