← Вакансіі

TechKher Discovery Platform (SaaS)

Бюджэт: $300.0 FIXED / ⭐ 0.00 (0) India

node.js, react-js, docker, saas, python, microsoft-windows-powershell, microsoft-active-directory

Preferred qualifications

  • Talent type: Agency
  • Experience: Intermediate
  • English: Fluent
  • Job Success: 90%+
  • Min. earnings: $10,000+
TechKher Services is building a commercial SaaS environment discovery platform. It will be sold and delivered from our website as a hosted product. The platform connects to a customer's Microsoft cloud tenant — and, in hybrid deployments, their on-premises infrastructure — and produces a complete, structured inventory of the environment. The primary market is merger & acquisition technical due diligence and pre-migration assessment: the situation where a business has acquired another business and needs a defensible, comprehensive picture of what they've just bought before planning integration. We are not starting from zero. We have a working desktop discovery tool, built in Python with a PowerShell orchestration engine, already proven against live production tenants. Its Exchange Online, Entra ID, SharePoint, mail flow and application discovery modules are debugged and running today. That codebase and its PowerShell discovery logic will be handed to the selected agency at kickoff as the foundation. Your job is to re-platform it as a multi-tenant SaaS product and extend coverage to the full scope below — not to reinvent the discovery logic we've already proven. Critical constraint: the platform is 100% read-only. It must never create, modify, or delete any object in a connected environment. Every consent scope requested must be read-only. This is a product guarantee we make to customers and it is non-negotiable. Part 1 — Microsoft Cloud Discovery (Complete Coverage) The requirement is everything. If Microsoft exposes it in a cloud service and it's relevant to understanding or migrating an environment, we want it inventoried. Entra ID / Identity Users and groups, with sync source (cloud-only vs directory-synced), attribute completeness, UPN suffix inventory Administrative units, group types (security, M365, dynamic, mail-enabled), dynamic membership rules MFA registration and enforcement state, per-user authentication methods, passwordless / FIDO2 / Windows Hello adoption Sign-in activity, last successful sign-in, stale and never-used accounts Conditional Access policies with full condition, control, session and named-location detail — plus report-only policies Authentication methods policy, authentication strengths, legacy auth usage Directory role assignments, PIM eligible and active assignments, PIM policy settings, access reviews Guest / B2B users, external collaboration settings, cross-tenant access policies, B2B direct connect Enterprise applications, app registrations, service principals, OAuth2 consent grants, app roles Sensitive and high-risk scope flagging, credential expiry on app registrations Identity Protection risk detections, risky users and sign-ins (P2) Entitlement Management: access packages, catalogs, connected organizations Custom security attributes, self-service password reset and group configuration Tenant branding, licensing model, domain inventory and verification state Exchange Online Mailbox inventory — user, shared, room, equipment, discovery, scheduling — sizes, item counts, quotas, archive and auto-expanding archive state Mailbox permissions: Full Access, Send As, Send on Behalf, folder-level and calendar delegates Auto-forwarding, inbox rules with external forwarding, mailbox audit configuration Distribution groups, mail-enabled security groups, dynamic distribution groups, M365 groups, mail contacts, mail users Mail flow: transport rules with conditions/actions/exceptions, inbound and outbound connectors, accepted and remote domains Anti-spam, outbound spam, anti-malware, anti-phishing, Safe Links, Safe Attachments policies and rule associations Retention policies and tags, litigation and in-place holds, journaling rules Mobile device policies and mailbox device inventory, ActiveSync and OWA policies Address lists, offline address books, email address policies Public folder hierarchy and mailboxes Organisation config, sharing policies, availability address spaces Message trace summary statistics and mail volume profile SharePoint Online & OneDrive for Business Site inventory: template, storage used and quota, last activity, lock state, hub associations Site collection administrators, group and permission structure, unique permission inventory Tenant and site-level external sharing configuration, anonymous link policy and expiry Sharing links inventory and external user access exposure OneDrive inventory per user, storage consumption, sharing configuration, orphaned OneDrives Term store / managed metadata, content types, site designs and scripts Retention and DLP policy application, sensitivity label application on sites Storage trend and growth profile, largest sites and libraries Access control policies (unmanaged device, IP location), OneDrive sync restrictions Microsoft Teams Teams inventory: membership, owners, guests, privacy, orphaned and inactive teams Channels — standard, private, shared — with membership and associated site Teams policies: messaging, meeting, calling, live events, app permission and setup, app catalog Teams Phone: voice routing, dial plans, call queues, auto attendants, phone number inventory, emergency addresses Federation and external access configuration, guest access settings Teams apps installed and app permission grants Usage and activity profile per team Microsoft Intune / Endpoint Manager Managed device inventory: ownership, platform, OS build, enrolment type, compliance state, last check-in, encryption state BitLocker: encryption status per device, recovery key escrow presence, BitLocker policy configuration, FileVault equivalent for macOS Compliance policies with full setting detail and assignment scope Device configuration profiles, settings catalog policies, administrative templates, security baselines Endpoint security policies: antivirus, firewall, disk encryption, EDR, attack surface reduction, account protection App protection and app configuration policies (MAM), managed app inventory Application inventory, deployment types, assignment and install status Windows Autopilot profiles and device registrations Enrolment restrictions and configurations, device categories Windows Update rings, feature update and driver update profiles, Windows Update for Business reports Conditional Access integration, device compliance dependencies Scripts and remediations, Endpoint Analytics Apple / Google enrolment token and certificate expiry (APNs, VPP, DEP) Microsoft Defender Suite Defender for Office 365: policy inventory, threat protection status, Safe Links/Attachments coverage, quarantine policy, priority accounts Defender for Endpoint: onboarded device inventory, onboarding method, sensor health, ASR rule configuration and exclusions, vulnerability and exposure summary, device risk levels Defender for Identity: sensor inventory and health, monitored domain controllers, detection configuration Defender for Cloud Apps: connected apps, discovered shadow IT summary, policy inventory, OAuth app governance Defender for Cloud: secure score, recommendations, regulatory compliance posture, defender plan coverage per subscription Microsoft Secure Score with full control breakdown and improvement actions Incidents and alerts summary, custom detection rules Threat and vulnerability management: exposed devices, missing patches, software inventory Microsoft Purview / Compliance DLP policies, rules and locations across all workloads, including endpoint DLP Sensitivity labels, label policies, auto-labelling policies, encryption and marking configuration Retention policies, retention labels and label policies, adaptive scopes Records management, disposition review configuration eDiscovery cases (Standard and Premium), holds and search inventory Communication compliance policies, insider risk policies Information barriers, segments and policies Unified audit log state, retention policy, audit log search configuration Data lifecycle management, Compliance Manager score and assessments Data classification: trainable classifiers, sensitive info types, content explorer summary Power Platform Environment inventory: type, region, Dataverse presence, security group scoping Power Apps inventory (canvas and model-driven), owners, sharing, connector usage Power Automate flow inventory, owners, connectors, run history summary, orphaned flows Custom and standard connector inventory, connection references DLP policies and connector classification per environment Power BI workspace inventory, datasets, gateways, capacity assignment, sharing exposure Power Pages / Portals inventory Capacity consumption and licence allocation Dynamics 365 Instance and environment inventory with version and region Deployed applications and solutions, managed vs unmanaged, dependency mapping Security roles, business units, teams, field-level security profiles Entity/table inventory, custom entities, record volumes Integrations, plug-ins, custom workflows and Azure-registered services Licence assignment and consumption per app Note: this uses the Dataverse Web API and Power Platform Admin API, not Microsoft Graph. Your proposal should reflect that you know this. Microsoft 365 Core / Tenant Tenant configuration, organisation profile, verified domains and DNS state Licensing: SKU inventory, assigned vs available, service plan breakdown, group-based licensing, licence waste analysis (unlicensed enabled users, licensed disabled users, duplicate/overlapping SKUs) Service health and message centre summary Microsoft 365 Groups inventory, expiration and naming policies, creation restrictions Viva module inventory where deployed (Engage/Yammer, Insights, Learning, Connections) Copilot licence assignment and readiness signals Booking, Forms, Planner, To Do, Stream, Whiteboard and Loop tenant configuration Usage analytics: per-workload adoption and active user profile Azure Tenant, management group hierarchy, subscription inventory with state and offer type Resource group and full resource inventory by type, location and tag RBAC: role assignments at every scope, custom role definitions, inherited and PIM-eligible assignments Azure Policy: assignments, initiatives, compliance state, exemptions Cost and consumption summary per subscription and resource group Compute: VMs with size, OS, disks, extensions, availability configuration; VM Scale Sets; Azure Virtual Desktop host pools, session hosts, app groups, workspaces, FSLogix configuration Storage: storage accounts, replication, access tiers, public access configuration, lifecycle policies Networking: VNets, subnets, NSGs and rules, route tables, peerings, VPN and ExpressRoute gateways, Azure Firewall, Front Door, App Gateway, Private Endpoints, DNS zones Data: SQL servers and databases, Cosmos DB, Storage, managed instances, backup and DR configuration App services: App Service plans, web apps, function apps, containers, AKS clusters Identity & security: managed identities, Key Vaults with access policy/RBAC model and secret expiry, Defender for Cloud plan coverage Operations: Log Analytics workspaces, retention, diagnostic settings coverage, Automation Accounts, Recovery Services Vaults and backup item state Resource locks, tags and tagging compliance, orphaned resources (unattached disks, unused IPs, empty resource groups) Part 2 — On-Premises Discovery (Hybrid Deployments) Read this section carefully — this is where most bidders fail. On-premises environments are not reachable from a cloud-hosted SaaS backend. Domain controllers, Exchange servers and SharePoint farms sit behind corporate firewalls with no inbound path from the internet. Required approach: a downloadable collector agent — a signed PowerShell module or lightweight compiled binary — that the customer runs inside their own network under a delegated read-only account. It performs local discovery, produces structured JSON, and either uploads the result to the platform over an authenticated outbound HTTPS channel or is manually imported by the customer. The collector must: Run under a standard domain user with delegated read rights — not require Domain Admin Be code-signed and verifiable, with a published hash — enterprise customers will scan it before running Show clear local progress and produce a readable local log Support fully offline operation with manual JSON upload, for air-gapped or restricted networks Never transmit anything the customer hasn't seen — the JSON output must be inspectable before upload Be self-contained where possible, minimising module prerequisites on the target server If your proposal doesn't address this architecture, I will assume you haven't understood the requirement and won't shortlist you. Active Directory — Full Discovery Forest and domain topology, functional levels, schema version, FSMO role holders Domain controller inventory: OS, roles, GC status, replication status and errors, SYSVOL replication method (FRS vs DFSR) Sites, subnets, site links, site link bridges, replication topology and latency Complete OU structure with delegation and inheritance blocking Group Policy Objects: inventory, links, scope, WMI filters, security filtering, delegation, full settings export, unlinked and orphaned GPOs User, group, computer, contact, service account and gMSA inventory with attribute analysis Stale, disabled, never-logged-on, password-never-expires, no-password-required and SPN-bearing accounts Privileged group membership: Domain Admins, Enterprise Admins, Schema Admins, Account Operators, Backup Operators, plus nested membership expansion AdminSDHolder, protected accounts, Kerberos delegation configuration (unconstrained, constrained, RBCD) Trust relationships: direction, type, transitivity, SID filtering, selective authentication DNS: zones, AD-integrated zones, conditional forwarders, scavenging configuration, stale records Password, account lockout and fine-grained password policies Certificate Services: CA inventory, templates, enrolment permissions, certificate expiry LAPS deployment state, DFS namespaces, file share inventory where in scope Schema extensions and custom attributes Exchange Server On-Premises Organisation configuration, Exchange version, CU and security update level per server Server inventory, roles, DAG configuration, database copy status and health Mailbox databases: size, mailbox count, white space, log truncation and backup state, quota configuration Full mailbox inventory with sizes, item counts, permissions, delegates, forwarding and archive state Public folder hierarchy, public folder mailboxes and permissions Send and receive connectors, accepted domains, email address policies, address lists, offline address books Transport rules, journal rules, transport configuration and message size limits Virtual directory configuration with internal and external URLs, authentication methods Certificate inventory with subject, SAN and expiry Retention policies and tags, mailbox and litigation holds ActiveSync device inventory and policies Hybrid configuration: HCW output, hybrid mail flow connectors, OAuth and federation trust state, free/busy configuration, MRS proxy state, Exchange hybrid version compatibility SharePoint Server On-Premises Farm topology, servers and roles, build and patch level, farm health Web applications, content databases with size, site count and status Site collection inventory: template, storage, quota, last modified, owners, locks Site and library inventory with permission structure and unique permissions Service applications: Search, User Profile, Managed Metadata, BCS, Secure Store, Workflow Installed solutions (WSP), features, add-ins and customisations Authentication configuration: Classic vs Claims, provider configuration, SAML/ADFS trust Alternate access mappings, host-named site collections Search topology, crawl schedules and content sources Workflow inventory (SP 2010/2013 workflows — flag for migration risk) Hybrid configuration: hybrid search, hybrid sites, cloud SSA state Note: requires Shell Admin rights on the farm and local execution on a farm server. Scope this accordingly. Hybrid Identity Entra Connect / Cloud Sync: version, server, sync scope, filtered OUs and domains Sync rules — standard and custom — attribute flow mappings, precedence and modifications Scheduler state, sync cycle interval, last sync time, export/import errors Sign-in method: Password Hash Sync, Pass-through Authentication, Federation, Certificate-based PTA agent inventory, version and health Seamless SSO state and computer account configuration ADFS: farm topology and version, relying party trusts, claims provider trusts, claim issuance rules, token signing and decrypting certificates with expiry and auto-rollover state, WAP topology, endpoints, access control policies, extranet lockout Password writeback, device writeback, group writeback configuration Hybrid Azure AD Join / Entra Join state, SCP configuration Duplicate and conflicting object detection between on-premises and cloud Sync errors: duplicate attributes, invalid characters, orphaned objects, quarantined objects Source anchor configuration (ObjectGUID vs ms-DS-ConsistencyGuid) Other On-Premises (where present in hybrid scope) Skype for Business Server topology and coexistence configuration On-premises file servers targeted for SharePoint/OneDrive migration — share inventory, size profile, permission structure, path length and illegal character analysis Part 3 — M&A Due Diligence & Migration Planning Layer This is what makes it a product rather than a reporting script. Discovery data must be transformed into decisions. Cross-environment reconciliation — cloud and on-premises data correlated within a single engagement view; source and target tenant comparison where both are connected Collision detection — duplicate UPNs, conflicting SMTP addresses, existing guest or contact objects in the target tenant referencing the acquired entity's domain, overlapping domain claims, duplicate group names Migration risk register — unsupported Exchange or SharePoint versions, expiring certificates, unresolved sync errors, legacy authentication dependency, deprecated features in use, path-length and character issues, workflow and customisation blockers Licensing gap analysis — what the acquired organisation holds today vs what the combined entity would need, with waste and overlap identified Security exposure summary — external sharing, anonymous links, guest sprawl, over-privileged and stale privileged accounts, legacy auth, unmanaged devices, missing MFA Complexity and effort scoring — per-workload indication of migration difficulty, with the drivers behind each score exposed Delta comparison — re-run a discovery against the same environment and diff it against a prior run, so change over time is visible Engagement-scoped storage — every run stored against a named engagement, retained, versioned and retrievable Part 4 — SaaS Platform Requirements This is a commercial product on our website, not an internal tool. It must be built accordingly. Multi-Tenant Microsoft Integration Multi-tenant Entra ID app registration (signInAudience: AzureADMultipleOrgs) with an admin consent flow that onboards a new customer tenant cleanly Publisher verification configured against our Microsoft Partner Center MPN ID — customers will not consent to an unverified app Token acquisition per customer tenant via client credentials, with our credentials held in Azure Key Vault and never exposed client-side Read-only scopes only, with the full requested permission set documented and presented to the customer before consent Graceful handling of consent revocation and token failure Per-tenant throttling awareness — Graph throttles per tenant per app; concurrent multi-customer runs must not cascade Platform Multi-Tenancy Customer account model: organisations, users, roles (owner / analyst / read-only) Strict data isolation between customers — enforced at the data layer, not just in application logic Engagement model: a customer can run multiple engagements, each scoped to a target environment Invite and team management, SSO login option for our own customers (Entra ID / Google) Job Orchestration Fully asynchronous — a complete run takes hours; queueing, worker scaling, progress reporting, resumability and cancellation are all required Per-module collection status: complete / partial / unavailable, with an explicit reason. Silent gaps are unacceptable. If a module can't run because of missing licensing or insufficient permissions, the report must say exactly that Retry with backoff on throttling, circuit-break on authorisation failure Run history, logs and diagnostics visible to the customer Output — all generated from a single run, no manual re-entry Interactive dashboard — the primary product surface, with drill-down per module Exports — Excel (multi-sheet, formatted, filterable), PDF, Word, and self-contained browser-viewable HTML with sortable/filterable tables Raw JSON per module — versioned, stored per engagement, downloadable White-label option — customer logo and branding on exported reports Reports must be generated from the stored JSON data layer, never from live API calls — any format must be regenerable without re-running discovery. Commercial & Data Protection Subscription / plan model with usage limits (engagements, runs, retained history) — Stripe integration Encryption at rest and in transit, tenant-scoped encryption where practical Configurable data retention and hard-delete on customer request Platform audit log — who ran what, against which environment, when Content is never collected: no message bodies, file contents, chat history or document contents Credentials, secrets and tokens never written into stored data or generated reports Architecture must support a future SOC 2 / ISO 27001 posture and Microsoft 365 Certification — we don't need certification at launch, but we need not to have to rebuild for it Preferred Stack Flexible if you justify your choice, but our existing codebase and expectations point to: Discovery engine: PowerShell 7 — Microsoft Graph SDK, Exchange Online Management v3, PnP PowerShell, Az, MSCommerce, plus ActiveDirectory, GroupPolicy, Exchange Management Shell and SharePoint Server cmdlets in the collector agent Backend: Python or Node.js, containerised Frontend: React Data: PostgreSQL with JSONB for raw module output; blob storage for exports Queue: Redis / Celery, or equivalent Hosting: Azure, containerised and IaC-defined Collector agent: signed PowerShell module, or Go/.NET binary if you make a case for it What We Provide The existing working codebase — Python desktop application with a PowerShell orchestration engine, with production-proven modules covering Exchange Online, Entra ID, SharePoint, mail flow, applications and OAuth, plus capability pre-flight detection, throttle handling with exponential backoff, and multi-format export. This is real, debugged code that has run against live tenants. It is the starting point Production PowerShell and Graph API discovery scripts from real client engagements Test tenant access Detailed per-module field specifications Fast, consolidated feedback — batched review comments, not drip-fed Out of Scope Any write, modify, remediation or configuration-change capability — read-only is absolute Content collection: message bodies, file contents, chat history, document contents Actual migration execution — this is assessment and planning only Certification audits (SOC 2 / ISO / Microsoft 365 Certification) — architecture must support them, achieving them is separate
Адкрыць заказ

AI-чарнавік адказу

Згенеруйце кароткі cover letter па гэтай вакансіі. Перад адпраўкай адрэдагуйце.

Увайдзіце, каб згенерыраваць AI-чарнавік.

Увайсці