ORB-REC-0046
The ForgeRock Engineer will design, configure, and support ForgeRock within a complex workforce IAM environment. The role is critical for enabling federation with Microsoft Entra ID, supporting legacy and modern application authentication, and enabling a phased migration toward Entra ID as the single workforce entry point. Key Responsibilities Engineer and support ForgeRock Access Management (AM) for workforce authentication. Configure and manage authentication flows, federation, and application integrations. Implement and support ForgeRock ↔ Microsoft Entra ID federation (POC and production). Support integrations with RSA, ADFS, and legacy identity systems. Assess applications tightly integrated with ForgeRock and define migration or coexistence strategies. Troubleshoot complex SSO, federation, and authentication issues. Support remediation of legacy or nonstandard authentication patterns. Mandatory Skills & Experience Strong hands on experience with ForgeRock AM (authentication trees, federation, access policies). Deep understanding of SAML 2.0, OAuth 2.0, OpenID Connect (OIDC). Experience integrating ForgeRock with Microsoft Entra ID / Azure AD. Experience in multiIDP enterprise environments. Strong troubleshooting skills across authentication, claims, certificates, and federation flows.