Lab 01 - Identity Risk Baseline
Produce a Graph PowerShell baseline covering MFA, privileged roles, dormant accounts and SMS reliance.
A twelve-lab hardening programme for a Microsoft Entra tenant. Assess, harden, govern, report.
# Track 02 Entra ID Security 12 hands-on labs # prepare → do → prove → explain
Each lab is standalone but builds on the last. Capture evidence as you go, and read the track FAQ for the concepts behind them.
Produce a Graph PowerShell baseline covering MFA, privileged roles, dormant accounts and SMS reliance.
Plan and validate a controlled migration from SMS to Microsoft Authenticator.
Stage, test and activate Conditional Access MFA policies safely with exclusions.
Roll out phishing-resistant methods to your highest-risk roles.
Protect the recovery path and trust surface with SSPR and domain hygiene.
Build dry-run-first lifecycle automation for leavers and contractors.
Replace standing admin privilege with eligibility and approval workflows.
Keep guest and privileged access accountable through recurring reviews.
Protect the route between on-prem AD and Entra.
Connect risk signals to a repeatable response flow.
Convert one-off assessments into reusable evidence packs.
Turn technical results into an actionable board-ready roadmap.
New to Entra ID Security? The knowledge-base article explains every concept in plain English before you touch a keyboard.