
Explore Microsoft Entra ID and conditional access to secure user identities, implement zero-trust security, and practice hands-on labs on MFA, device-based access, Entra ID protection, and sign-in logs.
Understand why identity is the primary attack surface in a cloud-first world, explore identity-based threats like password spray, and see how Microsoft Antwerp protects with zero trust and conditional access.
Explore modern identity attacks, including password spray, MFA fatigue, token theft, and session hijacking, and understand why layered identity security with Microsoft Enterprise Security Controls is essential.
Identity has become the security parameter as attacks evolved. Learn common identity attacks—phishing, password spraying, token theft, and MFA fatigue—and how to detect and mitigate them with Microsoft Entra.
Explore how password spray attacks test a password across many accounts, differ from brute force, and why they are efficient; implement strong passwords, MFA, and conditional access to mitigate risk.
Explore how authentication tokens enable seamless access within Microsoft Entra. Understand how token theft and session hijacking threaten cloud resources, and how conditional access and continuous evaluation protect sessions.
Implement defense in depth with strong authentication, conditional access, and least privilege to defend against password spray, token theft, and session hijacking while monitoring sign-ins and enforcing zero trust.
Explore the core capabilities of Microsoft Entra ID, including users, groups, authentication, authorization, and roles. Set up a ready lab environment for hands-on labs, including multi-factor authentication and conditional access.
Explore how Microsoft Entra ID protects identities and enables secure access to cloud and on-prem resources. Discover MFA, conditional access, and authentication monitoring in modern identity and access management.
Explore core identity objects in Microsoft Entra ID, including user accounts, security groups, and Microsoft 365 groups, and understand administrative roles and the principle of least privilege.
Differentiate authentication from authorization in Microsoft Entra, verifying identity through credentials or MFA, then granting access based on permissions, policies, and device risk.
prepare the Microsoft enter lab environment within a dedicated Microsoft 365 tenant, establishing administrative and standard user accounts, test identities, and baselines for MFA, conditional access, and authentication investigations.
Review the Microsoft Entra lab environment identities, configure admin.user and standard department accounts, enable multi-factor authentication, apply conditional access policies, and prepare the environment for hands-on labs.
Create a realistic lab environment in Microsoft Entra ID by building a standard user, an admin user, and a test attacker, then assign E5 licenses and enable attack simulations.
Learn how multi-factor authentication strengthens Microsoft Entra identity security by configuring MFA, troubleshooting issues, and analyzing sign-in events through hands-on labs to prepare for conditional access.
Explore how Microsoft Entra strengthens identity security by requiring two or more factors—something you know, have, or are—protecting cloud identities with Microsoft Authenticator and security keys.
Understand the Microsoft Entra MFA sign-in flow, from password validation to the MFA challenge and token issuance, plus how sign-in logs aid troubleshooting.
Explore common MFA configuration mistakes and a structured troubleshooting approach for Microsoft Entra ID and conditional access. Examine policy targeting, user registration, and legacy authentication to ensure reliable authentication.
Learn best practices for implementing multi-factor authentication in Microsoft Entra, including number matching, phishing-resistant methods, appropriate authentication strengths, emergency access accounts, user education, and continuous monitoring of sign-in activity.
This lab shows that configuring an mfa method alone does not enforce multi-factor authentication in Microsoft Entra ID. Without an enforcement policy, sign-ins succeed with only the password.
Enforce MFA for a standard user by creating a conditional access policy that requires MFA on all cloud apps, then test and observe the MFA prompt during sign-in.
Explores MFA fatigue, the risks of repeated push-based prompts, and mitigation strategies like number matching, monitoring, and user awareness to strengthen identity protection.
Learn how conditional access in Microsoft Entra uses policy-based controls to evaluate identity, device, location, and risk, enabling context-aware, zero-trust access decisions beyond passwords.
Learn how conditional access signals—user or group targeted, target resource, device state, location, sign-in risk, and user risk—combine to determine access decisions and underpin every policy.
Microsoft Entra evaluates every applicable conditional access policy during sign-in, enforcing combined requirements such as MFA and device compliance. It also offers report-only mode to test policy impact before production.
Identify common conditional access mistakes, including incorrect targeting, unintended exclusions, and overlapping policies, and apply a structured troubleshooting approach using Microsoft Entra sign-in logs to resolve access issues.
Learn how conditional access evaluates authentication requests, applies policies with report-only mode, reviews sign-in logs, and implements least privilege, emergency access, named locations, and continuous monitoring to reduce risk.
Explore why a conditional access policy may not apply at sign-in, and learn to diagnose misconfigurations, test impacts on MFA prompts, and verify correct policy enforcement.
Explore how multiple conditional access policies in Microsoft Entra ID interact; see how a blocking policy can be skipped when location conditions don't match, and how to fix it.
Understand how a misconfigured conditional access policy can cause an admin lockout, and learn to create a backup admin (break glass) account, test the policy, and recover access safely.
Explore how Microsoft Entra ID and Intune enable device-based access control in a zero trust model by evaluating device trust and enforcing compliance through compliant devices, with hands-on labs.
Explore why device trust is essential to zero trust, and how Microsoft Entra and Intune distinguish trusted and untrusted devices to inform access decisions based on device posture and compliance.
Explore Microsoft Entra-registered, Entra-joined, and hybrid Entra-joined devices, learn how each creates a device identity for authentication, management with Intune, and conditional access in cloud and on-premises environments.
Learn how Microsoft Entra uses Intune compliance and device filters during authentication to evaluate multiple signals and enforce access in a zero-trust model.
Enforce device-based access with well-designed compliance policies and continuous monitoring. Manage the device lifecycle, support BYOD, and apply zero-trust principles to secure access.
Learn how conditional access evaluates user, device, and compliance to block unmanaged devices in a zero-trust framework. See how MFA can be used when device compliance is not met.
Intune evaluates device compliance, and conditional access enforces it, blocking non-compliant devices and granting access only when the device meets policy requirements, as a core zero trust principle.
Explore how Microsoft Entra ID protection automatically detects suspicious authentication activity, protects user accounts from compromise, and applies risk-based conditional access to respond to identity risks.
Discover how Microsoft Entra ID protection analyzes authentication activity and identity signals to detect compromised identities, assign risk levels, and automate responses such as forcing password resets or blocking access.
Learn how risk-based conditional access uses Microsoft Enter ID Protection to automatically enforce controls based on user and sign-in risk, with automated remediation via MFA, password resets, or blocks.
Investigate identity risks by examining risky users and sign-ins, reviewing risk level, detections, authentication activity, location, IP address, and device details. Correlate data from multiple sources to decide remediation actions.
Learn best practices for identity protection with risk-based policies, automated remediation, multi-factor authentication, and continuous monitoring to support zero-trust and secure sign-ins.
Explore identity-based sign-in analysis with Microsoft Android ID protection, examining authentication telemetry, sign-in logs, and how unusual activity from different IPs or locations is assessed for risk in zero trust.
Explore how Microsoft Entra ID protection and risk-based conditional access automatically block high-risk sign-ins, differentiate risky sign-ins vs risky users, and enforce zero-trust access.
Explore how session controls extend conditional access after authentication, monitoring active sessions and restricting actions, while integrating conditional access app control with Microsoft Defender for Cloud Apps for real-time visibility.
Learn how Conditional Access App Control monitors active cloud sessions in real time via a reverse proxy with Microsoft Defender for Cloud Apps to enforce session policies and protect data.
Practice active session controls with Microsoft Entra ID and Defender for Cloud Apps to restrict downloads and sensitive actions while monitoring impact in monitor-only mode.
Apply session controls and conditional access app control to protect sensitive cloud apps after authentication, prioritizing Microsoft 365 services and data while enforcing least privilege and monitoring under zero trust.
Explore session-based data protection with conditional access app control and Defender for cloud apps to block downloads from unmanaged devices, illustrating zero-trust data protection in Microsoft 365.
Explore Microsoft Entra sign-in logs, the starting point for authentication investigations, detailing user, device, location, MFA information, and conditional access evaluations.
Apply a structured authentication investigation workflow using Microsoft Entra sign-in logs, conditional access evaluations, and multi-factor authentication troubleshooting to quickly identify the root cause and remediate while preserving security.
Investigate authentication events and conditional access decisions to troubleshoot MFA and strengthen your Microsoft Entra security posture through structured investigation workflows.
Investigate blocked authentication using Microsoft Entra sign-in logs and conditional access evaluation, review policy results, and apply Zero Trust troubleshooting concepts for enterprise identity protection.
Explore simulated password spray and MFA fatigue attacks in a controlled lab, learn how Microsoft Entra detects suspicious activity and identity protection events, and apply remediation via sign-in logs.
Explore identity attack simulations in a safe lab to see how Microsoft Entra detects suspicious activity, reviews authentication events, and guides defenders through investigation, identity protection, and remediation.
Learn how password spray attacks unfold across many accounts and evade lockout. Discover how administrators detect and investigate them using Microsoft Entra sign-in logs, identity protection, and conditional access.
Explore how MFA fatigue attacks use repeated push notifications to bypass authentication and learn to detect, investigate, and remediate these threats with Microsoft Entra.
Contain the attack by blocking sign-ins and revoking sessions while increasing monitoring. Remediate with identity verification, MFA re-registration, password reset, and strengthened conditional access to prevent reattack.
Simulate a password spray across multiple user accounts using the same password and study failed sign-ins and sign-in logs in Microsoft Entra, including IP address, location, and device indicators.
Master Microsoft Entra ID & Conditional Access with 20 Real Enterprise Labs
Are you looking to build practical Microsoft Entra ID and Conditional Access skills that you can apply in real-world enterprise environments?
This course is designed to help you master Microsoft Entra ID through 20 hands-on enterprise labs that simulate real administrative and security scenarios. Whether you're an IT Administrator, Microsoft 365 Administrator, Security Administrator, Security Engineer, or someone looking to strengthen your identity and access management skills, this course will provide the practical experience needed to confidently secure Microsoft Entra environments.
You'll start with the fundamentals of Microsoft Entra ID before progressing to modern authentication, Multi-Factor Authentication (MFA), and Conditional Access. As the course advances, you'll learn how to implement device-based access control using Microsoft Intune, protect identities with Microsoft Entra Identity Protection, investigate authentication events using Microsoft Entra Sign-in Logs, and apply Zero Trust principles to secure organizational resources.
Unlike courses that focus primarily on theory, this training emphasizes real enterprise implementation. Every concept is explained clearly and reinforced through practical demonstrations and hands-on labs so you understand not only how to configure Microsoft Entra features, but also why organizations implement them.
You'll also gain experience investigating authentication events, troubleshooting Conditional Access decisions, and understanding common identity attacks such as Password Spray and MFA Fatigue in a controlled lab environment.
What you'll learn
Microsoft Entra ID Fundamentals
Authentication & Authorization
Multi-Factor Authentication (MFA)
Modern Authentication Methods
Conditional Access
Device-Based Access Control
Microsoft Intune Integration
Microsoft Entra Identity Protection
Authentication Investigation
Microsoft Entra Sign-in Logs
Session Controls
Zero Trust Identity Security
Password Spray & MFA Fatigue Attack Simulations
Identity Security Best Practices
20 Real Enterprise Labs
By the end of this course, you'll have the confidence to deploy, manage, troubleshoot, and secure Microsoft Entra ID using Microsoft's recommended best practices and real-world enterprise scenarios.