LAB-ID-101 · Cloud and identity foundations

Entra ID, MFA and Conditional Access - design for safe access and recovery.

Identity controls work best when each has a clear purpose: groups scale assignment, roles limit administrative power, MFA strengthens sign-in and Conditional Access applies well-tested conditions without locking out the people who must recover the tenant.

Estimated time: 60 minutes · Browser-only tenant simulation · No sign-in, tenant data or policy changes

Lab summary

Match the control to the risk, then roll it out with proof and recovery.

  • 01
    Separate identity-control concepts.
    Users, groups, roles, authentication methods and Conditional Access controls solve different problems.
  • 02
    Apply least privilege.
    Use group-based assignment and a task-specific role instead of giving broad permanent administrative access.
  • 03
    Plan a safe policy rollout.
    Pilot or report on impact, monitor results, retain governed emergency access and expand through change control.

Training boundary: no live tenant changes

This is a fictional tenant design exercise. It does not request Microsoft credentials, query a directory or configure MFA, roles or Conditional Access. Use documented authority, current Microsoft guidance and a formal rollback/recovery plan before changing a production tenant.

Module 1

Give each identity control a specific job.

A good access design avoids using one broad control everywhere. Work from the resource, user population and risk, then choose the smallest control that achieves the intended outcome.

Identity and group

A user is an identity; a group makes assignment manageable.

Groups support scalable entitlement management and lifecycle actions. They do not automatically give an administrative capability.

Directory role

A role grants administrative capabilities.

Choose the minimum role that matches an approved task. A high-privilege role is not a convenience setting for routine work.

MFA and policy

MFA strengthens sign-in; Conditional Access applies conditions.

Conditional Access can evaluate user, app, device, risk or location signals and apply an access decision in scope.

Student group

Assign learner access to Academy resources through a managed learner group.

Support role

Grant narrowly scoped administration only to approved support personnel with a real operational duty.

Access policy

Evaluate named conditions and require an appropriate grant control after a tested rollout.

Which statement best describes a sound identity design?

Module 2

Design access for a fictional Academy support case.

The training tenant has learners, instructors and a support coordinator. The coordinator needs to manage membership of an approved learning-access group, not take ownership of every directory control.

Fictional tenant scenario

Grant the smallest useful capability.

Simulation only

Role and assignment map

PersonaRegular access needAdministration need
LearnerCourse and lab resources through Learners groupNone
InstructorCourse authoring resources through Instructors groupOnly the approved learning-content task
Support coordinatorSupport portal accessManaged learning-group membership under an approved, limited role/scope
Emergency accessNot for routine operationsGoverned recovery procedure, monitoring and current-policy validation
Which design is the most appropriate for the support coordinator?

Module 3

Plan a Conditional Access rollout that can be observed and recovered.

A policy can improve security and still create a major outage if it is broad, untested or has no recovery plan. Treat it as a governed production change, not a checkbox.

Fictional policy proposal

Require stronger sign-in for a high-value training-administration app.

No policy is created
  • 1
    Define: document the app, target group, intended authentication control, expected exceptions and business owner.
  • 2
    Validate recovery: review governed emergency-access accounts and exclusion/monitoring requirements against current Microsoft and organisation policy.
  • 3
    Pilot or report: start with a defined test population or report-only evaluation so impact appears before blocking users.
  • 4
    Monitor and expand: review sign-in impact, support outcomes and rollback plan under change control before broadening scope.
Emergency access is a resilience control, not a bypass for everyday work. Microsoft publishes current guidance for governed, monitored emergency accounts. Validate the design in your tenant before deploying a policy that could restrict sign-in.
What is the most responsible first implementation sequence?

Module 4

Knowledge check

Answer all seven questions. A score of six or higher marks this browser-only lab as complete.

This assessment checks identity-governance reasoning. It does not configure or validate a real Microsoft Entra tenant.

1. Which construct is best suited to scalable assignment of ordinary learner access?

2. How should a routine administrative need be assigned?

3. What control primarily strengthens authentication at sign-in?

4. What does Conditional Access primarily provide?

5. What rollout pattern reduces Conditional Access lockout risk?

6. Why must a policy design account for emergency access?

7. What is required before a real tenant policy is changed?

Evidence of learning

Create your local completion record.

After completing the checkpoints and assessment, record your name for a printable personal learning record. It is not a Microsoft certification, a tenant design approval or an authorisation to change identity controls.

Skunkworks Academy · Labs

Entra ID, MFA and Conditional Access

This confirms that the learner completed the browser-only learning activities on .

Lab code: LAB-ID-101 · 60 minutes · Fictional tenant design

Local learning record only. It does not verify identity, Microsoft certification, tenant access, policy approval or practical administrative competence.