Identity and group
A user is an identity; a group makes assignment manageable.Groups support scalable entitlement management and lifecycle actions. They do not automatically give an administrative capability.
LAB-ID-101 · Cloud and identity foundations
Identity controls work best when each has a clear purpose: groups scale assignment, roles limit administrative power, MFA strengthens sign-in and Conditional Access applies well-tested conditions without locking out the people who must recover the tenant.
Estimated time: 60 minutes · Browser-only tenant simulation · No sign-in, tenant data or policy changes
Lab summary
This is a fictional tenant design exercise. It does not request Microsoft credentials, query a directory or configure MFA, roles or Conditional Access. Use documented authority, current Microsoft guidance and a formal rollback/recovery plan before changing a production tenant.
Module 1
A good access design avoids using one broad control everywhere. Work from the resource, user population and risk, then choose the smallest control that achieves the intended outcome.
Identity and group
A user is an identity; a group makes assignment manageable.Groups support scalable entitlement management and lifecycle actions. They do not automatically give an administrative capability.
Directory role
A role grants administrative capabilities.Choose the minimum role that matches an approved task. A high-privilege role is not a convenience setting for routine work.
MFA and policy
MFA strengthens sign-in; Conditional Access applies conditions.Conditional Access can evaluate user, app, device, risk or location signals and apply an access decision in scope.
Assign learner access to Academy resources through a managed learner group.
Grant narrowly scoped administration only to approved support personnel with a real operational duty.
Evaluate named conditions and require an appropriate grant control after a tested rollout.
Module 2
The training tenant has learners, instructors and a support coordinator. The coordinator needs to manage membership of an approved learning-access group, not take ownership of every directory control.
Fictional tenant scenario
| Persona | Regular access need | Administration need |
|---|---|---|
| Learner | Course and lab resources through Learners group | None |
| Instructor | Course authoring resources through Instructors group | Only the approved learning-content task |
| Support coordinator | Support portal access | Managed learning-group membership under an approved, limited role/scope |
| Emergency access | Not for routine operations | Governed recovery procedure, monitoring and current-policy validation |
Module 3
A policy can improve security and still create a major outage if it is broad, untested or has no recovery plan. Treat it as a governed production change, not a checkbox.
Fictional policy proposal
Module 4
Answer all seven questions. A score of six or higher marks this browser-only lab as complete.
Evidence of learning
After completing the checkpoints and assessment, record your name for a printable personal learning record. It is not a Microsoft certification, a tenant design approval or an authorisation to change identity controls.
Skunkworks Academy · Labs
This confirms that the learner completed the browser-only learning activities on .
Local learning record only. It does not verify identity, Microsoft certification, tenant access, policy approval or practical administrative competence.