Course scenario

Lakeview Logistics

A fictional 50-person freight and logistics company migrating from a mix of Google Workspace and on-premises file servers to Microsoft 365. Students act as the M365 administrator — Sarah Chen — building and securing the tenant from scratch over eight weeks. Every lab, policy, and governance decision is made in the context of a real business with real users, a real domain, and real consequences when things go wrong.

The tenant accumulates across the course. Controls configured in Week 1 are enforced in Week 2. SharePoint sites from Week 4 become Teams file tabs in Week 5. DLP policies from Week 7 are tested by the capstone audit in Week 8. Nothing is throwaway.

Key people — Lakeview Logistics
Sarah Chen
IT Administrator
Global Admin
Dev Sharma
IT Support
Helpdesk Admin
Priya Nair
Finance Manager
LL-Finance
Marcus Webb
CEO
LL-Management
Diane Rousseau
CFO
LL-Management
Kevin Park
Sales Lead
LL-Sales
Leila Farrokhzad
Sales Rep
LL-Sales
James Okafor
Operations
LL-Operations
Aisha Mwangi
Operations
LL-Operations
Tom Eriksson
Warehouse
LL-AllStaff
Licence timeline
Wk 1
Business
Standard
trial
Wk 2
Business
Standard
Wk 3
Business
Standard
Wk 4
Business
Standard
Wk 5
+ E5 Security
& Compliance
trial added
Wk 6
Both active
Wk 7
Both active
Wk 8
Both active
Trial expiry watchBusiness Standard trials are 30 days. Students activate the E5 Security & Compliance trial around Week 5 — confirm the Business Standard trial has been converted or extended before adding the E5 add-on. Without an active base licence, the E5 trial has nothing to attach to. Build a "licence health check" step into Week 4 Day 5.
Phase 1 — Weeks 1–2 Foundation & Identity
Week 1 — Foundation
Tenant setup, users & DNS
Spin up the M365 Business Standard trial, verify the nw7.nat-acc.ca subdomain, create all Lakeview Logistics users and security groups, assign licences, and explore the admin centre landscape.
Day 1Tenant architecture, Entra ID, admin centres · Lab 1-A: sign up, domain verify, DNS records
Day 2User accounts, UPNs, licences · Lab 1-B: create all 10 LL users, assign Business Standard
Day 3Groups — M365, security, distribution · Lab 1-C: LL-Finance, LL-IT, LL-Management, LL-Sales, LL-Operations, LL-AllStaff
Day 4Admin roles, delegation, break-glass intro · Lab 1-D: assign Helpdesk/SharePoint admin roles, RBAC review
Day 5Review & Week 1 assessment · Assessment: tenant config, DNS, users, groups, roles
admin.microsoft.comentra.microsoft.comDNS / MX / SPFUPNLicences Assessment Day 5
Week 2 — Identity
MFA, Conditional Access & Identity Protection
Enable MFA across the tenant, build four Conditional Access policies (all starting in Report-only), configure Named Locations, Identity Protection risk policies, and create the break-glass emergency account.
Day 1MFA architecture, authentication methods, SSPR · Lab 2-A: enable MFA, configure auth methods policy, register admin MFA
Day 2Conditional Access — conditions, controls, evaluation · Lab 2-B: CA001 (require MFA, Report-only) + CA002 (block legacy auth, On)
Day 3Named Locations, country restrictions, risk levels · Lab 2-C: trusted IP named location + CA003 (block high-risk countries)
Day 4Break-glass accounts, auth strength, CA What If · Lab 2-D: break-glass account + CA004 (phishing-resistant MFA for admins)
Day 5Review & Week 2 assessment · Assessment: CA policy analysis, sign-in log investigation, break-glass verify
Conditional AccessMFAIdentity ProtectionNamed LocationsSSPRBreak-glass Assessment Day 5
Phase 2 — Weeks 3–4 Core Services
Week 3 — Exchange Online
Email infrastructure & hygiene
Configure Exchange Online from the Exchange Admin Centre — mailboxes, mail flow, anti-spam/phishing, transport rules, shared mailboxes, and email compliance fundamentals.
Day 1Exchange architecture, EAC navigation, mailbox types · Lab 3-A: configure shared mailbox (reception@), room/equipment resources
Day 2Mail flow, connectors, SPF/DKIM/DMARC · Lab 3-B: verify DKIM, configure DMARC policy, test mail flow via Message Trace
Day 3Anti-spam, anti-phishing, Safe Attachments preview · Lab 3-C: configure anti-spam + anti-phishing policies, quarantine management
Day 4Transport rules, disclaimers, MRM retention tags · Lab 3-D: external email warning rule, executive disclaimer, MRM tag
Day 5Review & Week 3 assessment · Assessment: mail flow config, DMARC, transport rule, quarantine investigation
Exchange Admin CentreDKIMDMARCTransport rulesQuarantineShared mailbox Assessment Day 5
Week 4 — SharePoint & OneDrive
File governance & collaboration
Create and govern SharePoint site collections, configure permissions and inheritance, control external sharing, manage OneDrive policies, and set up information architecture that carries forward to Teams in Week 5.
Day 1SharePoint architecture, sites, hubs, content types · Lab 4-A: create Finance, Operations, Sales, and Intranet site collections
Day 2Permissions model, groups, inheritance · Lab 4-B: configure site permissions, break inheritance on Finance library
Day 3External sharing controls, guest access policies · Lab 4-C: restrict Finance site to internal, configure Intranet external sharing
Day 4OneDrive governance, storage quotas, retention settings · Lab 4-D: configure OneDrive policies, set 180-day retention (later formalised in Purview Week 8)
Day 5Review & Week 4 assessment · Assessment: permissions audit, external sharing scenario, OneDrive policy
SharePoint Admin CentrePermissionsExternal sharingOneDriveHub sites Assessment Day 5
Phase 3 — Weeks 5–6 Collaboration & Endpoint Management
Week 5 — Teams & Collaboration
Teams admin, policies & E5 activation
Administer Teams from the Teams Admin Centre — teams, channels, policies, guest access. Activate the E5 Security & Compliance trial mid-week, unlocking Defender for Endpoint, Purview, and advanced compliance for the second half of the course.
Day 1Teams architecture, M365 Group link, channels · Lab 5-A: create LL-AllStaff and Finance teams from existing M365 groups
Day 2Teams policies, messaging governance, app policies + E5 trial activation · Lab 5-B: configure meeting/messaging policies, activate E5 Security & Compliance trial
Day 3Guest access, external federation, monitoring · Lab 5-C: configure guest access, test external collaboration with Finance team
Day 4Teams Phone intro, calling policies, meeting recordings · Lab 5-D: configure calling policy, meeting recording storage and expiry settings
Day 5Review & Week 5 assessment · Assessment: Teams policy scenario, guest access config, E5 licence verification
Teams Admin CentrePolicy packagesGuest accessTeams PhoneMeeting recordings Assessment Day 5 E5 trial activated Day 2
Week 6 — Intune & Endpoint Management
Device enrolment, compliance & app deployment
Configure Microsoft Intune for Windows device management — MDM enrolment, compliance policies, configuration profiles, Windows Update rings, app deployment, and Conditional Access device compliance integration.
Day 1Intune architecture, MDM vs MAM, enrolment methods · Lab 6-A: configure Windows auto-enrolment, enrol WIN-CLIENT-01 via Settings
Day 2Compliance policies, device groups, Defender risk level integration · Lab 6-B: LL-Windows Baseline Compliance policy, device compliance CA policy
Day 3Configuration profiles, KFM (Known Folder Move), Update rings · Lab 6-C: deploy KFM profile, configure Windows Update ring (Semi-Annual)
Day 4App deployment — required, available, Win32 · Lab 6-D: deploy Microsoft 365 Apps as required app to LL-AllStaff group
Day 5Review & Week 6 assessment · Assessment: compliance policy config, non-compliance scenario, app deployment verify
Intune / endpoint.microsoft.comMDM enrolmentCompliance policiesConfig profilesWindows Update rings Assessment Day 5
Phase 4 — Weeks 7–8 Security, Compliance & Capstone
Week 7 — Security & Threat Protection
Defender, DLP & sensitivity labels
Deploy Microsoft Defender for M365 and Defender for Endpoint, configure DLP policies for financial data, create sensitivity labels, and investigate the Priya Nair Finance incident — a phishing-originated file exfiltration used in Week 8 forensics.
Day 1Defender for M365 — Safe Links, Safe Attachments, anti-phishing · Lab 7-A: configure Defender M365 policies, test Threat Explorer
Day 2Defender for Endpoint — onboarding, EDR, vulnerability assessment · Lab 7-B: onboard WIN-CLIENT-01 to MDE, review device health and alerts
Day 3Secure Score, Attack Simulation Training, audit log enable · Lab 7-C: review Secure Score, launch credential harvest simulation, enable unified audit log
Day 4DLP policies — SITs, workloads, policy tips, alert notifications · Lab 7-D: LL-Financial Data Protection policy (Credit Card + Bank Account SITs, 5 workloads)
Day 5Sensitivity labels intro + Week 7 assessment · Lab 7-E: create Confidential/Finance label (header marking, no encryption yet) · Assessment: the Priya Nair incident — threat investigation, containment, control gap analysis
security.microsoft.comDefender for M365Defender for EndpointDLPSensitivity labelsSecure Score Assessment Day 5
Week 8 — Compliance, Governance & Capstone
Purview, eDiscovery, labels deep & capstone
Complete the governance layer — retention policies, eDiscovery with legal hold, audit log forensics, Insider Risk Management, and full sensitivity label encryption with auto-labelling. Ends with a 100-mark live-tenant capstone assessment.
Day 1Retention policies — Exchange, SharePoint, OneDrive, Teams · Lab 8-A: LL-Finance Retention Policy (7 yr) + LL-Exchange Retention Policy
Day 2eDiscovery — cases, legal hold, KQL search, export · Lab 8-B: eDiscovery case for Priya Nair incident, legal hold on Finance content, export package
Day 3Unified audit log — search operators, forensic export, Insider Risk Management · Lab 8-C: reconstruct Week 7 incident timeline, IRM Data Leaks policy
Day 4Sensitivity labels deep — encryption, auto-labelling, SharePoint defaults, DLP label condition · Lab 8-D: add RMS encryption to Confidential/Finance, auto-label policy, Finance library default, DLP label condition
Day 5Review (15 min) + Capstone assessment (90 min) · Capstone: Part A identity/CA (25) · Part B audit log/eDiscovery (25) · Part C label governance (25) · Part D written synthesis — governance gaps (25)
purview.microsoft.comRetention policieseDiscoveryAudit logIRMLabel encryptionAuto-labelling Capstone Day 5 — 100 marks
Assessments at a glance
WeekAssessmentFormatKey skills tested
1Tenant foundationPractical (tenant screenshots)DNS verification, user accounts, group structure, admin role assignment
2Identity & CA investigationPractical + writtenCA policy analysis, sign-in log interpretation, break-glass account, MFA registration
3Exchange Online configPracticalMail flow, DMARC, transport rules, quarantine, shared mailbox
4SharePoint governancePractical + writtenPermissions audit, external sharing scenario, OneDrive policy
5Teams & collaborationPracticalTeams policy, guest access, E5 licence verification, recording settings
6Intune endpoint managementPracticalCompliance policy, non-compliance scenario, app deployment
7The Priya Nair incidentPractical + written (4 parts × 25)Threat investigation, email recall, DLP alert, control gap analysis, hardening
8Capstone — Lakeview LogisticsPractical + written (4 parts × 25)CA investigation, audit log forensics, eDiscovery hold, label governance, written synthesis of governance gaps
MS-102 exam domain alignment
MS-102 DomainWeightCourse coverage
Deploy and manage a Microsoft 365 tenant~20%Weeks 1, 3, 4 — tenant setup, Exchange Online, SharePoint/OneDrive
Implement and manage identity and access~25%Weeks 1–2 — Entra ID, MFA, Conditional Access, Identity Protection
Manage security and threats~25%Weeks 7–8 — Defender for M365/Endpoint, DLP, Secure Score, IRM
Manage compliance~30%Weeks 7–8 — Purview, retention, eDiscovery, sensitivity labels, audit log
Key design principles
The tenant accumulatesNothing is throwaway. Week 1 users appear in Week 6 Intune compliance policies. Week 3 Exchange mailboxes are the source for Week 8 eDiscovery. Week 7's Confidential/Finance label (cosmetic only) becomes an enforcement control in Week 8 Day 4. Students who treat each week as isolated will struggle in the capstone.
Lab before lecture where possibleThe recommended split is ~45 min lecture / 75 min hands-on. M365 admin skills are built in the portal, not on slides. For concepts that require portal context to make sense (CA policy evaluation, DLP policy simulation, IRM signal correlation), keep the lecture tight and let the lab answer the "why."
The Priya Nair incident is the course spineThe Week 7 assessment seeds a Finance file exfiltration event in every student's tenant. Week 8 Days 2–4 use that event as the source material for eDiscovery, audit log forensics, and label governance verification. The capstone adds a second actor (Dev Sharma) to the same investigation. Students who complete Week 7 carefully will have richer forensic data to work with in Week 8.