0:00–0:30
Structured review
0:30–1:40
Assessment
1:40–2:00
Debrief & Week 2 preview
0:00 – 0:30Structured review · 30 min

Week 1 concept review — open-book, instructor-led

Students may have their lab journal open. Instructor walks through each topic area with questions. The goal is to surface gaps before the live-tenant assessment begins.

Tenant & domain What is the difference between the *.onmicrosoft.com domain and the custom domain? What DNS records are required for domain verification? What happens if the MX record is missing?
User accounts What is a UPN? What fields are required when creating a user? What is usage location and why is it required before licence assignment? What does "Block sign-in" do to an account?
Licences What services does M365 Business Standard include? What happens to a user's data when a licence is removed? What is the difference between a licence and a service plan?
Groups What is the difference between a security group and an M365 Group? What gets created automatically when you create an M365 Group? When would you use a dynamic group vs assigned membership?
Admin roles What can a Helpdesk Administrator do that a regular user cannot? What can a Global Administrator do that a Helpdesk Administrator cannot? What is the principle of least privilege?
Admin centres Which admin centre manages email flow rules? Which manages device compliance policies? Which manages sensitivity labels and DLP policies? Which is used for conditional access?
Instructor note: Run the review as rapid-fire questions to the class — not a lecture. 30 seconds per question, cold-call students, accept partial answers and build on them. The goal is not comprehensive coverage but surfacing the two or three concepts that are most shaky before students go live in their tenants. Common gaps at this point: confusing security groups with M365 Groups, not knowing which admin centre manages which service, and UPN vs display name confusion.
0:30 – 1:40Assessment · 70 min · live tenant

Week 1 Assessment — new-hire onboarding scenario

Open-tenant, scenario-based. Students work independently in their own M365 tenant. No documentation beyond the admin centres themselves — no external search, no notes (lab journal permitted for reference). Each task is completed and verified live.

Assessment scenario: Lakeview Logistics has just hired a new employee. Priya Nair (Finance Manager) has submitted the new-hire request. The details are below. As Sarah Chen (IT Manager), you must onboard this employee completely — account, licence, groups, role (if applicable), and documentation — by end of session. A second, independent task then tests your understanding of group management and role boundaries.
Task A — New hire onboarding 40 marks

New hire details (provided on assessment day by instructor):

  • Full name, job title, and department — provided by instructor on assessment day (e.g. "Ryan Kowalski, Logistics Analyst, Operations")
  • Create the user account with a correct UPN following the firstname.lastname@[yoursubdomain] naming convention — 10 marks
  • Set the display name, first name, last name, job title, department, and usage location (Canada) correctly — 5 marks
  • Assign the correct M365 Business Standard licence — 5 marks
  • Add the user to all correct security groups based on their department — 10 marks (LL-AllStaff plus the correct department group)
  • Verify the user can sign in: open a private browser window, sign in as the new user with the temporary password, and change the password — 5 marks
  • Document your steps: in your lab journal, record the exact UPN created, the groups added, the licence assigned, and the sign-in verification result — 5 marks
Task B — Role boundary scenario 30 marks
  • B1 — Role assignment decision (10 marks): The new hire's manager has requested that they be given the ability to reset passwords for their direct reports if the helpdesk is unavailable. Which Entra ID role would you assign? Would you assign it? What are the risks? Assign the role if appropriate and document your decision with reasoning.
  • B2 — Boundary test (10 marks): Using a private browser, sign in as Dev Sharma (Helpdesk Admin). Attempt to: (a) reset the new hire's password — record whether this succeeds. (b) assign a licence to the new hire — record whether this succeeds. (c) view the Security admin centre — record what Dev can and cannot access. Provide screenshots or written observations for each.
  • B3 — Written justification (10 marks): In 3–5 sentences, explain why Lakeview Logistics uses scoped admin roles rather than giving all IT staff Global Administrator access. Reference the specific actions that Dev Sharma cannot perform and explain why those restrictions protect the organisation.
Task C — Tenant structure verification 30 marks
  • C1 — Group membership audit (10 marks): Navigate to each of the six security groups and verify that the membership is correct — all 10 original users plus the new hire are in the right groups. Record any group membership that is incorrect and fix it.
  • C2 — Admin centre identification (10 marks): The instructor will name five tasks (e.g. "configure an email forwarding rule", "set a Teams meeting lobby policy", "view device compliance status", "create a DLP policy", "review a failed sign-in"). For each task, identify the correct admin centre and the navigation path to reach the relevant setting.
  • C3 — Custom domain verification (10 marks): Navigate to admin.microsoft.comSettings → Domains. Confirm your custom subdomain shows status Healthy. Record which DNS records are shown as verified. Explain in one sentence what would happen to email delivery if the MX record were removed.
Assessment rules: All work is performed live in your own tenant. Lab journal is permitted for reference — no external search engines, no AI assistants, no sharing with other students. Tasks are completed in your own tenant and verified by the instructor. If you encounter an error, troubleshoot it — the ability to identify and resolve errors is part of the assessment.
1:40 – 2:00Debrief & Week 2 preview · 20 min

Assessment debrief and Week 2 setup

Week 1 complete. By end of today, every student has: a verified M365 tenant with a custom domain, 10+ licenced user accounts with correct UPNs, six correctly populated security groups, two admin role assignments, and firsthand experience of role boundary behaviour. This is the complete foundation that all seven subsequent weeks build on.
Assessment mark summary
TaskDescriptionMarks
A — New hire onboardingUPN, user properties, licence, group membership, sign-in verification, documentation40
B — Role boundary scenarioRole assignment decision, empirical boundary test, written justification30
C — Tenant structure verificationGroup membership audit, admin centre identification, domain verification30
Total100

Learning outcomes verified by assessment

Provision usersCreate a correctly configured user account with all required fields and a valid UPN
Assign licencesAttach the correct M365 licence plan and verify the user can access services
Manage group membershipAdd a user to all correct security groups and verify membership
Apply least privilegeMake an evidence-based admin role assignment decision with written justification
Navigate admin centresIdentify which admin centre manages each M365 service and navigate to relevant settings
Verify and troubleshootConfirm a new user can sign in and resolve any issues encountered

What you need ready

All 10 user accounts active and verified All six security groups correctly populated Custom domain showing Healthy in admin centre Dev Sharma sign-in credentials known for Task B Lab journal available for reference Microsoft Authenticator installed before Week 2 Day 1
Week 2 →Week 1 Overview