0:00–0:20
Review
0:20–0:35
Tenant tidy
0:35–1:40
Assessment
1:40–2:00
Debrief
0:00 – 0:20 Review · 20 min

Week 2 consolidation — the identity security stack

Connect the four days of work into one coherent security posture. Not re-teaching — synthesising.

Instructor note: Before the session, pre-seed the assessment scenario in student tenants: disable MFA on one user account, add an unknown user to a security group, and create a sign-in from an unexpected location in the audit log (or describe a fabricated incident on the assessment sheet). The assessment works best when students are investigating something real in their own tenant rather than a purely hypothetical scenario.
0:20 – 0:35 Tenant tidy · 15 min

Final self-audit before the assessment window opens

Assessment boundary: At 0:35 no further tenant changes are permitted unless instructed by the assessment sheet. Students work from the current state of their tenant — plus any deliberate pre-seeded changes made by the instructor.
0:35 – 1:40 Assessment · 65 min

Week 2 assessment — the Lakeview Logistics identity incident

Students receive the assessment sheet describing an overnight identity security incident at Lakeview Logistics. They must investigate using audit logs and sign-in logs, remediate the damage, strengthen the configuration based on what they found, and provide a written incident report.

SectionWhat is assessedMarks
Section A — Incident investigation Students use Entra sign-in logs and audit logs to reconstruct what happened. Navigate to specific log locations, filter for the incident window, and document findings. 25 pts
Section B — Remediation actions Students take specific remediation steps: revoke sessions, reset a compromised account, review and correct MFA state, verify group membership integrity, and check CA policy state. 30 pts
Section C — Configuration hardening Based on the incident, students identify a gap in the Week 2 security configuration and implement a specific hardening improvement — either enabling a CA policy, tightening an SSPR method, or adjusting a PIM role setting. 20 pts
Section D — Written incident report A structured written incident report: what happened, how it was detected, what was done, and what recommendations prevent recurrence. Closed-notes. Assesses synthesis, not recall. 25 pts
Instructor note: The assessment scenario is built around a fabricated overnight incident — a Lakeview Logistics user account (Kevin Park, Sales Manager) was accessed from an unexpected location, MFA was bypassed (because Kevin hadn't completed MFA registration), a new user was added to LL-AllStaff, and a distribution list email address was changed. Students investigate, remediate, and report. The "pre-seeded" changes in student tenants make Section B a live remediation exercise rather than a hypothetical one.
1:40 – 2:00 Debrief · 20 min

Assessment debrief & Week 3 preview

Assessment rubric — marking guidance
CriterionFull marksPartialNo marks
Section A — InvestigationCorrect log locations used, incident timeline reconstructed accurately with evidence, all findings documented with navigation pathsCorrect logs used but timeline incomplete or evidence missingLogs not used or incorrect location, findings not documented
Section B — RemediationAll required actions completed correctly, each step documented with what was done and why, tenant state verified after each actionMost actions completed but one missing or incorrectly executedFewer than half of required actions completed
Section C — HardeningCorrect gap identified based on the incident, appropriate hardening step selected and implemented, reasoning explainedGap identified but hardening step incorrect or only partially implementedGap not identified or wrong hardening step applied
Section D — Written reportAll four elements present (what happened, how detected, what was done, recommendations), technically accurate, written clearlyThree of four elements present, or all present but technically inaccurate in one areaFewer than three elements present or fundamental technical misunderstanding
Learning outcomes — by end of Week 2, students can…
Build an M365 security baselineConfigure roles, MFA, CA policies, SSPR, and PIM from scratch on a live tenant
Investigate an identity incidentUse sign-in logs and audit logs to reconstruct what happened and when
Remediate a compromised accountRevoke sessions, reset credentials, verify MFA state, and check group membership integrity
Write an incident reportDocument a security event with timeline, findings, actions taken, and preventive recommendations
Connect security controls to riskExplain which control prevents which attack and identify the gap that allowed an incident to occur
Week 3, Day 1 →Week 2 Overview