0:00–0:20
Review
0:20–0:35
Tenant tidy
0:35–1:40
Assessment
1:40–2:00
Debrief
0:00 – 0:20
Review · 20 min
Week 2 consolidation — the identity security stack
Connect the four days of work into one coherent security posture. Not re-teaching — synthesising.
- The layered security model — draw the stack on the board: Entra ID roles (who can administer) → MFA & auth methods (how users prove identity) → Conditional Access (under what conditions access is granted) → SSPR (self-service recovery) → PIM (just-in-time privilege). Each layer addresses a different attack surface. Ask: "Which layer would stop a password spray attack? Which layer would stop an attacker who already has valid credentials?"
- The Secure Score connection — briefly navigate to security.microsoft.com → Secure Score. Show how the controls configured this week map to specific score improvements. This previews Week 7 (Defender and Secure Score) and gives students a quantified view of the security posture they've built.
- What the E5 trial will unlock — briefly flag that three Week 2 features were gated: CA policy enforcement (P1), dynamic group rules (P1), and PIM activation (P2). When E5 is added in Week 5, students return and activate all of these. Day 3 CA policies flip from Report-only to Enabled. PIM activation is tested live.
- 5 minutes open Q&A — concepts only, not assessment answers
Instructor note: Before the session, pre-seed the assessment scenario in student tenants: disable MFA on one user account, add an unknown user to a security group, and create a sign-in from an unexpected location in the audit log (or describe a fabricated incident on the assessment sheet). The assessment works best when students are investigating something real in their own tenant rather than a purely hypothetical scenario.
0:20 – 0:35
Tenant tidy · 15 min
Final self-audit before the assessment window opens
- All 10 users have MFA Enabled (per-user MFA) — verify in Entra ID Protection → MFA
- SSPR enabled for All users with correct method settings
- All 5 role assignments from Lab 2-A confirmed — check each user's Assigned roles tab
- All 4 CA policies present in Report-only mode — none accidentally Enabled or Disabled
- Two named locations present — Trusted Network and Allowed Countries
- PIM eligible assignments for Sarah Chen and Dev Sharma confirmed
- Lab Journal entries complete for Days 1–4
Assessment boundary: At 0:35 no further tenant changes are permitted unless instructed by the assessment sheet. Students work from the current state of their tenant — plus any deliberate pre-seeded changes made by the instructor.
0:35 – 1:40
Assessment · 65 min
Week 2 assessment — the Lakeview Logistics identity incident
Students receive the assessment sheet describing an overnight identity security incident at Lakeview Logistics. They must investigate using audit logs and sign-in logs, remediate the damage, strengthen the configuration based on what they found, and provide a written incident report.
| Section | What is assessed | Marks |
| Section A — Incident investigation |
Students use Entra sign-in logs and audit logs to reconstruct what happened. Navigate to specific log locations, filter for the incident window, and document findings. |
25 pts |
| Section B — Remediation actions |
Students take specific remediation steps: revoke sessions, reset a compromised account, review and correct MFA state, verify group membership integrity, and check CA policy state. |
30 pts |
| Section C — Configuration hardening |
Based on the incident, students identify a gap in the Week 2 security configuration and implement a specific hardening improvement — either enabling a CA policy, tightening an SSPR method, or adjusting a PIM role setting. |
20 pts |
| Section D — Written incident report |
A structured written incident report: what happened, how it was detected, what was done, and what recommendations prevent recurrence. Closed-notes. Assesses synthesis, not recall. |
25 pts |
Instructor note: The assessment scenario is built around a fabricated overnight incident — a Lakeview Logistics user account (Kevin Park, Sales Manager) was accessed from an unexpected location, MFA was bypassed (because Kevin hadn't completed MFA registration), a new user was added to LL-AllStaff, and a distribution list email address was changed. Students investigate, remediate, and report. The "pre-seeded" changes in student tenants make Section B a live remediation exercise rather than a hypothetical one.
1:40 – 2:00
Debrief · 20 min
Assessment debrief & Week 3 preview
- Walk through Section A — how the sign-in log and audit log tell the story of what happened and in what order
- Discuss Section C — what hardening step was the correct response to this incident? Surface the range of approaches taken and why some are more targeted than others
- Ask: "Kevin Park's account was accessed because he hadn't registered MFA yet. What process should have existed to prevent this?" — surface the gap between enabling MFA and ensuring registration actually happens
- Ask: "Looking at the Secure Score now vs before Week 2 — what moved?" — reinforce the quantified security improvement
- Week 3 preview: The identity layer is hardened. Week 3 moves into Exchange Online — the email infrastructure layer. Students configure mailboxes, mail flow connectors, anti-spam and anti-phishing policies, transport rules, and shared mailboxes. The DNS work from Week 1, Day 2 (MX and SPF records) becomes directly relevant.
Assessment rubric — marking guidance
| Criterion | Full marks | Partial | No marks |
| Section A — Investigation | Correct log locations used, incident timeline reconstructed accurately with evidence, all findings documented with navigation paths | Correct logs used but timeline incomplete or evidence missing | Logs not used or incorrect location, findings not documented |
| Section B — Remediation | All required actions completed correctly, each step documented with what was done and why, tenant state verified after each action | Most actions completed but one missing or incorrectly executed | Fewer than half of required actions completed |
| Section C — Hardening | Correct gap identified based on the incident, appropriate hardening step selected and implemented, reasoning explained | Gap identified but hardening step incorrect or only partially implemented | Gap not identified or wrong hardening step applied |
| Section D — Written report | All four elements present (what happened, how detected, what was done, recommendations), technically accurate, written clearly | Three of four elements present, or all present but technically inaccurate in one area | Fewer than three elements present or fundamental technical misunderstanding |
Learning outcomes — by end of Week 2, students can…
Build an M365 security baselineConfigure roles, MFA, CA policies, SSPR, and PIM from scratch on a live tenant
Investigate an identity incidentUse sign-in logs and audit logs to reconstruct what happened and when
Remediate a compromised accountRevoke sessions, reset credentials, verify MFA state, and check group membership integrity
Write an incident reportDocument a security event with timeline, findings, actions taken, and preventive recommendations
Connect security controls to riskExplain which control prevents which attack and identify the gap that allowed an incident to occur