0:00–0:20
Labels lecture + mini-lab
0:20–0:35
Tenant tidy
0:35–1:40
Assessment
1:40–2:00
Debrief
0:00 – 0:20Labels · 20 min

Sensitivity labels — condensed lecture and hands-on setup

DLP protects data in transit. Sensitivity labels protect data at rest — the label travels with the file no matter where it goes.

Mini-lab — create two sensitivity labels before the assessment (15 min)

Instructor note: Keep this section tight — 20 minutes total including the mini-lab. Sensitivity labels are introduced here as a concept and a basic configuration. The full label deployment (encryption, auto-labelling, Office app integration, SharePoint defaults) is Week 8's primary topic. The goal today is that students understand the label model well enough to answer assessment questions about how labels interact with DLP.
0:20 – 0:35Tenant tidy · 15 min

Pre-assessment self-audit

Assessment boundary: At 0:35 no further configuration changes unless directed by the assessment. The instructor will pre-seed the incident conditions in the tenant before class — a phishing-originated external file share to be investigated in Section A.
0:35 – 1:40Assessment · 65 min

Week 7 assessment — the Lakeview Logistics security incident

A combined phishing + data exfiltration incident. Students investigate using Threat Explorer and DLP alerts, contain it, and recommend hardening.

SectionWhat is assessedMarks
Section A — Threat investigationUsing Threat Explorer, locate a specific suspicious email sent to Priya Nair. Determine: sender, delivery action, authentication results, detection technology, and whether it reached the inbox. Then investigate whether a Finance file was shared externally — use DLP alerts and SharePoint Manage access.25 pts
Section B — ContainmentRecall the phishing email from all affected mailboxes using Threat Explorer. Revoke the external sharing link on the Finance file using SharePoint Manage access. Verify both containment actions succeeded.25 pts
Section C — Control gap analysisWritten: explain why the phishing email was not blocked by Safe Attachments or Safe Links, and why the file was not caught by DLP before it was shared. Identify the specific control gap in each case.25 pts
Section D — Hardening recommendationImplement one control that would have prevented or detected either incident earlier. Options: apply a sensitivity label to the Finance file (and explain how a label-based DLP condition would have helped), tighten the anti-phishing policy (higher threshold or additional protected users), or configure a DLP rule that uses the Confidential/Finance label as a condition. Implement and document.25 pts
Instructor note — pre-seed the incident: Before class: (1) Send an email from an external free-mail address to priya.nair@[studentsubdomain] with a subject like "Invoice Payment Required" and a link. This creates a phishing-pattern email in Threat Explorer. (2) In the Finance SharePoint site, upload a document called "Payroll-Q4.docx" and create an "Anyone with the link" sharing link — this is the external share students must find and revoke. Both actions take 5 minutes per student tenant. Section A requires navigating to Threat Explorer and SharePoint Manage access specifically — the correct path is the assessment of knowledge.
1:40 – 2:00Debrief · 20 min

Assessment debrief & Week 8 preview

Assessment rubric — marking guidance

CriterionFull marksPartialNo marks
Section ABoth the phishing email (via Threat Explorer) and the external share (via SharePoint Manage access + DLP alerts) correctly identified with all required metadata fields recordedOne found correctly, one not found or wrong path usedNeither found
Section BEmail recalled from all affected mailboxes via Threat Explorer, external sharing link revoked in SharePoint, both verified as closedOne contained and verified, one not attempted or not verifiedNeither contained
Section CPrecise explanation of why Safe Attachments/Links didn't help (no attachment/URL to detect), and why DLP didn't catch the share (label-based condition absent, or share happened before DLP propagated) — technically accurateGap identified but explanation imprecise or confuses the controlsGap not identified or explanation fundamentally wrong
Section DAppropriate control chosen, correctly implemented in tenant, clear reasoning for why it addresses the specific gap — implementation verifiedControl chosen but not implemented, or reasoning doesn't address the gapControl not chosen or not relevant

Learning outcomes — by end of Week 7, students can…

Investigate email threatsUse Threat Explorer to locate, analyse, and recall suspicious emails
Configure email defencesDeploy Safe Attachments, Safe Links, and anti-phishing impersonation policies
Onboard to EDRUse Intune to deploy Defender for Endpoint and wire risk levels to compliance
Run attack simulationsLaunch and interpret credential harvest simulations and training campaigns
Deploy DLP policiesCreate cross-workload DLP policies with SITs, rules, and endpoint restrictions
Describe sensitivity labelsExplain the label hierarchy model and how labels interact with DLP conditions
Week 8 →Week 7 Overview