Peters School of Business · Assiniboine College · Networking 7
Full M365 stack · 2 hours · Networking 7 · Assiniboine College · Assessment day
8-week stack recap & tenant tidy
This is the end of the course. The capstone is not a quiz — it is a live-tenant investigation. Students receive a scenario (a suspicious overnight sign-in by Dev Sharma, plus an outstanding legal review of the Priya Nair incident), then must investigate, contain, document, and reason about what is still missing — using the full stack built over eight weeks.
Capstone — four parts × 25 marks
Students work independently in their own tenant. All portal work is live — students take screenshots or write detailed navigation records as evidence. Parts A, B, and C require portal actions; Part D is written only.
| Part | Topic | Tasks | Marks |
|---|---|---|---|
| A — Identity & CA | Suspicious overnight sign-in — Dev Sharma | Investigate the sign-in in Entra ID logs · identify the CA policy gap · revoke sessions + force password reset · create CA005 (sign-in risk: medium/high → require MFA) · written trade-off explanation | 25 |
| B — Audit & eDiscovery | Dev Sharma 48-hr activity reconstruction | Audit log search covering the 48-hr window · export to CSV · identify most forensically significant event · place Dev Sharma mailbox on legal hold · run eDiscovery search on Finance content · initiate export for legal counsel | 25 |
| C — Data Governance | Label encryption + auto-labelling + memo | Verify Confidential/Finance encryption is active · test that a non-Finance user is blocked · review auto-labelling simulation status · write a board-level retention policy justification memo (300–400 words) | 25 |
| D — Written Synthesis | Three remaining governance gaps | No portal work. Identify 3 significant remaining governance gaps. For each: name it precisely (portal + feature + scope), describe the risk scenario (actor + asset + consequence), recommend the specific control, and connect it to an existing lab configuration. | 25 |
Written synthesis — what a full-marks answer looks like
For each of the three governance gaps, your answer must contain four components. Generic descriptions score partial or zero marks on each criterion.
| Component | What is required | Marks |
|---|---|---|
| Gap precisely named | The exact control gap — portal, feature, and scope. Example: "No Conditional Access policy requiring an Intune-compliant device for guest accounts accessing SharePoint Online." Not: "MFA gap." | 2 |
| Risk scenario specific | Name the actor, the asset, and the consequence. All three are required for full marks. Example: "An external auditor [actor] accesses the Finance SharePoint site [asset] from a personal unmanaged laptop, downloads Payroll-Q4.docx, and the download is not blocked by Intune compliance [consequence]." | 3 |
| Control recommendation | The portal, the feature, and the key setting. Example: "Entra ID Conditional Access — new policy targeting Guest users, app: SharePoint Online, grant: Require MFA." | 2 |
| Connection to existing config | Explain how the recommendation builds on a specific control already in place. Reference the lab. Example: "The Intune compliance policy from Lab 6-B already defines what 'compliant' means — this CA policy enforces it at the access layer for external users." | 1 |
| Gap 3 bonus | For your third gap only: explain why it is more significant than alternatives, OR identify an interaction between two gaps. Example: "The absence of an HR connector compounds the audit retention gap — the 30-day IRM lookback window runs out of log history if audit retention is only 90 days." | +1 |
Submission & whole-class reflection
Instructor checklist — before class