0:00–0:15
Review & briefing
0:15–1:45
Assessment · 90 min
1:45–2:00
Submission & debrief
0:00 – 0:15Review & briefing · 15 min

8-week stack recap & tenant tidy

This is the end of the course. The capstone is not a quiz — it is a live-tenant investigation. Students receive a scenario (a suspicious overnight sign-in by Dev Sharma, plus an outstanding legal review of the Priya Nair incident), then must investigate, contain, document, and reason about what is still missing — using the full stack built over eight weeks.

0:15 – 1:45Assessment · 90 min · open-tenant, open-notes

Capstone — four parts × 25 marks

Students work independently in their own tenant. All portal work is live — students take screenshots or write detailed navigation records as evidence. Parts A, B, and C require portal actions; Part D is written only.

PartTopicTasksMarks
A — Identity & CA Suspicious overnight sign-in — Dev Sharma Investigate the sign-in in Entra ID logs · identify the CA policy gap · revoke sessions + force password reset · create CA005 (sign-in risk: medium/high → require MFA) · written trade-off explanation 25
B — Audit & eDiscovery Dev Sharma 48-hr activity reconstruction Audit log search covering the 48-hr window · export to CSV · identify most forensically significant event · place Dev Sharma mailbox on legal hold · run eDiscovery search on Finance content · initiate export for legal counsel 25
C — Data Governance Label encryption + auto-labelling + memo Verify Confidential/Finance encryption is active · test that a non-Finance user is blocked · review auto-labelling simulation status · write a board-level retention policy justification memo (300–400 words) 25
D — Written Synthesis Three remaining governance gaps No portal work. Identify 3 significant remaining governance gaps. For each: name it precisely (portal + feature + scope), describe the risk scenario (actor + asset + consequence), recommend the specific control, and connect it to an existing lab configuration. 25
Assessment rules: All work is performed live in the student's own tenant. Lab Journal is permitted for reference. No external search engines, no AI assistants, no sharing between students. Portal actions must be documented — screenshots or written navigation records with timestamps. Part D is written only — no portal actions required or expected.
Part D — marking note for instructor: the rubric rewards specificity and breadth. Generic answers ("MFA gap", "audit issue") score 0. Gaps must span at least two different product areas. Any well-reasoned, specific gap scores full marks — the model answers in the marking guide are not the only acceptable responses. Brief students on this at the start.
Part D guidanceShown to students on assessment sheet

Written synthesis — what a full-marks answer looks like

For each of the three governance gaps, your answer must contain four components. Generic descriptions score partial or zero marks on each criterion.

ComponentWhat is requiredMarks
Gap precisely namedThe exact control gap — portal, feature, and scope. Example: "No Conditional Access policy requiring an Intune-compliant device for guest accounts accessing SharePoint Online." Not: "MFA gap."2
Risk scenario specificName the actor, the asset, and the consequence. All three are required for full marks. Example: "An external auditor [actor] accesses the Finance SharePoint site [asset] from a personal unmanaged laptop, downloads Payroll-Q4.docx, and the download is not blocked by Intune compliance [consequence]."3
Control recommendationThe portal, the feature, and the key setting. Example: "Entra ID Conditional Access — new policy targeting Guest users, app: SharePoint Online, grant: Require MFA."2
Connection to existing configExplain how the recommendation builds on a specific control already in place. Reference the lab. Example: "The Intune compliance policy from Lab 6-B already defines what 'compliant' means — this CA policy enforces it at the access layer for external users."1
Gap 3 bonusFor your third gap only: explain why it is more significant than alternatives, OR identify an interaction between two gaps. Example: "The absence of an HR connector compounds the audit retention gap — the 30-day IRM lookback window runs out of log history if audit retention is only 90 days."+1
1:45 – 2:00Submission & debrief · 15 min

Submission & whole-class reflection

Instructor checklist — before class

Dev Sharma account active — Global Reader + Security Admin roles Priya Nair mailbox has Finance content (Payroll-Q4.docx) Finance SharePoint site accessible with test documents Confidential/Finance label — encryption active (Lab 8-D) LL — Financial Data Protection DLP policy — On eDiscovery Manager role on admin account Unified audit log enabled and populated Assessment docx distributed at 0:15 — not before Marking guide printed (instructor only)
Course Outline →Week 8 Overview