0:00–0:10
E5 activation
0:10–0:20
Recap
0:20–0:45
Lecture
0:45–1:40
Guided Lab
1:40–1:50
Bonus
1:50–2:00
Debrief
0:00 – 0:10
E5 trial activation · 10 min
Adding the Microsoft 365 E5 trial
Before anything else today, every student activates the E5 trial. This unlocks the Week 2 deferred features — CA policy enforcement, PIM activation, and Entra ID P1/P2 capabilities — while there is still time before the Business Standard trial expires.
- Navigate to admin.microsoft.com → Billing → Purchase services
- Search for Microsoft 365 E5 → select the trial → Start free trial (25 licences, 30 days)
- After activation, navigate to Billing → Licences and confirm both Business Standard and E5 trial appear
- Record the E5 trial expiry date in Lab Journal — this is now the critical expiry date to track
What E5 unlocks immediately: Conditional Access policy enforcement (Week 2 CA001–CA004 can now be enabled), PIM role activation and approval workflows, Entra ID P2 features including dynamic group rules and risk-based sign-in policies, and Microsoft Defender for Identity. Students who completed the Week 2 bonus tasks can now return and activate those configurations.
Instructor note: Do not assign E5 licences to users yet — that happens as a bonus task today. The trial just needs to be activated in the tenant. Assigning licences triggers a wave of service provisioning that can slow the tenant during the main lab. Have students activate and record, then proceed to the recap.
0:10 – 0:20
Recap · 10 min
Week 3 debrief & the Week 1 connection
- Return Week 3 assessments with brief verbal feedback
- Ask: "In Lab 1-D you created a Microsoft 365 Group called 'Lakeview Logistics'. When you created it, what else got provisioned automatically alongside it?" — answer: a SharePoint site, shared mailbox, Teams (if enabled), Planner, OneNote
- Ask: "Open your SharePoint admin centre right now. How many sites already exist?" — students discover the auto-provisioned site from Week 1 is there waiting
- Frame Week 4: that auto-provisioned site is the foundation. This week students build the complete file infrastructure on top of it — department sites, a hub, permissions, external sharing controls, and OneDrive policies
0:20 – 0:45
Lecture · 25 min
SharePoint Online site types, the M365 Group relationship, and hub sites
Before building anything, students need to understand what site types exist, when to use each, and how SharePoint's hub model creates a governed, connected site architecture.
| Type | What it is | Has M365 Group? | Best used for |
| Team site (Group-connected) | Collaboration site connected to an M365 Group — shares membership, calendar, mailbox, Teams | Yes — auto-created | Department or project teams with ongoing collaboration |
| Team site (no Group) | Standalone team site — SharePoint only, no connected services | No | Legacy content migration, IT-managed repositories |
| Communication site | Broadcast/publishing site — content flows one-to-many. No M365 Group. Visually polished. | No | Intranet home, department news, company policies |
| Hub site | Not a separate site type — any site can be designated a hub. Hub sites aggregate news, search, and navigation from associated sites. | Depends on base type | Intranet home page, connecting related department sites |
- The M365 Group ↔ SharePoint relationship — when an M365 Group is created (from Teams, Outlook, the admin centre, or Planner), a SharePoint team site is auto-provisioned and linked. The site URL is based on the group name. The group's members become the site's Members, owners become Site Owners, and guests become Visitors. Deleting the group deletes the site. Deleting the site leaves the group intact but orphaned. This relationship is one-way — you cannot retrospectively connect a standalone SharePoint site to an existing M365 Group.
- Hub sites — the architecture layer — a hub site is a regular site promoted to hub status. Associated sites inherit the hub's navigation and theme, and their news and content are surfaced in the hub's rollup. Hub association is a lightweight connection — it does not change permissions. A site can only belong to one hub, but a hub can have unlimited associated sites. Designating hub sites requires SharePoint Administrator role.
- The SharePoint admin centre — located at admin.microsoft.com → SharePoint admin centre, or directly at [tenant]-admin.sharepoint.com. Key sections: Active sites (all sites, their type, storage, and owners), Policies (sharing, access control), Settings (notifications, sync, etc.). Different from the SharePoint site settings that exist on every individual site.
- Lakeview Logistics site architecture plan:
| Site | Type | Hub role | Purpose |
| Lakeview Logistics Intranet | Communication site | Hub site (root) | Company home — news, policies, announcements |
| Lakeview Logistics | Team site (Group-connected) | Associated to hub | Already exists from Week 1 — company-wide collaboration |
| IT Department | Team site (Group-connected) | Associated to hub | IT team collaboration, asset tracking, runbooks |
| Finance Department | Team site (Group-connected) | Associated to hub | Finance documents, budgets, accounts payable |
| HR Department | Team site (Group-connected) | Associated to hub | HR policies, onboarding docs, employee records |
| Sales Department | Team site (Group-connected) | Associated to hub | CRM support, proposals, client materials |
Instructor note: The Lakeview Logistics team site from Week 1 already exists — students don't re-create it. Start by finding it in the SharePoint admin centre and showing its properties. This connects Week 1 lab work to Week 4 content immediately and makes the M365 Group relationship concrete.
0:45 – 1:40
Guided lab · 55 min
Lab 4-A: Building the Lakeview Logistics site architecture
Students explore the SharePoint admin centre, create the intranet communication site (which becomes the hub), create four department team sites, associate all sites to the hub, and verify the architecture via PowerShell.
- Step 1 — Explore the SharePoint admin centre (5 min)
Navigate to admin.microsoft.com → Show all → SharePoint (or directly to [tenant]-admin.sharepoint.com). Go to Active sites. Identify the Lakeview Logistics team site that was auto-provisioned in Week 1. Record its URL, template type, storage used, and primary owner in your Lab Journal.
- Step 2 — Create the intranet communication site (10 min)
In the SharePoint admin centre: Active sites → + Create → Communication site.
· Site name: Lakeview Logistics Intranet
· Site address: /sites/lakeviewintranet
· Site owner: Sarah Chen
· Language: English
After creation, note the full URL. This site will become the hub.
- Step 3 — Designate the intranet site as a hub (5 min)
In Active sites, click the Lakeview Logistics Intranet site. In the right panel, click Hub → Register as hub site. Give the hub the name: Lakeview Logistics. Save. The site now shows a hub icon in the Active sites list.
- Step 4 — Create four department team sites (20 min)
In the SharePoint admin centre: Active sites → + Create → Team site. Create each site below. For each, set the group owner to the relevant department head and add the department security group from Lab 1-D as members.
| Site name | URL path | Group owner | Members group |
| IT Department | /sites/IT | Sarah Chen | LL-IT |
| Finance Department | /sites/Finance | Priya Nair | LL-Finance |
| HR Department | /sites/HR | Diane Rousseau | LL-HR |
| Sales Department | /sites/Sales | Kevin Park | LL-Sales |
- Step 5 — Associate all sites to the hub (10 min)
For each site (including the original Lakeview Logistics team site from Week 1), click the site in Active sites → right panel → Hub → Associate with a hub → Lakeview Logistics. Associate all five team sites to the hub. Verify the hub association column in the Active sites list shows "Lakeview Logistics" for each.
- Step 6 — Verify via PowerShell (5 min)
Connect to SharePoint Online PowerShell:
Connect-SPOService -Url https://[tenant]-admin.sharepoint.com
List all sites with their hub associations:
Get-SPOSite | Select-Object Title, Url, Template, HubSiteId | Format-Table -AutoSize
Record the output. The hub site will show a HubSiteId equal to its own site ID. Associated sites will show the hub's site ID. Sites not yet associated will show an empty HubSiteId.
SharePoint Online PowerShell module: Install with Install-Module Microsoft.Online.SharePoint.PowerShell. This is a third module — separate from both Exchange Online PowerShell and Microsoft Graph PowerShell. Each workload has its own management shell in M365.
Instructor note: The department site creation in Step 4 creates M365 Groups alongside each team site. This is expected — each department site will have its own Group with its own shared mailbox, calendar, and potential Teams channel. Students may notice the new groups appear in Entra ID after site creation. This is the M365 Group ↔ SharePoint relationship in action.
1:40 – 1:50
Bonus material · 10 min
⭐ Bonus: E5 licence assignment & Week 2 CA policy activation
⭐ Bonus A — Assign E5 licences and validate unlocked features
- In admin.microsoft.com → Billing → Licences → Microsoft 365 E5 → assign to all 10 Lakeview Logistics users
- After assignment, navigate to entra.microsoft.com → Identity governance → Privileged Identity Management — confirm PIM is now fully accessible (no licence gate)
- Navigate to security.microsoft.com → Identity → Identity protection — confirm sign-in risk and user risk policies are now configurable
- In your Lab Journal: list three specific features that are now unlocked by E5 that were gated in Week 2, and for each one note which lab step you deferred and can now complete
⭐ Bonus B — Enable CA001 (Require MFA for all users)
- Navigate to entra.microsoft.com → Protection → Conditional Access → Policies → CA001 — Require MFA for all users
- Review the sign-in log results in Report-only mode — confirm the policy would have applied correctly to sign-ins from outside the trusted network
- Change the policy state from Report-only to On. Save.
- Sign out and sign back in to your admin account — verify you are prompted for MFA by the CA policy (not just per-user MFA)
- In your Lab Journal: what is the difference in user experience between per-user MFA (Week 2) and CA-enforced MFA? Is it possible to have both active simultaneously and what happens?
1:50 – 2:00
Debrief · 10 min
Reflection & preview
- Ask: "You created an IT Department team site. An M365 Group was auto-created alongside it. How does this affect the LL-IT security group you created in Week 1? Are they the same thing?" — surface the distinction: the M365 Group has a different membership model than the security group
- Ask: "The intranet communication site is the hub. A user navigates to the IT Department site — what do they see from the hub that they wouldn't see if the site wasn't associated?" — surface hub navigation inheritance and news rollup
- Collect exit ticket: what is the difference between a team site and a communication site — give a specific Lakeview Logistics scenario where each is the right choice
- Preview Day 2: the sites are built — tomorrow is about who can access what and under what conditions. SharePoint's permissions model is the most nuanced of any M365 service and the most likely source of accidental data exposure
Learning outcomes — by end of Day 1, students can…
Activate the E5 trialAdd the E5 trial subscription and identify the features it unlocks
Distinguish site typesDescribe team sites, communication sites, and hub sites and select the right type for a given use case
Explain the M365 Group linkDescribe how M365 Group creation auto-provisions a SharePoint site and what the relationship means for lifecycle management
Create and configure sitesCreate communication and team sites in the SharePoint admin centre with correct owners and members
Register and associate hub sitesDesignate a hub site and associate department sites to it
Audit sites via PowerShellUse Get-SPOSite to produce a site inventory with hub association data
What you need ready
SharePoint Online PowerShell module
Week 3 assessments marked and returned
Lakeview Logistics M365 Group confirmed from Week 1
Slide deck: site types & hub architecture
Lab 4-A step sheet