Identity security lab

Microsoft 365 | Entra ID | MFA | Conditional Access

M365 / Entra Zero Trust Lab

A Microsoft 365 and Entra ID lab plan for report-only Conditional Access, MFA, legacy authentication blocking, compliant-device access, and sign-in log review.

3

Policies

3

Groups

Report

First

Microsoft 365 Entra topology showing users, devices, Entra ID, Conditional Access, MFA, compliant devices, apps, and logs.

What it demonstrates

Practical lab work with clear operational context.

Conditional Access

Plans MFA, legacy authentication blocking, and compliant-device requirements in report-only mode.

Pilot Rollout

Uses pilot groups and staged enforcement to reduce lockout and business disruption risk.

Audit Review

Frames sign-in log and policy-impact review as part of responsible Zero Trust rollout.

Workflow

Show the process, not just the result.

Each case study includes a diagrammed workflow so the environment, design choices, safety controls, and troubleshooting paths are easy to understand.

Zero Trust workflow showing pilot groups, report-only policies, log review, tuning, and enforcement planning.

Safety controls

Designed for a Microsoft 365 developer or test tenant

Policies start in report-only mode

Pilot groups are used before broad enforcement

No tenant IDs, usernames, or secrets are included

Demo commands
powershell.exe -NoProfile -ExecutionPolicy Bypass -File .\scripts\New-ZeroTrustPlan.ps1

# Live tenant work belongs in the Entra admin center
# Start Conditional Access policies in report-only mode

Review the technical case study.

The diagrams and workflow summarize the environment, controls, and operational reasoning without exposing internal prep material.