Secure Access Hands-on Lab
Day 1 · Core Foundations Get Ready for AI
Welcome to the Kloudynet partner lab for the Microsoft Technical Workshop. In the next 2.5 hours you will configure and prove, with your own hands, the Zero Trust controls that make an organisation ready for AI: phishing-resistant sign-in, risk-based access, device trust, identity-centric network access with Microsoft Entra Suite, and data access that Microsoft 365 Copilot cannot bypass.
You are lab number NN. Enter it in the box above so every page shows your own account names.
How this lab works
- You work in a shared test tenant. Every attendee has their own numbered admin and user accounts. Everything you create carries your number, so you never touch anyone else's work.
- Your own laptop is the "untrusted device". It is not joined to the lab tenant, so it plays the role of a personal or unmanaged PC. That is intentional.
LAB-PC-NNis your "corporate device". It is a Windows 11 desktop in Azure, joined to the lab tenant, managed by Intune, and running the Global Secure Access client. You open it inside your browser. No software to install.- Two browser windows. Keep one InPrivate window signed in as the admin and a second one signed in as the user. Lab 0 sets this up.
Your accounts
| Role | Account | Used for |
|---|---|---|
| Lab administrator | lab-adminNN@ |
Building policies in the admin portals |
| Lab user | lab-userNN@ |
Testing what the policies do |
| Lab desktop | LAB-PC-NN |
Compliant, Entra-joined Windows 11 in Azure |
The tenant domain and temporary passwords are on your credential card.
Agenda
| Lab | Topic | Time | Status |
|---|---|---|---|
| Lab 0 | Getting started: accounts, PIM, your lab desktop | 10 min | Core |
| Lab 1 | Zero Trust Assessment and risk review | 15 min | Optional |
| Lab 2 | Phishing-resistant authentication with passkeys | 30 min | Core |
| Lab 3 | Identity Protection and risk-based access | 20 min | Core |
| Lab 4 | Compliant device access with Intune | 25 min | Core |
| Lab 5 | Secure access with Microsoft Entra Suite (Global Secure Access) | 35 min | Core |
| Lab 6 | AI-ready data access: Copilot respects permissions | 20 min | Optional |
| Wrap-up | What you built and what to take home | 5 min | Core |
Core labs take about 125 minutes. Your instructor will tell you whether the optional labs are in scope today.
Before you begin
- Your credential card (lab number, tenant domain, two temporary passwords)
- A laptop with Microsoft Edge or Google Chrome
- A smartphone with Microsoft Authenticator installed (iOS or Android)
- Bluetooth switched on, on the phone and the laptop (needed for passkey sign-in in Lab 2)
- This guide open in a normal browser window, not InPrivate, so your lab number is remembered
- About 2.5 hours and a coffee
Ground rules for a shared tenant
- Only create, change or delete objects whose name contains your number
(
CA-NN-...,WCF-NN-...). - Never edit anything that starts with
BASE-. Those are the instructor's baseline policies that all labs depend on. - Never assign a policy to "All users". Always target your own group
Lab-Users-NN. - If something looks broken, ask the instructor before "fixing" it.
Conventions used on these pages
Expected result
Green boxes tell you exactly what you should see after a step. If you see something else, re-read the step, wait a minute, and try again in a fresh InPrivate window.
Wait for propagation
Orange boxes flag steps where Microsoft Entra needs a minute or two before a policy takes effect.
Instructor note
Blue boxes are for parts the instructor shows on the main screen.
Ready? Start with Lab 0: Getting started.
Delivered by Kloudynet Technologies, Microsoft Solutions Partner for Security. Kuala Lumpur · Singapore · Dubai.