Secure Access Hands-on Lab
Day 1 · Core Foundations Get Ready for AI
Welcome to the Kloudynet partner lab for the Microsoft Technical Workshop. In the next 2.5 hours you will configure and prove, with your own hands, the Zero Trust controls that make an organisation ready for AI: phishing-resistant sign-in, risk-based access, device trust, identity-centric network access with Microsoft Entra Suite, and data access that Microsoft 365 Copilot cannot bypass.
Every step on this site tells you exactly where to click and what you should see. You do not need previous experience with the Microsoft Entra admin center.
Your pod
You work in a pod of up to five people around one set of lab accounts. Your pod card shows your pod number. Enter it in the box at the top of any page so that every account and object name on this site becomes yours.
| What | Value | Used for |
|---|---|---|
| Pod number | NN | Names of everything you create |
| Lab administrator | lab-adminNN@aurnis.dev |
Building policies in the admin portals |
| Lab user | lab-userNN@aurnis.dev |
Testing what the policies do |
| Lab desktop | LAB-PC-NN |
A managed Windows 11 desktop in Azure, opened in your browser |
| Test tenant | aurnistech.onmicrosoft.com (custom domain aurnis.dev) |
Where all of this lives |
Temporary passwords and a one-time Temporary Access Pass are printed on the pod card.
Choose a driver. One person in the pod registers Microsoft Authenticator and a passkey on their phone for both accounts. Everyone in the pod can sign in on their own laptop with the shared credentials; the driver approves the Authenticator prompts and reads out the number shown. Rotate the driver between labs if you like.
How the labs are laid out
Admin window An InPrivate browser window signed in as the lab administrator. Policies are built here.
User window A separate browser session signed in as the lab user. This is how you feel what the policy does.
Lab desktop LAB-PC-NN,
opened inside the User window. It is joined to the tenant, managed by Intune, and runs the
Global Secure Access client. Your own laptop, by contrast, is deliberately the
"untrusted" device.
Driver's phone Microsoft Authenticator prompts and passkeys.
Each task ends with an "I finished this task" checkbox. Tick it and the progress bar at the top of the page moves; the table below shows your progress across the whole lab. The checkboxes are stored in your browser only.
Agenda
| Lab | Topic | Time | Type | Your progress |
|---|---|---|---|---|
| Lab 0 | Getting started: accounts, PIM, your lab desktop | 10 min | Core | |
| Lab 1 | Zero Trust Assessment and risk review | 15 min | Optional | |
| Lab 2 | Phishing-resistant authentication with passkeys | 30 min | Core | |
| Lab 3 | Identity Protection and risk-based access | 20 min | Core | |
| Lab 4 | Compliant device access with Intune | 25 min | Core | |
| Lab 5 | Secure access with Microsoft Entra Suite (Global Secure Access) | 35 min | Core | |
| Lab 6 | AI-ready data access: Copilot respects permissions | 20 min | Optional | |
| Wrap-up | What you built and what to take home | 5 min | Core |
Core labs take about 125 minutes. Your instructor will tell you whether the optional labs are in scope today.
Before you begin
- Your pod card (pod number, two temporary passwords, one Temporary Access Pass)
- A laptop with Microsoft Edge or Google Chrome
- The driver's smartphone with Microsoft Authenticator installed (iOS or Android)
- Bluetooth switched on, on the driver's phone and laptop (passkey sign-in in Lab 2)
- This guide open in a normal browser window, not InPrivate, so your pod number and progress are remembered
Ground rules for a shared tenant
- Only create, change or delete objects whose name contains your pod number
(
CA-NN-...,WCF-NN-...). - Never edit anything that starts with
BASE-. Those are the instructor's baseline policies that every pod depends on. - Never assign a policy to All users. Always target your own group
Lab-Users-NN. - If something looks broken, ask the instructor before "fixing" it.
Conventions used on these pages
Menu paths are shown like this: Protection Conditional Access Policies. Each arrow is one click in the left menu or on the page.
Values you must type exactly are shown like this: CA-NN-Phishing-Resistant.
Expected result
Green boxes tell you exactly what you should see after a step. If you see something else, re-read the step, wait a minute, and try again in a fresh InPrivate window.
Wait for propagation
Orange boxes flag steps where Microsoft Entra needs a minute or two before a policy takes effect.
Instructor note
Blue boxes are for parts the instructor shows on the main screen.
Ready? Start with Lab 0: Getting started.
Delivered by Kloudynet Technologies, Microsoft Solutions Partner for Security. Kuala Lumpur · Singapore · Dubai.