Skip to content

Secure Access Hands-on Lab

Day 1 · Core Foundations Get Ready for AI

Welcome to the Kloudynet partner lab for the Microsoft Technical Workshop. In the next 2.5 hours you will configure and prove, with your own hands, the Zero Trust controls that make an organisation ready for AI: phishing-resistant sign-in, risk-based access, device trust, identity-centric network access with Microsoft Entra Suite, and data access that Microsoft 365 Copilot cannot bypass.

Every step on this site tells you exactly where to click and what you should see. You do not need previous experience with the Microsoft Entra admin center.

Your pod

You work in a pod of up to five people around one set of lab accounts. Your pod card shows your pod number. Enter it in the box at the top of any page so that every account and object name on this site becomes yours.

What Value Used for
Pod number NN Names of everything you create
Lab administrator lab-adminNN@aurnis.dev Building policies in the admin portals
Lab user lab-userNN@aurnis.dev Testing what the policies do
Lab desktop LAB-PC-NN A managed Windows 11 desktop in Azure, opened in your browser
Test tenant aurnistech.onmicrosoft.com (custom domain aurnis.dev) Where all of this lives

Temporary passwords and a one-time Temporary Access Pass are printed on the pod card.

Choose a driver. One person in the pod registers Microsoft Authenticator and a passkey on their phone for both accounts. Everyone in the pod can sign in on their own laptop with the shared credentials; the driver approves the Authenticator prompts and reads out the number shown. Rotate the driver between labs if you like.

How the labs are laid out

Admin window An InPrivate browser window signed in as the lab administrator. Policies are built here.

User window A separate browser session signed in as the lab user. This is how you feel what the policy does.

Lab desktop LAB-PC-NN, opened inside the User window. It is joined to the tenant, managed by Intune, and runs the Global Secure Access client. Your own laptop, by contrast, is deliberately the "untrusted" device.

Driver's phone Microsoft Authenticator prompts and passkeys.

Each task ends with an "I finished this task" checkbox. Tick it and the progress bar at the top of the page moves; the table below shows your progress across the whole lab. The checkboxes are stored in your browser only.

Agenda

Lab Topic Time Type Your progress
Lab 0 Getting started: accounts, PIM, your lab desktop 10 min Core
Lab 1 Zero Trust Assessment and risk review 15 min Optional
Lab 2 Phishing-resistant authentication with passkeys 30 min Core
Lab 3 Identity Protection and risk-based access 20 min Core
Lab 4 Compliant device access with Intune 25 min Core
Lab 5 Secure access with Microsoft Entra Suite (Global Secure Access) 35 min Core
Lab 6 AI-ready data access: Copilot respects permissions 20 min Optional
Wrap-up What you built and what to take home 5 min Core

Core labs take about 125 minutes. Your instructor will tell you whether the optional labs are in scope today.

Before you begin

  • Your pod card (pod number, two temporary passwords, one Temporary Access Pass)
  • A laptop with Microsoft Edge or Google Chrome
  • The driver's smartphone with Microsoft Authenticator installed (iOS or Android)
  • Bluetooth switched on, on the driver's phone and laptop (passkey sign-in in Lab 2)
  • This guide open in a normal browser window, not InPrivate, so your pod number and progress are remembered

Ground rules for a shared tenant

  • Only create, change or delete objects whose name contains your pod number (CA-NN-..., WCF-NN-...).
  • Never edit anything that starts with BASE-. Those are the instructor's baseline policies that every pod depends on.
  • Never assign a policy to All users. Always target your own group Lab-Users-NN.
  • If something looks broken, ask the instructor before "fixing" it.

Conventions used on these pages

Menu paths are shown like this: Protection Conditional Access Policies. Each arrow is one click in the left menu or on the page.

Values you must type exactly are shown like this: CA-NN-Phishing-Resistant.

Expected result

Green boxes tell you exactly what you should see after a step. If you see something else, re-read the step, wait a minute, and try again in a fresh InPrivate window.

Wait for propagation

Orange boxes flag steps where Microsoft Entra needs a minute or two before a policy takes effect.

Instructor note

Blue boxes are for parts the instructor shows on the main screen.

Ready? Start with Lab 0: Getting started.


Delivered by Kloudynet Technologies, Microsoft Solutions Partner for Security. Kuala Lumpur · Singapore · Dubai.