Skip to content

Lab 0. Getting started

Time 10 minutes
Admin account lab-adminNN@aurnis.dev
User account lab-userNN@aurnis.dev
Roles Eligible PIM roles, activated here

Scenario

You are the identity and security engineer for Contoso, a company about to roll out Microsoft 365 Copilot and AI agents. Before any of that happens you must prove the identity, device and network foundation is solid. Today you get an admin account with eligible privileges only, a standard user account to test with, and a managed Windows desktop in the cloud.

Objectives

  • Set up two separate browser sessions, one per account
  • Register Microsoft Authenticator for both accounts on the driver's phone
  • Activate your eligible admin roles through Privileged Identity Management (PIM)
  • Confirm your lab desktop LAB-PC-NN is available

Task 1. Open your two browser windows

Admin window User window

  1. Open Microsoft Edge.
  2. Press Ctrl+Shift+N. A new InPrivate window opens. This is your Admin window. Drag it to the left half of the screen.
  3. For the user you need a session that does not share the admin sign-in. A second InPrivate window would share it, so use one of these instead:
    • a normal (not InPrivate) Edge window, or
    • Google Chrome, or
    • a second Edge profile: select your profile picture at the top right of Edge, then Add profile, then Add without signing in.
  4. Put that second window on the right half of the screen. This is your User window.

Expected result

Two windows you can tell apart at a glance. Everything on this site says which window a step belongs in.

Task 2. Sign in as the lab administrator

Admin window

  1. In the Admin window go to https://entra.microsoft.com.
  2. On the sign-in page type lab-adminNN@aurnis.dev and select Next.
  3. Type the admin temporary password from your pod card and select Sign in.
  4. On Update your password, type the temporary password once more, then a new password twice. Choose something the whole pod can remember; write it on the pod card. Select Sign in.
  5. A page titled More information required appears. Select Next.
Microsoft sign-in page titled More information required with a Next button
First sign-in: the tenant asks the account to register a security method.
  1. Driver's phone Install Microsoft Authenticator from the App Store or Google Play if it is not already installed, open it, and allow notifications.
  2. Back in the Admin window, on Keep your account secure, select Next, then Next again. A QR code appears.
  3. On the phone, in Authenticator, tap + (top right), choose Work or school account, then Scan a QR code, and scan the QR code on the laptop screen.
  4. Select Next on the laptop. Authenticator shows a notification with a two-digit number on screen; type that number into the app and tap Yes.
  5. Select Next, then Done.
Keep your account secure page showing a QR code to scan with Microsoft Authenticator
Scan this QR code with Authenticator on the driver's phone.
  1. The Microsoft Entra admin center home page opens.

Expected result

The Entra admin center shows Home with your name at the top right. On the phone, Authenticator lists an account under aurnistech or Aurnis Tech.

If the page asks about staying signed in

Choose No. It keeps the two windows from mixing sessions later.

Task 3. Activate your eligible roles with PIM

Admin window

Your admin account holds no standing privileges. It is eligible for the roles the labs need, and you activate them for a limited time with a justification. This is the least-privilege model you should expect in a real tenant.

  1. In the left menu select Identity governance. If the left menu is collapsed, select the three-line menu icon at the top left first.
  2. Select Privileged Identity Management.
  3. Under Tasks select My roles.
  4. Select Microsoft Entra roles.
  5. The Eligible assignments tab lists the roles you may activate:

    Role Needed in
    Conditional Access Administrator Labs 2, 4, 5
    Authentication Policy Administrator Lab 2
    Security Operator Lab 3
    Intune Administrator Lab 4
    Global Secure Access Administrator Lab 5
    Security Reader All labs (reading logs)
PIM My roles page, Microsoft Entra roles, Eligible assignments tab listing six roles with Activate links
Eligible assignments: each role has an Activate link on the right.
  1. On the row Conditional Access Administrator select Activate.
  2. A panel opens on the right. If it says Additional verification required, select Click to continue and approve the prompt in Authenticator (the driver reads the number on screen and types it into the phone).
  3. Set Duration (hours) to 4.
  4. In Reason type Day 1 lab.
  5. Select Activate at the bottom of the panel. The panel shows three stages (activating, processing, done) and closes.
Activate Conditional Access Administrator panel with duration 4 hours and reason Day 1 lab
The activation panel. Duration 4 hours, reason "Day 1 lab".
  1. Repeat steps 6 to 10 for the other five roles. Each activation takes about a minute.
  2. Select the Active assignments tab.

Expected result

All six roles are listed under Active assignments with an End time about four hours from now. If a later page says you do not have permission, sign out of the Admin window and sign in again so the browser picks up a token with the new roles.

Instructor note

If PIM is not available, the roles are assigned directly. The Eligible list is empty and the pod continues to Task 4.

Task 4. Sign in as the lab user

User window

  1. In the User window go to https://myaccount.microsoft.com.
  2. Type lab-userNN@aurnis.dev and select Next.
  3. Type the user temporary password from the pod card and select Sign in.
  4. Set a new password when asked and write it on the pod card.
  5. On More information required select Next and register Microsoft Authenticator for this account exactly as in Task 2, steps 7 to 10. The phone will end up with two accounts in the app, one admin and one user.
  6. When My Account opens, select Security info in the left menu.
My Account Security info page listing Microsoft Authenticator as a sign-in method
Security info for the lab user. Keep this page: Lab 2 adds a passkey here.

Expected result

Security info lists Microsoft Authenticator for lab-userNN. Leave this tab open for Lab 2.

Task 5. Find your lab desktop

User window

  1. In the User window open a new tab and go to https://windows.cloud.microsoft.
  2. If asked, sign in as lab-userNN@aurnis.dev.
  3. Select Devices in the left menu (on a narrow window it is under the menu icon).
  4. Look for a desktop tile named LAB-PC-NN.
Windows App web client, Devices page showing a desktop tile named LAB-PC-NN
Windows App: your pod's desktop tile. Do not connect yet.
  1. Do not connect yet. Starting the desktop takes a couple of minutes; you connect for the first time in Lab 4.

Expected result

The tile is visible. If the page is empty, wait 30 seconds and refresh. If it is still empty, tell the instructor now so the assignment can be fixed before Lab 4.

Alternative client

The older Remote Desktop web client at https://client.wvd.microsoft.com/arm/webclient/ shows the same desktop.

Reflection

  • Your admin account can do nothing until you activate a role and give a reason. Where in your own tenant are administrators holding standing Global Administrator today?
  • What would an attacker gain from your admin password alone, right now?

Checklist

  • Admin window signed in to the Entra admin center
  • Six roles under Active assignments
  • User window signed in to My Account with Authenticator registered
  • LAB-PC-NN visible in Windows App

Next: Lab 1: Zero Trust Assessment if your instructor includes it, otherwise Lab 2: Phishing-resistant authentication.