Lab 0. Getting started
Scenario
You are the identity and security engineer for Contoso, a company about to roll out Microsoft 365 Copilot and AI agents. Before any of that happens you must prove the identity, device and network foundation is solid. Today you get an admin account with eligible privileges only, a standard user account to test with, and a managed Windows desktop in the cloud.
Objectives
- Set up two separate browser sessions, one per account
- Register Microsoft Authenticator for both accounts on the driver's phone
- Activate your eligible admin roles through Privileged Identity Management (PIM)
- Confirm your lab desktop
LAB-PC-NNis available
Task 1. Open your two browser windows
Admin window User window
- Open Microsoft Edge.
- Press Ctrl+Shift+N. A new InPrivate window opens. This is your Admin window. Drag it to the left half of the screen.
- For the user you need a session that does not share the admin sign-in. A second
InPrivate window would share it, so use one of these instead:
- a normal (not InPrivate) Edge window, or
- Google Chrome, or
- a second Edge profile: select your profile picture at the top right of Edge, then Add profile, then Add without signing in.
- Put that second window on the right half of the screen. This is your User window.
Expected result
Two windows you can tell apart at a glance. Everything on this site says which window a step belongs in.
Task 2. Sign in as the lab administrator
Admin window
- In the Admin window go to
https://entra.microsoft.com. - On the sign-in page type lab-adminNN@aurnis.dev and select Next.
- Type the admin temporary password from your pod card and select Sign in.
- On Update your password, type the temporary password once more, then a new password twice. Choose something the whole pod can remember; write it on the pod card. Select Sign in.
- A page titled More information required appears. Select Next.

- Driver's phone Install Microsoft Authenticator from the App Store or Google Play if it is not already installed, open it, and allow notifications.
- Back in the Admin window, on Keep your account secure, select Next, then Next again. A QR code appears.
- On the phone, in Authenticator, tap + (top right), choose Work or school account, then Scan a QR code, and scan the QR code on the laptop screen.
- Select Next on the laptop. Authenticator shows a notification with a two-digit number on screen; type that number into the app and tap Yes.
- Select Next, then Done.

- The Microsoft Entra admin center home page opens.
Expected result
The Entra admin center shows Home with your name at the top right. On the phone, Authenticator lists an account under aurnistech or Aurnis Tech.
If the page asks about staying signed in
Choose No. It keeps the two windows from mixing sessions later.
Task 3. Activate your eligible roles with PIM
Admin window
Your admin account holds no standing privileges. It is eligible for the roles the labs need, and you activate them for a limited time with a justification. This is the least-privilege model you should expect in a real tenant.
- In the left menu select Identity governance. If the left menu is collapsed, select the three-line menu icon at the top left first.
- Select Privileged Identity Management.
- Under Tasks select My roles.
- Select Microsoft Entra roles.
-
The Eligible assignments tab lists the roles you may activate:
Role Needed in Conditional Access Administrator Labs 2, 4, 5 Authentication Policy Administrator Lab 2 Security Operator Lab 3 Intune Administrator Lab 4 Global Secure Access Administrator Lab 5 Security Reader All labs (reading logs)

- On the row Conditional Access Administrator select Activate.
- A panel opens on the right. If it says Additional verification required, select Click to continue and approve the prompt in Authenticator (the driver reads the number on screen and types it into the phone).
- Set Duration (hours) to 4.
- In Reason type Day 1 lab.
- Select Activate at the bottom of the panel. The panel shows three stages (activating, processing, done) and closes.

- Repeat steps 6 to 10 for the other five roles. Each activation takes about a minute.
- Select the Active assignments tab.
Expected result
All six roles are listed under Active assignments with an End time about four hours from now. If a later page says you do not have permission, sign out of the Admin window and sign in again so the browser picks up a token with the new roles.
Instructor note
If PIM is not available, the roles are assigned directly. The Eligible list is empty and the pod continues to Task 4.
Task 4. Sign in as the lab user
User window
- In the User window go to
https://myaccount.microsoft.com. - Type lab-userNN@aurnis.dev and select Next.
- Type the user temporary password from the pod card and select Sign in.
- Set a new password when asked and write it on the pod card.
- On More information required select Next and register Microsoft Authenticator for this account exactly as in Task 2, steps 7 to 10. The phone will end up with two accounts in the app, one admin and one user.
- When My Account opens, select Security info in the left menu.

Expected result
Security info lists Microsoft Authenticator for lab-userNN. Leave this tab open for Lab 2.
Task 5. Find your lab desktop
User window
- In the User window open a new tab and go to
https://windows.cloud.microsoft. - If asked, sign in as lab-userNN@aurnis.dev.
- Select Devices in the left menu (on a narrow window it is under the menu icon).
- Look for a desktop tile named
LAB-PC-NN.

- Do not connect yet. Starting the desktop takes a couple of minutes; you connect for the first time in Lab 4.
Expected result
The tile is visible. If the page is empty, wait 30 seconds and refresh. If it is still empty, tell the instructor now so the assignment can be fixed before Lab 4.
Alternative client
The older Remote Desktop web client at
https://client.wvd.microsoft.com/arm/webclient/ shows the same desktop.
Reflection
- Your admin account can do nothing until you activate a role and give a reason. Where in your own tenant are administrators holding standing Global Administrator today?
- What would an attacker gain from your admin password alone, right now?
Checklist
- Admin window signed in to the Entra admin center
- Six roles under Active assignments
- User window signed in to My Account with Authenticator registered
-
LAB-PC-NNvisible in Windows App
Next: Lab 1: Zero Trust Assessment if your instructor includes it, otherwise Lab 2: Phishing-resistant authentication.