Skip to content

Instructor setup runbook

This page lists every tenant object the labs depend on, how to build it, and what to do on the day. It contains no secrets: passwords, Temporary Access Passes and deployment tokens live only in the instructor's private notes.

Tenant: aurnistech.onmicrosoft.com, custom domain aurnis.dev. SharePoint: https://aurnistech.sharepoint.com.

1. Pod model

Ten pods (NN = 01 to 10), up to five attendees each, one set of accounts per pod. Each pod nominates a driver whose phone carries Authenticator and the passkey. Ten pods x four Conditional Access policies = 40 policies, far below the tenant limit of 240.

2. Licences

Assign through group-based licensing so the pod accounts pick them up automatically.

Licence Assigned to Used by
Microsoft 365 E5 (or E3 + Intune + SharePoint) Lab-Users-All, Lab-Admins-All Labs 4, 5, 6; Windows Enterprise rights for the lab desktops
Microsoft Entra ID P2 Lab-Users-All, Lab-Admins-All PIM (Lab 0), Identity Protection (Lab 3)
Microsoft Entra Suite (or Private Access + Internet Access standalone) Lab-Users-All Lab 5
Microsoft 365 Copilot (optional) Lab-Users-All Lab 6 Tasks 2 and 3

Ten of each licence covers every pod; trial subscriptions (usually 25) are enough.

3. Identities and groups

Object Naming Notes
Pod admin lab-adminNN@aurnis.dev, NN = 01 to 10 No standing roles. PIM-eligible for the six roles below. Temporary password, force change at first sign-in. Usage location set (licensing).
Pod user lab-userNN@aurnis.dev No roles. Member of Lab-Users-NN and Lab-Users-All. Assigned user of LAB-PC-NN. Usage location set.
Per-pod group Lab-Users-NN Security group, single member lab-userNN. Target of every pod policy.
All users Lab-Users-All Every lab-userNN. Target of every BASE- policy and the GSA forwarding profiles.
All admins Lab-Admins-All Every lab-adminNN. Excluded from all BASE- block policies.
Break-glass one cloud-only Global Administrator Excluded from every Conditional Access policy. FIDO2 key or passkey only.

PIM-eligible roles for every pod admin, maximum activation 4 hours, MFA on activation, justification required: Conditional Access Administrator, Authentication Policy Administrator, Security Operator, Intune Administrator, Global Secure Access Administrator, Security Reader.

Temporary Access Pass: issue one per pod user before the event (Users, the user, Authentication methods, Add authentication method, Temporary Access Pass, one-time use, valid for the whole session). Print it on the pod card.

4. Baseline objects

Every object below is prefixed BASE- (policies) or named exactly as shown. Pods read them and never change them.

Object Where Settings Scope
Passkey (FIDO2) method Entra, Protection, Authentication methods, Policies Enabled, target All users, self-service set up allowed, no key restrictions Lab 2
Microsoft Authenticator method same Enabled, number matching, show app name and location Lab 0
Temporary Access Pass method same Enabled, one-time use, maximum lifetime 8 hours Lab 2 fallback
MFA registration policy Entra, Protection, Identity Protection, Multifactor authentication registration policy Enabled. Without it the "More information required" interrupt in Lab 0 never appears and pods reach Lab 2 with no Authenticator. Lab-Users-All, Lab-Admins-All
BASE-User-risk-Block Conditional Access Users Lab-Users-All; exclude Lab-Admins-All, break-glass. All resources. Condition user risk High. Grant Block. On. Lab 3
BASE-Sign-in-risk-MFA Conditional Access Users Lab-Users-All; exclude admins, break-glass. All resources. Condition sign-in risk Medium and High. Grant Require MFA. Session sign-in frequency every time. On. Lab 3
BASE-Windows-Compliance Intune, Devices, Manage devices, Compliance Windows 10 and later. Defender real-time protection on, minimum OS 10.0.26100. No BitLocker requirement. Non-compliant immediately. Assign to a device group (dynamic: device name starts with LAB-PC-) as well as Lab-Users-All; pool-built session hosts have no user affinity, so a user-only assignment can leave them Not evaluated. Lab 4
AVD host pool hp-lab-day1 Azure, Azure Virtual Desktop Personal, direct assignment. Windows 11 Enterprise 24H2 single-session. Join Microsoft Entra ID with Enrol VM with Intune ticked. LAB-PC-NN assigned to lab-userNN. Users need Virtual Machine User Login on the resource group. RDP Properties, Advanced: add targetisaadjoined:i:1, or the web client cannot sign in to Entra-joined hosts. Start VM on connect enabled. Ten hosts. Labs 4, 5, 6
GSA client on session hosts Custom script extension or Intune Win32 app Latest Global Secure Access client for Windows. Verify the tray icon shows Connected after the first user sign-in. Lab 5
Global Secure Access activation Entra, Global Secure Access, Get started Activate. Connect, Traffic forwarding: Microsoft 365, Private access and Internet access profiles all enabled and assigned to Lab-Users-All. Lab 5
Conditional Access signalling Entra, Global Secure Access, Settings, Session management, Adaptive access Enable Conditional Access signaling On and Source IP restoration On. This creates the All Compliant Network locations named location that Lab 5 Task 5 depends on. Lab 5
Private Network connector A Windows Server VM in the intranet VNet Connector installed, connector group Lab-Connectors. Lab 5
Intranet web server Windows or Linux VM, private IP only, same VNet Serves a one-page "Contoso intranet" site on port 80. Private DNS zone lab.internal with A record intranet. Lab 5
Lab-Intranet Entra, Global Secure Access, Applications, Enterprise applications Private Access app. Segment: FQDN intranet.lab.internal, TCP 80, connector group Lab-Connectors. Users Lab-Users-All. Lab 5
BASE-Block-Gambling Global Secure Access, Secure, Web content filtering policies Action Block. Rule: web category Gambling. Lab 5
BASE-Lab-Profile Global Secure Access, Secure, Security profiles Priority 500. Links BASE-Block-Gambling at priority 100. Lab 5
BASE-GSA-Internet-Access Conditional Access Users Lab-Users-All. Target: Global Secure Access, Internet traffic. Session: security profile BASE-Lab-Profile. On. Create at least 2 hours before the session so tokens carry the profile. Lab 5
SharePoint site Day1Lab https://aurnistech.sharepoint.com/sites/Day1Lab Team site. Members: Lab-Users-All. Libraries: Public (inherits), Restricted (unique permissions, Lab-Users-All read), Confidential (unique permissions, instructor only). Sample files: Project-Plan.docx and Vendor-Notes.docx in Public and Restricted, Budget-FY27.xlsx in Confidential. Labs 4, 5, 6
Sensitivity label Lab Confidential Purview, Information protection, Labels Encryption on. Permissions: Lab-Users-All Viewer, instructor Co-Author. Published to Lab-Users-All. Applied to Public/Lab-Confidential-Sample.docx. Lab 6

5. Screenshots for the guide

Every lab page has screenshot slots that render as labelled placeholders until the image exists. Capture them during the dry run at 1400 px wide, PNG, and save them to site-src/docs/assets/shots/ with the exact file names below. Redact nothing except real passwords; the pod accounts are disposable.

File Page What to capture
lab0-01-more-info-required.png Lab 0 "More information required" page
lab0-02-authenticator-qr.png Lab 0 "Keep your account secure" QR code page
lab0-03-pim-eligible.png Lab 0 PIM, My roles, Microsoft Entra roles, Eligible assignments with six roles
lab0-04-pim-activate.png Lab 0 Activate panel with duration 4 and reason "Day 1 lab"
lab0-05-security-info.png Lab 0 My Account, Security info, Authenticator listed
lab0-06-windows-app-devices.png Lab 0 Windows App, Devices, the LAB-PC tile
lab1-01-overview.png Lab 1 Zero Trust Assessment demo, Overview
lab1-02-identity.png Lab 1 Zero Trust Assessment demo, Identity pillar
lab2-01-auth-methods.png Lab 2 Authentication methods, Policies list
lab2-02-new-policy-blank.png Lab 2 Empty New policy page
lab2-03-users-group.png Lab 2 Users assignment with Lab-Users-NN selected
lab2-04-target-exchange.png Lab 2 Target resources with Exchange Online ticked
lab2-05-grant-strength.png Lab 2 Grant, Require authentication strength, Phishing-resistant MFA
lab2-06-user-blocked.png Lab 2 The user's interrupt or block page
lab2-07-signin-log-ca.png Lab 2 Sign-in log, Conditional Access tab, policy Failure
lab2-08-add-passkey.png Lab 2 Security info, Add sign-in method, Passkey in Authenticator
lab2-09-passkey-qr.png Lab 2 Cross-device passkey QR code at sign-in
lab3-01-base-user-risk.png Lab 3 BASE-User-risk-Block policy open
lab3-02-account-blocked.png Lab 3 "Your account is blocked" page
lab3-03-risky-users.png Lab 3 Risky users with lab-userNN selected, Confirmed compromised
lab3-04-risky-signin-ca.png Lab 3 Risky sign-in, Conditional Access tab
lab3-05-dismiss-risk.png Lab 3 Risky user panel with Dismiss user risk button
lab4-01-intune-device.png Lab 4 Intune device overview, Compliant
lab4-02-compliance-policy.png Lab 4 BASE-Windows-Compliance properties
lab4-03-target-sharepoint.png Lab 4 Target resources with SharePoint Online ticked
lab4-04-grant-compliant.png Lab 4 Grant, Require device to be marked as compliant
lab4-05-cant-get-there.png Lab 4 "You can't get there from here" page
lab4-06-windows-app-connect.png Lab 4 Windows App connect dialog
lab4-07-sharepoint-opens.png Lab 4 Day1Lab open in Edge on the lab desktop
lab5-01-gsa-dashboard.png Lab 5 Global Secure Access dashboard
lab5-02-traffic-forwarding.png Lab 5 Traffic forwarding, three profiles
lab5-03-private-app-segment.png Lab 5 Lab-Intranet network access properties
lab5-04-gsa-client-connected.png Lab 5 GSA client, Connections view
lab5-05-intranet-page.png Lab 5 Contoso intranet page in Edge on the desktop
lab5-06-category-blocked.png Lab 5 Gambling site blocked in Edge
lab5-07-traffic-logs.png Lab 5 Traffic logs filtered by user with both flows
lab5-08-network-compliant-exclude.png Lab 5 Network assignment excluding All Compliant Network locations
lab5-09-wcf-policy.png Lab 5 Web content filtering policy wizard
lab5-10-security-profile.png Lab 5 Security profile wizard with policy linked
lab5-11-ca-session-profile.png Lab 5 CA Session control with the security profile
lab6-01-access-denied.png Lab 6 SharePoint Access denied
lab6-02-copilot-allowed.png Lab 6 Copilot Chat citing allowed files
lab6-03-copilot-denied.png Lab 6 Copilot Chat refusing the confidential file
lab6-04-label-banner.png Lab 6 Word for the web with the Lab Confidential label

6. Timing notes

What Delay to expect Consequence for the runbook
New Conditional Access policy 1 to 2 minutes Every lab page already warns pods.
New GSA security profile in a token Up to 90 minutes Create BASE-GSA-Internet-Access well before the session; pod profiles are report-only.
Intune compliance evaluation on a new device Up to 8 hours for the first evaluation Build and sign in to every LAB-PC-NN the day before and confirm Compliant in Intune.
AVD first connection About 2 minutes if the VM is deallocated Start all hosts 60 minutes before the session.
PIM activation About 1 minute per role Lab 0 budgets 10 minutes.

7. Day-of timeline

Time Action
T-1 day Full rehearsal with two pods' worth of accounts. Reset afterwards. Confirm every LAB-PC-NN shows Compliant.
T-60 min Start all session hosts. Open the Entra admin center as break-glass on the instructor laptop. Check BASE-GSA-Internet-Access is On.
T-0 Hand out pod cards (pod number, two temporary passwords, one Temporary Access Pass). Pods start Lab 0.
Start of Lab 3 Only after every pod has finished Lab 2 Task 4 (passkey registered and signed in), run the confirm-compromised call for every pod user (Graph POST /identityProtection/riskyUsers/confirmCompromised with the list of user IDs). Announce that users are now flagged. Running it early blocks slow pods mid-registration.
During Lab 5 Keep the traffic logs page open on the main screen to show flows arriving.
T+150 min Wrap-up. Ask pods to sign out everywhere.
After Run the reset (section 8). Deallocate session hosts.

8. Reset between events

  1. Delete every Conditional Access policy whose name starts with CA- followed by two digits. Leave all BASE- policies.
  2. Delete every web content filtering policy WCF-NN-* and security profile SP-NN.
  3. Dismiss user risk for every lab-userNN.
  4. Revoke sessions and reset passwords for every lab-adminNN and lab-userNN. Remove their registered authentication methods (Authenticator and passkeys) so the next pod registers fresh. Issue new Temporary Access Passes.
  5. Deactivate any active PIM assignments.
  6. Confirm the Conditional Access policy count: 10 pods x 4 = 40 plus the baseline policies.
  7. Sign out all sessions on every LAB-PC-NN and deallocate them.

Scripts for sections 3 and 8 are delivered separately in the tooling folder of the repository.