Instructor setup runbook
This page lists every tenant object the labs depend on, how to build it, and what to do on the day. It contains no secrets: passwords, Temporary Access Passes and deployment tokens live only in the instructor's private notes.
Tenant: aurnistech.onmicrosoft.com, custom domain aurnis.dev. SharePoint:
https://aurnistech.sharepoint.com.
1. Pod model
Ten pods (NN = 01 to 10), up to five attendees each, one set of accounts per pod. Each pod nominates a driver whose phone carries Authenticator and the passkey. Ten pods x four Conditional Access policies = 40 policies, far below the tenant limit of 240.
2. Licences
Assign through group-based licensing so the pod accounts pick them up automatically.
| Licence | Assigned to | Used by |
|---|---|---|
| Microsoft 365 E5 (or E3 + Intune + SharePoint) | Lab-Users-All, Lab-Admins-All |
Labs 4, 5, 6; Windows Enterprise rights for the lab desktops |
| Microsoft Entra ID P2 | Lab-Users-All, Lab-Admins-All |
PIM (Lab 0), Identity Protection (Lab 3) |
| Microsoft Entra Suite (or Private Access + Internet Access standalone) | Lab-Users-All |
Lab 5 |
| Microsoft 365 Copilot (optional) | Lab-Users-All |
Lab 6 Tasks 2 and 3 |
Ten of each licence covers every pod; trial subscriptions (usually 25) are enough.
3. Identities and groups
| Object | Naming | Notes |
|---|---|---|
| Pod admin | lab-adminNN@aurnis.dev, NN = 01 to 10 |
No standing roles. PIM-eligible for the six roles below. Temporary password, force change at first sign-in. Usage location set (licensing). |
| Pod user | lab-userNN@aurnis.dev |
No roles. Member of Lab-Users-NN and Lab-Users-All. Assigned user of LAB-PC-NN. Usage location set. |
| Per-pod group | Lab-Users-NN |
Security group, single member lab-userNN. Target of every pod policy. |
| All users | Lab-Users-All |
Every lab-userNN. Target of every BASE- policy and the GSA forwarding profiles. |
| All admins | Lab-Admins-All |
Every lab-adminNN. Excluded from all BASE- block policies. |
| Break-glass | one cloud-only Global Administrator | Excluded from every Conditional Access policy. FIDO2 key or passkey only. |
PIM-eligible roles for every pod admin, maximum activation 4 hours, MFA on activation, justification required: Conditional Access Administrator, Authentication Policy Administrator, Security Operator, Intune Administrator, Global Secure Access Administrator, Security Reader.
Temporary Access Pass: issue one per pod user before the event (Users, the user, Authentication methods, Add authentication method, Temporary Access Pass, one-time use, valid for the whole session). Print it on the pod card.
4. Baseline objects
Every object below is prefixed BASE- (policies) or named exactly as shown. Pods read
them and never change them.
| Object | Where | Settings | Scope |
|---|---|---|---|
| Passkey (FIDO2) method | Entra, Protection, Authentication methods, Policies | Enabled, target All users, self-service set up allowed, no key restrictions | Lab 2 |
| Microsoft Authenticator method | same | Enabled, number matching, show app name and location | Lab 0 |
| Temporary Access Pass method | same | Enabled, one-time use, maximum lifetime 8 hours | Lab 2 fallback |
| MFA registration policy | Entra, Protection, Identity Protection, Multifactor authentication registration policy | Enabled. Without it the "More information required" interrupt in Lab 0 never appears and pods reach Lab 2 with no Authenticator. | Lab-Users-All, Lab-Admins-All |
BASE-User-risk-Block |
Conditional Access | Users Lab-Users-All; exclude Lab-Admins-All, break-glass. All resources. Condition user risk High. Grant Block. On. |
Lab 3 |
BASE-Sign-in-risk-MFA |
Conditional Access | Users Lab-Users-All; exclude admins, break-glass. All resources. Condition sign-in risk Medium and High. Grant Require MFA. Session sign-in frequency every time. On. |
Lab 3 |
BASE-Windows-Compliance |
Intune, Devices, Manage devices, Compliance | Windows 10 and later. Defender real-time protection on, minimum OS 10.0.26100. No BitLocker requirement. Non-compliant immediately. Assign to a device group (dynamic: device name starts with LAB-PC-) as well as Lab-Users-All; pool-built session hosts have no user affinity, so a user-only assignment can leave them Not evaluated. |
Lab 4 |
AVD host pool hp-lab-day1 |
Azure, Azure Virtual Desktop | Personal, direct assignment. Windows 11 Enterprise 24H2 single-session. Join Microsoft Entra ID with Enrol VM with Intune ticked. LAB-PC-NN assigned to lab-userNN. Users need Virtual Machine User Login on the resource group. RDP Properties, Advanced: add targetisaadjoined:i:1, or the web client cannot sign in to Entra-joined hosts. Start VM on connect enabled. Ten hosts. |
Labs 4, 5, 6 |
| GSA client on session hosts | Custom script extension or Intune Win32 app | Latest Global Secure Access client for Windows. Verify the tray icon shows Connected after the first user sign-in. | Lab 5 |
| Global Secure Access activation | Entra, Global Secure Access, Get started | Activate. Connect, Traffic forwarding: Microsoft 365, Private access and Internet access profiles all enabled and assigned to Lab-Users-All. |
Lab 5 |
| Conditional Access signalling | Entra, Global Secure Access, Settings, Session management, Adaptive access | Enable Conditional Access signaling On and Source IP restoration On. This creates the All Compliant Network locations named location that Lab 5 Task 5 depends on. |
Lab 5 |
| Private Network connector | A Windows Server VM in the intranet VNet | Connector installed, connector group Lab-Connectors. |
Lab 5 |
| Intranet web server | Windows or Linux VM, private IP only, same VNet | Serves a one-page "Contoso intranet" site on port 80. Private DNS zone lab.internal with A record intranet. |
Lab 5 |
Lab-Intranet |
Entra, Global Secure Access, Applications, Enterprise applications | Private Access app. Segment: FQDN intranet.lab.internal, TCP 80, connector group Lab-Connectors. Users Lab-Users-All. |
Lab 5 |
BASE-Block-Gambling |
Global Secure Access, Secure, Web content filtering policies | Action Block. Rule: web category Gambling. | Lab 5 |
BASE-Lab-Profile |
Global Secure Access, Secure, Security profiles | Priority 500. Links BASE-Block-Gambling at priority 100. |
Lab 5 |
BASE-GSA-Internet-Access |
Conditional Access | Users Lab-Users-All. Target: Global Secure Access, Internet traffic. Session: security profile BASE-Lab-Profile. On. Create at least 2 hours before the session so tokens carry the profile. |
Lab 5 |
SharePoint site Day1Lab |
https://aurnistech.sharepoint.com/sites/Day1Lab |
Team site. Members: Lab-Users-All. Libraries: Public (inherits), Restricted (unique permissions, Lab-Users-All read), Confidential (unique permissions, instructor only). Sample files: Project-Plan.docx and Vendor-Notes.docx in Public and Restricted, Budget-FY27.xlsx in Confidential. |
Labs 4, 5, 6 |
Sensitivity label Lab Confidential |
Purview, Information protection, Labels | Encryption on. Permissions: Lab-Users-All Viewer, instructor Co-Author. Published to Lab-Users-All. Applied to Public/Lab-Confidential-Sample.docx. |
Lab 6 |
5. Screenshots for the guide
Every lab page has screenshot slots that render as labelled placeholders until the image
exists. Capture them during the dry run at 1400 px wide, PNG, and save them to
site-src/docs/assets/shots/ with the exact file names below. Redact nothing except real
passwords; the pod accounts are disposable.
| File | Page | What to capture |
|---|---|---|
| lab0-01-more-info-required.png | Lab 0 | "More information required" page |
| lab0-02-authenticator-qr.png | Lab 0 | "Keep your account secure" QR code page |
| lab0-03-pim-eligible.png | Lab 0 | PIM, My roles, Microsoft Entra roles, Eligible assignments with six roles |
| lab0-04-pim-activate.png | Lab 0 | Activate panel with duration 4 and reason "Day 1 lab" |
| lab0-05-security-info.png | Lab 0 | My Account, Security info, Authenticator listed |
| lab0-06-windows-app-devices.png | Lab 0 | Windows App, Devices, the LAB-PC tile |
| lab1-01-overview.png | Lab 1 | Zero Trust Assessment demo, Overview |
| lab1-02-identity.png | Lab 1 | Zero Trust Assessment demo, Identity pillar |
| lab2-01-auth-methods.png | Lab 2 | Authentication methods, Policies list |
| lab2-02-new-policy-blank.png | Lab 2 | Empty New policy page |
| lab2-03-users-group.png | Lab 2 | Users assignment with Lab-Users-NN selected |
| lab2-04-target-exchange.png | Lab 2 | Target resources with Exchange Online ticked |
| lab2-05-grant-strength.png | Lab 2 | Grant, Require authentication strength, Phishing-resistant MFA |
| lab2-06-user-blocked.png | Lab 2 | The user's interrupt or block page |
| lab2-07-signin-log-ca.png | Lab 2 | Sign-in log, Conditional Access tab, policy Failure |
| lab2-08-add-passkey.png | Lab 2 | Security info, Add sign-in method, Passkey in Authenticator |
| lab2-09-passkey-qr.png | Lab 2 | Cross-device passkey QR code at sign-in |
| lab3-01-base-user-risk.png | Lab 3 | BASE-User-risk-Block policy open |
| lab3-02-account-blocked.png | Lab 3 | "Your account is blocked" page |
| lab3-03-risky-users.png | Lab 3 | Risky users with lab-userNN selected, Confirmed compromised |
| lab3-04-risky-signin-ca.png | Lab 3 | Risky sign-in, Conditional Access tab |
| lab3-05-dismiss-risk.png | Lab 3 | Risky user panel with Dismiss user risk button |
| lab4-01-intune-device.png | Lab 4 | Intune device overview, Compliant |
| lab4-02-compliance-policy.png | Lab 4 | BASE-Windows-Compliance properties |
| lab4-03-target-sharepoint.png | Lab 4 | Target resources with SharePoint Online ticked |
| lab4-04-grant-compliant.png | Lab 4 | Grant, Require device to be marked as compliant |
| lab4-05-cant-get-there.png | Lab 4 | "You can't get there from here" page |
| lab4-06-windows-app-connect.png | Lab 4 | Windows App connect dialog |
| lab4-07-sharepoint-opens.png | Lab 4 | Day1Lab open in Edge on the lab desktop |
| lab5-01-gsa-dashboard.png | Lab 5 | Global Secure Access dashboard |
| lab5-02-traffic-forwarding.png | Lab 5 | Traffic forwarding, three profiles |
| lab5-03-private-app-segment.png | Lab 5 | Lab-Intranet network access properties |
| lab5-04-gsa-client-connected.png | Lab 5 | GSA client, Connections view |
| lab5-05-intranet-page.png | Lab 5 | Contoso intranet page in Edge on the desktop |
| lab5-06-category-blocked.png | Lab 5 | Gambling site blocked in Edge |
| lab5-07-traffic-logs.png | Lab 5 | Traffic logs filtered by user with both flows |
| lab5-08-network-compliant-exclude.png | Lab 5 | Network assignment excluding All Compliant Network locations |
| lab5-09-wcf-policy.png | Lab 5 | Web content filtering policy wizard |
| lab5-10-security-profile.png | Lab 5 | Security profile wizard with policy linked |
| lab5-11-ca-session-profile.png | Lab 5 | CA Session control with the security profile |
| lab6-01-access-denied.png | Lab 6 | SharePoint Access denied |
| lab6-02-copilot-allowed.png | Lab 6 | Copilot Chat citing allowed files |
| lab6-03-copilot-denied.png | Lab 6 | Copilot Chat refusing the confidential file |
| lab6-04-label-banner.png | Lab 6 | Word for the web with the Lab Confidential label |
6. Timing notes
| What | Delay to expect | Consequence for the runbook |
|---|---|---|
| New Conditional Access policy | 1 to 2 minutes | Every lab page already warns pods. |
| New GSA security profile in a token | Up to 90 minutes | Create BASE-GSA-Internet-Access well before the session; pod profiles are report-only. |
| Intune compliance evaluation on a new device | Up to 8 hours for the first evaluation | Build and sign in to every LAB-PC-NN the day before and confirm Compliant in Intune. |
| AVD first connection | About 2 minutes if the VM is deallocated | Start all hosts 60 minutes before the session. |
| PIM activation | About 1 minute per role | Lab 0 budgets 10 minutes. |
7. Day-of timeline
| Time | Action |
|---|---|
| T-1 day | Full rehearsal with two pods' worth of accounts. Reset afterwards. Confirm every LAB-PC-NN shows Compliant. |
| T-60 min | Start all session hosts. Open the Entra admin center as break-glass on the instructor laptop. Check BASE-GSA-Internet-Access is On. |
| T-0 | Hand out pod cards (pod number, two temporary passwords, one Temporary Access Pass). Pods start Lab 0. |
| Start of Lab 3 | Only after every pod has finished Lab 2 Task 4 (passkey registered and signed in), run the confirm-compromised call for every pod user (Graph POST /identityProtection/riskyUsers/confirmCompromised with the list of user IDs). Announce that users are now flagged. Running it early blocks slow pods mid-registration. |
| During Lab 5 | Keep the traffic logs page open on the main screen to show flows arriving. |
| T+150 min | Wrap-up. Ask pods to sign out everywhere. |
| After | Run the reset (section 8). Deallocate session hosts. |
8. Reset between events
- Delete every Conditional Access policy whose name starts with
CA-followed by two digits. Leave allBASE-policies. - Delete every web content filtering policy
WCF-NN-*and security profileSP-NN. - Dismiss user risk for every
lab-userNN. - Revoke sessions and reset passwords for every
lab-adminNNandlab-userNN. Remove their registered authentication methods (Authenticator and passkeys) so the next pod registers fresh. Issue new Temporary Access Passes. - Deactivate any active PIM assignments.
- Confirm the Conditional Access policy count: 10 pods x 4 = 40 plus the baseline policies.
- Sign out all sessions on every
LAB-PC-NNand deallocate them.
Scripts for sections 3 and 8 are delivered separately in the tooling folder of the
repository.