Wrap-up
What your pod built this afternoon
| Layer | What you did | Object you own |
|---|---|---|
| Identity | Signed in with least-privilege, time-bound admin roles | PIM activations |
| MFA | Required phishing-resistant authentication and proved a passkey beats a stolen password | CA-NN-Phishing-Resistant |
| Risk | Watched a compromised account get blocked automatically, investigated, remediated | Risk history for lab-userNN |
| Device | Required a compliant, Intune-managed device for SharePoint | CA-NN-Require-Compliant-Device |
| Network | Reached a private app with no VPN, blocked a web category, required the compliant network | CA-NN-Compliant-Network, WCF-NN-Block-Social, SP-NN, CA-NN-Internet-Profile |
| Data | Confirmed Copilot inherits permissions and labels travel with files | your observations |
Read the table top to bottom: Identity, MFA, Risk, Device, Network, Data, AI. Each layer only makes sense because the one above it holds. That is the order in which to fix a real tenant before AI is switched on, and it is the order Day 1 of this workshop follows.
The one-line version
A valid user with a phishing-resistant sign-in, on a compliant device, through the compliant network, to an authorised app, reading data they are permitted to read. Anything less is a block, not a warning.
Take it home
- Microsoft Entra Suite trial: 90 days of Private Access, Internet Access, ID Governance, ID Protection and Verified ID.
- Zero Trust Assessment: run the real report on your own tenant.
- Global Secure Access documentation: deployment guides for Private Access and Internet Access.
- Conditional Access authentication strengths: how to roll out phishing-resistant MFA in stages.
- Microsoft 365 Copilot data protection: how Copilot honours permissions and labels.
Kloudynet runs Zero Trust assessments, Entra Suite deployments and Copilot readiness reviews across Malaysia, Singapore and the UAE. Talk to us at www.kloudynet.com.
Before you leave
- Sign out of the User window and close it
- Sign out of the Admin window and close it
- Sign out of
LAB-PC-NN(Start, your name, Sign out) - Driver: remove the two lab accounts from Microsoft Authenticator when you are home; the accounts are reset after the event
- Hand the pod card back to the instructor
Thank you for building with us.