Lab 06: MFA, Password Reset and Licensing

Validated the Nietz Ltd Microsoft 365 account-security baseline across Office 365 E5 licensing, MFA pilot scope, authentication methods, user security information, Self-Service Password Reset readiness and Entra sign-in evidence.

Overview

In this lab, I built on the Microsoft 365 user administration work completed in Lab 05. I reviewed the Office 365 E5 licensing baseline for the existing @nietz.co.uk cloud identities, validated user-level licence assignment, checked the controlled MFA pilot scope, confirmed available authentication methods, reviewed Self-Service Password Reset readiness, and validated Chloe Bennett's security information and sign-in logs.

This lab keeps the same Nietz Ltd environment established across Labs 01-05: on-premises Active Directory uses corp.nietz.co.uk, while Microsoft 365 user sign-in uses nietz.co.uk. Hybrid identity is still planned for Lab 12 and was not configured in this lab.

Objective

The objective was to produce clean build evidence for Microsoft 365 account security and licensing readiness before moving into Exchange Online and Outlook. The lab validated Office 365 E5 licence usage, user-level licence assignment, pilot group targeting, authentication method availability, user-side MFA/security information, Self-Service Password Reset readiness, and successful OfficeHome sign-in events.

Environment

Environment
ComponentValue
CompanyNietz Ltd
On-premises AD Domaincorp.nietz.co.uk
NetBIOS NameCORP
Microsoft 365 / Tenant Domainnietz.co.uk
Tenant Admin[email protected] - setup/global admin, intentionally unlicensed
Daily Admin[email protected] - licensed daily administrator
Primary Validation User[email protected]
Pilot GroupGRP_CA_Pilot
Previous Lab DependencyLab 05: Microsoft 365 User Admin

Configuration

1. Office 365 E5 Licensing Baseline

I reviewed the Office 365 E5 licensing baseline before applying account security checks. This confirmed assigned licence usage and validated that the core Nietz Ltd user accounts, including Mia Taylor, were present with the correct @nietz.co.uk primary email format.

Office 365 E5 licensing baseline showing assigned users including Mia Taylor
Figure 1Office 365 E5 licensing baseline reviewed, showing assigned users and correct @nietz.co.uk email format.
Context: Licensing baseline checks are important before troubleshooting or configuring Microsoft 365 services because licence state affects mailbox availability, Microsoft 365 apps, Teams, SharePoint, OneDrive, and later service testing.

2. User-Level Licence Assignment

I opened Chloe Bennett's user record and confirmed that the Office 365 E5 licence was assigned with the United Kingdom usage location set.

Chloe Bennett Licenses and apps page showing Office 365 E5 assigned
Figure 2Office 365 E5 licence assignment validated for Chloe Bennett.
Context: User-level licence checks are common Microsoft 365 support tasks because licence state affects mailbox availability, Microsoft 365 apps, Teams, SharePoint, OneDrive, and later service testing.

3. MFA Pilot Scope

I confirmed that GRP_CA_Pilot contained the controlled pilot users [email protected] and [email protected].

GRP_CA_Pilot showing Chloe Bennett and Kristian Nietzold as members
Figure 3GRP_CA_Pilot confirmed with Chloe Bennett and Kristian Nietzold as pilot members.
Context: Piloting identity controls against a small group reduces lockout risk and creates a safe foundation for later Conditional Access and Intune policy work.

4. Authentication Method Policies

I reviewed the Authentication methods policy page and confirmed which sign-in methods were enabled or disabled in the tenant.

Authentication methods policies showing enabled and disabled authentication methods
Figure 4Authentication methods reviewed, including Microsoft Authenticator, Temporary Access Pass, Software OATH tokens, and Email OTP availability.
Context: Authentication method visibility is important for MFA readiness and user support. This lab reviewed available methods only; it did not create or enforce Conditional Access policies.

5. Password Reset Readiness Review

I reviewed Self-Service Password Reset and confirmed that full SSPR rollout required Premium licensing or an eligible trial before it could be configured for the intended scope.

Self-Service Password Reset page showing Premium trial requirement
Figure 5Self-Service Password Reset reviewed and deferred until Premium/Business Premium licensing is active.
Context: Identifying licensing limitations is a realistic Microsoft 365 administration task. Full SSPR configuration will be revisited after the appropriate Business Premium or Entra Premium licensing is available.

6. User Security Information

I validated Chloe Bennett's user-side security information and confirmed that an authenticator app method was registered for sign-in.

Chloe Bennett Security info page showing password and authenticator app methods
Figure 6Chloe Bennett's security information confirmed an authenticator app registered for sign-in.
Context: Security info checks are directly relevant to helpdesk work because users often need support with changed phones, authenticator registration, missing methods, or repeated MFA prompts.

7. Entra Sign-In Log Validation

I filtered Entra sign-in events for Chloe Bennett and confirmed successful OfficeHome sign-ins after the licence and authentication readiness checks.

Entra sign-in events filtered to successful OfficeHome sign-ins for Chloe Bennett
Figure 7Entra sign-in events confirmed successful OfficeHome sign-ins for Chloe Bennett.
Context: Sign-in logs provide admin-side evidence of successful user access and are a key tool for Microsoft 365 helpdesk and identity troubleshooting.

Validation

The lab was validated when the Office 365 E5 licensing baseline showed the expected assigned users, Chloe Bennett's Office 365 E5 licence was confirmed, GRP_CA_Pilot contained the intended pilot users, authentication methods were reviewed, Chloe Bennett's security information showed an authenticator app method, and Entra sign-in events showed successful OfficeHome access.

Self-Service Password Reset was reviewed but not configured because the tenant prompted for Premium licensing. This was recorded as a deferred item for a later Business Premium or Entra Premium-enabled phase.

Key Technical Outcomes

This lab demonstrated the relationship between licence assignment, pilot group targeting, authentication method availability, user security information, Self-Service Password Reset readiness, and sign-in log evidence.

It also preserved a safe pilot approach so later Entra ID, Conditional Access, Intune, Exchange, and Outlook labs can build on controlled users and groups rather than broad tenant-wide changes.

Summary

  • I reviewed the Office 365 E5 licensing baseline for the core Nietz Ltd users.
  • I validated Office 365 E5 assignment for Chloe Bennett.
  • I confirmed the GRP_CA_Pilot group contained the intended pilot users.
  • I reviewed tenant authentication method policies for MFA readiness.
  • I reviewed Self-Service Password Reset and deferred full setup until Premium licensing is active.
  • I confirmed Chloe Bennett had an authenticator app registered in Security info.
  • I validated successful OfficeHome sign-ins in Entra sign-in events.
  • I left the tenant ready for Lab 07: Exchange Online.