Phase 3: Entra ID and Hybrid Identity Support

Identity support evidence covering Entra users and groups, delegated roles, sign-in investigation, MFA/SSPR support, hybrid identity readiness and a controlled Entra Connect sync pilot.

Phase Summary

This phase moves the lab from general Microsoft 365 administration into modern identity support. It is designed to show realistic helpdesk and service desk work: delegated password support, sign-in investigation, MFA/SSPR configuration, hybrid identity preparation and controlled sync validation before any wider rollout.

Lab 11: Entra ID Users, Groups and Roles

Configured cloud identity groups and delegated helpdesk administration using least privilege.

  • Entra security group review
  • Helpdesk group membership
  • Role assignment through a group
  • Password reset capability validation
Open Lab

Lab 12: Entra Sign-In Logs, MFA and SSPR Support

Investigated user sign-in failures and configured controlled MFA/SSPR support settings.

  • Failed sign-in log review
  • Error detail analysis
  • SSPR pilot scoping
  • Authentication method validation
Open Lab

Lab 13: Hybrid Identity Readiness

Prepared Active Directory for a controlled hybrid identity pilot without synchronizing the whole domain.

  • Hybrid Pilot OU structure
  • Public UPN suffix validation
  • Pilot user sign-in alignment
  • User, device and support/admin validation groups
Open Lab

Lab 14: Hybrid Identity Sync Pilot

Deployed Microsoft Entra Connect Sync on a dedicated server and validated a scoped pilot sync.

  • SYNC1 dedicated sync server
  • OU filtering to Hybrid Pilot
  • Password Hash Synchronization
  • Synced pilot user and groups validated in Entra ID
Open Lab

← Previous Phase Microsoft Infrastructure Next Phase →