Phase 3: Entra ID and Hybrid Identity Support
Identity support evidence covering Entra users and groups, delegated roles, sign-in investigation, MFA/SSPR support, hybrid identity readiness and a controlled Entra Connect sync pilot.
Phase Summary
This phase moves the lab from general Microsoft 365 administration into modern identity support. It is designed to show realistic helpdesk and service desk work: delegated password support, sign-in investigation, MFA/SSPR configuration, hybrid identity preparation and controlled sync validation before any wider rollout.
Lab 11: Entra ID Users, Groups and Roles
Configured cloud identity groups and delegated helpdesk administration using least privilege.
- Entra security group review
- Helpdesk group membership
- Role assignment through a group
- Password reset capability validation
Lab 12: Entra Sign-In Logs, MFA and SSPR Support
Investigated user sign-in failures and configured controlled MFA/SSPR support settings.
- Failed sign-in log review
- Error detail analysis
- SSPR pilot scoping
- Authentication method validation
Lab 13: Hybrid Identity Readiness
Prepared Active Directory for a controlled hybrid identity pilot without synchronizing the whole domain.
- Hybrid Pilot OU structure
- Public UPN suffix validation
- Pilot user sign-in alignment
- User, device and support/admin validation groups
Lab 14: Hybrid Identity Sync Pilot
Deployed Microsoft Entra Connect Sync on a dedicated server and validated a scoped pilot sync.
- SYNC1 dedicated sync server
- OU filtering to Hybrid Pilot
- Password Hash Synchronization
- Synced pilot user and groups validated in Entra ID