This lab documents baseline Microsoft Entra ID security hardening controls, including Multifactor Authentication, Self-Service Password Reset, Conditional Access, and legacy authentication blocking.
The goal is to demonstrate safe, documented, and testable identity security administration.
- Microsoft Entra ID security baseline documentation
- Multifactor Authentication planning
- Self-Service Password Reset awareness
- Conditional Access policy documentation
- Legacy authentication blocking
- Break-glass account awareness
- Testing and rollback planning
| Control | Purpose |
|---|---|
| Multifactor Authentication | Reduces risk from stolen passwords |
| Self-Service Password Reset | Enables controlled password recovery |
| Conditional Access | Applies access decisions based on user, device, app, risk, and location |
| Legacy Authentication Blocking | Reduces risk from older protocols that cannot satisfy modern controls |
| Break-glass Account | Emergency administrative access if normal access fails |
Conditional Access policies can lock administrators out if incorrectly configured. This lab uses documentation, staged testing, report-only where appropriate, and break-glass account planning.
No sensitive tenant details are published.
In progress.
Security and Privacy Notice
This repository is for portfolio and lab demonstration purposes only.
It does not contain:
- Real business data
- Live customer data
- Passwords
- Access tokens
- Tenant secrets
- Private keys
- Full tenant IDs
- Unredacted email addresses
- Confidential screenshots
All screenshots and examples are redacted before publication.