Lab 4 – Secure User Access & Privileged Identity Management
MS-102: Microsoft 365 Administrator Essentials
Overview
Hardened user authentication with smart lockout and MFA controls, then deployed and tested three distinct PIM role activation workflows — admin approval, self-approval, and peer approval. Also completed a Microsoft Learn exercise assigning Azure resource roles through PIM.
Tasks Completed
- Reviewed and configured Microsoft Entra smart lockout thresholds and lockout duration
- Verified MFA registration requirements and SSPR policy settings for pilot project users
- Configured a PIM role setting requiring admin approval before role activation
- Tested the admin-approval workflow: submitted a role activation request, approved it as a second admin, and verified activation
- Configured a second PIM role for self-approval and validated the self-service activation flow end-to-end
- Configured a third PIM role for teammate approval and verified the peer-approval path end-to-end
- Assigned an Azure Virtual Machine Contributor resource role in PIM and configured activation duration and justification requirements (Microsoft Learn exercise)
Source Material
Completed using Exercise 1, Exercise 2, Exercise 3, and Exercise 4 from the MS-102T00 MicrosoftLearning GitHub repository; and Assign Azure Resource Roles in PIM from Microsoft Learn. All steps were executed in a personal, paid Microsoft 365 test tenant.
← Back to MS-102 Labs