Lab 6 – Alert Policies & Attack Simulation Training
MS-102: Microsoft 365 Administrator Essentials
Overview
Created compliance alert policies for mailbox permission changes, SharePoint permission changes, and eDiscovery case activity. Then ran phishing and password spray attack simulations and validated that both the alerts and simulation results fired correctly.
Tasks Completed
- Verified audit logging status and IRM configuration as prerequisites for alert policy creation
- Created a mailbox permission alert policy to fire on non-owner mailbox access events
- Created a SharePoint permission change alert policy targeting site permission modifications
- Created an eDiscovery case activity alert policy to monitor compliance case actions
- Launched a credential harvest phishing simulation targeting pilot project users via Attack Simulation Training
- Launched a password spray attack simulation to test user susceptibility
- Triggered mailbox and SharePoint alert conditions to generate test notifications
- Validated that alert notifications fired and reviewed simulation click rates, user behavior reports, and training assignment results in the Microsoft Defender portal
Source Material
Completed using Lab 6 Exercises 1–7 from the MS-102T00 MicrosoftLearning GitHub repository: Ex1, Ex2, Ex3, Ex4, Ex5, Ex6, Ex7. All steps were executed in a personal, paid Microsoft 365 test tenant.
← Back to MS-102 Labs