AdvancedENTRA-HARD-001

Entra ID Hardening — Identity Protection Deep-Dive

Eliminate identity risk in Microsoft Entra ID with risk-based access, PIM, and Zero Trust controls

Identity is the new perimeter — and Microsoft Entra ID is the identity perimeter for most Australian organisations. This deep-dive programme goes beyond Conditional Access fundamentals into risk-based access, Entra ID Protection, Privileged Identity Management (PIM) at scale, lifecycle automation, and continuous access evaluation — building a hardened Entra ID posture aligned to ASD Essential Eight ML2 and the ACSC Information Security Manual identity control families.

24 hours (3 days intensive or 6 weeks part-time)
New course
Certificate Included
Entra ID Hardening — Identity Protection Deep-Dive

At a Glance

Who it's for

  • Identity engineers who completed the Conditional Access Workshop and want depth beyond policy design
  • Entra ID administrators implementing Privileged Identity Management for Essential Eight ML2
  • Security architects hardening identity infrastructure before Copilot deployment
  • IT managers accountable for identity security posture under ACSC ISM and privacy obligations

Course Details

Duration:24 hours (3 days intensive or 6 weeks part-time)
Format:Live online deep-dive — 3 days intensive or 6 weeks part-time, with individual Entra ID P2 lab access
Next intake:September 2026 — register your interest at educ4te.com
Alignment:Aligned to ASD Essential Eight Maturity Level 2 and 3 (MFA, Restrict Administrative Privileges) and ACSC Information Security Manual identity and access management control families

Course Overview

The Conditional Access Workshop (CA-WS-001) covers policy design and zero-trust fundamentals. This Entra ID Hardening deep-dive takes engineers into the operational detail: how Entra ID Protection risk signals work and how to tune them for Australian organisations, how to implement Privileged Identity Management for every privileged role including Global Administrator, how to automate the identity lifecycle with Lifecycle Workflows so joiner-mover-leaver controls are consistent and auditable, and how Continuous Access Evaluation provides real-time token revocation for high-value sessions. The programme also addresses the specific hardening steps required before deploying Microsoft 365 Copilot — identity hygiene is the most frequently missed prerequisite in Australian Copilot deployments.

What You'll Learn

Configure Entra ID Protection user risk and sign-in risk policies tuned to Australian organisational patterns
Implement named location and travel anomaly policies using ACSC-aligned trusted IP ranges
Deploy Privileged Identity Management (PIM) for all privileged roles: just-in-time activation, approval workflows, and access reviews
Design break-glass accounts and emergency access procedures with audit alerting
Automate joiner-mover-leaver lifecycle using Entra ID Lifecycle Workflows and HR-driven provisioning
Configure Continuous Access Evaluation (CAE) for real-time token revocation on session compromise
Implement Entra ID audit log export to Microsoft Sentinel for persistent identity monitoring
Produce an identity hardening evidence pack aligned to ASD Essential Eight ML2 Restrict Administrative Privileges

Course Curriculum

Module 1: Entra ID Protection — Risk-Based Access

6 hours
  • Entra ID Protection risk signal architecture: sign-in risk, user risk, and the Microsoft threat intelligence feed
  • Risk policy design: self-remediation vs. block vs. MFA step-up — tuning for false positive tolerance
  • Named locations and trusted IP management for Australian offices, VPNs, and cloud egress points
  • Risky user workflow: investigation, remediation, and dismissal procedures for SOC integration
  • Continuous Access Evaluation: real-time token revocation for device compliance loss and location change

Module 2: Privileged Identity Management at Scale

6 hours
  • PIM for Entra ID roles: scope, activation settings, approval workflows, and notification configuration
  • PIM for Azure RBAC roles: resource-scoped just-in-time access for Azure subscription owners
  • PIM access reviews: quarterly review cycles, auto-apply, and reviewer delegation for Essential Eight ML2 evidence
  • Break-glass account design: naming conventions, MFA exclusion, monitoring alerts, and annual access test
  • Privileged Access Workstations (PAW) and Secure Admin Workstation (SAW) concepts for Tier 0 admins

Module 3: Identity Lifecycle Automation

6 hours
  • Entra ID Lifecycle Workflows: joiner, mover, and leaver workflow design and trigger configuration
  • HR-driven provisioning from Workday and SAP SuccessFactors to Entra ID
  • Entitlement Management: access packages, connected organisations, and auto-assignment for role lifecycle
  • Guest user lifecycle: external collaboration policies, review cadence, and automated expiry
  • Access review design: frequency, reviewer selection, and auto-apply for Privacy Act APP 11 obligations

Module 4: Advanced Hardening and Evidence Pack

6 hours
  • Copilot identity prerequisites: sensitivity labels, guest access review, admin role reduction, and Secure Score targets
  • Entra ID audit log export to Sentinel: diagnostic settings, retention, and identity threat analytics
  • Microsoft Secure Score identity hardening: recommended actions mapped to Essential Eight ML2 and ML3
  • Identity hardening evidence pack: PIM access reviews, CA policy exports, and risk policy configurations for IRAP
  • Capstone lab: produce a complete ML2 identity hardening evidence document for an Australian SMB or enterprise scenario

Who Should Attend

  • Identity engineers who have Conditional Access in production and need operational depth
  • Entra ID administrators rolling out Privileged Identity Management for Essential Eight ML2
  • Security architects hardening identity posture ahead of a Microsoft 365 Copilot deployment
  • IT managers accountable for identity security evidence under the ACSC ISM and Privacy Act 1988
  • Platform engineers automating joiner-mover-leaver provisioning from Workday or SAP SuccessFactors
  • IRAP-adjacent assessors and internal auditors reviewing privileged access controls

Prerequisites

Before enrolling, please ensure you meet these requirements:

  • • Completion of the Microsoft Entra Conditional Access Workshop (CA-WS-001) or equivalent operational CA experience
  • • At least one year of Entra ID administration in a production environment
  • • Microsoft Entra ID P2 tenant access — Microsoft 365 E5 or standalone Entra ID P2 (P1 is insufficient)
  • • Global Administrator or Privileged Role Administrator rights in the lab tenant
  • • Familiarity with PowerShell and Microsoft Graph is beneficial but not required

Delivery, Format and Logistics

Delivery Mode

Live online deep-dive — 3 days intensive or 6 weeks part-time, with individual Entra ID P2 lab access

Maximum 10 participants — lab-intensive with individual Entra ID P2 access

What You'll Need

  • Completion of Microsoft Entra Conditional Access Workshop (CA-WS-001) or equivalent operational CA experience
  • Microsoft Entra ID P2 tenant access (Microsoft 365 E5 or standalone Entra ID P2)
  • At least one year of Entra ID administration experience in a production environment
  • Familiarity with PowerShell and Microsoft Graph is beneficial

What You'll Receive

  • 24 hours of lab-intensive instruction capped at 10 participants
  • Individual Entra ID P2 lab tenant for risk policy, PIM and Lifecycle Workflow exercises
  • Risk policy tuning guide for Australian sign-in patterns and named location design
  • PIM rollout templates: activation settings, approval workflows and quarterly access review cycles
  • Break-glass account design standard with monitoring alerts and annual access test procedure
  • Copilot identity prerequisite checklist covering admin role reduction and guest access review
  • Capstone: a complete Essential Eight ML2 identity hardening evidence document for IRAP use
  • Recorded sessions for 6 months and a certificate of completion

Frequently Asked Questions

Not Ready to Enrol?

Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.

By subscribing, you agree to receive email updates from Educ4te. You can unsubscribe at any time. We respect your privacy and will never share your information.

$999AUD
$1299EARLY BIRD

Early-bird rate — apply your promo code at checkout.

1

Secure payment via Stripe · Promo codes accepted

Next Intake

September 2026 — register your interest at educ4te.com

Format

Live online deep-dive — 3 days intensive or 6 weeks part-time, with individual Entra ID P2 lab access

Group & Enterprise Options

Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.

What's Included

  • 24 hours of lab-intensive instruction capped at 10 participants
  • Individual Entra ID P2 lab tenant for risk policy, PIM and Lifecycle Workflow exercises
  • Risk policy tuning guide for Australian sign-in patterns and named location design
  • PIM rollout templates: activation settings, approval workflows and quarterly access review cycles
  • Break-glass account design standard with monitoring alerts and annual access test procedure
  • Copilot identity prerequisite checklist covering admin role reduction and guest access review
  • Capstone: a complete Essential Eight ML2 identity hardening evidence document for IRAP use
  • Recorded sessions for 6 months and a certificate of completion

Have questions about this course?