Course 05 · Founder cohort forming
Ten modules on the identity layer that either enables Zero Trust or silently defeats it. Conditional Access design — the ten policies every tenant needs and the five that shouldn't exist. Privileged Identity Management. Break-glass account hygiene. Guest access strategy. Cross-tenant access settings. And the audit and access-review programmes that keep it running.
Founder cohort — first fifty enrolments get 40% off launch pricing
Founder pricing
40% off standard CA$399 · locked in for founder cohort
Zero commitment · you pay only when the course ships
Why this course exists
Most M365 tenants have Conditional Access policies. Most of those policies were built by whichever admin was on call the day the security auditor called. They have five overlapping "MFA everywhere" policies, one that quietly excludes the CFO, and a break-glass account whose password hasn't been rotated in three years.
This course teaches Entra ID configuration as a coherent Zero Trust programme — not a pile of policies. The ten Conditional Access policies every tenant needs, in the right order, with the right exclusions, tested against the right personas. Privileged Identity Management as a working programme, not a checkbox. Break-glass account hygiene that survives an audit. Guest access strategy that lets the business collaborate without leaking identity data. And the operational cadence — access reviews, audit, incident response — that keeps the model working when the consultant leaves.
Curriculum
Each module includes video walkthrough, written reference, policy templates, and a knowledge-check quiz.
What Zero Trust actually means in a Microsoft 365 tenant. The Microsoft Zero Trust maturity model. The gap between "we bought E5" and "we implement Zero Trust." What to prioritise first, second, and never.
The ten Conditional Access policies every M365 tenant needs. Persona-based design (admins, users, guests, service accounts). Exclusion strategy. Report-only mode discipline. Testing plans that don't lock you out.
Device compliance, sign-in risk, user risk, session controls, continuous access evaluation. Restricted authentication contexts for high-sensitivity apps. Application-specific policies for Copilot, Power Platform, and third-party SaaS.
PIM as a working programme, not a checkbox. Role assignment hygiene. Just-in-time activation. Approval workflows for high-privilege roles. Access reviews specific to admin roles. Break-glass exclusions.
The two break-glass accounts every tenant needs. Naming, exclusion from Conditional Access, monitoring, rotation cadence, and the audit trail that survives an ISO 27001 review. What happens if the break-glass account itself is compromised.
B2B collaboration architecture. Guest onboarding via self-service. Cross-tenant sync. Federation trust decisions. Guest access-review programme. The five guest-access mistakes every organisation makes.
Cross-tenant access settings for B2B. Cross-tenant sync. B2B direct connect. Trust settings for MFA, device compliance, and Hybrid AD Join. How to design cross-tenant collaboration for M&A, subsidiaries, and long-running partnerships.
Entra ID Governance access reviews. Access packages. Entitlement management. How to design a review programme that scales beyond quarterly manual reviews. Automation, reviewer selection, and reporting.
Entra sign-in logs, audit logs, and provisioning logs. Log retention. Export to Log Analytics or SIEM. Investigation runbooks for common incidents (account takeover, impossible travel, guest privilege escalation).
Bringing the previous nine modules into a running operational programme. Steering cadence, exception process, joiner-mover-leaver lifecycle, and the metrics that tell you whether your Zero Trust posture is actually improving or just accumulating policies.
First fifty enrolments lock in CA$239. Zero payment now — we'll email when the course ships.