Course 05 · Available now
Eight modules on the Entra ID stack that makes Zero Trust real. Conditional Access anatomy (four blocks + report-only + policy impact), phishing-resistant MFA (WHfB / FIDO2 / passkeys / TAP), Identity Protection risk-based policies (with the Oct 2026 legacy retirement deadline), Privileged Identity Management, B2B + entitlement management, access reviews + emergency access accounts, and the 90-day rollout playbook.
CA$99 one-time · lifetime access · verified against Microsoft Learn
Enrolment
Lifetime access · no subscription · no renewals
Bundle all 6 courses · CA$399 (once all six ship)
Why this course exists
Everyone talks about Zero Trust. Very few practitioners can tell you the exact combination of Conditional Access policies, risk thresholds, PIM configurations, and break-glass accounts that make it real. This course closes that gap.
Eight modules. Every claim cited against Microsoft Learn. The 90-day rollout playbook that gets you from "we have Entra ID Free" to "we have Zero Trust identity" without locking out a single admin. Includes the licensing truths that stop projects at Day 30 (P2 is required for Identity Protection, PIM, access reviews, and entitlement management — most M365 E3 tenants don't have it).
Also covers the retirement deadlines that will surprise you: legacy Identity Protection risk policies retire October 1 2026 and must be migrated to Conditional Access.
Curriculum
Each module includes written reference, callouts for the traps, tables for the Conditional Access / MFA / PIM / risk matrices, and a knowledge-check quiz. Complete all eight plus the final exam to earn CCEZT certification.
The three principles (verify explicitly / use least privilege / assume breach). Entra ID as the policy decision point. The Microsoft three-tier pattern (Starting point / Enterprise / Specialized security).
Assignments + Conditions + Grant controls + Session controls. Filter for applications. Access tokens by default when no policy matches. Report-only mode + policy impact preview. Continuous access evaluation (CAE).
What qualifies (WHfB, FIDO2, passkeys, platform credential, cert-based). What doesn't (all password + code combos). Authentication Strength CA control. Temporary Access Pass (TAP) for onboarding.
Sign-in risk (per-auth) vs user risk (per-account). Auto-remediation. Microsoft's recommended thresholds. The Oct 2026 legacy retirement migration. Adaptive risk remediation. Admin manual remediation options.
Four assignment types (permanent eligible/active × time-bound). Activation flow (MFA + justification + approval + ticket). 8-hour max activation. Emergency access accounts as the only permanent-active exception. PIM for Azure RBAC roles.
Access packages + policies for self-service external access at scale. Expiration + lifecycle. Auto-remove on non-response access reviews. Cross-tenant access settings. Why exclude the EM app from guest CA.
What access reviews recertify. Reviewer options. Cadence recommendations (monthly for Global Admin, quarterly for guests). The full emergency access ('break-glass') account pattern — two accounts, cloud-only, permanent Global Admin, excluded from all CA.
Licensing matrix (Free vs P1 vs P2 vs ID Governance). 90-day phased rollout (assess → break-glass + baseline CA → enforce + risk → access reviews + external). The four rollout risks that end projects. Role delegation without Global Admin.
Eight modules · CCEZT certification exam · PDF certificate + LinkedIn credential · every claim citing its Microsoft Learn source. No subscription. No renewals.