Course 05 · Founder cohort forming

Microsoft Entra ID for Zero Trust

Ten modules on the identity layer that either enables Zero Trust or silently defeats it. Conditional Access design — the ten policies every tenant needs and the five that shouldn't exist. Privileged Identity Management. Break-glass account hygiene. Guest access strategy. Cross-tenant access settings. And the audit and access-review programmes that keep it running.

Founder cohort — first fifty enrolments get 40% off launch pricing

Founder pricing

CA$239 at launch

40% off standard CA$399 · locked in for founder cohort

  • 10 modules · 12 hours of content
  • Practitioner guide (PDF)
  • Conditional Access policy library
  • Access-review templates
  • Certification exam + LinkedIn credential
  • Lifetime access + free updates
Reserve your spot →

Zero commitment · you pay only when the course ships

Why this course exists

"We have Conditional Access" is not a Zero Trust posture.

Most M365 tenants have Conditional Access policies. Most of those policies were built by whichever admin was on call the day the security auditor called. They have five overlapping "MFA everywhere" policies, one that quietly excludes the CFO, and a break-glass account whose password hasn't been rotated in three years.

This course teaches Entra ID configuration as a coherent Zero Trust programme — not a pile of policies. The ten Conditional Access policies every tenant needs, in the right order, with the right exclusions, tested against the right personas. Privileged Identity Management as a working programme, not a checkbox. Break-glass account hygiene that survives an audit. Guest access strategy that lets the business collaborate without leaking identity data. And the operational cadence — access reviews, audit, incident response — that keeps the model working when the consultant leaves.

Curriculum

Ten modules. Zero Trust that actually holds.

Each module includes video walkthrough, written reference, policy templates, and a knowledge-check quiz.

Module 01

Zero Trust Principles for M365

What Zero Trust actually means in a Microsoft 365 tenant. The Microsoft Zero Trust maturity model. The gap between "we bought E5" and "we implement Zero Trust." What to prioritise first, second, and never.

Module 02

Conditional Access Foundation

The ten Conditional Access policies every M365 tenant needs. Persona-based design (admins, users, guests, service accounts). Exclusion strategy. Report-only mode discipline. Testing plans that don't lock you out.

Module 03

Conditional Access Advanced Patterns

Device compliance, sign-in risk, user risk, session controls, continuous access evaluation. Restricted authentication contexts for high-sensitivity apps. Application-specific policies for Copilot, Power Platform, and third-party SaaS.

Module 04

Privileged Identity Management

PIM as a working programme, not a checkbox. Role assignment hygiene. Just-in-time activation. Approval workflows for high-privilege roles. Access reviews specific to admin roles. Break-glass exclusions.

Module 05

Break-Glass Accounts

The two break-glass accounts every tenant needs. Naming, exclusion from Conditional Access, monitoring, rotation cadence, and the audit trail that survives an ISO 27001 review. What happens if the break-glass account itself is compromised.

Module 06

Guest Access & External Identities

B2B collaboration architecture. Guest onboarding via self-service. Cross-tenant sync. Federation trust decisions. Guest access-review programme. The five guest-access mistakes every organisation makes.

Module 07

Cross-Tenant Access Settings

Cross-tenant access settings for B2B. Cross-tenant sync. B2B direct connect. Trust settings for MFA, device compliance, and Hybrid AD Join. How to design cross-tenant collaboration for M&A, subsidiaries, and long-running partnerships.

Module 08

Access Reviews at Scale

Entra ID Governance access reviews. Access packages. Entitlement management. How to design a review programme that scales beyond quarterly manual reviews. Automation, reviewer selection, and reporting.

Module 09

Audit & Sign-in Log Analysis

Entra sign-in logs, audit logs, and provisioning logs. Log retention. Export to Log Analytics or SIEM. Investigation runbooks for common incidents (account takeover, impossible travel, guest privilege escalation).

Module 10

Identity Governance Programme

Bringing the previous nine modules into a running operational programme. Steering cadence, exception process, joiner-mover-leaver lifecycle, and the metrics that tell you whether your Zero Trust posture is actually improving or just accumulating policies.

Reserve your founder-cohort spot.

First fifty enrolments lock in CA$239. Zero payment now — we'll email when the course ships.

← Back to MigrationFox Learn