Skip to content

2026

Entra ID Identity & Access Governance Lab

Risk-based Conditional Access, just-in-time admin access, access packages and access reviews in an Entra ID P2 tenant, tied to an Intune-compliant Windows 11 device.

Overview

Built an identity and access governance lab in an Entra ID P2 trial tenant with an Intune-enrolled Windows 11 VM. Covers MFA registration enforcement, risk-based Conditional Access (user risk and sign-in risk), Privileged Identity Management with just-in-time Global Administrator access, entitlement management with approval workflows, automated access reviews, and break-glass accounts excluded from every policy to prevent tenant lockout. Includes PowerShell validation scripts and exported policy templates.

Highlights

  • Built four Conditional Access policies: require compliant device, MFA registration, user-risk remediation (high risk forces MFA and a password change) and sign-in risk (medium/high requires MFA)
  • Configured PIM so Global Administrator is eligible rather than permanently active, with MFA, a written justification and a 2-hour activation window
  • Created break-glass emergency accounts in a group excluded from every policy, so no policy change can lock admins out of the tenant
  • Set up entitlement management (catalog and access package with an approver and an expiry date) and an automated access review that removes access if reviewers do not respond
  • Documented the build with 54 screenshots, wrote Microsoft Graph PowerShell validation scripts, and exported the policy and PIM settings as JSON templates

Tech stack

  • Microsoft Entra ID P2
  • Conditional Access
  • Identity Protection
  • Privileged Identity Management
  • Entitlement Management
  • Access Reviews
  • Intune
  • Microsoft Graph PowerShell