TechMentor 2-Day Hands-on Virtual Seminar: Rocket-Boost Your Entra ID Skills: Hands-on from Basics to Advanced
December 3-4, 2026
9:00AM – 5:00PM Central
Level: Intermediate / Advanced
Move beyond basic Entra ID administration and learn how to build, govern, and secure identity environments with confidence. In this intensive two-day hands-on seminar, you’ll work in your own test tenant through guided labs based on real-world scenarios.
Day 1 builds your foundation across identity and applications, Administrative Units, Identity Governance, Privileged Identity Management (PIM), and B2B collaboration. Day 2 takes a deep dive into advanced Conditional Access, including phishing-resistant authentication, risk-based access, device controls, session restrictions, and Zero Trust strategies.
You’ll do more than learn where to configure features—you’ll understand how they work together, why particular approaches matter, and how to troubleshoot them when things don’t go as planned. You’ll leave with practical experience and proven strategies you can apply to design, harden, and manage Entra ID in real-world environments.
What You Will Learn:
- A solid, practical understanding of Entra ID fundamentals, delegation (AUs, restricted AUs), identity governance (access packages), PIM (including role enabled groups), B2B collaboration, and advanced Conditional Access.
- Hands on experience implementing and troubleshooting these capabilities in your own test tenant.
- The confidence to design, harden, and operate identity and access solutions that align with Zero Trust and modern security expectations.
Day 1 – Entra ID fundamentals, governance, and B2B
You'll establish the core building blocks for secure identity and access, then layer on governance, delegation, and collaboration capabilities used in real tenants.
Core identity & applications
- User and group types: cloud, guests, security, Microsoft 365, and dynamic groups
- Designing a practical group strategy for roles, licensing, and Conditional Access scoping
- App registrations, service principals, and enterprise applications: understanding the relationships and use cases
- Configuring API permissions (delegated and application) and validating token issuance in test scenarios
- Protecting yourself against over privileged apps: auditing granted permissions, identifying risky consent grants, and narrowing app permissions to the minimum required scopes
Delegation & scoped administration
- Administrative Units (AUs): scoping administration by department, region, or business unit
- Restricted Administrative Units: limiting what admins can do within an AU (e.g., password reset, group management)
Identity Governance & PIM
- Implementing access packages and catalogs for just in time, least privilege access
- Configuring approval workflows, access reviews, and expiration policies for access packages
- Enabling Privileged Identity Management (PIM) to replace standing admin rights with eligible, time bound roles
- Using role enabled groups to assign and manage Entra ID roles at scale, and understanding the security implications
- Configuring PIM activation requirements (MFA, justification, ticket number, approval) and reviewing PIM audit logs
B2B collaboration settings
- Controlling guest invitations, redemption experiences, and guest user permissions
- Tuning cross tenant access settings to balance collaboration and security
By the end of Day 1, you'll have a working tenant with a clear identity model, delegation model, governance patterns, and B2B settings ready to be protected with advanced policies on Day 2.
Day 2 – Conditional Access: from "require MFA" to Zero Trust
Embark on an in depth journey into Conditional Access and Entra ID, technologies that define how, when, and where users access cloud applications. While many are familiar with enforcing MFA, this 8 hour hands on workshop goes far beyond the basics, uncovering the full potential of Microsoft's Conditional Access.
Beyond the Basics
This workshop delves into advanced use cases such as:
- FIDO2 / passkey authentication and authentication strengths for phishing resistant MFA
- Session controls and download restrictions for sensitive applications
- Sign in risk and user risk evaluation to enable adaptive, risk based access
- Device based policies: blocking non compliant or unmanaged devices
Learn how to leverage the latest capabilities to strengthen your tenant's security posture.
Participants will set up their own test tenant and follow guided exercises designed to create those key "aha" moments that reveal the logic and mechanisms behind effective Entra ID and Conditional Access design.
Attendee Workstation Requirements:
- You must provide your own laptop computer (Windows or Mac)
- Your computer must have a camera, internet connection, speakers and a microphone
- You must provide your own smartphone with the Microsoft Authenticator app installed.
- You must have the ability to install PowerShell modules (local admin permissions).
- During the workshop, you'll register for a Microsoft 365 E5 Trial to create your test tenant (credit card required, no charge applied).