Entra ID Security
Read the controls, not just the alerts
You investigate identity attacks, and the configuration behind them belongs to somebody else. What each Entra ID control actually covers, which population it misses, and why a policy that was configured correctly still let the attack through. Conditional Access, authentication methods, PIM, tokens and app registrations, read the way an investigator reads them rather than the way a build guide describes them.
What you'll be able to do
“Spent a ton of time digging into Entra sign-in logs and looking at how token theft actually works in the real world; the Entra ID Security training was very helpful for this. Thankfully, not another 'turn on MFA' lecture. The course was very helpful in learning how to properly audit your environment.”
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: Foundations
What Entra ID Security teaches: engineer Entra ID into the perimeter that stops account takeover, MFA fatigue, and token theft, using Conditional Access, Identity Protection, PIM, and token security. The identity control plane you'll work, the policies and detections you walk away with, and how the course is structured. Start here.
Show 12 lessonsHide lessons
- 0.10.1 Why Identity Is the New PerimeterPreview
- 0.20.2 How Authentication Actually WorksPreview
- 0.30.3 The Entra ID Security StackPreview
- 0.40.4 Attack Patterns You Will Defend AgainstPreview
- 0.50.5 The Identity Kill ChainPreview
- 0.60.6 Zero Trust and IdentityPreview
- 0.70.7 Real-World Identity BreachesPreview
- 0.80.8 The Defense Design MethodPreview
- 0.90.9 Measuring Identity Security PosturePreview
- 0.100.10 The Lab EnvironmentPreview
- 0.11Module SummaryPreview
- 0.12Check My KnowledgePreview
The sign-in log is the single most important data source for identity security. Every field explained in security context. Interactive, non-interactive, and service principal authentication. Authentication details, conditional access evaluation, risk signals, device and location context. KQL query patterns for identity data. Cross-table correlation. Building a sign-in baseline that makes anomaly detection and policy verification possible.
Show 14 lessonsHide lessons
- 1.11.1 Anatomy of a Sign-In Log Entry
- 1.21.2 Interactive vs Non-Interactive Sign-Ins
- 1.31.3 Service Principal and Managed Identity Sign-Ins
- 1.41.4 Authentication Details Deep Dive
- 1.51.5 Conditional Access Evaluation in Sign-In Logs
- 1.61.6 Risk Signals and Identity Protection
- 1.71.7 Device and Location Signals
- 1.81.8 KQL Fundamentals for Identity Security
- 1.91.9 Advanced Query Patterns
- 1.101.10 Cross-Table Joins and Correlation
- 1.111.11 Building Your Sign-In Baseline
- 1.121.12 The Identity Query Library
- 1.13Module Summary
- 1.14Check My Knowledge
Every identity attack either exploits weak authentication or bypasses strong authentication. The full authentication method hierarchy, from passwords to phishing-resistant credentials. Microsoft Authenticator configuration and security. FIDO2 security keys and passkeys. Certificate-based authentication. Planning and deploying phishing-resistant authentication across your organization.
Show 14 lessonsHide lessons
- 2.1EI2.1 The Authentication Method Hierarchy
- 2.2EI2.2 Passwords and Why They Fail
- 2.3EI2.3 Microsoft Authenticator. Push and Number Matching
- 2.4EI2.4 FIDO2 Security Keys
- 2.5EI2.5 Passkeys in Microsoft Authenticator
- 2.6EI2.6 Certificate-Based Authentication
- 2.7EI2.7 Authentication Strength Policies
- 2.8EI2.8 Passwordless Authentication and Temporary Access Pass
- 2.9EI2.9 Planning the Migration to Phishing-Resistant Authentication
- 2.10EI2.10 Deploying and Monitoring Authentication Changes
- 2.11EI2.11 External Authentication Methods and Method Retirement
- 2.12EI2.12 The Authentication Method Operations Playbook
- 2.13Module Summary
- 2.14Check My Knowledge
Phase 2: Conditional Access & Identity Protection
How to design a conditional access architecture that stops attacks without breaking productivity. Evaluation engine, Zero Trust policy framework, named locations, device conditions, session controls, and emergency access.
Show 14 lessonsHide lessons
- 3.1EI3.1 How Conditional Access Evaluation Works
- 3.2EI3.2 Assignments: Users, Groups, and Roles
- 3.3EI3.3 Target Resources: Applications and Authentication Context
- 3.4EI3.4 Conditions: Location, Device Platform, and Client Apps
- 3.5EI3.5 Named Locations and Network Context
- 3.6EI3.6 Device Conditions and Compliance
- 3.7EI3.7 Grant Controls: MFA, Auth Strength, Device, Terms of Use
- 3.8EI3.8 Session Controls: Sign-In Frequency, Token Protection, and CAAC
- 3.9EI3.9 The Zero Trust Policy Framework
- 3.10EI3.10 Emergency Access and Break-Glass Accounts
- 3.11EI3.11 Policy Design Patterns for Common Scenarios
- 3.12EI3.12 Conditional Access Architecture as Code
- 3.13Module Summary
- 3.14Check My Knowledge
Specific real-world attack techniques and the conditional access policy combinations that stop each one. AiTM, password spray, MFA fatigue, token theft, consent phishing, legacy authentication, and workload identities.
Show 16 lessonsHide lessons
- 4.1EI4.1 The Attack-to-Defense Methodology
- 4.2EI4.2 Blocking Legacy Authentication
- 4.3EI4.3 Stopping Password Spray
- 4.4EI4.4 Defending Against AiTM Credential Phishing
- 4.5EI4.5 Preventing MFA Fatigue Attacks
- 4.6EI4.6 Token Theft and Session Replay Defense
- 4.7EI4.7 Consent Phishing and Illicit OAuth Grant Defense
- 4.8EI4.8 Blocking Unauthorized Device Types and Platforms
- 4.9EI4.9 Defending Against Credential Stuffing
- 4.10EI4.10 Insider Threat Through Identity Controls
- 4.11EI4.11 Attack Chain Defense: Multi-Stage Attack Scenarios
- 4.12EI4.12 The Defense Verification Playbook
- 4.13EI4.13 Defending Privileged Role Escalation
- 4.14EI4.14 Workload Identity Attacks and Service Principal Abuse
- 4.15Module Summary
- 4.16Check My Knowledge
How Identity Protection detects risk, how to configure risk policies, and how to operationalize risk signals for prevention and detection. Risk remediation, risky users investigation, tuning, and conditional access integration.
Show 15 lessonsHide lessons
- 5.1EI5.1 How Identity Protection Works
- 5.2EI5.2 Sign-In Risk Detections
- 5.3EI5.3 User Risk Detections
- 5.4EI5.4 Configuring Risk-Based Conditional Access
- 5.5EI5.5 Risk Remediation and Self-Service
- 5.6EI5.6 The Risky Users Investigation Workflow
- 5.7EI5.7 The Risky Sign-Ins Investigation Workflow
- 5.8EI5.8 Tuning Identity Protection
- 5.9EI5.9 Attack Disruption and Automatic Response
- 5.10EI5.10 Identity Protection in Sentinel
- 5.11EI5.11 Operationalizing Risk Signals
- 5.12EI5.12 Advanced Risk Scenarios
- 5.13EI5.13 Building a Risk Posture Dashboard
- 5.14Module Summary
- 5.15Check My Knowledge
Just-in-time, just-enough-access for administrative roles. PIM for Entra ID roles and Azure resources, access reviews, monitoring and alerting, and designing a complete privileged access strategy.
Show 14 lessonsHide lessons
- 6.1EI6.1 Why Standing Privileges Are Dangerous
- 6.2EI6.2 PIM for Entra ID Roles. Eligible vs Active
- 6.3EI6.3 Configuring PIM Role Settings
- 6.4EI6.4 PIM for Azure Resource Roles
- 6.5EI6.5 PIM Activation Security
- 6.6EI6.6 Access Reviews for Privileged Roles
- 6.7EI6.7 PIM Monitoring and Detection
- 6.8EI6.8 Emergency Access and PIM
- 6.9EI6.9 Designing a Privileged Access Strategy
- 6.10EI6.10 PIM for Groups
- 6.11EI6.11 PIM Operational Procedures
- 6.12EI6.12 Advanced PIM Scenarios
- 6.13Module Summary
- 6.14Check My Knowledge
Tokens are the currency of identity. Token types and lifecycle, how tokens are stolen, token protection deployment, continuous access evaluation, session lifetime controls, and protecting the Primary Refresh Token.
Show 16 lessonsHide lessons
- 7.1EI7.1 Token Types and Lifecycle
- 7.2EI7.2 Where Tokens Live
- 7.3EI7.3 How Tokens Are Stolen: Proxy-Based Attacks
- 7.4EI7.4 How Tokens Are Stolen: Device-Based Attacks
- 7.5EI7.5 How Tokens Are Stolen: Infrastructure Attacks
- 7.6EI7.6 Token Protection Deployment
- 7.7EI7.7 Continuous Access Evaluation (CAE)
- 7.8EI7.8 Session Lifetime and Sign-In Frequency
- 7.9EI7.9 Protecting the Primary Refresh Token
- 7.10EI7.10 Token Theft Detection
- 7.11EI7.11 Token Theft Response
- 7.12EI7.12 Browser Session Security
- 7.13EI7.13 Token Security for Non-Interactive Sign-Ins
- 7.14EI7.14 Building the Token Security Architecture
- 7.15Module Summary
- 7.16Check My Knowledge
You deployed conditional access policies. How do you know they work? Report-only mode, What-If simulation, sign-in log policy validation, troubleshooting access failures, and change management.
Show 14 lessonsHide lessons
- 8.1EI8.1 Report-Only Mode: How It Works
- 8.2EI8.2 Analyzing Report-Only Results
- 8.3EI8.3 The What-If Tool and Policy Simulation
- 8.4EI8.4 Policy Validation Queries
- 8.5EI8.5 Conditional Access Gap Analysis
- 8.6EI8.6 Troubleshooting Access Failures
- 8.7EI8.7 Common Misconfigurations
- 8.8EI8.8 Conditional Access Change Management
- 8.9EI8.9 Policy Drift Detection
- 8.10EI8.10 Validating Token Protection and Session Controls
- 8.11EI8.11 Testing Break-Glass and Emergency Access
- 8.12EI8.12 Building the CA Validation Dashboard
- 8.13Module Summary
- 8.14Check My Knowledge
Phase 3: Application Identity
Application registrations are the most overlooked attack surface in Entra ID. The dual-object model, credential management, permission governance, admin consent workflow, lifecycle security, and detecting malicious application activity.
Show 16 lessonsHide lessons
- 9.1EI9.1 The Dual-Object Model
- 9.2EI9.2 How Application Authentication Works
- 9.3EI9.3 Client Secrets: The Application Password Problem
- 9.4EI9.4 Certificate-Based Application Authentication
- 9.5EI9.5 Workload Identity Federation
- 9.6EI9.6 Permission Governance: Delegated vs Application
- 9.7EI9.7 The Consent Framework
- 9.8EI9.8 Admin Consent Workflow
- 9.9EI9.9 Publisher Verification and App Governance
- 9.10EI9.10 Application Lifecycle Security
- 9.11EI9.11 Detecting Malicious Application Activity
- 9.12EI9.12 Application Security Queries
- 9.13EI9.13 Securing Application Registrations
- 9.14EI9.14 Building the Application Governance Framework
- 9.15Module Summary
- 9.16Check My Knowledge
Phase 0: Course Resources
Subject-area sheets for identity work: where the control lives in the portal, the query that answers the question at scale, and what the answer does not prove.
Seven runbooks for the procedures an identity engineer repeats: deploying a policy, retiring a method, migrating to PIM, onboarding a partner, and getting a tenant back.
A complete build for an identity lab: tenant, workspace, telemetry, a population, a partner tenant, and the checks that prove it works.
Show 5 lessonsHide lessons
Worked identity investigations end to end, including the wrong turns, the queries that looked right and were not, and what would have changed each answer.
Seven configuration and governance events that fire at an identity engineer, each with the clearing check, what escalates it, and how to reverse it.
Where to practice the identity work in this course against real data, without a tenant of your own.
External sources this course draws on: Microsoft Entra documentation, attack research, frameworks and community identity security material.
Course Completion
Entra ID Security end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.
Show 1 lessonHide lessons
Course overview
The Entra ID Security course is built for analysts and responders who investigate identity attacks and need to read the configuration behind them. You'll be able to:
By the end you will be able to say, of any control in the tenant, who it protects and how you know: which is the answer a coverage question actually needs.
How this course works
Identity is the control plane, and every attack in this course arrives through a successful authentication. The loop repeats for every control it builds.
1. Read the sign-in record properly. The result field and the risk fields answer different questions, and an investigation that reads one of them reaches the wrong conclusion confidently.
2. Fix the authentication method before the policy. A Conditional Access policy requiring multifactor is only as strong as the methods registered against the account it protects.
3. Design the policy set, then the policy. Every applicable policy is evaluated and the strictest control wins. Policies written one at a time acquire gaps no single review finds.
4. Validate in report-only against real sign-ins. Report-only tells you who would have been blocked using your own traffic. It is the cheapest verification here and the most skipped.
5. Close the application surface. Consent, credentials and service principals are identity too, and they survive every action taken against a user account.
What this course assumes
No minimum experience and no prerequisite course. Tokens, the evaluation model, risk detections and the application model are explained where they first matter.
What makes it go faster: a tenant with Entra ID P2, even a developer one, so you can build the policies alongside. Not required, and every configuration is shown with the portal path behind it.
What this course does not cover: identity governance and lifecycle, which is its own course, and incident response process. This is the identity control surface and defending it.
Who this course is for
You investigate identity attacks, and when one lands the answer sits in a Conditional Access policy, an authentication method registration, or a token you did not issue. This course is built for you if you want to:
In short: if the sign-in succeeded and you need to know what should have stopped it, this course is for you.
What you'll learn
By the end of this Entra ID Security course you will be able to:
Key course takeaways
Lab Pack, Entra ID Security Toolkit
Downloadable lab pack with realistic identity evidence, deployable Conditional Access policies, detection rules, PIM configurations, and the complete governance framework for a production identity security program. Two PowerShell generators produce ~130 individual files covering every module in the course.
Identity evidence (~2,000+ entries across 6 tables): SigninLogs (14 days + AiTM, password spray, MFA fatigue, impossible travel), AuditLogs (admin activity + inbox rules, OAuth consent, GA role assignment, CA policy disable), NonInteractiveSignInLogs (token refresh + AiTM replay), ServicePrincipalSignInLogs (5 SPs + external auth), IdentityInfo (15 user records), RiskDetections (5 identity risk events).
Conditional Access (12 policies + validation): CA001–CA012 as individual JSON exports. 7 KQL validation queries. 6 What-If scenarios with expected outcomes.
Detection rules (30 files): 15 KQL rules + 15 Sigma equivalents covering AiTM token replay, password spray, MFA fatigue, impossible travel, inbox forwarding, GA assignment outside PIM, CA policy modification, OAuth consent to unverified publisher, and more.
Operational artifacts (~70 files): PIM role configs, Identity Protection risk policies, application security inventory, workload identity inventory, governance templates, monitoring runbooks, backup/recovery checklists, architecture templates, compliance mappings (ISO 27001, NIST CSF), and 3 capstone design challenges.
Course Resources - what comes with the modules
Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course builds from first principles. Familiarity with Entra ID and the Microsoft 365 admin center will help you move faster through the early modules, but neither is required. Every concept is explained at first use.
What are the device requirements?
A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) for hands-on Conditional Access, PIM, and Identity Protection configuration. The course walks you through tenant setup in Module 0.
How will the course benefit your career?
Identity is where most cloud attacks land, and the people investigating them are usually reading a configuration somebody else owns. Being able to say which control should have applied, which population it missed, and why the sign-in succeeded anyway is the difference between escalating an incident and closing it.
It is also the ground an analyst stands on when they move toward identity engineering, and the attacks it covers, AiTM phishing, token theft and MFA fatigue, are the ones that defeat a tenant with MFA switched on.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy scripts, queries, detection rules, and policies in your production environment. You may not redistribute course content or share account credentials.
Identity configurations: All Conditional Access policies, PIM configurations, and detection rules are provided as-is. Test every configuration in report-only mode before enforcement. Ridgeline Cyber Defence is not responsible for operational impact from deployed configurations.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.