Entra ID Security

Read the controls, not just the alerts

You investigate identity attacks, and the configuration behind them belongs to somebody else. What each Entra ID control actually covers, which population it misses, and why a policy that was configured correctly still let the attack through. Conditional Access, authentication methods, PIM, tokens and app registrations, read the way an investigator reads them rather than the way a build guide describes them.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Practice included: scored investigation scenarios, plus the Practice Hub.
View Pricing Download Lab Pack Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Read a Conditional Access estate and say what each policy covers, what it misses, and which sign-ins never reach it
✓Tell a satisfied MFA requirement from a proved one, and know which authentication methods survive a proxy
✓Trace a token from issue to replay, and say what revoking a session does and does not reach
✓Audit an app registration for the permissions it holds rather than the ones it was granted
✓Produce a coverage figure with its denominator attached, which is the difference between a number a CISO can act on and one that only rises
What students say about this course

“Spent a ton of time digging into Entra sign-in logs and looking at how token theft actually works in the real world; the Entra ID Security training was very helpful for this. Thankfully, not another 'turn on MFA' lecture. The course was very helpful in learning how to properly audit your environment.”

Hanna
ARC401 | Premium tier | 10 modules across 3 phases | 36–40 hours at your own pace | 40 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: Foundations

Module 0Course OrientationCourse Preview

What Entra ID Security teaches: engineer Entra ID into the perimeter that stops account takeover, MFA fatigue, and token theft, using Conditional Access, Identity Protection, PIM, and token security. The identity control plane you'll work, the policies and detections you walk away with, and how the course is structured. Start here.

Show 12 lessonsHide lessons
  1. 0.10.1 Why Identity Is the New PerimeterPreview
  2. 0.20.2 How Authentication Actually WorksPreview
  3. 0.30.3 The Entra ID Security StackPreview
  4. 0.40.4 Attack Patterns You Will Defend AgainstPreview
  5. 0.50.5 The Identity Kill ChainPreview
  6. 0.60.6 Zero Trust and IdentityPreview
  7. 0.70.7 Real-World Identity BreachesPreview
  8. 0.80.8 The Defense Design MethodPreview
  9. 0.90.9 Measuring Identity Security PosturePreview
  10. 0.100.10 The Lab EnvironmentPreview
  11. 0.11Module SummaryPreview
  12. 0.12Check My KnowledgePreview
Module 1Sign-In Logs, Your Identity Telemetry

The sign-in log is the single most important data source for identity security. Every field explained in security context. Interactive, non-interactive, and service principal authentication. Authentication details, conditional access evaluation, risk signals, device and location context. KQL query patterns for identity data. Cross-table correlation. Building a sign-in baseline that makes anomaly detection and policy verification possible.

Show 14 lessonsHide lessons
  1. 1.11.1 Anatomy of a Sign-In Log Entry
  2. 1.21.2 Interactive vs Non-Interactive Sign-Ins
  3. 1.31.3 Service Principal and Managed Identity Sign-Ins
  4. 1.41.4 Authentication Details Deep Dive
  5. 1.51.5 Conditional Access Evaluation in Sign-In Logs
  6. 1.61.6 Risk Signals and Identity Protection
  7. 1.71.7 Device and Location Signals
  8. 1.81.8 KQL Fundamentals for Identity Security
  9. 1.91.9 Advanced Query Patterns
  10. 1.101.10 Cross-Table Joins and Correlation
  11. 1.111.11 Building Your Sign-In Baseline
  12. 1.121.12 The Identity Query Library
  13. 1.13Module Summary
  14. 1.14Check My Knowledge

Phase 2: Conditional Access & Identity Protection

Phase 0: Course Resources

ResourcesCheatsheets

Subject-area sheets for identity work: where the control lives in the portal, the query that answers the question at scale, and what the answer does not prove.

Show 7 lessonsHide lessons
  1. 1Reading a Sign-In, and Tokens
  2. 2Authentication Methods and MFA
  3. 3Conditional Access
  4. 4Identity Protection and Risk
  5. 5Privileged Access and PIM
  6. 6Applications and Workload Identity
  7. 7Tables, Codes and Limits
ResourcesCookbooks

Seven runbooks for the procedures an identity engineer repeats: deploying a policy, retiring a method, migrating to PIM, onboarding a partner, and getting a tenant back.

Show 7 lessonsHide lessons
  1. 1Deploying a Conditional Access Policy
  2. 2Rolling Out Phishing-Resistant Authentication
  3. 3Retiring an Authentication Method
  4. 4Migrating a Role to PIM
  5. 5Onboarding an External Partner
  6. 6Responding to a Risky User
  7. 7Recovering a Locked-Out Tenant
ResourcesLab Setup

A complete build for an identity lab: tenant, workspace, telemetry, a population, a partner tenant, and the checks that prove it works.

Show 5 lessonsHide lessons
  1. 1Getting a Tenant
  2. 2Wiring the Telemetry
  3. 3Building a Population
  4. 4The Second Tenant
  5. 5Verify and Troubleshoot
ResourcesWalkthroughs

Worked identity investigations end to end, including the wrong turns, the queries that looked right and were not, and what would have changed each answer.

Show 7 lessonsHide lessons
  1. 1The Travel That Was Not Impossible
  2. 2The Policy That Covered Nobody
  3. 3The Token That Survived the Revocation
  4. 4The Consent That Was Not Phishing
  5. 5The Admins the Query Could Not See
  6. 6The MFA That Was Already Satisfied
  7. 7The Spray That Found One Door
ResourcesPlaybooks

Seven configuration and governance events that fire at an identity engineer, each with the clearing check, what escalates it, and how to reverse it.

Show 7 lessonsHide lessons
  1. 1A Conditional Access Policy Changed
  2. 2A Break-Glass Account Signed In
  3. 3A Permanent Role Assignment Appeared
  4. 4A Credential Landed on an Application
  5. 5PIM Settings Were Weakened
  6. 6A Guest Entered a Privileged Group
  7. 7Legacy Authentication Came Back
ResourcesPlayground

Where to practice the identity work in this course against real data, without a tenant of your own.

ResourcesReferences & Further Reading

External sources this course draws on: Microsoft Entra documentation, attack research, frameworks and community identity security material.

Course Completion

CompletionCourse Exam

Entra ID Security end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.

Show 1 lessonHide lessons
  1. 1Course Completion. Entra ID Security

Course overview

The Entra ID Security course is built for analysts and responders who investigate identity attacks and need to read the configuration behind them. You'll be able to:

✓ Read a Conditional Access estate and say what each policy covers and which sign-ins never reach it
✓ Tell a satisfied MFA requirement from a proved one, and know which methods survive a proxy
✓ Trace a token from issue to replay, and say what revoking a session does and does not reach
✓ Audit an app registration for the permissions it holds rather than the ones it was granted

By the end you will be able to say, of any control in the tenant, who it protects and how you know: which is the answer a coverage question actually needs.

How this course works

Identity is the control plane, and every attack in this course arrives through a successful authentication. The loop repeats for every control it builds.

1. Read the sign-in record properly. The result field and the risk fields answer different questions, and an investigation that reads one of them reaches the wrong conclusion confidently.

2. Fix the authentication method before the policy. A Conditional Access policy requiring multifactor is only as strong as the methods registered against the account it protects.

3. Design the policy set, then the policy. Every applicable policy is evaluated and the strictest control wins. Policies written one at a time acquire gaps no single review finds.

4. Validate in report-only against real sign-ins. Report-only tells you who would have been blocked using your own traffic. It is the cheapest verification here and the most skipped.

5. Close the application surface. Consent, credentials and service principals are identity too, and they survive every action taken against a user account.

What this course assumes

No minimum experience and no prerequisite course. Tokens, the evaluation model, risk detections and the application model are explained where they first matter.

What makes it go faster: a tenant with Entra ID P2, even a developer one, so you can build the policies alongside. Not required, and every configuration is shown with the portal path behind it.

What this course does not cover: identity governance and lifecycle, which is its own course, and incident response process. This is the identity control surface and defending it.

Who this course is for

You investigate identity attacks, and when one lands the answer sits in a Conditional Access policy, an authentication method registration, or a token you did not issue. This course is built for you if you want to:

✓ Close identity incidents without waiting on the team that owns the tenant
✓ Answer whether a control covers something, rather than whether it is enabled
✓ Understand Conditional Access, authentication methods, PIM and tokens well enough to argue about them
✓ Move toward identity engineering with the reasoning in place before the buttons

In short: if the sign-in succeeded and you need to know what should have stopped it, this course is for you.

What you'll learn

By the end of this Entra ID Security course you will be able to:

✓ Read a policy set and find the population every policy in it misses
✓ Separate standing privilege from activated privilege in a PIM assignment list
✓ Read an Identity Protection risk score and say what it does and does not establish
✓ Reconstruct a token theft from the sign-in record it leaves behind
✓ Audit an application registration for consent, credentials and permission scope
✓ Produce a coverage figure with its denominator attached

Key course takeaways

✓ A control that is switched on is not the same as a control that covers anybody
✓ Conditional Access, authentication methods, PIM, tokens and app registrations, in depth
✓ Most identity metrics rise on their own; the useful ones move only when somebody acts
✓ The attacks that matter defeat a tenant with MFA enabled, because they never touch the password
✓ A correctly configured policy failing is the normal case, not the exception
✓ The analyst who can read the configuration is the one who closes the incident

Lab Pack, Entra ID Security Toolkit

Downloadable lab pack with realistic identity evidence, deployable Conditional Access policies, detection rules, PIM configurations, and the complete governance framework for a production identity security program. Two PowerShell generators produce ~130 individual files covering every module in the course.

Identity evidence (~2,000+ entries across 6 tables): SigninLogs (14 days + AiTM, password spray, MFA fatigue, impossible travel), AuditLogs (admin activity + inbox rules, OAuth consent, GA role assignment, CA policy disable), NonInteractiveSignInLogs (token refresh + AiTM replay), ServicePrincipalSignInLogs (5 SPs + external auth), IdentityInfo (15 user records), RiskDetections (5 identity risk events).

Conditional Access (12 policies + validation): CA001–CA012 as individual JSON exports. 7 KQL validation queries. 6 What-If scenarios with expected outcomes.

Detection rules (30 files): 15 KQL rules + 15 Sigma equivalents covering AiTM token replay, password spray, MFA fatigue, impossible travel, inbox forwarding, GA assignment outside PIM, CA policy modification, OAuth consent to unverified publisher, and more.

Operational artifacts (~70 files): PIM role configs, Identity Protection risk policies, application security inventory, workload identity inventory, governance templates, monitoring runbooks, backup/recovery checklists, architecture templates, compliance mappings (ISO 27001, NIST CSF), and 3 capstone design challenges.

Entra ID Security Lab Pack
~130 files · 6 identity tables · 12 CA policies · 30 detection rules · PIM + governance + monitoring
Download Lab Pack (.zip)

Course Resources - what comes with the modules

Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.

✓ Walkthroughs work an identity finding back to its cause: the travel that was not impossible, the policy that covered nobody, the token that survived the revocation, the consent that was not phishing, and the admins the query could not see.
✓ Playbooks for the alerts you are handed rather than the ones you go looking for: a break-glass account signed in, a permanent role assignment appeared, PIM settings were weakened, legacy authentication came back.
✓ A cookbook for the work itself: deploying a Conditional Access policy, rolling out phishing-resistant authentication, retiring an authentication method, migrating a role to PIM, recovering a locked-out tenant.
✓ A command cheatsheet from reading a sign-in and its tokens through to the tables, result codes and limits.
✓ A lab setup guide for a tenant, the telemetry, a population and the second tenant the guest work needs.
✓ A playground that is explicit about what your own lab cannot do: you can deploy a Conditional Access policy in a tenant and you cannot investigate a credible intrusion in a twenty-user one, so the SOC Simulator, the query Practice surface and the Playbook Suite sit alongside it.
✓ A references module for the Microsoft documentation the course is gated against.

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course builds from first principles. Familiarity with Entra ID and the Microsoft 365 admin center will help you move faster through the early modules, but neither is required. Every concept is explained at first use.

What are the device requirements?

A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) for hands-on Conditional Access, PIM, and Identity Protection configuration. The course walks you through tenant setup in Module 0.

How will the course benefit your career?

Identity is where most cloud attacks land, and the people investigating them are usually reading a configuration somebody else owns. Being able to say which control should have applied, which population it missed, and why the sign-in succeeded anyway is the difference between escalating an incident and closing it.

It is also the ground an analyst stands on when they move toward identity engineering, and the attacks it covers, AiTM phishing, token theft and MFA fatigue, are the ones that defeat a tenant with MFA switched on.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy scripts, queries, detection rules, and policies in your production environment. You may not redistribute course content or share account credentials.

Identity configurations: All Conditional Access policies, PIM configurations, and detection rules are provided as-is. Test every configuration in report-only mode before enforcement. Ridgeline Cyber Defence is not responsible for operational impact from deployed configurations.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
2scenarios
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.