2026
Entra ID Identity & Access Governance Lab
Risk-based Conditional Access, just-in-time admin access, access packages and access reviews in an Entra ID P2 tenant, tied to an Intune-compliant Windows 11 device.
Overview
Built an identity and access governance lab in an Entra ID P2 trial tenant with an Intune-enrolled Windows 11 VM. Covers MFA registration enforcement, risk-based Conditional Access (user risk and sign-in risk), Privileged Identity Management with just-in-time Global Administrator access, entitlement management with approval workflows, automated access reviews, and break-glass accounts excluded from every policy to prevent tenant lockout. Includes PowerShell validation scripts and exported policy templates.
Highlights
- Built four Conditional Access policies: require compliant device, MFA registration, user-risk remediation (high risk forces MFA and a password change) and sign-in risk (medium/high requires MFA)
- Configured PIM so Global Administrator is eligible rather than permanently active, with MFA, a written justification and a 2-hour activation window
- Created break-glass emergency accounts in a group excluded from every policy, so no policy change can lock admins out of the tenant
- Set up entitlement management (catalog and access package with an approver and an expiry date) and an automated access review that removes access if reviewers do not respond
- Documented the build with 54 screenshots, wrote Microsoft Graph PowerShell validation scripts, and exported the policy and PIM settings as JSON templates
Tech stack
- Microsoft Entra ID P2
- Conditional Access
- Identity Protection
- Privileged Identity Management
- Entitlement Management
- Access Reviews
- Intune
- Microsoft Graph PowerShell