← Back to Projects

Identity & Access

Identity & Zero Trust Lab

A hands-on security lab focused on identity as the control plane: authentication, authorization, Conditional Access, lifecycle management, privileged access, and practical Zero Trust design.

Microsoft Entra IDIAMMFAConditional AccessRBACZero TrustAccount LifecyclePrivileged Access

Overview

Why Identity Comes First

Many security decisions eventually become identity decisions: who is requesting access, what they are allowed to reach, what conditions should apply, and how that access changes over time.

This lab gives me a structured environment for studying identity security beyond certification theory. The focus is on designing access around business roles and security conditions rather than simply granting permissions.

The project is intentionally iterative. I am building and documenting scenarios as my Entra ID, IAM, cloud security, and Zero Trust skills expand.

Identity Architecture

Access as a Lifecycle

01

Identity

Treat identity as the primary control plane for deciding who receives access and under what conditions.

02

Authentication

Use stronger authentication controls and MFA to reduce dependence on passwords alone.

03

Authorization

Apply role-based access and least privilege so users receive only the permissions required for their responsibilities.

04

Lifecycle

Design repeatable joiner, mover, and leaver processes so account access follows the user's relationship with the organization.

Lab Work

Scenarios I'm Building

The lab is organized around practical identity problems rather than isolated product features.

Project Status

This project is actively being developed. The page documents the lab design and the areas being implemented as my identity security work expands.

Lab Focus

Conditional Access

Design access policies around authentication strength, device state, user risk, location, and application sensitivity.

Lab Focus

MFA Enforcement

Explore how stronger authentication can be introduced while maintaining usability and operational continuity.

Lab Focus

Role-Based Access

Model permissions around job responsibilities instead of assigning broad access directly to individual users.

Lab Focus

Account Lifecycle

Build repeatable processes for creating, modifying, disabling, and reviewing user access.

Research

Privileged Workflows

Evaluate how administrative access should be separated, limited, monitored, and used only when required.

Research

Access Reviews

Explore periodic validation of permissions so access does not accumulate indefinitely as roles change.

Zero Trust

Verify Access Instead of Assuming Trust

01

Verify Explicitly

Use identity, authentication context, risk, device state, and other available signals when making access decisions.

02

Least Privilege

Reduce standing access and design permissions around what users and administrators actually need.

03

Assume Breach

Design access so one compromised account or device does not automatically provide unrestricted movement.

“Identity should answer more than who you are. It should help determine what you can reach, under what conditions, and for how long.”

Lessons

What I'm Learning

01

Identity architecture is as much about lifecycle and governance as authentication.

02

Least privilege becomes harder to maintain when access is assigned directly instead of through well-designed roles.

03

Security controls need to account for user experience and operational requirements.

04

Documentation makes identity decisions easier to review and improve.

Next Steps

Expanding the Lab

01

Build additional Conditional Access scenarios

02

Document joiner, mover, and leaver workflows

03

Expand privileged-access design

04

Add access-review exercises

05

Map controls to practical business scenarios

More Projects

Explore the rest of the lab.

Back to Projects →