Free guides, interview Q&As, and job responsibility breakdowns — curated by industry veterans to help you crack MNC interviews
CATEGORY 1 — Identity, Users & Tenant Governance
LAB 1. Unlock & Reset a Locked-Out User Account
🎫 TICKET
User Priya Sharma is locked out after 5 failed password attempts.
Objective: Practice identity verification and a standard password reset/unlock in Microsoft Entra ID.
Verification: The user signs in with the temporary password and is prompted to change it.
Practice Tip: Always verify identity before any reset — this is the top social-engineering target on a helpdesk.
LAB 2. Onboard a New User & Assign Group Membership
🎫 TICKET
New hire Rahul Verma starts Monday — create his account and add him to Sales.
Objective: Practice standard new-user onboarding end-to-end.
Verification: Rahul's account appears under Active users and the Sales group's member list.
Practice Tip: Double-check username spelling and domain — renaming later is more work than getting it right first.
LAB 3. Diagnose a Missing-App Issue Caused by Licensing
🎫 TICKET
Meena Iyer says Teams is missing from her Office apps.
Objective: Diagnose and resolve a missing-app complaint caused by a licensing gap.
Verification: Teams shows enabled under Meena's license and she can launch it.
Practice Tip: 'Missing app' tickets are almost always licensing — check licenses before assuming a bug.
LAB 4. Bulk-Create Users from an Approved CSV Batch
🎫 TICKET
HR sends an approved CSV of 8 new campus hires starting the same day.
Objective: Practice a small, supervised bulk user-creation workflow.
Verification: All 8 accounts appear active with correct licenses assigned.
Practice Tip: Always review the validation screen before confirming — one bad row can silently skip a whole account.
LAB 5. Offboard a Departing Employee
🎫 TICKET
Employee's last day is Friday — disable access and convert mailbox to shared per policy.
Objective: Practice a complete, policy-compliant offboarding sequence.
Verification: The account can no longer sign in, and the mailbox is retained as a shared mailbox.
Practice Tip: Never delete an account outright on day one — disabling first protects against needing quick reversal.
LAB 6. Fix a Duplicate/Incorrect UPN Blocking Sign-In
🎫 TICKET
User can't sign in — error suggests the username may already exist.
Objective: Diagnose and correct a UPN conflict.
Verification: The user signs in successfully with a unique, correct UPN.
Practice Tip: Search broadly (including disabled accounts) — duplicate UPN issues often hide in old, inactive accounts.
LAB 7. Update Profile Attributes for Org Chart Accuracy
🎫 TICKET
New reporting structure — update 5 users' manager and department fields.
Objective: Practice bulk-style profile attribute updates.
Verification: All 5 users show the correct manager and department in their profile.
Practice Tip: Manager-field accuracy affects approval workflows elsewhere (like access requests) — treat it as more than cosmetic.
LAB 8. Investigate an Unexpectedly Disabled Account
🎫 TICKET
User says their account was working yesterday but is now disabled.
Objective: Diagnose why an account was disabled and determine next steps.
Verification: The cause is identified and the account is either safely re-enabled or correctly escalated.
Practice Tip: Never re-enable an account disabled by a security action without escalating first — it may be an active containment step.
LAB 9. Resolve a Shared Calendar Visibility Issue
🎫 TICKET
User can't see a colleague's calendar despite being told they should have access.
Objective: Diagnose a calendar-sharing/group-membership issue.
Verification: The user can now see the colleague's calendar at the expected permission level.
Practice Tip: Clarify the expected access level (free/busy only vs. full details) before granting — over-granting is a common mistake.
LAB 10. Reclaim a License from an Inactive Account
🎫 TICKET
Finance flags a license assigned to an account that's been inactive for 60 days.
Objective: Practice license reclamation as part of routine tenant hygiene.
Verification: The license is removed from the inactive account and reassigned to an active user.
Practice Tip: Always confirm with HR/manager before touching a license — 'inactive' isn't always the same as 'terminated.'
LAB 11. Process a Legal Name Change (UPN/Display Name Update)
🎫 TICKET
Employee legally changed their name and needs their account updated to match.
Objective: Practice updating identity details following a legal name change request.
Verification: The user's profile, display name, and email reflect the new legal name, with the old address still working as an alias.
Practice Tip: Keep the old address as an alias — breaking it can cause missed emails from external contacts still using the old address.
LAB 12. Clean Up Group Membership After a Department Restructuring
🎫 TICKET
Marketing and Sales merged into one department — group memberships need reconciling.
Objective: Practice a supervised group-membership cleanup project.
Verification: Group membership matches the new department structure exactly, with no accidental access loss.
Practice Tip: Before removing anyone, check what that group grants access to — cleanup tickets are a common source of accidental lockouts.
CATEGORY 2 — Exchange Online & Mail Services
LAB 13. Check Mailbox Size & Quota
🎫 TICKET
User's mailbox is 'almost full' — they want their current usage.
Objective: Locate mailbox size/quota information through the EAC and PowerShell.
Verification: You can state the exact mailbox size and quota limit.
Practice Tip: Get comfortable reading both the EAC UI and PowerShell output for the same data.
LAB 14. Grant Delegated Mailbox Access
🎫 TICKET
Manager needs Full Access + Send As on a departing employee's mailbox.
Objective: Practice granting approved delegated mailbox permissions.
Verification: The manager can open and send as the departing employee's mailbox.
Practice Tip: Never grant this without a documented, approved request — it's a common audit checkpoint.
LAB 15. Investigate a Missing Email with Message Trace
🎫 TICKET
Client never received an important quote sent yesterday.
Objective: Use Message Trace to determine exactly what happened to a message.
Verification: You can state exactly what happened to the message and why.
Practice Tip: Message Trace is one of the most-used L1 tools — learn its status codes cold.
LAB 16. Manage a Distribution List & Create a Shared Mailbox
🎫 TICKET
Add 2 employees to 'AllStaff-Announcements' and create an 'Events' shared mailbox.
Objective: Practice DL membership management and shared mailbox provisioning.
Verification: Both new members receive DL mail; the Events team can access the shared mailbox.
Practice Tip: Shared mailboxes are free under the storage limit — useful when licensing cost is questioned.
LAB 17. Set Up Out-of-Office on Behalf of a User on Leave
🎫 TICKET
Employee on emergency leave needs an OOF reply set up; they can't do it themselves.
Objective: Configure automatic replies on a user's behalf with proper authorization.
Verification: Internal and external senders receive the correct automatic reply during the leave period.
Practice Tip: Always get explicit permission before touching someone's mailbox settings, even for a simple OOF.
LAB 18. Investigate External Email Not Being Received
🎫 TICKET
User says they've stopped receiving any email from one specific external company.
Objective: Diagnose whether a block list or filtering rule is the cause.
Verification: New test emails from the external company reach the inbox.
Practice Tip: Check the user's own inbox rules, not just tenant block lists — self-created rules are an easy thing to overlook.
LAB 19. Resolve an Unwanted Auto-Forwarding Rule
🎫 TICKET
Security flags that a user's mailbox is silently forwarding mail to an external address.
Objective: Investigate and remediate a suspicious forwarding rule.
Verification: The forwarding rule is either confirmed legitimate and documented, or escalated as a possible compromise.
Practice Tip: Unexplained external auto-forwarding is one of the most common signs of a compromised mailbox — treat it seriously.
LAB 20. Enable Online Archive for a Long-Tenured User
🎫 TICKET
User with 10+ years of email history needs an archive mailbox enabled.
Objective: Practice enabling and explaining the in-place/online archive feature.
Verification: The Online Archive folder appears and is accessible in the user's mailbox.
Practice Tip: Check licensing first — not every plan includes archive mailbox rights by default.
LAB 21. Investigate a Duplicate Emails Complaint
🎫 TICKET
User says they're receiving every email twice.
Objective: Diagnose a common cause of duplicate message delivery.
Verification: The user receives each message only once going forward.
Practice Tip: This is rarely a 'server bug' — it's almost always a rule, duplicate mailbox connection, or DL overlap.
LAB 22. Manage Membership on a Moderated Distribution List
🎫 TICKET
Add a new team member to a DL that requires moderator approval for posts.
Objective: Practice managing a moderated distribution list correctly.
Verification: The new member is added and understands their messages require moderator approval.
Practice Tip: Don't accidentally change moderation settings while just trying to add a member — verify settings before and after.
LAB 23. Investigate a Bounce-Back (NDR) Message
🎫 TICKET
User got a bounce-back error when emailing a client and doesn't understand it.
Objective: Read and explain a non-delivery report to a non-technical user.
Verification: The user understands why the message bounced and what to do next.
Practice Tip: Learn the common NDR codes (5.1.1, 5.7.1, 4.4.7) — they come up constantly and instantly narrow the cause.
LAB 24. Update a Shared Mailbox's Display Name and Alias
🎫 TICKET
The 'Support' team rebranded and wants their shared mailbox renamed to match.
Objective: Practice updating a shared mailbox's identity without breaking existing mail flow.
Verification: The mailbox shows the new display name, and both old and new addresses receive mail.
Practice Tip: Add new addresses as aliases rather than immediately removing the old one — this avoids breaking existing contacts/links.
LAB 25. Convert a User Mailbox to a Shared Mailbox
🎫 TICKET
Departing employee's mailbox needs to become a team-accessible shared mailbox.
Objective: Practice the standard mailbox-type conversion during offboarding.
Verification: The mailbox is now shared, accessible to the team, and no longer needs a paid license.
Practice Tip: Confirm mailbox size is under the shared-mailbox limit before converting — oversized mailboxes need special handling.
LAB 26. Restore a Soft-Deleted Mailbox
🎫 TICKET
A user account was accidentally deleted yesterday; the mailbox needs to come back.
Objective: Practice restoring a recently deleted user/mailbox within the recovery window.
Verification: The account and mailbox are restored with mail history intact.
Practice Tip: Act quickly — soft-deleted accounts are only recoverable for a limited window (typically 30 days).
LAB 27. Fix a Resource (Meeting Room) Mailbox Booking Issue
🎫 TICKET
Bookings for the 'Conference Room A' resource mailbox are being auto-declined incorrectly.
Objective: Diagnose a room mailbox's booking/calendar processing settings.
Verification: A valid test booking for Conference Room A is now accepted correctly.
Practice Tip: Room mailbox issues are almost always a calendar-processing setting, not a 'broken' room — check settings before escalating.
LAB 28. Communicate a Reported Mail Flow Delay
🎫 TICKET
Multiple users report emails arriving 30+ minutes late this morning.
Objective: Practice checking service health and communicating a mail-flow delay professionally.
Verification: Affected users receive an accurate, timely update referencing the correct incident status.
Practice Tip: Always check Service Health first during a delay — it saves duplicate investigation across many tickets for the same root cause.
CATEGORY 3 — Microsoft Teams
LAB 29. Provision a New Team & Add Members
🎫 TICKET
Create a Team for 'Q4 Product Launch' and add the 6 listed members.
Objective: Practice creating and populating a new Team correctly.
Verification: All 6 members can see and post in the new Team with the correct owner assigned.
Practice Tip: Confirm privacy setting matches the request — getting this wrong causes access complaints later.
LAB 30. Resolve a Meeting-Policy Restriction
🎫 TICKET
User can't record Teams meetings — option is greyed out.
Objective: Diagnose and fix a feature restriction caused by an assigned meeting policy.
Verification: The recording option is now available to the user.
Practice Tip: Never create a new policy for this — check if an existing approved policy already covers it.
LAB 31. Fix a Private Channel Visibility Issue
🎫 TICKET
User says they can't find a channel their teammates are actively using.
Objective: Diagnose a private-channel membership issue.
Verification: The user can now see and access the private channel.
Practice Tip: Private channel membership is separate from Team membership — being in the Team doesn't guarantee access to every channel.
LAB 32. Reset Teams Client Cache for a Persistent Sign-In Error
🎫 TICKET
User's Teams app keeps showing a sign-in error even after multiple attempts.
Objective: Walk a user through the standard Teams cache-reset procedure.
Verification: The user signs into Teams successfully after the cache reset, or the real underlying block is identified.
Practice Tip: Cache resets fix a large share of 'random' Teams errors, but don't stop there if it doesn't resolve — check for a real sign-in block.
LAB 33. Rename a Team and Restructure Its Channels
🎫 TICKET
Project was renamed — update the Team name and reorganize channels per the new plan.
Objective: Practice safely updating Team-level settings and channel structure.
Verification: The Team reflects the new name and channel structure with no lost content.
Practice Tip: Archive channels instead of deleting them — deletion can permanently remove content members still need.
LAB 34. Add an External Guest to a Team for Client Collaboration
🎫 TICKET
Sales needs a client contact added to the 'Acme Deal' Team for a joint project.
Objective: Practice B2B guest invitation and scoped Teams access.
Verification: The external guest can access only the 'Acme Deal' Team as intended.
Practice Tip: Always note a review date for guest access — forgotten guest accounts are a common audit finding.
LAB 35. Troubleshoot a 'Can't Share Screen' Complaint
🎫 TICKET
User reports they can't share their screen during Teams meetings.
Objective: Diagnose whether the cause is a policy, permission, or client issue.
Verification: The user can successfully share their screen in a test meeting.
Practice Tip: Distinguish between a tenant-wide policy issue and a single meeting's organizer settings — they look identical to the user but have different fixes.
LAB 36. Restore an Accidentally Deleted Channel
🎫 TICKET
A user says they deleted a channel by mistake and needs it restored.
Objective: Practice channel recovery within the standard recovery window.
Verification: The channel and its content are restored and visible to members again.
Practice Tip: Act quickly — channel recovery is only available for a limited window after deletion.
LAB 37. Clarify a Large-Meeting Attendee Limit Question
🎫 TICKET
User is planning an all-hands meeting and isn't sure how many people can join.
Objective: Provide accurate guidance on meeting size limits and options.
Verification: The user selects and sets up the correct meeting format for their expected audience size.
Practice Tip: Confirm attendee count expectations early — switching meeting types close to the event date can cause a scramble.
LAB 38. Investigate Messages Not Syncing Across Devices
🎫 TICKET
User says a Teams chat isn't showing the same messages on their phone as their laptop.
Objective: Diagnose a sync inconsistency across Teams clients.
Verification: Messages appear consistently across both devices after the basic troubleshooting steps.
Practice Tip: Always confirm it's genuinely the same account on both devices first — a surprising number of 'sync' tickets are actually a second account.
CATEGORY 4 — SharePoint Online & OneDrive
LAB 39. Restore Site Access After a Team Restructure
🎫 TICKET
User lost access to the 'Marketing' site after a team restructure.
Objective: Diagnose and fix a standard site-access issue.
Verification: The user can open and edit files on the Marketing site.
Practice Tip: Site access issues are almost always a group-membership problem, not a broken site.
LAB 40. Fix Sync Issues & Recover a Deleted File
🎫 TICKET
OneDrive isn't syncing new files, and a deleted file needs recovering.
Objective: Resolve a sync issue and recover a file from the recycle bin.
erification: New files sync correctly, and the deleted file is restored.
Practice Tip: Always check the online recycle bin before telling a user a file is unrecoverable.
LAB 41. Resolve a Large File Upload Failure
🎫 TICKET
User can't upload a 20GB training video to a SharePoint library.
Objective: Diagnose a file-size or type restriction issue.
Verification: The file uploads successfully, or the user is redirected to an appropriate alternative.
Practice Tip: Large file uploads often succeed via the OneDrive/SharePoint sync client even when the browser upload times out — try that before escalating.
LAB 42. Fix Broken External Sharing Link Permissions
🎫 TICKET
An external partner says their shared link permission suddenly stopped working.
Objective: Diagnose and correct an external sharing link issue.
Verification: The external partner confirms they can access the shared content again.
Practice Tip: Check link expiration first — many 'broken sharing' tickets are simply an expired link, not a permissions bug.
LAB 43. Restore a Deleted SharePoint Site from the Recycle Bin
🎫 TICKET
A site was accidentally deleted last week and is needed back urgently.
Objective: Practice site-collection recovery from the second-stage recycle bin.
Verification: The site is restored with content and permissions intact.
Practice Tip: Site recovery has a firm cutoff window — always check the deletion date before promising a full recovery.
LAB 44. Investigate a Site Approaching Its Storage Quota
🎫 TICKET
A department site shows a storage warning and users can't upload new files.
Objective: Diagnose and address a site nearing its storage limit.
Verification: The site can accept new uploads again, either from cleanup or an approved quota increase.
Practice Tip: Don't request a blanket quota increase as a first response — check what's actually consuming space first.
LAB 45. Resolve a Document 'Checked Out' Lock Issue
🎫 TICKET
User can't edit a document that colleague accidentally left checked out before going on leave.
Objective: Diagnose and safely resolve a stuck document check-out.
Verification: The document is available for editing again with the appropriate resolution (checked in vs. discarded) documented.
Practice Tip: Get approval before forcing a check-in/discard — you could be undoing a colleague's unsaved work.
LAB 46. Transfer Ownership of an Orphaned Site
🎫 TICKET
A site's only owner has left the company and no one can manage its permissions anymore.
Objective: Practice reassigning ownership of a site left without an active owner.
Verification: The new owner can fully manage the site's permissions and content.
Practice Tip: Orphaned sites are a common audit finding — always confirm the departed owner's access is also removed, not just the new owner added.
LAB 47. Configure OneDrive Known Folder Move for a New Laptop
🎫 TICKET
User got a new laptop and wants Desktop/Documents automatically backed up to OneDrive like before.
Objective: Set up Known Folder Move (KFM) redirection for a new device.
Verification: Desktop, Documents, and Pictures folders are now syncing automatically to OneDrive on the new laptop.
Practice Tip: Confirm sync completion before the user assumes files are 'backed up' — large folders can take time to fully upload.
LAB 48. Investigate Missing Version History on a Document
🎫 TICKET
User says previous versions of an important document have disappeared.
Objective: Diagnose a version-history visibility or configuration issue.
Verification: The user understands why versions are or aren't available, and versioning is confirmed enabled going forward.
Practice Tip: Don't assume version history is always on — many libraries have it disabled by default or trimmed by a version-limit setting.
CATEGORY 5 — Endpoint & Device Management
LAB 49. Diagnose a Device Compliance Block
🎫 TICKET
User's laptop shows 'Not Compliant' and they can't access email on it.
Objective: Identify the specific compliance failure and guide the user to resolution.
Verification: The device shows Compliant and email access is restored.
Practice Tip: Compliance re-evaluation isn't instant — set the right expectation with the user about timing.
LAB 50. Troubleshoot a Failed BYOD Enrollment
🎫 TICKET
New employee's personal iPhone won't complete MDM enrollment.
Objective: Walk through and troubleshoot self-service device enrollment.
Verification: The device successfully completes enrollment and appears as managed in Intune.
Practice Tip: Keep the standard error-code guide bookmarked — most failures map to a handful of repeat causes.
LAB 51. Perform an Approved Selective Wipe
🎫 TICKET
Employee's phone was lost — manager approved wiping company data only.
Objective: Practice a correctly scoped, approved remote action on a lost device.
Verification: Company data is removed; personal data remains untouched (selective wipe).
Practice Tip: Always distinguish Retire (company data only) from Wipe (full factory reset).
LAB 52. Reset/Guide Re-Enrollment for a Locked Managed Device
🎫 TICKET
User forgot their device passcode and is now locked out.
Objective: Assist with regaining access to a managed device without a full wipe.
Verification: The user regains access to their device with a new passcode, or a properly approved wipe/re-enroll is completed.
Practice Tip: Not all platforms support a remote passcode reset — know your platform's limits before promising a quick fix.
LAB 53. Investigate an App Deployment Failure on a Managed Device
🎫 TICKET
A required business app failed to install on a user's managed laptop.
Objective: Diagnose a failed application deployment.
Verification: The app either installs successfully after retry, or is escalated with a clear error code and diagnosis.
Practice Tip: Note the exact error/status code — it saves L2 significant time if escalation is needed.
LAB 54. Fix a Device Not Showing Up in Intune After Enrollment
🎫 TICKET
User completed enrollment but IT can't find the device in the admin console.
Objective: Diagnose a check-in/sync delay or enrollment completion issue.
Verification: The device appears in the Intune device list, correctly associated with the user.
Practice Tip: A short delay between enrollment and console visibility is normal — don't panic immediately, but don't ignore it past a reasonable window either.
LAB 55. Assist with a Windows Autopilot Self-Deploy Failure
🎫 TICKET
New laptop is stuck during the Autopilot out-of-box setup screen.
Objective: Provide basic first-line troubleshooting for an Autopilot deployment issue.
Verification: The device either completes Autopilot setup, or is escalated with full diagnostic detail.
Practice Tip: Always capture the device serial number and exact error code — Autopilot issues are hard to diagnose remotely without them.
LAB 56. Resolve a Corporate Wi-Fi Profile Not Applying
🎫 TICKET
Managed laptop isn't automatically connecting to the corporate Wi-Fi network.
Objective: Diagnose a Wi-Fi configuration profile deployment issue.
Verification: The Wi-Fi profile successfully applies, and the device connects automatically.
Practice Tip: Check profile deployment status per-device before assuming a device-side issue — it may be a profile targeting problem instead.
LAB 57. Investigate a BitLocker/Encryption Compliance Failure
🎫 TICKET
Device is marked non-compliant specifically due to disk encryption not being enabled.
Objective: Diagnose and help resolve a BitLocker compliance failure.
Verification: The device shows BitLocker enabled and compliance status updates to Compliant.
Practice Tip: Always confirm the recovery key escrows successfully — encryption without an escrowed key is a support risk if the user is ever locked out.
LAB 58. Retire a Returned Corporate Device
🎫 TICKET
Employee returned their company laptop after resignation — needs to be retired from inventory.
Objective: Practice properly retiring a returned corporate device.
Verification: The device no longer shows as an active managed device and inventory records are updated.
Practice Tip: Always update the physical asset inventory too — Intune retirement alone doesn't track that the hardware itself was returned.
LAB 59. Fix a Company Portal App Stuck Installing
🎫 TICKET
User's Company Portal app is stuck at 'Installing' on their mobile device for over an hour.
Objective: Troubleshoot a stuck mobile app installation.
Verification: The app completes installation successfully, or is escalated with complete diagnostic detail.
Practice Tip: Storage space is a surprisingly common cause of 'stuck' mobile installs — check it early.
LAB 60. Investigate a Conditional Access Block Tied to Device Compliance
🎫 TICKET
User can access email on their phone but is blocked on their laptop with a compliance-related message.
Objective: Diagnose a Conditional Access block caused by device compliance status, and know when to escalate.
Verification: The block is either resolved via a compliance fix, or escalated with complete diagnostic detail.
Practice Tip: Compliance and Conditional Access are separate systems that work together — diagnosing which one is actually blocking access is the key L1 skill here.
CATEGORY 6 — Security & Threat Protection
LAB 61. Investigate and Release a Quarantined Message
🎫 TICKET
User says a legitimate vendor invoice went to quarantine.
Objective: Practice safely investigating and releasing (or escalating) a quarantined message.
Verification: The legitimate message is released, or the ticket is correctly escalated with reasoning.
Practice Tip: When a 'false positive' claim involves money or urgency, slow down — that's a classic phishing pattern.
LAB 62. Investigate Spam and Apply a Block-List Entry
🎫 TICKET
User is getting flooded with spam from a specific domain.
Objective: Practice spam triage and an approved block-list update.
Verification: New messages from the blocked domain no longer reach the inbox.
Practice Tip: Confirm the sender isn't a real contact before blocking — over-blocking creates new tickets.
LAB 63. Submit a Phishing Report and Confirm Tenant-Wide Protection
🎫 TICKET
User forwards a suspicious email claiming to be from IT asking for their password.
Objective: Practice the standard phishing-report submission workflow.
Verification: The phishing message is submitted for analysis, and its distribution scope is documented.
Practice Tip: Always check Threat Explorer for how many other mailboxes received the same message — a single report is often the tip of a larger campaign.
LAB 64. Investigate an Executive Impersonation Alert
🎫 TICKET
Defender flags an email impersonating the CEO's display name sent to Finance.
Objective: Review and appropriately handle an impersonation-protection alert.
Verification: The impersonation attempt is confirmed contained, with any user interaction fully documented and escalated if needed.
Practice Tip: Impersonation alerts targeting Finance/Payroll are frequently the first sign of a Business Email Compromise attempt — treat with urgency.
LAB 65. Review a Safe Links Click-Time Report
🎫 TICKET
User reports they clicked a link in an email that now seems suspicious.
Objective: Use Safe Links reporting to assess what happened when a link was clicked.
Verification: The click outcome is clearly determined, and appropriate next steps (reassurance or escalation) are taken.
Practice Tip: A 'blocked' verdict means Safe Links did its job — but always check the actual verdict rather than assuming based on the user's worry alone.
LAB 66. Check a Safe Attachments Detonation Result
🎫 TICKET
User's email with a PDF attachment was delayed — they ask why.
Objective: Explain a Safe Attachments scanning delay and confirm its result.
Verification: The user receives an accurate explanation, and any genuinely malicious attachment is escalated rather than released.
Practice Tip: A short delivery delay for attachments is expected behavior, not a bug — knowing this prevents unnecessary escalations.
LAB 67. Investigate a 'My Account Sent Spam' Complaint
🎫 TICKET
A colleague tells the user that they've been receiving spam-like emails from the user's own address.
Objective: Diagnose a possible account compromise indicated by outbound spam.
Verification: The account is confirmed either compromised (and escalated/secured) or spoofed (and explained), never left ambiguous.
Practice Tip: Spoofing (fake sender address) and compromise (real account misuse) look similar to the reporting user but require very different responses — the sign-in logs are what tell them apart.
LAB 68. Review Anti-Spam Quarantine Notification Settings
🎫 TICKET
User complains they never get notified when something of theirs is quarantined.
Objective: Check and explain quarantine notification configuration for a user.
Verification: The user starts receiving quarantine notifications as expected.
Practice Tip: Distinguish between a tenant-wide policy setting (needs L2) and a personal notification preference (L1 can usually help directly).
LAB 69. Assist with Attack Simulation Training Follow-Up
🎫 TICKET
A user failed a simulated phishing test and has been assigned follow-up training.
Objective: Support the attack simulation training remediation process.
Verification: The user can access and begins their assigned phishing-awareness training.
Practice Tip: Simulation failures are a training opportunity, not a disciplinary matter — the tone of your communication with the user matters.
LAB 70. Check the Tenant Allow/Block List for a Wrongly Blocked Sender
🎫 TICKET
A legitimate newsletter the marketing team subscribed to is being blocked tenant-wide.
Objective: Investigate and correct an overly broad block-list entry.
Verification: Messages from the sender now deliver normally without being blocked.
Practice Tip: Before removing any block, check why it was added in the first place — it may have been blocked for a good reason that's still relevant.
LAB 71. Investigate a 'Suspicious Sign-In' Alert Email with a User
🎫 TICKET
User receives a Microsoft security alert about a sign-in from an unfamiliar location and isn't sure if it's real.
Objective: Help a user assess and respond to a genuine security alert.
Verification: The sign-in is correctly classified as expected or suspicious, with appropriate action taken for either outcome.
Practice Tip: Teach users to check sign-in activity through the official admin/account portal rather than clicking links in the alert email itself — this also protects against alert-themed phishing.
LAB 72. Review Secure Score Recommendations for L2 Handoff
🎫 TICKET
L2 asks you to pull this month's Secure Score report and flag any new recommendations.
Objective: Practice reviewing and summarizing Secure Score data for escalation.
Verification: L2 receives a clear, accurate summary of new Secure Score recommendations for their review.
Practice Tip: Your role here is reporting, not implementation — most Secure Score actions involve tenant-wide policy changes reserved for L2/L3.
CATEGORY 7 — Compliance & Data Governance
LAB 73. Run a Supervised Content Search
🎫 TICKET
HR needs to know if a former employee sent emails externally in their last week — assist under supervision.
Objective: Practice running a properly scoped, approved content search.
Verification: The search results match the approved scope exactly, with nothing broader searched.
Practice Tip: Never widen scope on your own judgment — stick exactly to what was approved.
LAB 74. Explain a DLP Policy Tip to an End User
🎫 TICKET
User got a warning banner emailing a spreadsheet to a personal Gmail address.
Objective: Practice explaining a DLP trigger correctly without attempting to override it.
Verification: The user understands the policy trigger and either adjusts their approach or the case is escalated.
Practice Tip: Your job is to explain, not override — DLP policy changes always require L2 sign-off.
LAB 75. Check Retention & Explain Recoverability
🎫 TICKET
User accidentally deleted an email from 3 months ago and wants it back.
Objective: Practice checking retention status and giving an accurate recoverability answer.
Verification: The user receives a clear, accurate, correctly sourced recoverability answer.
Practice Tip: Know the difference between what's retained and what L1 can actually restore.
LAB 76. Verify a Sensitivity Label Is Applied Correctly
🎫 TICKET
Legal asks you to confirm a contract document has the 'Confidential' label properly applied.
Objective: Practice checking sensitivity label application and protection behavior.
Verification: The document shows the correct sensitivity label with its protections active.
Practice Tip: Applying a label and having its protections actually enforce correctly are two different things — verify both.
LAB 77. Investigate a 'Can't Share Externally' Complaint
🎫 TICKET
User says they can no longer share a specific file with an external partner as they did last month.
Objective: Diagnose whether a DLP rule or a sharing policy change is the cause.
Verification: The actual blocking mechanism (DLP vs. sharing policy) is correctly identified and communicated or escalated.
Practice Tip: These two systems produce similar-looking 'can't share' symptoms but require completely different fixes — always identify which one first.
LAB 78. Check the Audit Log for a Specific File-Access Investigation
🎫 TICKET
Manager asks whether a specific employee accessed a sensitive file last Tuesday.
Objective: Practice a guided, read-only audit log search for a legitimate investigation request.
Verification: An accurate, appropriately scoped answer is provided only to the approved requester.
Practice Tip: Audit findings about a specific employee are sensitive — never share results outside the approved request chain.
LAB 79. Assist with a Data Subject Access Request (DSAR)
🎫 TICKET
Legal is processing a former employee's request for their personal data — needs a scoped mailbox search.
Objective: Support a DSAR under L2/legal supervision.
Verification: The search is completed exactly to the approved scope, with export handled by the appropriate authorized party.
Practice Tip: DSARs have strict legal timelines and confidentiality requirements — always follow legal's exact scope, never your own judgment.
LAB 80. Verify Litigation Hold Status on a Mailbox
🎫 TICKET
Legal team asks you to confirm a specific mailbox is under litigation hold before an employee's planned offboarding.
Objective: Practice a read-only litigation hold status check.
Verification: Legal receives an accurate hold status, and no offboarding action is taken prematurely.
Practice Tip: A mailbox under litigation hold must not be altered or converted until legal explicitly clears it — this overrides normal offboarding steps.
LAB 81. Review the Insider Risk Alert Dashboard
🎫 TICKET
L2 asks for a read-only summary of this week's insider risk alerts before a compliance meeting.
Objective: Practice reviewing insider risk alerts at a triage level.
Verification: L2 receives an accurate, appropriately high-level summary in time for the meeting.
Practice Tip: Insider risk case details are highly sensitive — your role is aggregate reporting, not individual case investigation.
LAB 82. Review a Communication Compliance Flagged Message
🎫 TICKET
A message was flagged by a communication compliance policy for review — L2 asks you to confirm it reached the review queue correctly.
Objective: Practice a basic, read-only check of the communication compliance workflow.
Verification: L2 receives confirmation that the flagged item is correctly in the review queue.
Practice Tip: Confirming workflow mechanics is different from reviewing content — stay within the mechanical check unless you're an authorized reviewer.
CATEGORY 8 — Identity Security, Monitoring & Advanced Administration
LAB 83. Reset a User's MFA Method After a Device Change
🎫 TICKET
User got a new phone and isn't receiving MFA codes anymore.
Objective: Practice a verified MFA method reset and re-registration.
Verification: The user successfully signs in using their newly registered MFA method.
Practice Tip: Never skip identity verification for an MFA reset, even under time pressure.
LAB 84. Diagnose a Conditional Access Block & Escalate
🎫 TICKET
User traveling abroad suddenly can't log in at all.
Objective: Practice diagnosing (without modifying) a Conditional Access-related block.
Verification: The ticket is escalated with complete diagnostic detail, ready for immediate L2 action.
Practice Tip: Your value here is diagnosis, not the fix — good documentation saves L2 significant time.
LAB 85. Process a Privileged Role Request Correctly
🎫 TICKET
A team lead requests Helpdesk Administrator rights to assist with password resets.
Objective: Practice routing a privileged access request through proper approval.
Verification: The role request is fully documented and correctly routed — no direct L1 grant made.
Practice Tip: Even a 'small' admin role is still privileged access — always goes through the approval workflow.
LAB 86. Triage Overnight Security Alerts
🎫 TICKET
The Defender dashboard shows 3 new medium-severity alerts overnight.
Objective: Practice first-pass alert triage using the incident-response checklist.
Verification: All 3 alerts are triaged and either explained-and-logged or escalated within SLA.
Practice Tip: 'Medium severity' doesn't mean 'not urgent' — triage promptly every time.
LAB 87. Run a Pre-Approved Reporting Script Safely
🎫 TICKET
L2 asks for a report of mailboxes over 90% quota using a provided script.
Objective: Practice safely running a read-only PowerShell script provided by L2.
Verification: An accurate report is generated and delivered, with no write actions taken.
Practice Tip: If a script contains any New-/Set-/Remove- cmdlet, stop and confirm explicit sign-off first.
LAB 88. Use an Existing Graph-Based Reporting Dashboard
🎫 TICKET
Pull this month's new-user count from the existing Graph-based dashboard for the ops report.
Objective: Practice using and sanity-checking a Graph-powered internal reporting tool.
Verification: The correct figure is reported, with source and sanity-check documented.
Practice Tip: Understanding what's behind the dashboard makes you far more useful when something looks off.
LAB 89. Diagnose a Stale-Attribute Sync Issue
🎫 TICKET
User's phone number update in on-prem AD isn't reflecting in Outlook/Teams.
Objective: Practice checking Entra Connect sync health for a stale-attribute complaint.
Verification: A complete, well-documented escalation ticket is ready for L2, including sync health status.
Practice Tip: 'Probably a sync issue' isn't enough — always check and report actual sync health first.
LAB 90. Investigate a GAL Visibility Issue Post-Migration
🎫 TICKET
User migrated to Exchange Online last week still can't be found in the Global Address List.
Objective: Practice a read-only hybrid mailbox/sync lookup before escalating.
Verification: A complete diagnostic handoff is ready for L2, with all read-only checks completed.
Practice Tip: Many GAL tickets are just normal propagation delay — check timestamps before assuming a break.
LAB 91. Recover Missing Emails & Identify a Possible Migration Gap
🎫 TICKET
User says several emails from last week are completely missing, not even in Deleted Items.
Objective: Practice in-place recovery and correctly identifying when to escalate.
Verification: A complete, well-documented ticket is ready for L2 with all read-only checks completed.
Practice Tip: Always rule out the simple explanation before assuming something more serious like a migration gap.
LAB 92. Investigate a Risky Sign-In Flagged by Identity Protection
🎫 TICKET
Entra ID Protection flags a 'risky sign-in' for a user overnight.
Objective: Practice a read-only triage of an Identity Protection risk detection.
Verification: The risky sign-in is either explained and logged, or escalated promptly with full detail.
Practice Tip: Never dismiss a risk flag purely because the user 'says it's fine' without at least a basic cross-check of details.
LAB 93. Check a PIM Activation Request Status
🎫 TICKET
User says they requested a Privileged Identity Management role activation an hour ago and it's still pending.
Objective: Practice checking (read-only) a PIM activation request's status.
Verification: The activation request's exact status and blocker is identified, with appropriate follow-up taken.
Practice Tip: PIM approvals often stall simply because the approver hasn't acted yet — checking the workflow status avoids assuming a technical fault.
LAB 94. Investigate a Self-Service Password Reset (SSPR) Failure
🎫 TICKET
User says the self-service password reset tool won't accept their registered phone number.
Objective: Diagnose a common SSPR configuration or registration issue.
Verification: The user either successfully completes SSPR, or understands why it isn't available and what the alternative is.
Practice Tip: A stale registered phone number is one of the most common causes of 'SSPR doesn't work' tickets.
LAB 95. Review a Failed Multi-Factor Challenge in Sign-In Logs
🎫 TICKET
User says they keep getting an MFA prompt but it always fails, even though they enter the code correctly.
Objective: Diagnose a recurring MFA failure using sign-in log detail.
Verification: The user completes MFA successfully after the specific cause is corrected.
Practice Tip: Authenticator app time-sync drift is a frequently overlooked cause of 'my code never works' tickets.
LAB 96. Check Service Health Before Escalating a Reported Outage
🎫 TICKET
Multiple users report they can't access Outlook on the web at the same time.
Objective: Practice checking Service Health first during a suspected widespread issue.
Verification: Affected users receive a consistent, accurate status update tied to the correct incident ID.
Practice Tip: Always check Service Health first for multi-user reports — it can turn 10 separate tickets into one tracked incident.
LAB 97. Review a Message Center Post for an Upcoming Change
🎫 TICKET
L2 asks you to review this week's Message Center posts and flag anything affecting end users.
Objective: Practice proactive Message Center monitoring and impact assessment.
Verification: L2 receives a clear summary of upcoming changes relevant to end users, with dates noted.
Practice Tip: Catching a disruptive change in the Message Center before it happens prevents a wave of confused tickets after the fact.
LAB 98. Assist with a Guest User Access Review
🎫 TICKET
An access review campaign is running for external guests on a sensitive Team, and a manager needs help completing it.
Objective: Support a scheduled Entra ID access review as an L1 facilitator.
Verification: All guest decisions are recorded accurately and submitted before the review deadline.
Practice Tip: Access reviews have hard deadlines — a late submission can result in default (often overly permissive) access decisions.
LAB 99. Run a Basic Read-Only Graph PowerShell Query for a User Attribute
🎫 TICKET
L2 asks you to confirm a specific user's usage location attribute via Graph PowerShell as part of a licensing troubleshoot.
Objective: Practice a basic, safe, read-only Microsoft Graph PowerShell query.
Verification: The correct attribute value is confirmed and reported accurately to L2.
Practice Tip: Even simple read-only Graph queries are a great way to build comfort with the tool L2/L3 use for everything else — practice them whenever asked.
LAB 100. Document and Escalate a Suspected Compromised Account
🎫 TICKET
Multiple signs point to a user's account being compromised: unusual sign-ins, a new forwarding rule, and sent-spam reports.
Objective: Practice the full documentation and escalation workflow for a suspected compromise — the most critical L1 judgment call.
Verification: The account is contained, evidence is fully documented, and L2/L3 has everything needed to continue the investigation without delay.
Practice Tip: This is the single most important escalation type in the entire lab set — speed and complete documentation matter more here than anywhere else.