Courses Job Ready Program Fresher Trainings AI For Class 7 to 12 Corporate Training Placements Tutorials
Free Learning Resources

IT Tutorials & Interview Prep

Free guides, interview Q&As, and job responsibility breakdowns — curated by industry veterans to help you crack MNC interviews

236+
Tutorial Articles
16
Topic Categories
100%
Free to Read
← Back to Microsoft 365 Administrator (MS-102) Lab Module

Microsoft 365 Administrator (MS-102) Internship Program Lab Module

Microsoft 365 Administrator (MS-102) Lab Module Last Updated: Sep 05, 2026

Microsoft 365 Administrator (MS-102) Internship Program Lab Module

CATEGORY 1  —  Identity, Users & Tenant Governance

LAB 1.  Unlock & Reset a Locked-Out User Account

🎫 TICKET

User Priya Sharma is locked out after 5 failed password attempts.

Objective: Practice identity verification and a standard password reset/unlock in Microsoft Entra ID.

Verification: The user signs in with the temporary password and is prompted to change it.

Practice Tip: Always verify identity before any reset — this is the top social-engineering target on a helpdesk.

LAB 2.  Onboard a New User & Assign Group Membership

🎫 TICKET

New hire Rahul Verma starts Monday — create his account and add him to Sales.

Objective: Practice standard new-user onboarding end-to-end.

Verification: Rahul's account appears under Active users and the Sales group's member list.

Practice Tip: Double-check username spelling and domain — renaming later is more work than getting it right first.

LAB 3.  Diagnose a Missing-App Issue Caused by Licensing

🎫 TICKET

Meena Iyer says Teams is missing from her Office apps.

Objective: Diagnose and resolve a missing-app complaint caused by a licensing gap.

Verification: Teams shows enabled under Meena's license and she can launch it.

Practice Tip: 'Missing app' tickets are almost always licensing — check licenses before assuming a bug.

LAB 4.  Bulk-Create Users from an Approved CSV Batch

🎫 TICKET

HR sends an approved CSV of 8 new campus hires starting the same day.

Objective: Practice a small, supervised bulk user-creation workflow.

Verification: All 8 accounts appear active with correct licenses assigned.

Practice Tip: Always review the validation screen before confirming — one bad row can silently skip a whole account.

LAB 5.  Offboard a Departing Employee

🎫 TICKET

Employee's last day is Friday — disable access and convert mailbox to shared per policy.

Objective: Practice a complete, policy-compliant offboarding sequence.

Verification: The account can no longer sign in, and the mailbox is retained as a shared mailbox.

Practice Tip: Never delete an account outright on day one — disabling first protects against needing quick reversal.

LAB 6.  Fix a Duplicate/Incorrect UPN Blocking Sign-In

🎫 TICKET

User can't sign in — error suggests the username may already exist.

Objective: Diagnose and correct a UPN conflict.

Verification: The user signs in successfully with a unique, correct UPN.

Practice Tip: Search broadly (including disabled accounts) — duplicate UPN issues often hide in old, inactive accounts.

LAB 7.  Update Profile Attributes for Org Chart Accuracy

🎫 TICKET

New reporting structure — update 5 users' manager and department fields.

Objective: Practice bulk-style profile attribute updates.

Verification: All 5 users show the correct manager and department in their profile.

Practice Tip: Manager-field accuracy affects approval workflows elsewhere (like access requests) — treat it as more than cosmetic.

LAB 8.  Investigate an Unexpectedly Disabled Account

🎫 TICKET

User says their account was working yesterday but is now disabled.

Objective: Diagnose why an account was disabled and determine next steps.

Verification: The cause is identified and the account is either safely re-enabled or correctly escalated.

Practice Tip: Never re-enable an account disabled by a security action without escalating first — it may be an active containment step.

LAB 9.  Resolve a Shared Calendar Visibility Issue

🎫 TICKET

User can't see a colleague's calendar despite being told they should have access.

Objective: Diagnose a calendar-sharing/group-membership issue.

Verification: The user can now see the colleague's calendar at the expected permission level.

Practice Tip: Clarify the expected access level (free/busy only vs. full details) before granting — over-granting is a common mistake.

LAB 10.  Reclaim a License from an Inactive Account

🎫 TICKET

Finance flags a license assigned to an account that's been inactive for 60 days.

Objective: Practice license reclamation as part of routine tenant hygiene.

Verification: The license is removed from the inactive account and reassigned to an active user.

Practice Tip: Always confirm with HR/manager before touching a license — 'inactive' isn't always the same as 'terminated.'

LAB 11.  Process a Legal Name Change (UPN/Display Name Update)

🎫 TICKET

Employee legally changed their name and needs their account updated to match.

Objective: Practice updating identity details following a legal name change request.

Verification: The user's profile, display name, and email reflect the new legal name, with the old address still working as an alias.

Practice Tip: Keep the old address as an alias — breaking it can cause missed emails from external contacts still using the old address.

LAB 12.  Clean Up Group Membership After a Department Restructuring

🎫 TICKET

Marketing and Sales merged into one department — group memberships need reconciling.

Objective: Practice a supervised group-membership cleanup project.

Verification: Group membership matches the new department structure exactly, with no accidental access loss.

Practice Tip: Before removing anyone, check what that group grants access to — cleanup tickets are a common source of accidental lockouts.

CATEGORY 2  —  Exchange Online & Mail Services

LAB 13.  Check Mailbox Size & Quota

🎫 TICKET

User's mailbox is 'almost full' — they want their current usage.

Objective: Locate mailbox size/quota information through the EAC and PowerShell.

Verification: You can state the exact mailbox size and quota limit.

Practice Tip: Get comfortable reading both the EAC UI and PowerShell output for the same data.

LAB 14.  Grant Delegated Mailbox Access

🎫 TICKET

Manager needs Full Access + Send As on a departing employee's mailbox.

Objective: Practice granting approved delegated mailbox permissions.

Verification: The manager can open and send as the departing employee's mailbox.

Practice Tip: Never grant this without a documented, approved request — it's a common audit checkpoint.

LAB 15.  Investigate a Missing Email with Message Trace

🎫 TICKET

Client never received an important quote sent yesterday.

Objective: Use Message Trace to determine exactly what happened to a message.

Verification: You can state exactly what happened to the message and why.

Practice Tip: Message Trace is one of the most-used L1 tools — learn its status codes cold.

LAB 16.  Manage a Distribution List & Create a Shared Mailbox

🎫 TICKET

Add 2 employees to 'AllStaff-Announcements' and create an 'Events' shared mailbox.

Objective: Practice DL membership management and shared mailbox provisioning.

Verification: Both new members receive DL mail; the Events team can access the shared mailbox.

Practice Tip: Shared mailboxes are free under the storage limit — useful when licensing cost is questioned.

LAB 17.  Set Up Out-of-Office on Behalf of a User on Leave

🎫 TICKET

Employee on emergency leave needs an OOF reply set up; they can't do it themselves.

Objective: Configure automatic replies on a user's behalf with proper authorization.

Verification: Internal and external senders receive the correct automatic reply during the leave period.

Practice Tip: Always get explicit permission before touching someone's mailbox settings, even for a simple OOF.

LAB 18.  Investigate External Email Not Being Received

🎫 TICKET

User says they've stopped receiving any email from one specific external company.

 

Objective: Diagnose whether a block list or filtering rule is the cause.

Verification: New test emails from the external company reach the inbox.

Practice Tip: Check the user's own inbox rules, not just tenant block lists — self-created rules are an easy thing to overlook.

LAB 19.  Resolve an Unwanted Auto-Forwarding Rule

🎫 TICKET

Security flags that a user's mailbox is silently forwarding mail to an external address.

 

Objective: Investigate and remediate a suspicious forwarding rule.

Verification: The forwarding rule is either confirmed legitimate and documented, or escalated as a possible compromise.

Practice Tip: Unexplained external auto-forwarding is one of the most common signs of a compromised mailbox — treat it seriously.

LAB 20.  Enable Online Archive for a Long-Tenured User

🎫 TICKET

User with 10+ years of email history needs an archive mailbox enabled.

Objective: Practice enabling and explaining the in-place/online archive feature.

Verification: The Online Archive folder appears and is accessible in the user's mailbox.

Practice Tip: Check licensing first — not every plan includes archive mailbox rights by default.

LAB 21.  Investigate a Duplicate Emails Complaint

🎫 TICKET

User says they're receiving every email twice.

Objective: Diagnose a common cause of duplicate message delivery.

Verification: The user receives each message only once going forward.

Practice Tip: This is rarely a 'server bug' — it's almost always a rule, duplicate mailbox connection, or DL overlap.

LAB 22.  Manage Membership on a Moderated Distribution List

🎫 TICKET

Add a new team member to a DL that requires moderator approval for posts.

Objective: Practice managing a moderated distribution list correctly.

Verification: The new member is added and understands their messages require moderator approval.

Practice Tip: Don't accidentally change moderation settings while just trying to add a member — verify settings before and after.

LAB 23.  Investigate a Bounce-Back (NDR) Message

🎫 TICKET

User got a bounce-back error when emailing a client and doesn't understand it.

Objective: Read and explain a non-delivery report to a non-technical user.

Verification: The user understands why the message bounced and what to do next.

Practice Tip: Learn the common NDR codes (5.1.1, 5.7.1, 4.4.7) — they come up constantly and instantly narrow the cause.

LAB 24.  Update a Shared Mailbox's Display Name and Alias

🎫 TICKET

The 'Support' team rebranded and wants their shared mailbox renamed to match.

Objective: Practice updating a shared mailbox's identity without breaking existing mail flow.

Verification: The mailbox shows the new display name, and both old and new addresses receive mail.

Practice Tip: Add new addresses as aliases rather than immediately removing the old one — this avoids breaking existing contacts/links.

LAB 25.  Convert a User Mailbox to a Shared Mailbox

🎫 TICKET

Departing employee's mailbox needs to become a team-accessible shared mailbox.

Objective: Practice the standard mailbox-type conversion during offboarding.

Verification: The mailbox is now shared, accessible to the team, and no longer needs a paid license.

Practice Tip: Confirm mailbox size is under the shared-mailbox limit before converting — oversized mailboxes need special handling.

LAB 26.  Restore a Soft-Deleted Mailbox

🎫 TICKET

A user account was accidentally deleted yesterday; the mailbox needs to come back.

 

Objective: Practice restoring a recently deleted user/mailbox within the recovery window.

Verification: The account and mailbox are restored with mail history intact.

Practice Tip: Act quickly — soft-deleted accounts are only recoverable for a limited window (typically 30 days).

LAB 27.  Fix a Resource (Meeting Room) Mailbox Booking Issue

🎫 TICKET

Bookings for the 'Conference Room A' resource mailbox are being auto-declined incorrectly.

Objective: Diagnose a room mailbox's booking/calendar processing settings.

Verification: A valid test booking for Conference Room A is now accepted correctly.

Practice Tip: Room mailbox issues are almost always a calendar-processing setting, not a 'broken' room — check settings before escalating.

LAB 28.  Communicate a Reported Mail Flow Delay

🎫 TICKET

Multiple users report emails arriving 30+ minutes late this morning.

Objective: Practice checking service health and communicating a mail-flow delay professionally.

Verification: Affected users receive an accurate, timely update referencing the correct incident status.

Practice Tip: Always check Service Health first during a delay — it saves duplicate investigation across many tickets for the same root cause.

CATEGORY 3  —  Microsoft Teams

LAB 29.  Provision a New Team & Add Members

🎫 TICKET

Create a Team for 'Q4 Product Launch' and add the 6 listed members.

Objective: Practice creating and populating a new Team correctly.

Verification: All 6 members can see and post in the new Team with the correct owner assigned.

Practice Tip: Confirm privacy setting matches the request — getting this wrong causes access complaints later.

LAB 30.  Resolve a Meeting-Policy Restriction

🎫 TICKET

User can't record Teams meetings — option is greyed out.

Objective: Diagnose and fix a feature restriction caused by an assigned meeting policy.

Verification: The recording option is now available to the user.

Practice Tip: Never create a new policy for this — check if an existing approved policy already covers it.

LAB 31.  Fix a Private Channel Visibility Issue

🎫 TICKET

User says they can't find a channel their teammates are actively using.

Objective: Diagnose a private-channel membership issue.

Verification: The user can now see and access the private channel.

Practice Tip: Private channel membership is separate from Team membership — being in the Team doesn't guarantee access to every channel.

LAB 32.  Reset Teams Client Cache for a Persistent Sign-In Error

🎫 TICKET

User's Teams app keeps showing a sign-in error even after multiple attempts.

Objective: Walk a user through the standard Teams cache-reset procedure.

Verification: The user signs into Teams successfully after the cache reset, or the real underlying block is identified.

Practice Tip: Cache resets fix a large share of 'random' Teams errors, but don't stop there if it doesn't resolve — check for a real sign-in block.

LAB 33.  Rename a Team and Restructure Its Channels

🎫 TICKET

Project was renamed — update the Team name and reorganize channels per the new plan.

Objective: Practice safely updating Team-level settings and channel structure.

Verification: The Team reflects the new name and channel structure with no lost content.

Practice Tip: Archive channels instead of deleting them — deletion can permanently remove content members still need.

LAB 34.  Add an External Guest to a Team for Client Collaboration

🎫 TICKET

Sales needs a client contact added to the 'Acme Deal' Team for a joint project.

Objective: Practice B2B guest invitation and scoped Teams access.

Verification: The external guest can access only the 'Acme Deal' Team as intended.

Practice Tip: Always note a review date for guest access — forgotten guest accounts are a common audit finding.

LAB 35.  Troubleshoot a 'Can't Share Screen' Complaint

🎫 TICKET

User reports they can't share their screen during Teams meetings.

Objective: Diagnose whether the cause is a policy, permission, or client issue.

Verification: The user can successfully share their screen in a test meeting.

Practice Tip: Distinguish between a tenant-wide policy issue and a single meeting's organizer settings — they look identical to the user but have different fixes.

LAB 36.  Restore an Accidentally Deleted Channel

🎫 TICKET

A user says they deleted a channel by mistake and needs it restored.

Objective: Practice channel recovery within the standard recovery window.

Verification: The channel and its content are restored and visible to members again.

Practice Tip: Act quickly — channel recovery is only available for a limited window after deletion.

LAB 37.  Clarify a Large-Meeting Attendee Limit Question

🎫 TICKET

User is planning an all-hands meeting and isn't sure how many people can join.

Objective: Provide accurate guidance on meeting size limits and options.

Verification: The user selects and sets up the correct meeting format for their expected audience size.

Practice Tip: Confirm attendee count expectations early — switching meeting types close to the event date can cause a scramble.

LAB 38.  Investigate Messages Not Syncing Across Devices

🎫 TICKET

User says a Teams chat isn't showing the same messages on their phone as their laptop.

Objective: Diagnose a sync inconsistency across Teams clients.

 

Verification: Messages appear consistently across both devices after the basic troubleshooting steps.

Practice Tip: Always confirm it's genuinely the same account on both devices first — a surprising number of 'sync' tickets are actually a second account.

CATEGORY 4  —  SharePoint Online & OneDrive

LAB 39.  Restore Site Access After a Team Restructure

🎫 TICKET

User lost access to the 'Marketing' site after a team restructure.

Objective: Diagnose and fix a standard site-access issue.

Verification: The user can open and edit files on the Marketing site.

Practice Tip: Site access issues are almost always a group-membership problem, not a broken site.

LAB 40.  Fix Sync Issues & Recover a Deleted File

🎫 TICKET

OneDrive isn't syncing new files, and a deleted file needs recovering.

Objective: Resolve a sync issue and recover a file from the recycle bin.

erification: New files sync correctly, and the deleted file is restored.

Practice Tip: Always check the online recycle bin before telling a user a file is unrecoverable.

LAB 41.  Resolve a Large File Upload Failure

🎫 TICKET

User can't upload a 20GB training video to a SharePoint library.

Objective: Diagnose a file-size or type restriction issue.

Verification: The file uploads successfully, or the user is redirected to an appropriate alternative.

Practice Tip: Large file uploads often succeed via the OneDrive/SharePoint sync client even when the browser upload times out — try that before escalating.

LAB 42.  Fix Broken External Sharing Link Permissions

🎫 TICKET

An external partner says their shared link permission suddenly stopped working.

Objective: Diagnose and correct an external sharing link issue.

Verification: The external partner confirms they can access the shared content again.

Practice Tip: Check link expiration first — many 'broken sharing' tickets are simply an expired link, not a permissions bug.

LAB 43.  Restore a Deleted SharePoint Site from the Recycle Bin

🎫 TICKET

A site was accidentally deleted last week and is needed back urgently.

Objective: Practice site-collection recovery from the second-stage recycle bin.

Verification: The site is restored with content and permissions intact.

Practice Tip: Site recovery has a firm cutoff window — always check the deletion date before promising a full recovery.

LAB 44.  Investigate a Site Approaching Its Storage Quota

🎫 TICKET

A department site shows a storage warning and users can't upload new files.

Objective: Diagnose and address a site nearing its storage limit.

Verification: The site can accept new uploads again, either from cleanup or an approved quota increase.

Practice Tip: Don't request a blanket quota increase as a first response — check what's actually consuming space first.

LAB 45.  Resolve a Document 'Checked Out' Lock Issue

🎫 TICKET

User can't edit a document that colleague accidentally left checked out before going on leave.

Objective: Diagnose and safely resolve a stuck document check-out.

Verification: The document is available for editing again with the appropriate resolution (checked in vs. discarded) documented.

Practice Tip: Get approval before forcing a check-in/discard — you could be undoing a colleague's unsaved work.

LAB 46.  Transfer Ownership of an Orphaned Site

🎫 TICKET

A site's only owner has left the company and no one can manage its permissions anymore.

Objective: Practice reassigning ownership of a site left without an active owner.

Verification: The new owner can fully manage the site's permissions and content.

Practice Tip: Orphaned sites are a common audit finding — always confirm the departed owner's access is also removed, not just the new owner added.

LAB 47.  Configure OneDrive Known Folder Move for a New Laptop

🎫 TICKET

User got a new laptop and wants Desktop/Documents automatically backed up to OneDrive like before.

Objective: Set up Known Folder Move (KFM) redirection for a new device.

Verification: Desktop, Documents, and Pictures folders are now syncing automatically to OneDrive on the new laptop.

Practice Tip: Confirm sync completion before the user assumes files are 'backed up' — large folders can take time to fully upload.

LAB 48.  Investigate Missing Version History on a Document

🎫 TICKET

User says previous versions of an important document have disappeared.

Objective: Diagnose a version-history visibility or configuration issue.

Verification: The user understands why versions are or aren't available, and versioning is confirmed enabled going forward.

Practice Tip: Don't assume version history is always on — many libraries have it disabled by default or trimmed by a version-limit setting.

CATEGORY 5  —  Endpoint & Device Management

LAB 49.  Diagnose a Device Compliance Block

🎫 TICKET

User's laptop shows 'Not Compliant' and they can't access email on it.

Objective: Identify the specific compliance failure and guide the user to resolution.

Verification: The device shows Compliant and email access is restored.

Practice Tip: Compliance re-evaluation isn't instant — set the right expectation with the user about timing.

LAB 50.  Troubleshoot a Failed BYOD Enrollment

🎫 TICKET

New employee's personal iPhone won't complete MDM enrollment.

Objective: Walk through and troubleshoot self-service device enrollment.

Verification: The device successfully completes enrollment and appears as managed in Intune.

Practice Tip: Keep the standard error-code guide bookmarked — most failures map to a handful of repeat causes.

LAB 51.  Perform an Approved Selective Wipe

🎫 TICKET

Employee's phone was lost — manager approved wiping company data only.

Objective: Practice a correctly scoped, approved remote action on a lost device.

Verification: Company data is removed; personal data remains untouched (selective wipe).

Practice Tip: Always distinguish Retire (company data only) from Wipe (full factory reset).

LAB 52.  Reset/Guide Re-Enrollment for a Locked Managed Device

🎫 TICKET

User forgot their device passcode and is now locked out.

Objective: Assist with regaining access to a managed device without a full wipe.

Verification: The user regains access to their device with a new passcode, or a properly approved wipe/re-enroll is completed.

Practice Tip: Not all platforms support a remote passcode reset — know your platform's limits before promising a quick fix.

LAB 53.  Investigate an App Deployment Failure on a Managed Device

🎫 TICKET

A required business app failed to install on a user's managed laptop.

Objective: Diagnose a failed application deployment.

Verification: The app either installs successfully after retry, or is escalated with a clear error code and diagnosis.

Practice Tip: Note the exact error/status code — it saves L2 significant time if escalation is needed.

LAB 54.  Fix a Device Not Showing Up in Intune After Enrollment

🎫 TICKET

User completed enrollment but IT can't find the device in the admin console.

Objective: Diagnose a check-in/sync delay or enrollment completion issue.

Verification: The device appears in the Intune device list, correctly associated with the user.

Practice Tip: A short delay between enrollment and console visibility is normal — don't panic immediately, but don't ignore it past a reasonable window either.

LAB 55.  Assist with a Windows Autopilot Self-Deploy Failure

🎫 TICKET

New laptop is stuck during the Autopilot out-of-box setup screen.

Objective: Provide basic first-line troubleshooting for an Autopilot deployment issue.

Verification: The device either completes Autopilot setup, or is escalated with full diagnostic detail.

Practice Tip: Always capture the device serial number and exact error code — Autopilot issues are hard to diagnose remotely without them.

LAB 56.  Resolve a Corporate Wi-Fi Profile Not Applying

🎫 TICKET

Managed laptop isn't automatically connecting to the corporate Wi-Fi network.

Objective: Diagnose a Wi-Fi configuration profile deployment issue.

Verification: The Wi-Fi profile successfully applies, and the device connects automatically.

Practice Tip: Check profile deployment status per-device before assuming a device-side issue — it may be a profile targeting problem instead.

LAB 57.  Investigate a BitLocker/Encryption Compliance Failure

🎫 TICKET

Device is marked non-compliant specifically due to disk encryption not being enabled.

Objective: Diagnose and help resolve a BitLocker compliance failure.

Verification: The device shows BitLocker enabled and compliance status updates to Compliant.

Practice Tip: Always confirm the recovery key escrows successfully — encryption without an escrowed key is a support risk if the user is ever locked out.

LAB 58.  Retire a Returned Corporate Device

🎫 TICKET

Employee returned their company laptop after resignation — needs to be retired from inventory.

Objective: Practice properly retiring a returned corporate device.

Verification: The device no longer shows as an active managed device and inventory records are updated.

Practice Tip: Always update the physical asset inventory too — Intune retirement alone doesn't track that the hardware itself was returned.

LAB 59.  Fix a Company Portal App Stuck Installing

🎫 TICKET

User's Company Portal app is stuck at 'Installing' on their mobile device for over an hour.

Objective: Troubleshoot a stuck mobile app installation.

Verification: The app completes installation successfully, or is escalated with complete diagnostic detail.

Practice Tip: Storage space is a surprisingly common cause of 'stuck' mobile installs — check it early.

LAB 60.  Investigate a Conditional Access Block Tied to Device Compliance

🎫 TICKET

User can access email on their phone but is blocked on their laptop with a compliance-related message.

Objective: Diagnose a Conditional Access block caused by device compliance status, and know when to escalate.

Verification: The block is either resolved via a compliance fix, or escalated with complete diagnostic detail.

Practice Tip: Compliance and Conditional Access are separate systems that work together — diagnosing which one is actually blocking access is the key L1 skill here.

CATEGORY 6  —  Security & Threat Protection

LAB 61.  Investigate and Release a Quarantined Message

🎫 TICKET

User says a legitimate vendor invoice went to quarantine.

Objective: Practice safely investigating and releasing (or escalating) a quarantined message.

Verification: The legitimate message is released, or the ticket is correctly escalated with reasoning.

Practice Tip: When a 'false positive' claim involves money or urgency, slow down — that's a classic phishing pattern.

LAB 62.  Investigate Spam and Apply a Block-List Entry

🎫 TICKET

User is getting flooded with spam from a specific domain.

Objective: Practice spam triage and an approved block-list update.

Verification: New messages from the blocked domain no longer reach the inbox.

Practice Tip: Confirm the sender isn't a real contact before blocking — over-blocking creates new tickets.

LAB 63.  Submit a Phishing Report and Confirm Tenant-Wide Protection

🎫 TICKET

User forwards a suspicious email claiming to be from IT asking for their password.

Objective: Practice the standard phishing-report submission workflow.

Verification: The phishing message is submitted for analysis, and its distribution scope is documented.

Practice Tip: Always check Threat Explorer for how many other mailboxes received the same message — a single report is often the tip of a larger campaign.

LAB 64.  Investigate an Executive Impersonation Alert

🎫 TICKET

Defender flags an email impersonating the CEO's display name sent to Finance.

Objective: Review and appropriately handle an impersonation-protection alert.

Verification: The impersonation attempt is confirmed contained, with any user interaction fully documented and escalated if needed.

Practice Tip: Impersonation alerts targeting Finance/Payroll are frequently the first sign of a Business Email Compromise attempt — treat with urgency.

LAB 65.  Review a Safe Links Click-Time Report

🎫 TICKET

User reports they clicked a link in an email that now seems suspicious.

Objective: Use Safe Links reporting to assess what happened when a link was clicked.

Verification: The click outcome is clearly determined, and appropriate next steps (reassurance or escalation) are taken.

Practice Tip: A 'blocked' verdict means Safe Links did its job — but always check the actual verdict rather than assuming based on the user's worry alone.

LAB 66.  Check a Safe Attachments Detonation Result

🎫 TICKET

User's email with a PDF attachment was delayed — they ask why.

Objective: Explain a Safe Attachments scanning delay and confirm its result.

Verification: The user receives an accurate explanation, and any genuinely malicious attachment is escalated rather than released.

Practice Tip: A short delivery delay for attachments is expected behavior, not a bug — knowing this prevents unnecessary escalations.

LAB 67.  Investigate a 'My Account Sent Spam' Complaint

🎫 TICKET

A colleague tells the user that they've been receiving spam-like emails from the user's own address.

Objective: Diagnose a possible account compromise indicated by outbound spam.

Verification: The account is confirmed either compromised (and escalated/secured) or spoofed (and explained), never left ambiguous.

Practice Tip: Spoofing (fake sender address) and compromise (real account misuse) look similar to the reporting user but require very different responses — the sign-in logs are what tell them apart.

LAB 68.  Review Anti-Spam Quarantine Notification Settings

🎫 TICKET

User complains they never get notified when something of theirs is quarantined.

Objective: Check and explain quarantine notification configuration for a user.

Verification: The user starts receiving quarantine notifications as expected.

Practice Tip: Distinguish between a tenant-wide policy setting (needs L2) and a personal notification preference (L1 can usually help directly).

LAB 69.  Assist with Attack Simulation Training Follow-Up

🎫 TICKET

A user failed a simulated phishing test and has been assigned follow-up training.

Objective: Support the attack simulation training remediation process.

Verification: The user can access and begins their assigned phishing-awareness training.

Practice Tip: Simulation failures are a training opportunity, not a disciplinary matter — the tone of your communication with the user matters.

LAB 70.  Check the Tenant Allow/Block List for a Wrongly Blocked Sender

🎫 TICKET

A legitimate newsletter the marketing team subscribed to is being blocked tenant-wide.

Objective: Investigate and correct an overly broad block-list entry.

Verification: Messages from the sender now deliver normally without being blocked.

Practice Tip: Before removing any block, check why it was added in the first place — it may have been blocked for a good reason that's still relevant.

LAB 71.  Investigate a 'Suspicious Sign-In' Alert Email with a User

🎫 TICKET

User receives a Microsoft security alert about a sign-in from an unfamiliar location and isn't sure if it's real.

Objective: Help a user assess and respond to a genuine security alert.

Verification: The sign-in is correctly classified as expected or suspicious, with appropriate action taken for either outcome.

Practice Tip: Teach users to check sign-in activity through the official admin/account portal rather than clicking links in the alert email itself — this also protects against alert-themed phishing.

LAB 72.  Review Secure Score Recommendations for L2 Handoff

🎫 TICKET

L2 asks you to pull this month's Secure Score report and flag any new recommendations.

Objective: Practice reviewing and summarizing Secure Score data for escalation.

Verification: L2 receives a clear, accurate summary of new Secure Score recommendations for their review.

Practice Tip: Your role here is reporting, not implementation — most Secure Score actions involve tenant-wide policy changes reserved for L2/L3.

CATEGORY 7  —  Compliance & Data Governance

LAB 73.  Run a Supervised Content Search

🎫 TICKET

HR needs to know if a former employee sent emails externally in their last week — assist under supervision.

Objective: Practice running a properly scoped, approved content search.

Verification: The search results match the approved scope exactly, with nothing broader searched.

Practice Tip: Never widen scope on your own judgment — stick exactly to what was approved.

LAB 74.  Explain a DLP Policy Tip to an End User

🎫 TICKET

User got a warning banner emailing a spreadsheet to a personal Gmail address.

Objective: Practice explaining a DLP trigger correctly without attempting to override it.

Verification: The user understands the policy trigger and either adjusts their approach or the case is escalated.

Practice Tip: Your job is to explain, not override — DLP policy changes always require L2 sign-off.

LAB 75.  Check Retention & Explain Recoverability

🎫 TICKET

User accidentally deleted an email from 3 months ago and wants it back.

Objective: Practice checking retention status and giving an accurate recoverability answer.

Verification: The user receives a clear, accurate, correctly sourced recoverability answer.

Practice Tip: Know the difference between what's retained and what L1 can actually restore.

LAB 76.  Verify a Sensitivity Label Is Applied Correctly

🎫 TICKET

Legal asks you to confirm a contract document has the 'Confidential' label properly applied.

Objective: Practice checking sensitivity label application and protection behavior.

Verification: The document shows the correct sensitivity label with its protections active.

Practice Tip: Applying a label and having its protections actually enforce correctly are two different things — verify both.

LAB 77.  Investigate a 'Can't Share Externally' Complaint

🎫 TICKET

User says they can no longer share a specific file with an external partner as they did last month.

Objective: Diagnose whether a DLP rule or a sharing policy change is the cause.

Verification: The actual blocking mechanism (DLP vs. sharing policy) is correctly identified and communicated or escalated.

Practice Tip: These two systems produce similar-looking 'can't share' symptoms but require completely different fixes — always identify which one first.

LAB 78.  Check the Audit Log for a Specific File-Access Investigation

🎫 TICKET

Manager asks whether a specific employee accessed a sensitive file last Tuesday.

Objective: Practice a guided, read-only audit log search for a legitimate investigation request.

Verification: An accurate, appropriately scoped answer is provided only to the approved requester.

Practice Tip: Audit findings about a specific employee are sensitive — never share results outside the approved request chain.

LAB 79.  Assist with a Data Subject Access Request (DSAR)

🎫 TICKET

Legal is processing a former employee's request for their personal data — needs a scoped mailbox search.

Objective: Support a DSAR under L2/legal supervision.

Verification: The search is completed exactly to the approved scope, with export handled by the appropriate authorized party.

Practice Tip: DSARs have strict legal timelines and confidentiality requirements — always follow legal's exact scope, never your own judgment.

LAB 80.  Verify Litigation Hold Status on a Mailbox

🎫 TICKET

Legal team asks you to confirm a specific mailbox is under litigation hold before an employee's planned offboarding.

Objective: Practice a read-only litigation hold status check.

Verification: Legal receives an accurate hold status, and no offboarding action is taken prematurely.

Practice Tip: A mailbox under litigation hold must not be altered or converted until legal explicitly clears it — this overrides normal offboarding steps.

LAB 81.  Review the Insider Risk Alert Dashboard

🎫 TICKET

L2 asks for a read-only summary of this week's insider risk alerts before a compliance meeting.

Objective: Practice reviewing insider risk alerts at a triage level.

Verification: L2 receives an accurate, appropriately high-level summary in time for the meeting.

Practice Tip: Insider risk case details are highly sensitive — your role is aggregate reporting, not individual case investigation.

LAB 82.  Review a Communication Compliance Flagged Message

🎫 TICKET

A message was flagged by a communication compliance policy for review — L2 asks you to confirm it reached the review queue correctly.

Objective: Practice a basic, read-only check of the communication compliance workflow.

Verification: L2 receives confirmation that the flagged item is correctly in the review queue.

Practice Tip: Confirming workflow mechanics is different from reviewing content — stay within the mechanical check unless you're an authorized reviewer.

CATEGORY 8  —  Identity Security, Monitoring & Advanced Administration

LAB 83.  Reset a User's MFA Method After a Device Change

🎫 TICKET

User got a new phone and isn't receiving MFA codes anymore.

Objective: Practice a verified MFA method reset and re-registration.

Verification: The user successfully signs in using their newly registered MFA method.

Practice Tip: Never skip identity verification for an MFA reset, even under time pressure.

LAB 84.  Diagnose a Conditional Access Block & Escalate

🎫 TICKET

User traveling abroad suddenly can't log in at all.

Objective: Practice diagnosing (without modifying) a Conditional Access-related block.

Verification: The ticket is escalated with complete diagnostic detail, ready for immediate L2 action.

Practice Tip: Your value here is diagnosis, not the fix — good documentation saves L2 significant time.

LAB 85.  Process a Privileged Role Request Correctly

🎫 TICKET

A team lead requests Helpdesk Administrator rights to assist with password resets.

Objective: Practice routing a privileged access request through proper approval.

Verification: The role request is fully documented and correctly routed — no direct L1 grant made.

Practice Tip: Even a 'small' admin role is still privileged access — always goes through the approval workflow.

LAB 86.  Triage Overnight Security Alerts

🎫 TICKET

The Defender dashboard shows 3 new medium-severity alerts overnight.

Objective: Practice first-pass alert triage using the incident-response checklist.

Verification: All 3 alerts are triaged and either explained-and-logged or escalated within SLA.

Practice Tip: 'Medium severity' doesn't mean 'not urgent' — triage promptly every time.

LAB 87.  Run a Pre-Approved Reporting Script Safely

🎫 TICKET

L2 asks for a report of mailboxes over 90% quota using a provided script.

Objective: Practice safely running a read-only PowerShell script provided by L2.

Verification: An accurate report is generated and delivered, with no write actions taken.

Practice Tip: If a script contains any New-/Set-/Remove- cmdlet, stop and confirm explicit sign-off first.

LAB 88.  Use an Existing Graph-Based Reporting Dashboard

🎫 TICKET

Pull this month's new-user count from the existing Graph-based dashboard for the ops report.

Objective: Practice using and sanity-checking a Graph-powered internal reporting tool.

Verification: The correct figure is reported, with source and sanity-check documented.

Practice Tip: Understanding what's behind the dashboard makes you far more useful when something looks off.

LAB 89.  Diagnose a Stale-Attribute Sync Issue

🎫 TICKET

User's phone number update in on-prem AD isn't reflecting in Outlook/Teams.

Objective: Practice checking Entra Connect sync health for a stale-attribute complaint.

Verification: A complete, well-documented escalation ticket is ready for L2, including sync health status.

Practice Tip: 'Probably a sync issue' isn't enough — always check and report actual sync health first.

LAB 90.  Investigate a GAL Visibility Issue Post-Migration

🎫 TICKET

User migrated to Exchange Online last week still can't be found in the Global Address List.

Objective: Practice a read-only hybrid mailbox/sync lookup before escalating.

Verification: A complete diagnostic handoff is ready for L2, with all read-only checks completed.

Practice Tip: Many GAL tickets are just normal propagation delay — check timestamps before assuming a break.

LAB 91.  Recover Missing Emails & Identify a Possible Migration Gap

🎫 TICKET

User says several emails from last week are completely missing, not even in Deleted Items.

Objective: Practice in-place recovery and correctly identifying when to escalate.

Verification: A complete, well-documented ticket is ready for L2 with all read-only checks completed.

Practice Tip: Always rule out the simple explanation before assuming something more serious like a migration gap.

LAB 92.  Investigate a Risky Sign-In Flagged by Identity Protection

🎫 TICKET

Entra ID Protection flags a 'risky sign-in' for a user overnight.

Objective: Practice a read-only triage of an Identity Protection risk detection.

Verification: The risky sign-in is either explained and logged, or escalated promptly with full detail.

Practice Tip: Never dismiss a risk flag purely because the user 'says it's fine' without at least a basic cross-check of details.

LAB 93.  Check a PIM Activation Request Status

🎫 TICKET

User says they requested a Privileged Identity Management role activation an hour ago and it's still pending.

Objective: Practice checking (read-only) a PIM activation request's status.

Verification: The activation request's exact status and blocker is identified, with appropriate follow-up taken.

Practice Tip: PIM approvals often stall simply because the approver hasn't acted yet — checking the workflow status avoids assuming a technical fault.

LAB 94.  Investigate a Self-Service Password Reset (SSPR) Failure

🎫 TICKET

User says the self-service password reset tool won't accept their registered phone number.

Objective: Diagnose a common SSPR configuration or registration issue.

Verification: The user either successfully completes SSPR, or understands why it isn't available and what the alternative is.

Practice Tip: A stale registered phone number is one of the most common causes of 'SSPR doesn't work' tickets.

LAB 95.  Review a Failed Multi-Factor Challenge in Sign-In Logs

🎫 TICKET

User says they keep getting an MFA prompt but it always fails, even though they enter the code correctly.

Objective: Diagnose a recurring MFA failure using sign-in log detail.

Verification: The user completes MFA successfully after the specific cause is corrected.

Practice Tip: Authenticator app time-sync drift is a frequently overlooked cause of 'my code never works' tickets.

LAB 96.  Check Service Health Before Escalating a Reported Outage

🎫 TICKET

Multiple users report they can't access Outlook on the web at the same time.

Objective: Practice checking Service Health first during a suspected widespread issue.

Verification: Affected users receive a consistent, accurate status update tied to the correct incident ID.

Practice Tip: Always check Service Health first for multi-user reports — it can turn 10 separate tickets into one tracked incident.

LAB 97.  Review a Message Center Post for an Upcoming Change

🎫 TICKET

L2 asks you to review this week's Message Center posts and flag anything affecting end users.

Objective: Practice proactive Message Center monitoring and impact assessment.

Verification: L2 receives a clear summary of upcoming changes relevant to end users, with dates noted.

Practice Tip: Catching a disruptive change in the Message Center before it happens prevents a wave of confused tickets after the fact.

LAB 98.  Assist with a Guest User Access Review

🎫 TICKET

An access review campaign is running for external guests on a sensitive Team, and a manager needs help completing it.

Objective: Support a scheduled Entra ID access review as an L1 facilitator.

Verification: All guest decisions are recorded accurately and submitted before the review deadline.

Practice Tip: Access reviews have hard deadlines — a late submission can result in default (often overly permissive) access decisions.

LAB 99.  Run a Basic Read-Only Graph PowerShell Query for a User Attribute

🎫 TICKET

L2 asks you to confirm a specific user's usage location attribute via Graph PowerShell as part of a licensing troubleshoot.

Objective: Practice a basic, safe, read-only Microsoft Graph PowerShell query.

Verification: The correct attribute value is confirmed and reported accurately to L2.

Practice Tip: Even simple read-only Graph queries are a great way to build comfort with the tool L2/L3 use for everything else — practice them whenever asked.

LAB 100.  Document and Escalate a Suspected Compromised Account

🎫 TICKET

Multiple signs point to a user's account being compromised: unusual sign-ins, a new forwarding rule, and sent-spam reports.

Objective: Practice the full documentation and escalation workflow for a suspected compromise — the most critical L1 judgment call.

Verification: The account is contained, evidence is fully documented, and L2/L3 has everything needed to continue the investigation without delay.

Practice Tip: This is the single most important escalation type in the entire lab set — speed and complete documentation matter more here than anywhere else.