Agent Foskett Academy • Microsoft Entra Security

Microsoft Entra Security Academy.

Modern attacks rarely begin with malware.

They begin with identity: a risky sign-in, a stolen token, a weak policy, an over-privileged role or a user granting trust to something they should not.

Microsoft Entra sits at the centre of Microsoft security. It protects authentication, access, privilege, governance and the Zero Trust controls that decide who can access what.

The Agent Foskett Microsoft Entra Security Academy will teach identity security the practical way: one sign-in, one policy, one role and one investigation at a time.

Agent Foskett Microsoft Entra Security Academy learning path
Academy overview

Learn Microsoft Entra security from the ground up, covering identity protection, Conditional Access, authentication methods, privileged access, governance and real-world identity investigations.

Understand Microsoft Entra identity security
Design Conditional Access policies
Investigate risky users and sign-ins
Protect privileged access with PIM
🔎 Take your identity investigation skills into the SOC.
Continue into the new SOC Analyst Academy and use Microsoft Entra alongside KQL, Defender XDR, Sentinel and Security Copilot to investigate risky sign-ins, MFA abuse, privilege changes, suspicious sessions and compromised identities.
Open SOC Analyst Academy →

Microsoft Entra Security Academy roadmap

This new Academy series will build identity security knowledge progressively, from core Entra concepts through to Conditional Access, identity governance, privileged access and advanced identity investigations.
Module 1 — Entra FoundationsWhat Microsoft Entra is, how identity works, how tenants are structured and why identity is now the control plane for Microsoft security.
Module 2 — Authentication SecurityMFA, authentication methods, passwordless sign-in, FIDO2, Windows Hello for Business, Temporary Access Pass and authentication strengths.
Module 3 — Conditional AccessPolicy design, named locations, device compliance, session controls, report-only mode, exclusions and safe rollout strategy.
Module 4 — Identity ProtectionRisky users, risky sign-ins, user risk, sign-in risk, risk policies and investigation workflows for compromised identities.
Module 5 — Privileged AccessPrivileged Identity Management, eligible roles, active assignments, approval workflows, just-in-time administration and role activation evidence.
Module 6 — Identity GovernanceAccess reviews, entitlement management, lifecycle workflows, guest access governance and identity lifecycle controls.

Microsoft Entra Academy lessons

Begin with the foundations of Microsoft Entra, then continue into sign-in analysis, Conditional Access, authentication security, identity risk and privileged access.
📘 Module 1
Lesson 1 — What is Microsoft Entra? Learn how Microsoft Entra ID manages tenants, users, groups, devices, applications, roles, authentication and access across Microsoft 365 and Azure.
📘 Module 1
Lesson 2 — Understanding Sign-in Logs Learn how Microsoft Entra sign-in logs reveal authentication status, IP addresses, device context, Conditional Access decisions, authentication details and identity risk.
📘 Module 1
Lesson 3 — Conditional Access Fundamentals Learn how Microsoft Entra Conditional Access evaluates identities, applications, devices, locations and risk to enforce Zero Trust access decisions.
📘 Module 1
Lesson 4 — MFA and Authentication Methods Learn how Microsoft Entra uses Microsoft Authenticator, passkeys, FIDO2, Windows Hello for Business, Temporary Access Pass and authentication strengths to secure sign-ins.
📘 Module 1
Lesson 5 — Risky Users and Risky Sign-ins Learn how Microsoft Entra ID Protection identifies risky users, risky sign-ins, identity risk detections and suspected account compromise.
📘 Module 1
Lesson 6 — Privileged Identity Management Basics Learn how Microsoft Entra Privileged Identity Management (PIM) uses eligible assignments, just-in-time activation, approvals and auditing to reduce standing administrative privilege.
📘 Module 1
Lesson 7 — Microsoft Entra Roles and Administrative Units Learn how Microsoft Entra built-in roles, Administrative Units and least-privilege administration help securely delegate access across an organisation.
📘 Module 1
Lesson 8 — Identity Governance Fundamentals Learn how Microsoft Entra Identity Governance manages identity lifecycles, entitlement management, access reviews and least-privilege access across your organisation.
📘 Module 1
Lesson 9 — Entitlement Management and Access Packages Learn how Microsoft Entra Entitlement Management uses catalogues, access packages, approval workflows and assignment policies to automate secure access throughout the identity lifecycle.
📘 Module 1
Lesson 10 — Access Reviews in Microsoft Entra Learn how Microsoft Entra Access Reviews validate user, group, application and privileged role access using recurring reviews, recommendations and automated remediation.
📘 Module 1
Lesson 11 — Lifecycle Workflows in Microsoft Entra Learn how Microsoft Entra Lifecycle Workflows automate Joiner, Mover and Leaver processes using workflow triggers, tasks and identity lifecycle automation.
📘 Module 1
Lesson 12 — External Identities and B2B Guest Access Learn how Microsoft Entra External Identities enables secure B2B collaboration, guest access, cross-tenant trust and Conditional Access protection for external users.
📘 Module 1
Lesson 13 — Enterprise Applications in Microsoft Entra Learn how Microsoft Entra Enterprise Applications uses service principals, user assignments, permissions and Conditional Access to securely manage application access across your organisation.
📘 Module 2
Lesson 14 — App Registrations in Microsoft Entra Learn how Microsoft Entra App Registrations define application identities, authentication, API permissions, client secrets, certificates and secure application access across your organisation.
📘 Module 2
Lesson 15 — Authentication Methods Policies in Microsoft Entra Learn how Microsoft Entra Authentication Methods Policies manage Microsoft Authenticator, FIDO2 security keys, passkeys, Temporary Access Pass and passwordless authentication to strengthen identity security.
📘 Module 2
Lesson 16 — Authentication Strengths in Microsoft Entra Learn how Microsoft Entra Authentication Strengths work with Conditional Access to require multifactor, passwordless or phishing-resistant authentication methods for secure access.
📘 Module 2
Lesson 17 — Self-Service Password Reset in Microsoft Entra Learn how Microsoft Entra Self-Service Password Reset enables secure account recovery through registration, verification methods, password writeback and audit reporting.
📘 Module 2
Lesson 18 — Microsoft Entra Password Protection Learn how Microsoft Entra Password Protection blocks weak passwords using Microsoft's global intelligence, custom banned-password lists and hybrid Active Directory protection.
📘 Module 2
Lesson 19 — Smart Lockout in Microsoft Entra Learn how Microsoft Entra Smart Lockout detects password attacks, separates familiar and unfamiliar sign-in activity, and protects cloud and hybrid identities from brute-force attacks.
📘 Module 2
Lesson 20 — Microsoft Entra Identity Protection Policies Learn how Microsoft Entra Identity Protection uses user risk, sign-in risk and Conditional Access to detect compromised identities, require MFA and secure password remediation.
📘 Module 2
Lesson 21 — Microsoft Entra Sign-in Diagnostics Learn how Microsoft Entra Sign-in Diagnostics helps troubleshoot authentication failures, Conditional Access decisions, MFA prompts, device compliance and sign-in errors.
📘 Module 2
Lesson 22 — Microsoft Entra Diagnostic Settings Learn how Microsoft Entra Diagnostic Settings exports audit, sign-in and identity logs to Log Analytics, Microsoft Sentinel, Event Hubs and Azure Storage for monitoring and investigation.
📘 Module 2
Lesson 22 — Microsoft Entra Diagnostic Settings Learn how Microsoft Entra Diagnostic Settings exports audit, sign-in and identity logs to Log Analytics, Microsoft Sentinel, Event Hubs and Azure Storage for monitoring and investigation.
📘 Module 2
Lesson 24 — Microsoft Entra Workbooks Learn how Microsoft Entra Workbooks transforms identity telemetry into interactive dashboards using KQL, charts, parameters and built-in templates for monitoring and investigation.
📘 Module 2
Lesson 25 — Microsoft Entra Monitoring Alerts Learn how Microsoft Entra Monitoring Alerts uses Log Analytics, KQL, Azure Monitor and Action Groups to detect risky identity activity and proactively notify security teams.
📘 Module 2
Lesson 26 — Microsoft Entra Monitoring and Health Learn how Microsoft Entra Monitoring and Health provides visibility into tenant health, diagnostic settings, log ingestion, hybrid identity and operational monitoring across your identity platform.
📘 Module 2
Lesson 27 — Microsoft Entra Connect Health Learn how Microsoft Entra Connect Health monitors synchronisation services, health agents, password hash synchronisation, staging servers and hybrid identity to maintain reliable identity operations.
📘 Module 2
Lesson 28 — Microsoft Entra Cloud Sync Learn how Microsoft Entra Cloud Sync uses lightweight provisioning agents, cloud-managed synchronisation, agent pools and high availability to securely synchronise identities between on-premises Active Directory and Microsoft Entra ID.
📘 Module 2
Lesson 29 — Microsoft Entra Provisioning Logs Learn how Microsoft Entra Provisioning Logs record synchronisation activity, object matching, attribute changes, provisioning status and troubleshooting information for hybrid identity investigations.
📘 Module 2
Lesson 30 — Microsoft Entra Cloud Sync Troubleshooting Learn how to troubleshoot Microsoft Entra Cloud Sync using provisioning logs, agent health, connectivity checks, scope validation, object matching and quarantine recovery techniques.
📘 Module 2
Lesson 31 — Microsoft Entra Hybrid Identity Best Practices Learn the best practices for designing secure, resilient hybrid identity using Microsoft Entra ID, Active Directory, Cloud Sync, authentication methods, high availability and identity lifecycle management.
📘 Module 3
Lesson 32 — Microsoft Entra Identity Secure Score Learn how Microsoft Entra Identity Secure Score measures identity security posture, prioritises recommendations, tracks security improvements and helps strengthen your Microsoft Entra environment.
📘 Module 3
Lesson 33 — Microsoft Entra Recommendations Learn how Microsoft Entra Recommendations identify security, health and usage improvements, prioritise remediation, highlight affected resources and support secure identity operations.
📘 Module 3
Lesson 34 — Microsoft Entra Security Defaults Learn how Microsoft Entra Security Defaults provide baseline identity protection through MFA registration, administrator security, legacy authentication blocking and a secure foundation before Conditional Access.
📘 Module 3
Lesson 35 — Microsoft Entra Conditional Access Design Learn how to design Microsoft Entra Conditional Access policies using secure policy architecture, assignments, conditions, grant controls, report-only testing and operational governance.
📘 Module 3
Lesson 36 — Microsoft Entra Conditional Access Best Practices Learn Microsoft Entra Conditional Access best practices for policy architecture, minimising exclusions, protecting privileged identities, report-only testing, monitoring and long-term governance.
📘 Module 3
Lesson 37 — Microsoft Entra Named Locations and Trusted Networks Learn how Microsoft Entra Named Locations uses IP addresses, trusted networks and geographic locations within Conditional Access while applying Zero Trust principles to location-based access decisions.
📘 Module 3
Lesson 38 — Microsoft Entra Conditional Access Device Conditions Learn how Microsoft Entra Conditional Access evaluates device platforms, compliance, Microsoft Entra join state, device filters and managed devices to strengthen Zero Trust access decisions.
📘 Module 3
Lesson 39 — Microsoft Entra Conditional Access Grant Controls Learn how Microsoft Entra Conditional Access Grant Controls uses MFA, authentication strengths, compliant devices, approved client applications and app protection policies to enforce Zero Trust access decisions.
📘 Module 3
Lesson 40 — Microsoft Entra Conditional Access Session Controls Learn how Microsoft Entra Conditional Access Session Controls manages sign-in frequency, persistent browser sessions, application restrictions and Continuous Access Evaluation to strengthen Zero Trust access after authentication.

How Entra connects to the existing Academy

The KQL and Defender XDR Academy pages already teach how to investigate telemetry. Entra adds the identity control plane that explains who accessed what, from where, and under which policy decision.
IdentityLogonEventsUse Defender XDR identity telemetry to investigate logons, failures, locations, IP addresses and suspicious authentication patterns.
IdentityDirectoryEventsTrack directory changes, group membership, role activity and identity changes that may indicate privilege abuse.
Impossible TravelConnect Entra risk signals and Defender identity telemetry to investigate suspicious sign-in location changes.
OAuth AbuseUnderstand how malicious consent, service principals and delegated permissions can create persistent access.
Cloud Identity Attack WorkflowUse the existing incident response workflow as the bridge between Defender XDR, Entra ID and identity-led investigations.
SOC Analyst AcademyTake Entra identity evidence into realistic SOC triage and investigation workflows, correlating sign-ins, sessions, privilege, endpoint and cloud activity.

Entra skills this Academy will teach

The goal is not just to explain the portal. The goal is to teach identity security thinking.
Identity architectureUnderstand tenants, users, groups, enterprise applications, app registrations, roles and identity security boundaries.
Conditional Access designDesign policies that protect access without locking out administrators, service accounts or business-critical workflows.
Risk investigationInvestigate risky users, risky sign-ins, impossible travel, unfamiliar sign-in properties and suspicious authentication activity.
Privileged access controlUse PIM and role governance to reduce standing privilege and create traceable administrative activity.
Authentication hardeningImprove MFA, passwordless authentication, authentication strengths and secure registration processes.
Identity governanceManage access reviews, entitlement management, guest access and lifecycle workflows for joiners, movers and leavers.

Start with the foundations

The Academy now contains 40 published Entra lessons. New learners should begin with Lesson 1 and build from identity foundations into authentication, monitoring and Conditional Access.
Lesson 1 — What is Microsoft Entra?Agent Foskett will explain Microsoft Entra as the identity platform behind Microsoft 365 and Azure, showing how users, groups, roles, applications, authentication and Conditional Access all fit together.
Why this mattersThe KQL Academy taught students how to query security data. The Entra Academy will teach them how identity decisions are made, protected, investigated and governed.

Final thought

If attackers can control identity, they may not need malware at all.
Agent Foskett mindsetDo not treat identity as an admin task only. Identity is evidence, control, privilege, risk and access all in one place.
New Academy SeriesThe Microsoft Entra Security Academy expands Agent Foskett from KQL and XDR investigations into identity protection, Zero Trust and privileged access security.
Develop IT. Protect IT.GEMXIT PTY LTD | GEMXIT UK LTD

Microsoft Entra Security Academy by Agent Foskett

The Agent Foskett Microsoft Entra Security Academy teaches identity security, Conditional Access, Identity Protection, authentication methods, privileged access, governance and real-world Microsoft identity investigations.

Learn Microsoft Entra security for Microsoft 365 and Azure

This Entra learning path explains risky users, risky sign-ins, Conditional Access policies, MFA, passwordless authentication, PIM, access reviews, entitlement management and Zero Trust identity controls.

Microsoft Entra training for Defender XDR and Sentinel analysts

The Microsoft Entra Security Academy builds on the Agent Foskett KQL Academy by showing defenders how to investigate identity signals, authentication behaviour, privileged access and suspicious cloud identity activity.