WWL Tenants - Terms of use
If you are being provided with a tenant as part of an instructor-led training delivery, please note that the tenant is made available for the purpose of supporting the hands-on labs in the instructor-led training.
Tenants should not be shared or used for purposes outside of hands-on labs. The tenant used in this course is a trial tenant and cannot be used or accessed after the class is over and is not eligible for extension.
Tenants must not be converted to a paid subscription. Tenants obtained as part of this course remain the property of Microsoft Corporation and we reserve the right to obtain access and repossess at any time.
Lab setup - Prepare your environment for administration
In this lab, you’ll configure and prepare your environment for administration tasks. You’ll enable required features, configure permissions, and prepare core services for administration.
Tasks:
- Enable Audit in the Microsoft Purview portal
- Enable device onboarding
- Enable insider risk analytics and data sharing
- Set user passwords for lab exercises
- Initialize Microsoft Defender XDR
Estimated time: 30-45 minutes
Task 1 - Enable Audit in the Microsoft Purview portal
In this task, you’ll enable Audit in the Microsoft Purview portal to monitor portal activities.
-
Log into Client 1 VM (SC-401-CL1) with the Admin account.
-
Open Microsoft Edge.
-
In Microsoft Edge, navigate to
https://purview.microsoft.comand sign in as MOD Administrator,admin@WWLxZZZZZZ.onmicrosoft.com(where ZZZZZZ is your unique tenant prefix provided by your lab hosting provider). Admin’s password should be provided by your lab hosting provider. -
A message about the new Microsoft Purview portal will appear on the screen. Select Get started to access the new portal.

-
Select Solutions from the left sidebar, then select Audit.
-
On the Search page, select the Start recording user and admin activity bar to enable audit logging.

-
Once you select this option, the blue bar should disappear from this page.
Note: If the Audit button doesn’t enable logging
In some tenants, selecting Start recording user and admin activity might not activate Audit. If this happens, you can enable Audit through PowerShell instead:
1. Open an elevated Terminal window by right-clicking the Windows button and selecting Terminal (Admin).
2. Install the latest Exchange Online PowerShell module:Install-Module ExchangeOnlineManagement— Confirm any prompts by typing Y for Yes and pressing Enter.
3. Run the following command to change your execution policy:Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser
4. Close the elevated Terminal window and open a regular PowerShell session.
5. Connect to Exchange Online:Connect-ExchangeOnline— Sign in asadmin@WWLxZZZZZZ.onmicrosoft.com(where ZZZZZZ is your unique tenant prefix provided by your lab hosting provider). Admin’s password should be provided by your lab hosting provider.
6. Check if Audit is enabled:Get-AdminAuditLogConfig | FL UnifiedAuditLogIngestionEnabled— If it returns False, enable Audit:Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true
7. Verify that it’s now enabled:Get-AdminAuditLogConfig | FL UnifiedAuditLogIngestionEnabled— The command should return True once Audit is active.
You have successfully enabled auditing in Microsoft 365.
Task 2 – Enable device onboarding
In this task, you’ll enable device onboarding for your organization.
-
You should still be logged into Client 1 VM (SC-401-CL1) as the SC-401-CL1\admin account and logged in as the MOD Administrator in Microsoft Purview.
-
Select Settings from the left sidebar, then expand Device onboarding.
-
On the Device onboarding page, select Devices.
-
On the Devices page, select Turn on device onboarding, then select Ok to confirm.
-
When prompted, select OK to confirm that device monitoring is being turned on.
You have now enabled device onboarding and can start to onboard devices to be protected with Endpoint DLP policies. The process of enabling the feature might take up to 30 minutes.
Task 3 – Enable insider risk analytics and data sharing
In this task, you’ll enable analytics and data sharing for Insider Risk Management.
-
You should still be logged into Client 1 VM (SC-401-CL1) as the SC-401-CL1\admin account and logged in as the MOD Administrator in Microsoft Purview.
-
In Microsoft Purview, navigate to Settings > Insider Risk Management > Analytics.
-
Toggle these settings to On:
-
Show insights at tenant level
-
Show insights at user level
-
-
Select Save at the bottom of the page.
-
Select Data sharing on the left navigation pane.
-
In the Data sharing section, toggle Share user risk details with other security solutions to On.
-
Select Save at the bottom of the page.
You have enabled analytics and data sharing for Insider Risk Management.
Task 4 - Set user passwords for lab exercises
In this task, you’ll set passwords for the user accounts needed for the labs.
-
You should still be logged into Client 1 VM (SC-401-CL1) as the SC-401-CL1\admin account and logged in as the MOD Administrator in Microsoft 365.
-
Open Microsoft Edge and navigate to
https://admin.microsoft.comto log into the Microsoft 365 admin center as the MOD Administrator,admin@WWLxZZZZZZ.onmicrosoft.com(where ZZZZZZ is your unique tenant prefix provided by your lab hosting provider). Admin’s password should be provided by your lab hosting provider. -
In the prompt to set up multifactor authentication, select Set up now.
-
On the Let’s keep your account secure page, select Next.
-
On the Install Microsoft Authenticator page, ensure the Microsoft Authenticator app is installed on your mobile device, then select Next.
Note: Using a different authenticator app
If you choose to use a different authenticator app from the Microsoft Authenticator, select Set up a different authentication app. -
On the Set up your account in app page, select Next.
-
On the Scan the QR code page, use the multifactor authentication app on your mobile device to scan the QR code, then select Next.
-
On the Let’s try it out page, enter the number on the screen in Microsoft Authenticator to add the authenticator.
Note: Using a different authenticator app
If you’re using a different authenticator app, adding the authenticator might be a different process. Follow the steps provided to ensure your authenticator is registered successfully. -
On the Authenticator Added page, select Ok to get signed into the Microsoft 365 admin center.
-
On the left navigation pane, expand Users then select Active users.
-
Select the checkbox to the left of Joni Sherman, Lynne Robbins, and Megan Bowen.
These accounts will be used throughout the lab exercises.

-
Select the Reset password button from the top navigation to reset all three passwords.

-
In the Reset Password flyout page on the right, ensure that both checkboxes are deselected.
This will ensure that you can select a password for the three users being used for exercises, and that these passwords won’t need to be reset when you first sign in.
-
In the Password field, enter a password you can remember to reset the user passwords to be used in future exercises.
-
At the bottom of the Reset password flyout page, select the Reset password button.
-
On the Passwords have been reset page, you should see the three user accounts that have been reset. At the bottom of this flyout page, select Close.
You have successfully reset passwords for lab exercises.
Task 5 – Initialize Microsoft Defender XDR
In this task, you’ll go to Microsoft Defender and wait for Microsoft Defender XDR to initialize.
-
You should still be logged into Client 1 VM (SC-401-CL1) as the SC-401-CL1\admin account and logged in as the MOD Administrator in Microsoft Purview.
-
In Microsoft Edge, navigate to
https://security.microsoft.com/to open Microsoft Defender. -
From the navigation pane, select Show navigation, then select Incidents.
Note: Microsoft Defender XDR initialization
The navigation might appear differently depending on whether Microsoft Defender XDR is already initialized. If initialization has completed, Incidents & alerts appears as a top-level option instead of under Investigation & response. -
You’ll see a message stating that Microsoft Defender XDR is being prepared. This process runs automatically and might take a few minutes.

Microsoft Defender XDR is being initialized. You can continue with other tasks while it finishes setting up.