Release 1: Hybrid Workplace and Microsoft 365¶
Status: Implemented and evidenced
Release 1 is implemented and evidenced through screenshots, configuration captures, policy evidence, PowerShell output, recovery operation records, and public-safe documentation in screenshots/ and docs/release1/.
Release 1 establishes the realistic Microsoft hybrid enterprise environment: on-premises Active Directory, Exchange Hybrid, Microsoft 365 services, endpoint management, information protection, operational visibility, recovery workflows, and script-based administration.
Architecture overview¶
flowchart TD
subgraph OnPrem["On-premises Hyper-V"]
AD["Active Directory<br>Domain Services"]
DNS["DNS"]
EX["Exchange 2019<br>Hybrid"]
end
subgraph Cloud["Microsoft 365 and Azure"]
EConnect["Entra Connect Sync"]
EXOnline["Exchange Online"]
CloudServices["Teams and SharePoint"]
Intune["Intune and Autopilot"]
Purview["Microsoft Purview"]
Sentinel["Microsoft Sentinel"]
end
AD --> DNS
AD --> EConnect
EConnect --> Intune
EConnect --> EXOnline
EX --> EXOnline
EConnect --> CloudServices
Intune --> Autopilot["Windows Autopilot"]
Purview --> DLP["Data Loss Prevention"]
Purview --> Labels["Sensitivity Labels"]
Sentinel --> Alerts["Security Alerts"]
Delivered capabilities¶
- Hybrid identity - Entra Connect synchronisation, pilot identity scope, Conditional Access, MFA, and identity operations.
- Exchange Hybrid and Microsoft 365 services - hybrid mail flow, pilot mailbox migration, Teams, SharePoint, and Microsoft 365 service operations.
- Modern endpoint management - Intune enrollment, Autopilot provisioning, compliance policies, BitLocker encryption, Windows LAPS, and Defender controls.
- Information protection - Microsoft Purview, data loss prevention, sensitivity labels, and user-visible policy behaviour.
- Operational recovery - BitLocker recovery, stale device cleanup, trust-break handling, rebuild, and re-enrollment evidence.
- Operational visibility - sign-in and audit log review, device compliance tracking, policy and control review, and practical admin alerting.
- Script-based operations - Microsoft Microsoft Graph PowerShell for Graph connection validation, pilot user state, managed device state, and device lifecycle operations.
- Security operations evidence - Sentinel, Defender for Cloud context, alert visibility, audit records, and security operations proof.
Capability matrix¶
| Capability | Implementation | Evidence route |
|---|---|---|
| Hybrid identity | Entra Connect, Conditional Access, MFA, pilot identity scope, and identity operations | screenshots/, Release 1 identity evidence |
| Conditional Access and MFA | MFA, compliant-device context, legacy-auth controls, and sign-in result review | Conditional Access and sign-in evidence under Release 1 screenshots |
| Exchange Hybrid and Microsoft 365 | Hybrid mail flow, pilot mailbox migration, Teams, SharePoint, and Microsoft 365 service operations | screenshots/release1/modern-workplace/exchange-hybrid/ |
| Endpoint management | Intune enrollment, Autopilot, compliance policies, BitLocker, Windows LAPS, and Defender controls | Release 1 endpoint-management evidence |
| Information protection | Microsoft Purview, sensitivity labels, DLP, and policy behaviour | Release 1 information-protection evidence |
| Operational recovery | BitLocker recovery, stale or duplicate device cleanup, trust-break handling, rebuild, and re-enrollment | Release 1 recovery evidence |
| Operational visibility | Sign-in review, audit-log review, device compliance checks, policy review, and alert review | screenshots/release1/monitoring-and-operations/monitoring/ |
| Microsoft Graph PowerShell | Connect-BelfastMgGraph, Get-BelfastPilotUserState, Get-BelfastManagedDeviceState, and Rename-BelfastManagedDevice evidence | screenshots/release1/identity-and-access/identity-operations/graph-powershell/ |
| Security operations | Sentinel, Defender for Cloud context, alert visibility, audit records, and operational review evidence | Release 1 security and monitoring evidence |
Evidence hub¶
Release 1 evidence is organised across the public repository by operating area:
- Identity and access - Entra Connect, Conditional Access, MFA, sign-in evidence, and Graph/PowerShell operations.
- Exchange Hybrid and Microsoft 365 services - Exchange Hybrid configuration, pilot mailbox migration, mail flow validation, Teams, SharePoint, and Microsoft 365 service evidence.
- Endpoint management - Intune configuration, Autopilot deployment, compliance policy evidence, BitLocker, Windows LAPS, and Defender controls.
- Information protection - Microsoft Purview, sensitivity labels, DLP, and policy evidence.
- Monitoring and operations - sign-in review, audit-log review, device compliance checks, policy review, practical alerting, and operational visibility.
- Recovery operations - BitLocker recovery, device cleanup, trust-break handling, rebuild, and re-enrollment records.
- Documentation - Release 1 public documentation under
docs/release1/.
Engineering deep dives¶
- Hybrid Identity Engineering
- Exchange Hybrid and Microsoft 365 Services
- Modern Endpoint Management
- Microsoft Graph PowerShell Operations
- Monitoring and Operational Visibility
Skills demonstrated¶
- Microsoft 365 tenant administration and hybrid identity architecture.
- Exchange Hybrid design and mailbox migration.
- Endpoint security engineering with zero-trust principles.
- Data governance and information protection implementation.
- Security operations workflow design and validation.
- Operational visibility and review discipline.
- Automation with Microsoft Microsoft Graph PowerShell.
- Evidence-led documentation and reviewer-facing presentation.