Identity and Access Management (IAM) is one of the most critical parts of modern enterprise security. It is involved in every login and permission check an environment relies on. Building it yourself lets you see how permissions are enforced, and how mismanaging them can result in a compromise.

The goal is not to recreate a complex enterprise identity system. It's to work with real identities and see what happens when you put requirements around them. That's the foundation you need before the identity side of cybersecurity comes together.

Start With a Simple Identity Foundation

The first task is to build the lab. Start simple with two core components: a small local Active Directory environment and a Microsoft 365 Business Premium subscription. These two alone create the hybrid setup many companies run on, without real activity.

To do this, use a Windows Server evaluation ISO in VirtualBox as your domain controller and a Windows evaluation ISO as the test workstation, also in VirtualBox. Both of these can be downloaded for free from the Microsoft Evaluation Center. Once your VMs are set up, use Microsoft Entra Connect Sync (previously Azure AD Connect) to connect the on-premises server to Entra ID. This syncs up your on-premises accounts to Entra ID, so both identities work on your local network and in the cloud.

While many new and some older companies are set up in the cloud today, there are still a large number of established companies operating somewhere in this hybrid middle ground. Setting up your lab this way will prepare you for that hybrid reality, which is more complex than managing just cloud. If you're able to manage an on-premises or hybrid environment, a cloud-only one will feel quite familiar.

Users and Access

The Microsoft 365 Business Premium free trial has enough features to help with your IAM practice. You can create users and build Conditional Access (CA) policies that govern their access to resources.

User Lifecycle

Start with projects that put you through the full lifecycle of a test user, from creating the account, to assigning it to groups, to granting access to specific resources, and finally disabling or deleting it. This is the center of IAM. It may seem simple, but this is where you start.

Conditional Access

Build a CA policy that enforces Multifactor Authentication (MFA) for a particular group, then compare what happens when a user authenticates correctly versus when they don't. Another CA policy suggestion is to enforce location-based access. Once the policy is set up, use a VPN to sign in from a disallowed country and note what happens. For both of these, extend your analysis from the at-a-glance logs to the Activity Details pane, to see how the Conditional Access policy affected each attempt. This is how you learn to connect the dots confidently.

Keep the Lab Affordable

Everyone's budget is different, but your lab does not need expensive tools for IAM practice. VirtualBox can run your server and workstation VMs at no cost, and the Microsoft 365 Business Premium free trial handles identity, authentication, and policy fundamentals. Everything beyond that is optional.

Maintaining Your Lab Over Time

In live environments, IAM can grow stale when nothing changes; to keep your lab active, keep up with security news and think about how you would configure the environment to defend against what you're reading. Every few weeks, revisit your policies and add a new rule, remove one, or test a different access pattern. Break something on purpose and fix it to challenge yourself.

If you’re tracking your progress for a portfolio, keep short notes like what you changed, what broke, and what you discovered.

Over time, your lab will be less of an IAM foundation and more of a testing ground for the complex identity controls you design.