Build a small M365 + Intune home lab to practise admin skills
You can read about Intune all week, but things only really make sense once you've enrolled a device yourself, watched a policy not apply, and worked out why. Practising on your employer's tenant is a bad idea, and so is practising on your daily laptop. You need a small lab you're allowed to break.
This is the setup I'd suggest to anyone who wants hands-on M365 and Intune admin practice. It fits on one decent laptop or desktop, costs little or nothing beyond the hardware you already own, and stays well away from production.
Quick version (TL;DR):
- Get a tenant you control. That might be a developer sandbox (if you're eligible), a product trial, or a small paid subscription. Check current Microsoft terms first. Don't assume anything is free.
- Run two or three VMs on Hyper-V or VirtualBox: one or two Windows 11 clients and an optional Windows Server for AD practice.
- Create fake users and groups with an obvious naming scheme, plus one break-glass admin.
- Practise the basics first: users, groups, licences, enrolment, one compliance policy, one config profile, one app.
- Keep lab and production apart: separate browser profile, separate accounts, separate passwords, no real data.
- Put cost reminders on your calendar for every trial end date.
1. Getting a tenant: options, and why you should check eligibility first
The biggest misconception in home lab threads is "just grab a free E5 developer tenant." That used to be easy. Today, the Microsoft 365 Developer Program sandbox is only available to members who meet specific qualification paths (for example, certain Visual Studio subscriptions or partner programs), and the rules have changed several times. Read the current Developer Program FAQ and eligibility pages yourself before you plan around it.
Your realistic options, roughly:
| Option | Good for | Watch out for |
|---|---|---|
| Microsoft 365 Developer Program sandbox | Full E5-style feature set, if you qualify | Eligibility is restricted and changes. Check current terms. Windows licences aren't included |
| Product trials (for example Microsoft 365 Business Premium, Intune, or Entra ID P1/P2 trials) | Time-boxed practice on a specific feature set | Limited length. Some trials ask for a payment method and can convert to paid unless you cancel. Read the terms on the signup page |
| Small paid subscription (one or two user licences) | A lab that lasts past 30 days | It's a real monthly cost. Pick the cheapest SKU that includes what you want to practise (Intune + Entra ID P1 covers most of this article) |
| Your employer's test tenant | Realistic config | Only with written permission, and only if it's genuinely a test tenant |
Whichever you pick:
-
Sign up with a new identity (a fresh
*.onmicrosoft.comadmin), not your work account. - Write the trial end date down the day you start, and set a reminder a few days before it.
-
Don't add your real custom domain to the lab. The default
onmicrosoft.comdomain is fine for practice.
Licensing matters for what you can practise. Dynamic groups and Conditional Access need Entra ID P1 (or a bundle that includes it), and devices only enrol into Intune when the user has an Intune licence. If a feature is missing, check licensing before you assume you've misconfigured something.
2. Hypervisor and VM layout
Hypervisor:
- Hyper-V is built into Windows 10/11 Pro, Enterprise, and Education (not Home). It supports Gen 2 VMs with Secure Boot and a virtual TPM, which Windows 11 expects.
- VirtualBox works on Windows Home, macOS (Intel), and Linux. Recent versions support virtual TPM 2.0 and Secure Boot for Windows 11 guests. Check the docs for your version.
RAM is usually the limit. 16 GB on the host is a comfortable minimum for a client and a server running at the same time. With 8 GB, run one VM at a time.
A layout that works:
| VM | OS | vCPU / RAM / disk | Purpose |
|---|---|---|---|
lab-w11-01 |
Windows 11 Enterprise or Pro | 2 / 4 GB / 64 GB+ (dynamic) | Main Intune client: Entra join + enrol |
lab-w11-02 (optional)
|
Windows 11 | 2 / 4 GB / 64 GB+ | A second client so you can compare "pilot" vs "everyone" groups |
lab-dc01 (optional)
|
Windows Server (evaluation) | 2 / 2–4 GB / 60 GB | On-prem AD, DNS, GPO practice, and later hybrid identity if you want it |
Notes:
- Use legal media. The Microsoft Evaluation Center offers time-limited evaluation editions of Windows Server and Windows Enterprise. Evaluation periods end, so plan to rebuild (good practice anyway).
- Windows Home can't enrol into Intune as a managed corporate device. Use Pro, Enterprise, or Education in your client VMs.
- Network: use NAT or a host-only/internal switch for VM-to-VM traffic, plus outbound internet so the clients can reach Microsoft 365. Don't port-forward RDP to the internet "for convenience".
-
Naming: prefix everything with
lab-(VMs, users, groups, policies). When you're looking at a screenshot later, you'll know immediately it's the lab.
Checkpoints / snapshots: use them, but know the catch
Take a checkpoint before enrolling a client (20261006-clean-w11-pre-enrol). Reverting a VM to a point before it enrolled is clean.
Reverting an already-enrolled VM to an older checkpoint is messier. The cloud still remembers the newer state, so you'll often see duplicate or stale device records in the admin center. That isn't broken, it's just what happens. Clean up stale records in your lab tenant and re-enrol. It's a good lesson in why device naming and record hygiene matter.
3. Test users and groups
Create a small, fictional org. Five to ten users is enough:
| Account | Role in the lab |
|---|---|
lab-admin-breakglass@<tenant>.onmicrosoft.com |
Emergency Global Admin. Long random password in your password manager. Exclude it from any Conditional Access you test |
lab-admin-daily@… |
Your day-to-day admin. Practise using a lower role (for example Intune Administrator) instead of Global Admin |
lab-helpdesk1@… |
Practise scoped/limited admin roles |
lab-user-pilot1, lab-user-pilot2
|
Pilot group members |
lab-user-std1 … lab-user-std4
|
"Everyone else" |
Groups to start with:
-
lab-sg-pilot-users(assigned): your first ring for every new policy -
lab-sg-all-users(assigned, or dynamic if you have P1) -
lab-sg-devices-pilot(device group): practise the user-vs-device assignment difference -
lab-sg-lic-intune(if your tenant supports group-based licensing): assign licences by group, not by hand
Rule: every user in the lab is fake. Don't import real names, real phone numbers, or a CSV from work.
4. What to practise first (in this order)
Resist the urge to start with the scariest feature. Build up:
- Users, groups, licences. Create users, assign licences through a group, and check a user actually received Intune. Most "my device won't enrol" problems in a lab are licensing.
- Enrol one Windows 11 VM. Entra-join it during OOBE or from Settings → Accounts → Access work or school. Find it in the Intune admin center. Note how long it takes to appear.
- One compliance policy, assigned to the pilot group. Keep it simple (for example require a minimum OS version). Watch the device go from "Not evaluated" to a real state.
- One configuration profile from the settings catalog. Pick something visible, like a desktop or lock-screen setting or a Start menu tweak, so you can confirm it applied without a log viewer.
- One app. Deploy a Microsoft Store app to the pilot group as Available, then Required. See the difference from the user's side.
- Read the logs. Entra sign-in logs, audit logs, and the device's Intune status pages. Learning to read "why didn't this apply?" is the actual job.
-
Roles. Sign in as
lab-helpdesk1and see what they can and can't do. Practise least privilege on purpose.
Once those feel boring, move on to harder topics (Conditional Access in report-only, update rings, Win32 apps, Autopilot). There are plenty of write-ups on each of those, so I won't repeat them here.
Journal everything. A two-line note per session ("Goal / what broke / what fixed it") becomes your interview story bank later:
## 2026-10-06
Goal: enrol lab-w11-01, apply first compliance policy
Broke: device enrolled but stayed "Not evaluated" for 40 min
Fix/lesson: policy was assigned to a user group, I was checking a device group. Read the assignment tab first.
5. Keeping lab and production completely separate
This is the part people skip, and it's the one that actually causes incidents.
- Separate browser profile (or a separate browser) for the lab tenant. Never have lab and work admin portals open in the same profile. It's very easy to click "Assign" in the wrong tenant.
-
Different names and colours. Give the lab browser profile a loud theme and name it
LAB. Check the tenant name in the top-right of the portal before every change. -
Separate accounts and passwords. Don't reuse your work password or MFA method name. Lab admin passwords go in your password manager under a
LABfolder. - Don't enrol your daily driver or your work laptop into the lab tenant. Lab policies belong on lab VMs.
- Don't connect the lab to production. No syncing your work AD, no trust relationships, no guest-inviting your work account into the lab "just to test."
- No real data. No exported user lists, no real mailboxes, no screenshots of production pasted into lab notes.
- Employer tenant = written permission, every time, even if it's called "test."
6. Cost awareness
- Trials: put the end date in your calendar the day you sign up. If the trial asked for a payment method, check whether it auto-converts and cancel in time if you don't want to pay.
- Paid licences: one or two licences is enough. Remove spare licences you added "just to try."
- Cloud VMs (if you use Azure instead of local VMs): set a budget alert, enable auto-shutdown, and delete resource groups you're done with. Unattached disks and public IPs still cost money after you stop a VM.
- Local costs: disk space for checkpoints adds up quickly. Keep three or four per VM and delete old ones monthly.
- Evaluation media: time-limited. Rebuilding is free; extending past the terms isn't something to rely on.
7. A one-month plan
- Week 1: hypervisor + network, first Windows 11 VM, tenant signup, fake users and groups, journal started.
- Week 2: enrolment, compliance policy, settings catalog profile, one app. Break each one on purpose and fix it.
-
Week 3: roles and least privilege, sign-in and audit logs, optional
lab-dc01with a few OUs and GPOs. - Week 4: tear down and rebuild one VM from scratch in an evening. Write up three incidents from your journal as interview stories.
8. Want the lab plan in a ready-made pack?
The Home Lab Starter Pack for Aspiring Admins from Admin Pack Studio ($19) is the planning and practice side of this post in a set of Markdown playbooks: a lab map with budget tiers and network isolation, a domain controller + member build order with an OU sketch, snapshot naming and a lab journal template, practice ticket drills (seven AD/Windows drills plus four cloud-optional ones for a practice tenant) with a simple self-scoring table, and a 30-day study path geared towards interviews. It also includes a small read-only PowerShell script that records your host's RAM, free disk, and Hyper-V status to a CSV so you can size the lab. It doesn't include ISOs or licences, and it's mostly focused on the VM/AD side, with the cloud practice kept optional.
👉 https://cashflow4375.gumroad.com/l/ivqwrn
Moving on to the Intune side? The Intune & M365 Admin Starter Pack ($19 launch price, normally $29) has enrolment/compliance checklists and read-only snapshot scripts you can run against your lab tenant: https://cashflow4375.gumroad.com/l/joonf
Admin Pack Studio. Not affiliated with Microsoft. Microsoft 365, Intune, Entra ID, Hyper-V, and Windows are Microsoft products. Program eligibility, trial terms, licensing, and portal menus change, so check current Microsoft documentation before you sign up for anything. Use only tenants and devices you're authorised to manage. Examples use placeholder names.
Top comments (0)