Enterprise Foundation
Microsoft 365 tenant, Entra ID, Intune, SharePoint and Azure security services
Enterprise Security Lab
Brunner Security Labs is a practical cybersecurity project demonstrating how a modern enterprise environment can be designed, protected, monitored and continuously improved.
Mission
The lab simulates the security environment of a small or medium-sized enterprise. It combines cloud identity, managed endpoints, security monitoring, governance and incident response into one integrated security program.
Enterprise Security Architecture
The lab follows a vendor-neutral security architecture in which identity, endpoint protection, monitoring, incident response and governance work together as an integrated security system.
Authentication, authorization and controlled access to enterprise resources.
Centralized device management, configuration and compliance assessment.
Protection, detection and response capabilities for enterprise endpoints.
Centralized collection and analysis of security events and telemetry.
Investigation, containment, recovery and evidence-based analysis.
Policies, risk management, compliance and continuous security improvement.
Core Security Domains
The lab organizes its security architecture around four core domains that work together to protect identities, devices, data and business operations.
Secure authentication, authorization, privileged access and identity governance across the enterprise.
Explore this domain
Managed endpoints, security baselines, encryption, compliance and endpoint detection and response.
Explore this domain
Centralized logging, SIEM, threat detection, investigation, threat hunting and incident response.
Explore this domain
Security policies, risk management, regulatory requirements and continuous security improvement.
Explore this domain
Implementation Roadmap
The roadmap shows which parts of the enterprise security architecture have already been implemented and which areas are currently being expanded.
Microsoft 365 tenant, Entra ID, Intune, SharePoint and Azure security services
Identity lifecycle, authentication, authorization and privileged access management
Device management, compliance, encryption and endpoint protection
Microsoft Sentinel, Defender telemetry, KQL analytics and detection engineering
Microsoft Purview, information protection, compliance assessments, auditing and Secure Score
Incident handling, investigation, evidence collection and forensic analysis