Applies to: the current cohort (September 20 – October 4, 2026), which
runs entirely on per-student pod member servers
(PODXX-SRV). The three shared-DC waivers are retired — IA M2-L1's
stored-credential step, IA M3-L2's password policy and MP's media mounting are
now performed by the student and graded for real. The historical cohort-1
behaviour is kept at the bottom of each section for context.
On the shared domain controller (cohort 1, August 2026) students were
deliberately not administrators of the host, so three lab steps were credited
rather than performed. On their own member server the student is a local
administrator of that one machine, so all 57 labs are now hands-on.
On PODXX-SRV the student is a local administrator of that server, so tools open
the normal way and elevation prompts are theirs to approve:
| Tool | Launch |
|---|---|
| ADUC | Desktop shortcut Active Directory Users and Computers, or Windows + R → dsa.msc |
| Group Policy Management | Windows + R → gpmc.msc |
| Task Scheduler | Windows + R → taskschd.msc |
| Local Security Policy | Windows + R → secpol.msc |
| PowerShell | Start → Windows PowerShell (elevated also works) |
Local administrator on the member server grants no domain privilege: ADUC
binds to DC01-P01/DC02-P01 and the student's directory rights are still scoped to
their own OU=PodXX. Students no longer sign in to the domain controllers at
all.
Cohort 1 only: ADUC had to be launched unelevated with
cmd /c "set __COMPAT_LAYER=RunAsInvoker&& start "" mmc.exe dsa.msc", because
anything elevating produced "Logon failure: the user has not been granted the
requested logon type at this computer". That workaround is unnecessary on a
member server.
| Item | State |
|---|---|
Step 1 — create PXX-svc_backup |
Graded |
Step 2 — repoint PodXX ACS Nightly Backup at the service account |
Graded |
| Verifier | ia_m2l1_task_step_waived: false in member-server mode |
Storing a scheduled-task credential requires SeTcbPrivilege, i.e. local
administrator — which the student now holds on their own session host, so the
step is real work. The verifier reads the task from the session host's
HostState\host-state.json, refreshed on every evidence pull
(playbooks/sync-pod-evidence.yml); a snapshot older than 24 hours is reported
as stale rather than guessed at. Students who need it are told how to grant the
batch logon right in the IA guide.
Cohort 1: the step was credited (ia_m2l1_task_step_waived: true) because the
privilege is unavailable on a shared DC, tested with password, S4U and
interactive logon types. Separately, the task's security descriptor originally
excluded student accounts so the task looked missing in Task Scheduler and
Get-ScheduledTask; that was fixed on all 20 pods.
In member-server mode the lab is graded against the local account policy of the
student's own server, which they are free to change:
| Setting | Required value |
|---|---|
| Minimum password length | 12 |
| Complexity (upper, lower, number, symbol) | Enabled |
| Lockout threshold | 10 attempts or fewer |
| Password history | 24 |
| Maximum age | 90 days |
The shared acs-p01.local Default Domain Password Policy remains hardened to the
same values centrally, so Set-ADDefaultDomainPasswordPolicy and domain GPO
edits are still denied by design — the student changes their own server's policy
via secpol.msc, not the domain's.
Knock-on effect (unchanged): every lab that sets a password — AC L2.1, IA
M1-L2, IA M2-L1's service account and IA M3-L3 — must use 12+ characters with
upper case, lower case, a number and a symbol. A student's own sign-in password
predates the policy and is shorter, so reusing it when creating an account gives
"The password does not meet the password policy requirements". That rejection
is the policy working, not a fault; the guides and quick starts print a compliant
example.
Mounting a VHDX requires SeManageVolumePrivilege, which the student holds on
their own server, so the media is really mounted and inspected
(mp_media_mount_waived: false in member-server mode) and MP runs on the session
host.
The published contents listings remain in C:\CyberLab\PodXX\MP-Artifacts\ as a
fallback and reference:
PXX-FCI-USB-Contents.txtPXX-Employee-Handbook-Contents.txtThe classification worksheet, sanitization log and certificate are graded as
before.
Cohort 1: both hands-on steps were credited because granting those privileges
on a shared domain controller is an administrator escalation path.
The PODXX-GW Guacamole tiles were created with protocol http, which guacd
does not implement (Support for protocol "http" is not installed), so clicking
one failed and the tile's autoretry looped. All 20 tiles are hidden from
students — the connection objects still exist for administrators, so restoring
them is a single permission statement.
The supported path is a browser inside the student's own desktop:
http://10.51.XX.1 (Pod 06 → http://10.51.6.1).This required routing work — the pod hosts are on 10.50.x while the pfSense
LANs are on 10.51.x. See Network & Firewall for the
per-pod route/SNAT service. PODXX-GW remains the firewall's name in diagrams;
it is simply not a clickable connection.
Each student receives exactly one connection, PODXX-SRV, pointing at their
own member server (10.50.XX.20) and granted only to the matching studentXX.
The 20 PODXX-WS01 connections were deleted in June 2026 and the 20 PODXX-GW
tiles are hidden, so all guides and handouts list PODXX-SRV only.
Two leftovers from the shared-DC era: student07 and student11 still carry
their legacy POD07-DC / POD11-DC tiles. They are not part of any guide and
are listed in the Backlog.
Both messages were unreadable and M3-L1 was also wrong.
M3-L1 compared rules across every interface, so the separate default-deny rule
that each interface needs after M2-L2 (DMZ) and M2-L3 (VLANs) counted as a duplicate
of the LAN deny — a correctly segmented pod could not pass. Duplicates are now judged
within one interface tab and include protocol and port, and the failure names the
rule: FAIL:Issues(1): rule 29 on opt5 ('Allow HTTPS'): duplicate of rule 28. N is
the number of rules objected to, not a task number.
M3-L3 printed ExtraPorts(0) when no rule targeted the accounting host at all,
which reads like a passing count but actually means the one rule the lab asks you to
keep is gone. It now reports FAIL:NoHTTPSRuleTo10.51.XX.100 for a missing keeper
rule and FAIL:ExtraPorts(2): 21,3306 — naming the ports — when unnecessary ports
survive. 443, HTTPS, 443-443 and a destination written 10.51.XX.100/32 all
count.
Student fix for the missing rule: Firewall → Rules → LAN → + Add, Action Pass,
Protocol TCP, Destination Single host or alias 10.51.XX.100, Destination port
range HTTPS (443), placed above the Default Deny, then Apply Changes. If a
rule for the accounting application already exists, check that the protocol is TCP, the
destination is the host and not an interface or network address, and the port is
443. Re-verification picks the change up on the next scheduled run.
The capstone's logging check requires every rule whose action is Block to have
Log packets that are handled by this rule ticked. pfSense stores this per rule, so
turning logging on under Status → System Logs → Settings does not satisfy it, and the
block rule created back in the segmentation lab (typically Block DMZ to LAN lateral
movement on the OPT1/DMZ tab, not LAN) is the one students overlook.
The grader now names each offender:
capstone: passed 4/5 checks; failing: logging
(logging off on rule 10 on opt1 ('Block DMZ to LAN lateral movement'))
no block rules exist yet in that position means Task 1's default deny is missing rather
than unlogged. Student fix: edit the named rule, tick the log option under Extra
Options, Save, Apply Changes; the next scheduled verification credits the lab.
| Change | Live now |
|---|---|
| Member-server session hosts for all 20 pods, student logon retired on the DCs | Yes |
| IA M2-L1, IA M3-L2 and MP waivers retired (graded for real) | Yes — AWX project 10 synced to f4293d5 (PR #42) |
| Scheduled-task visibility fix (all 20 pods) | Yes |
| MP contents listings in all 20 pods | Yes |
| Guacamole GW tiles hidden, per-pod firewall routing | Yes |
| SC M3-L1 per-interface duplicates + named M3-L3 failure | Yes (PR #39) |
| SC M4-L3 logging failure names the offending block rules | Yes (PR #40) |
| Anti-lockout baseline + SC M4-L1 log evidence | Yes |
| Tolerant MP/PE/IA/SC wording and identifier grading | Yes |
| Revised guides (AC/IA/SI/SC/MP/PE) | Published on this wiki and in the portal; the repo DOCX/PDF branch still cannot be pushed (git proxy 403) |
| Unseeded-AC/SC reset correction | No — crc-awx-labops PR #43 pending merge, then an AWX project 10 sync |
Pods 7 and 11 are held back from auto-advance (crc_held_back_pods: 7,11)
until their member servers are activated.
AWX project 10 has update revision on launch disabled, so merging alone
does not activate a verifier change — the project must be synced
(AWX Automation).
| Page | Purpose |
|---|---|
| Student Quick Start | Student-facing version of these instructions |
| Lab Guides | Guides carrying the same notices |
| Pod Member Servers | Session hosts that removed these waivers |
| Backlog & Known Issues | Outstanding work |