Everything you need for your first 10 minutes in the CRC Cyber Lab.
| Step | What to do |
|---|---|
| 1 | Open https://crc.guac.01.tcecure.com/#/ in any browser (Chrome or Edge recommended) |
| 2 | Log in with the Guacamole username and password your instructor issued |
| 3 | Double-click your pod's connection — named PODXX-SRV (e.g. POD05-SRV for Pod05) |
| 4 | Sign in as studentXX@acs-p01.local with your domain password |
PODXX-SRV is your own pod member server — one server per student, and the only connection you need. Every lab in all six families is done on that desktop, including the firewall labs.
The server is joined to acs-p01.local, so you administer Active Directory remotely from it with the management tools installed there (ADUC, AD PowerShell, GPMC). The domain controllers DC01-P01 and DC02-P01 still hold the directory you are graded on, but you no longer sign in to them. If an old PODXX-DC tile is still visible during the transition, ignore it.
Use studentXX@acs-p01.local (or ACS-P01\studentXX) to sign in. The short form ACS\studentXX is not valid — the NetBIOS domain name is ACS-P01. Nothing needs to be installed — the desktop runs inside the browser tab.
Everything you touch is scoped to your pod. Replace XX with your pod number (01–20) everywhere in the guides.
| Item | Pattern | Example (Pod05) |
|---|---|---|
| Domain | acs-p01.local |
acs-p01.local |
| Your login account | studentXX (domain acs-p01.local) |
student05 |
| Lab account prefix | PXX- |
P05-it.admin |
| Your OU | OU=PodXX,OU=Students,DC=acs-p01,DC=local |
OU=Pod05,… |
| Guacamole connection | PODXX-SRV |
POD05-SRV |
| Your session host | PODXX-SRV at 10.50.XX.20 |
POD05-SRV, 10.50.5.20 |
| Domain controllers (no sign-in) | DC01-P01, DC02-P01 |
10.50.1.10, 10.50.1.11 |
| Evidence folder | C:\CyberLab\PodXX\ |
C:\CyberLab\Pod05\ |
| Progress page | https://training.status.tcecure.com/pod/XX |
…/pod/05 |
Active Directory delegation stops you from changing anything outside your own pod — if an action is denied on another pod's objects, that is expected.
You are a local administrator of your own server (PODXX-SRV) and nothing else. Elevation prompts on your own server work normally — approve them with your own account. In the domain you are still a standard user with delegated rights over your own pod OU only, and you cannot sign in to a domain controller.
| Tool | How to open it |
|---|---|
| Active Directory Users and Computers | Start → Windows Administrative Tools → Active Directory Users and Computers, or Windows + R → dsa.msc |
| Group Policy Management | Windows + R → gpmc.msc |
| AD PowerShell | Start → Windows PowerShell → Import-Module ActiveDirectory |
| Task Scheduler | Windows + R → taskschd.msc |
| Local Security Policy | Windows + R → secpol.msc |
ADUC binds over the network to DC01/DC02 and edits the same directory objects you were graded on before — the only thing that changed is the desktop you run it from. An Access denied on another pod's objects is your OU delegation working, not a broken tool.
The firewall is not a separate Guacamole tile. From inside your own desktop:
http://10.51.XX.1 — Pod 01 → http://10.51.1.1, Pod 12 → http://10.51.12.1.The old PODXX-GW tile has been removed; it could never open a website. PODXX-GW is still the firewall's name in the diagrams.
Your own member server means the steps that used to need rights nobody had on a shared domain controller — the Task Scheduler stored-credential step and mounting lab media — are now possible on PODXX-SRV. Until instructors retire the waivers below they stay credited automatically, so do the surrounding work as written either way. Editing the domain password policy is still an administrator action on the domain and remains waived.
| Lab | What to do |
|---|---|
| IA M2-L1 | Create PXX-svc_backup as written (graded). The Task Scheduler stored-credential step now works on your own server — do it if you want the practice; the step stays credited automatically until the waiver is retired |
| IA M3-L2 | Do not run the Set- command or edit the GPO. Verify the live policy with Get-ADDefaultDomainPasswordPolicy and document it. Credited automatically |
| MP M1-L1 / M1-L2 | Mounting the .vhdx media now works on your own server, but the graded evidence is unchanged: classify from the published listings PXX-FCI-USB-Contents.txt and PXX-Employee-Handbook-Contents.txt in C:\CyberLab\PodXX\MP-Artifacts\. The worksheet, log and certificate are graded normally |
New password rule: any password you set — every new account you create in AC
L2.1, IA M1-L2/M2-L1/M3-L3, and any reset — needs at least 12 characters with
upper case, lower case, a number and a symbol (for example LabUser!2026#ac),
and cannot repeat a recent password. Your own sign-in password above is shorter
than that, so it will not work as a password for accounts you create. If you see
"The password does not meet the password policy requirements", that is the
policy working — nothing is wrong with your account.
The curriculum runs in this order, and the environment unlocks it the same way:
AC → IA → SI → SC → MP → PE
| # | Family | Labs | Completion Guide |
|---|---|---|---|
| 1 | Access Control (AC) | 12 | AC Guide |
| 2 | Identification & Authentication (IA) | 12 | IA Guide |
| 3 | System & Information Integrity (SI) | 12 | SI Guide |
| 4 | System & Communications Protection (SC) | 12 | SC Guide |
| 5 | Media Protection (MP) | 3 | MP Guide |
| 6 | Physical Protection (PE) | 6 | PE Guide |
| Total | 57 |
Start with AC Lab L1.1 and work down the AC guide. Do not skip ahead — later families assume the skills (and the cleaned-up directory) from earlier ones.
Several labs are graded on files you produce (CSV exports, worksheets, review notes). They must be saved under your own pod folder with the exact filename the guide gives you, or automated verification will mark the lab FAIL:
C:\CyberLab\PodXX\AC-Artifacts\
C:\CyberLab\PodXX\IA-Artifacts\
C:\CyberLab\PodXX\SI-Artifacts\
C:\CyberLab\PodXX\SC-Artifacts\
C:\CyberLab\PodXX\MP-Artifacts\
C:\CyberLab\PodXX\PE-Artifacts\
Tips:
notes.txt.txt.Automated verification runs on a schedule (roughly every 30 minutes) — you do not need to ask anyone to grade you.
| Status | Meaning |
|---|---|
| PASS | Objective verified — move on |
| FAIL | Something is still misconfigured, or evidence is missing/misnamed |
| NOT SEEDED | Lab is not deployed for your pod — tell your instructor |
The tracker never shows solutions, only whether your remediation worked. When you complete a family, the next family is unlocked automatically.
| Symptom | What to try |
|---|---|
| Guacamole connection is blank or drops | Close the tab, reopen the connection; if it persists, tell your instructor |
| Windows login fails | Sign in as studentXX@acs-p01.local — ACS\studentXX is not a valid domain name |
| A lab still shows FAIL after you fixed it | Re-read the verification note at the end of that lab section — usually a filename or an OU/group scope |
| A tool is missing | Everything needed is on your server's desktop or in Start → Windows Administrative Tools |
| A User Account Control box appears | Approve it with your own account — you are a local administrator on PODXX-SRV |
| Something is denied on another pod's objects or another pod's server | Expected: your rights stop at your own pod OU and your own server |
| The firewall page will not load | Make sure you are browsing from inside PODXX-SRV to http://10.51.XX.1 with your own pod number, not from your laptop |
| A lab step demands administrator rights | Check the notices in section 5 — IA M2-L1, IA M3-L2 and MP M1-L1/M1-L2 are credited this cohort |
Do not reset anything yourself — resets are run by instructors through AWX.
| Resource | Link |
|---|---|
| Lab Guides | All six completion guides |
| Current Cohort Notices | Waivers and known issues |
| Lab Families | Curriculum overview |
| Progress Tracker | https://training.status.tcecure.com |
| Guacamole | https://crc.guac.01.tcecure.com/#/ |
TCecure CRC Cyber Lab — Cyber Ready Clinic