Cybersecurity is one of the main uses of Azure Lab Services, not a niche. Published case studies include colleges running Kali for ethical hacking, network penetration testing courses, and a Windows Server course that runs a Hyper-V domain inside each student's machine. Microsoft's own setup guide names "networking or ethical hacking classes" as the reason for its nested virtualization sizes.
These courses need more from a lab than a desktop.
What they need
- Each student has their own machine, with admin rights inside it, so they can install tools and break things without affecting anyone else.
- No internet on the class network, so attack tools and malware samples stay inside the lab.
- A hypervisor inside the student's machine, for Hyper-V, KVM, or a network emulator such as GNS3 or EVE-NG.
- A clean start, so every student begins the exercise from the same known image.
- Several networked machines per student for attacker-and-target exercises.
How Hyperamplify Labs handles it
Isolated machines. Every student's machine is separate. Lab machines cannot reach each other, have no public address, and are reached only through our browser console.
No internet on class machines. Outbound internet from class machines is blocked by firewall. Template machines, where your staff install software, have internet access so installers download. The saved image then runs without it.
A nested virtualization size. A larger machine with virtualization switched on, about $1.00 an hour, so a student can run KVM, a network emulator, or a lab of guest machines inside it. It is enabled per college on request, because it uses more of the cloud quota. Windows guests inside it need their own licensing, so we offer it for Linux-based exercises.
Clean starts and reset. Every start boots a clean machine from the lab image. A student who breaks their machine presses Reset and is back at the start of the exercise.
Your staff build the image. Start from a fresh Ubuntu desktop, install Kali tools or your exercise environment, and save a version. Or have an AI agent run the install steps for you through our API.
What is not there yet
Several networked machines per student, such as an attacker and a target on their own network, are on the roadmap. Until then, the nested size runs multi-machine exercises inside one student machine.
Layer-2 attacks between separate cloud machines, such as ARP spoofing or rogue DHCP, are not possible on any major cloud network. They work inside the nested size, where the network is virtual.
If you run a cybersecurity or Windows Server program, request information. We would like to hear exactly what your exercises need.
