Microsoft 365 Certified: Administrator Expert flashcards
145 free flashcards. Tap a card to flip it.
Federated Identity (AD FS)
Flip cardAn identity model where user authentication requests for cloud services are redirected to an on-premises identity provider (like AD FS), which then authenticates the user against the on-premises Active Directory.
- Authentication occurs on-premises.
- Requires AD FS infrastructure.
- Provides single sign-on (SSO) experience.
- Supports advanced authentication policies defined on-premises.
Memory trick: Federated identity is like a border checkpoint: your on-premises AD is the authority stamping your passport for cloud access.
Defender for Cloud Apps File Policies
Flip cardMicrosoft Defender for Cloud Apps File policies allow administrators to scan files in connected cloud apps for sensitive content and apply governance actions, including applying Microsoft Information Protection sensitivity labels and encryption.
- Scans content of files in cloud storage.
- Can detect sensitive information (e.g., PII, credit card numbers).
- Applies governance actions like labeling, encryption, deletion, quarantine.
- Integrates with Microsoft Information Protection (MIP).
Memory trick: Remember, to 'Govern' 'Files' in the 'Cloud' with 'Labels', you need a 'File Policy' to 'Protect' them.
Microsoft Entra Privileged Identity Management (PIM)
Flip cardA service within Microsoft Entra ID that enables you to manage, control, and monitor access to important resources in your organization. This includes Microsoft Entra ID, Azure, and other Microsoft Online Services.
- Provides just-in-time (JIT) privileged access.
- Enforces time-bound access for roles.
- Requires approval workflows for activation.
- Offers audit trails and access reviews for privileged roles.
Memory trick: PIM protects Privileged roles with Just-In-Time access.
Azure AD HR-Driven User Provisioning & Dynamic Groups
Flip cardA combined solution where Azure AD automates user account creation and attribute population from an HR system, and Dynamic Groups automatically manage group memberships based on user attributes.
- Automates user lifecycle from hire to retire.
- Generates UPNs and email addresses using attribute-based expressions.
- Dynamic Groups ensure users are automatically added/removed from relevant groups.
Memory trick: HR Provisioning is the 'new hire wizard', and Dynamic Groups are the 'smart department sorter'.
Microsoft 365 Multi-Geo
Flip cardA Microsoft 365 feature that enables organizations to store user data at rest in specified geographic locations (geos) to meet data residency requirements.
- Requires an Enterprise Agreement and specific license types (e.g., E3, E5).
- Applies to Exchange Online, SharePoint Online, OneDrive, and Teams.
- Administrators can assign users to a preferred data location (PDL).
Memory trick: Think of Multi-Geo as a global map where you can draw boundaries for your data's home.
Microsoft Entra Identity Protection Sign-in Risk Policy
Flip cardA Microsoft Entra Identity Protection Sign-in risk policy automatically detects and responds to real-time sign-in risks. It can enforce actions such as blocking access or requiring multi-factor authentication (MFA) based on the risk level associated with a user's sign-in attempt.
- Evaluates risk of individual sign-in attempts.
- Actions include block access or require MFA.
- Works with Microsoft Entra Conditional Access.
Memory trick: ID Protect: Risk-Based Reactions
Azure AD Entitlement Management
Flip cardAn identity governance feature in Azure AD that enables organizations to manage identity and access lifecycle at scale by automating access requests, approvals, access reviews, and expiration.
- Automates access to groups, applications, and SharePoint sites.
- Supports both internal and external users (B2B collaboration).
- Allows defining access packages with expiration dates and periodic access reviews.
Memory trick: Entitlement Management is like a self-expiring guest pass system for your digital resources.
Pass-through Authentication (PTA)
Flip cardA Microsoft Entra Connect authentication method where user sign-in requests are redirected to an agent running on an on-premises server, which validates the password directly against Active Directory.
- Passwords never leave the on-premises network.
- Requires one or more lightweight agents on-premises.
- Provides a seamless sign-in experience for users.
Memory trick: Pass-Through: Passwords Stay Safe On-Premises.
Microsoft Entra Connect Attribute Filtering
Flip cardA filtering method in Microsoft Entra Connect that allows administrators to define which objects synchronize to Microsoft Entra ID based on the values of their attributes.
- Provides granular control over synchronization.
- Can be used to include or exclude objects based on specific attribute values.
- Configured using the Synchronization Rules Editor.
- More flexible than OU filtering for complex inclusion/exclusion criteria.
Memory trick: Attribute Filtering: Apply rules to Specific Attributes.
Federated Identity
Flip cardA system where a user's identity and authentication are managed by one system (identity provider) but trusted by another system (service provider) to grant access.
- Enables single sign-on across multiple services.
- Requires an identity provider (e.g., AD FS) to handle authentication.
- Provides centralized control over authentication policies.
Memory trick: Think of different bridges connecting your on-premises castle to the Microsoft 365 cloud kingdom.
Azure AD Dynamic Groups
Flip cardAzure AD groups (security or Microsoft 365) whose membership is automatically updated based on predefined rules that query user or device attributes.
- Requires an Azure AD Premium P1 or P2 license.
- Supports dynamic membership for users or devices.
- Simplifies group management for large and frequently changing organizations.
Memory trick: Think of dynamic groups as smart filters that automatically sort users into the right club.
Microsoft Entra Entitlement Management
Flip cardAn identity governance feature that enables organizations to manage identity and access lifecycle at scale, automating access requests, approvals, provisioning, and de-provisioning.
- Uses 'access packages' to bundle resources (groups, applications, SharePoint sites).
- Supports automatic assignment and removal of access based on user attributes.
- Streamlines onboarding, offboarding, and internal transfers.
Memory trick: Govern Identities, Grant Entitlements, Ensure Control.
Defender XDR Streaming API
Flip cardThe Microsoft Defender XDR Streaming API enables continuous, real-time export of raw event data and alerts to Azure Storage, Azure Event Hubs, or a SIEM, facilitating centralized logging, long-term retention, and custom analytics.
- Exports raw event data and security alerts.
- Provides a continuous, real-time stream.
- Integrates with SIEMs, Azure Storage, Event Hubs.
- Essential for centralized logging and long-term retention.
Memory trick: Streaming API is like a live broadcast, continuously sending all security data to your external systems.
Microsoft Entra Connect Cloud Sync
Flip cardMicrosoft Entra Connect Cloud Sync is a lightweight Microsoft Entra Connect agent-based service that synchronizes users, groups, and contacts from on-premises Active Directory to Microsoft Entra ID. It's designed for hybrid identity scenarios with simpler requirements, minimal infrastructure, and high resilience.
- Lightweight agents, cloud-managed.
- Good for multi-forest, disconnected forests, or small environments.
- Supports high availability with multiple agents.
Memory trick: Sync Options: Choose Your Engine
Cloud Sync Domain and OU Filtering
Flip cardIn Microsoft Entra Connect Cloud Sync, filtering allows administrators to explicitly define which domains and Organizational Units (OUs) from on-premises Active Directory are synchronized to Microsoft Entra ID.
- Configured directly in the Microsoft Entra admin center.
- Supports both domain-level and OU-level filtering.
- Essential for controlling the scope of synchronized objects.
- More granular than domain filtering alone.
Memory trick: Cloud Sync: Configure OUs directly in the Cloud.
Usage Location
Flip cardA mandatory user property in Microsoft 365 that determines the country/region where the user is located, impacting licensing and service availability.
- Required for assigning most Microsoft 365 licenses.
- Affects data residency and compliance for some services.
- Can be set per user or as a default for the organization.
Memory trick: Think of the 'Org settings' as the blueprint for your entire Microsoft 365 house.
Password Hash Synchronization (PHS)
Flip cardA Microsoft Entra Connect authentication method where a cryptographic hash of a user's password hash is synchronized from on-premises Active Directory to Microsoft Entra ID.
- Provides a cloud-only authentication experience.
- Allows users to sign in even if on-premises AD DS is unavailable.
- Simplest to deploy and manage among hybrid authentication methods.
- Offers built-in high availability and disaster recovery for authentication.
Memory trick: PHS: Passwords Hashed, Safe in the Cloud.
Azure AD Administrative Units
Flip cardAn Azure AD Premium feature that allows the creation of logical containers to group users, groups, or devices, enabling granular delegation of administrative roles to specific scopes.
- Requires Azure AD Premium P1 or P2 license.
- Used to delegate administrative permissions to a subset of the organization.
- Supports delegation for roles like User Administrator, Group Administrator, Helpdesk Administrator.
Memory trick: Think of Administrative Units as custom-sized boxes that hold users/groups, letting you give a key to only that box.
Azure AD Default Usage Location
Flip cardA configuration in Azure AD that sets a default country/region for new user accounts, which is essential for license assignment, service availability, and compliance with regional regulations.
- Mandatory property for assigning licenses to users.
- Impacts service availability and feature enablement.
- Can be set globally for the tenant in Azure AD user settings.
Memory trick: Think of the default usage location as the 'home address' for all new digital citizens in your tenant.
DNS TXT Record for Domain Verification
Flip cardA type of DNS record containing text information, used by services like Microsoft 365 to verify ownership of a domain by requiring the domain owner to publish a specific string.
- Contains a unique string provided by Microsoft 365.
- Must be added to the domain's public DNS zone.
- Temporary for verification, though often left in place.
Memory trick: TXT is like signing your name to prove you own the domain.
Microsoft Entra Connect OU Filtering
Flip cardMicrosoft Entra Connect Organizational Unit (OU) filtering allows administrators to select specific OUs within their on-premises Active Directory that should be synchronized to Microsoft Entra ID. This is used to control which objects are provisioned to the cloud.
- Prevents unwanted objects from syncing.
- Configured during or after Microsoft Entra Connect installation.
- Reduces cloud clutter and improves security.
Memory trick: Filter: Only the Best Bits Go Up
Microsoft Entra Connect Staging Mode
Flip cardMicrosoft Entra Connect Staging mode allows a second Microsoft Entra Connect server to be installed and configured in parallel with an active server. It performs full synchronization cycles (import and synchronize) but does not export any changes to Microsoft Entra ID, making it ideal for testing, disaster recovery, and configuration validation.
- Performs full sync but no export.
- Used for testing, DR, and configuration validation.
- Can be easily promoted to active server.
Memory trick: Modes: Prepare, Then Produce
KQL 'join' operator
Flip cardThe Kusto Query Language (KQL) 'join' operator merges rows from two tables by matching values from specified columns in each table, allowing for correlation of distinct but related events across different data sources.
- Combines rows from two or more tables.
- Requires a common column (or columns) between tables.
- Essential for correlating events across different data types (e.g., device events and cloud app events).
- Supports various join kinds (inner, leftouter, rightouter, etc.).
Memory trick: Join is like a matchmaker for tables, bringing together related events from different families.
Microsoft Entra B2B Collaboration
Flip cardA feature in Microsoft Entra ID that enables external users to access your organization's applications and resources without creating a new local account.
- Users authenticate with their home directory credentials.
- Guest user accounts are created in your tenant, linked to their original identity.
- Facilitates secure collaboration with partners, customers, and vendors.
Memory trick: External Users, Easy Access, Entra B2B.
DNS MX Record for Email Routing
Flip cardA DNS record that specifies the mail servers responsible for receiving email messages on behalf of a domain name, essential for directing email to the correct mailboxes in Exchange Online.
- Mandatory for incoming email delivery.
- Must point to the Microsoft 365 mail servers (e.g., example-com.mail.protection.outlook.com).
- Can have a priority value to specify preferred mail servers.
Memory trick: The MX record is like the post office sign, pointing all emails to the correct mail delivery service.
Microsoft 365 Service Health
Flip cardA dedicated dashboard within the Microsoft 365 admin center that provides real-time information on the status and health of Microsoft 365 services relevant to a specific tenant.
- Shows active incidents, advisories, and planned maintenance.
- Provides tenant-specific impact details.
- Accessible only to administrators with appropriate roles.
Memory trick: Think of the Service Health dashboard as your tenant's personal doctor's report.
Defender for Endpoint Attack Surface Reduction (ASR) Rules
Flip cardAttack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint target common attack vectors and prevent behaviors often used by malware, such as blocking unsigned scripts, disabling malicious macros, and preventing execution of suspicious processes.
- Prevents common malware behaviors and exploits.
- Blocks unsigned scripts and malicious macros.
- Reduces the attack surface of devices.
- Part of proactive defense against fileless and advanced attacks.
Memory trick: ASR rules are like bouncers for your system, blocking suspicious behaviors before they cause trouble.
M365 Network Connectivity Performance Dashboard
Flip cardA tool in the Microsoft 365 admin center that provides insights and recommendations for optimizing network connectivity to Microsoft 365 services, identifying performance bottlenecks.
- Analyzes latency, bandwidth, and connectivity paths.
- Helps identify localized network issues affecting user experience.
- Provides recommendations for network improvements.
Memory trick: Network Connectivity Dashboard: Your map to speed.
Defender for Cloud Apps Cloud Discovery
Flip cardCloud Discovery in Microsoft Defender for Cloud Apps identifies all cloud applications used across an organization, assesses their risk, and detects shadow IT.
- Uses traffic logs from firewalls, proxies, and endpoints.
- Provides a risk score for each discovered app.
- Helps identify sanctioned vs. unsanctioned cloud services.
- Crucial for gaining visibility into an organization's cloud app landscape.
Memory trick: To DISCOVER all cloud apps, you need CLOUD DISCOVERY.
DNS TXT Record
Flip cardA type of DNS record that provides text information to sources outside your domain, often used for verification or policy data.
- Used for domain ownership verification (e.g., Microsoft 365, Google).
- Can contain SPF or DKIM records for email authentication.
- Does not directly affect mail flow or website access.
Memory trick: Remember DNS records are like signs on the internet highway, each with a different purpose.
Azure AD Conditional Access
Flip cardAn Azure AD feature that allows administrators to enforce specific access controls (e.g., MFA, device compliance) based on various conditions (user, location, device, application, sign-in risk).
- Requires Azure AD Premium P1 or P2 licenses.
- Works on an 'if-then' basis (If 'conditions' are met, then 'access controls' are applied).
- Can integrate with Azure AD Identity Protection for risk-based policies.
Memory trick: Think of Conditional Access as a smart traffic cop at your digital intersection, directing users based on their 'credentials' and 'vehicle' status.
Conditional Access with Identity Protection Risk
Flip cardAn Azure AD Conditional Access policy that uses sign-in risk levels (detected by Azure AD Identity Protection) as a condition to enforce access controls like blocking access or requiring MFA.
- Identity Protection detects the risk, Conditional Access enforces the action.
- Can be configured to block, require MFA, or require password change.
- Targets specific cloud apps, users, and risk levels.
Memory trick: Risk gets flagged, Conditional Access seals the deal.
Conditional Access Session Controls
Flip cardAzure AD Conditional Access policies that apply controls during a user's session, enabling actions like blocking downloads, requiring compliant devices, or using a less restrictive experience.
- Enforces policies after initial authentication.
- Integrates with Microsoft Defender for Cloud Apps (MDCA) for advanced controls.
- Can restrict actions like download, print, or copy on unmanaged devices.
Memory trick: Conditional Access is the bouncer for your digital club.
Privileged Identity Management (PIM)
Flip cardMicrosoft Entra Privileged Identity Management (PIM) is a service that enables you to manage, control, and monitor access to important resources in your organization.
- Provides just-in-time (JIT) privileged access.
- Enforces time-bound access for roles and resources.
- Offers comprehensive auditing and alerts for privileged role usage.
Memory trick: PIM protects Privileged identities, Access Reviews review who has what, Identity Protection protects against risks.
Defender for Identity Lightweight Sensor
Flip cardThe Microsoft Defender for Identity Lightweight Sensor is deployed directly on domain controllers to monitor network traffic and Windows events for identity-based threats and suspicious activities.
- Installed on domain controllers.
- Monitors NTLM, Kerberos, DNS, RPC, and other network traffic.
- Collects Windows Events (e.g., security event logs).
- Detects identity-based attacks like Golden Ticket, Pass-the-Hash, suspicious service creation.
Memory trick: Remember, the 'Identity' 'Sensor' is 'Lightweight' but 'Heavy' on 'Domain Controller' 'Eyes'.
M365 Domain Removal Prerequisites
Flip cardA set of conditions that must be met before a custom domain can be successfully removed from a Microsoft 365 tenant, primarily ensuring no objects or services are still dependent on it.
- All users, groups, and contacts must be updated or removed.
- No mail-enabled public folders or distribution lists can use the domain.
- The domain cannot be the primary domain for the tenant or any user.
Memory trick: Empty the domain's pockets before it leaves.
Microsoft Entra Connect Synchronization Service Manager
Flip cardThe Microsoft Entra Connect Synchronization Service Manager is a management console used to configure advanced synchronization features, including custom synchronization rules, attribute flow, connector spaces, and metaverse objects. It provides granular control over how identities are processed and synchronized.
- Manages synchronization rules and attribute flow.
- Resolves identity conflicts (joins).
- Advanced configuration tool for complex scenarios.
Memory trick: Sync Manager: Master of the Flow
Advanced Hunting Tables: DeviceNetworkEvents
Flip cardThe DeviceNetworkEvents table in Microsoft Defender XDR's Advanced Hunting schema contains information about network connections and related events on devices.
- Records outbound and inbound network connections.
- Includes details like LocalIP, RemoteIP, LocalPort, RemotePort, Protocol.
- Useful for investigating command and control (C2) communication, data exfiltration, and lateral movement.
Memory trick: Network events are for NETWORK DETAILS, not processes or files.
Microsoft 365 Unified Audit Log
Flip cardA comprehensive logging service in Microsoft 365 that captures user and administrator activity across various services, providing a single source for auditing and forensic investigations.
- Records activities across Exchange, SharePoint, Teams, Azure AD, etc.
- Retains logs for a configurable period (up to 10 years with E5).
- Searchable through the Microsoft Purview compliance portal.
Memory trick: The Unified Audit Log is your detective's notebook, recording every admin move across Microsoft 365.
Password Hash Synchronization (PHS) Resilience
Flip cardEnsuring continuous availability of password hash synchronization to Microsoft Entra ID by deploying redundant Microsoft Entra Connect infrastructure.
- Achieved by deploying a second Microsoft Entra Connect server in staging mode.
- Both primary and staging servers perform PHS to Microsoft Entra ID simultaneously.
- If the primary server fails, the staging server can be promoted to active with minimal downtime for synchronization.
- Ensures users can continue to authenticate even if one sync server is down.
Memory trick: PHS Resilience: Prepare a Partner Server.
Microsoft 365 Network Connectivity Performance Dashboard
Flip cardThis dashboard provides administrators with detailed insights into their organization's network connectivity to Microsoft 365 services. It helps identify network latency, bandwidth issues, and routing problems that can impact user experience, offering actionable recommendations for improvement.
- Located in the Microsoft 365 admin center under Health > Network connectivity.
- Analyzes network path from user locations to Microsoft's global network.
- Provides tenant-specific network performance scores and metrics.
- Offers recommendations to optimize network configurations (e.g., direct routing, proxy bypass).
Memory trick: Green light, but slow pace? Network dashboard shows the race!
Defender XDR Unified Activity Timeline
Flip cardThe Microsoft Defender XDR unified activity timeline provides a consolidated, chronological view of a user's activities across various Microsoft 365 services, streamlining investigations into user-centric threats.
- Consolidates activities from email, SharePoint, Teams, devices, etc.
- Presents data in a chronological order.
- Accessible within the Microsoft 365 Defender portal.
- Aids in insider threat and user compromise investigations.
Memory trick: Remember, for a 'Unified View' of a 'User's Activities', check the 'Unified Activity Timeline'.
Advanced Hunting DeviceFileEvents Table
Flip cardThe DeviceFileEvents table in Microsoft Defender XDR Advanced Hunting contains information about file system activities on devices, including file creation, modification, deletion, and access. It is crucial for detecting suspicious file operations and identifying new or unauthorized files.
- Records file creation, modification, deletion, and access.
- Provides details like file name, path, hash, and action type.
- Essential for detecting new executables or malware drops.
- Used to track sensitive file interactions.
Memory trick: DeviceFileEvents is like the file cabinet's security log, tracking every file that comes in or out.
Defender for O365 Safe Links
Flip cardSafe Links is a feature of Microsoft Defender for Office 365 that provides time-of-click verification of URLs in email messages and other Microsoft 365 apps, protecting users from malicious links even if they change after delivery.
- Rewrites URLs in emails and Office documents.
- Checks URLs in real-time at the time of click.
- Blocks access to malicious sites.
- Protects against changing malicious content.
Memory trick: Links can be tricky; make sure they're safe when clicked, not just when seen.
KQL 'in' Operator
Flip cardThe KQL 'in' operator is a membership operator used to check if a scalar value matches any value in a provided list of scalar values.
- Syntax: `scalarExpression in (value1, value2, ...)`.
- Case-sensitive by default; use `!in` for 'not in' and `in~` for case-insensitive.
- Efficient for matching against multiple discrete values.
- Equivalent to multiple `or` conditions (e.g., `x == 'a' or x == 'b'`).
Memory trick: To check if a value is IN a LIST, use the 'in' operator.
Advanced Hunting IdentityLogonEvents Table
Flip cardThe IdentityLogonEvents table in Microsoft Defender XDR Advanced Hunting contains information about authentication attempts and logon events from both on-premises Active Directory (via Defender for Identity) and Azure Active Directory, including details for user and service accounts.
- Captures authentication activities for identities.
- Includes data from on-premises AD and Azure AD.
- Records logon type, source IP, success/failure.
- Essential for investigating identity-related threats.
Memory trick: IdentityLogonEvents is like the security guard's logbook for every person trying to enter, including the service staff.
Defender for Identity Sensitive Account Protection
Flip cardA feature within Microsoft Defender for Identity that allows organizations to designate specific accounts as 'sensitive' to apply enhanced monitoring, detection logic, and protection against advanced threats, such as credential theft and brute-force attacks.
- Tags high-value accounts (e.g., executives, admins).
- Applies stricter detection logic for anomalous behavior.
- Helps protect against credential compromise and abuse.
Memory trick: Identity protection needs to track movement, score security, and guard key accounts.
Defender Vulnerability Management Security Recommendations
Flip cardA feature within Microsoft Defender Vulnerability Management that provides actionable insights and guidance to improve the security posture of an organization's devices by identifying and prioritizing vulnerabilities and misconfigurations.
- Identifies software vulnerabilities and misconfigurations.
- Provides prioritized security recommendations.
- Helps achieve compliance and reduce attack surface.
Memory trick: Endpoints need protection and constant vigilance from known weaknesses.
Safe Links for Attachments
Flip cardMicrosoft Defender for Office 365 Safe Links can be configured to scan and rewrite URLs found within email attachments, providing an additional layer of protection against phishing and malware.
- Requires explicit enablement in Safe Links policy.
- Protects against malicious URLs in documents like PDFs, Word, Excel.
- Separate setting from scanning URLs in email body.
Memory trick: Remember, 'Safe Links' needs to 'Scan' 'Attachments' 'Explicitly' to catch hidden threats.
IdentityLogonEvents KQL Table
Flip cardThe `IdentityLogonEvents` KQL table in Microsoft Defender XDR Advanced Hunting provides detailed information about logon attempts to user identities, including source, client, and authentication method.
- Populated by Microsoft Defender for Identity and Azure AD data.
- Records successful and failed logon attempts.
- Includes details like IP address, application, authentication method, logon type.
- Crucial for identity compromise investigations.
Memory trick: Remember, for 'Identity' 'Logons', the 'IdentityLogonEvents' table is the 'Key' to 'Logon Investigations'.
Microsoft Entra Connect Topologies - Multiple Forests
Flip cardDeployment configurations for Microsoft Entra Connect when synchronizing identities from more than one on-premises Active Directory forest.
- Common scenarios include mergers, acquisitions, or complex enterprise structures.
- A single Microsoft Entra Connect server or multiple servers (one per forest) can be used.
- Requires careful planning for identity matching and attribute flow to ensure unique user identities in Entra ID.
Memory trick: Connect Forests to Cloud, Choose Your Path.
Microsoft 365 Retention Policies
Flip cardPolicies in Microsoft 365 that allow organizations to retain or delete content for a specified period to comply with business, legal, or regulatory requirements.
- Applies to various content types: Exchange email, SharePoint, OneDrive, Teams chats.
- Can retain content or delete it after a period, or both.
- Content is held in an inaccessible location for end-users during retention.
Memory trick: Retention Policies: Keep it or trash it, by the rules.
Microsoft Entra Conditional Access Named Locations
Flip cardMicrosoft Entra Conditional Access Named locations are custom IP address ranges or countries/regions that can be defined in Microsoft Entra ID. These locations can then be used as conditions in Conditional Access policies to grant or block access based on a user's network origin.
- Defines trusted or untrusted IP ranges/countries.
- Used as a condition in Conditional Access policies.
- Crucial for location-based access control.
Memory trick: Conditions: What's the Context?
Mail Flow Rules for Content Filtering
Flip cardMail flow rules (transport rules) in Exchange Online (part of Microsoft 365) allow administrators to apply specific actions, such as quarantining, to email messages based on conditions like the presence of sensitive keywords in the message content.
- Configured in Exchange admin center or Microsoft 365 Defender portal.
- Use conditions to match message properties (sender, recipient, content).
- Apply actions like quarantine, reject, redirect, add disclaimers.
- Highly customizable for specific content filtering needs.
Memory trick: Remember, for 'Custom Content' 'Filtering' and 'Quarantine', 'Mail Flow Rules' are your 'Go-to'.
Microsoft 365 Usage Location
Flip cardA critical user attribute that specifies the country or region where a user is located, which is required for license assignment and service provisioning.
- Mandatory for most Microsoft 365 licenses.
- Impacts data residency and service availability.
- Can be set during user creation or edited later.
Memory trick: Think of the Usage Location as the 'address' for your license to be delivered and activated.
Default Usage Location
Flip cardThe default Usage Location in Microsoft 365/Azure AD allows administrators to pre-set a geographical location for all newly created user accounts. This simplifies user provisioning by ensuring consistent application of the 'Usage Location' attribute, which is crucial for license assignment and service availability.
- Configured in the Azure AD admin center under User settings.
- Applies to users created directly in Azure AD (cloud-only users).
- Does not apply to users synchronized from on-premises Active Directory.
- Crucial for correct license assignment and compliance with regional service availability.
Memory trick: New user's home, set by default, no manual fault.
Azure AD PIM Role Settings
Flip cardAzure AD Privileged Identity Management (PIM) allows administrators to manage, control, and monitor access to important resources. PIM role settings define the rules for how eligible users activate their roles, including requirements for MFA, justification, approval, and maximum activation duration.
- Configurable per role in Azure AD PIM.
- Includes settings for activation duration (e.g., 4 hours).
- Allows requiring MFA for role activation.
- Enables requiring justification for role activation.
Memory trick: PIM settings: Time, MFA, and a reason, secure access for every season.
Defender for Office 365 Safe Links
Flip cardA feature in Microsoft Defender for Office 365 that provides URL scanning and rewriting of inbound email messages and other content. It protects users from malicious links by checking them at the time of click.
- Rewrites URLs in emails and Office documents.
- Scans links in real-time at the time of click.
- Protects against malicious links, even if initially safe.
- Allows for custom blocked URLs configuration.
Memory trick: Safe Links is like a bouncer for URLs, checking every ID at the door, even if they passed the first check.
Defender for Cloud Apps with Purview Information Protection
Flip cardMicrosoft Defender for Cloud Apps integrates with Microsoft Purview Information Protection to enforce data protection policies, including encryption and access controls, on sensitive files shared or stored in cloud applications.
- Extends Purview Information Protection labels and policies to cloud apps.
- Enables real-time control over file activities (upload, download, share).
- Prevents data exfiltration and ensures compliance in cloud environments.
- Applies to SharePoint, OneDrive, and other connected cloud storage services.
Memory trick: To protect CLOUD files with Purview, use CLOUD APPS.
Microsoft 365 Domain Removal Prerequisites
Flip cardBefore removing a custom domain from a Microsoft 365 tenant, all associated users, groups, aliases, SharePoint sites, and other services must be moved to another domain. The Microsoft 365 admin center provides tools to identify these dependencies.
- All users must have their UPN and primary email address changed.
- All groups (Microsoft 365 Groups, distribution lists, mail-enabled security groups) must have their primary email address and proxy addresses updated.
- SharePoint and OneDrive URLs associated with the domain may need to be updated or migrated (less common for simple domain removal).
- Any services (e.g., Skype for Business, Teams) using the domain must be reconfigured.
Memory trick: Before you delete the domain, check the admin center for remaining claim.