Microsoft 365 Certified: Administrator Expert flashcards
145 free flashcards. Tap a card to flip it.
Azure AD Pass-through Authentication (PTA)
Flip cardAzure AD Pass-through Authentication (PTA) is a free feature that allows users to sign in to both on-premises and cloud-based applications using the same password. It achieves this by validating users' passwords directly against their on-premises Active Directory without storing hashes in Azure AD or requiring federation servers.
- Uses lightweight agents installed on-premises for password validation.
- No federation servers (like AD FS) are required.
- Provides a seamless single sign-on experience.
- User passwords are never stored in the cloud in any form.
Memory trick: On-prem credentials, no new servers? Pass-through is the answer, no more queries!
Azure AD Dynamic Group Attributes
Flip cardAzure AD Dynamic Groups automatically manage membership based on user attributes. Administrators define rules using attributes like 'department', 'country', or 'job title', and Azure AD adds or removes users as their attributes change.
- Simplifies group management by automating membership.
- Rules are based on user properties stored in Azure AD.
- Common attributes include Department, Company, Country, Usage Location, Job Title.
- Supports 'AND', 'OR', 'NOT' operators for complex rules.
Memory trick: Attributes drive the dynamic group's flow, ensuring access where users go.
PIM Role Settings
Flip cardConfigurable parameters within Azure AD Privileged Identity Management that define how eligible users can activate and use privileged roles.
- Control activation duration.
- Enforce justification for activation.
- Require MFA for activation.
- Set up approval workflows.
Memory trick: PIM settings are your access control panel: how long, why, and how secure.
Azure AD Privileged Identity Management (PIM)
Flip cardAn Azure AD feature that allows organizations to manage, control, and monitor access to important resources by providing just-in-time and time-bound access to privileged roles.
- Enforces 'just-in-time' (JIT) and 'just-enough-access' (JEA) principles.
- Requires activation and optional approval for privileged roles.
- Provides audit trails and access reviews for privileged role assignments.
Memory trick: PIM is like a secure vault for your admin keys, only opening when needed and for a short time.
Microsoft 365 Multi-Geo Prerequisites
Flip cardMulti-Geo capabilities in Microsoft 365 allow an organization to provision and store data at rest in specified geographical locations to meet data residency requirements. It requires specific licensing and tenant-level configuration before individual user data locations can be set.
- Requires specific Microsoft 365 subscription plans (e.g., Enterprise Agreement, specific E plans).
- Must be enabled at the tenant level by Microsoft before use.
- Allows administrators to define satellite geo locations for data storage.
- Users' preferred data location (PDL) is then set to route their data to these geo locations.
Memory trick: Global data, local rules, Multi-Geo is the key.
Azure AD PIM Audit History
Flip cardThe Azure AD Privileged Identity Management (PIM) audit history provides a comprehensive record of all activities related to PIM, including role activations, role assignments, and changes to PIM settings. It is crucial for security investigations and compliance auditing of privileged access.
- Records who activated a privileged role, when, and for how long.
- Tracks role assignments (eligible, active, permanent).
- Logs changes to PIM role settings and policies.
- Accessible within the PIM blade in the Azure AD admin center.
Memory trick: PIM audit history: every king's move, time, and reason.
Azure AD Group-based Licensing
Flip cardA feature in Azure AD that allows administrators to assign Microsoft 365 product licenses to security groups, automating license assignment and removal for group members.
- Supports both assigned and dynamic security groups.
- Automates license management as users join or leave groups.
- Simplifies license administration for large organizations.
Memory trick: Group-based licensing is like a smart license vending machine for your teams.
Conditional Access for MFA
Flip cardAzure AD Conditional Access policies can be configured to enforce Multi-Factor Authentication (MFA) based on specific conditions, such as user location (trusted vs. untrusted networks), device state, or application being accessed. This allows for flexible and risk-based MFA enforcement.
- Requires Azure AD Premium P1 or P2 license (included in Microsoft 365 E3/E5).
- Allows defining trusted network locations (named locations).
- Can enforce MFA for specific users, apps, and conditions.
- Provides a more granular control over MFA than Security Defaults.
Memory trick: Location-based MFA: Conditional Access makes the call.
Microsoft Entra Seamless SSO
Flip cardMicrosoft Entra Seamless Single Sign-On (Seamless SSO) automatically signs users in when they are on their corporate network and connected to a domain-joined device.
- Enhances user experience by eliminating password prompts.
- Works with Password Hash Synchronization (PHS) and Pass-through Authentication (PTA).
- Uses Kerberos authentication for seamless sign-in.
Memory trick: SSO makes sign-in Smooth, Conditional Access Controls it, MFA Makes it safer, ID Protection Protects it.
KQL String Operators
Flip cardKusto Query Language (KQL) provides various operators for string manipulation and searching, including `contains`, `has`, and `matches regex`, each suited for different search criteria and performance considerations.
- `has` is for case-insensitive whole-term search, optimized for performance.
- `contains` is for case-insensitive substring search.
- `matches regex` for complex pattern matching.
- Choosing the right operator impacts query performance.
Memory trick: Searching text needs to be exact, partial, or pattern-based, and performance matters.
Defender for Endpoint Device Discovery
Flip cardDevice discovery in Microsoft Defender for Endpoint is a capability that uses onboarded endpoints to passively scan the network and actively probe for unmanaged devices, providing a comprehensive inventory of all network-connected assets, both managed and unmanaged.
- Identifies unmanaged devices on the network.
- Uses existing onboarded devices as sensors.
- Provides asset inventory and security recommendations.
- Enables integration with network access control.
Memory trick: Managing devices means discovering them, reducing attack surface, and responding to threats.
Conditional Access Sign-in Frequency
Flip cardA session control in Microsoft Entra Conditional Access that defines how often users are required to re-authenticate when accessing resources protected by the policy.
- Can be configured to enforce re-authentication after a specific duration (e.g., 1 hour, 1 day).
- Helps enforce stricter security for privileged accounts or sensitive applications.
- Applied as a session control within a Conditional Access policy.
- Can override default token lifetimes for enhanced security.
Memory trick: Conditional Access: Control How Often Users Sign-In.
Microsoft Entra Connect Federation (AD FS)
Flip cardAn authentication method where Microsoft Entra ID redirects authentication requests to an on-premises Active Directory Federation Services (AD FS) farm, which then authenticates users against Active Directory.
- Leverages existing AD FS infrastructure.
- Passwords never leave the on-premises network.
- Provides advanced authentication features (e.g., smart card authentication, third-party MFA).
- Requires more infrastructure and management overhead than PHS or PTA.
Memory trick: Federation: Focus on Existing AD FS.
Microsoft 365 Group Naming Policy
Flip cardA feature in Azure Active Directory Premium P1 that allows administrators to enforce naming conventions for Microsoft 365 Groups, including prefixes, suffixes, and blocked words, to maintain organizational consistency and governance.
- Requires Azure AD Premium P1 license.
- Applies to all new Microsoft 365 Groups.
- Supports prefixes, suffixes, and custom blocked words.
- Helps with group organization and discoverability.
Memory trick: Group Naming Policy is the name tag police, making sure every group follows the rules and avoids forbidden words.
Defender for Endpoint Onboarding Methods
Flip cardMicrosoft Defender for Endpoint supports various methods for onboarding devices, including Group Policy, Microsoft Endpoint Configuration Manager (SCCM), local script, and Microsoft Intune, to accommodate different organizational needs and infrastructures.
- Intune is ideal for modern, cloud-managed devices.
- GPO/SCCM for on-premises/hybrid environments.
- Local script for small scale or testing.
- APIs for custom, advanced deployments.
Memory trick: Onboarding devices needs to be scalable, automated, and fit existing management.
Windows Defender Application Control (WDAC)
Flip cardWindows Defender Application Control (WDAC) is a security feature that restricts which applications are allowed to run on Windows devices by creating policies that define trusted executables.
- Blocks untrusted applications from launching.
- Can be configured to whitelist (allow only specific apps) or blacklist (block specific apps).
- Rules can be based on publisher, file path, hash, or process.
- Critical for preventing unauthorized software and malware execution.
Memory trick: Remember, to 'Control' 'Applications' from 'Launching', use 'Application Control' to 'Block' them.
Defender for Endpoint EDR
Flip cardEndpoint Detection and Response (EDR) in Microsoft Defender for Endpoint continuously monitors endpoint activity, detects advanced threats and post-breach behaviors, and provides investigation and response capabilities.
- Focuses on post-execution detection and behavioral analysis.
- Identifies sophisticated attacks like fileless malware, supply chain attacks, and lateral movement.
- Provides deep visibility into endpoint events (processes, network, files, registry).
- Enables automated investigation and remediation.
Memory trick: For POST-EXECUTION suspicious behavior, EDR is the DETECTIVE.
Exchange Hybrid Deployment
Flip cardA configuration that integrates an on-premises Exchange organization with Exchange Online, allowing for seamless co-existence, bi-directional mail flow, and gradual mailbox migration.
- Provides a unified address book and calendaring.
- Enables moving mailboxes between on-premises and cloud.
- Requires the Exchange Hybrid Configuration Wizard (HCW).
Memory trick: Hybrid deployment: The best of both mail worlds.
DNS MX Record
Flip cardA Mail Exchanger (MX) record is a type of resource record in the Domain Name System (DNS) that specifies a mail server responsible for accepting email messages on behalf of a recipient's domain.
- Essential for email delivery.
- Points to the mail server (e.g., Exchange Online).
- Multiple MX records can be used for redundancy with priority settings.
Memory trick: MX marks the spot where mail goes, like a postal code for your domain's inbox.
Microsoft 365 Customer Key
Flip cardA Microsoft 365 feature that allows customers to provide and manage their own encryption keys for data at rest in eligible Microsoft 365 services.
- Enhances data privacy and control for customers.
- Uses Azure Key Vault for key management.
- Applies to Exchange Online, SharePoint Online, OneDrive, and Teams data (via underlying services).
Memory trick: Imagine your data as a treasure chest; Customer Key is like using your own special lock and key.
Microsoft Entra Access Reviews for Guests
Flip cardMicrosoft Entra Access Reviews allow organizations to efficiently manage group memberships, access to enterprise applications, and role assignments by regularly reviewing who has access.
- Can be configured to review guest user access periodically.
- Enables automatic removal of guest users who are not approved.
- Helps ensure compliance and reduces stale access for external users.
Memory trick: Access Reviews review who stays, PIM is for privileged ways, Entitlement Management grants, Conditional Access commands.
Test-FederationTrust Cmdlet
Flip cardA PowerShell cmdlet used in Exchange Online or Azure AD PowerShell to verify the health and configuration of the federation trust with an on-premises Active Directory Federation Services (AD FS) environment.
- Diagnoses issues with federated authentication.
- Checks connectivity and certificate validity.
- Helps troubleshoot intermittent sign-in problems.
- Requires Exchange Online PowerShell or Azure AD PowerShell.
Memory trick: Test-FederationTrust is your federation's health check, ensuring the trust bridge isn't broken.
Microsoft Entra Connect Topology: Multiple Forests, Single Microsoft Entra Tenant
Flip cardA Microsoft Entra Connect deployment topology where identities from multiple on-premises Active Directory forests (trusted or untrusted) are synchronized to a single Microsoft Entra ID tenant.
- Supports multiple AD forests, even if they are not trusted.
- Requires a single Microsoft Entra Connect sync server or multiple servers in staging mode.
- Common in mergers, acquisitions, or complex enterprise environments.
- Ensures a unified identity platform in Microsoft Entra ID.
Memory trick: Multiple Forests, Single Cloud: United in Entra.
Principle of Least Privilege
Flip cardA security best practice dictating that users and services should only be granted the minimum permissions necessary to perform their required tasks.
- Reduces the attack surface and potential damage from compromised accounts.
- Requires careful selection of roles and permissions.
- Often involves using built-in roles or creating custom roles.
Memory trick: Think of roles as different keys, each opening specific doors in your Microsoft 365 castle.
Service Principal for Applications
Flip cardA security identity that represents an application in a specific Microsoft Entra tenant. It defines what the application can do in that tenant, which users can access it, and what resources it can access.
- Represents the application itself, not a user.
- Used for applications that need to authenticate and access resources without a user context (e.g., background services, daemons).
- Permissions granted to a service principal are 'application permissions'.
- Each application has one application object (global) and one or more service principals (tenant-specific).
Memory trick: Service Principal: Service Power, No User Required.
Conditional Access Policies
Flip cardMicrosoft Entra Conditional Access policies are if-then statements that define conditions under which users can access resources. They are used to enforce organizational policies like requiring MFA, blocking access from untrusted locations, or enforcing device compliance.
- If-then statements for access control.
- Combines signals like user, location, device, application.
- Enforces requirements like MFA, compliant devices, approval.
Memory trick: Conditional Access: Conditions Control Entry
Microsoft 365 Service Health Dashboard
Flip cardA centralized dashboard in the Microsoft 365 admin center that provides real-time information about the status and health of Microsoft 365 services, including incident reports and planned maintenance.
- Communicates service incidents and advisories.
- Provides status updates and estimated resolution times.
- Helps administrators understand service impact and communicate with users.
Memory trick: Service Health is Microsoft's traffic light for their cloud services: Green means go, Yellow means caution (they know!), Red means stop (major issue).
Conditional Access Named Locations
Flip cardA feature in Microsoft Entra Conditional Access that allows administrators to define trusted IP address ranges or countries/regions.
- Used in Conditional Access policies to include or exclude users based on their network origin.
- Can mark IP ranges as 'trusted' to reduce MFA prompts.
- Enhances security by enforcing stricter controls for connections from untrusted locations.
Memory trick: Location Matters for Access Control.
Microsoft Entra Connect Domain Filtering
Flip cardMicrosoft Entra Connect Domain filtering allows administrators to select which on-premises Active Directory domains are included in the synchronization process to Microsoft Entra ID. This is a high-level filtering mechanism to manage identity flow from multi-domain or multi-forest environments.
- Selects entire AD domains for sync.
- Configured during Microsoft Entra Connect installation.
- Useful in multi-domain or multi-forest scenarios.
Memory trick: Scope: Domains Define the Boundary
Exchange Administrator Role
Flip cardThe Exchange Administrator role in Microsoft 365 grants permissions to manage Exchange Online features, including mailboxes, distribution lists, mail flow rules, and compliance settings. It is a specialized administrative role that adheres to the principle of least privilege for email-related management.
- Manages recipients (mailboxes, groups, contacts).
- Manages mail flow and transport rules.
- Can configure Exchange Online settings.
- Does not have permissions outside of Exchange Online services.
Memory trick: Mailbox tasks? Exchange Admin is your expert, no more, no less.
Defender for Endpoint Onboarding with Azure Arc
Flip cardFor Windows Server 2019 and newer, Azure Arc for Servers provides a streamlined and recommended method to onboard servers to Microsoft Defender for Endpoint's unified solution, extending Azure management capabilities to hybrid environments.
- Recommended for Server 2019+ (and Linux servers).
- Extends Azure management to on-premises/other cloud servers.
- Enables Defender for Endpoint as an Azure extension.
- Provides a unified control plane in Azure.
Memory trick: Remember, for 'Servers' to join 'Defender's Unified' team, 'Azure Arc' is the 'Bridge'.
Defender for Endpoint Unified Solution for Servers
Flip cardThe unified solution for Microsoft Defender for Endpoint extends advanced threat protection, EDR, and automated investigation and remediation capabilities to Windows Server operating systems.
- Provides full Defender for Endpoint capabilities on servers.
- Supports various Windows Server versions, including 2019.
- Includes EDR, vulnerability management, and automated incident response features.
Memory trick: Servers need a UNIFIED shield for full endpoint defense.
Defender for Endpoint Data Retention
Flip cardMicrosoft Defender for Endpoint allows administrators to configure the retention period for security events collected from endpoints, ensuring compliance and forensic readiness.
- Default retention is 30 days.
- Can be extended up to 180 days (or more with specific licenses/integrations).
- Configured in Defender for Endpoint settings.
Memory trick: Remember, the 'Endpoint's Data' has a 'Retention' 'Setting' that controls its 'Time'.
Defender for Identity Sensor Proxy Configuration
Flip cardThe Microsoft Defender for Identity Lightweight Sensor, installed on domain controllers, can be configured to use a proxy server to communicate with the Defender for Identity cloud service, especially for isolated network segments.
- Lightweight Sensor deployed directly on domain controllers.
- Proxy configuration allows communication without direct internet access.
- Required for DCs in isolated or air-gapped networks.
- Ensures identity threat detection from all DCs.
Memory trick: Remember, for 'Isolated' 'DCs', the 'Defender for Identity Sensor' needs a 'Proxy' to 'Connect'.
Next-generation protection
Flip cardThe core antivirus and anti-malware capabilities of Microsoft Defender for Endpoint, utilizing behavioral analysis, heuristics, and cloud-delivered protection to detect and block threats in real-time, even when devices are offline.
- Includes antivirus, anti-malware, and behavioral monitoring.
- Leverages cloud-delivered protection for up-to-date threat intelligence.
- Provides offline protection against known threats.
Memory trick: Next-gen protection is like a smart guard, always on duty, even when the internet is off.
Microsoft Entra Connect Sync Service Manager
Flip cardThe Microsoft Entra Connect Synchronization Service Manager is a tool used to configure advanced synchronization settings, including custom synchronization rules, attribute flow, and connector space management.
- Enables granular control over identity synchronization.
- Essential for complex multi-forest environments and schema extensions.
- Allows for creation and modification of inbound and outbound synchronization rules.
Memory trick: Connect Health checks health, Sync Manager handles rules, Cloud Sync is lightweight, PTA is for authentication.
Azure AD Naming Convention for Microsoft 365 Groups
Flip cardA feature in Azure AD that enforces a naming policy for Microsoft 365 Groups, allowing administrators to define prefixes, suffixes, and a list of blocked words for group names.
- Ensures consistent naming for easier identification and management.
- Prevents inappropriate or sensitive words in group names.
- Applies to groups created in various Microsoft 365 applications.
Memory trick: Think of the Naming Convention as the 'name tag' police for your Microsoft 365 Groups.
Microsoft Entra Connect UPN Matching
Flip cardEnsuring that on-premises User Principal Names (UPNs) match a verified custom domain in Microsoft Entra ID for seamless synchronization and sign-in.
- On-premises UPNs ending in non-routable suffixes (e.g., .local) should be updated.
- The desired UPN suffix must be added and verified as a custom domain in Microsoft Entra ID.
- Consistency between on-premises and cloud UPNs is crucial for user experience and identity matching.
Memory trick: UPN Prep: Verify, Change, Sync.
Defender for Office 365 Mail Flow Rules
Flip cardMail flow rules (transport rules) in Exchange Online Protection (part of Defender for Office 365) allow administrators to identify and take action on messages that flow through their organization.
- Offer granular control over email processing.
- Can be configured with complex conditions and actions (e.g., quarantine, reject, add header).
- Ideal for custom content filtering, compliance, and specific threat scenarios beyond standard policies.
Memory trick: For custom email content, you need a RULE, not just a standard policy.
Defender for Cloud Apps - Defender for Endpoint Integration
Flip cardA powerful integration that enables Microsoft Defender for Cloud Apps to leverage network traffic information from Microsoft Defender for Endpoint-onboarded devices for comprehensive Shadow IT discovery, including applications accessed from unmanaged devices.
- Provides comprehensive cloud app discovery (Shadow IT).
- Leverages network data from Defender for Endpoint.
- Discovers apps on both managed and unmanaged devices.
- Enables risk assessment for discovered apps.
Memory trick: Defender for Endpoint is like the ultimate spy on every device, telling Cloud Apps everything it sees.
CloudAppEvents KQL Table
Flip cardThe `CloudAppEvents` KQL table in Microsoft Defender for Cloud Apps contains records of activities performed by users and applications within connected cloud services.
- Includes login attempts (success/failure).
- Records user agents, IP addresses, activity types.
- Crucial for investigating cloud app security incidents.
- Used in Advanced Hunting queries.
Memory trick: Remember, 'Cloud App' 'Events' are found in the 'CloudAppEvents' table for 'Cloud' 'Login' 'Investigations'.
Azure AD Conditional Access (with MDCA Session Control)
Flip cardAn Azure AD feature that evaluates conditions (e.g., user, device, location) and, if met, enforces specific access controls, including integrating with Microsoft Defender for Cloud Apps for advanced session-level restrictions.
- Requires Azure AD Premium P1 and MDCA license.
- Can apply session controls like 'Block downloads' or 'Require web-only access'.
- Used to enforce security policies based on device compliance or management status.
Memory trick: Conditional Access is the smart bouncer at the cloud club, checking your device's ID and setting rules for your session.
Defender for Office 365 DLP
Flip cardData Loss Prevention (DLP) policies in Microsoft Defender for Office 365 help prevent sensitive information from leaving the organization by identifying, monitoring, and automatically protecting sensitive data across emails, documents, and other services.
- Identifies sensitive information types (SITs).
- Uses keywords, regular expressions, and sensitivity labels.
- Can block, quarantine, or notify based on policy matches.
Memory trick: Office 365 needs varied defenses: phish, spam, bad files, and data leaks.
Microsoft Entra Connect Staging Mode Behavior
Flip cardA Microsoft Entra Connect server in staging mode imports and synchronizes data from connected directories but does not export any changes to Microsoft Entra ID.
- Allows full testing of synchronization configuration without affecting production.
- Used for high availability as a warm standby.
- Prevents accidental exports during initial setup or migration.
Memory trick: If sync works but nothing leaves, Staging Mode often deceives.
Defender Vulnerability Management
Flip cardMicrosoft Defender Vulnerability Management is a module within Microsoft Defender for Endpoint that provides continuous visibility into an organization's vulnerabilities and misconfigurations, prioritizing them based on risk and offering actionable remediation guidance.
- Discovers and assesses software vulnerabilities.
- Identifies misconfigurations.
- Prioritizes based on threat landscape and asset value.
- Provides remediation recommendations.
Memory trick: Investigating requires hunting, managing vulnerabilities, automating responses, and understanding threats.
DeviceTvmSoftwareInventory KQL Table
Flip cardThe `DeviceTvmSoftwareInventory` KQL table in Microsoft Defender XDR Advanced Hunting provides detailed information about installed software on devices, including its version and update status (`IsUpToDate`).
- Populated by Microsoft Defender Vulnerability Management.
- Lists all installed software and its properties.
- Includes `SoftwareName`, `SoftwareVersion`, `IsUpToDate`.
- Essential for identifying outdated software and managing software inventory.
Memory trick: Remember, for 'Device' 'Software' 'Inventory' and 'Vulnerability Management', use 'DeviceTvmSoftwareInventory' to find 'Outdated' apps.
Defender for Cloud Apps Activity Policies
Flip cardActivity policies in Microsoft Defender for Cloud Apps allow you to monitor specific user activities across connected cloud applications based on granular conditions and take actions like alerting or blocking.
- Detects specific actions like file uploads, downloads, logins, and administrative actions.
- Can be customized with filters for users, groups, apps, activity types, and file properties.
- Used for compliance, data loss prevention (DLP), and insider threat detection.
Memory trick: To track SPECIFIC user ACTIONS, you need an ACTIVITY policy.
KQL Join Operator
Flip cardThe `join` operator in Kusto Query Language (KQL) combines rows from two or more tables based on matching values in specified common columns, enabling the correlation of related events or data points.
- Combines rows from different tables.
- Requires a common column for matching.
- Supports various join kinds (inner, leftouter, rightouter, etc.).
- Essential for correlating events over time.
Memory trick: Correlating events means linking them by commonalities, especially over time.
Defender for Endpoint Indicators
Flip cardIndicators in Microsoft Defender for Endpoint allow security teams to define custom detection, prevention, and exclusion rules based on file hashes, IP addresses, URLs/domains, or certificates.
- Can be set to 'Allow', 'Audit', or 'Block'.
- Applied globally across all onboarded devices.
- Effective for blocking known malicious entities like IP addresses or files.
- Supports various indicator types: file hash, IP address, URL/domain, certificate.
Memory trick: To BLOCK a specific IP ACROSS the org, use an INDICATOR.
KQL DeviceNetworkEvents Table Fields
Flip cardThe `DeviceNetworkEvents` table in Advanced Hunting records network connections, with `LocalIP` and `LocalPort` representing the destination of incoming connections, and `RemoteIP` and `RemotePort` representing the source.
- LocalIP: IP address of the device on which the event occurred (destination for incoming).
- LocalPort: Port on the device on which the event occurred (destination port for incoming).
- RemoteIP: IP address of the remote device (source for incoming).
- RemotePort: Port on the remote device (source port for incoming).
Memory trick: Remember, for 'Network' 'Connections', 'Local' is 'Destination', 'Remote' is 'Source', and 'distinct' finds 'Unique'.
Microsoft Entra Connect Cloud Sync Prerequisites
Flip cardMicrosoft Entra Connect Cloud Sync has specific prerequisites for its agent installation, primarily concerning the operating system version and network connectivity.
- Requires Windows Server 2016 or later for agent host.
- Outbound connectivity to specific Microsoft Entra ID and M365 URLs on port 443.
- Does not require SQL Server; uses an embedded database.
Memory trick: Cloud Sync needs a newer Server OS, outbound connectivity, and no SQL.
Defender for Cloud Apps File Policy
Flip cardA type of policy in Microsoft Defender for Cloud Apps that allows administrators to monitor, classify, and apply governance actions to files stored in connected cloud applications, often leveraging Microsoft Purview Information Protection for content inspection and labeling.
- Scans files in cloud storage for sensitive content.
- Can integrate with Microsoft Purview Information Protection.
- Applies governance actions like encryption, access control, and external sharing restrictions.
- Enforces data compliance and prevents data leakage.
Memory trick: File policies are like a smart librarian, categorizing and protecting every document based on its content.
Event-Based Retention
Flip cardEvent-based retention is a feature within Microsoft Purview retention labels that allows the retention period for content to start based on the occurrence of a specific event, rather than creation or last modification date.
- Retention period triggered by a custom event.
- Ideal for project-based or contract-based retention.
- Requires defining event types and asset IDs for matching.
Memory trick: Events kick off retention, ensuring proper deletion.
Keyword Query Retention Policy
Flip cardA retention policy that uses specific keywords or properties to identify and preserve content across Microsoft 365 workloads, ensuring that only relevant items are retained based on defined criteria.
- Automatically identifies content based on keywords/properties.
- Applies retention to existing and new matching content.
- Efficiently preserves specific types of data for legal or regulatory needs.
Memory trick: Keywords in, retention wins!
Sensitivity Labels with Container Management
Flip cardSensitivity labels applied to containers (SharePoint sites, Teams, Microsoft 365 Groups) allow organizations to enforce access controls, external sharing restrictions, and other settings directly on the container and its content.
- Applies labels to SharePoint sites, Teams, M365 Groups.
- Enforces access control (public/private, specific groups).
- Can restrict external sharing, unmanaged device access.
Memory trick: Labels protect the container, excluding the strainer.
Custom SITs & Auto-labeling
Flip cardCustom Sensitive Information Types (SITs) allow organizations to define unique patterns for sensitive data. Auto-labeling policies then use these SITs to automatically apply sensitivity labels to content, enforcing protection actions like encryption.
- Custom SITs detect unique data patterns.
- Auto-labeling applies labels based on SIT detection.
- Labels enforce protection (encryption, watermarking).
Memory trick: Custom patterns trigger auto-labels, keeping data safe.
Information Barriers (IB)
Flip cardA Microsoft Purview compliance solution that prevents designated groups of users from communicating or collaborating with other groups within an organization.
- Prevents unauthorized communication between user segments.
- Applies to Microsoft Teams, SharePoint, OneDrive, Exchange Online.
- Crucial for preventing conflicts of interest or protecting sensitive info.
- Requires segmenting users based on attributes.
Memory trick: IB: Information Barriers build walls between your teams.
Multi-Geo Capabilities
Flip cardA feature in Microsoft 365 that allows organizations to provision and store user data at rest in specified data center geographies (Geo locations) to meet data residency requirements.
- Enables data residency for Exchange, SharePoint, OneDrive, Teams.
- Data at rest for specific users/groups stored in chosen Geo locations.
- Manages data residency within a single Microsoft 365 tenant.
- Crucial for compliance with local regulatory requirements.
Memory trick: Multi-Geo: Data stays local, no matter the global tenant.
Communication Compliance
Flip cardA Microsoft Purview solution that helps organizations detect, capture, and act on inappropriate messages in Microsoft 365, including policy violations related to sensitive information, harassment, or regulatory non-compliance.
- Monitors communications across Exchange, Teams, Yammer, etc.
- Detects policy violations (e.g., sensitive info, harassment, unapproved channels).
- Provides tools for review, investigation, and remediation.
- Uses machine learning for intelligent detection.
Memory trick: Comm Compliance keeps an eye on your digital chats for rule-breakers.
Sensitivity Labels (MPIP)
Flip cardLabels applied to content (documents, emails) to classify it and enforce protection actions like encryption and usage restrictions, which persist with the content.
- Classify data based on sensitivity.
- Apply encryption and access restrictions (e.g., Do Not Forward, Do Not Print).
- Protection persists with the content, even when shared externally.
- Integrates with Microsoft Office apps.
Memory trick: Labels tag and lock your secrets, even when they travel.