Free knowledge base

Microsoft 365 Certified: Administrator Expert — key terms, tricks & tips

Everything from the course in one searchable place: 208 entries. Use it to review before a practice test or look up a word you forgot.

208 results

Key term

Scaled Scoring

Exam scoring method where raw scores are converted to a standardized scale.

Getting Started: Exam Overview

Key term

Skill Area

Major topic categories on the exam, each with a percentage weight.

Getting Started: Exam Overview

Key term

Case Study

Exam question type presenting a scenario with multiple related questions.

Getting Started: Exam Overview

Key term

Lab Simulation

Interactive exam questions requiring tasks in a simulated environment.

Getting Started: Exam Overview

Key term

Official Exam Guide

Microsoft's definitive document outlining exam objectives and content.

Getting Started: Exam Overview

Key term

Multiple-Response

Question type requiring selection of all correct answers from a list.

Getting Started: Exam Overview

Key term

Prerequisites

Prior knowledge or certifications recommended before taking an exam.

Getting Started: Exam Overview

Memory trick

Understanding the MS-102 Exam Structure

To remember the scoring: 700 to heaven! You need 700 points to reach the 'heaven' of passing the exam.

Getting Started: Exam Overview

Exam tip

Understanding the MS-102 Exam Structure

The MS-102 exam is a prerequisite for the Microsoft 365 Certified: Administrator Expert certification. You must also hold one of several prerequisite associate-level certifications, such as Microsoft 365 Certified: Endpoint Administrator Associate, Microsoft 365 Certified: Messaging Administrator Associate, or Microsoft 365 Certified: Teams Administrator Associate. Make sure you have one of these before taking MS-102.

Getting Started: Exam Overview

Common mistake

Understanding the MS-102 Exam Structure

Ignoring the official exam guide and relying only on third-party study materials.

Getting Started: Exam Overview

Common mistake

Understanding the MS-102 Exam Structure

Not practicing hands-on in a lab environment, especially for complex configurations.

Getting Started: Exam Overview

Common mistake

Understanding the MS-102 Exam Structure

Spending too much time on topics you already know well, instead of focusing on weaker areas.

Getting Started: Exam Overview

Key term

Lab Environment

An isolated, non-production space for testing and learning.

Getting Started: Exam Overview

Key term

Trial Tenant

A temporary, full-featured Microsoft 365 subscription for evaluation.

Getting Started: Exam Overview

Key term

Developer Program

Microsoft program offering free, renewable E5 subscriptions for development.

Getting Started: Exam Overview

Key term

Sandbox

An isolated testing environment, often with sample data.

Getting Started: Exam Overview

Key term

Tenant

A dedicated instance of Microsoft 365 services for an organization.

Getting Started: Exam Overview

Key term

E5 License

Microsoft's most comprehensive enterprise subscription plan.

Getting Started: Exam Overview

Key term

onmicrosoft.com

The default domain name for new Microsoft 365 tenants.

Getting Started: Exam Overview

Key term

PowerShell

A command-line shell and scripting language for administration.

Getting Started: Exam Overview

Memory trick

Setting Up Your Microsoft 365 Lab Environment

LAB: L-earn, A-utomate, B-uild. Use your lab to Learn, Automate, and Build your skills!

Getting Started: Exam Overview

Exam tip

Setting Up Your Microsoft 365 Lab Environment

The MS-102 exam expects you to know the purpose and benefits of using a lab environment for testing configurations and policies. Be aware of the differences between trial tenants and developer subscriptions, especially regarding their longevity and included features (e.g., E5 license in developer program).

Getting Started: Exam Overview

Common mistake

Setting Up Your Microsoft 365 Lab Environment

Not using a lab environment at all, relying only on theoretical knowledge.

Getting Started: Exam Overview

Common mistake

Setting Up Your Microsoft 365 Lab Environment

Testing critical configurations directly in a production environment without prior lab validation.

Getting Started: Exam Overview

Common mistake

Setting Up Your Microsoft 365 Lab Environment

Forgetting to clean up lab resources, leading to confusion or potential security risks.

Getting Started: Exam Overview

Common mistake

Setting Up Your Microsoft 365 Lab Environment

Letting a trial tenant expire before completing your learning objectives.

Getting Started: Exam Overview

Key term

Custom Domain

Your organization's unique internet domain (e.g., yourcompany.com).

Microsoft 365 Tenant Management

Key term

DNS Records

Entries in a Domain Name System that map domain names to IP addresses.

Microsoft 365 Tenant Management

Key term

Global Administrator

The highest level of administrative privilege in Microsoft 365.

Microsoft 365 Tenant Management

Key term

Security Defaults

Baseline security policies like MFA, automatically enabled for new tenants.

Microsoft 365 Tenant Management

Key term

Service Health

Dashboard showing the operational status of Microsoft 365 services.

Microsoft 365 Tenant Management

Key term

Data Residency

The geographic location where an organization's data is stored.

Microsoft 365 Tenant Management

Memory trick

Deploying & Managing Your M365 Tenant

To remember the domain verification steps: 'Add, Get, Go, Wait, Verify'. Add the domain, Get the DNS record, Go to your registrar, Wait for propagation, then Verify in M365.

Microsoft 365 Tenant Management

Exam tip

Deploying & Managing Your M365 Tenant

For the exam, remember that the '.onmicrosoft.com' domain is always retained and cannot be removed, even after adding custom domains. Know the common DNS record types (TXT, MX, CNAME, SRV) used for Microsoft 365 services.

Microsoft 365 Tenant Management

Common mistake

Deploying & Managing Your M365 Tenant

Forgetting to add required DNS records for custom domain verification, leading to services not working.

Microsoft 365 Tenant Management

Common mistake

Deploying & Managing Your M365 Tenant

Not enabling Security Defaults early on, leaving the tenant vulnerable to common attacks.

Microsoft 365 Tenant Management

Common mistake

Deploying & Managing Your M365 Tenant

Ignoring the Service Health dashboard, missing critical updates or outages that affect users.

Microsoft 365 Tenant Management

Key term

Subscription Plan

A bundle of Microsoft 365 services with specific features.

Microsoft 365 Tenant Management

Key term

License

A per-user entitlement to use Microsoft 365 services.

Microsoft 365 Tenant Management

Key term

Microsoft 365 Admin Center

Web portal for managing Microsoft 365 services and users.

Microsoft 365 Tenant Management

Key term

Org Settings

Tenant-wide configurations affecting all users and services.

Microsoft 365 Tenant Management

Key term

Multi-Geo

Microsoft 365 feature for storing data in multiple geographic regions.

Microsoft 365 Tenant Management

Key term

CSP

Cloud Solution Provider, a partner selling Microsoft cloud services.

Microsoft 365 Tenant Management

Memory trick

Managing Microsoft 365 Subscriptions & Org Settings

Remember 'LICENSES' for how to manage: L-Look at needs, I-Identify plan, C-Choose provider, E-Enroll licenses, N-Nail assignments, S-Set org settings, E-Evaluate costs, S-Stay compliant.

Microsoft 365 Tenant Management

Exam tip

Managing Microsoft 365 Subscriptions & Org Settings

The exam often tests your knowledge of specific features included in different Enterprise (E3 vs. E5) and Business (Basic vs. Standard vs. Premium) subscription plans. Memorize the key differentiators, especially around advanced security, compliance, and analytics features.

Microsoft 365 Tenant Management

Common mistake

Managing Microsoft 365 Subscriptions & Org Settings

Over-licensing users with features they don't need, leading to unnecessary costs.

Microsoft 365 Tenant Management

Common mistake

Managing Microsoft 365 Subscriptions & Org Settings

Not periodically reviewing subscription usage and billing, missing optimization opportunities.

Microsoft 365 Tenant Management

Common mistake

Managing Microsoft 365 Subscriptions & Org Settings

Ignoring data residency requirements, potentially leading to non-compliance and legal issues.

Microsoft 365 Tenant Management

Common mistake

Managing Microsoft 365 Subscriptions & Org Settings

Not configuring global organizational settings to align with company policies, creating security gaps.

Microsoft 365 Tenant Management

Key term

Multi-Factor Authentication (MFA)

Requires two or more verification factors for access.

Microsoft 365 Tenant Management

Key term

Conditional Access

Policy engine enforcing access controls based on conditions.

Microsoft 365 Tenant Management

Key term

Password Hash Sync (PHS)

Synchronizes password hashes from on-premises AD to Azure AD.

Microsoft 365 Tenant Management

Key term

Pass-through Authentication (PTA)

Validates on-premises AD passwords directly against on-premises domain controllers.

Microsoft 365 Tenant Management

Key term

Self-Service Password Reset (SSPR)

Allows users to reset their own passwords without admin help.

Microsoft 365 Tenant Management

Key term

FIDO2 Security Key

A hardware device used for passwordless authentication.

Microsoft 365 Tenant Management

Memory trick

Implementing & Managing User Authentication

MFA: 'More Factors Always' makes your account safer.

Microsoft 365 Tenant Management

Exam tip

Implementing & Managing User Authentication

The exam often distinguishes between Security Defaults (free, basic MFA for all) and Conditional Access (premium, granular control). Remember that Conditional Access requires Microsoft Entra ID P1 or P2 licenses.

Microsoft 365 Tenant Management

Common mistake

Implementing & Managing User Authentication

Not understanding the difference between Security Defaults and Conditional Access for MFA enforcement.

Microsoft 365 Tenant Management

Common mistake

Implementing & Managing User Authentication

Forgetting that Conditional Access requires premium Microsoft Entra ID licenses.

Microsoft 365 Tenant Management

Common mistake

Implementing & Managing User Authentication

Overlooking the importance of testing Conditional Access policies in report-only mode before full enforcement.

Microsoft 365 Tenant Management

Key term

Role-Based Access Control (RBAC)

System for delegating permissions based on job functions.

Microsoft 365 Tenant Management

Key term

Principle of Least Privilege

Granting only the minimum necessary permissions for a task.

Microsoft 365 Tenant Management

Key term

User Principal Name (UPN)

Unique identifier for a user account, typically their email address.

Microsoft 365 Tenant Management

Key term

Security Group

Used to grant access to resources and for email distribution.

Microsoft 365 Tenant Management

Key term

Microsoft 365 Group

Collaboration group with shared mailbox, calendar, files, etc.

Microsoft 365 Tenant Management

Key term

Distribution Group

Used solely for sending emails to a collection of users.

Microsoft 365 Tenant Management

Key term

Dynamic Security Group

Group with membership automatically updated based on rules.

Microsoft 365 Tenant Management

Memory trick

Managing Roles, Assignments, Users & Groups

Remember 'GLUE' for Group types: Global (Admin), Least (Privilege), Users (Admin), Exchange (Admin). This helps recall key roles and principles.

Microsoft 365 Tenant Management

Exam tip

Managing Roles, Assignments, Users & Groups

The exam frequently tests your knowledge of which specific administrative role is required for a given task. Memorize the core responsibilities of Global Administrator, User Administrator, Exchange Administrator, and SharePoint Administrator. Also, know the differences between Security Groups and Microsoft 365 Groups.

Microsoft 365 Tenant Management

Common mistake

Managing Roles, Assignments, Users & Groups

Over-assigning the Global Administrator role: This is a common security risk. Only a very small number of trusted individuals should hold this role.

Microsoft 365 Tenant Management

Common mistake

Managing Roles, Assignments, Users & Groups

Not using groups for role assignments: Managing individual user role assignments is inefficient and prone to errors in larger environments.

Microsoft 365 Tenant Management

Common mistake

Managing Roles, Assignments, Users & Groups

Forgetting to offboard users properly: This leaves dormant accounts that can be security vulnerabilities or consume unnecessary licenses.

Microsoft 365 Tenant Management

Key term

Microsoft Entra ID

Cloud-based identity and access management service.

Microsoft Entra ID Implementation

Key term

Dynamic Group

Group whose membership is automatically managed by rules.

Microsoft Entra ID Implementation

Key term

Entra ID Joined

Device owned by organization, joined directly to Entra ID.

Microsoft Entra ID Implementation

Key term

Privileged Identity Management (PIM)

Manages, controls, and monitors access to important resources.

Microsoft Entra ID Implementation

Memory trick

Implementing & Managing Microsoft Entra ID

Think of Entra ID as the 'ID card' for all your cloud apps and devices. It verifies 'who' you are and 'what' you can do.

Microsoft Entra ID Implementation

Exam tip

Implementing & Managing Microsoft Entra ID

The exam often tests the distinction between Entra ID registered, Entra ID joined, and Hybrid Entra ID joined devices. Memorize their characteristics and use cases.

Microsoft Entra ID Implementation

Common mistake

Implementing & Managing Microsoft Entra ID

Confusing Entra ID with on-premises Active Directory; they are distinct services.

Microsoft Entra ID Implementation

Common mistake

Implementing & Managing Microsoft Entra ID

Not implementing MFA for all administrative accounts, leaving a major security gap.

Microsoft Entra ID Implementation

Common mistake

Implementing & Managing Microsoft Entra ID

Over-provisioning permissions by assigning users to too many high-privilege roles instead of using least privilege.

Microsoft Entra ID Implementation

Key term

Pass-Through Auth (PTA)

Authenticates users by validating passwords against on-prem AD.

Microsoft Entra ID Implementation

Key term

Synchronization Engine

Core component applying rules for object flow.

Microsoft Entra ID Implementation

Key term

Metaverse

Central identity store within Entra Connect.

Microsoft Entra ID Implementation

Key term

Entra Connect Health

Monitoring service for Entra Connect and AD FS.

Microsoft Entra ID Implementation

Key term

Staging Server

Secondary Entra Connect server for testing/failover.

Microsoft Entra ID Implementation

Key term

Synchronization Rules

Define how attributes flow between directories.

Microsoft Entra ID Implementation

Key term

Connector Space

Staging area for objects from connected directories.

Microsoft Entra ID Implementation

Memory trick

Implementing & Managing Microsoft Entra Connect

PHS is 'Password Hashes Sent' – simple and secure. PTA is 'Pass Through Authenticate' – like a bouncer checking ID at the door. AD FS is 'Active Directory Federated Services' – for complex, on-prem authentication.

Microsoft Entra ID Implementation

Exam tip

Implementing & Managing Microsoft Entra Connect

The exam frequently tests on the different authentication methods (PHS, PTA, AD FS) and when to use each. Pay close attention to the components of Entra Connect and how to monitor its health using Entra Connect Health.

Microsoft Entra ID Implementation

Common mistake

Implementing & Managing Microsoft Entra Connect

Not planning filtering before initial synchronization, leading to unwanted objects in Microsoft Entra ID.

Microsoft Entra ID Implementation

Common mistake

Implementing & Managing Microsoft Entra Connect

Ignoring Microsoft Entra Connect Health alerts, which can lead to unnoticed synchronization failures.

Microsoft Entra ID Implementation

Common mistake

Implementing & Managing Microsoft Entra Connect

Directly modifying synchronization rules without proper testing on a staging server, potentially breaking identity flow.

Microsoft Entra ID Implementation

Key term

Microsoft Entra Registered

Personal devices signed in with a Microsoft Entra account.

Microsoft Entra ID Implementation

Key term

Microsoft Entra Joined

Corporate devices exclusively managed by Microsoft Entra ID.

Microsoft Entra ID Implementation

Key term

Hybrid Microsoft Entra Joined

Corporate devices joined to on-premises AD and registered with Entra ID.

Microsoft Entra ID Implementation

Key term

Multifactor Authentication (MFA)

Requires two or more verification methods for login.

Microsoft Entra ID Implementation

Memory trick

Managing Microsoft Entra ID Identities

For Device Types: R-J-H. Registered is 'R'egular (personal), Joined is 'J'ust Entra, Hybrid is 'H'alf-and-half (AD + Entra).

Microsoft Entra ID Implementation

Exam tip

Managing Microsoft Entra ID Identities

The exam frequently tests your understanding of the different types of user and device identities (cloud-only, synced, guest; registered, joined, hybrid joined) and when to use each. Pay close attention to the characteristics and management methods for each type.

Microsoft Entra ID Implementation

Common mistake

Managing Microsoft Entra ID Identities

Not enabling MFA for all users, especially administrators, leaving accounts vulnerable.

Microsoft Entra ID Implementation

Common mistake

Managing Microsoft Entra ID Identities

Granting excessive permissions (over-privileging) to users or groups, violating the principle of least privilege.

Microsoft Entra ID Implementation

Common mistake

Managing Microsoft Entra ID Identities

Failing to regularly review and clean up stale or unused user, group, and device accounts, creating security risks.

Microsoft Entra ID Implementation

Key term

Access Reviews

Periodically verifying who has access to resources.

Microsoft Entra ID Implementation

Key term

Entitlement Management

Automates access lifecycle for internal and external users.

Microsoft Entra ID Implementation

Key term

Access Package

A bundle of resources for a user to request.

Microsoft Entra ID Implementation

Key term

Just-in-Time (JIT) Access

Granting temporary, time-bound access to resources.

Microsoft Entra ID Implementation

Key term

Access Lifecycle

The process of granting, reviewing, and revoking access.

Microsoft Entra ID Implementation

Memory trick

Implementing & Managing Entra ID Governance

P-A-E: PIM for Privileged, Access Reviews for Auditing, Entitlement Management for Everyone (especially external).

Microsoft Entra ID Implementation

Exam tip

Implementing & Managing Entra ID Governance

The exam frequently tests on the specific use cases for each governance feature. Remember that Access Reviews are for periodic verification, Entitlement Management is for lifecycle management (especially for external users and projects), and PIM is for securing privileged roles with JIT access.

Microsoft Entra ID Implementation

Common mistake

Implementing & Managing Entra ID Governance

Confusing the primary purpose of PIM with Entitlement Management. PIM focuses on privileged roles, while Entitlement Management handles general user access lifecycle.

Microsoft Entra ID Implementation

Common mistake

Implementing & Managing Entra ID Governance

Forgetting to configure automatic actions (like removal of access) after an access review, which can negate its security benefits.

Microsoft Entra ID Implementation

Common mistake

Implementing & Managing Entra ID Governance

Not understanding that Entitlement Management requires users to request access packages, rather than being directly assigned resources.

Microsoft Entra ID Implementation

Key term

Defender XDR

Extended Detection and Response; unified security platform.

Microsoft Defender XDR Implementation

Key term

Cross-domain correlation

Linking alerts across different security products.

Microsoft Defender XDR Implementation

Key term

Microsoft Defender portal

Central web interface for managing Defender XDR.

Microsoft Defender XDR Implementation

Key term

Advanced hunting

Proactive threat detection using KQL queries.

Microsoft Defender XDR Implementation

Key term

Kusto Query Language (KQL)

Powerful language for querying security data.

Microsoft Defender XDR Implementation

Key term

Automated investigation

System-driven analysis of alerts and incidents.

Microsoft Defender XDR Implementation

Key term

Action center

Central hub for pending and completed remediation actions.

Microsoft Defender XDR Implementation

Memory trick

Implementing & Managing Microsoft Defender XDR

Think of XDR as an 'eXtraordinary Detective Robot' that connects all the clues (signals) from different places (endpoints, emails, identities) to solve the whole mystery (incident).

Microsoft Defender XDR Implementation

Exam tip

Implementing & Managing Microsoft Defender XDR

The exam will test your understanding of how Defender XDR integrates its component services (Endpoint, O365, Identity, Cloud Apps) into a single, unified platform. Look for questions about 'cross-domain correlation' and 'unified incident management' as key benefits.

Microsoft Defender XDR Implementation

Common mistake

Implementing & Managing Microsoft Defender XDR

Treating Defender XDR components as separate, siloed products instead of an integrated platform.

Microsoft Defender XDR Implementation

Common mistake

Implementing & Managing Microsoft Defender XDR

Not utilizing the 'Advanced hunting' feature for proactive threat detection and deeper investigations.

Microsoft Defender XDR Implementation

Common mistake

Implementing & Managing Microsoft Defender XDR

Failing to configure automated investigation and remediation, leading to slower incident response.

Microsoft Defender XDR Implementation

Key term

Endpoint Detection and Response (EDR)

Capabilities to detect, investigate, and respond to advanced threats on endpoints.

Microsoft Defender XDR Implementation

Key term

Attack Surface Reduction (ASR)

Set of capabilities that harden devices against common attack vectors.

Microsoft Defender XDR Implementation

Key term

Live Response

Allows security analysts to gain immediate remote access to a device for investigation.

Microsoft Defender XDR Implementation

Key term

Automated Investigation and Remediation

MDE feature that automatically investigates alerts and resolves common threats.

Microsoft Defender XDR Implementation

Key term

Threat & Vulnerability Management (TVM)

Continuously discovers, prioritizes, and remediates software vulnerabilities.

Microsoft Defender XDR Implementation

Key term

Onboarding Package

Configuration file or script used to connect a device to the MDE service.

Microsoft Defender XDR Implementation

Key term

Microsoft 365 Defender Portal

Unified portal for managing all Microsoft 365 Defender services.

Microsoft Defender XDR Implementation

Memory trick

Implementing & Managing Defender for Endpoint

EDR: Every Device Reacts. Remember that EDR is about detecting and reacting to threats on individual devices.

Microsoft Defender XDR Implementation

Exam tip

Implementing & Managing Defender for Endpoint

The exam frequently tests your understanding of MDE's core capabilities (ASR, EDR, Next-gen AV, TVM) and how devices are onboarded. Pay close attention to the various onboarding methods and their use cases.

Microsoft Defender XDR Implementation

Common mistake

Implementing & Managing Defender for Endpoint

Forgetting to onboard all relevant device types, leaving security gaps.

Microsoft Defender XDR Implementation

Common mistake

Implementing & Managing Defender for Endpoint

Not configuring Attack Surface Reduction rules, missing a key preventative measure.

Microsoft Defender XDR Implementation

Common mistake

Implementing & Managing Defender for Endpoint

Failing to integrate MDE with other Defender services, losing out on cross-domain correlation benefits.

Microsoft Defender XDR Implementation

Key term

Safe Attachments

Sandboxes email attachments to detect unknown malware.

Microsoft Defender XDR Implementation

Key term

Safe Links

Scans URLs in real-time at the time of click for malicious content.

Microsoft Defender XDR Implementation

Key term

Anti-Phishing

Protects against impersonation and spoofing attacks.

Microsoft Defender XDR Implementation

Key term

Threat Explorer

A tool for security analysts to investigate threats.

Microsoft Defender XDR Implementation

Key term

Automated Investigation and Remediation (AIR)

Automates incident response for detected threats.

Microsoft Defender XDR Implementation

Key term

Dynamic Delivery

Delivers email body while attachments are scanned.

Microsoft Defender XDR Implementation

Key term

Zero-day threat

A vulnerability or exploit unknown to security vendors.

Microsoft Defender XDR Implementation

Memory trick

Implementing & Managing Defender for Office 365

SAFE-T: Safe Attachments, Anti-Phishing, Forensics (Threat Explorer), Email Links (Safe Links), Training (Attack Simulation).

Microsoft Defender XDR Implementation

Exam tip

Implementing & Managing Defender for Office 365

The exam often tests the differences between Defender for Office 365 Plan 1 and Plan 2. Memorize which advanced features (like AIR, Threat Explorer, Attack Simulation Training) are exclusive to Plan 2. Also, understand the default actions and configurable options for Safe Attachments, Safe Links, and Anti-Phishing policies.

Microsoft Defender XDR Implementation

Common mistake

Implementing & Managing Defender for Office 365

Not configuring anti-phishing policies for high-profile users (e.g., C-suite executives).

Microsoft Defender XDR Implementation

Common mistake

Implementing & Managing Defender for Office 365

Setting Safe Attachments policies to 'Monitor' instead of 'Block' or 'Dynamic Delivery' in production environments, allowing malicious attachments to reach users.

Microsoft Defender XDR Implementation

Common mistake

Implementing & Managing Defender for Office 365

Failing to regularly review Threat Explorer and other reports, missing critical insights into attack trends and policy effectiveness.

Microsoft Defender XDR Implementation

Key term

Defender for Identity (MDI)

Cloud-based security for on-premises identities and hybrid environments.

Microsoft Defender XDR Implementation

Key term

MDI Sensor

Software installed on domain controllers to monitor traffic and events.

Microsoft Defender XDR Implementation

Key term

Defender for Cloud Apps (MDCA)

CASB solution for visibility, control, and protection of cloud apps.

Microsoft Defender XDR Implementation

Key term

Cloud Access Security Broker (CASB)

Software that sits between cloud service users and cloud applications.

Microsoft Defender XDR Implementation

Key term

Shadow IT

Cloud applications used without IT department knowledge or approval.

Microsoft Defender XDR Implementation

Key term

Conditional Access App Control (CAAC)

MDCA feature using reverse proxy for real-time session monitoring.

Microsoft Defender XDR Implementation

Key term

API Connector

Integration method for MDCA to deeply connect with sanctioned cloud apps.

Microsoft Defender XDR Implementation

Key term

Lateral Movement

Technique used by attackers to move through a network after initial access.

Microsoft Defender XDR Implementation

Memory trick

Implementing & Managing Defender for Identity & Cloud Apps

Identity is ON-PREM (MDI on Domain Controllers). Cloud Apps are IN THE CLOUDS (MDCA with APIs/Proxies).

Microsoft Defender XDR Implementation

Exam tip

Implementing & Managing Defender for Identity & Cloud Apps

The exam often asks about the primary function and deployment method for each service. Remember MDI protects on-premises/hybrid identities via sensors on DCs, while MDCA protects cloud apps via API connectors, log collectors, and reverse proxy for CASB functionality.

Microsoft Defender XDR Implementation

Common mistake

Implementing & Managing Defender for Identity & Cloud Apps

Confusing MDI's role with Defender for Endpoint; MDI protects identities, not devices.

Microsoft Defender XDR Implementation

Common mistake

Implementing & Managing Defender for Identity & Cloud Apps

Assuming MDCA only works with Microsoft cloud apps; it protects a wide range of third-party SaaS apps.

Microsoft Defender XDR Implementation

Common mistake

Implementing & Managing Defender for Identity & Cloud Apps

Forgetting that MDI sensors are agentless on domain controllers, not agents on every workstation.

Microsoft Defender XDR Implementation

Key term

Microsoft Purview

Unified suite for data governance, protection, and compliance.

Microsoft Purview Compliance

Key term

Data Loss Prevention (DLP)

Policies to prevent sensitive data from leaving the organization.

Microsoft Purview Compliance

Key term

eDiscovery

Tools to identify, preserve, and collect electronic data for legal cases.

Microsoft Purview Compliance

Key term

Communication Compliance

Monitors internal/external communications for policy violations.

Microsoft Purview Compliance

Key term

Compliance Manager

Assesses and improves an organization's compliance score.

Microsoft Purview Compliance

Key term

Sensitive Information Types

Predefined or custom patterns to identify sensitive data.

Microsoft Purview Compliance

Key term

Compliance Portal

Centralized web interface for managing Purview solutions.

Microsoft Purview Compliance

Key term

Legal Hold

Preserves electronic data for legal or investigative purposes.

Microsoft Purview Compliance

Memory trick

Implementing & Managing Microsoft Purview Compliance

PURVIEW: P-Protect, U-Understand, R-Regulate, V-Validate, I-Identify, E-Enforce, W-Watch. It's how you keep your data safe!

Microsoft Purview Compliance

Exam tip

Implementing & Managing Microsoft Purview Compliance

The exam often tests your ability to distinguish between different Purview solutions. Remember that DLP is for preventing data loss, eDiscovery for legal holds and investigations, and Communication Compliance for monitoring internal communications. Keywords like 'preventing unauthorized sharing' or 'legal proceedings' are crucial.

Microsoft Purview Compliance

Common mistake

Implementing & Managing Microsoft Purview Compliance

Confusing Data Loss Prevention (DLP) with Information Protection (labeling). DLP prevents actions, while Information Protection classifies data.

Microsoft Purview Compliance

Common mistake

Implementing & Managing Microsoft Purview Compliance

Not understanding that Purview covers data across multiple environments, not just Microsoft 365.

Microsoft Purview Compliance

Common mistake

Implementing & Managing Microsoft Purview Compliance

Failing to regularly review and update compliance policies, leading to outdated or ineffective controls.

Microsoft Purview Compliance

Key term

Sensitivity Label

A tag that classifies data and applies protection actions.

Microsoft Purview Compliance

Key term

Label Policy

Defines which sensitivity labels are available to users.

Microsoft Purview Compliance

Key term

Auto-labeling

Automatic application of sensitivity labels based on content.

Microsoft Purview Compliance

Key term

Sensitive Info Type

Predefined patterns for common sensitive data (e.g., SSN).

Microsoft Purview Compliance

Key term

Encryption

Scrambling data to prevent unauthorized access.

Microsoft Purview Compliance

Memory trick

Implementing & Managing Information Protection

L-A-B-E-L: L for 'Label' the data, A for 'Auto-label' for consistency, B for 'Block' with DLP, E for 'Encrypt' sensitive info, L for 'Limit' access.

Microsoft Purview Compliance

Exam tip

Implementing & Managing Information Protection

The exam often tests your understanding of the relationship between sensitivity labels and DLP policies. Remember that labels classify and protect data at rest and in transit, while DLP focuses on preventing data exfiltration based on content detection.

Microsoft Purview Compliance

Common mistake

Implementing & Managing Information Protection

Confusing sensitivity labels with retention labels; sensitivity labels protect, retention labels govern lifecycle.

Microsoft Purview Compliance

Common mistake

Implementing & Managing Information Protection

Not testing auto-labeling policies thoroughly before full deployment, leading to misclassifications.

Microsoft Purview Compliance

Common mistake

Implementing & Managing Information Protection

Overlooking the need for user education on manual labeling, even with auto-labeling in place.

Microsoft Purview Compliance

Key term

Retention Policy

Broad rules for retaining/deleting content across locations.

Microsoft Purview Compliance

Key term

Retention Label

Granular, item-level rules for retaining/deleting content.

Microsoft Purview Compliance

Key term

Adaptive Scope

Dynamic groups for policy application based on attributes.

Microsoft Purview Compliance

Key term

Disposition Review

Process for human review before content deletion.

Microsoft Purview Compliance

Key term

Event-Based Retention

Retention period starts based on a specific event.

Microsoft Purview Compliance

Key term

Record

Content with strict retention that cannot be modified/deleted.

Microsoft Purview Compliance

Key term

Data Lifecycle Management

Managing data from creation to deletion, ensuring compliance.

Microsoft Purview Compliance

Memory trick

Implementing & Managing Data Lifecycle Management

Remember 'LAP-D': Labels Always Precede Policies for Deletion. This helps recall the precedence of retention rules.

Microsoft Purview Compliance

Exam tip

Implementing & Managing Data Lifecycle Management

The exam often tests the precedence of retention rules: retention labels generally override retention policies, and explicit delete rules override implicit delete rules. Also, understand that content under a legal hold is always retained, regardless of other retention settings.

Microsoft Purview Compliance

Common mistake

Implementing & Managing Data Lifecycle Management

Confusing retention policies with retention labels: Policies are broad, labels are granular.

Microsoft Purview Compliance

Common mistake

Implementing & Managing Data Lifecycle Management

Forgetting that legal holds always take precedence over retention policies/labels.

Microsoft Purview Compliance

Common mistake

Implementing & Managing Data Lifecycle Management

Not understanding the difference between a retention period starting from creation vs. an event.

Microsoft Purview Compliance

Key term

Insider Risk Management (IRM)

Identifies and manages malicious or inadvertent insider activities.

Microsoft Purview Compliance

Key term

Audit (Standard)

Basic logging of M365 activities with 90-day retention.

Microsoft Purview Compliance

Key term

Audit (Premium)

Advanced logging, longer retention, high-value events, and integration.

Microsoft Purview Compliance

Key term

Audit Log Search

Tool in Purview portal to investigate M365 user and admin activities.

Microsoft Purview Compliance

Key term

Indicators

Specific user actions or events monitored by IRM policies.

Microsoft Purview Compliance

Key term

Policy Scope

The group of users or content targeted by an IRM policy.

Microsoft Purview Compliance

Key term

Adaptive Analytics

Machine learning used by IRM to detect evolving risk patterns.

Microsoft Purview Compliance

Memory trick

Insider Risk Management & Audit in Purview

IRM: 'I' for Identify, 'R' for Respond, 'M' for Mitigate. It's about spotting the bad apples and dealing with them!

Microsoft Purview Compliance

Exam tip

Insider Risk Management & Audit in Purview

Memorize the retention periods for Audit (Standard) and Audit (Premium) as they are frequently tested. Audit (Standard) is 90 days, Audit (Premium) is up to 10 years, depending on the activity and license.

Microsoft Purview Compliance

Common mistake

Insider Risk Management & Audit in Purview

Assuming IRM automatically blocks all risky activities; it primarily detects and alerts, requiring admin action.

Microsoft Purview Compliance

Common mistake

Insider Risk Management & Audit in Purview

Not regularly reviewing and updating IRM policies, leading to outdated detection rules or excessive false positives.

Microsoft Purview Compliance

Common mistake

Insider Risk Management & Audit in Purview

Confusing Audit (Standard) with Audit (Premium) capabilities, especially regarding log retention and advanced features.

Microsoft Purview Compliance