Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium

A Microsoft 365 administrator is managing user accounts. The organization has a policy that all user accounts must have a 'Usage Location' attribute set to 'United States' to ensure proper licensing and service availability. The administrator needs to automate the setting of this attribute for all new user accounts created directly in Azure AD. Which method should the administrator use?

  1. AUse PowerShell to set a default value for new user accounts.
  2. BSet the default Usage Location in the Microsoft 365 admin center.
  3. CConfigure an Azure AD Identity Governance entitlement management policy.
  4. DCreate an Azure AD Conditional Access policy.
Show answer & explanation

Correct answer: B. Set the default Usage Location in the Microsoft 365 admin center.

The Microsoft 365 admin center (or Azure AD admin center) allows administrators to set a default 'Usage Location' for all new user accounts created directly within Azure AD. This ensures that the required attribute is automatically applied, simplifying the onboarding process and ensuring compliance with licensing requirements.

Why the other options are wrong

  • A. While PowerShell can be used, setting the default in the admin center is a simpler, built-in solution for this specific requirement for new user accounts.
  • C. Entitlement management focuses on access packages and approvals, not default user attribute provisioning.
  • D. Conditional Access policies enforce access based on conditions, they do not set user attributes during creation.

Default Usage Location

The default Usage Location in Microsoft 365/Azure AD allows administrators to pre-set a geographical location for all newly created user accounts. This simplifies user provisioning by ensuring consistent application of the 'Usage Location' attribute, which is crucial for license assignment and service availability.

  • Configured in the Azure AD admin center under User settings.
  • Applies to users created directly in Azure AD (cloud-only users).
  • Does not apply to users synchronized from on-premises Active Directory.
  • Crucial for correct license assignment and compliance with regional service availability.

Memory trick: New user's home, set by default, no manual fault.

More Deploy and manage a Microsoft 365 tenant questions