Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium
A Microsoft 365 administrator wants to implement a policy where all new Microsoft 365 Groups created in the tenant must have a specific naming convention (e.g., 'GRP_DepartmentName_Project'). They also need to ensure that certain words (e.g., 'Confidential', 'HR') are blocked from being used in group names. Which feature should the administrator configure?
- AMicrosoft 365 Group Naming Policy
- BMicrosoft Purview Data Loss Prevention (DLP)
- CAzure AD Access Reviews
- DAzure AD Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft 365 Group Naming Policy
The Microsoft 365 Group Naming Policy (an Azure AD feature for Microsoft 365 Groups) allows administrators to define a prefix/suffix naming convention and a list of blocked words to prevent their use in group names and aliases. This directly addresses both requirements.
Why the other options are wrong
- B. DLP is for preventing sensitive data from leaving the organization, not for enforcing group naming policies.
- C. Access Reviews are used to periodically review group memberships or access to applications, not for naming restrictions.
- D. Identity Protection focuses on detecting and remediating identity-based risks, not group naming conventions.
Microsoft 365 Group Naming Policy
An Azure AD Premium feature that enforces naming conventions and prevents the use of specific blocked words when creating Microsoft 365 Groups.
- Requires an Azure AD Premium P1 license.
- Applies to groups created by users, not by administrators (unless admin creates via specific methods).
- Helps with organization, discoverability, and compliance.
Memory trick: Think of the Group Naming Policy as a gatekeeper for group names, ensuring they follow rules and avoid forbidden words.