Skip to content

Section 05 / Final chapter

Troubleshooting

Microsoft 365 Administrator

14 topic guides with diagnostic sections. Use this chapter after the core material, or when an implementation behaves differently from the expected result. Each link opens the relevant section in its original reference.

Before changing anything

  1. Record the affected user, device or resource, the exact error, and when it started.
  2. Compare the current state with the prerequisites and expected result in the topic reference.
  3. Collect the relevant logs, check the scope, and test one change at a time.
  4. Verify the result and document the change. Review rollback and impact before changing production.

01Microsoft 365 Tenant Management

Microsoft 365 Custom Domains & Tenant Health

Add and verify custom domains, configure service DNS and email authentication, and monitor Microsoft 365 service health without relying on stale DNS targets.

Microsoft Entra Privileged Identity Management (PIM)

Design eligible role assignments, activation controls, approvals, access reviews, and emergency access for Microsoft Entra and Azure resource roles.

Administrative Units & Cross-Tenant Access

Delegate scoped Microsoft Entra administration and configure inbound/outbound B2B trust without overstating administrative-unit or Conditional Access boundaries.

02Identity & Access in Microsoft Entra ID

Microsoft Entra Connect Sync, Cloud Sync & Hybrid Authentication

Choose and operate Microsoft Entra Connect Sync or Cloud Sync, understand password hash synchronization timing, and design staging and authentication resilience correctly.

Conditional Access: Zero Trust & Phishing-Resistant Authentication

Design, test, and deploy Microsoft Entra Conditional Access policies for administrators, device compliance, legacy authentication, risk signals, and phishing-resistant authentication strengths.

Microsoft Entra ID Protection & Risk-Based Conditional Access

Investigate user and sign-in risk and deploy current Conditional Access remediation policies while retiring legacy Identity Protection risk policies before October 2026.

Access Reviews, Entitlement Management & PIM for Groups

Govern recurring access, access-package lifecycle, external users, and just-in-time group membership with Microsoft Entra ID Governance.

03Threat Protection with Microsoft Defender XDR

Defender for Office 365: Anti-Phishing, Safe Links & Safe Attachments

Implement advanced email and collaboration threat protection with Safe Links, Safe Attachments, impersonation protection, quarantine policies, and validation workflows.

Defender for Cloud Apps: Cloud Discovery & Session Controls

Discover cloud application usage, govern sanctioned and unsanctioned apps, and apply Conditional Access App Control without overstating blocking coverage or inventing Graph APIs.

Microsoft Defender XDR: Incidents, AIR & Advanced Hunting

Investigate cross-workload incidents, review automated actions, hunt with valid Defender schemas, and create controlled custom detections.

04Compliance with Microsoft Purview

Microsoft Purview Data Loss Prevention (DLP)

Design, simulate, deploy, and investigate Microsoft Purview DLP policies across supported Microsoft 365 and endpoint locations without overstating enforcement or timing.

Sensitivity Labels, Encryption & Container Protection

Design and publish Microsoft Purview sensitivity labels for files, email, meetings, groups, Teams, and sites with accurate metadata, encryption, priority, and coauthoring behavior.

Microsoft Purview Retention, Records & eDiscovery

Apply retention policies and labels, preserve content, manage inactive mailboxes, and use the post-2025 Microsoft Purview eDiscovery experience.

Insider Risk, Communication Compliance & Microsoft Purview Audit

Configure privacy-aware insider and communication risk workflows and use current Audit Standard/Premium retention and mailbox-investigation capabilities.