Microsoft 365 Custom Domains & Tenant Health
Add and verify custom domains, configure service DNS and email authentication, and monitor Microsoft 365 service health without relying on stale DNS targets.
Section 05 / Final chapter
Microsoft 365 Administrator
14 topic guides with diagnostic sections. Use this chapter after the core material, or when an implementation behaves differently from the expected result. Each link opens the relevant section in its original reference.
Add and verify custom domains, configure service DNS and email authentication, and monitor Microsoft 365 service health without relying on stale DNS targets.
Design eligible role assignments, activation controls, approvals, access reviews, and emergency access for Microsoft Entra and Azure resource roles.
Delegate scoped Microsoft Entra administration and configure inbound/outbound B2B trust without overstating administrative-unit or Conditional Access boundaries.
Choose and operate Microsoft Entra Connect Sync or Cloud Sync, understand password hash synchronization timing, and design staging and authentication resilience correctly.
Design, test, and deploy Microsoft Entra Conditional Access policies for administrators, device compliance, legacy authentication, risk signals, and phishing-resistant authentication strengths.
Investigate user and sign-in risk and deploy current Conditional Access remediation policies while retiring legacy Identity Protection risk policies before October 2026.
Govern recurring access, access-package lifecycle, external users, and just-in-time group membership with Microsoft Entra ID Governance.
Implement advanced email and collaboration threat protection with Safe Links, Safe Attachments, impersonation protection, quarantine policies, and validation workflows.
Discover cloud application usage, govern sanctioned and unsanctioned apps, and apply Conditional Access App Control without overstating blocking coverage or inventing Graph APIs.
Investigate cross-workload incidents, review automated actions, hunt with valid Defender schemas, and create controlled custom detections.
Design, simulate, deploy, and investigate Microsoft Purview DLP policies across supported Microsoft 365 and endpoint locations without overstating enforcement or timing.
Design and publish Microsoft Purview sensitivity labels for files, email, meetings, groups, Teams, and sites with accurate metadata, encryption, priority, and coauthoring behavior.
Apply retention policies and labels, preserve content, manage inactive mailboxes, and use the post-2025 Microsoft Purview eDiscovery experience.
Configure privacy-aware insider and communication risk workflows and use current Audit Standard/Premium retention and mailbox-investigation capabilities.