Naslovnica

MS-102: Microsoft 365 Administrator

Tijekom treningom polaznici se upoznaju s ključnim elementima Microsoft 365 administracije, a to su Microsoft 365 tenant menadžment, Microsoft 365 sinkronizacija identiteta te Microsoft 365 sigurnost i usklađenost.

U dijelu Microsoft 365 tenant menadžment naučit ćete kako konfigurirati tenant, uključujući organizacijski profil, opcije tenant pretplate, korisničke račune i licence, sigurnosne grupe i administrativne uloge. Trening zatim prelazi na dubinsko ispitivanje Microsoft 365 sinkronizacije identiteta s fokusom na Azure Active Directory Connect i Connect Cloud Sync.

Kroz dio Microsoft 365 upravljanja sigurnošću početi ćete ispitivati vrste vektora prijetnji i povrede podataka s kojima se današnje organizacije suočavaju te ćete saznati kako Microsoft 365 sigurnosna rješenja rješavaju te prijetnje. Na kraju ćete ispitati ključne komponente Microsoft 365 upravljanja usklađenošću kao što su ključni aspekti upravljanja podacima, arhiviranje i zadržavanje podataka, šifriranje poruka Microsoft Purview te sprječavanje gubitka podataka (engl. Data Loss Prevention).

Što ćete naučiti

Kome je namijenjeno

  • IT stručnjacima koje žele postati Microsoft 365 administrator te imaju položenu barem jednu certifikaciju na putu za Microsoft 365 role-based administratora.

Preduvjeti

  • Završen barem jedan trening za role-based administratora kao što su Messaging, Teamwork, Security, Compliance ili Collaboration.
  • Razumijevanje DNS-a i osnovno iskustvo u radu s Microsoft 365 uslugama.
  • Razumijevanje općih IT praksi.
  • Iskustvo u radu s PowerShellom.

Nastavni plan

Pregledaj
Module 1: Configure your Microsoft 365 experience  This module examines each of the tasks that an organization must complete to successfully configure its Microsoft 365 experience.  After completing this module, students will be able to: 
  • Configure your company’s organization profile, which is essential for setting up for your company’s tenant 
  • Maintain minimum subscription requirements for your company 
  • Manage your services and add-ins by assigning more licenses, purchasing more storage, and so on 
  • Create a checklist that enables you to confirm your Microsoft 365 tenant meets your business needs 
Module 2: Manage users, contacts, and licenses in Microsoft 365  This module provides instruction on how to manage user accounts and licenses in Microsoft 365, create and manage user accounts, assign Microsoft 365 licenses to users, and recover deleted user accounts.  After completing this module, students will be able to: 
  • Identify which user identity model best suited for your organization 
  • Create user accounts from both the Microsoft 365 admin center and Windows PowerShell 
  • Manage user accounts and licenses in Microsoft 365 
  • Recover deleted user accounts in Microsoft 365 
  • Perform bulk user maintenance in Azure Active Directory 
Module 3: Manage groups in Microsoft 365  This module provides instruction on how to create groups for distributing email to multiple users within Exchange Online. It also explains how to create groups to support collaboration in SharePoint Online.  After completing this module, students will be able to: 
  • Describe the various types of groups available in Microsoft 365 
  • Create and manage groups using the Microsoft 365 admin center and Windows PowerShell 
  • Create and manage groups in Exchange Online and SharePoint Online 
Module 4: Add a custom domain in Microsoft 365  This module provides instruction on how to add a custom domain to your Microsoft 365 deployment. It also examines the DNS requirements that are necessary to support a new domain.  After completing this module, students will be able to: 
  • Identify the factors that must be considered when adding a custom domain to Microsoft 365 
  • Plan the DNS zones used in a custom domain 
  • Plan the DNS record requirements for a custom domain 
  • Add a custom domain to your Microsoft 365 deployment 
Module 5: Configure client connectivity to Microsoft 365  This module examines how clients connect to Microsoft 365. It also provides instruction on how to configure name resolution and Outlook clients, and how to troubleshoot client connectivity.  After completing this module, students will be able to: 
  • Describe how Outlook uses Autodiscover to connect an Outlook client to Exchange Online 
  • Identify the DNS records needed for Outlook and other Office-related clients to automatically locate the services in Microsoft 365 using the Autodiscover process 
  • Describe the connectivity protocols that enable Outlook to connect to Microsoft 365 
  • Identify the tools that can help you troubleshoot connectivity issues in Microsoft 365 deployments 
Module 6: Configure administrative roles in Microsoft 365  This module examines the key functionality that's available in the more commonly used Microsoft 365 admin roles. It also provides instruction on how to configure these roles.  After completing this module, students will be able to: 
  • Describe the Azure RBAC permission model used in Microsoft 365 
  • Describe the most common Microsoft 365 admin roles 
  • Identify the key tasks assigned to the common Microsoft 365 admin roles 
  • Delegate admin roles to partners 
  • Manage permissions using administrative units in Azure Active Directory 
  • Elevate privileges to access admin centers by using Azure AD Privileged Identity Management 
Module 7: Manage tenant health and services in Microsoft 365  This module examines how to monitor your organization's transition to Microsoft 365 using Microsoft 365 tools.  After completing this module, students will be able to: 
  • Monitor your organization's Microsoft 365 service health in the Microsoft 365 admin center 
  • Develop an incident response plan to deal with incidents that may occur with your Microsoft 365 service 
  • Request assistance from Microsoft to address technical, pre-sales, billing, and subscription support issues 
Module 8: Deploy Microsoft 365 Apps for enterprise  This module examines how to implement the Microsoft 365 Apps for enterprise productivity suite in both user-driven and centralized deployments.  After completing this module, students will be able to: 
  • Describe the Microsoft 365 Apps for enterprise functionality 
  • Configure the Readiness Toolkit 
  • Plan a deployment strategy for Microsoft 365 Apps for enterprise 
  • Complete a user-driven installation of Microsoft 365 Apps for enterprise 
  • Deploy Microsoft 365 Apps for enterprise with Microsoft Endpoint Configuration Manager 
  • Identify the mechanisms for managing centralized deployments of Microsoft 365 Apps for enterprise 
  • Deploy Microsoft 365 Apps for enterprise with the Office Deployment Toolkit 
  • Describe how to manage Microsoft 365 Apps for enterprise updates 
  • Determine which update channel and application method applies for your organization 
Module 9: Analyze your Microsoft 365 workplace data using Microsoft Viva Insights  This module examines the workplace analytical features of Microsoft Viva Insights, including how it works, and how it generates insights and improves collaboration within an organization.  After completing this module, students will be able to: 
  • Identify how Microsoft Viva Insights can help improve collaboration behaviors in your organization 
  • Discover the sources of data used in Microsoft Viva Insights 
  • Explain the high-level insights available through Microsoft Viva Insights 
  • Create custom analysis with Microsoft Viva Insights 
  • Summarize tasks and considerations for setting up Microsoft Viva Insights and managing privacy 
Module 10: Explore identity synchronization  This module examines identity synchronization and explores the authentication and provisioning options that can be used, and the inner-workings of directory synchronization.  After completing this module, students will be able to: 
  • Describe the Microsoft 365 authentication and provisioning options 
  • Explain the two identity models in Microsoft 365 - cloud-only identity and hybrid identity 
  • Explain the three authentication methods in the hybrid identity model - Password hash synchronization, Pass-through authentication, and federated authentication 
  • Describe how Microsoft 365 commonly uses directory synchronization 
Module 11: Prepare for identity synchronization to Microsoft 365  This module examines all the planning aspects that must be considered when implementing directory synchronization between on-premises Active Directory and Microsoft 365.  After completing this module, students will be able to: 
  • Identify the tasks necessary to configure your Azure Active Directory environment 
  • Plan directory synchronization to synchronize your on-premises Active Directory objects to Azure AD 
  • Identify the features of Azure AD Connect sync and Azure AD Connect Cloud Sync 
  • Choose which directory synchronization best fits your environment and business needs 
Module 12: Implement directory synchronization tools  This module examines the Azure AD Connect and Azure AD Connect Cloud Sync installation requirements, the options for installing and configuring the tools, and how to monitor synchronization services using Azure AD Connect Health.  After completing this module, students will be able to: 
  • Configure Azure AD Connect and Azure AD Connect Cloud Sync prerequisites 
  • Set up Azure AD Connect and Azure AD Connect Cloud Sync 
  • Monitor synchronization services using Azure AD Connect Health 
Module 13: Manage synchronized identities  This module examines how to manage user identities when Azure AD Connect is configured, how to manage users and groups in Microsoft 365 with Azure AD Connect, and how to maintain directory synchronization.  After completing this module, students will be able to: 
  • Ensure users synchronize efficiently 
  • Manage groups with directory synchronization 
  • Use Azure AD Connect Sync Security Groups to help maintain directory synchronization 
  • Configure object filters for directory synchronization 
  • Troubleshoot directory synchronization using various troubleshooting tasks and tools 
Module 14: Manage secure user access in Microsoft 365  This module examines various password-related tasks for users and administrators, including:  After completing this module, students will be able to: 
  • Creating and configuring password policies 
  • Configuring self-service password management 
  • Configuring multifactor authentication 
  • Implementing entitlement packages 
  • Implementing conditional access policies 
Module 15: Examine threat vectors and data breaches  This module examines the types of threat vectors and their potential outcomes that organizations must deal with on a daily basis and how users can enable hackers to access targets by unwittingly executing malicious content.  After completing this module, students will be able to: 
  • Describe techniques hackers use to compromise user accounts through email 
  • Describe techniques hackers use to gain control over resources 
  • Describe techniques hackers use to compromise data 
  • Mitigate an account breach 
  • Prevent an elevation of privilege attack 
  • Prevent data exfiltration, data deletion, and data spillage 
Module 16: Explore the Zero Trust security model  This module examines the concepts and principles of the Zero Trust security model, as well as how Microsoft 365 supports it, and how your organization can implement it.  After completing this module, students will be able to: 
  • Describe the Zero Trust approach to security in Microsoft 365 
  • Describe the principles and components of the Zero Trust security model 
  • Describe the five steps to implementing a Zero Trust security model in your organization 
  • Explain Microsoft's story and strategy around Zero Trust networking 
Module 17: Explore security solutions in Microsoft Defender XDR  This module introduces you to several features in Microsoft 365 that can help protect your organization against cyberthreats, detect when a user or computer has been compromised, and monitor your organization for suspicious activities.  After completing this module, students will be able to: 
  • Identify the features of Microsoft Defender for Office 365 that enhance email security in a Microsoft 365 deployment 
  • Explain how Microsoft Defender for Identity identifies, detects, and investigates advanced threats, compromised identities, and malicious insider actions directed at your organization 
  • Explain how Microsoft Defender for Endpoint helps enterprise networks prevent, detect, investigate, and respond to advanced threats 
  • Describe how Microsoft 365 Threat Intelligence can be beneficial to your organization’s security officers and administrators 
  • Describe how Microsoft Cloud App Security enhances visibility and control over your Microsoft 365 tenant through three core areas 
Module 18: Examine Microsoft Secure Score  This module examines how Microsoft Secure Score helps organizations understand what they've done to reduce the risk to their data and show them what they can do to further reduce that risk.  After completing this module, students will be able to: 
  • Describe the benefits of Secure Score and what kind of services can be analyzed 
  • Describe how to collect data using the Secure Score API 
  • Describe how to use the tool to identify gaps between your current state and where you would like to be regarding security 
  • Identify actions that increase your security by mitigating risks 
  • Explain where to look to determine the threats each action mitigates and the impact it has on users 
Module 19: Examine Privileged Identity Management  This module examines how Privileged Identity Management ensures users in your organization have just the right privileges to perform the tasks they need to accomplish.  After completing this module, students will be able to: 
  • Describe how Privileged Identity Management enables you to manage, control, and monitor access to important resources in your organization 
  • Configure Privileged Identity Management for use in your organization 
  • Describe how Privileged Identity Management audit history enables you to see all the user assignments and activations within a given time period for all privileged roles 
  • Explain how Microsoft Identity Manager helps organizations manage the users, credentials, policies, and access within their organizations and hybrid environments 
  • Explain how Privileged Access Management provides granular access control over privileged admin tasks in Microsoft 365 
Module 20: Examine Microsoft Entra ID Protection  This module examines how Azure Identity Protection provides organizations the same protection systems used by Microsoft to secure identities.  After completing this module, students will be able to: 
  • Describe Azure Identity Protection (AIP) and what kind of identities can be protected 
  • Enable the three default protection policies in AIP 
  • Identify the vulnerabilities and risk events detected by AIP 
  • Plan your investigation in protecting cloud-based identities 
  • Plan how to protect your Azure Active Directory environment from security breaches 
Module 21: Examine email protection in Microsoft 365  This module examines how Exchange Online Protection (EOP) protects organizations from phishing and spoofing.  After completing this module, students will be able to: 
  • Describe how Exchange Online Protection analyzes email to provide anti-malware pipeline protection 
  • List several mechanisms used by Exchange Online Protection to filter spam and malware 
  • Describe other solutions administrators may implement to provide extra protection against phishing and spoofing 
  • Understand how EOP provides protection against outbound spam 
Module 22: Enhance your email protection using Microsoft Defender for Office 365  This module examines how Microsoft Defender for Office 365 extends EOP protection by filtering targeted attacks such as zero-day attacks in email attachments and Office documents, and time-of-click protection against malicious URLs.  After completing this module, students will be able to: 
  • Describe how the Safe Attachments feature in Microsoft Defender for Office 365 blocks zero-day malware in email attachments and documents 
  • Describe how the Safe Links feature in Microsoft Defender for Office 365 protects users from malicious URLs embedded in email and documents that point to malicious websites 
  • Create outbound spam filtering policies 
  • Unblock users who violated spam filtering policies so they can resume sending emails 
Module 23: Manage Safe Attachments  This module examines how to manage Safe Attachments in your Microsoft 365 tenant by creating and configuring policies and using transport rules to disable a policy from taking effect in certain scenarios.  After completing this module, students will be able to: 
  • Create and modify a Safe Attachments policy using Microsoft 365 Defender 
  • Create a Safe Attachments policy by using PowerShell 
  • Configure a Safe Attachments policy 
  • Describe how a transport rule can disable a Safe Attachments policy 
  • Describe the end-user experience when an email attachment is scanned and found to be malicious 
Module 24: Manage Safe Links  This module examines how to manage Safe Links in your tenant by creating and configuring policies and using transport rules to disable a policy from taking effect in certain scenarios.  After completing this module, students will be able to: 
  • Create and modify a Safe Links policy using Microsoft 365 Defender 
  • Create a Safe Links policy using PowerShell 
  • Configure a Safe Links policy 
  • Describe how a transport rule can disable a Safe Links policy 
  • Describe the end-user experience when Safe Links identifies a link to a malicious website embedded in email, and a link to a malicious file hosted on a website 
Module 25: Explore threat intelligence in Microsoft Defender XDR  This module examines how Microsoft 365 Threat Intelligence provides admins with evidence-based knowledge and actionable advice that can be used to make informed decisions about protecting and responding to cyber-attacks against their tenants.  After completing this module, students will be able to: 
  • Describe how threat intelligence in Microsoft 365 is powered by the Microsoft Intelligent Security Graph 
  • Create alerts that can identify malicious or suspicious events 
  • Understand how the Microsoft 365 Defender's Automated investigation and response process works 
  • Describe how threat hunting enables security operators to identify cybersecurity threats 
  • Describe how Advanced hunting in Microsoft 365 Defender proactively inspects events in your network to locate threat indicators and entities 
Module 26: Implement app protection by using Microsoft Defender for Cloud Apps  This module examines how to implement Microsoft Defender for Cloud Apps, which identifies and combats cyberthreats across all your Microsoft and third-party cloud services.  After completing this module, students will be able to: 
  • Describe how Microsoft Defender for Cloud Apps provides improved visibility into network cloud activity and increases the protection of critical data across cloud applications 
  • Explain how to deploy Microsoft Defender for Cloud Apps 
  • Control your cloud apps with file policies 
  • Manage and respond to alerts generated by those policies 
  • Configure and troubleshoot Cloud Discovery 
Module 27: Implement endpoint protection by using Microsoft Defender for Endpoint  This module examines how Microsoft Defender for Endpoint helps enterprise networks prevent, detect, investigate, and respond to advanced threats by using endpoint behavioral sensors, cloud security analytics, and threat intelligence.  After completing this module, students will be able to: 
  • Describe how Microsoft Defender for Endpoint helps enterprise networks prevent, detect, investigate, and respond to advanced threats 
  • Onboard supported devices to Microsoft Defender for Endpoint 
  • Implement the Threat and Vulnerability Management module to effectively identify, assess, and remediate endpoint weaknesses 
  • Configure device discovery to help find unmanaged devices connected to your corporate network 
  • Lower your organization's threat and vulnerability exposure by remediating issues based on prioritized security recommendations 
Module 28: Implement threat protection by using Microsoft Defender for Office 365  This module examines the Microsoft Defender for Office 365 protection stack and its corresponding threat intelligence features, including Threat Explorer, Threat Trackers, and Attack simulation training.  After completing this module, students will be able to: 
  • Describe the protection stack provided by Microsoft Defender for Office 365 
  • Understand how Threat Explorer can be used to investigate threats and help to protect your tenant 
  • Describe the Threat Tracker widgets and views that provide you with intelligence on different cybersecurity issues that might affect your company 
  • Run realistic attack scenarios using Attack Simulator to help identify vulnerable users before a real attack impacts your organization 
Module 29: Examine data governance solutions in Microsoft Purview  This module introduces Microsoft Purview, which is designed to meet the challenges of today’s decentralized, data-rich workplace by providing a comprehensive set of solutions that help organizations govern, protect, and manage their entire data estate.  After completing this module, students will be able to: 
  • Protect sensitive data with Microsoft Purview Information Protection 
  • Govern organizational data using Microsoft Purview Data Lifecycle Management 
  • Minimize internal risks with Microsoft Purview Insider Risk Management 
  • Explain the Microsoft Purview eDiscovery solutions 
Module 30: Explore archiving and records management in Microsoft 365  This module examines how Microsoft 365 supports data governance by enabling organizations to archive content by using archive mailboxes, and manage their high-value content for legal, business, or regulatory obligations by implementing records management.  After completing this module, students will be able to: 
  • Enable and disable an archive mailbox in the Microsoft Purview compliance portal and through Windows PowerShell 
  • Run diagnostic tests on an archive mailbox 
  • Learn how retention labels can be used to allow or block actions when documents and emails are declared records 
  • Create your file plan for retention and deletion settings and actions 
  • Determine when items should be marked as records by importing an existing plan (if you already have one) or create new retention labels. Restore deleted data in Exchange Online and SharePoint Online 
Module 31: Explore retention in Microsoft 365  This module examines how data can be retained and ultimately removed in Microsoft 365 by using data retention policies and data retention labels in retention policies.  After completing this module, students will be able to: 
  • Explain how a retention policies and retention labels work 
  • Identify the capabilities of both retention policies and retention labels 
  • Select the appropriate scope for a policy depending on business requirements 
  • Explain the principles of retention 
  • Identify the differences between retention settings and eDiscovery holds 
  • Restrict retention changes by using preservation lock 
Module 32: Explore Microsoft Purview Message Encryption  This module introduces Microsoft Purview Message Encryption, an online service that’s built on Microsoft Azure Rights Management and includes encryption, identity, and authorization policies to help organizations secure their email.  After completing this module, students will be able to: 
  • Describe the features of Microsoft Purview Message Encryption 
  • Explain how Microsoft Purview Message Encryption works and how to set it up 
  • Define mail flow rules that apply branding and encryption templates to encrypt email messages 
  • Add organizational branding to encrypted email messages 
  • Explain the extra capabilities provided by Microsoft Purview Advanced Message Encryption 
Module 33: Explore compliance in Microsoft 365  This module explores the tools Microsoft 365 provides to help ensure an organization's regulatory compliance, including the Microsoft Purview compliance portal, Compliance Manager, and the Microsoft compliance score.  After completing this module, students will be able to: 
  • Describe how Microsoft 365 helps organizations manage risks, protect data, and remain compliant with regulations and standards 
  • Plan your beginning compliance tasks in Microsoft Purview 
  • Manage your compliance requirements with Compliance Manager 
  • Manage compliance posture and improvement actions using the Compliance Manager dashboard 
  • Explain how an organization's compliance score is determined 
Module 34: Implement Microsoft Purview Insider Risk Management  This module examines how Microsoft Purview Insider Risk Management helps organizations minimize internal risks by enabling them to detect, investigate, and act on malicious and inadvertent activities.  After completing this module, students will be able to: 
  • Describe insider risk management functionality in Microsoft 365 
  • Develop a plan to implement the Microsoft Purview Insider Risk Management solution 
  • Create insider risk management policies 
  • Manage insider risk management alerts and cases 
Module 35: Implement Microsoft Purview Information Barriers  This module examines how Microsoft Purview uses information barriers to restrict communication and collaboration in Microsoft Teams, SharePoint Online, and OneDrive for Business.  After completing this module, students will be able to: 
  • Describe how information barriers can restrict or allow communication and collaboration among specific groups of users 
  • Describe the components of an information barrier and how to enable information barriers 
  • Understand how information barriers help organizations determine which users to add or remove from a Microsoft Team, OneDrive account, and SharePoint site 
  • Describe how information barriers prevent users or groups from communicating and collaborating in Microsoft Teams, OneDrive, and SharePoint 
Module 36: Explore Microsoft Purview Data Loss Prevention  This module examines the data loss prevention features in Microsoft 365 that help organizations identify, monitor, report, and protect sensitive data through deep content analysis while helping users understand and manage data risks.  After completing this module, students will be able to: 
  • Describe how Data Loss Prevention (DLP) is managed in Microsoft 365 
  • Understand how DLP in Microsoft 365 uses sensitive information types and search patterns 
  • Describe how Microsoft Endpoint DLP extends the DLP activity monitoring and protection capabilities 
  • Describe what a DLP policy is and what it contains 
  • View DLP policy results using both queries and reports 
Module 37: Implement Microsoft Purview Data Loss Prevention  This module examines how organizations can use Microsoft Purview Data Loss Prevention to help protect sensitive data and define the protective actions that organizations can take when a DLP rule is violated.  After completing this module, students will be able to: 
  • Create a data loss prevention implementation plan. Implement Microsoft 365's default DLP policy 
  • Create a custom DLP policy from a DLP template and from scratch 
  • Create email notifications and policy tips for users when a DLP rule applies 
  • Create policy tips for users when a DLP rule applies 
  • Configure email notifications for DLP policies 
Module 38: Implement data classification of sensitive information  This module introduces you to data classification in Microsoft 365, including how to create and train classifiers, view sensitive data using Content explorer and Activity explorer, and implement Document Fingerprinting.  After completing this module, students will be able to: 
  • Explain the benefits and pain points of creating a data classification framework 
  • Identify how data classification of sensitive items is handled in Microsoft 365 
  • Understand how Microsoft 365 uses trainable classifiers to protect sensitive data 
  • Create and then retrain custom trainable classifiers 
  • Analyze the results of your data classification efforts in Content explorer and Activity explorer 
  • Implement Document Fingerprinting to protect sensitive information being sent through Exchange Online 
Module 39: Explore sensitivity labels  This module examines how sensitivity labels from the Microsoft Information Protection solution let you classify and protect your organization's data, while making sure that user productivity and collaboration isn't hindered.  After completing this module, students will be able to: 
  • Describe how sensitivity labels let you classify and protect your organization's data 
  • Identify the common reasons why organizations use sensitivity labels 
  • Explain what a sensitivity label is and what they can do for an organization 
  • Configure a sensitivity label's scope 
  • Explain why the order of sensitivity labels in your admin center is important 
  • Describe what label policies can do 
Module 40: Implement sensitivity labels  This module examines the process for implementing sensitivity labels, including applying proper administrative permissions, determining a deployment strategy, creating, configuring, and publishing labels, and removing and deleting labels.  After completing this module, students will be able to: 
  • Describe the overall process to create, configure, and publish sensitivity labels 
  • Identify the administrative permissions that must be assigned to compliance team members to implement sensitivity labels 
  • Develop a data classification framework that provides the foundation for your sensitivity labels 
  • Create and configure sensitivity labels 
  • Publish sensitivity labels by creating a label policy 
  • Identify the differences between removing and deleting sensitivity labels 

Za što vas priprema?

  • Certifikacijski ispit: Exam MS-102: Microsoft 365 Administrator
  • Certifikat: Microsoft 365 Certified: Administrator Expert