Instiq

Microsoft 365 Administrator — knowledge map

The 51 core concepts of Microsoft 365 Administrator and how they connect. Click a node in the map above to explore related terms and prerequisites; the list below indexes every concept with its definition and links to its prerequisites and related concepts.

Concepts (51)

  • Microsoft 365

    A SaaS productivity suite delivering email, documents, and meetings in the cloud, used via per-user subscription.

  • Microsoft Entra ID

    Cloud identity/access management (formerly Azure AD) providing MFA/SSO/Conditional Access; distinct from on-prem AD DS.

    Prerequisites: Conditional Access

  • Microsoft Defender XDR

    Unifies protection across endpoints/email/identity/SaaS, correlating signals across domains (Endpoint/Office 365/Identity/Cloud Apps).

  • Microsoft Purview

    Microsoft's unified governance and compliance solutions: information protection, data lifecycle, risk management, eDiscovery, and auditing, plus cross-estate data governance via the data map/catalog (integrating the former Azure Purview).

    Related: Purview Information Protection

  • Microsoft 365 contact

    A directory object with no sign-in capability, intended purely as a mail recipient. Used when you want an external contact to appear in the organization's Exchange Online address book or distribution list without granting tenant access—its key distinction from a guest user. Requires no license or Entra ID sign-in.

    Prerequisites: Microsoft Entra IDExchange OnlineMicrosoft 365

    Related: Role groupsExternal user (B2B guest)

  • SharePoint

    The basis for team/org sites and document sharing; many people co-edit shared documents. Teams channel files are stored here.

    Related: Microsoft Teams

  • Conditional Access

    Grants or challenges access based on conditions like location, device, or risk (a Zero Trust implementation).

  • Content explorer

    A Microsoft Purview tool that visualizes the actual content and storage location (SharePoint, Exchange, OneDrive, etc.) of items with applied sensitivity labels or sensitive information types (SITs). It is a snapshot of what exists where, distinct from Activity explorer, which tracks who did what over time. Viewing content requires an additional permission.

    Prerequisites: Microsoft PurviewOneDriveSensitivity labelsSharePoint

  • Microsoft 365 Backup

    Protection that quickly restores Exchange/SharePoint/OneDrive data from accidental deletion/corruption. Different purpose from Purview retention (compliance preservation).

    Prerequisites: Microsoft 365Microsoft PurviewOneDriveRetention policy

  • OneDrive

    Personal cloud file storage and sync—keep your own files and share as needed (SharePoint is for org sharing).

    Prerequisites: SharePoint

  • External user (B2B guest)

    A user object registered as a guest in Microsoft Entra ID, retaining the partner organization's existing identity. Accepting an invitation creates a user object in the tenant (UserType=Guest), which can be targeted by Conditional Access and license assignment. It is the object created by the B2B collaboration feature, distinct from a role group (a permission-delegation unit).

    Prerequisites: Conditional AccessMicrosoft Entra IDRole groups

    Related: Microsoft 365 contact

  • Microsoft Teams

    A collaboration hub for chat, meetings, calls, and teamwork; files are stored behind the scenes in SharePoint/OneDrive.

    Prerequisites: OneDrive

    Related: SharePoint

  • Microsoft Purview Data Loss Prevention (DLP)

    Prevents sensitive information from leaking outside the org by applying DLP policies to Exchange Online/SharePoint Online/OneDrive/Teams to block sharing/sending and warn via policy tips. Distinct from labels (classify) and retention (preserve).

    Prerequisites: Exchange OnlineMicrosoft PurviewMicrosoft TeamsOneDrive

  • Microsoft 365 admin center

    The central admin portal for Microsoft 365. It manages users, licenses, groups, domain names, and org settings, and is the gateway to each workload-specific admin center. Copilot license assignment and usage reports are done here too.

    Prerequisites: Microsoft 365

  • Authentication (AuthN)

    Verifying "who you are" (identity); performed before authorization.

  • Hybrid identity (Entra Connect)

    Syncs on-prem Active Directory with Entra ID for hybrid identity. Choose authentication among password hash sync, pass-through authentication, and federation (AD FS).

    Prerequisites: Authentication methods (MFA / passwordless)Authentication (AuthN)Microsoft Entra ID

  • Role groups

    A delegation unit for permissions within an individual workload's admin center, such as Microsoft Defender or Microsoft Purview. Adding a user to a role group grants the permissions of the roles assigned to that group (e.g., Security Reader, Compliance Administrator). It provides workload-scoped least privilege distinct from tenant-wide Entra ID roles.

    Prerequisites: Microsoft Entra IDMicrosoft Defender XDRMicrosoft Purview

    Related: Microsoft 365 contact

  • Microsoft Defender for Office 365

    Email/collaboration threat protection—threat policies (anti-phishing/spam/malware), Safe Attachments, Safe Links, Threat Explorer, attack simulation. Distinct from device-EDR Defender for Endpoint.

    Prerequisites: Microsoft Defender XDRAttack simulation trainingSafe AttachmentsSafe Links

  • Microsoft 365 Groups

    A backbone that provides shared membership and resources across multiple services (Teams, SharePoint, Outlook, Planner, etc.), enabling cross-service collaboration from one group.

    Prerequisites: Microsoft 365Microsoft TeamsSharePoint

  • Retention policy

    Keeps data for the required period and deletes it when no longer needed, managing its lifecycle.

  • Sensitivity labels

    Classify data and apply protection (encryption, usage limits); labels travel with the file, persisting outside the org.

  • Data Lifecycle Management and retention labels

    Microsoft Purview Data Lifecycle Management uses retention labels to keep information only as long as needed and delete it afterward, balancing compliance and storage optimization.

    Prerequisites: Microsoft PurviewRetention policy

  • Purview Information Protection

    Microsoft Purview Information Protection discovers and classifies sensitive information and applies protection (encryption, access restriction, watermarks) via sensitivity labels. It is foundational to limiting exposure in Copilot responses.

    Prerequisites: Sensitivity labels

    Related: Microsoft Purview

  • Multi-factor authentication (MFA)

    Strengthens identity proof with a second factor beyond a password.

    Prerequisites: Authentication (AuthN)

  • Tenant configuration (domains/Organization profile)

    Tenant-wide basics in the Microsoft 365 admin center—adding custom domains (DNS TXT verification) and the Organization profile (name, contact, release preferences).

    Prerequisites: Microsoft 365 admin centerMicrosoft 365 contactMicrosoft 365

  • Authentication methods (MFA / passwordless)

    Means of verifying identity. Methods stronger than passwords alone, such as multifactor authentication (MFA) and passwordless (FIDO2 security keys, Authenticator, Windows Hello).

    Prerequisites: Authentication (AuthN)Multi-factor authentication (MFA)

  • Data classification (SITs / trainable classifiers)

    Data classification identifies content using sensitive information types (patterns like credit cards or national IDs) and trainable classifiers. It informs where to apply sensitivity labels and DLP.

    Prerequisites: Sensitivity labels

  • License assignment (direct / group-based)

    Access to Microsoft 365 and Copilot features depends on license type, assigned directly to users or in bulk via group-based licensing. Copilot needs a separate license on top of existing M365 licenses.

    Prerequisites: Microsoft 365

  • Self-service password reset (SSPR)

    An Entra feature letting users reset passwords without an admin, requiring multiple authentication methods and supporting password writeback to on-prem.

    Prerequisites: Authentication (AuthN)

    Related: Password writeback

  • Microsoft Entra ID Protection

    Computes user/sign-in risk from leaked credentials, impossible travel, etc., integrating with Conditional Access.

    Prerequisites: Conditional AccessMicrosoft Entra ID

  • Exchange Online

    A cloud service for email and calendar (hosted mailboxes); Outlook is the client that uses it.

  • Attack simulation training

    Sends simulated phishing to train users—an educational feature. Different purpose from Threat Explorer (investigating actually delivered threats).

  • IdFix

    A pre-sync cleansing tool that detects/fixes on-prem AD format errors/duplicates (invalid UPNs, duplicate proxy addresses, illegal characters) before syncing to Microsoft Entra ID.

    Prerequisites: Microsoft Entra ID

  • Network connectivity insights

    Evaluates and improves each location’s connection path to Microsoft 365 (optimal egress, latency). Distinct from Service Health (Microsoft-side outages).

    Prerequisites: Microsoft 365

  • Restricted entities

    Shows users restricted from sending (e.g., due to bulk spam); remediate the cause and remove the restriction. Distinct from Conditional Access (sign-in control).

    Prerequisites: Conditional Access

  • Service Health (Microsoft 365)

    In the Microsoft 365 admin center, shows Microsoft-side service incidents/advisories (outage, degradation, planned maintenance) and configures notifications. Distinct from Network connectivity insights (your network path).

    Prerequisites: Microsoft 365 admin centerMicrosoft 365Network connectivity insights

  • Shared mailbox

    Lets multiple people share one address (e.g., info@) without a license. Distinct from a Microsoft 365 Group (full collaboration set).

    Prerequisites: Microsoft 365

  • Microsoft Defender Threat Intelligence

    Provides external threat info—threat actors, IOCs, threat analytics reports—to match observed indicators against known attacks. Distinct from advanced hunting (your own KQL).

    Prerequisites: Microsoft Defender XDRAdvanced hunting (KQL)

  • Microsoft Secure Score

    A measure that quantifies an organization’s security posture with recommended improvement actions and progress, viewed in the Microsoft Defender portal.

    Prerequisites: Microsoft Defender XDR

  • Microsoft Entra Connect Health

    Monitors the health, errors, and performance of sync/authentication agents (Connect Sync, PTA, AD FS, etc.), giving visibility into the hybrid identity foundation.

    Prerequisites: Authentication (AuthN)Hybrid identity (Entra Connect)

  • Advanced hunting (KQL)

    Uses KQL in Defender XDR / Sentinel to proactively hunt threats across telemetry, turning queries into analytics rules for automated detection.

    Prerequisites: Microsoft Defender XDR

  • Data / Activity Explorer

    Purview tools where Data Explorer (content explorer) reveals where sensitive data resides and Activity Explorer surfaces actions taken on that data.

    Prerequisites: Content explorerMicrosoft Purview

  • Compliant device

    A device evaluated as compliant by Intune, used as a Conditional Access grant control ("require a compliant device").

    Prerequisites: Conditional Access

  • Microsoft Defender for Endpoint

    Provides device (endpoint) EDR/protection, rolled out onboarding→endpoint settings→vulnerability management. Distinct from Defender for Office 365 (email protection).

    Prerequisites: Microsoft Defender XDR

  • Safe Attachments

    In Defender for Office 365, detonates attachments in a sandbox to detect unknown malware. Distinct from Safe Links (which protects URLs).

    Related: Safe Links

  • Security group (Entra ID)

    A Microsoft Entra ID group used for resource access and license assignment. Distinct from a Microsoft 365 Group (which bundles collaboration resources).

    Prerequisites: Microsoft Entra IDMicrosoft 365

  • Tamper protection

    A Microsoft Defender for Endpoint setting that blocks malware or attackers—even with local admin rights—from disabling real-time protection, stopping signature updates, or uninstalling Defender. It is commonly deployed and enforced tenant-wide via Intune security settings management.

    Prerequisites: Microsoft Defender XDRMicrosoft Defender for Endpoint

  • Microsoft Graph PowerShell

    A PowerShell module to automate Entra/Microsoft 365. The successor to the older AzureAD/MSOnline modules, used to programmatically run repetitive tasks like attribute updates and license assignment.

    Prerequisites: Microsoft 365

  • Password writeback

    Reflects a password reset (via SSPR) in the cloud back to on-prem AD, configured in Connect Sync.

    Related: Self-service password reset (SSPR)

  • Microsoft Defender for Cloud Apps

    A CASB (cloud access security broker) that discovers and controls cloud-app usage and shadow IT.

    Prerequisites: Microsoft Defender XDR