Microsoft 365 Administrator — knowledge map
The 51 core concepts of Microsoft 365 Administrator and how they connect. Click a node in the map above to explore related terms and prerequisites; the list below indexes every concept with its definition and links to its prerequisites and related concepts.
Concepts (51)
Microsoft 365
A SaaS productivity suite delivering email, documents, and meetings in the cloud, used via per-user subscription.
Microsoft Entra ID
Cloud identity/access management (formerly Azure AD) providing MFA/SSO/Conditional Access; distinct from on-prem AD DS.
Prerequisites: Conditional Access
Microsoft Defender XDR
Unifies protection across endpoints/email/identity/SaaS, correlating signals across domains (Endpoint/Office 365/Identity/Cloud Apps).
Microsoft Purview
Microsoft's unified governance and compliance solutions: information protection, data lifecycle, risk management, eDiscovery, and auditing, plus cross-estate data governance via the data map/catalog (integrating the former Azure Purview).
Related: Purview Information Protection
Microsoft 365 contact
A directory object with no sign-in capability, intended purely as a mail recipient. Used when you want an external contact to appear in the organization's Exchange Online address book or distribution list without granting tenant access—its key distinction from a guest user. Requires no license or Entra ID sign-in.
Prerequisites: Microsoft Entra ID、Exchange Online、Microsoft 365
Related: Role groups、External user (B2B guest)
Conditional Access
Grants or challenges access based on conditions like location, device, or risk (a Zero Trust implementation).
Content explorer
A Microsoft Purview tool that visualizes the actual content and storage location (SharePoint, Exchange, OneDrive, etc.) of items with applied sensitivity labels or sensitive information types (SITs). It is a snapshot of what exists where, distinct from Activity explorer, which tracks who did what over time. Viewing content requires an additional permission.
Prerequisites: Microsoft Purview、OneDrive、Sensitivity labels、SharePoint
Microsoft 365 Backup
Protection that quickly restores Exchange/SharePoint/OneDrive data from accidental deletion/corruption. Different purpose from Purview retention (compliance preservation).
Prerequisites: Microsoft 365、Microsoft Purview、OneDrive、Retention policy
OneDrive
Personal cloud file storage and sync—keep your own files and share as needed (SharePoint is for org sharing).
Prerequisites: SharePoint
External user (B2B guest)
A user object registered as a guest in Microsoft Entra ID, retaining the partner organization's existing identity. Accepting an invitation creates a user object in the tenant (UserType=Guest), which can be targeted by Conditional Access and license assignment. It is the object created by the B2B collaboration feature, distinct from a role group (a permission-delegation unit).
Prerequisites: Conditional Access、Microsoft Entra ID、Role groups
Related: Microsoft 365 contact
Microsoft Teams
A collaboration hub for chat, meetings, calls, and teamwork; files are stored behind the scenes in SharePoint/OneDrive.
Prerequisites: OneDrive
Related: SharePoint
Microsoft Purview Data Loss Prevention (DLP)
Prevents sensitive information from leaking outside the org by applying DLP policies to Exchange Online/SharePoint Online/OneDrive/Teams to block sharing/sending and warn via policy tips. Distinct from labels (classify) and retention (preserve).
Prerequisites: Exchange Online、Microsoft Purview、Microsoft Teams、OneDrive
Microsoft 365 admin center
The central admin portal for Microsoft 365. It manages users, licenses, groups, domain names, and org settings, and is the gateway to each workload-specific admin center. Copilot license assignment and usage reports are done here too.
Prerequisites: Microsoft 365
Authentication (AuthN)
Verifying "who you are" (identity); performed before authorization.
Hybrid identity (Entra Connect)
Syncs on-prem Active Directory with Entra ID for hybrid identity. Choose authentication among password hash sync, pass-through authentication, and federation (AD FS).
Prerequisites: Authentication methods (MFA / passwordless)、Authentication (AuthN)、Microsoft Entra ID
Role groups
A delegation unit for permissions within an individual workload's admin center, such as Microsoft Defender or Microsoft Purview. Adding a user to a role group grants the permissions of the roles assigned to that group (e.g., Security Reader, Compliance Administrator). It provides workload-scoped least privilege distinct from tenant-wide Entra ID roles.
Prerequisites: Microsoft Entra ID、Microsoft Defender XDR、Microsoft Purview
Related: Microsoft 365 contact
Microsoft Defender for Office 365
Email/collaboration threat protection—threat policies (anti-phishing/spam/malware), Safe Attachments, Safe Links, Threat Explorer, attack simulation. Distinct from device-EDR Defender for Endpoint.
Prerequisites: Microsoft Defender XDR、Attack simulation training、Safe Attachments、Safe Links
Microsoft 365 Groups
A backbone that provides shared membership and resources across multiple services (Teams, SharePoint, Outlook, Planner, etc.), enabling cross-service collaboration from one group.
Prerequisites: Microsoft 365、Microsoft Teams、SharePoint
Retention policy
Keeps data for the required period and deletes it when no longer needed, managing its lifecycle.
Sensitivity labels
Classify data and apply protection (encryption, usage limits); labels travel with the file, persisting outside the org.
Data Lifecycle Management and retention labels
Microsoft Purview Data Lifecycle Management uses retention labels to keep information only as long as needed and delete it afterward, balancing compliance and storage optimization.
Prerequisites: Microsoft Purview、Retention policy
Purview Information Protection
Microsoft Purview Information Protection discovers and classifies sensitive information and applies protection (encryption, access restriction, watermarks) via sensitivity labels. It is foundational to limiting exposure in Copilot responses.
Prerequisites: Sensitivity labels
Related: Microsoft Purview
Multi-factor authentication (MFA)
Strengthens identity proof with a second factor beyond a password.
Prerequisites: Authentication (AuthN)
Tenant configuration (domains/Organization profile)
Tenant-wide basics in the Microsoft 365 admin center—adding custom domains (DNS TXT verification) and the Organization profile (name, contact, release preferences).
Prerequisites: Microsoft 365 admin center、Microsoft 365 contact、Microsoft 365
Authentication methods (MFA / passwordless)
Means of verifying identity. Methods stronger than passwords alone, such as multifactor authentication (MFA) and passwordless (FIDO2 security keys, Authenticator, Windows Hello).
Prerequisites: Authentication (AuthN)、Multi-factor authentication (MFA)
Data classification (SITs / trainable classifiers)
Data classification identifies content using sensitive information types (patterns like credit cards or national IDs) and trainable classifiers. It informs where to apply sensitivity labels and DLP.
Prerequisites: Sensitivity labels
License assignment (direct / group-based)
Access to Microsoft 365 and Copilot features depends on license type, assigned directly to users or in bulk via group-based licensing. Copilot needs a separate license on top of existing M365 licenses.
Prerequisites: Microsoft 365
Self-service password reset (SSPR)
An Entra feature letting users reset passwords without an admin, requiring multiple authentication methods and supporting password writeback to on-prem.
Prerequisites: Authentication (AuthN)
Related: Password writeback
Microsoft Entra ID Protection
Computes user/sign-in risk from leaked credentials, impossible travel, etc., integrating with Conditional Access.
Prerequisites: Conditional Access、Microsoft Entra ID
Exchange Online
A cloud service for email and calendar (hosted mailboxes); Outlook is the client that uses it.
Attack simulation training
Sends simulated phishing to train users—an educational feature. Different purpose from Threat Explorer (investigating actually delivered threats).
IdFix
A pre-sync cleansing tool that detects/fixes on-prem AD format errors/duplicates (invalid UPNs, duplicate proxy addresses, illegal characters) before syncing to Microsoft Entra ID.
Prerequisites: Microsoft Entra ID
Network connectivity insights
Evaluates and improves each location’s connection path to Microsoft 365 (optimal egress, latency). Distinct from Service Health (Microsoft-side outages).
Prerequisites: Microsoft 365
Restricted entities
Shows users restricted from sending (e.g., due to bulk spam); remediate the cause and remove the restriction. Distinct from Conditional Access (sign-in control).
Prerequisites: Conditional Access
Service Health (Microsoft 365)
In the Microsoft 365 admin center, shows Microsoft-side service incidents/advisories (outage, degradation, planned maintenance) and configures notifications. Distinct from Network connectivity insights (your network path).
Prerequisites: Microsoft 365 admin center、Microsoft 365、Network connectivity insights
Microsoft Defender Threat Intelligence
Provides external threat info—threat actors, IOCs, threat analytics reports—to match observed indicators against known attacks. Distinct from advanced hunting (your own KQL).
Prerequisites: Microsoft Defender XDR、Advanced hunting (KQL)
Microsoft Secure Score
A measure that quantifies an organization’s security posture with recommended improvement actions and progress, viewed in the Microsoft Defender portal.
Prerequisites: Microsoft Defender XDR
Microsoft Entra Connect Health
Monitors the health, errors, and performance of sync/authentication agents (Connect Sync, PTA, AD FS, etc.), giving visibility into the hybrid identity foundation.
Prerequisites: Authentication (AuthN)、Hybrid identity (Entra Connect)
Advanced hunting (KQL)
Uses KQL in Defender XDR / Sentinel to proactively hunt threats across telemetry, turning queries into analytics rules for automated detection.
Prerequisites: Microsoft Defender XDR
Data / Activity Explorer
Purview tools where Data Explorer (content explorer) reveals where sensitive data resides and Activity Explorer surfaces actions taken on that data.
Prerequisites: Content explorer、Microsoft Purview
Compliant device
A device evaluated as compliant by Intune, used as a Conditional Access grant control ("require a compliant device").
Prerequisites: Conditional Access
Microsoft Defender for Endpoint
Provides device (endpoint) EDR/protection, rolled out onboarding→endpoint settings→vulnerability management. Distinct from Defender for Office 365 (email protection).
Prerequisites: Microsoft Defender XDR
Safe Attachments
In Defender for Office 365, detonates attachments in a sandbox to detect unknown malware. Distinct from Safe Links (which protects URLs).
Related: Safe Links
Safe Links
In Defender for Office 365, re-evaluates URLs at click time to block malicious links (effective for delayed weaponization). Distinct from Safe Attachments (which protects attachments).
Related: Safe Attachments
Security group (Entra ID)
A Microsoft Entra ID group used for resource access and license assignment. Distinct from a Microsoft 365 Group (which bundles collaboration resources).
Prerequisites: Microsoft Entra ID、Microsoft 365
Tamper protection
A Microsoft Defender for Endpoint setting that blocks malware or attackers—even with local admin rights—from disabling real-time protection, stopping signature updates, or uninstalling Defender. It is commonly deployed and enforced tenant-wide via Intune security settings management.
Prerequisites: Microsoft Defender XDR、Microsoft Defender for Endpoint
Microsoft Graph PowerShell
A PowerShell module to automate Entra/Microsoft 365. The successor to the older AzureAD/MSOnline modules, used to programmatically run repetitive tasks like attribute updates and license assignment.
Prerequisites: Microsoft 365
Password writeback
Reflects a password reset (via SSPR) in the cloud back to on-prem AD, configured in Connect Sync.
Related: Self-service password reset (SSPR)
Microsoft Defender for Cloud Apps
A CASB (cloud access security broker) that discovers and controls cloud-app usage and shadow IT.
Prerequisites: Microsoft Defender XDR

