Instiq
Chapter 1 · Core features and objects of Microsoft 365 services·v1.1.0·Updated 6/11/2026·~14 min

What's changed: Added per-section figures (cert-figure-retrofit). New AB-900 Chapter 1 (Domain 1 "Core M365 features and objects": core objects = licenses/admin centers (M365/Exchange/SharePoint/Teams)/objects and roles; security principles = three Zero Trust principles/authentication-authorization/threat protection/Defender XDR; core security features = Entra/conditional access/SSO/sign-in troubleshooting/Identity Secure Score/audit logs/PIM/app registrations-enterprise apps)

1.2Microsoft 365 security principles

Key points

Understand Zero Trust principles, authorization vs authentication methods, threat protection and intelligence, and the features and role of Microsoft Defender XDR—the security foundation of Microsoft 365.

Because Copilot and agents operate on the data a user can access, understanding Microsoft 365 security (who accesses what, and how) is a prerequisite. The central idea is Zero Trust.

1.2.1The three Zero Trust principles

  • Verify explicitly: always authenticate/authorize using signals like user, device, location, and risk.
  • Least privilege: grant only the minimum needed, using Just-In-Time / Just-Enough-Access.
  • Assume breach: segment to minimize impact and continuously monitor, detect, and respond.

1.2.2Authentication and authorization

Authentication verifies "who you are," with methods beyond passwords such as multifactor authentication (MFA) and passwordless (Windows Hello, FIDO2, Authenticator). Authorization decides "what you can do," expressed via roles and permissions. They are distinct; AB-900 asks you not to confuse "authentication = identity" with "authorization = permissions."

1.2.3Threat protection and Microsoft Defender XDR

Threat protection and threat intelligence detect and defend against known/unknown attacks using up-to-date attack data. In Microsoft 365, Microsoft Defender XDR is central, unifying signals across domains (XDR = Extended Detection and Response)—email (Defender for Office 365), identity (Defender for Identity), endpoint (Defender for Endpoint), and cloud apps (Defender for Cloud Apps)—to detect, investigate, and respond to incidents holistically. Defender also helps mitigate Copilot risks.

Warning

Watch the mix-ups: (1) authentication (who = MFA/passwordless) vs authorization (what you can do = roles/permissions). (2) Zero Trust’s three principles: verify explicitly, least privilege, assume breach. (3) Defender XDR unifies signals across domains for incident response—not a single-product antivirus.

Exam point

Common: concept → term. E.g., "stronger identity verification" = MFA/passwordless; "deciding permissions" = authorization; "always verify, least privilege, assume breach" = Zero Trust; "unify signals across domains to detect/respond" = Defender XDR.

Diagram of the three Zero Trust principles: verify explicitly, use least privilege, assume breach.
The three Zero Trust principles

1.2.4Section summary

  • Zero Trust = verify explicitly, least privilege, assume breach
  • Authentication (identity: MFA/passwordless) and authorization (permissions) are distinct
  • Defender XDR = unified detection/response across email/identity/endpoint/cloud-app signals

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Which set correctly lists the three Zero Trust principles?

Q2. Which Microsoft 365 capability unifies signals across email, identity, endpoint, and cloud apps to detect, investigate, and respond?

Q3. Which correctly pairs "verify who you are" with "decide what you can do"?

Q4. Which authentication approach requires an additional factor so a leaked password alone cannot pass?

Q5. Which best represents the Zero Trust principle of least privilege?

Q6. What is the use of up-to-date attack data to detect and defend against known/unknown threats called?

Check your understandingPractice questions for Chapter 1: Core features and objects of Microsoft 365 services