What's changed: Added per-section figures (cert-figure-retrofit). New AB-900 Chapter 1 (Domain 1 "Core M365 features and objects": core objects = licenses/admin centers (M365/Exchange/SharePoint/Teams)/objects and roles; security principles = three Zero Trust principles/authentication-authorization/threat protection/Defender XDR; core security features = Entra/conditional access/SSO/sign-in troubleshooting/Identity Secure Score/audit logs/PIM/app registrations-enterprise apps)
1.2Microsoft 365 security principles
Understand Zero Trust principles, authorization vs authentication methods, threat protection and intelligence, and the features and role of Microsoft Defender XDR—the security foundation of Microsoft 365.
Because Copilot and agents operate on the data a user can access, understanding Microsoft 365 security (who accesses what, and how) is a prerequisite. The central idea is Zero Trust.
1.2.1The three Zero Trust principles
- Verify explicitly: always authenticate/authorize using signals like user, device, location, and risk.
- Least privilege: grant only the minimum needed, using Just-In-Time / Just-Enough-Access.
- Assume breach: segment to minimize impact and continuously monitor, detect, and respond.
1.2.2Authentication and authorization
Authentication verifies "who you are," with methods beyond passwords such as multifactor authentication (MFA) and passwordless (Windows Hello, FIDO2, Authenticator). Authorization decides "what you can do," expressed via roles and permissions. They are distinct; AB-900 asks you not to confuse "authentication = identity" with "authorization = permissions."
1.2.3Threat protection and Microsoft Defender XDR
Threat protection and threat intelligence detect and defend against known/unknown attacks using up-to-date attack data. In Microsoft 365, Microsoft Defender XDR is central, unifying signals across domains (XDR = Extended Detection and Response)—email (Defender for Office 365), identity (Defender for Identity), endpoint (Defender for Endpoint), and cloud apps (Defender for Cloud Apps)—to detect, investigate, and respond to incidents holistically. Defender also helps mitigate Copilot risks.
Watch the mix-ups: (1) authentication (who = MFA/passwordless) vs authorization (what you can do = roles/permissions). (2) Zero Trust’s three principles: verify explicitly, least privilege, assume breach. (3) Defender XDR unifies signals across domains for incident response—not a single-product antivirus.
Common: concept → term. E.g., "stronger identity verification" = MFA/passwordless; "deciding permissions" = authorization; "always verify, least privilege, assume breach" = Zero Trust; "unify signals across domains to detect/respond" = Defender XDR.
1.2.4Section summary
- Zero Trust = verify explicitly, least privilege, assume breach
- Authentication (identity: MFA/passwordless) and authorization (permissions) are distinct
- Defender XDR = unified detection/response across email/identity/endpoint/cloud-app signals
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which set correctly lists the three Zero Trust principles?
Q2. Which Microsoft 365 capability unifies signals across email, identity, endpoint, and cloud apps to detect, investigate, and respond?
Q3. Which correctly pairs "verify who you are" with "decide what you can do"?
Q4. Which authentication approach requires an additional factor so a leaked password alone cannot pass?
Q5. Which best represents the Zero Trust principle of least privilege?
Q6. What is the use of up-to-date attack data to detect and defend against known/unknown threats called?

