What's changed: Created MS-102 Chapter 1 (domain: Deploy and manage a Microsoft 365 tenant): tenant and service management (tenant creation, domain DNS TXT verification, org settings, Service Health/notifications, Network connectivity insights, software updates, Microsoft 365 Backup, adoption/usage), users and groups (Entra ID users/external B2B guests/contacts, Microsoft 365 Groups/security groups/shared mailboxes, group-based licensing, Microsoft Graph PowerShell bulk management), and roles and role groups (Entra roles/workload role groups, administrative unit delegation, PIM Just-In-Time elevation).
1.1Manage the tenant and services
Understand creating a Microsoft 365 tenant, adding/verifying domains, org settings (Security & privacy / Organization profile), service health monitoring and notifications via Service Health, Network connectivity insights, software updates, Microsoft 365 Backup, and adoption/usage.
A Microsoft 365 administrator is the integrating hub for all workloads. The foundation is configuring the tenant and monitoring service health.
1.1.1Tenant and domains
A tenant is the organization’s dedicated Microsoft 365 / Microsoft Entra ID instance with a default onmicrosoft.com domain. Add custom domains in the Microsoft 365 admin center, verify ownership with a DNS TXT record, then set records for mail (MX) and other services. In org settings, configure the Organization profile (name, contact, release preferences) and Security & privacy (password expiration, privacy).
1.1.2Service health and network
Service Health shows service-side incidents/advisories (outage, degradation, planned maintenance), letting you assess impact and configure notifications (email). By contrast, Network connectivity insights evaluates your organization’s network path (optimal egress per location, latency). Distinguish: "is it a Microsoft-side outage?" = Service Health; "is it our network to optimize?" = Network connectivity insights.
1.1.3Updates, backup, and adoption
Configure and monitor update channels for Microsoft 365 Apps in the admin center. Microsoft 365 Backup protects Exchange/SharePoint/OneDrive with fast restore—a different purpose from long-term retention (Purview) (Backup = restore; retention = compliance preservation). Use Microsoft 365 adoption/usage reports to understand usage and drive rollout.
Cues: "verify domain ownership" = DNS TXT record. "Microsoft-side outage/degradation/notification" = Service Health. "optimize our network path" = Network connectivity insights. "restore data fast" = Microsoft 365 Backup. "compliance long-term retention" = Purview retention.
Watch the mix-ups: (1) Service Health (Microsoft-side outage) vs Network connectivity insights (your network). (2) Microsoft 365 Backup (restore) vs Purview retention (preservation/compliance) are different. (3) Domain verification is TXT; mail delivery is MX—different roles.
1.1.4Section summary
- Tenant defaults to onmicrosoft.com; add custom domains in admin center and verify ownership via DNS TXT
- Service Health = Microsoft-side outage/notification; Network connectivity insights = your network path
- Microsoft 365 Backup = fast restore; Purview retention = long-term preservation (different purpose)
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. When adding a custom domain to Microsoft 365, which DNS record do you add to verify ownership?
Q2. You want to check whether Exchange Online is degraded on Microsoft’s side, see impact/ETA, and get notifications. What do you use?
Q3. You want to evaluate and improve the connection path from each location to Microsoft 365 (optimal egress, latency). Best?
Q4. You want protection that quickly restores SharePoint/OneDrive/Exchange data from accidental deletion or corruption. Best?
Q5. You want to configure tenant-wide basics like org name, technical contact, and release preferences. Where in the Microsoft 365 admin center?

