Instiq
Chapter 1 · Configure and manage a Teams environment·v1.0.0·Updated 6/29/2026·~14 min

What's changed: Created MS-700 Chapter 1 (domain: Configure and manage a Teams environment): network planning (bandwidth capacity, Network planner, ports/protocols UDP, Network Assessment Tool, connectivity test tool), governance/lifecycle (update policies, policy packages, policy assignment, M365 group creation/expiration/naming policy, archive/delete/restore, Access reviews, PowerShell/Graph), and security/compliance (Teams admin roles, alert policies, Defender for Office 365 threat policies, retention, sensitivity labels, Purview DLP, Conditional Access, Information Barriers, Communication Compliance, Insider Risk Management).

1.2Governance and lifecycle

Key points

Understand update policies, policy packages, policy assignment, Microsoft 365 group creation control/expiration/naming policies, team archive/delete/restore, Microsoft Entra Access reviews, and PowerShell/Microsoft Graph.

Teams governance consistently manages policy design and assignment, group lifecycle control, and team retention/deletion.

1.2.1Policy packages and assignment

Update policies control Teams client updates (e.g., preview ring). Policy packages are predefined bundles of multiple policies tailored to a role (education, healthcare), applied together. Policy assignment assigns those policies to users or groups (group assignment auto-rolls out). Distinguish "the bundled definition" = policy package from "who it applies to" = policy assignment.

1.2.2Group and team lifecycle

Teams rely on the underlying Microsoft 365 group. Restrict group creation to specific users, use an expiration policy to expire unused groups, and a naming policy to enforce prefixes/suffixes and blocked words. Manage teams via archive (read-only retention) and delete (with restore/unarchive typically within 30 days). Use Microsoft Entra Access reviews to periodically review member/guest access, and automate bulk operations with PowerShell / Microsoft Graph.

Exam point

Cues: "role-based predefined policy bundle" = policy package. "apply policies to users/groups" = policy assignment. "expire unused groups" = expiration policy. "enforce prefixes/blocked words" = naming policy. "read-only retention" = archive; "remove" = delete (restore within 30 days). "periodic access review" = Access reviews.

Warning

Watch the mix-ups: (1) Policy package (bundle of definitions) vs policy assignment (whom to assign). (2) Expiration policy (expire) vs naming policy (naming)—different purposes. (3) Archive (read-only retention) vs delete (removal); archive is reactivated via unarchive, not restore. (4) Group-creation restriction is a tenant-wide governance setting.

Diagram: a policy package is a role-based bundle, policy assignment applies it to users/groups; control M365 groups via creation restriction/expiration policy/naming policy (blocked words); manage teams via archive (read-only) and delete (restore within 30 days); Access reviews periodically review access; bulk-operate via PowerShell/Graph.
Policy and lifecycle

1.2.3Section summary

  • Policy package = role-based predefined bundle; policy assignment = assigning to users/groups
  • Control M365 groups via creation restriction/expiration policy/naming policy (blocked words)
  • Archive = read-only retention; delete = removal (restore within 30 days); Access reviews periodically review access

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. For education, you want to apply multiple Teams policies as a predefined role-based bundle. Best?

Q2. You want unused Microsoft 365 groups (teams) to auto-expire after a period to clean up. Best?

Q3. You want to enforce a department prefix in team names and block names with certain banned words. Best?

Q4. After a project ends, you want to keep team data but prevent new posts. Best?

Q5. What correctly distinguishes a policy package from policy assignment?

Check your understandingPractice questions for Chapter 1: Configure and manage a Teams environment