Skip to content

01 Microsoft 365 Fundamentals

Microsoft 365 is one of the most widely used enterprise cloud platforms.

It combines:

Identity
Email
Collaboration
Document Management
Communication
Endpoint Integration
Security
Compliance

into a connected enterprise ecosystem.

For a cybersecurity professional, Microsoft 365 should not be viewed only as:

Word
Excel
PowerPoint
Outlook

The more useful security view is:

USER
IDENTITY
DEVICE
MICROSOFT 365 SERVICE
CORPORATE DATA
SECURITY & COMPLIANCE

Certification Area: Microsoft 365 Fundamentals
Level: Beginner
Primary Focus: Microsoft 365 cloud, services, identity, security, compliance, administration
Career Relevance: Microsoft 365 Administrator, Endpoint Administrator, SOC Analyst, Identity Engineer, Security Engineer, Cloud Security Engineer

By the end of this lesson, you should be able to:

  • Explain Microsoft 365
  • Understand SaaS, PaaS, and IaaS
  • Understand public, private, and hybrid cloud
  • Identify major Microsoft 365 services
  • Understand Microsoft Entra ID
  • Explain users and groups
  • Understand Exchange Online
  • Understand SharePoint Online
  • Understand OneDrive
  • Understand Microsoft Teams
  • Understand endpoint-management concepts
  • Explain Microsoft Intune at a high level
  • Understand Microsoft 365 security concepts
  • Understand Microsoft Defender concepts
  • Explain Zero Trust
  • Understand compliance and data-protection concepts
  • Understand service availability and administration
  • Build a practical Microsoft 365 study plan
  • Prepare for Microsoft 365-related interview questions

Microsoft 365 is a cloud-based productivity, collaboration, identity, management, security, and compliance ecosystem.

A simplified architecture looks like:

USERS
|
v
Microsoft Entra ID
|
+------------+------------+
| | |
v v v
Email Collaboration Files
| | |
v v v
Exchange Teams OneDrive
Online SharePoint
|
+------------+------------+
|
v
Security
|
+------------+------------+
| |
v v
Defender Compliance

Instead of installing and managing every business service locally, organizations can consume services through Microsoft 365.

Examples include:

Email
Exchange Online
Collaboration
Microsoft Teams
Documents
SharePoint Online
Personal Cloud Storage
OneDrive
Identity
Microsoft Entra ID
Device Management
Microsoft Intune

Part 02 — Why Organizations Use Microsoft 365

Section titled “Part 02 — Why Organizations Use Microsoft 365”

Organizations adopt Microsoft 365 for:

Anywhere Access
Collaboration
Centralized Identity
Cloud Email
Device Management
Security
Compliance
Reduced Infrastructure Management

Historically:

Users
Corporate Network
On-Premises Active Directory
Exchange Server
File Server
Office Applications

Organizations managed much of the infrastructure themselves.

Modern architecture may look like:

Users
Internet
Microsoft Entra ID
Microsoft 365
├── Exchange Online
├── Teams
├── SharePoint
├── OneDrive
├── Intune
└── Security Services

Before learning Microsoft 365, understand cloud computing.

Cloud computing provides computing capabilities as services.

These can include:

Servers
Storage
Networking
Databases
Applications
Security Services
Organization
Purchases Hardware
Builds Datacenter
Installs Software
Maintains Infrastructure
Organization
Cloud Provider
Consumes Required Services

Three common service models are:

IaaS
PaaS
SaaS

With IaaS, the provider manages much of the physical infrastructure.

The customer still manages significant portions of the operating environment.

Examples conceptually include:

Virtual Machines
Virtual Networks
Cloud Storage

A simplified model:

Customer:
Applications
Data
Operating System
Provider:
Virtualization
Servers
Storage
Networking
Datacenter

With PaaS, the provider manages more of the platform.

The customer focuses more on:

Application
Data
Configuration

The provider manages more of:

Operating System
Runtime
Infrastructure

Microsoft 365 is primarily consumed as:

SaaS

The organization uses the software as a cloud service.

Examples:

Exchange Online
Microsoft Teams
SharePoint Online
OneDrive

Even though Microsoft operates the platform, the customer still has security responsibilities.

For example:

Microsoft
Secures Cloud Platform

while the organization manages areas such as:

Users
Roles
Access
Data
Device Policies
Security Configuration

Never assume:

Cloud
=
Microsoft Secures Everything

A better model:

MICROSOFT
+
CUSTOMER
=
CLOUD SECURITY

Common cloud deployment models include:

Public Cloud
Private Cloud
Hybrid Cloud

Services are provided by a cloud provider.

Example:

Microsoft 365

Cloud-like services are operated for a specific organization.

Hybrid combines:

On-Premises
+
Cloud

This is common in Microsoft environments.

On-Premises
Active Directory
|
|
v
Identity Integration
|
v
Microsoft Entra ID
|
v
Microsoft 365

Microsoft 365 brings several major service categories together.

Microsoft 365
|
+-- Identity
|
+-- Productivity
|
+-- Collaboration
|
+-- Endpoint Management
|
+-- Security
|
+-- Compliance

Primarily centered around:

Microsoft Entra ID

Includes familiar productivity applications and cloud services.

Includes:

Teams
SharePoint
OneDrive

Includes capabilities associated with:

Microsoft Intune

Includes Microsoft security capabilities across identities, endpoints, email, applications, and cloud services.

Includes capabilities for:

Data Protection
Governance
Risk
Compliance
Investigation

Microsoft Entra ID is the cloud identity and access-management foundation used across many Microsoft cloud services.

It helps manage:

Users
Groups
Applications
Devices
Authentication
Authorization
Roles
USER
Microsoft Entra ID
Authentication
Authorization
Microsoft 365

If an attacker compromises:

User Identity

they may gain access to:

Email
Files
Teams
Applications
Cloud Resources

This is why identity security is central to Microsoft 365 security.

A user identity represents a person or workload that needs access.

Examples:

Employee
Administrator
Contractor
Guest

Each user may have:

Username
Authentication Methods
Group Membership
Licenses
Roles
Application Access

A professional identity process follows:

JOIN
PROVISION
GRANT ACCESS
REVIEW
MODIFY
DEPROVISION

Access should not remain forever simply because it was once granted.

Groups simplify access administration.

Instead of:

User A → Permission
User B → Permission
User C → Permission

use:

Users
Group
Permission

Groups support:

Scalability
Consistency
Role-Based Access
Simpler Administration

Poorly managed group membership can cause:

Privilege Creep

where users accumulate access over time.

Microsoft cloud services include administrative roles.

Examples conceptually include:

Tenant Administration
Identity Administration
Security Administration
Exchange Administration
Endpoint Administration

Do not grant:

Maximum Administrative Role

when a smaller role is sufficient.

Prefer:

Task
Required Role
Minimum Permission

Authentication answers:

Who Are You?

Common authentication methods may include:

Password
Authenticator Application
Security Key
Certificate
Biometric

A password alone may be vulnerable to:

Phishing
Password Reuse
Credential Theft
Guessing

Therefore modern security increasingly uses:

Multi-Factor Authentication

MFA combines multiple authentication factors.

Conceptually:

Something You Know
+
Something You Have

or:

Something You Are

If a password is stolen:

Password
Not Enough by Itself

because additional verification may still be required.

MFA significantly improves security but does not eliminate every identity threat.

Security still requires:

Phishing-Resistant Methods
Session Protection
Conditional Access
Monitoring
User Awareness

Authorization answers:

What Are You Allowed to Do?

Examples:

Read Mail
Edit Documents
Administer Users
Manage Devices
Review Security Alerts
Authentication
Who Are You?
Authorization
What Can You Do?

This distinction is fundamental.

Exchange Online provides cloud-based email and calendaring capabilities.

Users may use:

Outlook

to access:

Mailbox
Calendar
Contacts
USER
Microsoft Entra ID
Exchange Online
Mailbox

Email is a major attack surface.

Common threats include:

Phishing
Malicious Links
Malicious Attachments
Account Takeover
Business Email Compromise
Spam

Security teams should ask:

Is MFA Enabled?
Are Malicious Messages Detected?
Are Suspicious Links Protected?
Are Administrative Activities Monitored?
Are Mailbox Rules Reviewed?
Are Security Alerts Investigated?

Microsoft Teams provides:

Chat
Meetings
Calling
Collaboration
File Sharing

Teams often connects with other Microsoft 365 services.

USER
Teams
Chat / Meeting / Collaboration
Microsoft 365 Data

Consider:

Guest Access
External Access
File Sharing
Meeting Policies
Application Integration
Data Protection

SharePoint Online is widely used for:

Team Sites
Document Libraries
Intranets
Business Content
Collaboration
USER
SITE
LIBRARY
DOCUMENT

Access can be controlled at multiple levels.

Who Owns the Site?
Who Has Access?
Is External Sharing Required?
Are Sensitive Documents Protected?
Are Permissions Reviewed?

OneDrive provides cloud storage primarily associated with individual users.

Examples:

Personal Work Files
Shared Documents
Synchronized Files

Review:

Sharing
External Access
Sensitive Data
Synchronization
Device Security
Account Security

A useful high-level distinction:

OneDrive
Individual User File Storage
SharePoint
Team / Organizational Content

They are closely connected technologies.

Microsoft 365 applications include familiar tools such as:

Word
Excel
PowerPoint
Outlook

Modern Microsoft 365 administration may manage:

Deployment
Updates
Configuration
Licensing
Security

Office applications can interact with:

Email
Cloud Files
Macros
Documents
External Content

Application security is therefore part of the broader endpoint-security strategy.

Organizations need to control devices that access company resources.

Devices may include:

Corporate Windows PCs
Laptops
Mobile Devices
Personally Owned Devices
Virtual Desktops
Who Owns the Device?
Is It Managed?
Is It Compliant?
Is It Patched?
Is It Encrypted?
Can It Access Corporate Data?

Microsoft Intune provides cloud-based endpoint-management capabilities.

At a high level, it can help organizations manage:

Devices
Applications
Configuration
Compliance
Security Policies
DEVICE
ENROLL
CONFIGURE
ASSESS COMPLIANCE
GRANT ACCESS
MONITOR

A common security model is:

User Identity
+
Managed Device
+
Policy
Resource Access

A device may be considered compliant when it meets required security conditions.

Examples conceptually include:

Supported OS
Required Security Settings
Encryption
No Critical Security Violations

Device compliance means:

Meets Defined Policy

It does not mean:

Impossible to Compromise

Zero Trust is an important security model across Microsoft environments.

Three core ideas are commonly summarized as:

Verify Explicitly
Use Least Privilege
Assume Breach
Inside Corporate Network
Trusted
Every Access Request
Evaluate
Identity
Device
Risk
Resource
Context
Grant Appropriate Access

Conditional Access allows organizations to make access decisions based on conditions.

Conceptually:

USER REQUEST
Evaluate
Identity
Device
Location
Application
Risk
Decision

Possible outcomes can include:

Allow
Require Additional Verification
Require Compliant Device
Block

Instead of:

Correct Password
Always Allow

a stronger model may consider:

Password
+
MFA
+
Device
+
Risk
+
Application

Microsoft security services operate across multiple layers.

IDENTITY
ENDPOINT
EMAIL
APPLICATIONS
CLOUD

The security objective is to:

Prevent
Detect
Investigate
Respond

Microsoft Defender is a family of security capabilities.

Depending on the service and licensing, organizations may use Defender technologies across areas such as:

Endpoints
Identity
Email
Cloud Applications
Cloud Infrastructure
Telemetry
Detection
Alert
Incident
Investigation
Response

An alert represents detected activity requiring review.

Examples may involve:

Suspicious Sign-In
Malicious Email
Endpoint Malware
Unexpected Process
Risky Identity

Remember:

ALERT
CONFIRMED INCIDENT

Security teams should:

Validate
Investigate
Correlate
Determine Impact

A security incident may group related alerts and activities into a broader investigation.

For example:

Phishing Email
Credential Theft
Risky Login
Mailbox Activity

These events may represent one incident.

Part 28 — Microsoft 365 Security Mindset

Section titled “Part 28 — Microsoft 365 Security Mindset”

For every Microsoft 365 environment ask:

Who Are the Users?
Who Are the Administrators?
Is MFA Enabled?
How Are Devices Managed?
Which Services Are Used?
What Data Is Sensitive?
Who Can Share Externally?
Which Security Controls Are Enabled?
What Is Being Monitored?

Microsoft 365 also provides capabilities to help organizations meet governance and compliance requirements.

Common areas include:

Data Classification
Data Protection
Retention
Data Loss Prevention
Audit
Risk Management

Do not confuse:

Compliance

with:

Security

A compliant organization can still have security weaknesses.

A useful model is:

COMPLIANCE
+
SECURITY
+
RISK MANAGEMENT

Organizations need to understand:

What Data Do We Have?

and:

How Sensitive Is It?

Example categories:

Public
Internal
Confidential
Restricted
CREATE
STORE
USE
SHARE
RETAIN
DELETE

Security should exist throughout the lifecycle.

DLP aims to reduce inappropriate exposure of sensitive data.

Examples may include:

Credit Card Information
Personal Data
Financial Data
Confidential Business Information
Sensitive Data
Policy
Detect Activity
Warn / Restrict / Audit

Organizations may need to retain data for:

Business Requirements
Legal Requirements
Regulatory Requirements
Investigation

Retention defines how long information should remain available.

Audit capabilities help answer:

Who Did What?
When?
To Which Resource?

This is essential for:

Security Investigation
Compliance
Governance
Troubleshooting

Microsoft 365 administrators may manage services through administrative portals and management interfaces.

Administrators should understand:

Tenant
Users
Groups
Roles
Licenses
Services
Security
Health

A Microsoft 365 tenant represents an organization’s cloud environment.

Think:

Organization
Microsoft Cloud Tenant
Users
Services
Configuration
Data

Microsoft 365 capabilities can depend on licensing.

Do not attempt to memorize every current commercial bundle.

Instead understand:

License
Entitlement
Service Capability

Different organizations may have access to different security and compliance capabilities.

Focus on:

What Capability Does the Service Provide?

rather than memorizing every commercial price or bundle detail.

Cloud administrators need visibility into Microsoft service availability.

A service-health capability can help identify:

Service Incident
Degraded Performance
Planned Maintenance

Before changing local configuration during a widespread service issue, ask:

Is Microsoft Reporting
a Service Problem?

Part 37 — Microsoft 365 Security Architecture

Section titled “Part 37 — Microsoft 365 Security Architecture”

Bring the layers together:

USER
|
v
Microsoft Entra ID
|
Authentication
|
v
Conditional Access
|
v
Microsoft 365
+---------+---------+
| | |
v v v
Exchange Teams SharePoint
| |
+---------+---------+
|
v
DATA
|
+---------+---------+
| |
v v
Security Compliance
| |
+---------+---------+
|
v
Monitoring

Part 38 — Shared Responsibility in Microsoft 365

Section titled “Part 38 — Shared Responsibility in Microsoft 365”

Microsoft generally secures and operates the underlying cloud service.

Customers still manage critical areas such as:

Identity
Access
Administrative Roles
Device Security
Data
Configuration
Monitoring

Even if the Microsoft 365 platform itself is healthy:

Compromised Admin Account
Incorrect Configuration
Data Exposure

can still occur.

Part 39 — Practical Exercise — Map the Environment

Section titled “Part 39 — Practical Exercise — Map the Environment”

Create a basic Microsoft 365 architecture on paper or in your notes.

Include:

5 Users
1 Administrator
Microsoft Entra ID
Exchange Online
Teams
SharePoint
OneDrive
Managed Endpoint

Then map:

Who Authenticates?
Where Data Lives?
Who Administers Services?
Where Security Controls Apply?

Part 40 — Practical Exercise — Identity Review

Section titled “Part 40 — Practical Exercise — Identity Review”

Create a conceptual identity inventory:

Identity Type Role MFA Required Privileged
Alice User Employee Yes No
Bob User Admin Yes Yes
Guest1 Guest External Yes No
App1 Workload Application N/A Review

Ask:

Does Every Identity Need Its Current Access?

Part 41 — Practical Exercise — Access Model

Section titled “Part 41 — Practical Exercise — Access Model”

Design:

Finance Team
Finance Group
Finance SharePoint Site

instead of granting access user by user.

Then ask:

Who Maintains Group Membership?
How Often Is Access Reviewed?
What Happens When an Employee Leaves?

Part 42 — Practical Exercise — Security Scenario

Section titled “Part 42 — Practical Exercise — Security Scenario”

Scenario:

User Receives Phishing Email
Enters Credentials
Suspicious Sign-In Occurs

Which security layers matter?

Email Security
Identity Security
MFA
Conditional Access
Security Monitoring
Incident Response

This demonstrates:

Defense in Depth

Part 43 — Practical Exercise — Device Scenario

Section titled “Part 43 — Practical Exercise — Device Scenario”

Scenario:

Employee Tries to Access
Corporate Data
from Unmanaged Device

A modern access strategy may consider:

Identity
Authentication
Device State
Application
Policy

before granting access.

When a user reports:

I Cannot Access Microsoft 365

investigate:

User
Account State
License
Authentication
MFA
Access Policy
Device
Service Health
Application

Microsoft 365 Security Assessment Questions

Section titled “Microsoft 365 Security Assessment Questions”

Ask:

Are All Administrative Accounts Known?
Is MFA Enforced for Privileged Users?
Are Guest Accounts Controlled?
Are Dormant Accounts Removed?
Are Devices Managed?
Is External Sharing Controlled?
Are Security Alerts Reviewed?
Are Audit Logs Available?
Is Sensitive Data Protected?

Use four learning stages.

Focus on:

Cloud Concepts
Microsoft 365 Services
Identity
Security
Compliance

Be able to answer:

Which Microsoft 365 Service
Solves This Requirement?

Example:

Email
→ Exchange Online
Collaboration
→ Teams
Team Documents
→ SharePoint
Personal Cloud Files
→ OneDrive
Identity
→ Microsoft Entra ID
Endpoint Management
→ Intune

Practice:

Business Requirement
Microsoft Capability

For every service ask:

Who Has Access?
How Is It Protected?
How Is It Monitored?
What Happens If It Is Compromised?

For scenario questions:

01 Read the Requirement
02 Identify the Service Category
03 Identify the Security or Business Need
04 Remove Unrelated Services
05 Select the Best-Fit Capability

Do not confuse:

Entra ID
with
Active Directory

Do not confuse:

SharePoint
with
OneDrive

Do not confuse:

Authentication
with
Authorization

Do not confuse:

Security
with
Compliance

Do not confuse:

Device Management
with
Threat Detection

Microsoft 365 fundamentals support many roles.

Microsoft 365 Administrator
Help Desk Engineer
Endpoint Administrator
Identity Administrator
SOC Analyst
Security Engineer
Cloud Security Engineer
Security Consultant

You may be asked:

What Is Microsoft 365?
What Is Entra ID?
How Does MFA Improve Security?
What Is Conditional Access?
Difference Between OneDrive and SharePoint?
What Is Intune?
How Would You Secure an Admin Account?
What Is Zero Trust?

30 Microsoft 365 Fundamentals Interview Questions

Section titled “30 Microsoft 365 Fundamentals Interview Questions”
  1. What is Microsoft 365?
  2. What is cloud computing?
  3. What is SaaS?
  4. How does SaaS differ from IaaS?
  5. What is a public cloud?
  6. What is hybrid cloud?
  7. What is Microsoft Entra ID?
  8. What is an identity?
  9. What is a Microsoft 365 tenant?
  10. What is authentication?
  11. What is authorization?
  12. What is MFA?
  13. What is least privilege?
  14. What is Conditional Access?
  15. What is Exchange Online?
  16. What is Microsoft Teams?
  17. What is SharePoint Online?
  18. What is OneDrive?
  19. What is the difference between SharePoint and OneDrive?
  20. What is Microsoft Intune?
  21. What is device compliance?
  22. What is Zero Trust?
  23. What is Microsoft Defender?
  24. What is a security alert?
  25. What is a security incident?
  26. What is data classification?
  27. What is DLP?
  28. What is retention?
  29. Why are audit logs important?
  30. What responsibilities remain with the customer in Microsoft 365?

You are ready to move forward when you can explain:

MICROSOFT 365
IDENTITY
APPLICATIONS
DEVICES
SECURITY
COMPLIANCE

without relying on memorized definitions.

  • Understand cloud computing
  • Understand SaaS
  • Understand PaaS
  • Understand IaaS
  • Understand public cloud
  • Understand hybrid cloud
  • Understand shared responsibility
  • Understand Microsoft 365
  • Understand tenant concept
  • Understand service relationships
  • Understand administration basics
  • Understand Microsoft Entra ID
  • Understand users
  • Understand groups
  • Understand roles
  • Understand authentication
  • Understand authorization
  • Understand MFA
  • Understand Exchange Online
  • Understand Teams
  • Understand SharePoint
  • Understand OneDrive
  • Understand Microsoft 365 Apps
  • Understand endpoint-management concepts
  • Understand Intune
  • Understand device compliance
  • Understand Zero Trust
  • Understand Conditional Access concept
  • Understand Microsoft Defender concept
  • Understand alerts
  • Understand incidents
  • Understand least privilege
  • Understand data classification
  • Understand DLP
  • Understand retention
  • Understand audit
  • Understand security vs compliance

Before considering the fundamentals stage complete:

  • Review Microsoft 365 terminology
  • Understand the major services
  • Map services to business requirements
  • Review Microsoft Entra ID
  • Review security concepts
  • Review compliance concepts
  • Practice scenario questions
  • Practice explaining services without notes
  • Complete basic hands-on exploration where available
  • Review weak topics

Remember Microsoft 365 as:

IDENTITY
MICROSOFT 365
+-----------------------------+
| Exchange |
| Teams |
| SharePoint |
| OneDrive |
| Applications |
+-----------------------------+
DEVICES
SECURITY
COMPLIANCE
MONITORING

You now understand the Microsoft 365 foundation behind the broader Microsoft security ecosystem.

The key lesson is:

Microsoft 365
Is Not Just Productivity Software

It is an enterprise platform connecting:

Identity
Users
Devices
Applications
Data
Security
Compliance

This foundation is important before moving into deeper endpoint and identity-security administration.

➡️ 02 — Endpoint Administration

In the next lesson, you will move from cloud-service fundamentals into enterprise device management.

You will learn how organizations manage:

Windows Endpoints
Device Enrollment
Microsoft Intune
Configuration Profiles
Compliance Policies
Application Management
Windows Updates
Endpoint Security
Access Control

The career progression continues:

01 Microsoft 365 Fundamentals
02 Endpoint Administration
03 Microsoft Identity & Security
Microsoft Security Labs
Microsoft Security Runbooks