Microsoft 365 Administration
Microsoft 365 administration is the work of operating an organization's cloud tenant. It connects identities, licenses, domains, collaboration services, security controls, and service monitoring so people receive the right access and administrators can respond to change or failure.
itWindows and Microsoft infrastructure | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic: Microsoft 365 Administration
Microsoft 365 administration is the craft of keeping a tenant, the organization’s cloud boundary, coherent while it contains identities, subscriptions, domains, and several services that have all brought their own control panels. The Microsoft 365 admin center is the foyer, not the building. It gets you to users, groups, licenses, health, and support, then politely points toward Exchange, Teams, SharePoint, Intune, Defender, Purview, and Microsoft Entra when a workload wants its own rules. This is not indecision. It is a distributed service collection wearing one logo.
Most trouble becomes less mysterious when you ask four questions in order: which identity is changing, which authority permits it, which license and service plan enable it, and which workload signal confirms it. A user account is a directory object, not a parcel of Outlook and Teams with a name tag. License assignment starts provisioning, but a service still needs to finish its part of the arrangement. The portal can congratulate itself early. Your verification should wait for the workload.
A custom domain adds another small expedition. It is an organization-owned name attached to the tenant, not a second tenant. DNS first proves ownership, then routes services. Change mail routing only after the intended users and mailboxes exist, keep the prior records, and define the return path before the change. DNS propagation has an unhelpful habit of making different observers correct at different times.
When something breaks, a green Service health panel is useful but not magical. It can point to a Microsoft incident; it cannot certify the tenant’s roles, licenses, DNS, policies, or workload objects. Start with scope, then health, recent changes, identity, entitlement, network path, and the workload’s own evidence. Preserve timestamps, error text, correlation identifiers, and audit information before a repair turns the crime scene into a renovation project.
Read the Intro when you want the complete tenant map. The Slides compress the control paths and decisions. The Cheatsheet is the operational order of checks. Field Notes deals with the costs that hide behind tidy portal actions. The practice reference and exercise keep the work inside a developer sandbox, where a test user can be inconvenienced without becoming someone’s Monday. The Quiz then asks whether the four questions still hold together when the portals do their best impression of a maze.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://learn.microsoft.com/en-us/microsoft-365/admin/?view=o365-worldwide
Supports
- Microsoft 365 administration areas for setup, users, groups, domains, subscriptions, service status, and troubleshooting
- Microsoft 365 admin center as the common help and task entry point
- https://learn.microsoft.com/en-us/microsoft-365/admin/admin-overview/admin-center-overview?view=o365-worldwide
Supports
- Common admin-center tasks for users, licenses, passwords, groups, billing, reports, and support
- Relationship between the common admin center and specialist workspaces
- Targeted release can cause administrators to see different features
- https://learn.microsoft.com/en-us/microsoft-365/enterprise/setup-overview-for-enterprises
Supports
- Deployment sequence covering network, identities, security, client software, mobile-device management, services, and training
- Cloud-only and hybrid identity as deployment choices
- Microsoft 365 as a connected set of productivity and management services
- https://learn.microsoft.com/en-us/microsoft-365/admin/add-users/about-admin-roles?view=o365-worldwide
Supports
- Microsoft 365 task-specific administrator roles and their responsibilities
- Role-dependent visibility and authorization in the admin center
- Multifactor authentication guidance for administrators
- https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task
Supports
- Selection of least-privileged Microsoft Entra roles by administrative task
- Role-based delegation for users, groups, applications, and licenses
- https://learn.microsoft.com/en-us/microsoft-365/admin/setup/add-domain?view=o365-worldwide
Supports
- Custom-domain ownership verification through DNS or Domain Connect
- Required service DNS records and the manual configuration path
- Preparing users before changing the mail exchange record
- Incorrect DNS records can cause email and service outages
- https://learn.microsoft.com/en-us/microsoft-365/admin/get-help-with-domains/information-for-dns-records?view=o365-worldwide
Supports
- TXT verification record workflow
- Retrieval and publication of workload-specific DNS records
- https://learn.microsoft.com/en-us/microsoft-365/admin/manage/assign-licenses-to-users?view=o365-worldwide
Supports
- Direct user license assignment and role requirements
- Product licenses contain selectable applications and services
- A deleted user's license becomes available for reassignment
- https://learn.microsoft.com/en-us/microsoft-365/admin/manage/manage-group-licenses?view=o365-worldwide
Supports
- Group-based license assignment in the Microsoft 365 admin center
- Usage-location requirement and inheritance behavior
- Nested groups are not processed for group-based licensing
- Assignment errors, processing behavior, and move ordering between licensed groups
- https://learn.microsoft.com/en-us/microsoft-365/admin/manage/message-center?view=o365-worldwide
Supports
- Message center categories for prevention, change planning, and feature information
- Upcoming changes, planned maintenance, and administrator actions
- Location of Message center under Health in the admin center
- https://learn.microsoft.com/en-us/microsoft-365/enterprise/view-service-health?view=o365-worldwide
Supports
- Service health incidents and advisories
- Public status fallback when the admin center is unavailable
- Planned maintenance is tracked in Message center
- Tenant administrators can report an issue not shown on Service health
- https://learn.microsoft.com/en-us/microsoft-365/admin/manage/health-dashboard-overview?view=o365-worldwide
Supports
- Health dashboard combines service, software update, security, usage, and license indicators
- Critical service and billing alerts can appear in the tenant health view
- https://github.com/sindresorhus/awesome
Supports
- Starting directory used for the required awesome-list discovery pass
- https://github.com/fmorrison42/Awesome-Microsoft365
Supports
- Discovery of Microsoft Remote Connectivity Analyzer
- Discovery of Office Deployment Tool and Office Customization Tool
- Discovery of the Exchange Online PowerShell module
- https://testconnectivity.microsoft.com/
Supports
- Microsoft-hosted connectivity tests for Microsoft 365 services
- Awesome Links rationale for service-specific connectivity diagnostics
- https://learn.microsoft.com/en-us/microsoft-365-apps/deploy/overview-office-deployment-tool
Supports
- Office Deployment Tool configuration of products, languages, update behavior, display, and installation source
- Awesome Links rationale for controlled Microsoft 365 Apps deployment
- https://learn.microsoft.com/en-us/microsoft-365-apps/admin-center/overview-office-customization-tool
Supports
- Web-based creation of Office Deployment Tool configuration files
- Awesome Links rationale for repeatable client configuration
- https://www.powershellgallery.com/packages/ExchangeOnlineManagement
Supports
- Official Exchange Online Management PowerShell module package
- Awesome Links rationale for supported Exchange Online automation
- https://www.coreview.com/
Supports
- CoreView Microsoft 365 tenant management and resilience positioning
- Landscape placement for multi-tenant visibility and configuration oversight
- https://help.coreview.com/en_US/understanding-operators
Supports
- CoreView delegated operators, roles, permissions, virtual tenants, and audit log
- CoreView placement in the course's authority and scope model
- https://www.avepoint.com/products/enpower
Supports
- AvePoint EnPower delegated Microsoft 365 operations and policy management
- Workload coverage across Microsoft 365 services
- https://www.manageengine.com/microsoft-365-management-reporting/
Supports
- M365 Manager Plus management, auditing, monitoring, and reporting functions
- Landscape placement as a consolidated administration interface
- https://admindroid.com/
Supports
- AdminDroid reporting, audit, license, usage, and Microsoft 365 management capabilities
- Landscape placement for delegated reporting and operational visibility
- https://admindroid.com/understand-admindroid-licensing
Supports
- AdminDroid free and paid capability structure
- https://www.quest.com/on-demand/
Supports
- Quest On Demand migration, management, reporting, security, and recovery for hybrid Microsoft 365
- Landscape placement for migration and multi-tenant operations
- https://www.bettercloud.com/
Supports
- BetterCloud cross-SaaS user, application, spend, governance, and workflow scope
- Landscape placement for lifecycle operations beyond Microsoft 365
- https://microsoft365dsc.com/user-guide/get-started/introduction/
Supports
- Microsoft365DSC as open-source Microsoft 365 configuration as code
- Tenant snapshots, deployment, comparison, reporting, and drift monitoring
- https://news.microsoft.com/source/2011/06/28/microsoft-launches-office-365-globally/
Supports
- June 28, 2011 global availability of Office 365
- Initial combination of Office, Exchange Online, SharePoint Online, and Lync Online
- https://blogs.microsoft.com/blog/2013/02/27/office-365-to-the-cloud-and-beyond/
Supports
- February 27, 2013 release milestone for updated Office 365 services
- https://www.microsoft.com/en-us/microsoft-365/blog/2016/09/27/office-365-administration-announcements-new-admin-center-reaches-general-availability-and-introducing-the-service-health-dashboard/
Supports
- September 2015 preview of the redesigned Office 365 admin center
- September 27, 2016 general availability of the new admin center
- Introduction of the Service health dashboard
- https://blogs.microsoft.com/blog/2017/07/10/microsoft-puts-partners-center-4-5-trillion-transformation-opportunity/
Supports
- July 10, 2017 introduction of Microsoft 365
- Combination of Office 365, Windows, and Enterprise Mobility and Security offerings
- https://techcommunity.microsoft.com/blog/microsoft_365blog/introducing-the-microsoft-365-admin-center/167392
Supports
- March 2, 2018 rollout of the Microsoft 365 admin center at admin.microsoft.com
- Unified management vision for users, devices, applications, and services
- https://www.microsoft.com/en-gb/microsoft-365/blog/2018/04/27/making-it-simpler-with-a-modern-workplace/
Supports
- April 27, 2018 expansion of Microsoft 365 admin center access to Office 365 users
- Common entry point while retaining Microsoft service capabilities
- https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults
Supports
- Security-default behavior for tenants created on or after October 22, 2019
- Baseline multifactor authentication and legacy-authentication protections
- https://www.microsoft.com/en-us/security/blog/2023/07/11/microsoft-entra-expands-into-security-service-edge-and-azure-ad-becomes-microsoft-entra-id/
Supports
- July 11, 2023 announcement that Azure Active Directory would become Microsoft Entra ID
- Rename did not change deployments, configurations, sign-in URLs, APIs, capabilities, or licensing plans
- https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq
Supports
- Eligible Microsoft 365 Developer Program members receive a Microsoft 365 E5 developer subscription with 25 user licenses for development and testing
- Instant sandboxes include test users, sample data, and an administrator account that can be managed through the admin center
- The practice reference and exercise requirement to use an isolated developer tenant rather than a production tenant
- https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access
Supports
- Emergency access accounts should be cloud-only, protected with phishing-resistant authentication, monitored, and validated regularly
- Conditional Access exclusions and authentication dependencies can prevent recovery accounts from working during the emergency they are intended to address
- https://www.microsoft.com/en-us/security/blog/2023/12/05/microsoft-incident-response-lessons-on-preventing-cloud-identity-compromise/
Supports
- Microsoft Incident Response findings on privilege paths through roles, hybrid identity, workload identities, and delegated administration
- Field Notes guidance to review delegated partner relationships and privileged non-human identities as administration paths
- https://learn.microsoft.com/en-us/purview/audit-log-retention-policies
Supports
- Microsoft Purview audit retention differs by audit capability, license, activity, policy, and record generation date
- Field Notes guidance to verify audit retention before an investigation depends on historical evidence
