Target Audience
This course is designed for administrators aspiring to the Microsoft 365 Administrator role. It is intended for professionals responsible for coordinating across Microsoft 365 workloads, including identity, security, compliance, endpoints, applications, collaboration, and productivity services. It is also valuable for organizations that need administrators capable of operating as the integrating hub for Microsoft 365 environments. The course supports teams that manage tenant configuration, identity synchronization, security posture, threat protection, compliance controls, user administration, service health, and Microsoft 365 governance in enterprise environments.
Instructor-Led (Live Virtual/Classroom)
A live course led by a certified instructor, in virtual or classroom format — one full day of guided sessions with projects and case studies.
Course Overview
MS-102 covers the core responsibilities of a Microsoft 365 administrator, including tenant deployment and management, Microsoft 365 service configuration, identity synchronization, authentication and secure access, Microsoft Defender XDR threat protection, and Microsoft Purview compliance management. The course connects administrative tasks with real operational scenarios across Microsoft 365 cloud and hybrid environments. Participants will learn how to configure organizational settings, domains, subscriptions, users, groups, licenses, administrative roles, and service health. They will also explore Microsoft Entra Connect Sync, Microsoft Entra Cloud Sync, multifactor authentication, self-service password reset, Conditional Access, Microsoft Defender for Office 365, Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, Microsoft Secure Score, Microsoft Purview information protection, retention, sensitivity labels, and data loss prevention.
Last Updated: 2026-09-01
Course Exam Overview
- Program Name: Microsoft 365 Administrator
- Included: Course, applicable labs, and virtual instructor-led facilitation included; certification exam attempt is managed separately when required.
- Duration: 100 minutes
- Prerequisites: Experience with Microsoft 365 workloads and Microsoft Entra ID required. Must have administered at least one workload. Basic knowledge of networking, AD DS, DNS, and PowerShell recommended. Requires a qualifying Microsoft associate-level certification.
- Exam Format: Proctored expert-level exam with possible interactive components. Covers tenant management, identity and access, security with Defender XDR, and compliance with Purview. Passing score is 700 or higher.
- Delivery: Pearson VUE. Available online or at test centers, depending on region.
- Outcome: Microsoft 365 Administrator Expert certification upon meeting all requirements.
Skills You’ll Gain
Job Roles & Industry Outlook
Microsoft 365 Administrator
Manages Microsoft 365 tenant configuration, users, licenses, identities, security services, compliance controls, and workload administration across cloud and hybrid environments.
Microsoft 365 Security Administrator
Implements Microsoft Defender XDR, identity protection, threat protection, and security posture improvements to reduce organizational risk across Microsoft 365 services.
Microsoft 365 Security Administrator
Configures Microsoft Purview capabilities such as retention, sensitivity labels, data loss prevention, insider risk management, and information governance.
Course Includes
• Five-day instructor-led training experience aligned to Microsoft Learn MS-102T00-A.• Administrative coverage of Microsoft 365 tenant management, users, groups, roles, licenses, services, and client connectivity.
• Technical guidance for Microsoft Entra identity synchronization, secure access, MFA, self-service password management, and identity protection.
• Practical coverage of Microsoft Defender XDR, Microsoft Defender for Cloud Apps, Microsoft Defender for Endpoint, Microsoft Secure Score, and security reporting.
• Preparation alignment for the Microsoft 365 Administrator exam, with exam attempt managed separately when required.
What You'll Learn
This module introduces the tenant-level capabilities required to establish, configure, monitor, and maintain a Microsoft 365 environment. Participants work with organizational settings, domains, subscriptions, service health, network insights, software updates, adoption information, and Microsoft 365 Backup.
Lessons:
• Implement a Microsoft 365 tenant: create and configure a tenant, review subscription options, configure the organizational profile, and establish foundational administrative settings.
• Configure domains and organizational settings: add and verify custom domains, configure DNS requirements, and manage security, privacy, release, and organization-profile settings.
• Monitor tenant health and connectivity: use Service Health, configure service notifications, review network connectivity insights, and develop an administrative response process for service incidents.
• Manage updates, adoption, and backup: monitor Microsoft 365 usage, configure software-update settings, review adoption information, and configure and manage Microsoft 365 Backup.
Key Topics:
• Microsoft 365 tenants.
• Tenant subscriptions.
• Organizational profile.
• Custom domains.
• DNS configuration.
• Security and privacy settings.
• Service Health.
• Service notifications.
• Network connectivity insights.
• Software updates.
• Adoption and usage monitoring.
• Microsoft 365 Backup.
Labs / Practical Exercises (if applicable):
• Configure organizational settings and a custom domain in a Microsoft 365 tenant.
• Review Service Health and configure administrative notifications.
• Analyze tenant usage and network connectivity information.
• Configure tenant update and backup settings.
This module develops the skills required to administer users, external identities, contacts, groups, shared mailboxes, licenses, roles, role groups, administrative units, and privileged access across Microsoft 365 and Microsoft Entra ID.
Lessons:
• Manage users and external identities: create and maintain internal users, external users, guests, contacts, and shared mailboxes and perform bulk identity-management operations.
• Manage groups and collaboration identities: create and configure Microsoft 365 Groups, security groups, distribution groups, dynamic groups, and group ownership and membership.
• Manage licenses: assign, modify, monitor, and recover Microsoft 365 licenses through individual and group-based licensing processes.
• Manage roles and delegated administration: configure Microsoft 365 and Microsoft Entra roles, workload role groups, administrative units, and privileged role activation through Microsoft Entra Privileged Identity Management.
• Automate administrative operations: use Microsoft Graph PowerShell and Microsoft Entra PowerShell to perform bulk user, group, license, and role-management activities.
Key Topics:
• Internal and external users.
• Guests and contacts.
• Shared mailboxes.
• Microsoft 365 Groups.
• Security and distribution groups.
• Dynamic membership.
• Individual licensing.
• Group-based licensing.
• Administrative roles.
• Workload role groups.
• Administrative units.
• Privileged Identity Management.
• Microsoft Graph PowerShell.
• Microsoft Entra PowerShell.
Labs / Practical Exercises (if applicable):
• Create and manage users, guests, contacts, and groups.
• Configure individual and group-based license assignments.
• Delegate administration through roles and administrative units.
• Perform bulk identity-management operations using PowerShell.
This module focuses on deploying, configuring, updating, and maintaining Microsoft 365 Apps for enterprise. Participants also examine client-connectivity requirements, user-driven and centralized deployment methods, and techniques for troubleshooting access to Microsoft 365 services.
Lessons:
• Plan Microsoft 365 Apps deployments: assess organizational requirements, select deployment channels, configure application packages, and prepare users and devices for installation.
• Implement user-driven and centralized deployments: manage self-service installations, centralized deployment processes, assignment settings, and application availability.
• Manage application updates: configure update channels, deployment rings, release settings, and update monitoring through Microsoft 365 administrative tools.
• Configure and troubleshoot client connectivity: review DNS, network, proxy, authentication, and Office-client requirements and investigate connectivity failures.
Key Topics:
• Microsoft 365 Apps for enterprise.
• Deployment planning.
• User-driven installation.
• Centralized deployment.
• Application assignments.
• Update channels.
• Deployment rings.
• Release preferences.
• Office client connectivity.
• DNS and network requirements.
• Connectivity troubleshooting.
Labs / Practical Exercises (if applicable):
• Prepare a Microsoft 365 Apps deployment configuration.
• Configure installation and update-channel settings.
• Review application deployment and update status.
• Diagnose a simulated Microsoft 365 client-connectivity issue.
This module examines the planning, implementation, monitoring, and troubleshooting of identity synchronization between on-premises Active Directory Domain Services and Microsoft Entra ID using Microsoft Entra Connect Sync and Microsoft Entra Cloud Sync.
Lessons:
• Prepare for identity synchronization: assess directory requirements, review domain and identity readiness, remediate directory issues with IdFix, and select an appropriate synchronization architecture.
• Implement Microsoft Entra Connect Sync: install and configure synchronization, define scope and filtering, manage synchronized identities, and review supported authentication options.
• Implement Microsoft Entra Cloud Sync: evaluate appropriate use cases, configure provisioning agents, define synchronization scope, and manage cloud-based synchronization.
• Monitor and troubleshoot synchronization: use Microsoft Entra Connect Health, review synchronization status and errors, and resolve issues affecting Connect Sync or Cloud Sync.
Key Topics:
• Hybrid identity.
• Directory readiness.
• IdFix.
• Microsoft Entra Connect Sync.
• Microsoft Entra Cloud Sync.
• Synchronization scope.
• Domain and organizational-unit filtering.
• Provisioning agents.
• Synchronized identities.
• Microsoft Entra Connect Health.
• Synchronization troubleshooting.
Labs / Practical Exercises (if applicable):
• Evaluate an on-premises directory for synchronization readiness.
• Compare Microsoft Entra Connect Sync and Cloud Sync for a hybrid scenario.
• Configure synchronization scope and filtering.
• Investigate and resolve simulated synchronization errors.
This module develops the capabilities required to manage authentication methods, self-service password reset, password protection, identity risk, Conditional Access, and multifactor authentication across Microsoft 365 and Microsoft Entra ID.
Lessons:
• Manage authentication methods: configure supported authentication methods, registration policies, combined security-information registration, and authentication-related user settings.
• Implement password management: configure self-service password reset, password writeback where applicable, Microsoft Entra Password Protection, and processes for investigating authentication failures.
• Implement Microsoft Entra Identity Protection: plan identity-risk controls, review risky users and sign-ins, configure risk policies, and investigate identity-protection detections.
• Implement Conditional Access and MFA: plan, create, test, deploy, monitor, and troubleshoot Conditional Access policies and enforce multifactor authentication according to organizational risk requirements.
Key Topics:
• Authentication methods.
• Security-information registration.
• Self-service password reset.
• Password writeback.
• Microsoft Entra Password Protection.
• Authentication troubleshooting.
• Identity Protection.
• Risky users and sign-ins.
• Conditional Access.
• Multifactor authentication.
• Policy testing and monitoring.
• Emergency access considerations.
Labs / Practical Exercises (if applicable):
• Configure authentication methods and self-service password reset.
• Review and investigate risky users and sign-in events.
• Design and test Conditional Access policies.
• Implement multifactor authentication through Conditional Access.
This module introduces the unified security-operations capabilities of Microsoft Defender XDR. Participants evaluate organizational exposure, improve security posture, investigate incidents and alerts, use advanced hunting, and respond to threat intelligence and security reports.
Lessons:
• Review security posture and exposure: use Microsoft Security Exposure Management and Microsoft Secure Score to identify weaknesses, prioritize recommended actions, and monitor security improvements.
• Investigate Defender XDR incidents and alerts: review correlated incidents, analyze affected assets and evidence, assign classifications, determine scope, and coordinate response actions.
• Use advanced hunting and security reports: query security information, investigate suspicious behavior, review Microsoft Defender XDR reports, and identify unresolved security issues.
• Review Microsoft Defender Threat Intelligence: examine threat actors, indicators, infrastructure, and intelligence reports and apply findings to organizational defense decisions.
Key Topics:
• Microsoft Defender XDR.
• Security Exposure Management.
• Microsoft Secure Score.
• Recommended security actions.
• Incidents and alerts.
• Evidence and affected assets.
• Incident investigation.
• Advanced hunting.
• Security reports.
• Threat Intelligence.
• Threat indicators.
• Response coordination.
Labs / Practical Exercises (if applicable):
• Review Secure Score and prioritize security recommendations.
• Investigate a simulated Microsoft Defender XDR incident.
• Perform an advanced-hunting query to identify suspicious activity.
• Review threat-intelligence information and recommend response actions.
This module focuses on implementing and managing threat protection across email, collaboration workloads, endpoints, and cloud applications using Microsoft Defender for Office 365, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud Apps.
Lessons:
• Protect email and collaboration: configure Exchange Online Protection, anti-phishing and anti-malware settings, Safe Attachments, Safe Links, threat policies, rules, and alert policies in Microsoft Defender for Office 365.
• Investigate email and collaboration threats: analyze malicious messages and campaigns, respond to detected threats, manage restricted entities and blocked users, and configure attack-simulation training campaigns.
• Implement Defender for Endpoint: onboard devices, configure endpoint settings, review security recommendations, and investigate vulnerabilities through Microsoft Defender Vulnerability Management.
• Implement Defender for Cloud Apps: configure the Microsoft 365 app connector, create policies and alerts, review the activity log, configure Cloud App Discovery, and investigate discovered cloud applications.
Key Topics:
• Exchange Online Protection.
• Anti-phishing and anti-malware.
• Safe Attachments.
• Safe Links.
• Threat policies and rules.
• Alert policies.
• Attack simulation training.
• Restricted entities.
• Defender for Endpoint onboarding.
• Endpoint security settings.
• Vulnerability Management.
• Defender for Cloud Apps.
• Cloud App Discovery.
• Activity monitoring.
Labs / Practical Exercises (if applicable):
• Configure email and collaboration threat-protection policies.
• Investigate and respond to a simulated malicious email campaign.
• Review endpoint vulnerabilities and recommended remediation actions.
• Configure Cloud App Discovery policies and analyze discovered activity.
This module develops the skills required to discover, classify, retain, protect, and monitor organizational information using Microsoft Purview. Participants configure sensitive information types, retention, sensitivity labels, data loss prevention, Endpoint DLP, and compliance reporting across Microsoft 365 workloads.
Lessons:
• Implement sensitive information types: create and manage classifications using keywords, keyword lists, regular expressions, confidence levels, and supporting evidence.
• Implement information protection: create sensitivity labels and publishing policies, configure protection and content markings, and monitor label adoption and usage.
• Implement data lifecycle management: configure retention labels, retention-label policies, retention policies, and disposition requirements for Microsoft 365 information.
• Implement data loss prevention: configure DLP policies across Exchange Online, SharePoint Online, OneDrive, Teams, Power BI, Microsoft 365 Copilot, and supported endpoint locations.
• Monitor compliance controls: use Content explorer, Activity explorer, label reports, DLP alerts, events, and reports to evaluate policy effectiveness and investigate compliance issues.
Key Topics:
• Microsoft Purview.
• Sensitive information types.
• Keywords and regular expressions.
• Sensitivity labels.
• Label publishing policies.
• Content explorer.
• Activity explorer.
• Retention labels.
• Retention policies.
• Data lifecycle management.
• Data loss prevention.
• Endpoint DLP.
• DLP for Microsoft 365 Copilot.
• Compliance alerts and reports.
Labs / Practical Exercises (if applicable):
• Create a sensitive information type for an organizational data pattern.
• Configure and publish sensitivity and retention labels.
• Create a DLP policy covering Microsoft 365 workloads and endpoints.
• Review label activity and investigate simulated DLP alerts.
Recommended Courses
Frequently Asked Questions
If you see Register Now, the course is free and available for direct registration; simply complete the form to secure your seat.
If you see More Information, share your contact details and an ITG Learning Advisor will contact you to confirm pricing, available dates, delivery options, and next steps.
We’ll help you find the right fit. Select More Information, and one of our ITG Learning Advisors will present other available dates, related courses, delivery formats, and learning paths based on your goals.
BlockSkill is ITG’s learning and skilling platform. It brings your learning experience together in one place, giving you access to your enrolled courses, learning materials, available videos, activities, surveys, progress information, and certificates of completion.
Available resources may vary depending on the course and delivery format.
An exam voucher is a code or authorization that covers one attempt at an official certification exam. A practice assessment is included only when it is specifically listed as part of the selected package.
To earn the official certification, you must pass the corresponding vendor exam or assessment. Ask an ITG Learning Advisor whether the exam voucher is included with your course.
Yes. You may purchase an exam voucher without enrolling in the related course, subject to vendor availability, exam eligibility, and regional conditions.
Our team can help you identify the correct voucher for your certification goal and explain the available purchasing options.
ITG offers private and customized training for teams, businesses, government agencies, and other organizations. We can help you select the right courses and coordinate schedules, delivery formats, and learning paths aligned with your organization’s goals.
Select More Information to connect with an ITG Learning Advisor and explore the best training option for your team
Ready to start?
Get certified.
Join the next live cohort of AI+ Everyone™ and earn your industry-recognized credential.