Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Microsoft

Govern and secure Microsoft 365 tenants and workloads

Microsoft via Microsoft Learn

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
  • Provision and govern users, guests, groups, and privileged roles in Microsoft Entra using least-privilege administrative units, Privileged Identity Management, and Microsoft Graph PowerShell.

    After completing this module, you can:

    • Manage the full user and contact lifecycle, and govern guest and external collaboration.
    • Create and govern groups, including Microsoft 365 groups, naming policy, and expiration policy.
    • Assign and govern administrative roles using role groups and Privileged Identity Management (PIM).
    • Scope delegated administration with administrative units and perform bulk management using Microsoft Graph PowerShell.
    • Recognize directory synchronization, custom-role, and multitenant Organization options.
  • Configure authentication methods, Password Protection, self-service password reset, and Conditional Access policies that respond to sign-in risk, user risk, and device compliance, and investigate authentication issues using the Sign-in logs, Sign-in diagnostic, and What If tool.

    After completing this module, you can:

    • Evaluate the Microsoft Entra authentication method catalog and configure the unified Authentication methods policy to scope methods to a target group.
    • Enforce Microsoft Entra Password Protection with the global and custom banned password lists and smart lockout for cloud accounts.
    • Enable and troubleshoot self-service password reset (SSPR) registration, method requirements, and enablement scope.
    • Evaluate multiple interacting Conditional Access policies, including client app conditions, to determine sign-in outcomes.
    • Investigate and resolve authentication issues using the Sign-in logs, the Sign-in diagnostic, and the Conditional Access What If tool.
    • Design Conditional Access policies that respond to sign-in risk, user risk, and device compliance state.
  • Defend email and collaboration workloads using Microsoft Defender for Office 365—configure threat protection policies, manage alerts, investigate and respond to threats, and run attack simulation training—and understand how it fits the broader Microsoft Defender security estate.

    After completing this module, you can:

    • Manage the Microsoft Defender for Office 365 alert queue, including updating alert status.
    • Configure threat protection policies and their per-policy settings, and scope custom policies correctly around presets.
    • Investigate and respond to email and collaboration threats using Threat Explorer, the Email entity page, and automated investigation and response (AIR).
    • Configure and manage attack simulation training, including training campaigns.
    • Describe how Microsoft Defender for Office 365 fits within the broader Microsoft Defender security estate.
  • Specify information-protection requirements for sensitive content, choose the right classification technique for a given data shape, and verify Microsoft Copilot grounding against known label, encryption, and Teams-chat limitations.

    After completing this module, you can:

    • Identify requirements for information protection, including sensitive information types, sensitivity labels, and sensitivity label policies.
    • Choose the appropriate classification technique (sensitive information type, exact data match, or trainable classifier) to meet a requirement while minimizing false positives.
    • Recognize how Microsoft Purview reporting verifies that classification is being applied as specified.
    • Verify that classification and labeling support safe Microsoft Copilot grounding.
  • Specify data loss prevention requirements across Microsoft 365 workloads and Microsoft Copilot, respond to DLP alerts, specify data lifecycle management requirements, and monitor AI activity using Data Security Posture Management (DSPM) for AI.

    After completing this module, you can:

    • Identify requirements for DLP policies across Exchange, SharePoint, OneDrive, Teams, endpoints, and Microsoft Copilot.
    • Review and respond to DLP alerts, including alerts correlated in Microsoft Defender.
    • Identify requirements for data lifecycle management, including retention labels, retention label policies, and retention policies.
    • Monitor and secure AI activity by using Data Security Posture Management (DSPM) for AI.
    • Recognize the broader Microsoft Purview governance surface, including reporting and alerting, insider risk management, and auditing.

Syllabus

  • Provision and govern identities in Microsoft Entra
    • Introduction
    • Manage the user and contact lifecycle
    • Perform bulk identity management with Microsoft Graph PowerShell
    • Exercise - Bulk-provision Relecloud's new-hire users with Microsoft Graph PowerShell
    • Manage guests and external collaboration
    • Create and manage groups, naming policy, and expiration policy
    • Scope delegated administration with administrative units
    • Exercise - Scope Relecloud's regional HR admin with an administrative unit
    • Govern roles with role groups and Privileged Identity Management
    • Exercise - Configure a PIM approval workflow for Relecloud privileged role
    • Module assessment
    • Summary
  • Implement authentication and access in Microsoft Entra
    • Introduction
    • Evaluate and scope the authentication method catalog
    • Enforce Password Protection for cloud accounts
    • Enable and troubleshoot self-service password reset
    • Exercise - Scope authentication methods and enable SSPR for Relecloud's engineering team
    • Evaluate Conditional Access policies and client app conditions
    • Investigate and resolve authentication issues
    • Resolve sign-in risk and device compliance in Conditional Access
    • Exercise - Design and verify Conditional Access pilot policies
    • Module assessment
    • Summary
  • Secure email and collaboration with Microsoft Defender for Office 365
    • Introduction
    • Configure threat policies: presets, custom policies, and precedence
    • Configure the settings inside each threat policy
    • Extend protection to Teams, SharePoint, and OneDrive
    • Exercise - Configure and scope threat protection for Relecloud's finance team
    • Manage alerts and investigate threats
    • Remediate and reduce human risk: AIR and attack simulation training
    • Exercise - Investigate a threat and reduce human risk with attack simulation training
    • Coordinate with the broader Microsoft Defender security estate
    • Module assessment
    • Summary
  • Protect information with Microsoft Purview information protection
    • Introduction
    • Choose a classification technique for a data shape
    • Exercise - Create a custom sensitive information type for Woodgrove's transaction pattern
    • Design what a sensitivity label protects
    • Publish label policies and resolve conflicting settings
    • Exercise - Configure and publish a sensitivity label policy, then verify priority resolution
    • Verify classification is working with Purview reporting
    • Verify classification supports safe Microsoft Copilot grounding
    • Module assessment
    • Summary
  • Prevent data loss and govern the data lifecycle with Microsoft Purview
    • Introduction
    • Specify DLP requirements across Microsoft 365 locations
    • Exercise - Create a DLP policy for Microsoft Copilot
    • Attribute DLP alerts across AI apps and agents
    • Respond to DLP alerts in Microsoft Defender XDR
    • Exercise - Review a DLP alert in Microsoft Defender XDR
    • Specify data lifecycle management requirements
    • Monitor AI activity and oversharing risk with Data Security Posture Management
    • Exercise - Review a data risk assessment in Data Security Posture Management
    • Recognize the broader Microsoft Purview governance surface
    • Module assessment
    • Summary

Reviews

Start your review of Govern and secure Microsoft 365 tenants and workloads

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.