Index

A

A1/A3/A5 subscriptions. See Microsoft 365 Education

Abnormal Behavior Machine Learning, 89

access control lists (ACLs), 116117

Access from anywhere chart (Usage Analytics), 94

ACLs (access control lists), 116117

activating applications, 178

Active Directory. See AD DS (Active Directory Domain Services);

AD FS (Active Directory Federation Services); Azure AD (Active Directory)

AD DS (Active Directory Domain Services)

Active Directory Users and Computers, 125

compared to on-premises services, 4041

features and capabilities of, 114116, 146148

password policies, 133134

on-premises identities, 124125

structure and hierarchy of, 146148

user accounts, creating, 114116

AD FS (Active Directory Federation Services), 52, 131

Add-on USL (user subscription license), 186

Admin Center

Billing menu, 185, 194195

Exchange Online settings, 2627

features and capabilities of, 4647

Health menu, 204208

Licenses page, 185

New Group interface, 71

Purchase Services page, 185186

Service Health page, 204208

Support menu, 200205

Try The New Admin Center option, 209

Admin Centers menu (Admin Center), 47

administration, 36

Adoption chart (Usage Analytics), 94

Advanced Threat Analytics (ATA), 3334, 85, 8891, 143

Advanced Threat Protection (ATP), 22, 35, 143, 182

advisories, 205

AIP (Azure Information Protection), 33, 85, 105106, 117118, 139143, 182

alerts, 154

analytics

Microsoft 365 Usage Analytics, 9294

Microsoft ATA (Advanced Threat Analytics), 3334, 85, 8891, 143

MyAnalytics, 9496

Workplace Analytics, 9699

anomalous logins, 89

anticipation of threats, 111

Application Proxy, 129

Application Proxy Connector, 129

application scans, 112

Application Virtualization (App-V), 24, 64

applications, defined, 13. See also individual applications and services

App-V (Application Virtualization), 24, 64

architecture, cloud, 8

architecture, cloud services, 911

hybrid cloud, 1213

private cloud, 1112

Assess phase (compliance), 184

asset inventory, 104106

ATA (Advanced Threat Analytics), 3334, 85, 8891, 143

ATP (Advanced Threat Protection), 22, 35, 143, 182

audit reports, 156

authentication

with Azure AD (Active Directory), 130132

federated authentication, 131

pass-through authentication, 130

password authentication, 128

definition of, 113114

multifactor

biometric scans, 134

cell phone-based, 134

definition of, 134

overview of, 132

password

Azure AD (Active Directory), 128

password changes, 153

password hash synchronization, 129

password policies, 133134

SSPR (Self Service Password Reset), 5253, 153

authorization, 113114

automatic feature updates, 61

Automatically Register New Windows 10 Domain Joined Devices With Azure Active Directory Client setting, 150

Autopilot, 24

availability

definition of, 105

high, 108

Azure. See also Azure AD (Active Directory); cloud services

AIP (Azure Information Protection), 33, 85, 105106, 117118, 139143, 182

ATP (Advanced Threat Protection), 22, 35, 143, 182

management interface, 6

regions, 162

reliability mechanisms, 6

Rights Management (RMS), 33

RMS (Rights Management), 33

Update Management, 16

Azure AD (Active Directory)

Azure AD Connect, 142

Azure Information Protection, 145

cloud identities, 126127

features and capabilities of, 13, 32, 85, 143145

features and services of, 144145

hybrid identities

Application Proxy, 129

authentication, 130132

definition of, 127

first synchronization, 128

SSO (single sign-on), 129

synchronization, 128129

Identity Protection, 136139, 182

licenses, 143

MFA (multifactor authentication) in, 135136

on-premises services versus, 4041

Premium plans, 142, 144145

user accounts, creating, 114116

B

barriers to cloud adoption, overcoming

cost factors, 160161

data security concerns, 161

data storage locations, 162

overview of, 158159

performance latency, 159

personnel requirements, 163

sample scenario for, 165166

service provider selection, 159160

transition process, 163

vendor lock-in, 160

vendor robustness, 160

big switch transitions, 43

Billing Accounts option (Billing menu), 194

billing and bill management, 194196

Billing menu (Admin Center), 47, 185, 194195

Billing Notifications option (Billing menu), 194

Bills & Payments option (Billing menu), 194

biometric scans, 134

BranchCache, 45

Bring Your Own Device. See BYOD (Bring Your Own Device)

brute force attacks, 89

business subscriptions. See Microsoft 365 Business

BYOD (Bring Your Own Device), 57, 102, 120, 141

C

calendars, Exchange Online, 25, 68, 69

CapEx (capital expenditures), 188190

CASB (cloud access security broker), 34

CBA (cost-benefit analysis), 188190, 212213

cell phone-based authentication, 134

CJIS (Criminal Justice Information Services) Policy, 173

classification of users, 109111

Classification tools, 155

Click-to-Run, 6466

client health monitoring, 150

Client Management Tools (CMTs), 140

cloud access security broker (CASB), 34

Cloud App Security, 34, 121122, 143, 182

cloud identities, 126127

cloud services. See also Azure

adoption barriers, overcoming

Contoso Corp. case study, 165166

cost factors, 160161

data security concerns, 161

data storage locations, 162

overview of, 158159

performance latency, 159

personnel requirements, 163

service provider selection, 159160

transition process, 163

vendor lock-in, 160

vendor robustness, 160

advantages of, 3

administration, 36

consolidation, 45

costs and monetary savings, 34, 3536

deployment, 35

infrastructure, 78

manageability, 6

reliability, 56

sample scenario for, 19

scalability, 5

security, 7, 38

updates, 35

architecture of, 8

hybrid cloud, 1213

private cloud, 1112

public cloud, 911

concept of, 12

disadvantages of, 8

online resources, 15

service models

FaaS (Function as a Service), 17

IaaS (Infrastructure as a Service), 1416

infrastructure layers, 1314

PaaS (Platform as a Service), 1617

SaaS (Software as a Service), 18

transitioning to, 163

Wingtip Toys case study, 19

Cloud Solution Provider (CSP) program, 190193, 204

cmdlets

Enable-App, 24

New-ADUser, 125

Set-MsolPasswordPolicy, 133

Set-MsolUser, 133

CMTs (Client Management Tools), 140

Collaboration chart (Usage Analytics), 94

Collaboration pane (MyAnalytics), 95

collaboration tools. See also EMS (Enterprise Mobility + Security)

analytics for

MyAnalytics, 95

Usage Analytics, 94

Workplace Analytics, 97

Exchange Online

Admin Center settings, 2627

collaboration tools, 6768

compared to Exchange Server, 3940

features and capabilities of, 6768

services, 2526

subscription plans, 26

Microsoft Graph, 8182

Microsoft Planner, 72, 76

Microsoft Stream, 75

Microsoft Teams, 2931, 77, 180

Microsoft Yammer, 72

Office 365 groups, 6973

Office 365 ProPlus, 62

OneDrive for Business, 62, 75, 180

overview of, 6667, 179181

Planner, 180

selection of, 7880

SharePoint Online

features and capabilities of, 2729, 7374, 180

SharePoint Server compared to, 40

Skype for Business Online, 31, 77

Stream, 75, 180

Yammer, 7475, 175, 180

Co-management Configuration Wizard, 150151

co-management model, 44, 148152

Communication chart (Usage Analytics), 94

compliance

Compliance Manager, 157158

device compliance and configuration, 8687

services for, 182184

Compliance Manager, 157158

conditional access, 149

confidentiality, 105

consolidation, cloud-based services and, 45

Contact Support pane, 202

Contoso Corp. case study, 165166

core services. See also EMS (Enterprise Mobility + Security)

advantages of

administration, 36

costs, 3536

deployment, 35

security, 38

updates, 35

Exchange Online

Admin Center settings, 2627

collaboration tools, 6768

compared to Exchange Server, 3940

EOP (Exchange Online Protection), 25

features and capabilities of, 180

services, 2526

subscription plans, 26

Microsoft Teams, 2931, 180

Office 365 ProPlus

deployment of, 5456, 6366

features of, 5961, 178179

Microsoft Office suite compared to, 3839, 6163

on-premises services versus

Active Directory, 4041

Exchange, 3940

hybrid service deployments, 40

Office, 3839

SharePoint, 40

SharePoint Online

Admin Center, 72

collaboration with, 180

compared to SharePoint Server, 40

features and capabilities of, 2729, 7374, 180

SharePoint Server compared to, 40

Windows 10 Business, 25

Windows 10 Enterprise

deployment of, 5354

features and capabilities of, 22

management, 24

security, 22

updates, 2224

Core Services and Engineering Operations (CSEO) group, 103

cost models, 34, 3536, 160161

cost-benefit analysis (CBA), 188190, 212213

Create a Virtual Machine interface, 2

Criminal Justice Information Services (CJIS) Policy, 173

Critical (Sev A) severity level, 203

CSEO (Core Services and Engineering Operations) group, 103

CSP (Cloud Solution Provider) program, 190, 191193, 204

Cybersecurity Reference Architecture, 155

D

Data Loss Prevention (DLP), 26, 59, 139140, 182

data privacy standards, compliance with, 182184

data storage locations, 162

database scans, 112

dedicated public cloud, 9

Defense Federal Acquisition Regulation Supplement (DFARS), 174

Delivery Optimization, 45

DEM (device enrollment manager), 58

deployment, 35

hybrid service, 40

Microsoft 365, 4959

deployment strategies, 4950

documentation for, 50

identity, 5153

information protection, 5859

MAM (Mobile Application Management), 57

MDM (Mobile Device Management), 5658

networking, 51

Office 365 ProPlus, 5456

Windows 10 Enterprise, 5354

modern management processes, 43

Office 365 ProPlus, 6366

applications to install, selecting, 6364

Click-to-Run, 6466

deployment, continued

customization options, 6465

Office 2016 and 2019 deployments, 66

sample scenario for, 99100

self-deployment, 50

Desktop Analytics, 23

device enrollment manager (DEM), 58

Device Health (Desktop Analytics), 23

device protection, 178

BYOD (Bring Your Own Device), 57, 102, 120, 141

with Cloud App Security, 121122

with MAM (Mobile Application Management), 121

with MDM (Mobile Device Management), 121

with Microsoft Intune, 119120

overview of, 118119

security usage scenarios, 152153

Devices menu (Admin Center), 46

DFARS (Defense Federal Acquisition Regulation Supplement), 174

digital estate, 102

directory services. See AD DS (Active Directory Domain Services); Azure AD (Active Directory)

disaster recovery, 108

distribution lists, 67

DLP (Data Loss Prevention), 26, 59, 117118, 139140

document protection

ACLs (access control lists)

AIP (Azure Information Protection), 117118

definition of, 116117

DLP (Data Loss Prevention), 117118

AIP (Azure Information Protection), 33, 105106, 117118, 139140, 143

DLP (Data Loss Prevention), 26, 59, 117118, 139140

overview of, 116118

Documents & Resources (Service Trust Portal), 157

Domain Services. See AD DS (Active Directory Domain Services)

downtime, 198199

Driving Value phase of onboarding, 163

dynamic distribution lists, 67

E

E3/E5 subscriptions. See Microsoft 365 Enterprise

EA (Enterprise Agreement), 190

education subscriptions. See Microsoft 365 Education

email hosting, 62

EMM (enterprise mobility management), 141

EMS (Enterprise Mobility + Security). See also Azure AD (Active Directory)

AIP (Azure Information Protection), 33, 85, 105106, 117118, 139143, 182

ATA (Advanced Threat Analytics), 3334, 143

ATP (Advanced Threat Protection), 22, 35, 143, 182

Cloud App Security, 34, 121122, 143, 182

features and capabilities of, 31, 8485, 142143

Microsoft Intune

co-management feature, 148152

device compliance and configuration, 8687

features and capabilities of, 3233, 85, 107, 141142, 182

service architecture, 119120

obstacles to mobility and, 85

Enable-App cmdlet, 24

endpoints, UEM (unified endpoint management)

development of, 140143

EMS (Enterprise Mobility + Security), 142143

Enterprise Agreement (EA), 190

Enterprise Mobility + Security. See EMS (Enterprise Mobility + Security)

enterprise mobility management (EMM), 141

Enterprise Source Licensing Program, 191

enterprise subscriptions. See Microsoft 365 Enterprise

Envisioning phase of onboarding, 163

EOP (Exchange Online Protection), 25

Exchange Online

Admin Center settings, 2627

collaboration tools, 6768

EOP (Exchange Online Protection), 25

Exchange Server compared to, 3940

features and capabilities of, 180

services, 2526

subscription plans, 26

Exchange Server, Exchange Online compared to, 3940

ExcludeApp, 64

expenditures, capital versus operational, 188190

Express Updates, Windows 10, 45

Extended Recovery indicator (Service Health), 206

Extended Support, 209

External collaboration metrics (Workplace Analytics), 97

F

F1 subscriptions. See Microsoft 365 F1

FaaS (Function as a Service), 17

facial recognition, 134

Fail-Over Rights, 191

Family Educational Rights and Privacy Act (FERPA), 183

FastTrack program, 49, 163, 203

FBI, Criminal Justice Information Services (CJIS) Policy, 173

Federal Information Security Modernization Act (FISMA), 182

Federal Risk and Authorization Management Program (FedRAMP), 156, 174

federated authentication, 131

FERPA (Family Educational Rights and Privacy Act), 183

fingerprint readers, 134

first line workers, 170

FISMA (Federal Information Security Modernization Act), 182

Fixed Lifecycle Policy, 209

Focus pane (MyAnalytics), 94

folders, public, 68

Forged PAC attacks, 88

From SA USL (user subscription license), 186

Full USL (user subscription license), 186

Function as a Service (FaaS), 17

G

GA (General Availability) releases, 210

Gateway (ATA), 90

GDPR (General Data Protection Regulation), 156, 183

Geography button (Microsoft Graph), 81

Golden Ticket attacks, 88

government subscriptions. See Microsoft 365 Government

Gramm-Leach-Bliley Act (GLBA), 183

Graph (Microsoft), 8182

groups

Group Policy, 133134

group-by-group transition, 43

Group-to-group queries (Workplace Analytics), 98

modification of, 89

Office 365, 6973

Groups menu (Admin Center), 46

H

hardware inventory, 106108

hardware requirements, 3

hashes, 128129

Health Insurance Portability and Accountability Act (HIPAA), 1112, 183

Health menu (Admin Center), 47, 204208

High (Sev B) severity level, 203

high availability, 108

HIPAA (Health Insurance Portability and Accountability Act), 1112, 183

horizontal scaling, 5

host scans, 112

Hunting tools, 155

Hybrid Azure AD, 149

hybrid cloud, 1213

hybrid identities, 127132

in Azure AD (Active Directory)

Application Proxy, 129

authentication, 130132

passwords, 128

SSO (single sign-on), 129

definition of, 127

first synchronization, 128129

hybrid service deployments, 40

hypervisors, 14

I

IaaS (Infrastructure as a Service), 1416

Identity phase (deployment), 5153

identity protection

in AD DS (Active Directory Domain Services)

hybrid identities, 127132

on-premises identities, 124125

user accounts, creating, 114116

authentication

definition of, 113114

multifactor, 134136

overview of, 132

password, 128129, 133134

authorization, 113114

in Azure AD (Active Directory), 13, 114116

Application Proxy, 129

authentication, 130132

cloud identities, 126127

hybrid identities, 127132

Identity Protection, 136139, 182

passwords, 128

SSO (single sign-on), 129

user accounts, creating, 114116

cloud identities, 126127

hybrid identities, 127132

modern management processes, 43

overview of, 113116, 123, 170

password authentication

in Azure AD (Active Directory), 128

password changes, 153

password hash synchronization, 129

password policies, 133134

SSPR (Self Service Password Reset), 5253, 153

on-premise identities, 124125

risk levels, 136139

Windows Hello for Business, 116

In Development release status, 210

incidents, 205

indirect providers, 193

indirect resellers, 193

Individual service usage chart (Usage Analytics), 94

Industries & Regions (Service Trust Portal), 157

infected devices, 153

information protection, 5859, 170

infrastructure, cloud services, 78

Infrastructure as a Service (IaaS), 1416

Insert Data button (Microsoft Graph), 82

Insert From File pane (Microsoft Graph), 81

installation. See deployment

integrity, data, 105

Internal networks metrics (Workplace Analytics), 97

International Organization for Standardization (ISO), 156

International Traffic in Arms Regulations (ITAR), 173174

international users, 173

Internet of Things (IoT), 141142

Intune. See Microsoft Intune

inventory

assets, 104106

hardware, 106108

Investigating indicator (Service Health), 206

Investigation Suspended indicator (Service Health), 206

IoT (Internet of Things), 141142

ISO (International Organization for Standardization), 156

ITAR (International Traffic in Arms Regulations), 173174

J-K-L

Kerberos, 41, 125

KMS (Key Management Service), 66, 178

labels

retention, 58

sensitivity, 5859

lateral movement, 89

Launched release status, 210

Licenses option (Billing menu), 194

Licenses page, 185

licensing options

Azure AD (Active Directory), 143

basic components, 167168

best practices, 187

CBA (cost-benefit analysis) of, 188190, 212213

feature comparison, 171173

Microsoft 365 Business, 168169, 171173

Microsoft 365 Education, 174177

Microsoft 365 Enterprise, 169173

Microsoft 365 F1, 170173

Microsoft 365 Government, 173174

Office 365 ProPlus, 61

USL (user subscription license), 185186

volume licensing

CSP (Cloud Solution Provider) program, 191193

licensing agreement types, 190

Software Assurance, 190191

support, 203

lifecycle policies, 208211

lists, distribution, 67

loss of devices, 152

LTSB (Long Term Servicing Branch), 24

LTSC (Long Term Servicing Channel), 24

M

mailboxes, Exchange Online, 25, 6869

mail-enabled security groups, 68

Mainstream Support, 209

MAKs (Multiple Activation Keys), 66, 178

malicious replications, 88

MAM (Mobile Application Management), 57, 121, 152

manageability, cloud-based services, 6

management

modern. See also Admin Center

concept of, 4243

configuration, 43

deployment, 43

identity, 43

Microsoft deployment and release model, 4959

Office 365 portal, 4749

traditional management compared to, 42

transitioning to, 4344

updates, 43

WaaS (Windows as a Service), 4445

workloads and scenarios, 59

traditional approach to, 42

Windows 10 Enterprise, 24

Management and coaching metrics (Workplace Analytics), 97

MDM (Mobile Device Management), 5658, 121, 140, 152

MDOP (Microsoft Desktop Optimization Pack), 191

Meeting queries (Workplace Analytics), 98

Meetings overview metrics (Workplace Analytics), 97

@mentions, 81

Message Center page, 207208

messaging

Exchange Online

Admin Center settings, 2627

services, 2526

subscription plans, 26

Microsoft Teams, 2931, 180

MFA (multifactor authentication)

Azure AD (Active Directory) and, 135136

biometric scans, 134

cell phone-based, 134

definition of, 134

overview of, 52

Microsoft 365 Business, 168169, 171173

Microsoft 365 DoD, 174

Microsoft 365 Education, 174177

Microsoft 365 Enterprise, 169173

Microsoft 365 F1, 170173

Microsoft 365 Government, 173174

Microsoft 365 Roadmap, 210211

Microsoft 365 U.S. Government Community (GCC), 174

Microsoft 365 U.S. Government Community (GCC) High, 174

Microsoft 365 Usage Analytics, 9294

Microsoft Application Virtualization (App-V), 24, 64

Microsoft ATA (Advanced Threat Analytics). See ATA (Advanced Threat Analytics)

Microsoft Azure. See Azure

Microsoft CSEO (Core Services and Engineering Operations) group, 103

Microsoft Cybersecurity Reference Architecture, 155

Microsoft Defender Advanced Threat Protection (ATP), 22

Microsoft Desktop Optimization Pack (MDOP), 191

Microsoft FastTrack. See FastTrack program

Microsoft Global Network, 108

Microsoft Graph, 8182

Microsoft Intelligent Security Graph, 155

Microsoft Intune

co-management feature, 148152

device compliance and configuration, 8687

features and capabilities of, 3233, 85, 107, 141142, 182

Intune for Education, 176

service architecture, 119120

Microsoft Office 365. See Office 365 ProPlus

Microsoft Office suite, 3839, 6163

Microsoft Planner, 72, 76, 180

Microsoft Products and Services Agreement (MPSA), 190

Microsoft Professional Support, 204

Microsoft Services Hub, 204205

Microsoft Stream, 75, 180

Microsoft Teams, 2931, 77, 180

Microsoft Threat Protection, 153155

Microsoft Unified Support, 204

Microsoft User Experience Virtualization (UE-V), 24

Microsoft Volume Licensing Service Level Agreement for Microsoft Online Services, 198200

Microsoft Yammer. See Yammer

middleware, 13

Minecraft Education Edition with Code Builder, 175

Mobile Application Management (MAM), 57, 121, 152

mobile apps, 178

Mobile Device Management (MDM), 5658, 121, 140, 152

mobile devices. See device protection

mobility. See EMS (Enterprise Mobility + Security)

Modern Lifecycle Policy, 209

modern management. See also Admin Center

concept of, 4243

configuration, 43

deployment, 43

identity, 43

Microsoft deployment and release model, 4959

deployment strategies, 4950

documentation for, 50

identity, 5153

information protection, 5859

MAM (Mobile Application Management), 57, 121, 152

MDM (Mobile Device Management), 5658, 121, 140, 152

networking, 51

Office 365 ProPlus, 5456

Windows 10 Enterprise, 5354

Office 365 portal, 4749

traditional management compared to, 42

transitioning to, 4344

updates, 43

WaaS (Windows as a Service), 4445

workloads and scenarios, 59

monitoring

client health, 150

service health, 204208

Monthly Channel, 56

Monthly Channel (Targeted), 56

MPSA (Microsoft Products and Services Agreement), 190

multifactor authentication. See MFA (multifactor authentication)

Multiple Activation Keys (MAKs), 66, 178

multiple master replication, 124125

My Library (Service Trust Portal), 157

MyAnalytics, 9496

N

National Institute of Standards and Technology (NIST), 156

Need Help? pane, 201202

Network pane (MyAnalytics), 95

Networking phase (deployment), 51

networks

requirements for, 34

scans of, 112

security model, 118119

VPNs (virtual private networks), authentication over, 115

New Object - User dialog box, 125

New Version Rights, 191

New-ADUser cmdlet, 125

NIST (National Institute of Standards and Technology), 156

Non-critical (Sev C) severity level, 203

notebooks, OneNote, 70, 175

NT LAN Manager (NTLM), 41

O

OAuth (Open Authorization), 41, 127

ODT (Office Deployment Tool), 55, 6365

Office 365 groups, 6973

Office 365 portal, 4749

Office 365 ProPlus

deployment of, 5456, 6366

applications to install, selecting, 6364

Click-to-Run, 6466

customization options, 6465

Office 2016 and 2019 deployments, 66

features of, 5961, 178179

Microsoft Office suite compared to, 3839, 6163

Office activation chart (Usage Analytics), 94

Office Deployment Tool (ODT), 55, 6365

Office Lens, 176

Onboarding phase of onboarding, 163

OneDrive for Business, 62, 75, 180

OneNote notebooks, 70, 175

one-time passwords (OTPs), 135136

Open Authorization (OAuth), 41, 127

Operating System Upgrade Package option, 53

operating systems

defined, 14

support for, 6162

OpEx (operational expenditures), 188190

OTPs (one-time passwords), 135136

Overpass-the-Hash attacks, 88

P

PaaS (Platform as a Service), 1617

PAC (Privileged Attribute Certificate), 88

Pass-the-Hash (PtH) attacks, 88

Pass-the-Ticket (PtT) attacks, 88

pass-through authentication, 130

password authentication

Azure AD (Active Directory), 128

OTPs (one-time passwords), 135136

password changes, 153

password hash synchronization, 129

password policies, 133134

password sharing, 89

SSPR (Self Service Password Reset), 5253, 153

Payment Methods option (Billing menu), 194

PBX (private branch exchange), 30

performance latency, 159

persistence (attacks), 89

Person queries (Workplace Analytics), 98

Personal Information Protection and Electronic Documents Act (PIPEDA), 183

personnel requirements, 4, 163

Person-to-group queries (Workplace Analytics), 98

physical networks, 14

physical security, 108

PIPEDA (Personal Information Protection and Electronic Documents Act), 183

Planner, 72, 76, 180

Planning Services, 190

Platform as a Service (PaaS), 1617

policies

Microsoft 365 security center, 155

password, 133134

threat management, 59

Post-Incident Report Published indicator (Service Health), 206

Power BI. See Usage Analytics

PowerShell cmdlets. See cmdlets

pricing and support. See also subscriptions

basic components, 167168

billing and bill management, 194196

key selling points, 177178

collaboration, 179181

compliance, 182184

productivity, 178179

security, 181182

Office 365 ProPlus, 62

service health, monitoring, 204208

service lifecycle policies, 208211

SLAs (service level agreements), 195200

limitations of, 197

Microsoft Volume Licensing Service Level Agreement for Microsoft Online Services, 198200

negotiating, 195196

support requests, creating, 200205

administrator and support team responsibilities, 200201

alternative support methods, 203205

Contact Support pane, 202

Need Help? pane, 201202

support severity levels, 203

support tickets, viewing, 203

supported issues, 202203

USL (user subscription license), 185186

volume licensing

CSP (Cloud Solution Provider) program, 191193

licensing agreement types, 190

Software Assurance, 190191

support, 203

private branch exchange (PBX), 30

private cloud, 1112

Private preview, 209

Privileged Attribute Certificate (PAC), 88

Product usage chart (Usage Analytics), 94

productivity services, 178179

Products & Services option (Billing menu), 194

Protect phase (compliance), 184

PSTN (Public Switched Telephone Network), 30

PtH (Pass-the-Hash) attacks, 88

PtT (Pass-the-Ticket) attacks, 88

public cloud, 911

public folders, 68

Public preview, 209

Public Switched Telephone Network (PSTN), 30

Purchase Services option (Billing menu), 194

Purchase Services page, 185186

Q-R

quarterly uptime percentages, 199200

Quick Analysis button (Microsoft Graph), 82

reconnaissance, 89

reduced functionality mode (Office 365 ProPlus), 62

redundancy, 4

regions, Microsoft Azure, 162

release cycles, 209211

reliability of cloud-based services, 56

remote actions, 149

remote execution, 89

reports

audit, 156

Microsoft 365 security center, 155

Reports menu (Admin Center), 47

Resources

Admin Center, 47

Service Trust Portal, 157

Respond phase (compliance), 184

Restoring Service indicator (Service Health), 206

retention labels, 58

Rights Management (RMS), 33

risk management

anticipation of threats, 111

asset inventory, 104106

definition of, 103

hardware inventory, 106108

identity protection risk levels, 136139

ongoing nature of, 112

overview of, 103

user classification, 109111

vulnerability assessments, 112

RMS (Rights Management), 33

Roadmap, 210211

Rolling Out release status, 210

runtime, 13

S

SaaS (Software as a Service), 18

SAML (Security Assertion Markup Language), 41

scalability of cloud-based services, 5

scans

application, 112

biometric, 134

database, 112

host, 112

network, 112

SCCM (System Center Configuration Manager)

co-management feature, 148152

features and capabilities of, 23, 140, 142

features of, 148149

in-place upgrade to Windows 10 Enterprise, 5354

Office 365 ProPlus deployment, 63

Office 365 ProPlus installation, 54

SDS (School Data Sync), 175

seamless single sign-on, 129

secure score, 155

security, 22. See also identity protection

ATA (Advanced Threat Analytics), 3334, 85, 8891, 143

ATP (Advanced Threat Protection), 22, 35, 143, 182

attack types, 8889

challenges of, 101103

Compliance Manager, 157158

device protection, 178

BYOD (Bring Your Own Device), 57, 102, 120, 141

with Cloud App Security, 121122

with MAM (Mobile Application Management), 121

with MDM (Mobile Device Management), 121

with Microsoft Intune, 119120

overview of, 118122

security usage scenarios, 152153

document protection

ACEs (access control entries), 116117

ACLs (access control lists), 116117

AIP (Azure Information Protection), 33, 105106, 117118, 139140, 143

DLP (Data Loss Prevention), 117118, 139140

overview of, 116118

Microsoft 365 Business, 168169

network security model, 118119

overview of, 7, 38

physical, 108

risk management

anticipation of threats, 111

asset inventory, 104106

definition of, 103

hardware inventory, 106108

ongoing nature of, 112

overview of, 103

user classification, 109111

vulnerability assessments, 112

SCCM (System Center Configuration Manager), 140, 142, 148152

security center, 154155

security principals, 113

security services, 181182

STP (Service Trust Portal), 156157

UEM (unified endpoint management), 140143

usage scenarios, 152153

Security Assertion Markup Language (SAML), 41

Self Service Password Reset (SSPR), 5253, 153

self-deployment, 50

Semi-annual Channel

Office 365 ProPlus, 56

Windows 10, 44

Semi-annual Channel (Targeted), 56

Send button (Microsoft Graph), 81

sensitivity labels, 5859

Server Disaster Recovery Rights, 191

serverless computing, 17

service credits, 199

Service Degradation indicator (Service Health), 206

Service Health page, 204208

Service Interruption indicator (Service Health), 206

service level agreements. See SLAs (service level agreements)

service lifecycle policies, 208211

service models (cloud services)

FaaS (Function as a Service), 17

IaaS (Infrastructure as a Service), 1416

infrastructure layers, 1314

PaaS (Platform as a Service), 1617

SaaS (Software as a Service), 18

Service Organization Controls (SOC), 156

service providers

robustness of, 160

selection of, 159160

vendor lock-in, 160

Service Restored indicator (Service Health), 206

Service Trust Portal (STP), 156157

Set Up School PCs app, 175

Set-MsolPasswordPolicy cmdlet, 133

Set-MsolUser cmdlet, 133

Settings menu (Admin Center), 47

Setup menu (Admin Center), 47

severity levels support, 203

Shadow IT, 34

shared mailboxes, 6869

shared public cloud, 9

SharePoint Online

Admin Center, 72

features and capabilities of, 2729, 7374, 180

SharePoint Server compared to, 40

sign-in risk, 137

single master replication, 126127

single sign-on (SSO), 129

six nines contract, 4

Sizing Tool (ATA), 90

Skype for Business Online, 31, 77

SLAs (service level agreements), 159, 195200

limitations of, 197

Microsoft Volume Licensing Service Level Agreement for Microsoft Online Services, 198200

negotiating, 195196

SOC (Service Organization Controls), 156

Software as a Service (SaaS), 18

Software Assurance, 190191

software licenses, 3

spread payments, 191

SSPR (Self Service Password Reset), 5253, 153

Status indicators (Service Health), 206

Step-up USL (user subscription license), 186

storage, 14, 178

Storage use chart (Usage Analytics), 94

STP (Service Trust Portal), 156157

Stream, 75, 180

subscriptions, 168

Azure AD (Active Directory), 145

best practices for, 187

CBA (cost-benefit analysis) of, 188190, 212213

subscriptions, continued

Exchange Online, 26

feature comparison, 171173

Microsoft 365 Business, 168169, 171173

Microsoft 365 Education, 174177

Microsoft 365 Enterprise, 169173

Microsoft 365 F1, 170173

Microsoft 365 Government, 173174

volume licensing

CSP (Cloud Solution Provider) program, 191193

licensing agreement types, 190

Software Assurance, 190191

support, 203

support. See pricing and support

Support menu (Admin Center), 47, 200205

synchronization

Azure AD (Active Directory), 128129

device data, 153

System Center Configuration Manager. See SCCM (System Center Configuration Manager)

Systems Management Server, 148

T

Take a Test app, 175

TAMs (technical account managers), 204

TCO (total cost of ownership)

calculating, 188190

cost models, comparison of, 160161

sample software licensing scenario, 212213

Teams (Microsoft), 2931, 77, 180

Teams collaboration metrics (Workplace Analytics), 97

technical account managers (TAMs), 204

threats. See security

three nines contract, 4

tiered cloud service model, 1617

total cost of ownership. See TCO (total cost of ownership)

training vouchers, 191

transitioning to cloud, 163

Trust Center (Service Trust Portal), 157

Try The New Admin Center option, 209

two nines contract, 4

U

UEM (unified endpoint management), 140143

UE-V (Microsoft User Experience Virtualization), 24

UM (Unified Messaging), 25

Unified Messaging (UM), 25

Update Management (Azure), 16

updates/upgrades, 3, 2224, 35, 43, 178

Upgrade Readiness (Desktop Analytics), 23

U.S. Government regions, 162

Usage Analytics, 9294

usage scenarios, security, 152153

user classification, 109111

user risk, 137

user subscription license (USL), 185186

Users menu (Admin Center), 46

USL (user subscription license), 185186

V

VDA (Windows Virtual Desktop Access Rights), 191

vendors

robustness of, 160

selection of, 159160

vendor lock-in, 160

vertical scaling, 5

View Service Requests option (Support menu), 203

VMs (virtual machines), 45

VoIP (Voice over IP), 30

volume licensing

CSP (Cloud Solution Provider) program, 191193

licensing agreement types, 190

Software Assurance, 190191

support, 203

VPNs (virtual private networks), authentication over, 115

vulnerability assessments, 112

W-X-Y-Z

WaaS (Windows as a Service), 4445

WDAC (Windows Defender Application Control), 22

Week in the life metrics (Workplace Analytics), 96

Wellbeing pane (MyAnalytics), 95

Windows 10 Business, 25

Windows 10 Enterprise

deployment of, 5354

features and capabilities of, 22

management, 24

security, 22

updates, 2224

Windows as a Service (WaaS), 4445

Windows Autopilot, 24, 150, 168

Windows Defender

Application Guard, 22

ATP (Advanced Threat Protection), 22

WDAC (Windows Defender Application Control), 22

Windows Hello for Business, 116, 134

Windows Information Protection (WIP), 59

Windows Insider Channel, 44

Windows Server Update Service (WSUS), 23

Windows Thin PC, 191

Windows to Go Use Rights, 191

Windows Update for Business, 23

Windows Virtual Desktop Access Rights (VDA), 191

WIP (Windows Information Protection), 59

wireless network scans, 112

wizards, Co-management Configuration, 150151

Workplace Analytics, 9699

WSUS (Windows Server Update Service), 23

Yammer, 72, 7475, 175, 180

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset