MS-100 Overview & My Tips
MS-100 or Microsoft 365 Identity and Services is one of two exams that make up the Microsoft 365 Certified Enterprise Administrator Expert certification. The certification also requires you to pass & hold a valid Microsoft 365 Associate level certification in addition to passing the MS-100 and MS-101.
The Microsoft 365 Certified: Enterprise Administrator Expert is the only Expert level certification for Microsoft 365. Whilst the Associate certification in Microsoft 365 require Administrator level knowledge and skills, this is the next step up. You could consider this the consultant level skillset. You need an in-depth understanding of all features, the configuration options, pros/cons of the options PLUS hands on administration skills across the full set of Microsoft 365 workloads. Tradition system administrator skills are also helpful as you should also understand DNS, Active Directory (on-prem), networking and on-prem server admin. The on-prem skills and knowledge is needed to design and configure Microsoft 365 in Hybrid to work in harmony with existing environments as well as to understand requirements of organisations moving to the cloud.
That said, regular visitors to my blog will know that I consider myself a ‘born in the cloud’ admin and as such the traditional system administrator skills are my personal weak area. Please don’t let that put you off going for this certification, if that also describes you. You can use your Microsoft 365 knowledge to answer migration and hybrid questions and remember you don’t have to get all 1000 availalbe points to pass.
This exam focuses on identity & access (Azure AD) plus workload security & configuration whilst the MS-101 focuses on device management plus the security & compliance tools.
Disclaimer: All these links were correct at the time of posting. But the Cloud changes regularly, so the referenced articles my change/be removed. Please do post a comment if you spot a broken link or have suggestions to add so others can benefit too.
General References
- MS-100 Exam page https://docs.microsoft.com/en-us/learn/certifications/exams/ms-100
- MeasureUp Official Practice Test https://www.measureup.com/catalogsearch/result/?cat=&q=MS-100
- Microsoft Learn. Provides searchable learning paths and modules for a variety of roles and levels. https://docs.microsoft.com/en-us/learn/
- Learn TV. Digital content so you can always keep updated on the latest announcements, features, and products from Microsoft. https://docs.microsoft.com/en-us/learn/tv/
- Microsoft 365 Blog https://techcommunity.microsoft.com/t5/microsoft-365-blog/bg-p/microsoft_365blog
- Channel 9. Informational videos, shows, and events on variety of technical topics. https://channel9.msdn.com/
- Microsoft Learning Community Blog. Get the latest information about the certification tests and exam study groups. https://www.microsoft.com/en-us/learning/community-blog.aspx
- Microsoft 365 Documentation https://docs.microsoft.com/en-us/microsoft-365
- Portals for Administrators https://msportals.xyz/
Taking a Microsoft Professional Exam
There are a number of blogs about taking MCP exams. My personal favourites are:
- Certification process overview | Microsoft Docs
- Microsoft Certification Routes https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RWtQJJ?keywords=Microsoft%20365%20Certified%20Teamwork%20Administrator%20Associate
- Microsoft Certifications – Microsoft Exam duration and question types – tiagocosta.com
- An MCT’s perspective on taking a Microsoft Fundamentals Exam (FAQ’s) – @Microsoft365Pro
- How to take a Microsoft Certification Exam Online – Thomas Maurer
Pre-study References
Before attending an MS-100 course you should have day-to-day admin experience managing multiple workloads in Microsoft 365 and have a good understanding of the availalbe tools and services in Microsoft 365 PLUS licencing of Microsoft 365.
- Complete an Associate Level Course & Exam – I recommend MS-203: Microsoft 365 Messaging or MS-700: Managing Microsoft Teams if you have no preference
- Microsoft 365 licensing guidance for security & compliance https://docs.microsoft.com/en-us/office365/servicedescriptions/microsoft-365-service-descriptions/microsoft-365-tenantlevel-services-licensing-guidance/microsoft-365-security-compliance-licensing-guidance#information-barriers
- License Comparisons https://github.com/AaronDinnage/Licensing
- Service Trust Portal https://servicetrust.microsoft.com/
- Compare Azure AD licenses https://azure.microsoft.com/en-gb/pricing/details/active-directory/
Microsoft Learn Learning Paths (MS-100)
- As a single collection: MS-100
- Protect identity & access with Azure AD https://docs.microsoft.com/en-us/learn/paths/m365-identity/
- Manage identity & access in Azure AD https://docs.microsoft.com/en-us/learn/paths/manage-identity-and-access/
- Microsoft 365 – Modernize your enterprise deployment with Windows 10 and Microsoft 365 Apps https://docs.microsoft.com/en-us/learn/paths/m365-getmodern/
- Stay current with Windows 10 & Microsoft 365 Apps https://docs.microsoft.com/en-us/learn/paths/m365-stay-current/
- Manage your enterprise deployment with Microsoft 365 https://docs.microsoft.com/en-us/learn/paths/manage-enterprise-deployment-m365/
References by Exam Objectives
Update to exam Objectives from August 3rd 2022. Please scroll down for May 2022 version.
The profile of the Microsoft 365 expert administrator has been updated with this revision, along with the objectives, to recognize that many organizations have completed their migration to Microsoft 365 and the Expert administrator now fulfills a overarching coordination role advising architects and workload administrators. As such this exam is more aligned to a senior administrator rather than a consultant position.
By objective references coming soon
Based on the objectives as at 3rd May 2022
It is recommended that you explore each concept in depth and DO NOT consider this list exhaustive. Please follow links on from these pages to dig deeper into each topic. This is the EXPERT level exam, after all! You may also find it helpful to review the exam objectives for the workload admin certifications:
Messaging: Microsoft 365 Certified: Messaging Administrator Associate – Learn | Microsoft Docs
Desktop: Microsoft 365 Certified: Modern Desktop Administrator Associate – Learn | Microsoft Docs
Teams: Microsoft 365 Certified: Teams Administrator Associate – Learn | Microsoft Docs
Security:Microsoft 365 Certified: Security Administrator Associate – Learn | Microsoft Docs
Design and Implement Microsoft 365 Services (25-30%)
See also Adoption guidance: https://adoption.microsoft.com/
Plan architecture
- plan integration of Microsoft 365 and on-premises environments
- Microsoft 365 integration with on-premises environments – Microsoft 365 Enterprise | Microsoft Docs
- https://docs.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-overview?view=o365-worldwide#transition-your-entire-organization
- https://docs.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-overview?view=o365-worldwide#plan-for-and-deploy
- Microsoft 365 deployment, migration and adoption tool | Microsoft 365
- plan an identity and authentication solution
- plan enterprise application modernization
Deploy a Microsoft 365 tenant
- manage domains
- configure organizational settings
- complete the organizational profile
- add a Microsoft partner or work with Microsoft FastTrack
- complete the subscription setup wizard
- plan and create a tenant
- edit an organizational profile
- plan and create subscription(s)
- configure tenant-wide workload settings
Manage Microsoft 365 subscription and tenant health
- manage service health alerts
- create and manage service requests
- create internal service health response plan
- This is not a technical topic, rather M365 Experts are expected to implement processes within their organizations to monitor & respond to service health issues, including reporting to Microsoft and responding to reports
- monitor service health
- As well as How to check Microsoft 365 service health – Microsoft 365 Enterprise | Microsoft Docs, you should also implement a strategy to ensure notifications are seen, such as email alerts using the Preferences within the Service Health page
- monitor license allocations
- configure and review reports, including Power BI, Azure Monitor logs, Log Analytics workspaces, and Microsoft 365 reporting
- Microsoft 365 usage analytics – Microsoft 365 admin | Microsoft Docs
- https://docs.microsoft.com/en-us/microsoft-365/admin/activity-reports/activity-reports?view=o365-worldwide
- https://docs.microsoft.com/en-us/microsoft-365/admin/productivity/productivity-score?view=o365-worldwide
- Azure Monitor Logs – Microsoft Docs
- Log Analytics Workspaces – Microsoft Docs
- schedule and review security and compliance reports
- schedule and review usage metrics
Plan migration of users and data
- identify data to be migrated and migration methods
- identify users and mailboxes to be migrated and migration methods
- plan migration of on-premises users and groups
- import PST files
Manage User Identity and Roles (25-30%)
Design identity strategy
- evaluate requirements and solutions for synchronization
- evaluate requirements and solutions for identity management
- This topic requires you to align organisations requirements to the Azure AD features. However this article listing 12 questions to ask is helpful – can you answer then for Azure AD? 12 Questions to Ask When Evaluating Identity & Access Management Solutions (mobliciti.com)
- evaluate requirements and solutions for authentication
Plan identity synchronization
- design directory synchronization
- implement directory synchronization with directory services, federation services, and Azure endpoints by using Azure AD Connect
- plan for directory synchronization using Azure AD cloud sync
Manage identity synchronization with Azure Active Directory (Azure AD)
- configure and manage directory synchronization by using Azure AD cloud sync
- configure and manage directory synchronization by using Azure AD Connect
- monitor Azure AD Connect Health
- https://docs.microsoft.com/en-gb/azure/active-directory/hybrid/whatis-azure-ad-connect#what-is-azure-ad-connect-health – including Next Steps linked articles
- manage Azure AD Connect synchronization
- configure object filters
- configure password synchronization
- implement multi-forest AD Connect scenarios
Manage Azure AD identities
- plan Azure AD identities
- implement and manage self-service password reset (SSPR)
- manage access reviews
- manage groups
- manage passwords
- manage product licenses
- manage users
- perform bulk user management
Manage roles
- plan user roles
- manage admin roles
- allocate roles for workloads
- This objective requires to you to know which role relates to which workload in Microsoft 365 and assign them using the concept of least privilege
- manage role allocations by using Azure AD
Manage Access and Authentication (15-20%)
Manage authentication
This section is covered by Azure Active Directory Authentication documentation | Microsoft Docs
- design an authentication method
- configure authentication
- implement an authentication method
- manage authentication
- monitor authentication
- Authentication Methods Activity – Azure Active Directory | Microsoft Docs
- Self-service password reset reports – Azure Active Directory | Microsoft Docs
- Sign-in event details for Azure AD Multi-Factor Authentication – Azure Active Directory | Microsoft Docs
- Azure AD MFA user data collection – Azure Active Directory | Microsoft Docs
Plan and implement secure access
- design a conditional access solution
- implement entitlement packages
- implement Azure AD Identity Protection
- manage identity protection
- implement conditional access
- manage conditional access
- implement and secure access for guest and external users
Configure application access
- configure application registration in Azure AD
- configure Azure AD Application Proxy
- publish enterprise apps in Azure AD
Plan Office 365 Workloads and Applications (25-30%)
This section information mainly links from Microsoft 365 for enterprise documentation and resources | Microsoft Docs and the following documents are also helpful to summarise features and deployment of Microsoft 365 Microsoft 365 productivity illustrations | Microsoft Docs
Adoption planning is also important and you should review the materials available at Microsoft 365 – Microsoft Adoption to support this.
Plan for Microsoft 365 Apps deployment
- plan for Microsoft connectivity
- manage Microsoft 365 Apps
- plan for Office online
- The main requirements for Office Online are the endpoints which your network needs to permit access to https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide#microsoft-365-common-and-office-online
- assess readiness using Microsoft analytics
- plan Microsoft 365 App compatibility
- manage Microsoft 365 apps deployment and software downloads
- plan for Microsoft apps updates
- plan Microsoft telemetry and reporting
- plan for and manage policy settings using the Office cloud policy service
Plan for messaging deployments
- plan migration strategy
- plan messaging deployment
- identify hybrid requirements
- plan for connectivity
- plan for mail routing
- plan email domains
Plan for Microsoft SharePoint Online and OneDrive for Business
- plan migration strategy
- plan external share settings
- identify hybrid requirements
- manage access configurations
- manage Microsoft groups
- manage SharePoint tenant and site settings
Plan for Microsoft Teams infrastructure
Start from Microsoft Teams deployment overview – Microsoft Teams | Microsoft Docs and also Microsoft Teams – Microsoft Adoption
- plan for communication and call quality and capacity
- plan for Phone System
- plan Microsoft Teams deployment
- plan Microsoft Teams organizational settings
- plan for guest and external access
- plan for Microsoft Teams hybrid connectivity and co-existence
- With the retirement of Skype for Business Online at the end of July 2021, the only real Hybrid expereince with Teams is with Exchange Hybrid. Configure an Exchange hybrid organization – Microsoft Teams | Microsoft Docs
Plan Microsoft Power Platform integration
- implement Microsoft Power Platform Center of Excellence (CoE) starter kit
- plan for Power Platform workload deployments
- plan resource deployment
- plan for connectivity (and data flow)
- manage environments
- manage resources
