
In August a major update for MS-100 was released, with changes in objective domain section naming and quite a few of the tested items. Let’s start off with a quick summary of what has been added and what has been removed from the exam, and then discuss some these changes.
What’s new?
- Privileged Identity Management
- Administrative Units
- Azure AD Password Protection
- IdFix
- AAD Connect multitenant, server requirements, troubleshooting
- OAuth apps and Microsoft Defender for Cloud Apps
The top takeaway here is that the exam has expanded the Azure AD Premium features from P1 and P2 plans, where previously only Conditional Access, Identity Protection and Access Reviews were included. I view this as the exam catching up with AAD functionality.
What’s been removed?
- Teams planning for communication, call quality and capacity
- Plan for Microsoft Teams hybrid connectivity and co-existence
- Exchange Migration
- Partner and FastTrack
- Office Online
- Federation services
- Security and compliance reports
- Power Platform section
The removal of more advanced Teams migration and voice topics makes a great deal of sense. Team’s voice capabilities aren’t necessarily features that Microsoft 365 admins might be exposed to (yet!), and the integration/migration from Skype for Business is something that I view as a more dated conversation due to the rapid adoption of Teams in many organizations. Federation removal makes sense, as this is something that has generally been deemphasized in favor of other Azure AD Connect authentication options. Security and compliance reports are better suited to other exams like MS-101 and MS-500. Power Platform’s inclusion was always an inclusion that I wasn’t fond of, and never really understood why it made an appearance in this exam. This exam is broad enough without bringing Power Platform capabilities in.
Deploy and manage a Microsoft 365 tenant (15—20%)
Plan and implement a Microsoft 365 tenant
- plan a tenant
- create a tenant
- implement and manage domains
- configure organizational settings, including security, privacy, and profile
Monitor Microsoft 365 tenant health
- create and manage service requests
- create an incident response plan
- monitor service health
- monitor application access
- configure and review reports, including Azure Monitor logs and Log Analytics workspaces
- schedule and review usage metrics, including Workplace Analytics and productivity score
Plan and manage user identity and roles (30—35%)
Plan identity synchronization
- design synchronization solutions for multitenant and multiforest scenarios
- evaluate whether objects should be synchronized, not synchronized, or created as cloud only
- identify which Azure Active Directory (AD) Connect features to enable, such as writeback and device synchronization
- identify synchronization pre-requisites, including connectivity method, permissions, and server requirements
- choose between Azure AD Connect and Azure AD Connect cloud sync
- plan user sign-in for Azure AD hybrid identities, including pass-through authentication, seamless, and SSO
Implement and manage identity synchronization with Azure AD
- prepare for identity synchronization by using IdFix
- configure and manage directory synchronization by using Azure AD Connect cloud sync
- configure and manage directory synchronization by using Azure AD Connect
- configure Azure AD Connect object filters
- monitor synchronization by using Azure AD Connect Health
- troubleshoot Azure AD Connect synchronization
Plan and manage Azure AD identities
- plan Azure AD identities
- create and manage users
- create and manage guest users
- create and manage groups, including Microsoft 365 groups
- manage and monitor Microsoft 365 license allocations
- perform bulk user management, including PowerShell
Plan and manage roles in Microsoft 365
- plan for role assignments
- manage roles in Microsoft 365 admin center
- manage administrative units
- plan and implement privileged identity management for Azure AD roles
Manage access and authentication (20—25%)
Plan and implement authentication
- choose an authentication method, including Windows Hello for Business, passwordless, and tokens
- implement and manage authentication methods
- implement and manage self-service password reset (SSPR)
- implement and manage Azure AD password protection
- configure and manage multi-factor authentication (MFA)
- investigate and resolve authentication issues
Plan and implement secure access
- plan and implement access reviews in Azure AD identity governance
- plan and implement entitlement packages in Azure AD identity governance
- plan for identity protection
- implement and manage Azure AD Identity Protection
- plan conditional access policies
- implement and manage conditional access policies
Plan and implement application access
- plan access and authentication to application registrations and Azure AD enterprise applications
- configure application registration in Azure AD
- manage user permissions for application registrations
- manage OAuth application requests in Azure AD, Microsoft Defender for Cloud Apps, and Microsoft 365 Defender
- configure Azure AD Application Proxy
- publish enterprise applications in Azure AD
Plan Microsoft 365 workloads and applications (20—25%)
Plan and implement Microsoft 365 Apps deployment
- plan for client connectivity to Microsoft 365 workloads
- plan Microsoft 365 App compatibility by using the Readiness Toolkit
- plan for Microsoft 365 Apps updates
- specify initial configuration for Microsoft 365 Apps by using the Microsoft 365 Apps admin center
- implement Microsoft 365 Apps deployment and software downloads
Plan and implement Exchange Online deployments
- plan for DNS records required by Exchange Online
- plan and implement an Exchange hybrid organization
- plan and implement mail routing, including connectors, mail flow rules, and remote domains
- plan and implement organizational settings
Plan and implement Microsoft SharePoint Online, OneDrive, and Microsoft Teams
- specify SharePoint site types, site collections, and lists
- plan a migration strategy for SharePoint Online and OneDrive
- identify hybrid requirements for SharePoint Online
- manage access configurations for SharePoint Online and Microsoft Teams
- manage SharePoint Online tenant and site settings
- map Phone System features to requirements
- plan and implement organizational settings
- plan, implement, and manage guest and external access