
Meet a Microsoft 365 administrator expert who shares Azure, cybersecurity, and cloud insights through real-world, hands-on experience in designing and implementing cloud and AI architectures.
Examine the three-tier SoC model: automation and tier one handle commodity malware, tier two covers advanced threats, and tier three performs proactive threat hunting and forensics, guiding escalation.
Implement the NIST-based incident response process, from preparation and stakeholder alignment through detection, analysis, containment, eradication, recovery, and post-incident lessons learned.
Demystify EDR, XDR, SIEM, and SOAR by illustrating how Defender for Endpoint and Defender for Cloud enable behavior monitoring, log correlation in Sentinel, and automated incident response with Logic Apps.
Combine blue and red teams to form purple teaming and boost security monitoring and posture. Collaborate on simulating adversary TTPs and defending against threats to upskill the team.
Define cyber threat intelligence as knowledge about adversaries' motivations, intentions, and methods gathered to protect enterprise assets by focusing on their tactics, techniques, and procedures for threat-informed defense.
Clarify how threat actors initiate threats by exploiting vulnerabilities, causing downtime, confidentiality breaches, or integrity violations, and define risk as the combined impact and likelihood of occurrence.
Explore threat informed defense by aligning your mission with threat actor motivations, their ttps, and how to detect and protect against them using focused cyber threat intelligence.
Understand tactics, techniques and procedures as a hierarchy from high-level threat actor objectives to detailed procedural steps, with reconnaissance, scanning, and vulnerability scanning illustrating the progression.
Differentiate iocs from ioas: iocs are breach evidence like file hashes and domains, while ioas focus on attacker intent and behavior for threat-informed defense in siem, edr, and xdr.
Explore the pyramid of pain, ranking attacker change difficulty from hashes and IPs to domains, tools, and TPS, and emphasize detecting tactics, techniques, and procedures to thwart compromise.
Explore CTI sources across enterprise tools, osint, and social media, with examples like Microsoft Defender Threat Intelligence, VirusTotal, Shodan, the attack framework, and insights from Twitter/X, LinkedIn, and Medium.
Zero trust is a security strategy and mindset, not a product; it emphasizes verify explicitly, least privilege access, and assume breach to minimize blast radius.
Discover the Microsoft security cosmos for cloud security and cyber threat intelligence, with defender xdr and defender for identity, defender for endpoint, defender for cloud apps, defender for all 365.
Explore cyber kill chain from phishing to data exfiltration. Learn to use Defender for Office, Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps to mitigate each stage.
Cloud computing enables on demand self service, broad network access, resource pooling, rapid elasticity, and measured service to deliver scalable resources.
Define public, private, hybrid, and multi-cloud models with Azure, AWS, and GCP, and explore Azure Stack, AWS Outposts, and Google Anthos for private cloud and enterprise workloads.
Explore how the Azure global backbone links data centers and continents through fiber, subsea cables, edge sites, and peering connections to deliver high performance, fault tolerance, and disaster recovery.
Explore the shared responsibility model across on-premises and cloud service models (IaaS, PaaS, SaaS) in Azure, AWS, and GCP. Understand which party handles security and operations at each layer.
Explore Azure's resource hierarchy from management groups to subscriptions and resource groups. Group resources that share the same lifecycle to optimize governance and cost tracking.
Learn Azure subscription types, including free (30 days credits and some services free 12 months), student (12 months free credits, no card needed), pay-as-you-go, and enterprise agreement.
Clarify the relationship between an identity provider tenant and Azure subscriptions. Debunk the misconception that subscriptions are tenants, and explain how identities access resources in subscriptions and resource groups.
learn how to create a free Azure subscription, compare it with pay-as-you-go, provide personal details, and access portal.azure.com to start building in Azure.
Learn how to obtain an E5 trial license, assign it to a user in the portal, and enable Defender XDR features built on Microsoft 365 E5.
Learn to manage and create entra ID tenants for your organization, including setting the initial domain and location, creating additional tenants, and switching between them.
Explore central tenant settings in the admin center to configure services, security and privacy, and organizational profile, including themes, logos, and colors.
Navigate the M365 admin center to view health overview, history, and issues. Report issues to Microsoft by selecting Exchange Online and mail or calendar problems.
Configure service health notifications in the Microsoft 365 admin center to receive email alerts for incidents, advisories, or issues by selecting visible services and setting your primary email.
Monitor adoption and usage of M365 services in the admin center using adoption score, the usage blade, and actions to boost adoption; track licenses, readiness, and active agents per service.
Learn Microsoft Entra, a four-pillar identity and access platform, including Entra ID (formerly Azure AD), governance, verified ID, external and workload identities, and cloud-wide permissions management.
Discover Microsoft Entra ID, the cloud-based identity and access management service formerly known as Azure Active Directory, with features like conditional access, B2B/B2C, and hybrid identity, plus licensing options.
Explore creating and managing Microsoft Entra ID user identities, including synchronized, cloud, and guest identities, with options for username/password, MFA, and passwordless authentication.
Learn how to create and manage users in Microsoft Entra ID, assign roles, add to groups, and review user properties including user principal name and display name.
Learn to create and manage groups in Entra ID to centralize access and governance. Explore security and M365 groups, and assigned, dynamic, and dynamic device memberships for automated, self-service access.
Create a security group in entra ID, name and describe it, and set membership and role options. Then assign Azure roles or administrative units and finalize the group.
Explore Entra ID roles and how they grant permissions across the Microsoft ecosystem, such as teams administrator and security administrator. Understand how these roles enable policy configuration, monitoring, and audits.
Explore built-in roles in Microsoft Entra ID and assign the security administrator role, reviewing its permissions to manage security services and create conditional access policies.
Create a custom role in Microsoft Entra ID, select permissions, and assign it to a user or group as active or eligible. Refresh to confirm the role is active.
Restrict permissions with administrative units to regional segments of the tenant, delegate help desk roles to regional specialists, and cluster users, devices, and security groups by geography.
Create administrative units in intra ID to cluster users, groups, devices, and roles, then add members and groups to a unit like Europe for streamlined management.
Explore how to manage privileged access in Entra ID with PIM, configuring eligible and active roles, time-bound activations, approvals, MFA, and conditional access for least-privilege workflows.
Provision a hybrid identity lab in Azure by creating a resource group and virtual network, then deploy two virtual machines for a domain controller and interconnect.
learn to purchase and set up a custom domain for Azure Active Directory, using App Service domains or external registrars, and verify ownership with a txt record.
Install Active Directory on an Azure domain controller by using Server Manager, add roles and features, promote the server to a new forest, and verify Active Directory Domain Services.
Align on-premises Active Directory with Microsoft Entra ID using Entra Connect, enabling password hash synchronization and pass-through authentication, with cloud sync as the modern alternative.
Install intra connect on an Azure virtual machine, configure private IP and DNS to reach the domain controller, then join the domain to enable password hash synchronization and single sign-on.
Explore intra domain services in the cloud to run legacy applications with domain join, LDAP, Kerberos, and NTLM without deploying domain controllers, while leveraging Entra ID integration with Azure.
Explore hybrid authentication in a Microsoft 365 environment, selecting the best method—password hash sync or pass-through authentication—based on on-premises and cloud requirements.
This course contains the use of artificial intelligence.
This MS-102 course by Christopher Nett is a meticulously organized Udemy course designed for IT professionals aiming to pass the MS-102: Microsoft 365 Administrator Expert exam. This course systematically guides you from the basis to advanced concepts of M365 administration.
By mastering Azure Security, you're developing expertise in essential topics in today's cloud administration landscape.
The course is always aligned with Microsoft's latest study guide and exam objectives:
Skills at a glance
Deploy and manage a Microsoft 365 tenant (15–20%)
Implement and manage Microsoft Entra identity and access (25–30%)
Manage security and threats by using Microsoft Defender XDR (35–40%)
Manage compliance by using Microsoft Purview (15–20%)
Deploy and manage a Microsoft 365 tenant (15–20%)
Implement and manage a Microsoft 365 tenant
Create a tenant
Implement and manage domains
Configure org settings, including Security & privacy and Organizational profile
Identify and respond to service health issues
Configure notifications in service health
Configure and review Network connectivity insights
Monitor adoption and usage
Manage users and groups
Create and manage users in Microsoft Entra, including external users and guests
Create and manage contacts in the Microsoft 365 admin center
Create and manage groups, including Microsoft 365 groups and shared mailboxes
Manage and monitor Microsoft 365 licenses, including group-based licensing
Perform bulk user management, including PowerShell
Manage roles and role groups
Implement and manage built-in roles in Microsoft 365 and Microsoft Entra
Implement and manage custom roles in Microsoft Entra admin center
Manage role groups in Microsoft Defender XDR, Microsoft Purview, and Microsoft 365 workloads
Manage delegation by using administrative units
Manage roles in Microsoft Entra privileged identity management
Implement and manage Microsoft Entra identity and access (25–30%)
Implement and manage identity synchronization with Microsoft Entra tenant
Prepare for identity synchronization by using IdFix
Implement and manage directory synchronization by using Microsoft Entra Connect cloud sync
Implement and manage directory synchronization by using Microsoft Entra Connect
Monitor synchronization by using Microsoft Entra Connect Health
Troubleshoot synchronization, including Microsoft Entra Connect and Microsoft Entra Connect cloud sync
Implement and manage authentication
Implement and manage authentication methods
Implement and manage self-service password reset (SSPR)
Implement and manage Microsoft Entra Password Protection
Investigate and resolve authentication issues
Implement and manage secure access
Plan for identity protection
Implement and manage Microsoft Entra ID Protection
Plan Conditional Access policies
Implement and manage Conditional Access policies
Implement and manage multi-factor authentication (MFA) by using conditional access policies
Manage security and threats by using Microsoft Defender XDR (35–40%)
Review and respond to security reports and alerts generated by Microsoft Defender XDR
Review and take actions to improve the Microsoft Secure Score
Review and respond to security incidents and alerts
Review and respond to issues identified in security and compliance reports
Review and respond to threats identified in threat analytics
Implement and manage email and collaboration protection by using Microsoft Defender for Office 365
Implement policies and rules in Defender for Office 365
Review and respond to threats identified in Defender for Office 365, including threats and investigations
Create and run campaigns, such as attack simulation
Unblock users
Implement and manage endpoint protection by using Microsoft Defender for Endpoint
Onboard devices to Defender for Endpoint
Configure endpoint settings
Review and respond to endpoint vulnerabilities
Review and respond to risks identified in the Microsoft Defender Vulnerability Management dashboard
Implement, and manage Microsoft Defender for Cloud Apps
Configure the app connector for Microsoft 365
Configure Microsoft Defender for Cloud Apps policies
Review and respond to Microsoft Defender for Cloud Apps alerts
Interpret activity log
Configure Cloud App Discovery
Review and respond to issues identified in Cloud App Discovery
Manage compliance by using Microsoft Purview (15–20%)
Implement Microsoft Purview information protection and data lifecycle management
Implement and manage sensitive information types by using keywords, keyword lists, or regular expressions
Implement retention labels, retention label policies, and retention policies
Implement sensitivity labels and sensitivity label policies
Monitor label usage by using Content explorer, Activity explorer, and label reports
Implement Microsoft Purview data loss prevention (DLP)
Configure DLP policies for Exchange, SharePoint, OneDrive, and Teams
Configure Endpoint DLP
Review and respond to DLP alerts, events, and reports
This course contains promotional materials.