15 49.0138 8.38624 1 0 4000 1 https://vladtalkstech.com 300 1
theme-sticky-logo-alt

MS-101 Study Guide – Microsoft 365 Mobility and Security

The MS-101 exam is the one of the two exams needed to get the Microsoft 365 Certified: Enterprise Administrator Expert certification. Candidates for this exam are Microsoft 365 Enterprise Administrators who take part in evaluating, planning, migrating, deploying, and managing Microsoft 365 services. They perform Microsoft 365 tenant management tasks for an enterprise, including its identities, security, compliance, and supporting technologies. Candidates have a working knowledge of Microsoft 365 workloads and should have been an administrator for at least one Microsoft 365 workload (Exchange, SharePoint, Skype for Business, Windows as a Service). Candidates also have a working knowledge of networking, server administration, and IT fundamentals such as DNS, Active Directory, and PowerShell

In this MS-101 Study Guide, I will share both free and paid options, whether books, video training or simply links to articles and blog posts. I will not share any dumps as those are against the Microsoft Terms of Service, and by using dumps, we decrease the value of our certifications.

MS-101 Study Guide

Certification Path

RequirementExam NameLink to Exam on Microsoft LearningStudy Guide
Optional Prerequisite: Microsoft 365 Fundamentals Certification
Optional

MS-900 – Microsoft 365 Fundamentals

https://www.microsoft.com/en-us/learning/exam-ms-900.aspx

https://vladtalkstech.com/ms-900-study-guide-microsoft-365-fundamentals

Required Prerequisite: Microsoft 365 Certified Teamwork Administrator Associate

(5 Options)

Microsoft 365 Certified: Teamwork Administrator

Microsoft 365 Certified: Modern Desktop Administrator Associate

Microsoft 365 Certified: Security Administrator Associate

Microsoft 365 Certified: Messaging Administrator Associate

MCSE Productivity

Study Guides: https://vladtalkstech.com/microsoft-certification-study-guides
Microsoft 365 Certified: Enterprise Administrator Expert
Required

MS-100: Microsoft 365 Identity and Services

https://www.microsoft.com/en-us/learning/exam-ms-100.aspx

https://vladtalkstech.com/ms-100-study-guide-microsoft-365-identity-and-services

Required

MS-101: Microsoft 365 Mobility and Security

https://www.microsoft.com/en-us/learning/exam-ms-101.aspx

https://vladtalkstech.com/ms-101-study-guide-microsoft-365-mobility-and-security

Books

MS-101 Study Guide

Exam Ref MS-101 Microsoft 365 Mobility and Security
Exam Ref MS-101 Microsoft 365 Mobility and Security offers professional-level preparation that helps candidates maximize their exam performance and sharpen their skills on the job. It focuses on the specific areas of expertise modern IT professionals need to demonstrate mastery of Microsoft 365 mobility, security, and related management tasks. Coverage includes:

  • Implementing Mobile Device Services
  • Implementing Microsoft 365 Security and Threat Management
  • Managing Microsoft 365 Governance and Compliance

Links:

Microsoft 365 Mobility and Security – Exam Guide MS 101: Implement threat management, prevent data loss, and manage data governance with the help of this certification guide
Written in a clear, succinct way with self-assessment questions, exam tips and mock exams with detailed answer explanations, this book covers common tasks in mobile device management (MDM) and device compliance, security reporting and alerts, threat detection and management, data loss prevention (DLP) and data governance, auditing and eDiscovery, and Azure information protection (AIP).You’ll learn how to properly plan for, deploy, and manage Microsoft 365 services such as MDM and DLP. You’ll discover best practices in properly configuring settings across your tenant to ensure compliance and security.

By the end of this book, you’ll have covered everything you need to pass the MS-101 exam and have a handy, on-the-job desktop reference guide.

Links:

Video Training

NOTE: Pluralsight is a paid resource unlike Channel9 and Microsoft Virtual Academy which are free. The quality they provide is also superior because of all the quality checks they go through, and the instructors are one of the best in the industry. The Pluralsight courses have a link to where you can get a free trial and decide for yourself if paying a subscription or not is worth it, but the 10-day free trial should allow you to view all those courses for free.

<Coming Soon>
Microsoft 365 Enterprise Admin role-based exam prep: MS-101 Mobility & Security – BRK2434
This Certification Exam Prep session is designed for people experienced with Microsoft 365 who are interested in certification. Specifically, attendees will learn more about the recently announced Microsoft 365 Mobility and Security MS-101 exam that is part of the new Microsoft 365 Enterprise Administrator certification. The session is led by a Microsoft Certified Trainer (MCT), experienced in delivering sessions on these topics.

<Coming Soon>

Instructor-led training (Microsoft Official Courses)

Management Course MS-101T01-A: Microsoft 365 Security Management
Learn about Microsoft 365 Security Management, including how to manage your security metrics, how to enable Azure AD Identity Protection, how to configure your Microsoft 365 security services, and user Microsoft 365 Threat Intelligence.

MS-101T02-A: Microsoft 365 Compliance Management
Learn about Microsoft 365 Compliance Management, including data retention and data loss prevention solutions in Microsoft 365, archiving and retention in Microsoft 365, implementing and managing data governance, and managing search and investigations.

Course MS-101T03-A: Microsoft 365 Device Management
This course introduces you to the world of Microsoft 365 device management – from establishing Microsoft Intune, to enrolling devices to Intune, to monitoring the devices, to controlling what users can do from the enrolled devices by using conditional access policies. If you are already managing devices by using a traditional device management tool such as Configuration Manager, you will be interested to know how you can seamlessly move to modern management, in which devices are managed by Intune, and how you can benefit from new device management capabilities, such as compliance, conditional access, and Windows Autopilot to deploy new devices from the cloud.

Articles / Blog Posts Per Objective

Implement modern device services (30-35%)

Implement Mobile Device Management (MDM)

  • plan for MDM
  1. Intune deployment planning, design, and implementation guide [Microsoft – Docs – Enterprise Mobility Security]
  • configure MDM integration with Azure AD
  1. What is device management in Azure Active Directory? [Microsoft – Docs – Azure]
  2. Quickstart: Set up automatic enrollment for Windows 10 devices [Microsoft – Docs – Enterprise Mobility Security]
  3. Set up enrollment for Windows devices [Microsoft – Docs – Enterprise Mobility Security]
  4. Azure Active Directory integration with MDM [Microsoft – Docs – Windows]
  5. Azure AD and Microsoft Intune: Automatic MDM enrollment in the new Portal [Microsoft – Docs – Windows]
  • set an MDM authority
  1. Set the mobile device management authority [Microsoft – Docs – Enterprise Mobility Security]
  2. Change your MDM authority [Microsoft – Docs – Enterprise Mobility Security]
  • set device enrollment limit for users
  1. Set enrollment restrictions [Microsoft – Docs – Enterprise Mobility Security]

Manage device compliance

  • plan for device Compliance
  1. Device compliance policies in System Center Configuration Manager [Microsoft – Docs – Enterprise Mobility Security]
  2. Create a compliance policy in Microsoft Intune [Microsoft – Docs – Enterprise Mobility Security]
  3. Monitor Intune Device compliance policies [Microsoft – Docs – Enterprise Mobility Security]
  • design Conditional Access Policies
  1. What are common ways to use conditional access with Intune? [Microsoft – Docs – Enterprise Mobility Security]
  • create Conditional Access Policies
  1. Create a compliance policy in Microsoft Intune [Microsoft – Docs – Azure]
  • configure device compliance policy
  1. Set rules on devices to allow access to resources in your organization using Intune [Microsoft – Docs – Enterprise Mobility Security]
  • manage Conditional Access Policies
  1. Monitor Intune Device compliance policies [Microsoft – Docs – Azure]

Plan for devices and apps

  • create and configure Microsoft Store for Business
  1. Microsoft Store for Business and Microsoft Store for Education overview [Microsoft – Docs – Microsoft store for business]
  2. Integrate Windows Store for Business with Microsoft Intune [Microsoft – Blog – Developer]
  3. Manage settings for Microsoft Store for Business and Education [Microsoft – Docs – Microsoft store for business]
  4. Settings reference: Microsoft Store for Business and Education [Microsoft – Docs – Microsoft store for business]
  • plan app deployment
  1. Distribute apps with a management tool [Microsoft – Docs – Microsoft store for business]
  2. Distribute apps using your private store [Microsoft – Docs – Microsoft store for business]
  3. Assign apps to employees [Microsoft – Docs – Microsoft store for business]
  4. Windows 10 app deployment using Microsoft Intune [Microsoft – Docs – Enterprise Mobility Security]
  • plan device co-management
  1. How to prepare internet-based devices for co-management [Microsoft – Docs – Enterprise Mobility Security]
  2. Tutorial: Enable co-management for existing Configuration Manager clients [Microsoft – Docs – Enterprise Mobility Security]
  3. Remote actions with co-management [Microsoft – Docs – Enterprise Mobility Security]
  4. Use Azure AD for co-management [Microsoft – Docs – Enterprise Mobility Security]
  5. How to monitor co-management in Configuration Manager [Microsoft – Docs – Enterprise Mobility Security]
  • plan device monitoring
  1. Monitor Intune Device compliance policies [Microsoft – Docs – Enterprise Mobility Security]
  • plan for device profiles
  1. Assign user and device profiles in Microsoft Intune [Microsoft – Docs – Enterprise Mobility Security]
  2. Apply features and settings on your devices using device profiles in Microsoft Intune [Microsoft – Docs – Enterprise Mobility Security]
  3. Create a device profile in Microsoft Intune [Microsoft – Docs – Enterprise Mobility Security]
  • plan for Mobile Application Management
  1. What is Microsoft Intune app management? [Microsoft – Docs – Enterprise Mobility Security]
  2. Overview of the app lifecycle in Microsoft Intune [Microsoft – Docs – Enterprise Mobility Security]
  • plan mobile device security
  1. Protect devices with Microsoft Intune [Microsoft – Docs – Enterprise Mobility Security]

Plan Windows 10 deployment

  • plan for Windows as a Service (WaaS)
  1. Overview of Windows as a service [Microsoft – Docs ]
  2. Plan for Windows 10 deployment [Microsoft – Docs ]

Implement Microsoft 365 security and threat management (30-35%)

Implement Cloud App Security (CAS)

Implement threat management

Implement Windows Defender Advanced Threat Protection (ATP)

Manage security reports and alerts

  • manage service assurance dashboard
  1. Office 365 Service Assurance—gaining your trust with transparency [Microsoft – Blog – Microsoft 365]
  2. Service assurance in the Security & Compliance Center [Microsoft – Docs – Office 365]
  3. An Overview of Office 365 Service Assurance Resources [Microsoft – Blog – technet]
  • manage tracing and reporting on Azure AD Identity Protection
  1. Azure advanced threat detection [Microsoft – Docs – Azure]
  2. What is Azure Active Directory Identity Protection? [Microsoft – Docs – Azure]
  3. Plan an Azure Active Directory reporting and monitoring deployment [Microsoft]
  • configure and manage Microsoft 365 security alerts
  1. Alerts in the Office 365 Security & Compliance Center [Microsoft – Docs – Office 365]
  2. Alert policies in the security and compliance center [Microsoft – Docs – Office 365]
  • configure and manage Azure Identity Protection dashboard and alerts
  1. Azure Active Directory Identity Protection [Microsoft – Docs – Azure]
  2. Remediate risks and unblock users [Microsoft – Docs – Azure]
  3. Azure Active Directory risk events [Microsoft – Docs – Azure]

Manage Microsoft 365 governance and compliance (35-40%)

Configure Data Loss Prevention (DLP)

  • configure DLP Policies
  1. Overview of data loss prevention [Microsoft – Docs – Office 365]
  2. Create a DLP policy from a template [Microsoft – Docs – Office 365]
  3. Get started with DLP policy recommendations [Microsoft – Docs – Office 365]
  4. Create, test, and tune a DLP policy [Microsoft – Docs – Office 365]
  • design data retention policies in Microsoft 365
  1. Data Retention, Deletion, and Destruction in Office 365 [Microsoft – Docs – Office 365]
  2. Set up an archive and deletion policy for mailboxes in your Office 365 organization [Microsoft – Docs – Office 365]
  3. Retention tags and retention policies [Microsoft – Docs – Exchange]
  4. Retention policies in Microsoft Teams [Microsoft – Docs – Microsoft Teams]
  5. Overview of retention labels [Microsoft – Docs – Office 365]
  6. Overview of document deletion policies [Microsoft – Docs – Office 365]
  • manage DLP exceptions
  1. Data loss prevention [Microsoft – Docs – Exchange]
  2. Create, test, and tune a DLP policy [Microsoft – Docs – Office 365]
  • monitor DLP policy matches
  1. View the reports for data loss prevention [Microsoft – Docs – Office 365]
  2. How DLP works between the Security & Compliance Center and Exchange admin center [Microsoft – Docs – Office 365]
  • manage DLP policy matches
  1. What the DLP functions look for [Microsoft – Docs – Office 365]

Implement Azure Information Protection (AIP)

  • plan AIP solution
  1. Azure Information Protection deployment roadmap [Microsoft – Docs – Enterprise mobility + security]
  2. Frequently asked questions about data protection in Azure Information Protection [Microsoft – Docs – Enterprise mobility + security]
  3. Requirements for Azure Information Protection [Microsoft – Docs – Enterprise mobility + security]
  • plan for deployment On-Prem rights management Connector
  1. Deploying the Azure Rights Management connector [Microsoft – Docs – Enterprise mobility + security]
  2. Installing and configuring the Azure Rights Management connector [Microsoft – Docs – Enterprise mobility + security]
  3. Configuring servers for the Azure Rights Management connector [Microsoft – Docs – Enterprise mobility + security]
  • plan for Windows information Protection (WIP) implementation
  1. Windows Information Protection (WIP) [Microsoft – Docs – Windows]
  2. Create and deploy a Windows Information Protection (WIP) policy using System Center Configuration Manager [Microsoft – Docs – Windows]
  3. Create a Windows Information Protection (WIP) policy using the Azure portal for Microsoft Intune [Microsoft – Docs – Windows]
  • plan for classification labeling
  1. Architect a classification schema for personal data [Microsoft – Docs – Office 365]
  2. Quickstart: Configure a label for users to easily protect emails that contain sensitive information [Microsoft – Docs – Enterprise mobility + security]
  3. Configure classification for your environment [Microsoft – Docs – Microsoft 365]
  4. Frequently asked questions about classification and labeling in Azure Information Protection [Microsoft – Docs – Enterprise mobility + security]
  • configure Information Rights Management (IRM) for Workloads
  1. Activate Rights Management in the Office 365 admin center [Microsoft – Docs – Office 365 Enterprise]
  • configure Super User
  1. Configuring super users for Azure Rights Management and discovery services or data recovery [Microsoft – Docs – Enterprise mobility + security]
  • deploy AIP Clients
  1. Azure Information Protection client administrator guide [Microsoft – Docs – Enterprise mobility + security]
  2. Admin Guide: Install the Azure Information Protection client for users [Microsoft – Docs – Enterprise mobility + security]
  3. Deploying the Azure Information Protection scanner to automatically classify and protect files [Microsoft – Docs – Enterprise mobility + security]
  4. Azure Information Protection client: Installation and configuration for clients [Microsoft – Docs – Enterprise mobility + security]
  • implement Azure Information Protection policies
  1. Configuring the Azure Information Protection policy [Microsoft – Docs – Enterprise mobility + security]
  2. How to configure the policy settings for Azure Information Protection [Microsoft – Docs – Enterprise mobility + security]
  3. Overview of the Azure Information Protection policy [Microsoft – Docs – Enterprise mobility + security]
  4. How to configure the Azure Information Protection policy for specific users by using scoped policies [Microsoft – Docs – Enterprise mobility + security]
  5. How to configure conditions for automatic and recommended classification for Azure Information Protection[Microsoft – Docs – Enterprise mobility + security]
  • implement AIP tenant key
  1. Planning and implementing your Azure Information Protection tenant key [Microsoft – Docs – Enterprise mobility + security]
  2. Operations for your Azure Information Protection tenant key [Microsoft – Docs – Enterprise mobility + security]
  3. Bring your own key (BYOK) details for Azure Information Protection [Microsoft – Docs – Enterprise mobility + security]

Manage data governance

  • configure information retention
  1. AIP AND RETENTION LABELS: WHAT’S THE DIFF? [Blog – Joanne Klein]
  2. Overview of retention policies [Microsoft – Docs – Office 365]
  • plan for Microsoft 365 backup
  1. Data protection beyond backup and recovery with Office 365 [Microsoft – techcommunity]
  2. Back up data before switching O365 for business plans [Microsoft – Docs – Office 365]
  • plan for restoring deleted content
  1. Restore a deleted Office 365 Group [Microsoft – Docs – Office 365]
  2. Recover deleted items in a user mailbox – Admin Help [Microsoft – Docs – Office 365 Enterprise]
  3. Restore your OneDrive [Microsoft – support office]
  4. How to recover missing, deleted or corrupted items in SharePoint Online and OneDrive for Business [Microsoft – support office]
  5. Restore deleted files or folders in OneDrive[Microsoft – support office]
  6. Restore items in the Recycle Bin of a SharePoint site [Microsoft – support office]
  7. Restore deleted items from the site collection recycle bin [Microsoft – support office]
  • plan information Retention Policies
  1. Overview of retention policies [Microsoft – Docs – Office 365]
  2. Microsoft Teams retention policies FAQ [Microsoft – Docs – Microsoft]
  3. Retention policies for Microsoft Teams [Microsoft – techcommunity]

Manage auditing

  • configure audit log retention
  1. Turn Office 365 audit log search on or off [Microsoft – Docs – Office 365]
  2. Search the audit log in the Security & Compliance Center (Before you begin section) [Microsoft Docs]
  • configure audit policy
  1. Configure your Office 365 tenant for increased security [Microsoft – Docs – Office 365]
  2. Auditing in Office 365 (for Admins) [Microsoft – Docs – Office 365]
  • monitor Unified Audit Logs
  1. Search the audit log in the Security & Compliance Center [Microsoft – Docs – Office 365]

Manage eDiscovery

  • search content by using Security and Compliance Center
  1. eDiscovery and Search Features [Microsoft – Docs – Office 365]
  2. Content Search in Office 365 [Microsoft – Docs – Office 365]
  3. eDiscovery cases in the Security & Compliance Center [Microsoft – Docs – Office 365]
  4. Use Content Search in your eDiscovery workflow [Microsoft – Docs – Office 365]
  5. Limits for Content Search in the Security & Compliance Center [Microsoft – Docs – Office 365]
  • plan for in-place and legal hold
  1. In-Place Hold and Litigation Hold [Microsoft – Docs – exchange]
  2. Create a Litigation Hold [Microsoft – Docs – Office 365]
  3. Manage legal investigations in Office 365 [Microsoft – Docs – Office 365]
  • configure eDiscovery
  1. Quick setup for Office 365 Advanced eDiscovery [Microsoft – Docs – Office 365]
  2. eDiscovery in Office 365 [Microsoft – Docs – Office 365]
  3. Set up an eDiscovery Center in SharePoint Online [Microsoft – Docs – support office]
  4. eDiscovery cases in the Security & Compliance Center [Microsoft – Docs – Office 365]
  5. Assign eDiscovery permissions in the Security & Compliance Center [Microsoft – Docs – Office 365]

Additional Tips

I think the best thing that you can do after reading this, or even meanwhile, is to open a free Microsoft 365 trial (or a few), and play with those features, follow the tutorials and you shouldn’t have any problems with the exam!

Did I miss any cool links in this guide? Let me know in the comments!

0 Comments

    Leave a Reply