Microsoft Certification Study Guide
MS-700 Managing Microsoft Teams certification badge

MS-700 Study Guide

Managing Microsoft Teams

Free study notes for every skill the exam measures, plus the books, courses and practice tests I recommend.

The MS-700 Study Guide helps you prepare for the Managing Microsoft Teams exam and the Microsoft 365 Certified: Teams Administrator Associate certification, the credential for administrators who plan, deploy and run collaboration and communication in Microsoft Teams.

Everything here lines up with the skills Microsoft measures: free Microsoft Learn paths and my own study notes for self-study, plus the books, courses and practice tests I recommend when you want more. No exam dumps, ever.

Exam length
100 min
Passing score
700 / 1000
Skills measured
4 domains, 97 skills
Guide reviewed
September 2026

Resources by the way you like to study

9 hand-picked, free and paid

Books

2 resources

Many learners prefer studying from books, which is why Microsoft continues to publish the Exam Ref series. Just keep in mind that books can lag behind exam updates, so always check the publication date and whether the skills measured changed since.

Exam Ref MS-700 Managing Microsoft Teams, book cover Recommended

Exam Ref MS-700 Managing Microsoft Teams

Prepare for Microsoft Exam MS-700 and demonstrate your real-world knowledge of Microsoft Teams planning, deployment, configuration, management, security, troubleshooting, and more. Designed for professionals with Microsoft Teams experience, this Exam Ref focuses on the critical thinking and decision-making acumen needed for success at the Microsoft 365 Certified: Teams Administrator Associate level.

See price on Amazon (opens in a new tab)
MS-700 Managing Microsoft Teams Exam Guide, book cover

MS-700 Managing Microsoft Teams Exam Guide: Ace the MS-700 exam and become a Certified Microsoft Teams Administrator

Do you want to build and test your proficiency in the deployment, management, and monitoring of Microsoft Teams features within the Microsoft 365 platform? Managing Microsoft Teams: MS-700 Exam Guide will help you to effectively plan and implement Microsoft Teams using the Microsoft 365 Teams admin center and Windows PowerShell. You'll also discover best practices for rolling out and managing MS services for Teams users within your Microsoft 365 tenant. The chapters are divided into three easy-to-follow parts: planning and design, feature policies and administration, and team management, while aligning with the skills the MS-700 exam measures to help you prepare effectively for the exam.

See price on Amazon (opens in a new tab)

On-Demand Video Training

3 resources

On-demand training lets you learn at your own pace, on your own schedule. Whether it's expert-led video courses from platforms like Pluralsight or Udemy, or hands-on modules from Microsoft Learn, you get flexible access to practical, real-world learning when you need it most.

Not all training platforms are the same. Some, like Pluralsight, rely on vetted authors and curated content, while others function as open marketplaces where quality can vary. I only recommend courses that are highly rated and closely aligned with the skills you need, and I still encourage reviewing course details and feedback before enrolling.

Pluralsight Recommended

Managing Microsoft Teams (MS-700) Certification Path

Practice test includedFree trial

This MS-700 learning path provides high-quality training to help you confidently manage Microsoft Teams. You'll learn how to configure, deploy, and administer Teams across chat, collaboration, networking, and endpoints. The content aligns with the skills MS-700 measures and includes exam-focused lessons and practice tests to help you prepare for certification.

Watch on Pluralsight (opens in a new tab)
Udemy

MS-700 Managing Microsoft Teams Training & Lab Simulations

Practice test included

Microsoft Teams Teamwork Administrator Associate certification course and MS-700 exam preparation. Simulations included!

Watch on Udemy (opens in a new tab)
Udemy

Microsoft MS-700 Certification: Managing Teams

This course will help you study for and pass the MS-700 exam by Microsoft, which will earn you the coveted Microsoft 365 Certified: Teams Administrator Associate badge.

Watch on Udemy (opens in a new tab)

Practice Tests

2 resources

These are practice exams, not exam dumps. I don't support dumps, as they undermine the value of the certification for everyone. Practice tests are a great way to validate your knowledge and get exam-ready after completing the content in this MS-700 study guide.

Microsoft

Practice Assessment for Exam MS-700: Managing Microsoft Teams

Free

Microsoft's own free practice assessment for the MS-700, written against the same skills measured as the exam. A good way to see where you stand before you pay for anything else.

Take the practice test (opens in a new tab)

Microsoft Learn Modules

1 resource

Microsoft Learn is a great free way to learn about the MS-700 exam content! It contains mostly text-based articles, while also providing you small quizzes at the end of every module.

The course syllabus below is Microsoft's own list of the learning paths and modules that cover the exam. When you want one topic rather than the whole curriculum, every skill in my study notes links the exact Microsoft Learn page for it.

Microsoft

Course MS-700T00-A: Manage collaboration and communication with Microsoft Teams

Free

Microsoft's official MS-700 course page. The syllabus lists every Microsoft Learn path and module the course teaches, and all of them are free to work through at your own pace.

Start on Microsoft Learn (opens in a new tab)

Live Training

1 resource

This is the Microsoft Official Course, which you can schedule at a Microsoft learning partner. Those classes are presented by Microsoft Certified Trainers. This is the best way to learn any topic as you can ask questions to a live instructor, but also the most expensive one.

Microsoft

Course MS-700T00-A: Manage collaboration and communication with Microsoft Teams

Instructor-led

The Manage collaboration and communication with Microsoft Teams course is designed for persons who are aspiring to the Microsoft 365 Teams Admin role. A Microsoft Teams administrator plans, deploys, configures, and manages Microsoft Teams to focus on efficient and effective collaboration and communication in a Microsoft 365 environment. In this course, you will learn about various Teams management tools, security and compliance feature for Teams, network requirement for Teams deployment as well as different Teams settings and policies for managing collaboration and communication experience in Teams.

Find a class (opens in a new tab)

Some links on this page are affiliate links. If you use them, I may earn a commission at no extra cost to you.

Skills measured and study notes

97 skills, free to study here
0 of 97 studied

The MS-700 exam covers four domains, and I have broken down every single skill below with an explanation, the facts the exam can actually ask, and a Microsoft Learn link. These notes follow the skills measured as of July 29, 2026. If you administer Teams every day you will recognise most of this, but read the governance and external collaboration sections carefully: they are where the exam gets specific about licences, defaults and which admin center owns which setting.

Here is how the four domains break down by weight:

Tip: Domain 1 is nearly half the exam on its own. If your study time is short, spend it on network planning, security and compliance settings, governance and external collaboration, then come back for the rest.

Domain 1 Configure and Manage a Teams Environment 40-45% of the exam 0 / 45 studied

This domain is the platform work: making sure the network can carry real-time media, putting the right security and compliance controls on Teams data, governing how teams are created and retired, deciding how people outside your tenant collaborate with you, and licensing and managing the devices in your meeting rooms. Expect a lot of questions of the form "which setting, in which admin center, and what licence does it need".

Plan network settings for Teams

01

Calculate network bandwidth capacity for Teams voice, video, meetings, and events

Teams adapts to the bandwidth it finds, so the planning question is not whether it will work but whether it will work well for the number of people in this office. Microsoft publishes minimum, recommended and best-performance figures per stream, and the numbers are per endpoint rather than per person.

What you need to know

Scenario Minimum (up/down) Recommended Best performance
Audio 10/10 kbps 58/58 kbps 76/76 kbps
Video, 1:1 150/150 kbps 1,500/1,500 kbps 4,000/4,000 kbps
Video, meetings 150/200 kbps 2,500/4,000 kbps 4,000/4,000 kbps
Screen sharing, meetings 250/250 kbps 2,500/2,500 kbps 2,500/2,500 kbps
  • Bandwidth is counted per endpoint, so one person joined from a laptop and a phone counts twice
  • Teams prioritises audio over video when bandwidth runs short, and the minimum tier caps video at 240p
  • Live-streamed events without an eCDN need roughly 2 Mbps per viewer per location, or 3 Mbps for 1080p
  • The Media bit rate (Kbps) meeting policy setting has a minimum of 30 Kbps and applies separately to uplink and downlink
  • Microsoft recommends planning 10,000 kbps for a Teams Rooms resource account, even though a room typically uses 3 to 4 Mbps

Exam tip: The Media bit rate policy value is applied in each direction, so 2,000 Kbps means 2,000 up and 2,000 down, and it has no effect on the Teams web client.

Microsoft Learn resource: Prepare your organization's network for Microsoft Teams (opens in a new tab)

02

Analyze network impact by using Network planner

Network planner is the modelling tool in the Teams admin center. You describe your sites and the kinds of people at them, and it works out the bandwidth Teams will need, without touching the live network.

What you need to know

  • Found at Teams admin center > Planning > Network planner; needs Global Administrator, Teams Administrator or Teams Communications Administrator
  • Three Microsoft personas ship in the box, office worker, remote worker and Teams Rooms System, and you can add up to three custom personas
  • A new report starts with a default user split of 80% office worker and 20% remote worker
  • A site needs a user count; optional detail includes WAN enabled, WAN capacity, internet egress (local or remote) and PSTN egress
  • The report's default allowed bandwidth is 30%, and shortfalls are highlighted in red with per-site recommendations

Exam tip: Network planner only models. If the question asks you to measure what the network actually does today, the answer is the Network Assessment Tool or the Microsoft 365 network connectivity test tool.

Microsoft Learn resource: Use the Network planner for Microsoft Teams (opens in a new tab)

03

Specify network ports and protocols used by Teams

Teams real-time media wants UDP, and the ports are a favourite exam fact because they are short and specific. Everything is initiated outbound, which is why no inbound firewall rules are needed.

What you need to know

  • Media uses UDP 3478 (STUN), 3479 (audio), 3480 (video) and 3481 (screen sharing and VBSS)
  • Signalling and services use TCP 443 and 80, plus UDP 443
  • Media is RTP secured by SRTP over UDP; TCP and HTTP tunnelling work but Microsoft explicitly does not recommend them because quality suffers
  • Recommended QoS client source port ranges are audio 50,000 to 50,019 (DSCP 46), video 50,020 to 50,039 (DSCP 34) and screen sharing 50,040 to 50,059 (DSCP 18)
  • Choosing "automatically use any available ports" gives the client the whole 1024 to 65535 range, which makes QoS marking impossible

Exam tip: No inbound firewall rules are required for Teams. All media and signalling starts from the client and returns on the stateful connection.

Microsoft Learn resource: Microsoft 365 URLs and IP address ranges (opens in a new tab)

04

Assess network readiness and connectivity by using the Microsoft Teams Network Assessment Tool and Microsoft 365 network connectivity test tool

These two tools measure the real network rather than modelling it. The Network Assessment Tool is a download that runs a media quality check from one location, and the connectivity test tool is a web page plus a Windows client that reports into your tenant.

What you need to know

  • The connectivity test tool lives at connectivity.m365.cloud.microsoft, and its advanced tests need a downloadable Windows client with the .NET 6.0 Runtime
  • Its pass thresholds are UDP packet loss under 1.00%, latency under 100 ms and jitter under 30 ms, measured with a ten-second test call
  • Results roll up into Microsoft 365 admin center > Health > Network connectivity, scored 0 to 100, where 80 means the location meets recommendations
  • The tool also flags a proxy more than 500 miles away and buffer bloat that adds 100 ms or more of latency
  • The Network Assessment Tool is a separate Microsoft download that runs a media quality check and writes its results to a local file

Exam tip: The admin center network insights are aggregated in-product measurements from many machines; the connectivity test tool is a one-off measurement from one place. They complement each other rather than replacing each other.

Microsoft Learn resource: Microsoft 365 network connectivity test tool (opens in a new tab)

Manage security and compliance settings for Teams

05

Identify licensing requirements for security and compliance features

This skill is licence recall, and the pattern is worth learning once: files and email are covered at E3, while message content and behavioural analytics are E5.

What you need to know

Feature Licence
DLP for SharePoint, OneDrive and Exchange, so files shared in Teams E3
DLP for Teams chat and channel messages E5 class
Retention policies for Teams Office 365 E3 or above
Communication Compliance, Insider Risk Management E5 class
Audit (Standard) and Audit (Premium) E3 and E5
Sensitivity labels applied to Teams meetings Teams Premium plus E5 Compliance
  • Guest users and federated senders are exempt from the DLP licensing requirement
  • eDiscovery (Premium) needs E5, the Purview Suite, or the eDiscovery and Audit add-on
  • Content search and eDiscovery (Standard) need no enabling step, unlike auditing

Exam tip: Blocking a sensitive document shared in a Teams chat is an E3 scenario, because the file lives in OneDrive or SharePoint. Blocking the sensitive chat message itself is E5.

Microsoft Learn resource: Security and compliance in Microsoft Teams (opens in a new tab)

06

Specify security and compliance alert policies for Teams

Alert policies are how Purview and Defender tell you that something happened. Teams has its own separate alerting in the Teams admin center, and the exam likes to test which one you reach for.

What you need to know

  • Purview and Defender alert policies live in the Microsoft Defender portal under Policies & rules > Alert policy; default policies show in bold and can only be switched off or given recipients
  • Categories are Data loss prevention, Information governance, Mail flow, Permissions, Threat management and Others; severities are Low, Medium, High and Informational
  • Threshold-based and unusual-activity alerts need E5 or an add-on; E1 and E3 can only alert every time an activity occurs
  • DLP alerts are aggregated over a one-minute window with E5 and a fifteen-minute window with E3
  • The Teams admin center has its own Notifications & alerts > Rules area, and those alerts post into an auto-created team called Admin Alerts and Notifications or to a webhook

Exam tip: In-progress meeting quality alert rules are configured in the Teams admin center, not in Purview, and every monitored attendee needs Teams Premium or Teams Rooms Pro.

Microsoft Learn resource: Alert policies in the Microsoft Defender portal (opens in a new tab)

07

Choose appropriate Teams administrator roles

Teams delegation is done with Microsoft Entra ID roles, and the exam almost always asks you to pick the least privileged role that still does the job.

What you need to know

  • Teams Administrator manages the whole service and can create and manage Microsoft 365 Groups
  • Teams Communications Administrator covers meetings and voice, but not teams, apps or devices
  • Teams Communications Support Engineer sees end user identifiable information in call troubleshooting; the Support Specialist does not, and can only look up one searched user at a time
  • Teams Device Administrator gets the whole Devices section, but no call quality data
  • Current documentation also lists Teams Reader and Teams Telephony Administrator
  • Creating and managing resource accounts needs a Teams admin role and the User Administrator role

Exam tip: Support Specialist versus Support Engineer is the classic pair. Specialist means basic tools and no user identifiable information; Engineer means advanced tools with it visible.

Microsoft Learn resource: Use Microsoft Teams administrator roles to manage Teams (opens in a new tab)

08

Plan and configure threat policies in Microsoft Defender for Office 365

Teams content can be scanned by Defender for Office 365, and threat policies are how you turn that on. The important idea is precedence: the first matching policy wins and policies do not merge.

What you need to know

  • There is no default Safe Attachments policy and no default Safe Links policy; the Built-in protection preset covers everyone not already covered by Standard, Strict or a custom policy
  • The three presets are Standard protection, Strict protection and Built-in protection; Standard and Strict apply to nobody until you assign users
  • Precedence runs Strict, then Standard, then evaluation policies, then custom policies by priority where 0 is highest, then Built-in protection and the default policies
  • Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is a single global setting that is off by default and is turned on by Built-in protection
  • The default anti-phishing policy gives only spoof protection and mailbox intelligence, not impersonation protection

Exam tip: Protection stops at the first matching policy for a recipient. If a user is in both a custom policy and the Strict preset, Strict is what applies.

Microsoft Learn resource: Preset security policies in cloud organizations (opens in a new tab)

09

Specify retention policies

Teams retention uses its own locations, and those locations cannot be mixed with Exchange and SharePoint in the same static policy. The other thing to remember is that the retention clock always starts at creation.

What you need to know

  • The Teams locations are Teams chats, Teams channel messages, Teams private channel messages and Teams call logs
  • Retention labels are not supported for Teams, only retention policies
  • The retention period always runs from when the message was created; the last modified option is ignored
  • Choosing a Teams location in a static policy excludes every other location, so use an adaptive scope if one policy must span workloads
  • Expired items sit in the hidden SubstrateHolds folder for at least a day before the timer job purges them, typically one to seven days
  • The Teams call logs policy can only be created with PowerShell and is read-only in the Purview portal

Exam tip: Files and meeting recordings are not covered by a Teams retention policy. Channel files need a Microsoft 365 Groups policy, and chat files and one-to-one meeting recordings need a OneDrive policy.

Microsoft Learn resource: Learn about retention for Microsoft Teams (opens in a new tab)

10

Specify sensitivity labels and publishing policies, including for Teams meetings

A sensitivity label can protect a meeting as well as a file, and in a meeting it can enforce settings the organizer cannot override. That makes labels the strongest of the ways to control meeting options.

What you need to know

  • A meeting label needs all three scopes selected, files and other data assets, emails, and meetings, because the invite, the attachments and the meeting are interdependent
  • On the protection page you choose Protect Teams meetings and chat to reveal the Teams settings
  • A label can enforce lobby bypass, who can present, who can record, end-to-end encryption, automatic recording, watermarking, and preventing copy or forward of the meeting chat
  • Teams Premium is required for meeting settings in labels, and end-to-end encrypted meetings support up to 200 participants
  • In a label policy, the entry at the top of the list has the lowest order number and the lowest priority, so on conflict the highest order number wins
  • For containers such as teams and sites, a label has to be applied when the container is created

Exam tip: The order of strength for meeting settings is admin policy, then label, then template, then organizer options. A label can turn on watermarking even when the template does not.

Microsoft Learn resource: Use sensitivity labels to protect calendar items, Teams meetings, and chat (opens in a new tab)

11

Specify Microsoft Purview Data Loss Prevention (DLP) policies

DLP for Teams inspects chat and channel messages. The scoping rules are unusual enough to be worth memorising, because scoping to individual users silently misses channel messages.

What you need to know

  • The location is called Teams chat and channel messages, and policy changes take about an hour to sync
  • A policy scoped to individual user accounts covers one-to-one and group chats but not channel messages; scope to a group to cover channels
  • Teams DLP sends no end user notification email; users see a message flag and a policy tip, and admins get the incident report
  • In an external access chat, messages are evaluated against the hosting tenant's policies
  • In a shared channel, messages are evaluated against the sender's own tenant policies
  • The first-run default Teams DLP policy watches for credit card numbers shared internally and externally

Exam tip: External access and shared channels evaluate DLP from opposite ends. External access follows the host; shared channels follow the sender.

Microsoft Learn resource: Data loss prevention and Microsoft Teams (opens in a new tab)

12

Specify Microsoft Entra Conditional Access policies for Teams

Conditional Access applies to resources, not to client apps, and Teams depends on other services to work. That is why a policy aimed at SharePoint can lock people out of Teams.

What you need to know

  • Target the Office 365 app grouping rather than individual cloud apps, so service dependencies stay consistent
  • Teams has early-bound dependencies on Exchange and SharePoint, and late-bound dependencies on Planner, Stream and Whiteboard
  • Early-bound means the dependent service's policy must be satisfied before the user can sign in to Teams; late-bound defers enforcement until Teams asks for that service's token
  • The client app condition Microsoft Teams Services covers every Teams client, but excluding it does not exempt Teams, because policy applies to the resource
  • For shared channels, only the host organization's policies apply to B2B direct connect users, scoped with the Office 365 SharePoint Online cloud app
  • Continuous access evaluation lets Teams react near-real-time to a disabled account, a password change or admin token revocation

Exam tip: If a Conditional Access change broke Teams and you only touched SharePoint, that is the early-bound dependency doing exactly what it is documented to do.

Microsoft Learn resource: Service dependencies in Microsoft Entra Conditional Access (opens in a new tab)

13

Specify Microsoft Purview Information Barriers policies

Information barriers stop two groups of people communicating, which is a regulatory requirement in finance and a conflict-of-interest control everywhere else. You define segments, then policies between them.

What you need to know

  • Segments and policies live in the Purview portal under Information Barriers, and the IB Compliance Management role owns them
  • Modern mode supports up to 5,000 segments and lets a user sit in several; legacy mode caps at 250 segments and one segment per user
  • You must enable scoped directory search in Teams before defining IB policies
  • The Teams IB modes are Open, where no policies apply, Implicit, the default for teams created after IB is on, and Owner Moderated
  • IB does not cover the team's SharePoint site by default; SharePoint and OneDrive IB is enabled separately and takes about 24 hours to propagate

Exam tip: Teams that existed before you activated information barriers stay in Open mode, so they are not protected until you move them to Implicit.

Microsoft Learn resource: Information Barriers in Microsoft Teams (opens in a new tab)

14

Identify appropriate use cases for Microsoft Purview Communication Compliance and Microsoft Purview Insider Risk Management

These two solutions look similar on a licence sheet and do very different jobs. One reads what people say, the other scores what people do.

Communication Compliance: detects offensive, profane or harassing language, adult or gory images, and sharing of sensitive information across Teams chats and channels, Exchange, Viva Engage and Copilot prompts. It can remove a message from Teams or notify the sender, which makes it the answer for workplace harassment and for regulatory conduct rules.

Insider Risk Management: correlates user behaviour signals for intellectual property theft, data leakage and security violations, using policy templates and feeding Defender XDR and Adaptive Protection. It scores risk and builds cases; it never deletes content.

Both are privacy-by-design, with usernames pseudonymized by default, role-based access for investigators and full audit logs, and both are E5 class rather than E3. Confirming an Insider Risk alert can create a dedicated team for the case and archive it when the case is resolved.

Exam tip: If the scenario is about the content of a message, it is Communication Compliance. If it is about a pattern of behaviour by a person, it is Insider Risk Management.

Microsoft Learn resource: Microsoft Teams and Microsoft Purview Communication Compliance (opens in a new tab)

Plan and implement governance for Teams

15

Identify licensing requirements for lifecycle management of teams

Lifecycle management is where Teams borrows from Microsoft Entra ID, and each control sits at a different licence level. The Teams governance planning page lays them out, and the exam quotes it closely.

What you need to know

Control Licence
Group expiration policy Microsoft Entra ID P1
Group naming policy Microsoft Entra ID P1
Restricting who can create groups Microsoft Entra ID P1
Retention policy Office 365 E3 or above, no Entra licence
Archive and restore a team No extra licence
Access reviews and entitlement management Microsoft Entra ID P2 or Entra ID Governance
  • Expiration and naming policy licences must be possessed for every member of the affected groups, including guests, but do not have to be assigned
  • Custom policy packages need a Teams Premium licence for every user they target
  • Plain group members who cannot create groups need no Entra licence at all

Exam tip: Archiving a team needs no licence, so it is the answer whenever a scenario wants a team taken out of use without any Entra premium licensing.

Microsoft Learn resource: Plan for governance in Teams (opens in a new tab)

16

Identify where Teams stores content

Teams is a front end over Exchange, SharePoint and OneDrive, and knowing which store holds which content is the single most reusable fact in this exam. eDiscovery, retention and troubleshooting questions all depend on it.

What you need to know

Content Where it lives
1:1 and group chat messages A hidden folder in each participant's Exchange Online mailbox
Standard channel messages The team's Exchange Online group mailbox
Files shared in a chat The OneDrive of the person who shared the file
Files uploaded to a channel The team's SharePoint site
Meeting recordings and transcripts The OneDrive of whoever started the recording, or the team's SharePoint site for a channel meeting
Voicemail, calendar and contacts Exchange Online
  • Private and shared channels each get their own SharePoint site collection; standard channels are folders in the team's default document library
  • The system of record is an Azure-powered chat service, and the mailbox copies exist so compliance tooling can reach the data
  • To search or preserve shared channel messages you target the parent team's mailbox

Exam tip: A file shared in a chat is never in SharePoint. It is in the sharer's OneDrive, in a folder called Microsoft Teams Chat Files.

Microsoft Learn resource: Finding content in Microsoft Teams in eDiscovery (opens in a new tab)

17

Plan and manage update policies

Teams update policies control one thing: whether a user sees Public preview features. They do not control which client version rolls out, which is the mistake the exam is hoping you make.

What you need to know

  • Found at Teams admin center > Teams > Teams update policies; Public preview is not enabled by default
  • The setting is Show Teams preview features, with four values: On for users in Current Channel (Preview), which is the default, Users can opt in, Off, and On for everyone
  • With the default or with On for everyone, users cannot turn Public preview off themselves
  • The cmdlet is Set-CsTeamsUpdateManagementPolicy with the -AllowPublicPreview parameter
  • The policy has no effect on users in Microsoft 365 Targeted release, and device policies are not applied in Teams on the web

Exam tip: If the scenario is about client versions rolling out or lagging behind, you want the Teams client update rollout alert rule and the client health dashboard, not an update policy.

Microsoft Learn resource: Microsoft Teams Public preview (opens in a new tab)

18

Create and manage policy packages in Teams

A policy package is a bundle of policies for one kind of person, so you assign one thing instead of six. Microsoft ships packages for education, frontline, healthcare, public safety and small business.

What you need to know

  • Packages predefine policies for messaging, meetings, calling, app setup and live events
  • Each policy a package creates is named after the package, such as Education_Teacher, Frontline_Manager or PublicSafety_Officer
  • Editing a policy inside a package applies immediately to every user already assigned that package
  • Custom policy packages are created in Teams admin center > Policy packages > Add, and every targeted user needs a Teams Premium licence
  • Assignment works per user, per group, or in a batch of up to 5,000 users
  • Get-CsPolicyPackage lists the packages and Grant-CsGroupPolicyPackageAssignment assigns one to a group

Exam tip: Policy packages are not available in GCC High or DoD, and they are not supported through granular delegated admin privileges.

Microsoft Learn resource: Managing policy packages in Teams (opens in a new tab)

19

Plan and configure policy assignment for users and groups

There are four ways to get a policy onto a user, and the precedence between them is one of the most reliably tested facts in the whole exam.

The precedence order:

  1. A direct assignment to the user, individually or in a batch, always wins
  2. Otherwise the group assignment with the highest rank wins, where rank 1 is the highest
  3. Otherwise the user gets the Global (Org-wide default) policy

What you need to know

  • A group assignment reaches direct members only, never members of nested groups
  • A policy type can be assigned to at most 64 groups across all its policy instances
  • Microsoft's recommended maximum is 50,000 users per group, and large groups can take 24 hours or more to propagate
  • Group assignment supports every policy type except app permission, network roaming, emergency call routing, voice applications and Teams upgrade policies
  • Get-CsOnlineUser shows only direct assignments; Get-CsUserPolicyAssignment shows the effective policy and where it came from

Exam tip: For group policy ranks, the lower number wins, which is the opposite of sensitivity label policies where the highest order number wins.

Microsoft Learn resource: Assign policies in Teams, getting started (opens in a new tab)

20

Configure settings for Microsoft 365 group creation

Every team is a Microsoft 365 group, so controlling who can create a team means controlling who can create a group. Microsoft's own advice is to leave it open, which surprises people.

What you need to know

  • All users can create Microsoft 365 groups by default, and Microsoft recommends leaving it that way
  • You can restrict creation to the members of exactly one group, so nest other groups inside it if you need more
  • The directory settings are EnableGroupCreation, which defaults to true, and GroupCreationAllowedGroupId
  • Entra ID P1 or P2 is needed for the admin who configures it and for the members of the allowed group
  • The restriction affects Outlook, SharePoint, Viva Engage, Teams, Planner and Project for the web, and can take 30 minutes or more to take effect
  • Several roles can still create groups regardless, including Teams Administrator, Groups Administrator, SharePoint Administrator and User Administrator

Exam tip: The restriction applies to users, not to service principals, so an app with group creation permissions keeps creating groups even when the setting says no.

Microsoft Learn resource: Manage who can create Microsoft 365 Groups (opens in a new tab)

21

Configure an expiration policy for Microsoft 365 groups

An expiration policy is how you stop unused teams accumulating forever. Activity renews a group automatically, so in practice it only removes the ones nobody touched.

What you need to know

  • Configured at Entra admin center > Groups > Expiration, and you get exactly one expiration policy per tenant
  • Group lifetime is in days and must be 30 days or more; the scope is All, Selected, which supports up to 500 groups, or None
  • Requires Microsoft Entra ID P1 possessed for the members of every affected group
  • Activity renews a group automatically: visiting a Teams channel, or viewing, editing or uploading in SharePoint, or reading in Outlook
  • Owners are emailed at 30 days, 15 days and 1 day before expiry, and the group is deleted one day after the expiration date
  • A deleted group can be restored for 30 days, and that window is not customisable

Exam tip: Archived teams still have the expiration policy applied, so an archived team can be deleted out from under you unless it is excluded or renewed.

Microsoft Learn resource: Configure the expiration policy for Microsoft 365 groups (opens in a new tab)

22

Configure a naming policy for Microsoft 365 groups, including blocked words

A naming policy forces a prefix and suffix onto every group name so teams are self-describing, and it keeps reserved words out of names people choose.

What you need to know

  • The structure is Prefix[GroupName]Suffix, and [GroupName] must appear exactly once
  • Supported attributes are [Department], [Company], [Office], [StateOrProvince], [CountryOrRegion] and [Title]; anything else is treated as a fixed string
  • Blocked words have an upper limit of 5,000 comma-separated phrases, matched case-insensitively and only as exact whole words
  • The policy applies to the group name and alias, at creation and on edit, across Outlook, Teams, SharePoint, Planner and Viva Engage
  • Global Administrator and User Administrator are exempt from the policy
  • The PowerShell values in the Group.Unified setting are PrefixSuffixNamingRequirement and CustomBlockedWordsList

Exam tip: Blocked words are exact matches, so blocking "lass" does not block "Class". And the Microsoft 365 group naming policy does not apply to Exchange distribution groups, which need their own.

Microsoft Learn resource: Enforce a naming policy on Microsoft 365 groups in Microsoft Entra ID (opens in a new tab)

23

Archive, delete, or unarchive one or more teams

Archiving takes a team out of use while keeping every message and file searchable. Deleting is recoverable for 30 days, but Microsoft's advice is to archive first.

What you need to know

  • Teams admin center > Teams > Manage teams > select the team > Archive, with an optional checkbox to make the SharePoint site read-only for members
  • Archiving a team also archives its private channels and their site collections; content stays viewable and searchable and owners can still change membership
  • Unarchiving is the Restore action, and the team is not automatically put back in the user's teams list
  • Deleting a team deletes the channels, sites, files and chats, except where a retention policy holds the content
  • Set-TeamArchivedState -GroupId -Archived:$true -SetSpoSiteReadOnlyForMembers:$true is the cmdlet, and Graph has POST /teams/{id}/archive as an async operation

Exam tip: Teams archive and Microsoft 365 Archive for SharePoint sites are independent features. Archiving the team does not archive the site, and archiving the site does not archive the team.

Microsoft Learn resource: Archive or delete a team in Microsoft Teams (opens in a new tab)

24

Restore or troubleshoot the deletion of a Microsoft 365 group

A deleted team is a soft-deleted Microsoft 365 group, and restoring the group brings the team back with it. The window is fixed and the restore is not instant.

What you need to know

  • Soft-delete retention is 30 days and is not customisable
  • Restoring brings back the group object and members, the mail addresses, the Exchange shared inbox and calendar, the SharePoint site and files, OneNote, Planner, the team, and its standard and private channels with their sites
  • A full restore can take up to 24 hours
  • Restore paths are Microsoft 365 admin center > Groups > Deleted groups, Entra admin center > Groups > Deleted groups, Teams admin center > Teams > View deleted teams, Outlook on the web for an owner, or Restore-MgDirectoryDeletedItem
  • After a restore, wait at least an hour before emailing the group or delivery can fail with 550 5.1.10 RESOLVER.ADR.RecipientNotFound

Exam tip: Distribution groups cannot be soft-restored at all. Only Microsoft 365 groups get the reliable 30-day window, which is another reason the exam favours archive over delete.

Microsoft Learn resource: Restore a deleted Microsoft 365 group in Microsoft Entra ID (opens in a new tab)

25

Identify when to use Microsoft Entra Access reviews for teams and groups

An access review asks a human whether people still need access, on a schedule, and can remove them automatically when nobody answers. For Teams it is the standard answer to guest sprawl.

What you need to know

  • Created at Entra admin center > ID Governance > Access reviews; for Teams you choose either All Microsoft 365 groups with guest users or Select Teams + groups
  • All Microsoft 365 groups with guest users is recurring, guests only, and excludes dynamic and role-assignable groups
  • Selecting several groups creates several separate reviews, one per group
  • Reviewers can be admins, group owners, delegated users, the members themselves, or managers, with a fallback reviewer
  • Guest offboarding uses Auto apply results, "if reviewers do not respond" set to Remove access, and the denied-guest action set to block sign-in then remove from the tenant
  • Licensing is Microsoft Entra ID Governance or Entra Suite, and licences are counted for reviewers and for the users being reviewed

Exam tip: Group owners cannot create their own access reviews until an admin turns that on in ID Governance settings, where the default is No.

Microsoft Learn resource: Create an access review of groups and applications in Microsoft Entra ID (opens in a new tab)

26

Perform operations for Teams by using PowerShell and Microsoft Graph

Anything you can do in the admin center you can script, and bulk work is where the exam expects PowerShell or Graph rather than clicking.

What you need to know

  • Install with Install-Module -Name MicrosoftTeams, then sign in with Connect-MicrosoftTeams; the module needs Windows PowerShell 5.1 or PowerShell 7.2 and later
  • The core team cmdlets are New-Team, Get-Team, Set-Team, Add-TeamUser, Remove-TeamUser, New-TeamChannel and Set-TeamArchivedState
  • The GroupId that Teams cmdlets use is the same value as the Identity returned by Get-UnifiedGroup in Exchange Online PowerShell
  • Teams created by cmdlet, API or client are hidden from Outlook by default, which you clear with Set-UnifiedGroup -HiddenFromExchangeClientsEnabled:$false
  • Graph archive, unarchive and clone are long-running async operations: poll the Location header rather than expecting a finished team
  • End users can run team cmdlets, but only against teams they own or belong to

Exam tip: Get-CsOnlineUser reports only directly assigned policies, so a user who inherits a policy from a group looks unassigned there. Get-CsUserPolicyAssignment is the cmdlet that tells the truth.

Microsoft Learn resource: Manage Teams with Microsoft Teams PowerShell (opens in a new tab)

Configure and manage external collaboration

27

Identify licensing requirements for external collaboration

Guests do not consume a Microsoft 365 licence, which people hear as "guests are free". The billing lives in Microsoft Entra External ID instead.

What you need to know

  • Guest access works with Microsoft 365 Business Standard, Enterprise and Education subscriptions with no extra Microsoft 365 licence for the guest
  • Guests are billed under the Entra External ID monthly active users model, counting unique external users who authenticate in a calendar month
  • MAU billing applies only to users whose type is Guest; external users with type Member, such as multitenant organization members, are not counted
  • External ID needs an Azure subscription linked to the tenant for billing
  • Sensitivity labels on Microsoft 365 groups need at least one active Entra ID P1 in the tenant, and a multitenant organization needs P1 in every tenant

Exam tip: The old "one paid licence covers five guests" ratio is gone from current documentation. The monthly active users model replaced it, so do not answer with 1:5.

Microsoft Learn resource: Microsoft Entra External ID pricing and billing (opens in a new tab)

28

Configure SharePoint Online and OneDrive external sharing settings

Teams files live in SharePoint and OneDrive, so Teams guest access is only as permissive as those settings allow. The relationship between tenant and site is one-directional.

What you need to know

  • SharePoint admin center > Policies > Sharing, with four levels: Anyone, New and existing guests, Existing guests, and Only people in your organization
  • A site's setting must be the same as or more restrictive than the organization setting, and the most restrictive value always wins
  • The OneDrive setting can be more restrictive than SharePoint but never more permissive
  • Limit external sharing by domain accepts up to 5,000 domains, set in the UI or with Set-SPOTenant
  • Other controls include guest access expiry in days, verification code reauthentication, and the default file and folder link type
  • Turning external sharing off removes guest access typically within one hour, and turning it back on restores it

Exam tip: Anyone links cannot be used with files in a Teams shared channel site, which is a good reason to keep shared channels rather than Anyone links in a regulated tenant.

Microsoft Learn resource: Manage sharing settings for SharePoint and OneDrive (opens in a new tab)

29

Configure External access in the Microsoft Teams admin center

External access is federation: your users chat and meet with people in another Microsoft 365 tenant using their own accounts, and nobody is added to your directory.

What you need to know

  • Teams admin center > Users > External access, with an Organization settings tab and a Policies tab; external access is on by default
  • The four domain scenarios are allow all external domains, which is the default, allow only specific domains, block only specific domains, and block all
  • Separate toggles cover communication with unmanaged Teams accounts and whether those users can start the contact
  • The block specific users list holds a maximum of 200 users, and adding someone removes them from existing chats
  • Blocking contoso.com does not block marketing.contoso.com unless you set -BlockAllSubdomains $True
  • The org-level cmdlet is Set-CsTenantFederationConfiguration

Exam tip: Federation is mutual. If the other organization has not allowed your domain, your users cannot chat with theirs, and their people join your meetings as anonymous participants instead.

Microsoft Learn resource: Manage external meetings and chat with people and organizations using Microsoft identities (opens in a new tab)

30

Control External Access by Domain for Specific Users and Groups

Org-wide federation settings apply to everyone. When only part of the organization should reach a partner, you need the external access policy instead.

What you need to know

  • The granular domain lists live in the external access policy on the Policies tab, assigned to users and groups
  • Three things must be true: the org-level setting allows managing external domains, a policy is assigned, and the external org federates back
  • The policy modes are OrganizationDefault, which is the default, AllowAllExternalDomains, AllowSpecificExternalDomains, and BlockSpecificExternalDomains
  • Each policy's domain list is capped at 100 domains
  • The Global (Org-wide default) policy can only be set to OrganizationDefault, so a custom policy is required for a custom list
  • AllowFederatedUsers must be true in the tenant federation configuration or the policy domain controls do nothing

Exam tip: A custom policy's domain list overrides the organization list for the users it is assigned to, so they talk to the policy's domains and nothing else.

Microsoft Learn resource: Manage external meetings and chat, related settings (opens in a new tab)

31

Configure External collaboration settings in Microsoft Entra ID for guest access

Entra ID decides who in your organization may invite guests, what a guest can see in the directory, and which domains are allowed. Teams then decides what a guest can do in Teams.

What you need to know

  • Entra admin center > Entra ID > External Identities > External collaboration settings
  • Guest user access has three levels, and the default is the middle one: limited access to properties and memberships of directory objects
  • Guest invite settings has four levels, and the default is the most inclusive: anyone in the organization including guests and non-admins
  • Collaboration restrictions can allow any domain, which is the default, deny specified domains, or allow only specified domains
  • External user leave settings can only be configured once you have added privacy contact information to the tenant
  • Guest access restriction changes can take up to 15 minutes to take effect

Exam tip: External collaboration settings and cross-tenant access settings are different things, and the most restrictive of the two wins. The first controls invitations and directory visibility; the second controls whether authentication with a named tenant is allowed at all.

Microsoft Learn resource: Configure external collaboration settings for B2B in Microsoft Entra External ID (opens in a new tab)

32

Configure guest access and sharing in the Microsoft Teams admin center, Microsoft 365 admin center, Microsoft Entra admin center, or the SharePoint admin center

Guest access is the one Teams feature that has to be switched on in four places. Every layer has to permit it, which is why "I enabled guest access and it still does not work" is such a common ticket.

The four layers, all of which must allow guests:

  1. Microsoft Entra admin center: external collaboration settings permit the invitation
  2. Microsoft 365 admin center: Settings > Org settings > Microsoft 365 Groups, both "let group owners add people outside your organization" and "let guest group members access group content"
  3. SharePoint admin center: external sharing set to New and existing guests or higher
  4. Teams admin center: Users > Guest access, master toggle on, plus the per-capability toggles

What you need to know

  • Guest screen sharing is not a simple toggle: the values are Not enabled, Single application and Entire screen
  • A guest must be added to at least one team before guest features become available to the account
  • Every guest carries the (Guest) label in Teams
  • Turning guest access off removes guests' access but does not remove them from teams, and they regain access if you turn it back on

Exam tip: Shared channel in Teams and multitenant organization sharing are disabled by default, while team, site and file sharing with guests, external chat and meetings, and anonymous meeting join are enabled by default.

Microsoft Learn resource: Turn guest access in Microsoft Teams on or off (opens in a new tab)

33

Control guest access to a specific team by using Microsoft Purview and Microsoft Entra ID

Teams guest access is organization-wide, so there is no per-team toggle. A Purview sensitivity label scoped to groups and sites is the only supported way to do it per team.

What you need to know

  • A container label can set Privacy to Public, Private or None, control external users access, control external sharing from the labeled SharePoint site, apply Conditional Access, and control Teams shared channels
  • The shared channel label options are Internal only, Same label only and Private team only, and only Private team only can remove teams that were already invited
  • Enabling container labels is a one-time two-step job: set EnableMIPLabels to true on the Group.Unified setting, then run Execute-AzureAdLabelSync
  • After the sync it can take up to 24 hours for the label to appear in Microsoft Entra ID
  • Applying the label to a team applies it to the backing Microsoft 365 group and the connected SharePoint site, and a Privacy of Public or Private locks that value

Exam tip: A container label protects the container, not the items in it. The files inside an externally blocked site are not themselves encrypted or labelled.

Microsoft Learn resource: Use sensitivity labels to protect collaborative workspaces (opens in a new tab)

34

Remove guests from Teams, including from a team or a tenant

Removing a guest from a team and removing them from the tenant are two different operations, and only one of them actually revokes access.

What you need to know

  • Removing a guest from a team, or the guest leaving it, does not delete the guest account from the directory
  • Tenant removal is Microsoft 365 admin center > Users > Guest users > select > Delete a user, or Entra admin center > Users > Delete user
  • Every guest added through Teams, SharePoint or Entra External ID appears in the single Guest users list in the Microsoft 365 admin center
  • PowerShell uses the #EXT# form of the UPN, as in Remove-MgUser -UserId "user@contoso.com#EXT#@tenant.onmicrosoft.com"
  • Guests can remove themselves only if external user leave settings is set to Yes, which needs tenant privacy information configured

Exam tip: Deleting the guest account from the tenant is the only action that revokes access everywhere. Turning off guest access or removing them from one team leaves the account and its other access intact.

Microsoft Learn resource: Manage guest access in Microsoft 365 groups (opens in a new tab)

35

Configure shared channels for external access

A shared channel lets someone from another tenant work inside your channel using their own account, with no guest object in your directory. It is the newest of the collaboration models and the one with the most prerequisites.

What you need to know

  • Shared channels are on by default, but external collaboration in shared channels is off by default
  • Guests cannot be added to a shared channel. External people join through Entra B2B direct connect with their own work account, and there is no tenant switching
  • Even though no guest account is created, Teams guest access must be enabled and the Microsoft 365 Groups guest settings must both be checked, or invitations fail
  • Teams admin center > Teams > Teams policies carries the four settings: create private channels, create shared channels, invite external users to shared channels, and join external shared channels
  • The cmdlet parameters are -AllowSharedChannelCreation, -AllowChannelSharingToExternalUser and -AllowUserToParticipateInExternalSharedChannel
  • A shared channel is permanently bound to its parent team and cannot be moved or converted

Exam tip: The Teams policy alone is never enough. Cross-tenant access settings have to be configured by both organizations before a shared channel invitation works.

Microsoft Learn resource: Shared channels in Microsoft Teams (opens in a new tab)

36

Configure and manage B2B direct connect cross-tenant access settings in Microsoft Entra ID for shared channels

B2B direct connect is the Entra half of shared channels. Its defaults are the opposite of B2B collaboration, which is why shared channels do nothing until somebody configures this.

What you need to know

  • Entra admin center > Entra ID > External Identities > Cross-tenant access settings, with Default settings and Organizational settings tabs
  • B2B direct connect is blocked inbound and outbound by default, unlike B2B collaboration which is allowed both ways
  • It requires mutual configuration: your inbound must allow the partner and their outbound must allow you
  • Organizational settings take precedence over default settings, and you add a partner by tenant ID
  • The four control types are inbound access, outbound access, tenant restrictions, and trust settings, which let you trust MFA and device claims from the partner
  • B2B direct connect users are not objects in your directory; they authenticate at home and are visible only in Teams shared channels

Exam tip: Enabling B2B direct connect outbound shares limited contact data about your users with the partner organization, so they can find and invite them.

Microsoft Learn resource: Set up B2B direct connect with an external organization (opens in a new tab)

37

Configure a multitenant organization (MTO)

A multitenant organization is for companies that own several tenants, usually after a merger. It syncs people between them as members rather than guests, so Teams treats them as colleagues.

What you need to know

  • Microsoft 365 admin center > Settings > Org settings > Organization profile > Multitenant collaboration
  • Maximum 100 active tenants including the owner; going beyond that needs a support request
  • The owner invites by tenant ID and a Global Administrator in each member tenant accepts; joining can take up to 4 hours
  • Users are provisioned into the other tenants as B2B collaboration users with type Member, not Guest, and Teams requires member type in an MTO
  • Creating the MTO auto-creates a cross-tenant sync configuration named MTO_Sync_ followed by the tenant ID, with jobs pre-configured but not started, and synced users take up to 24 hours to appear in Teams and up to 7 days to become searchable
  • Microsoft Entra ID P1 or above is required in every MTO tenant, and Microsoft Teams Rooms is not supported in an MTO

Exam tip: An MTO does not switch shared channels on for you. You still enable shared channels in Teams and configure B2B direct connect in Entra ID, exactly as with any other external organization.

Microsoft Learn resource: Plan for multitenant organizations in Microsoft 365 (opens in a new tab)

Manage Teams clients and devices

38

Identify licensing requirements for Teams Phone accounts and resource accounts

Auto attendants and call queues sign in as resource accounts, and those accounts take a free licence that is easy to get wrong. The word "resource account" also means two different things in Teams, which the exam enjoys.

What you need to know

  • Auto attendants and call queues need at least one Teams Phone licence in the tenant plus a free Microsoft Teams Phone Resource Account licence on each resource account
  • The resource account licence is required whether or not a phone number is assigned, and you still complete the purchase flow even though it costs nothing
  • Never assign Teams Phone Standard to a resource account, and never assign the resource account licence to a real user
  • Nested auto attendants and call queues that receive an already-answered call need no resource account and no licence
  • Outbound PSTN from a call queue or auto attendant needs Communications Credits, a voice routing policy, or an Operator Connect number on the resource account
  • Resource accounts are disabled for sign-in and must stay that way

Exam tip: A Teams voice resource account has no mailbox and never signs in. A Microsoft 365 device resource account for a Teams Room is an Exchange room mailbox that does sign in. Same phrase, opposite behaviour.

Microsoft Learn resource: Voice applications prerequisites and licensing (opens in a new tab)

39

Identify licensing requirements for Teams devices

Shared devices are licensed by the device, not the person, and the two families do not overlap. Putting the wrong one on a room system simply does not work.

What you need to know

  • Every meeting room device, console, Surface Hub or panel needs a Teams Rooms Basic or Teams Rooms Pro licence on its resource account
  • Microsoft Teams Shared Space, formerly Teams Shared Devices, licenses common area phones, panels in BYOD rooms and desk docks, and includes Teams Phone, Intune P1 and Exchange Online Plan 2 for cloud voicemail only
  • A Teams panel needs Teams Rooms Pro, shared with the room's system on one account, or a shared device licence where there is no room system; Teams Rooms Basic cannot licence a panel
  • Shared Space licences are not supported on Teams Rooms devices
  • Per-user Microsoft 365 suite licences are not authorized on shared meeting devices

Exam tip: One licence enables one device. A room with a Teams Rooms system and a panel can share one account and one Pro licence, but a second room system in the same room needs Pro rather than Basic.

Microsoft Learn resource: Microsoft Teams add-on licenses (opens in a new tab)

40

Manage configuration profiles for Teams devices

A configuration profile is how you push settings to devices without touching them. Profiles are per device type and cannot be shared across types.

What you need to know

  • Teams admin center > Teams Devices > device type > Configuration profiles > Add
  • With partial application, every setting starts as Not configured and anything left that way is not pushed, so the device keeps its current value
  • Saving forces a Review configured settings dialog comparing current and new values
  • A custom wallpaper in a profile must be under 500 KB
  • Assignment shows in the device History tab with the action Config Update and the profile name
  • You need one profile per unique combination of settings, so a naming convention that describes the settings pays off quickly

Exam tip: Where an OEM does not yet support partial application, all settings are pushed including the unconfigured ones with their defaults, which silently resets things you did not mean to change.

Microsoft Learn resource: Manage devices in Teams (opens in a new tab)

41

Configure accounts and systems for Microsoft Teams Rooms

A Teams Room signs in as a room mailbox with an enabled account, and the calendar processing settings decide whether the join button appears and whether the meeting subject survives.

What you need to know

  • Each Teams Rooms device needs its own Microsoft 365 resource account, and a paired Teams panel signs in with the same account
  • Create it with New-Mailbox -Room -EnableRoomMailboxAccount $true, or convert an existing room mailbox with Set-Mailbox
  • Recommended calendar processing is AutomateProcessing AutoAccept, DeleteComments $false so third-party join buttons survive, DeleteSubject $false and ProcessExternalMeetingMessages $true
  • The account's UPN must match its SMTP address, and the default time zone is Pacific Standard Time, which has to be changed
  • Microsoft recommends cloud-only resource accounts, a password set never to expire, and a naming convention such as an mtr- prefix
  • Do not assign OneDrive for Business to a room account, or recordings and transcripts land on the room's OneDrive

Exam tip: Room accounts cannot have MFA enforced. Exclude them from Conditional Access policies that require it and give them a dedicated policy instead.

Microsoft Learn resource: Create and configure resource accounts for Teams Rooms and panels (opens in a new tab)

42

Manage device settings and firmware

Firmware updates can be manual or automatic, and the automatic path runs in phases with a maintenance window. The phase names and windows are exam material.

What you need to know

  • The Teams admin center updates the Teams app and device firmware both manually and automatically, and the Company Portal and Admin agent apps manually only
  • The three automatic phases are Validation 0 to 15 days, General 16 to 45 days, which is the default for newly onboarded devices, and Final 46 to 60 days, counted from the release date
  • Pause auto-updates suspends Android device updates for 15 days, then they resume automatically
  • The maintenance window is set in a configuration profile and defaults to 01:00 to 04:00 device local time on Sunday, with a minimum length of 3 hours
  • Versions are labelled Verified by Microsoft, Microsoft Preview or Unknown version, and an unknown version cannot be auto-updated
  • Devices several versions behind are updated step-wise, one version at a time

Exam tip: Automatic updates from the Teams admin center and maintenance window configuration are not available in GCC High and DoD. Manual updates still work there.

Microsoft Learn resource: Remotely update firmware and software on Teams phones (opens in a new tab)

43

Manage Teams device tags

Tags are how you group devices so you can update or configure a subset of them. The surprise is what the tag is actually attached to.

What you need to know

  • Teams admin center > Teams Devices > any device pane > Actions > All device tags to create, rename or delete, and Manage tags on selected devices to apply
  • A tag can be up to 25 characters
  • Tags are assigned to the resource account signed in to the device, so signing that account in to a different device carries the tags across
  • You cannot delete a tag that is still applied; remove it everywhere first or accept the Untag devices prompt
  • Filtering supports match all and match any, so you can target a staged update or a different configuration profile at the filtered set

Exam tip: A tag can span device types, but searching for a tag inside a device pane only returns that pane's device type, so a tag search under Phones will never show a Teams Room.

Microsoft Learn resource: Manage Microsoft Teams device tags (opens in a new tab)

44

Provision and configure remote sign-in for new devices

Remote provisioning means the person unboxing the phone never needs the account password. You upload the MAC address, generate a code, and sign the account in from the admin center.

What you need to know

  • Upload the device's MAC address manually or from a file template, generate a verification code, have a technician enter it on the device, then sign a user in remotely
  • The verification code is valid for 24 hours and is invalidated if you edit the MAC address or hardware ID
  • Teams admin center > Teams Devices > Phones > Actions > Provision devices, moving through Waiting on activation and then Waiting for sign in
  • Remote provisioning is unavailable once a device has been signed in, so the device has to be factory reset to use it again
  • Remote sign-in needs a device account in Microsoft Entra ID, and bulk remote sign-in is not supported
  • Users can also self-serve at microsoft.com/devicelogin with a code

Exam tip: Devices bought from the Teams device store get their MAC address added automatically when they ship, but only in the United States and Canada.

Microsoft Learn resource: Remote provisioning and sign in for Teams phones (opens in a new tab)

45

Plan and configure Teams for VDI

In a virtual desktop, Teams without media optimization renders audio and video on the server, which is exactly as bad as it sounds. The optimization component moves the media to the endpoint.

What you need to know

  • Media optimization is certified with Azure Virtual Desktop, Windows 365, Citrix, Omnissa Horizon and Amazon WorkSpaces
  • Two optimization stacks exist: the newer SlimCore engine for new Teams, and the legacy WebRTC Redirector Service
  • On Azure Virtual Desktop and Windows 365 you set IsWVDEnvironment to 1 under HKLM\SOFTWARE\Microsoft\Teams for the client to be optimized
  • For pooled host pools, install Teams per-machine, and per-machine Teams on VDI does not auto-update, so you update the image
  • CsTeamsVdiPolicy is the control for the new stack, with VDI2Optimization enabled by default
  • Teams for web is not supported in VDI, and WebRTC optimization does not support QoS, 1080p, custom backgrounds or Teams Premium features

Exam tip: The client tells you which stack it is on. Hover the Optimized banner to see whether it is WebRTC or SlimCore, and an unoptimized user gets a warning icon with an error code.

Microsoft Learn resource: Install Teams for Virtualized Desktop Infrastructure (opens in a new tab)

Domain 2 Manage Teams, Channels, Chats, and Apps 20-25% of the exam 0 / 23 studied

This domain is the collaboration surface itself: creating teams at scale and from templates, choosing the right channel type for the job, managing who can post and who can delete, and governing which apps reach which users. Limits and defaults matter here more than anywhere else in the exam, and app management has changed enough recently that memorising the old model will cost you marks.

Create and manage teams

46

Plan for a Teams rollout by using Advisor for Teams

Advisor for Teams turns a rollout into a project plan. It creates a deployment team with a channel per workload, each with its own Planner plan and a user survey.

What you need to know

  • Found at Teams admin center > Planning > Teams Advisor
  • The minimum licence is Microsoft 365 Business Basic, and Teams, Forms and Planner licences are all needed because it uses Forms and Planner
  • The first run creates a Deployment team with one channel per selected workload, each carrying a Planner plan and a Forms survey
  • Non-admins can open Advisor, but only Teams Administrator or Global Administrator can open the tenant readiness assessments
  • It is not available in GCC High or DoD, and in GCC the surveys are created but not pinned as tabs
  • If Teams Advisor is missing under Planning, the signed-in user has no Teams licence

Exam tip: Only one person can create the deployment team. A second attempt by someone else fails by design, which is the expected behaviour rather than a fault.

Microsoft Learn resource: Use Advisor for Teams to help you roll out Microsoft Teams (opens in a new tab)

47

Create a team by using the Microsoft Teams admin center, Teams client, the Teams PowerShell module, or Microsoft Graph

Four ways to make the same object. The differences worth knowing are what each one names, what it hides, and how long it takes to appear.

What you need to know

  • New-Team -DisplayName is the only mandatory parameter, and it returns a group object with a GroupId
  • Useful New-Team parameters are -Visibility, -Template, -Owner, -MailNickName and -AllowCreatePrivateChannels
  • In Graph, create the Microsoft 365 group first, then POST to /teams with a template binding; the team gets the same ID as the group and the call returns 202 Accepted
  • Group to team conversion in Graph can take up to 15 minutes
  • Teams created by cmdlet, API or client are hidden from Outlook by default
  • In the admin center it is Teams > Manage teams > Add

Exam tip: Microsoft recommends at least two real user owners rather than a service account, and a one-second delay between member additions when you script a large team.

Microsoft Learn resource: Create teams and manage members using the Microsoft Teams API (opens in a new tab)

48

Create a team from an existing Microsoft 365 group, SharePoint site, or team

Teamifying an existing group keeps the group's site, members and permissions. Importing a group's members into a team is a different operation with different limits, and the exam knows it.

What you need to know

  • A Microsoft 365 group that is converted to a team can have up to 10,000 members, and membership stays in sync afterwards
  • A distribution list, security group or Microsoft 365 group imported into a team is capped at 3,500 and is a one-time copy
  • A team created from an existing group inherits its permissions and connects to that group's existing SharePoint site
  • Adding Teams to an existing SharePoint site connects that site rather than creating a new one
  • Graph team: clone copies apps, channel structure, members, settings and tabs, but not messages, and is not supported for org-wide teams

Exam tip: Convert versus import is the trap. Convert gives live sync and a 10,000 cap; import gives a snapshot and a 3,500 cap.

Microsoft Learn resource: Overview of Teams and SharePoint integration (opens in a new tab)

49

Create a team from a template

A template gives a new team its channels, tabs and apps so people do not start from an empty General channel. Microsoft ships general and industry templates, and you can add your own.

What you need to know

  • Template IDs are literal strings such as com.microsoft.teams.template.ManageAProject, ManageAnEvent, OnboardEmployees and OrganizeHelpDesk
  • Industry templates cover healthcare, financial services, manufacturing, retail, nonprofit and government
  • Template size limits are 15 channels, 20 tabs per channel and 50 apps per template
  • In Graph you create the team with a template@odata.bind pointing at the template
  • The limits apply to the template, not to the finished team, so people can add more channels afterwards

Exam tip: A template can create channels and pin tabs, but it cannot bring messages or files with it. For that you want team cloning or a team created from an existing group.

Microsoft Learn resource: Get started with team templates in the Teams admin center (opens in a new tab)

50

Create and manage templates and template policies for teams

A custom template is built in the admin center, and a templates policy decides who sees which templates. The split between the two is the thing to get right.

What you need to know

  • Teams admin center > Teams > Team templates > Add, choosing a brand new template, an existing team, or an existing template as the starting point
  • A new or changed custom template can take up to 24 hours to appear in the users' gallery
  • A templates policy hides templates, up to a maximum of 100 hidden templates per policy
  • New templates are visible by default and are not automatically hidden by existing policies
  • Templates policies cannot be created or managed in PowerShell, although you can assign them with New-CsBatchPolicyAssignmentOperation
  • The template cmdlets that do work are Get-CsTeamTemplate, New-CsTeamTemplate, Update-CsTeamTemplate and Remove-CsTeamTemplate

Exam tip: Templates policies cannot be assigned by group membership. Only individual and batch assignment is supported, which is unusual among Teams policies.

Microsoft Learn resource: Manage team templates in the admin center (opens in a new tab)

51

Manage the membership and roles for a team

Teams has only two roles, and everything else is a capability layered on top. Knowing what an owner can do that a member cannot is a steady source of exam questions.

What you need to know

  • The only roles are owner and member; guest is a user type, and moderator is a per-channel capability
  • A team can have up to 100 owners, and the creator becomes an owner automatically
  • Adding someone as an owner also adds them as a member, except when the team is created in the admin center or added to an existing group
  • Owners can add members to a private team, delete the team and promote or demote users; members can add members to a public team
  • Creating a shared channel is owner only, while standard and private channel creation can be delegated to members
  • If the last private channel owner leaves, a member is auto-promoted

Exam tip: Restricting who can create teams is done through Microsoft 365 group creation control, not through any Teams policy. By default every user with an Exchange Online mailbox can create a team.

Microsoft Learn resource: Assign team owners and members in Microsoft Teams admin center (opens in a new tab)

52

Manage a team in the Microsoft Teams admin center

Manage teams is the admin's view of every team in the tenant, and it can do things the client cannot, such as adding an owner to a team nobody owns any more.

What you need to know

  • Teams admin center > Teams > Manage teams; needs Global Administrator, Teams Administrator or Teams Reader
  • The grid shows separate counts for standard, private and shared channels, plus members, owners, guests, privacy, status, sensitivity, GroupID and expiration date
  • The Sensitivity column is labelled Classification when sensitivity labels are not set up
  • Actions include Add, Edit, Archive, View deleted teams with Restore, and Renew for an expiring team
  • On the team profile you can add or remove members, owners and channels, but you cannot remove the General channel or change standard channel membership
  • Editable properties are team name, description, privacy, sensitivity, member permissions, guest permissions and fun settings

Exam tip: Changes to the underlying Microsoft 365 group go to the audit log, while Teams-specific setting changes are posted into the team's General channel.

Microsoft Learn resource: Manage teams in the Microsoft Teams admin center (opens in a new tab)

53

Manage Teams environment settings

Teams settings are org-wide and have exactly one instance, which is what separates them from policies. They cover email into channels, cloud storage providers, tagging and the organization tab.

What you need to know

  • Teams admin center > Teams > Teams settings
  • Users can send emails to a channel email address is on by default, and you can restrict the source SMTP domains
  • The cloud storage providers Citrix Files, Dropbox, Box, Google Drive and Egnyte are all on by default and can be switched off individually
  • Tag limits are 200 tags per team, 25 tags per user per team and 200 team members per tag
  • Show organization tab for users is on by default and shows the Entra ID org hierarchy in personal chat

Exam tip: Teams settings cannot be scoped to a subset of users. If a scenario needs a different value for one department, you need a policy, not a setting.

Microsoft Learn resource: Teams settings and policies reference (opens in a new tab)

54

Configure privacy and sensitivity settings for a team

Privacy decides who can join, and a sensitivity label can set and lock that decision. Org-wide teams have their own rules, and the numbers collide in a way the exam likes.

What you need to know

  • The three privacy values are Private, Public and Org-wide
  • An org-wide team caps at 10,000 users, a tenant can have at most 5 of them, and only a Global Administrator can create one
  • Tenants new to Teams with no more than 5,000 users get an org-wide team created automatically
  • Org-wide teams exclude blocked accounts, guests, resource and service accounts, and room accounts, and members cannot leave
  • The hard per-team member limit is 25,000
  • A container label's Privacy option is Public, Private or None, where None lets the user choose and the other two lock the value

Exam tip: Three numbers live close together here: 25,000 members per team, 10,000 in an org-wide team, and 5,000 users as the threshold for automatic org-wide team creation.

Microsoft Learn resource: Use organization-wide teams in Microsoft Teams (opens in a new tab)

55

Create and manage frontline teams and experiences

Frontline workers get a different Teams by default: Shifts, Walkie Talkie and Approvals pinned for them, without an admin doing anything, as long as they hold an F licence.

What you need to know

  • Licensing is Microsoft 365 F1 and F3, and the tailored frontline app experience is on by default for F licence holders
  • E licence users do not get tailored pinning, so you need an app setup policy, and if you pin more than 10 apps Walkie Talkie must be in the first 10
  • Walkie Talkie deployment is three steps: allow it in Manage apps, allow it in an app permission policy, then pin it
  • Shifts needs only a Teams licence, does not support guests, and is available in GCC but not GCC High or DoD
  • Frontline teams deploy at scale as dynamic teams from the Teams admin center, with membership managed automatically, or as static teams from PowerShell, which are not
  • A frontline operational hierarchy is uploaded as a CSV

Exam tip: Dynamic frontline teams keep their membership current on their own; static ones do not. If the scenario complains that new hires never appear in the store team, the team is static.

Microsoft Learn resource: Tailor Teams apps for your frontline workers (opens in a new tab)

Manage channels and chats

56

Recommend channel types, including standard, private, and shared

Three channel types, and the single fact that separates them is storage. Get that straight and the rest of the comparison falls out of it.

What you need to know

Standard Private Shared
Own SharePoint site No, a folder in the team's library Yes Yes
Visible to the whole team Yes Members only Members only
Guests can participate Yes Yes No
External people Through guest access Through guest access B2B direct connect, own account
Can be shared with other teams No No Yes
  • Only a shared channel can add people without adding them to the team
  • Moderation, Planner, bots, connectors and messaging extensions are standard channels only
  • Neither private nor shared channels can be converted to or from standard, and neither can be moved to another team
  • Class teams support standard and private channels but not shared channels

Exam tip: If the question asks which channel type does not get its own SharePoint site, the answer is standard. Everything else about the three types follows from that one design decision.

Microsoft Learn resource: Overview of teams and channels in Microsoft Teams (opens in a new tab)

57

Add, edit, and remove channels

The channel limits changed, so answer from the current numbers rather than from memory of the old private channel cap.

What you need to know

  • A team supports 1,000 channels in any combination of standard, private and shared
  • That count includes deleted channels for their 30-day restore window, after which the slot is freed
  • A channel display name can be up to 50 characters
  • In Graph, creating a standard or private channel returns 201 Created, while a shared channel returns 202 Accepted with an async operation to poll
  • Private and shared channels require explicit members at creation, and a private channel must include at least one owner
  • A shared channel can be shared with up to 50 teams and hold 5,000 direct members, where each shared team counts as one

Exam tip: Private channels are no longer capped at 30 per team. The current limit is the same 1,000 that covers every channel type together.

Microsoft Learn resource: Limits and specifications for Microsoft Teams (opens in a new tab)

58

Manage channel settings

Channel settings decide who can post, who can reply and who can create more channels. Moderation is the one people reach for, and it has real limits.

What you need to know

  • Member permissions live at Teams admin center > Teams > Manage teams > team > Settings > Member permissions, where you can switch off channel create, update, delete and restore
  • Moderation is off by default and works on standard channels only, not on General and not on private channels
  • The Graph moderation values are userNewMessageRestriction of everyone, everyoneExceptGuests or moderators, and replyRestriction of everyone or authorAndModerators
  • Team owners are moderators by default, and moderators can add other moderators in that channel
  • A private or shared channel inherits the parent team's settings at creation and is independent afterwards
  • A channel site's permissions are read-only in SharePoint, and the description is edited from the channel settings in Teams

Exam tip: There is no moderation answer for a private channel or for General. If a question wants posting restricted in either, the honest answer is that moderation does not apply there.

Microsoft Learn resource: Manage large teams in Microsoft Teams, best practices (opens in a new tab)

59

Create and manage Teams policies for channel creation and sharing

The policy object called Teams policies carries exactly four channel settings, and two of them are about the outside world.

What you need to know

  • Teams admin center > Teams > Teams policies, with Create private channels, Create shared channels, Invite external users to shared channels and Join external shared channels
  • Create private channels applies to owners and members; Create shared channels is described as team owners
  • Policy changes can take up to 24 hours to take effect
  • The cmdlet is Set-CsTeamsChannelsPolicy, with -AllowPrivateChannelCreation, -AllowSharedChannelCreation, -AllowChannelSharingToExternalUser and -AllowUserToParticipateInExternalSharedChannel
  • Shared channels are enabled by default, but external collaboration in shared channels is disabled by default and also needs cross-tenant access settings on both sides

Exam tip: The portal calls it Teams policies, the documentation page calls it channel policies, and the cmdlet noun is CsTeamsChannelsPolicy. They are all the same object.

Microsoft Learn resource: Manage channel policies in Microsoft Teams (opens in a new tab)

60

Manage private and shared channel membership

Private channel membership is a subset of the team. Shared channel membership is not, and that difference drives most of the rules.

What you need to know

  • Only the private channel owner can add or remove people, and candidates must already be members of the parent team
  • New private channel members can see all prior conversations in that channel
  • Leaving or being removed from the team removes the user from every private channel in it, and rejoining the team does not restore that membership
  • Guests can never be added to a shared channel, including guests whose type was converted to member
  • In the admin center, search an external participant as ext:user@domain.com to get their organization account rather than a guest account
  • A team owner who is not a private channel member cannot see the channel in their list but can still delete it

Exam tip: Private channel sites use the site templates TEAMCHANNEL#0 and TEAMCHANNEL#1 and are created in the same region as the parent team's site. Deleting one outside Teams gets restored by a background job within about four hours.

Microsoft Learn resource: Private channels in Microsoft Teams (opens in a new tab)

61

Create and manage messaging policies

Messaging policies control what people can do with messages: edit, delete, react, use Giphy, and see read receipts. The delete settings are the pair the exam reuses.

What you need to know

  • Owners can delete sent messages is off by default and covers messages sent by other people
  • Delete sent messages is on by default and covers a user deleting their own message
  • Read receipts default to user controlled, work only in chats of 20 people or fewer, and are not captured in eDiscovery
  • Giphy in conversations is on by default with a content rating of Moderate
  • Priority notifications repeat every 2 minutes for 20 minutes or until the message is read
  • The cmdlets are Set-CsTeamsMessagingPolicy and Grant-CsTeamsMessagingPolicy

Exam tip: Read receipts only really work when every messaging policy in the tenant uses the same value, because a user whose policy differs will not send them.

Microsoft Learn resource: Manage messaging policies in Teams (opens in a new tab)

Manage apps for Teams

62

Manage Org-wide app settings in the Microsoft Teams admin center

Org-wide app settings are the outermost ring of app governance. They set the default for everyone, and blocking here blocks for all.

What you need to know

  • Teams apps > Manage apps > Actions > Org-wide app settings, and changes take a few hours
  • The sections are Tailored apps, Microsoft apps, Third-party apps and Custom apps
  • The custom app controls are "let users interact with custom apps in preview" and "let users install and use available apps by default"
  • In a brand new tenant all apps are allowed by default, Microsoft, third-party and your own
  • In GCC, GCC High and DoD, all third-party agents and apps are blocked by default
  • Built-in Teams agents moved out of the Microsoft apps setting onto their own page

Exam tip: To allow an app, every layer has to agree. To block it, any single layer is enough.

Microsoft Learn resource: Overview of agent and app management and governance in Teams admin center (opens in a new tab)

63

Create and manage app assignments and app setup policies

An app setup policy decides which apps are installed and pinned, and in what order. It is the answer whenever a scenario wants an app to appear on someone's app bar.

What you need to know

  • The two built-in policies are Global (Org-wide default) and FirstlineWorker, which cannot be customised
  • Default pinned apps are Activity, Chat, Teams, Calendar, Calling and Files; user pinning is on and upload custom apps is off
  • Admin pins always take precedence, and with user pinning on the user's pins appear below the admin's
  • Users cannot uninstall an app an admin installed, but can unpin it if user pinning is allowed
  • The in-meeting bar shows only two apps, and everything else goes under More
  • The mobile client needs at least two pinned apps or it ignores the policy

Exam tip: Setup policy and permission policy are different jobs. Setup decides what is installed and pinned; permission decides whether the user may use the app at all. A pinned app the user is not allowed to use is just a dead icon.

Microsoft Learn resource: Use setup policies to manage, install and pin agents and apps for users (opens in a new tab)

65

Recommend appropriate extensibility options, including apps, tabs, meetings, messaging extensions, and workflows

Teams extensibility is a small set of building blocks, and the exam asks you to pick the right one for a described need rather than to build anything.

What you need to know

  • Tabs are Teams-aware web pages pinned at the top of a channel or chat, or used as a personal app
  • Messaging extensions are search or action commands in the compose box, the command box, or on a message itself, so you can act on a post without leaving it
  • Bots can be conversational or notification-only, and a bot only receives channel messages where it is explicitly mentioned
  • Meeting extensions add tabs and bot capability to the meeting surface and can react to meeting lifecycle events
  • Workflows built in Power Automate are owned by a user, not by the team, so they become orphan flows when that person leaves
  • Consent for an app's capabilities is implied when the app is installed, so admins govern apps rather than capabilities

Exam tip: Shared channels support tabs but not bots, connectors or messaging extensions, so most of this list is unavailable there.

Microsoft Learn resource: Understand Microsoft Teams apps and their capabilities (opens in a new tab)

66

Manage purchasing of apps in the Teams app store

Some Teams apps are paid SaaS offers, and an admin can buy licences and assign them, or stop people buying at all.

What you need to know

  • Paid apps are bought from AppSource or from Teams admin center > Teams apps > Manage apps, where the Licenses column shows Purchase, Purchased, or nothing
  • Payment is by card or invoice billing, which needs a 24 to 48 hour credit review and both Teams Administrator and Billing Administrator
  • Global Administrators can manage subscriptions bought by anyone in the organization; Teams Administrators can manage only their own
  • Licences can be assigned to individual users or to a team, where the member count must be smaller than the number of licences
  • Disabling purchases uses the MSCommerce PowerShell module and the AllowSelfServicePurchase parameter, and applies to all users

Exam tip: Enabling app purchasing also enables in-app purchasing. The only way to stop in-app purchase offers for a given app is to block that app.

Microsoft Learn resource: Purchase third-party Microsoft Teams apps and manage subscriptions and licenses (opens in a new tab)

67

Customize the appearance of the Teams app store

You can brand your organization's corner of the Teams store, and separately rebrand an individual app. Two features, two pages, and the exam does mix them up.

What you need to know

  • Teams admin center > Teams apps > Customize store, which renders under Apps > Built for your org in the client
  • The logo is 240 by 60 pixels, the background image is 1212 by 100 pixels, both under 5 MB, in .svg, .png or .jpg
  • You can also set a logomark, a custom text colour, and either a custom colour or the Teams default theme
  • App customization is a different feature that rebrands one app's name, icon and colour, with up to 10 customizations per app, each assigned to exactly one app setup policy
  • Only store apps whose developer allowed it can be customized; custom apps published inside an org cannot be, and external users always see the original app

Exam tip: Customize store changes your storefront. App customization changes one app. If the scenario names an app, it is the second one.

Microsoft Learn resource: Customize your organization's app store in Microsoft Teams (opens in a new tab)

68

Upload an app to Teams

Uploading a custom app, still widely called sideloading, is controlled in three places at once, and the combination decides who can actually do it.

What you need to know

  • An app package is a .zip holding manifest.json plus a colour icon and an outline icon at the root
  • The user-facing control is Upload custom apps in an app setup policy, and it is off by default
  • Three controls stack: the org-wide custom app setting, the app setup policy setting, and the per-team allow members to upload custom apps
  • With the team setting off and the policy on, only team owners can upload; with the team setting on and the policy off, nobody can
  • An admin can upload at Teams apps > Manage apps > Actions > Upload new app, which needs no approval and is org-wide after a few hours
  • Any user can always submit a custom app for admin approval, and that cannot be switched off

Exam tip: When you upload a new version of an app, the policies from the previous version stay in effect, so you do not have to reassign anything.

Microsoft Learn resource: Manage custom apps in Microsoft Teams admin center (opens in a new tab)

Domain 3 Manage Meetings and Calling 15-20% of the exam 0 / 14 studied

This domain splits cleanly in two. The first half is meetings and events: which event type fits a business need, and which policy, template or label enforces a setting. The second half is Teams Phone: numbers, resource accounts, auto attendants, call queues and the policies around them. Event capacities and licensing moved recently, so be careful with any figure you learned more than a year ago.

Manage meetings and events

69

Recommend meeting types based on business requirements, including Appointments with Microsoft Teams, webinars, Teams town halls, and meetings

Four formats, and the choice comes down to how many people, how much they interact, and whether anyone has to register.

What you need to know

Format Use it when Capacity
Meeting Everyone takes part and nobody registers 1,000 interactive on Enterprise plans, 300 on Business plans, plus 10,000 view-only on Enterprise
Webinar You need registration, a lobby and attendee mic and camera Up to 1,000 attendees
Town hall A broadcast to a large audience, engagement through Q&A 3,000 engaged and 10,000 view-only on Teams Enterprise, up to 100,000 with an Attendee Capacity Pack
Appointment A scheduled one-to-one with an external person, delivered through Microsoft Bookings One appointment at a time
  • Meetings and events both cap at a 30-hour duration, and a single recording stops and restarts at 4 hours or 1.5 GB
  • Registration, attendee mic and camera, and a lobby exist only up to 1,000 attendees, which is why a town hall has none of them
  • External attendees can join a Bookings appointment from a browser without installing Teams
  • Microsoft recommends Teams Events Services for anything above 20,000 attendees

Exam tip: The 1,000 versus 300 interactive figure is a licensing difference, Enterprise versus Business, not a feature difference.

Microsoft Learn resource: Meetings and events feature and capacity comparison (opens in a new tab)

70

Configure meeting settings, including for Microsoft 365 Copilot

Meeting settings are org-wide, meeting policies are per user or per organizer, and Copilot sits in the policy rather than the settings page. The Copilot values are worth learning exactly, because they change what an organizer is allowed to choose.

What you need to know

  • Meetings > Meeting settings covers participants, cross-cloud meetings, email invitation branding and transcript API access
  • Email invitation fields are the logo URL, privacy and security URL, help URL and footer, all blank by default; the logo should be no more than 188 by 30 pixels and takes about an hour to propagate
  • The org-wide anonymous users can join a meeting setting defaults to on, and Microsoft is moving that decision to the per-organizer policy
  • The Copilot policy has four values: On, On with saved transcript required, which is the default, On with transcript saved by default, and Off
  • The organizer sees three modes: Only during the meeting, During and after the meeting, and Off; the default policy value forces "during and after" and the organizer cannot change it
  • Setting Copilot to Off for a meeting also turns off recording and transcription for it

Exam tip: "Only during the meeting" uses a temporary speech-to-text stream that is discarded at the end, so Copilot cannot answer questions afterwards and nothing is discoverable.

Microsoft Learn resource: Manage Teams meeting transcription (opens in a new tab)

71

Create and manage meeting templates and template policies

A template gives organizers a pre-set meeting, optionally with settings they cannot change. A template policy only decides which templates they can see.

What you need to know

  • Custom meeting templates require Teams Premium, and you can create up to 50 of them at Meetings > Meeting templates
  • Every option in a template has three properties: a default value, visibility, and a lock status that stops the organizer changing it
  • Template name and description truncate after 40 characters in the client, and a new template can take up to 24 hours to appear
  • Edits to a template apply to both new and already-scheduled meetings that use it
  • Meeting template policies move templates between viewable and hidden lists and nothing more; the Global policy shows everything
  • If a template names a sensitivity label, the label's settings override the template's equivalents

Exam tip: Templates and template policies are separate objects on separate pages. The template sets values, the policy only controls who sees it.

Microsoft Learn resource: Create a custom meeting template in Microsoft Teams (opens in a new tab)

72

Create and manage meeting policies

Meeting policies are where most meeting behaviour is decided, and the exam leans hard on the lobby settings and the recording defaults.

What you need to know

  • Settings are implemented per-organizer, per-user, or both, and a user has exactly one meeting policy at a time
  • Who can bypass the lobby defaults to people in my org and guests; anonymous users can join defaults to on, while anonymous and dial-in users starting a meeting defaults to off
  • Recording is on, recordings automatically expire after a default of 120 days, transcription is on and live captions are off
  • The PowerShell values for the lobby are -AutoAdmittedUsers with Everyone, EveryoneInSameAndFederatedCompany, EveryoneInCompany, InvitedUsers or OrganizerOnly
  • A policy name cannot exceed 64 characters and cannot be renamed after creation
  • Policy changes can take up to 24 hours to take effect

Exam tip: A meeting policy only sets a default the organizer can override in Meeting options. To enforce a lobby value you need a meeting template or a sensitivity label, which means Teams Premium.

Microsoft Learn resource: Manage lobby options in Microsoft Teams (opens in a new tab)

73

Create and manage meeting customization policies

Customization policies are the branding layer: your logo, your colours and your own reaction images on the meeting join experience.

What you need to know

  • Teams admin center > Meetings > Customization policies, available to Teams Premium licensed users
  • A policy can hold a maximum of five themes, and a theme is a light and dark logo, a light and dark image, and one brand hex colour
  • The logo appears on the join launcher, pre-join, lobby and invite; the image appears on the join launcher, pre-join and lobby only; the colour also reaches the meeting stage
  • Images are not visible on mobile clients, and users with high-contrast device settings never see themes
  • Only licensed users with a customization policy can create themed meetings, but anyone can see the theme, including guests and anonymous participants
  • The cmdlets are New-, Set- and Grant-CsTeamsMeetingBrandingPolicy, although images must be uploaded in the admin center

Exam tip: A logo in a meeting theme overrides the logo you set under Meeting settings > Email invitation.

Microsoft Learn resource: Create and manage meeting themes for Teams meetings (opens in a new tab)

74

Create and manage event settings and policies

Events policies govern webinars and town halls. Meeting policies still apply to anything events share with meetings, so events are governed by both.

What you need to know

  • Teams admin center > Meetings > Events policies, backed by CsTeamsEventsPolicy
  • Webinars and town halls both default to on, with "who can attend" defaulting to Everyone, registration on, and email customization on
  • -AllowWebinars and -AllowTownhalls together drive the Optimize for large audience switch: with both enabled it is off below 1,000 attendees and forced on above
  • Recording and publishing are separate controls: -RecordingForTownhall allows recording, while -AllowedTownhallTypesForRecordingPublish controls who can be given the recording afterwards
  • Microsoft recommends configuring a verified sending domain so event emails do not come from a Microsoft default address
  • The old Live event settings page applies to Teams live events, which are retired

Exam tip: As of April 1, 2026 many advanced event features moved from Teams Premium into Teams Enterprise, including eCDN, RTMP-In, 1080p and custom emails. A new Teams Premium licence no longer grants them.

Microsoft Learn resource: Manage who can schedule and attend events in Microsoft Teams (opens in a new tab)

75

Configure and manage Teams webinars

A webinar is the event format that still lets attendees speak and still asks them to register. The registration form is the part with specific, testable structure.

What you need to know

  • A webinar runs up to 1,000 attendees, and registration exists only at that tier
  • The registration form has three question categories: required (first name, last name and the Microsoft consent field, none of which can be removed), standard (address, job title, organization and the rest), and custom
  • The policy parameter is -AllowedQuestionTypesInRegistrationForm with DefaultOnly, DefaultAndPredefinedOnly, or AllQuestions, which is the default
  • Public webinars let anonymous people register and join; in-org webinars do not
  • Roles allow up to 10 co-organizers and 100 presenters, and external presenters get a unique link that bypasses the lobby
  • Attendees cannot dial in to events, in-org or public

Exam tip: A webinar template still uses webinar policy settings until the organizer turns Optimize for large audience on, at which point it quietly becomes a town hall and town hall policy applies.

Microsoft Learn resource: Manage the registration form for Teams events (opens in a new tab)

76

Configure and manage Teams town halls

A town hall is a broadcast. Attendees watch a stream, engage through Q&A, and cannot turn on a microphone, which is exactly why it scales.

What you need to know

  • There is no lobby in an event optimized for large audiences, and attendees cannot use mic, camera or content sharing
  • Attendees see the stream at a slight delay and can pause and rewind; Q&A is the primary way they engage
  • Chat, reactions, raise hand and polls work up to 20,000 attendees, and Q&A up to 100,000
  • Events are recorded automatically by default, and a published recording expires after 30 days, extendable by the organizer to 60
  • Microsoft eCDN is enabled by default for large-audience organizers, and Ultra-Low Latency and 1080p work only with it; partner eCDNs fall back
  • Town-hall-only capabilities include eCDN analytics, production tool control, silent testing and streaming encoders

Exam tip: Teams live events retired on June 30, 2026, with already-scheduled events honoured into early 2027. Town halls are the replacement, so any live events answer is now wrong.

Microsoft Learn resource: Plan for Teams events (opens in a new tab)

Manage phone numbers and services for Teams Phone

77

Provision and manage phone numbers for users, services, and conferencing bridges

Teams has three kinds of phone number, and the difference is capacity. A user number handles a few calls at once; a service number handles hundreds.

The three number usages:

  1. User (subscriber): assigned to a person, geographic or toll only, never toll-free
  2. Voice app (service): assigned to an auto attendant or call queue resource account, toll or toll-free
  3. Conference (service): assigned to an audio conferencing bridge, toll or toll-free

What you need to know

  • Numbers are acquired at Teams admin center > Voice > Phone numbers > Add, and you have 10 minutes to place the order before the reservation is released
  • The Voice node only appears once the tenant owns an E5, E3 with Phone System, or Audio Conferencing licence
  • The user number quantity limit is calling plan licences times 1.1, plus 10, and ported numbers do not count toward it
  • Getting new numbers and porting are different flows: porting makes Microsoft your service provider and biller
  • To repurpose a number, use Voice > Phone numbers > Change usage, and the number must be unassigned

Exam tip: How you get numbers depends on the PSTN connectivity option. The admin center wizard is for Calling Plans; Operator Connect and Teams Phone Mobile numbers are requested from the operator, and Direct Routing numbers stay with your carrier.

Microsoft Learn resource: Get telephone numbers in Microsoft Teams (opens in a new tab)

78

Assign, change, or remove a phone number for a user or a resource account

Assigning a number is two clicks in the portal and one cmdlet in PowerShell, but there are prerequisites that catch people out, particularly in hybrid tenants.

What you need to know

  • For a user: Users > Manage users > user > Account > General information > Edit, or Set-CsPhoneNumberAssignment
  • The number's country must match the user's usage location, and Calling Plan licences are assigned in the Microsoft 365 admin center, not the Teams admin center
  • In a hybrid tenant, any value in the on-premises msRTCSIP-Line attribute must be removed and synchronised first
  • Resource accounts are created at Voice > Resource accounts > Add, or with New-CsOnlineApplicationInstance
  • A Direct Routing number with an extension can only be assigned with PowerShell, because the portal supports extension-less Direct Routing numbers only
  • Get-CsPhoneNumberAssignment with -PstnAssignmentStatus Unassigned lists your spare numbers

Exam tip: A phone number is optional for an auto attendant or call queue and is only needed for direct inbound dialling, but the free resource account licence is mandatory either way.

Microsoft Learn resource: Manage phone numbers for users (opens in a new tab)

79

Manage voice settings and policies for users

Voice has more policy types than any other area of Teams, and each one owns a narrow slice of behaviour. Knowing which policy holds which setting is most of the battle.

What you need to know

  • The voice policy types are calling, call hold, call park, caller ID, emergency calling and call routing, mobility, shared calling, voice routing, voicemail and voice applications policies
  • Enterprise Voice is enabled per user under Account > Assigned phone number, or with Set-CsPhoneNumberAssignment -EnterpriseVoiceEnabled $true
  • Caller ID policies can replace the caller ID with a resource account number or make it anonymous; the cmdlet noun is CsCallingLineIdentity
  • Call park defaults to off, with a pickup range of 10 to 99 and a park timeout of 300 seconds
  • An emergency call routing policy applies to Direct Routing only, while an emergency calling policy applies to every PSTN option
  • A policy assigned to a network site overrides the one assigned to the user

Exam tip: A voice routing policy on its own does not let anyone make a PSTN call. It is a container for PSTN usage records, and the user still has to be enabled for Direct Routing.

Microsoft Learn resource: Teams settings and policies reference (opens in a new tab)

80

Create and manage voicemail policies

Voicemail policies control transcription, profanity masking, recording length and whether users can edit their own call answering rules.

What you need to know

  • Teams admin center > Voice > Voicemail policies, with New-, Set- and Grant-CsOnlineVoicemailPolicy in PowerShell
  • Maximum voicemail recording length defaults to 300 seconds, with an allowed range of 30 to 600 seconds
  • Transcription is on by default, translation of transcriptions is on, and profanity masking is off
  • Users can edit call answering rules by default
  • Prompt languages are blank by default, in which case the service falls back to the user's own voicemail language
  • The voicemail service caches policies and refreshes every 5 minutes, so changes take up to five minutes

Exam tip: Whether a call reaches voicemail at all is set in the calling policy, not the voicemail policy. Voicemail policies only govern voicemail features once the call gets there.

Microsoft Learn resource: Manage Cloud Voicemail policies for your users (opens in a new tab)

81

Manage auto-attendants and call queues

Auto attendants answer and route; call queues hold callers and distribute them to agents. The routing methods and the exception handling are the exam's favourite details.

The four call queue routing methods:

  1. Attendant: rings every agent at once, and is the default
  2. Serial: rings one agent at a time in list order
  3. Round robin: balances the number of calls each agent takes
  4. Longest idle: routes to the agent who has been Available longest

What you need to know

  • Presence-based routing includes only agents whose availability is Available, and Longest idle forces it on
  • Maximum calls in the queue defaults to 50 with a range of 0 to 200, and call timeout can be set from 0 seconds to 45 minutes
  • The three exception handlers are Overflow, Call timeout and No agents, and each can disconnect, or redirect to a person, a voice app, an external number or shared voicemail
  • A single call can make at most 25 transitions through auto attendants and call queues before it is disconnected
  • Auto attendants have separate business hours, after hours and holiday call flows; call queues have none of those
  • Greeting text can be up to 1,000 characters and an uploaded audio file up to 5 MB

Exam tip: Dial keys are matched before directory searches, so Microsoft recommends setting directory search to None when you assign dial keys and putting the search on a nested auto attendant instead.

Microsoft Learn resource: Set up a call queue (opens in a new tab)

82

Create and manage calling policies

The calling policy decides what a user can do with a call: forward it, delegate it, record it, send it to voicemail, or be told the line is busy.

What you need to know

  • Make private calls is on by default, and turning it off disables Teams calling entirely for those users
  • Call forwarding and simultaneous ringing to people in the organization and to external numbers are both on; voicemail for inbound calls defaults to "let users decide"
  • Busy on busy is off by default, with four values: Off, On, Use unanswered settings and Let users decide
  • Cloud recording for calling and transcription are both off, while music on hold, spam filtering and real-time captions are on
  • Per-user call settings are read and written with Get-CsUserCallingSettings and Set-CsUserCallingSettings
  • Delegate permissions are MakeCalls, ManageSettings, ReceiveCalls, PickUpHeldCalls and JoinActiveCalls, managed with the CsUserCallingDelegate cmdlets

Exam tip: Copilot appears in both the calling policy and the meeting policy, and they are independent. Copilot in a one-to-one or PSTN call is configured separately from Copilot in meetings.

Microsoft Learn resource: Calling policies in Teams (opens in a new tab)

Domain 4 Monitor, Report On, and Troubleshoot Teams 15-20% of the exam 0 / 15 studied

This domain is the operations half of the job: knowing which dashboard answers which question, how long the data lives, and what to do when a client will not start, will not sign in, or sounds terrible. The most reliable marks here come from telling apart tools that look similar, such as the Call Quality Dashboard and Call Analytics, or the client health dashboard and the client usage report.

Monitor and report on Teams

83

Monitor and report on voice and meeting quality

Two tools, two scopes. The Call Quality Dashboard looks across the tenant for patterns; Call Analytics looks at one person's calls. Most quality investigations use both, starting with the complaint.

What you need to know

Call Quality Dashboard Call Analytics
Scope Tenant-wide, aggregated One user at a time
Where cqd.teams.cloud.microsoft, or Analytics & reports Users > the user > Meetings & calls
Window Records within about 30 minutes, kept 12 months Last 30 days
Use it for Trends, a bad subnet, a bad building One person's bad call yesterday
  • CQD keeps records for 12 months, but end user identifiable information is purged after 28 days
  • The audio Poor thresholds are round trip over 500 ms, packet loss rate over 0.1 and jitter over 30 ms, applied only when packet utilization is above 500 packets
  • Building data is uploaded as a .tsv or .csv with no header row and takes up to four hours to process
  • Real-time telemetry is retained 7 days for Teams Premium or Teams Rooms Pro attendees, and only for the meeting's duration for everyone else

Exam tip: The Support Specialist cannot see the Advanced or Debug tabs, so no device names, IP addresses or subnets, and other participants appear only as Internal User or External User.

Microsoft Learn resource: Improve call quality in Microsoft Teams (opens in a new tab)

84

Configure alert rules

Teams has its own alerting in the admin center, separate from Purview. The rules are few enough to learn by name.

What you need to know

  • Teams admin center > Notifications & alerts > Rules, and you need to be a Teams service admin
  • The named rules are App submissions, Device state, and audio, video and screen sharing quality for in-progress meetings, plus a Teams client update rollout rule
  • App submissions is off by default and has to be set to Active
  • Notifications land in an auto-created team called Admin Alerts and Notifications, in the App submissions or MonitoringAlerts channel, or go to a webhook
  • In-progress meeting quality rules watch packet loss, jitter, local healed ratio and round-trip time, and monitored attendees need Teams Premium or Teams Rooms Pro
  • Alerting exists in commercial and GCC clouds only

Exam tip: The device state rule is scoped by the signed-in user rather than by the device, which matters when a shared device account moves between rooms.

Microsoft Learn resource: Microsoft Teams monitoring and alerting (opens in a new tab)

85

Report on Teams usage, including team activity, app usage, active users, per-meeting metrics, and storage usage

Usage data lives in two admin centers with slightly different definitions, and storage is not a Teams report at all.

What you need to know

  • Teams admin center > Analytics & reports > Usage reports, with a date range of 7, 30, 90 or 180 days
  • Global Reader sees tenant-level aggregates only, not per-user or per-team data
  • The app usage report has 24 to 48 hours of latency and excludes side-loaded line-of-business apps
  • Storage comes from Microsoft 365 admin center > Reports > Usage > SharePoint, refreshed every 48 to 72 hours, with a banner at 80% of quota
  • Per-meeting metrics come from the troubleshooting experience, where Export downloads a CSV of completed meetings in the 30-day window
  • Concealed user, group and site names are on by default, and a Global Administrator turns them off in Org settings > Reports

Exam tip: Active user means two different things. In the user activity report it means active users across the tenant; in the Teams usage report it means active users within active teams.

Microsoft Learn resource: Microsoft Teams analytics and reporting (opens in a new tab)

86

Monitor and report on the creation and deletion of teams

Team creation and deletion are audit events, not report rows. That means Purview Audit, and it means auditing has to have been on when it happened.

What you need to know

  • The audited operations are TeamCreated and TeamDeleted, with ChannelAdded and ChannelDeleted for channels
  • Search them in the Microsoft Purview portal > Audit, or with Search-UnifiedAuditLog
  • Audit data exists only from the moment auditing was enabled, so there is no retrospective search
  • Audit (Standard) retains records for 180 days; E5 gives a one-year default for Entra, Exchange, OneDrive and SharePoint, but Teams records stay at 180 days unless you create a custom retention policy
  • A tenant is capped at 50 audit log retention policies, and creating one needs the Organization Configuration role
  • Audit events from private channels are logged the same way as from standard channels

Exam tip: Defender for Cloud Apps can turn this into an alert rather than a search. Microsoft's own documented example is a user who deletes two or more teams within 30 minutes.

Microsoft Learn resource: Search the audit log for events in Microsoft Teams (opens in a new tab)

87

Monitor and report on guest access

Guest monitoring is spread across Teams reports, Entra audit logs and access reviews, because a guest is an Entra object that Teams happens to use.

What you need to know

  • Adding a guest in Teams is audited in Entra as "Added member to group", not as a Teams-specific event
  • Entra audit logs are at Entra ID > Monitoring & health > Audit logs, or per user under the user's own Audit logs
  • The Teams usage report separates active guests, who have a guest account in your directory, from external active users, who are shared channel participants using their own identity
  • Access reviews are the recurring control, and they need Entra ID P2 or Entra ID Governance
  • Guests are treated as inactive after 30 days without a sign-in, and the Sponsors field records who is responsible for each one
  • A guest access diagnostic for files exists at aka.ms/TeamsFilesGuestAccessDiag

Exam tip: Guest tracking is an Entra and Purview job, not a Teams admin center report. If the question asks who invited a guest and when, the answer is the Entra audit log.

Microsoft Learn resource: Guest access in Microsoft Teams (opens in a new tab)

88

Monitor the Microsoft 365 network connectivity test tool

The connectivity test tool feeds a dashboard in the Microsoft 365 admin center, and the dashboard is only as good as the locations and samples you give it.

What you need to know

  • Results appear at Microsoft 365 admin center > Health > Network connectivity, scored 0 to 100
  • There are three ways to feed it: Windows Location Services opt-in with at least two machines per site, manually added locations with LAN subnets in the range /8 to /29, or manual test runs
  • Samples from Location Services or LAN subnets appear after about 24 hours; a manual test report appears in 2 to 3 minutes
  • Remote worker insights are only shown for cities with a minimum of five remote employees
  • Discovered city locations remain for 90 days after samples stop arriving
  • The tool is not supported in GCC Moderate, GCC High or DoD

Exam tip: The browser test alone does not give media quality metrics. The user has to download and run the advanced tests client, and be signed in, for the results to reach your tenant.

Microsoft Learn resource: Network connectivity in the Microsoft 365 admin center (opens in a new tab)

89

Manage feedback, including policies

Feedback policies decide whether your users can send feedback to Microsoft and whether they see the in-product surveys. Two independent settings, one policy.

What you need to know

  • Teams feedback is governed by Set-CsTeamsFeedbackPolicy, and by the Cloud Policy service for Microsoft 365 at config.office.com
  • -UserInitiatedMode controls "give feedback" and defaults to Enabled
  • -ReceiveSurveysMode controls the survey and defaults to Enabled, with a third value EnabledUserOverride that lets the user opt out
  • Other parameters are -AllowLogCollection, -AllowScreenshotCollection, -AllowEmailCollection and -EnableFeatureSuggestions
  • By default every user gets the Global policy with both enabled; in Teams for Education it is enabled for teachers and disabled for students
  • Submitted feedback is reviewable on the Product feedback page in the Microsoft 365 admin center

Exam tip: The two settings are independent, and the documented example switches feedback on while switching surveys off. Do not assume one implies the other.

Microsoft Learn resource: Manage user feedback in Microsoft Teams (opens in a new tab)

Troubleshoot audio, video, and client issues

90

Collect client-side logs

There are two log sets, and only one of them is readable by you. Knowing which is which saves a support call.

What you need to know

  • MS Teams Support Log Files hold media, signalling and platform logs and are encrypted so only Microsoft Support can read them; Weblogs are application event logs in plain text
  • The keyboard shortcut is Ctrl + Alt + Shift + 1 on Windows and Option + Command + Shift + 1 on Mac
  • Both sets land in the Downloads folder, and the support log files have to be zipped by hand before upload
  • All timestamps in Teams logs are UTC
  • An admin can collect remotely at Users > the user > Client health > Request client logs; the logs are kept 30 days, can take up to 8 hours to appear, and no prompt is shown to the user
  • In the browser client only the keyboard shortcut works, and no support log files are produced

Exam tip: On VDI, log size is capped by default. Turn on Extended Logging in Teams privacy settings before you reproduce the problem or the interesting part will have rolled off.

Microsoft Learn resource: Collect Teams client diagnostic logs for Microsoft support (opens in a new tab)

91

Clear the Teams client cache

Clearing the cache is the standard fix for a client showing stale data, and the paths changed with the new Teams client.

What you need to know

Client Path
New Teams, Windows %userprofile%\appdata\local\Packages\MSTeams_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams
Classic Teams, Windows %appdata%\Microsoft\Teams
New Teams, macOS ~/Library/Group Containers/UBF8T346G9.com.microsoft.teams and ~/Library/Containers/com.microsoft.teams2
Teams Rooms on Windows C:\Users\Skype\AppData\Local\Packages\MSTeamsRooms_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams
  • On Windows you can also use Settings > Apps > Installed apps > Microsoft Teams > Advanced options > Reset, which also clears personalization
  • The service caches general user information for up to 3 days, the client caches display name and phone number for up to 28 days, and profile photos for up to 60 days
  • Expect the first restart after a clear to be slower while the cache rebuilds

Exam tip: Microsoft explicitly says not to clear the cache for missing messages, chat history that will not load, or wrong unread counts. It does not fix them and it deletes the logs you would need to find the real cause.

Microsoft Learn resource: Clear the Teams client cache (opens in a new tab)

92

Troubleshoot issues by using self-help diagnostics for Teams

Self-help diagnostics are read-only tests an admin runs from the Microsoft 365 admin center. They look at your configuration and tell you what is wrong with it.

What you need to know

  • Run them from the Help & Support button in the Microsoft 365 admin center: describe the problem, then Run tests
  • They are read-only and cannot change tenant configuration; they return findings plus remediation steps
  • Non-admin users get the Microsoft Remote Connectivity Analyzer at testconnectivity.microsoft.com instead
  • Named shortcuts include TeamsSignInDiag, TeamsFederationDiag, TeamsPresenceDiag, TeamsVoicemailDiag, MeetingRecordingDiag, MissingRecordingDiag and TeamsFilesGuestAccessDiag
  • Admin center diagnostics are not available in GCC High, DoD or 21Vianet, and the Remote Connectivity Analyzer is not available in GCC or GCC High
  • Customer content such as messages and documents is never accessed by a diagnostic

Exam tip: The two toolsets are not interchangeable. Some scenarios have only an admin center diagnostic, such as Teams Files Guest Access, and others have only a Remote Connectivity Analyzer test, such as Teams Exchange Integration.

Microsoft Learn resource: Self-help diagnostics for Microsoft Teams administrators (opens in a new tab)

93

Troubleshoot Teams client installation and update issues

The new Teams client installs as an MSIX package, which is why the failures are different from the old MSI ones and why group policy can block it.

What you need to know

  • The provisioning command is teamsbootstrapper.exe -p, and -o with a path does an offline install; its log is at C:\WINDOWS\Temp\teamsprovision.log
  • New Teams installs machine-wide to C:\Program Files\WindowsApps with auto-update enabled; classic Teams went to Program Files (x86) with auto-update disabled
  • "Due to org policy, you can't install the new Teams" comes from MSIX registry blocks such as BlockNonAdminUserInstall and AllowAllTrustedApps
  • The client checks for updates at startup and every few hours, downloads a differential update through Delivery Optimization, and requires a restart to apply
  • Blocking Teams CDN endpoints, disabling Delivery Optimization, or SSL inspection on Microsoft 365 endpoints all stop updates
  • Windows 10 users seeing "We've run into an issue" usually need the WebView2 Runtime

Exam tip: The client health insight called MSIX GPO block is fixed by bulk-deploying with teamsbootstrapper, not by touching the user's machine, and running the bootstrapper replaces any user-installed Teams.

Microsoft Learn resource: Resolve the new Teams client installation issues (opens in a new tab)

94

Troubleshoot Teams client health and issues in the Microsoft Teams admin center

The client health dashboard tells you which clients are crashing, failing to launch or failing to update, across the tenant and per user.

What you need to know

  • Teams admin center > Teams client health, supported for Windows non-VDI and Mac applications only
  • The health widget trends crashes and launch failures per day over the last 28 days
  • Top issues reports device reported crashes, launch failures and update failures, each over the last 7 and last 28 days
  • The client update widget buckets devices into Latest Build, one or more builds behind where the build is under 30 days old, and Outdated where it is more than 30 days old
  • The per-user view is Users > Manage users > user > Client health, showing client version, release date and recent crashes
  • Crash remediation starts with allow-listing the Teams client and Microsoft Edge WebView2 in third-party antivirus and DLP

Exam tip: Client health and the Teams client usage report are different pages. Client health is crashes and update failures; the usage report under Analytics & reports tells you which client version and deployment ring people are on.

Microsoft Learn resource: Teams client health dashboard in the Teams admin center (opens in a new tab)

95

Troubleshoot sign-in issues to Teams

Sign-in failures come with error codes, and the codes map to causes cleanly enough to be worth memorising.

What you need to know

  • Start with the Teams Sign-in diagnostic at aka.ms/TeamsSignInDiag in the Microsoft 365 admin center, which needs an admin account
  • 0xCAA82EE7 and 0xCAA82EE2 mean no internet or a blocked network path
  • 0xCAA20004 means a Conditional Access problem
  • 0xCAA70004 and 0xCAA70007 point at the older Office 2016 build connection issue, especially when other Office apps also fail
  • The reinstall sequence is uninstall, delete %appdata%\Microsoft\Teams, then reinstall as administrator
  • For Teams Rooms and Surface Hub accounts, AADSTS50076 and AADSTS50079 mean MFA is enabled on the resource account, AADSTS53003 means Conditional Access blocked it, and CAA20003 means the device clock is wrong

Exam tip: Room and Surface Hub resource accounts cannot have MFA or Conditional Access enforced, so their fix is an exclusion, not a password reset.

Microsoft Learn resource: Resolve sign-in errors in Teams (opens in a new tab)

96

Troubleshoot Microsoft 365 Copilot and AI experiences in Teams

Most Copilot-in-Teams problems are not Copilot problems. They are transcription problems, licence problems, or the Copilot app being blocked.

What you need to know

  • Copilot in Teams needs a Microsoft 365 Copilot licence per user; intelligent recap needs Teams Premium or Copilot
  • With the meeting policy Copilot set to Off, licensed users cannot use Copilot and nobody can record or transcribe that meeting
  • With transcription off and Copilot set to during and after, licensed users cannot use Copilot at all unless somebody starts a transcript
  • -AutomaticallyStartCopilot defaults to Disabled
  • Voice and face enrollment is set only in PowerShell with Set-CsTeamsAIPolicy, and both are enabled by default with no admin center UI
  • Copilot readiness and usage reporting lives in Microsoft 365 admin center > Reports > Usage > Microsoft Copilot, read as AI Administrator

Exam tip: A licensed user whose Copilot app is blocked in Manage apps loses Copilot even though the licence is valid. Check app availability before you look at the licence.

Microsoft Learn resource: Manage Teams meeting transcription (opens in a new tab)

97

Troubleshoot issues with joining meetings and accessing features in meetings

When someone outside your organization cannot join, the error message tells you which switch is off. Lobby settings are irrelevant until the right access setting is on.

What you need to know

  • Three org-level prerequisites govern external participants: guest access, external access with mutual trust, and anonymous meeting join
  • "Sign in to join this meeting" means anonymous join is disabled, either org-wide or in the organizer's meeting policy
  • "Sign in with a different account to join this meeting" means the person's domain is blocked or not allowed in external access, and anonymous join is off as well
  • Lobby settings control five categories: organizer and co-organizers, people in your organization, guests, people in trusted organizations, and anonymous participants
  • To stop only some organizers hosting anonymous-join meetings, leave the org setting on and turn it off in their meeting policy
  • The Teams Calendar App diagnostic checks meeting policies, guest access, external access, federation, lobby settings and cross-tenant access in one pass

Exam tip: In a federated meeting, an organization that joined but did not organize sees telemetry only for its own users. The organizing tenant sees everyone.

Microsoft Learn resource: Errors when external participants try to join a Teams meeting (opens in a new tab)

Quick reference: where to go for what

Task Where to go
Create, archive or restore a team Teams admin center > Teams > Manage teams
Restrict who can create teams Microsoft 365 admin center > Settings > Org settings, plus the Group.Unified directory setting
Set a group expiration or naming policy Microsoft Entra admin center > Groups > Expiration or Naming policy
Restore a deleted team Microsoft 365 admin center > Groups > Deleted groups, within 30 days
Turn guest access on or off Teams admin center > Users > Guest access
Allow a partner domain to chat with you Teams admin center > Users > External access
Allow a partner into a shared channel Microsoft Entra admin center > External Identities > Cross-tenant access settings
Control private and shared channel creation Teams admin center > Teams > Teams policies
Decide which apps a user can use Teams admin center > Teams apps > Manage apps, with app centric management
Pin an app to the app bar Teams admin center > Teams apps > Setup policies
Set who bypasses the meeting lobby Teams admin center > Meetings > Meeting policies
Enforce a meeting setting the organizer cannot change A meeting template or a Purview sensitivity label
Allow webinars or town halls Teams admin center > Meetings > Events policies
Get or port phone numbers Teams admin center > Voice > Phone numbers
Create an auto attendant or call queue Teams admin center > Voice > Auto attendants or Call queues, with a resource account
Set a Teams retention or DLP policy Microsoft Purview portal
Search who created or deleted a team Microsoft Purview portal > Audit
Investigate one user's bad call Teams admin center > Users > the user > Meetings & calls
Look for a tenant-wide quality pattern Call Quality Dashboard
See which clients are crashing Teams admin center > Teams client health
Update device firmware Teams admin center > Teams Devices
Model bandwidth for a new office Teams admin center > Planning > Network planner

Additional tips

I think the best thing that you can do after reading this, or even meanwhile, is to open a free Microsoft 365 trial and play with those features. If you qualify for the Microsoft 365 Developer Program (opens in a new tab), for example through a Visual Studio Professional or Enterprise subscription, its E5 developer sandbox is the better option, because it arrives with sample data already in it. Either way, follow the tutorials in your own tenant and you shouldn't have any problems with the exam!

Before exam day, explore the exam interface in the Microsoft exam sandbox (opens in a new tab), so the question types and the navigation hold no surprises.

Study resource

Microsoft 365 Developer Program

A Microsoft 365 E5 developer sandbox with sample data already loaded, so you can try every task in this guide without touching production. Microsoft gives it only to qualifying Developer Program members, for development use, and a valid billing account is required, so a Microsoft 365 trial is the fallback if you do not qualify.

Open the resource (opens in a new tab)

Frequently asked questions

How long should I study for the MS-700?

The MS-700 is an associate-level exam, so if you already administer Microsoft Teams day to day, three to four weeks of focused study is realistic. If Teams administration is new to you, plan for six to eight weeks and start with the Microsoft Learn paths in this guide before the study notes. The governance and external collaboration skills take the longest to absorb, because they reach into Microsoft Entra ID and Microsoft Purview as much as into Teams itself.

Do I need hands-on experience with Microsoft Teams to pass?

More than for most Microsoft exams, yes. The MS-700 keeps asking which setting to change and which admin center owns it, and those answers stick far better once you have clicked through them yourself. If you do not have a tenant to practise in, a Microsoft 365 trial will do, and if you qualify for the Microsoft 365 Developer Program, for example through a Visual Studio Professional or Enterprise subscription, its E5 developer sandbox comes with sample data already loaded.

Which certification should I take before the MS-700?

There is no prerequisite, so you can sit the MS-700 first if you already work with Microsoft Teams. If Microsoft 365 is new to you, start with a fundamentals exam such as the AB-900 or the SC-900 so that the identity, licensing and compliance vocabulary is already familiar. Looking further ahead, Teams Administrator Associate also counts toward Microsoft 365 Certified: Administrator Expert, which Microsoft retires on November 30, 2026.

How often does Microsoft update the MS-700 exam?

Microsoft revises the skills measured periodically, and the version these notes follow dates from July 29, 2026. The MS-700 study guide on Microsoft Learn (opens in a new tab) carries a change log at the bottom that shows exactly which skill groups moved in the last revision. Check it a week before your exam date so you are studying the version you will actually sit.

Does the MS-700 certification expire?

Yes. Microsoft associate certifications expire annually, and you renew by passing a free online assessment on Microsoft Learn rather than sitting the exam again. The renewal assessment is unproctored and you can retake it as many times as you need, and the renewal window opens six months before your expiry date, so set a reminder well ahead of it.

Maintained by Vlad Catrinescu, reviewed September 2026 · All study guides