Microsoft certification is a great way to validate your skills in a particular area. With many organizations seeking official certification as a prerequisite for a particular role, it’s a fantastic time to dive into the certification paths Microsoft have available. For experienced Microsoft 365 Administrators, the MS-500 exam (Microsoft 365 Security Administration) is a fantastic path to take to bring your experience to the next level. It is also the only required exam for the Microsoft 365 Certified Security Administrator Associate certification.
Over the next few weeks, I will be uploading a series of blog posts where I will dive into the exam blueprint, focusing on the relevant topics and going through some of the things you will need to know to prepare for this exam.
Exam Blueprint
The Official Microsoft Exam Skills Outline for the MS-500 exam is available on the Microsoft Certification site. The breakdown of the exam is listed below (as of December 2020). In the coming weeks, I will update the below list with links to the relevant posts and by the end, you should be able to follow the study guide from this page.
It’s important to note that I have no insider information on the exam questions or structure so I will interpret and explain the topics as I best I can. There may be things that I don’t address specifically that will appear on the exam.
Finally, I will be providing examples from my lab environment, it will help massively to follow along in your own environment if possible.
Implement and manage identity and access (30-35%)
Secure Microsoft 365 hybrid environments
- Plan Azure AD authentication options
- Plan Azure AD synchronization options
- Monitor and troubleshoot Azure AD Connect events
Secure Identities
- Implement Azure AD group membership
- Implement password management
- Configure and manage identity governance
Implement authentication methods
- Plan sign-on security
- Implement multi-factor authentication (MFA)
- Manage and monitor MFA
- Plan and implement device authentication methods like Windows Hello
- Configure and manage Azure AD user authentication options and self-service password management
Implement conditional access
- Plan for compliance and conditional access policies
- Configure and manage device compliance for endpoint security
- Implement and manage conditional access
Implement role-based access control (RBAC)
Implement Azure AD Privileged Identity Management (PIM)
- Plan for Azure PIM
- Assign eligibility and activate admin roles
- Manage Azure PIM role requests and assignments
- Monitor PIM history and alerts
Implement Azure AD Identity Protection
- Implement user risk policy
- Implement sign-in risk policy
- Configure Identity Protection alerts
- Review and respond to risk events
Implement and manage threat protection (20-25%)
Implement an enterprise hybrid threat protection solution
- Plan an Azure Advanced Threat Protection (ATP) solution
- Install and configure Azure ATP
- Monitor and manage Azure ATP
Implement device threat protection
- Plan a Microsoft Defender ATP solution
- Implement Microsoft Defender ATP
- Manage and monitor Microsoft Defender ATP
Implement and manage device and application protection
- Plan for device and application protection
- Configure and manage Microsoft Defender Application Guard
- Configure and manage Microsoft Defender Application Control
- Configure and manage exploit protection
- Configure Secure Boot
- Configure and manage Windows device encryption
- Configure and manage non-Windows device encryption
- Plan for securing applications data on devices
- Implement application protection policies
Implement and manage Office 365 ATP
Monitor Microsoft 365 Security with Azure Sentinel
- Plan and implement Azure Sentinel
- Configure playbooks in Azure Sentinel
- Manage and monitor Azure Sentinel
- Respond to threats in Azure Sentinel
Implement and manage information protection (15-20%)
Secure data access within Office 365
- Implement and manage Customer Lockbox
- Configure data access in Office 365 collaboration workloads
- Configure B2B sharing for external users
Manage sensitivity labels
- Plan a sensitivity label solution
- Configure sensitivity labels and policies
- Configure and use label analytics
- Use sensitivity labels with Teams, SharePoint, OneDrive and Office apps
Manage Data Loss Prevention (DLP)
- Plan a DLP solution
- Create and manage DLP policies
- Create and manage sensitive information types
- Monitor DLP reports
- Manage DLP notifications
Implement and manage Microsoft Cloud App Security
- Plan Cloud App Security implementation
- Configure Microsoft Cloud App Security
- Manage cloud app discovery
- Manage entries in the Cloud app catalog
- Manage apps in Cloud App Security
- Manage Microsoft Cloud App Security
- Configure Cloud App Security connectors and Oauth apps
- Configure Cloud App Security policies and templates
- Review, interpret and respond to Cloud App Security alerts, reports, dashboards and logs
Manage governance and compliance features in Microsoft 365 (25-
30%)
Configure and analyze security reporting
- Monitor and manage device security status using Microsoft Endpoint Manager Admin Center
- Manage and monitor security and dashboards using Microsoft 365 Security Center
- Plan for custom security reporting with Graph Security API
- Use secure score dashboards to review actions and recommendations
- Configure alert policies in the Security & Compliance admin center
Manage and analyze audit logs and reports
- Plan for auditing and reporting
- Perform audit log search
- Review and interpret compliance reports and dashboards
- Configure audit alert policy
Manage data governance and retention
- Plan for data governance and retention
- Review and interpret data governance reports and dashboards
- Configure retention policies
- Define data governance event types
- Define and manage communication compliance policies
- Configure Information holds
- Find and recover deleted Office 365 data
- Configure data archiving
- Manage inactive mailboxes
Manage search and investigation
- Plan for content search and eDiscovery
- Delegate permissions to use search and discovery tools
- Use search and investigation tools to perform content searches
- Export content search results
- Manage eDiscovery cases
Pingback: Study Guide Series: Exam MS-500 – Plan Azure AD Authentication Options – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Plan Azure AD Synchronization Options – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Monitor and Troubleshoot Azure AD Connect Events – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement Password Management – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement Azure AD Group Membership – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Configure and Manage Identity Governance – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Plan Sign-on Security – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement Multi-Factor Authentication (MFA) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage and Monitor MFA – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Plan and Implement Device Authentication Methods like Windows Hello – Sean McAvinue
Pingback: Study Guide Series – Exam MS-500: Configure and Manage Azure AD User Authentication Options and Self-Service Password Management – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement Conditional Access – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement Role-Based Access Control (RBAC) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement Azure AD Privileged Identity Management (PIM) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement Azure AD Identity Protection – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement an Enterprise Hybrid Threat Protection Solution – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Monitor and Manage Azure ATP – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Plan a Microsoft Defender ATP solution – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement Microsoft Defender ATP – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage and Monitor Microsoft Defender ATP – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement and Manage Device and Application Protection (Part 1) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement and Manage Device and Application Protection (Part 2) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement and Manage Device and Application Protection (Part 3) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Configure Office 365 ATP – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage Office 365 ATP – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Monitor Microsoft 365 Security with Azure Sentinel (Part 1) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Monitor Microsoft 365 Security with Azure Sentinel (Part 2) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Secure Data Access Within Office 365 – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage Sensitivity Labels (Part 1) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage Sensitivity Labels (Part 2) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage Data Loss Prevention (DLP) (Part 1) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage Data Loss Prevention (DLP) (Part 2) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement and Manage Microsoft Cloud App Security (Part 1) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement and Manage Microsoft Cloud App Security (Part 2) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement and Manage Microsoft Cloud App Security (Part 3) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement and Manage Microsoft Cloud App Security (Part 4) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Implement and Manage Microsoft Cloud App Security (Part 5) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Configure and Analyze Security Reporting (Part 1) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Configure and Analyze Security Reporting (Part 2) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage and Analyze Audit Logs and Reports – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage Data Governance and Retention (Part 1) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage Data Governance and Retention (Part 2) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage Data Governance and Retention (Part 3) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage Search and Investigation (Part 1) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage Search and Investigation (Part 2) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage Data Privacy Regulation Compliance (Part 1) – Sean McAvinue
Pingback: Study Guide Series: Exam MS-500 – Manage Data Privacy Regulation Compliance (Part 2) – Sean McAvinue
Hello ,
i am preparing for AZ-500 and i found your website.
thank you so much , there is a lot of documentation and each topic contains all the necessary details with screenshots.
Thank you for this amazing work and for your time.
LikeLike
Pingback: Study Guide Series – Exam MS-700: Managing Microsoft Teams – Sean McAvinue