# Solving Microsoft 365 > An independent, plain-English knowledge base for Microsoft 365 administrators, consultants, and buyers — 428 guides on Entra ID, Intune, Defender, Purview, Teams, SharePoint, Exchange, Copilot, and licensing, plus a glossary and curated learning paths. Written by Emil Björk, a Microsoft ecosystem consultant in Gothenburg, Sweden. No ads, no sponsorship. Every guide has a stable URL, a publication and review date, and a Further reading block pointing at Microsoft Learn. Guides state opinions and give recommendations; they are not Microsoft documentation. Prices quoted are list prices with an as-of date. ## Site map and machine-readable resources - [Sitemap](https://www.solvingmicrosoft365.com/sitemap.xml): every guide, glossary term, category, and path with lastModified dates - [Full content](https://www.solvingmicrosoft365.com/llms-full.txt): every guide in full, plain Markdown - Single-guide Markdown: append `.md` to any guide or glossary URL (e.g. `https://www.solvingmicrosoft365.com/guides/what-is-microsoft-365.md`), or send `Accept: text/markdown` to the HTML URL — either returns that one page as plain Markdown, no HTML - [All guides](https://www.solvingmicrosoft365.com/guides): index grouped by product - [Glossary](https://www.solvingmicrosoft365.com/glossary): short definitions of Microsoft 365 terms - [Learning paths](https://www.solvingmicrosoft365.com/paths): ordered reading lists by role - [Licensing calculator](https://www.solvingmicrosoft365.com/tools/licensing-calculator): seat mix to annual list cost, client-side - [Admin cheat sheet](https://www.solvingmicrosoft365.com/tools/admin-cheat-sheet): every PowerShell and KQL snippet from the guides, each linked to its source guide - [Comparison matrix](https://www.solvingmicrosoft365.com/comparisons): every "X vs Y" guide in one table, Microsoft vs competitor and within Microsoft - [Certification study paths](https://www.solvingmicrosoft365.com/certifications): reading orders for MS-900, MS-102, MD-102, MS-700, MS-721, SC-900, SC-300, SC-200, SC-401, SC-100 - [What's new](https://www.solvingmicrosoft365.com/changelog): every guide published or reviewed, newest first; also as [RSS](https://www.solvingmicrosoft365.com/feed.xml) - [Common questions](https://www.solvingmicrosoft365.com/q): direct answers to Microsoft 365 licensing and capability decisions, one page per question - [Topics](https://www.solvingmicrosoft365.com/topics): guides grouped by cross-product concept (Conditional Access, Autopilot, sensitivity labels...), a second axis alongside the product categories - [Reference](https://www.solvingmicrosoft365.com/reference): structured reference data, starting with a [retirements tracker](https://www.solvingmicrosoft365.com/reference/retirements) and its [ICS feed](https://www.solvingmicrosoft365.com/reference/retirements/feed.ics) - [About the author](https://www.solvingmicrosoft365.com/about) ## Flagship guides - [What is Microsoft 365?](https://www.solvingmicrosoft365.com/guides/what-is-microsoft-365): What Microsoft 365 is: what's in the suite, who each plan is for, how the pieces fit together, and what changed since the Office 365 days. - [Microsoft 365 plans and pricing](https://www.solvingmicrosoft365.com/guides/microsoft-365-plans-and-pricing): Microsoft 365 plans and pricing, made navigable: Business Premium for SMB, E3 plus add-ons for enterprise, E5 when you'll use it — with every comparison. - [Microsoft 365 E3 vs E5 — what's worth the upgrade](https://www.solvingmicrosoft365.com/guides/microsoft-365-plan-comparison-e3-vs-e5): A practical comparison of Microsoft 365 E3 and E5 plans — what E5 adds, where the value sits, and step-up patterns. - [Business Premium vs Microsoft 365 E3](https://www.solvingmicrosoft365.com/guides/microsoft-365-business-premium-vs-e3): Business Premium vs Microsoft 365 E3: Premium wins on security for less money, E3 wins on mailboxes, Windows, and scale. How to choose, and how to mix them. - [Microsoft 365 Copilot licensing](https://www.solvingmicrosoft365.com/guides/microsoft-365-copilot-licensing): Microsoft 365 Copilot licensing without the marketing: eligible SKUs, how the add-on works, the free and paid Copilot Chat tiers, and the trade-offs. - [What is Microsoft 365 Copilot?](https://www.solvingmicrosoft365.com/guides/what-is-microsoft-copilot-for-m365): What Microsoft 365 Copilot is: what it does in Word, Excel, Outlook, and Teams, how grounding works, what it costs, and what to fix before rollout. - [What is Microsoft Entra ID?](https://www.solvingmicrosoft365.com/guides/what-is-microsoft-entra-id): What Microsoft Entra ID is: the identity service behind every Microsoft 365 sign-in, how it relates to Active Directory, and the licensing tiers that matter. - [Entra ID Conditional Access design](https://www.solvingmicrosoft365.com/guides/entra-id-conditional-access-design): Designing a Conditional Access baseline: the policies, the principles, the order to write them in, and the habits that keep the estate healthy. - [The Entra Suite explained](https://www.solvingmicrosoft365.com/guides/entra-suite-explained): Entra Suite explained: Internet Access, Private Access, Verified ID, ID Governance, and Identity Protection in one licence — what each does and when it pays. - [Which Microsoft Defender is which](https://www.solvingmicrosoft365.com/guides/microsoft-defender-products-explained): Which Microsoft Defender is which: Endpoint, Office 365, Identity, Cloud Apps, Business, XDR, Cloud, Antivirus — what each does and which licence gets it. - [Microsoft Defender for Endpoint explained](https://www.solvingmicrosoft365.com/guides/defender-for-endpoint-explained): Defender for Endpoint is Microsoft's EDR/XDR platform for laptops, servers, and mobile. Here's what it does. - [What is Microsoft Purview?](https://www.solvingmicrosoft365.com/guides/what-is-microsoft-purview): What Microsoft Purview is: labels, DLP, retention, eDiscovery, insider risk, and the data-governance catalogue — how the two halves differ and where to start. - [Microsoft Purview sensitivity labels — a deep dive](https://www.solvingmicrosoft365.com/guides/purview-sensitivity-labels-deep-dive): How Purview sensitivity labels classify and protect content, how to design a taxonomy that survives contact with users, and the rollout order that works. - [Microsoft Intune and device management](https://www.solvingmicrosoft365.com/guides/microsoft-intune-and-device-management): Microsoft Intune explained: what it manages, how policies work, how enrollment and compliance fit together, and where it sits in Microsoft 365. - [The Intune Suite explained](https://www.solvingmicrosoft365.com/guides/intune-suite-explained): Intune Suite explained: Endpoint Privilege Management, Remote Help, Advanced Analytics, Enterprise App Management, Tunnel, Cloud PKI — and when it pays. - [Intune Windows Autopilot](https://www.solvingmicrosoft365.com/guides/intune-windows-autopilot): Windows Autopilot provisions new PCs straight to the end user with zero IT touch. Here's how it works. - [What is Microsoft Teams?](https://www.solvingmicrosoft365.com/guides/what-is-microsoft-teams): What Microsoft Teams is: chat, meetings, telephony, and collaboration in Microsoft 365, how it fits the platform, the licensing shape, and running it well. - [Microsoft Teams Phone](https://www.solvingmicrosoft365.com/guides/microsoft-teams-phone): Microsoft Teams Phone explained: what you get, the licensing, and the decision that shapes everything — Calling Plans vs Operator Connect vs Direct Routing. - [Microsoft Teams Rooms](https://www.solvingmicrosoft365.com/guides/microsoft-teams-rooms): Microsoft Teams Rooms explained: what the hardware does, Windows vs Android, Basic vs Pro licensing, and the operating rhythm that keeps a fleet healthy. - [What is SharePoint?](https://www.solvingmicrosoft365.com/guides/what-is-sharepoint): What SharePoint is: the platform behind Microsoft 365 file storage, team sites, intranets, Teams, and OneDrive — how it works and how to run it well. - [What is OneDrive?](https://www.solvingmicrosoft365.com/guides/what-is-onedrive): What OneDrive is: the personal file layer of Microsoft 365, how sync and Known Folder Move work, the OneDrive-vs-SharePoint rule, and what admins control. - [What is Exchange Online?](https://www.solvingmicrosoft365.com/guides/what-is-exchange-online): What Exchange Online is: Microsoft 365's cloud email and calendaring, how it fits the platform, the security and compliance layers, and running it well. - [External collaboration in Microsoft 365, explained](https://www.solvingmicrosoft365.com/guides/microsoft-365-external-collaboration-explained): B2B guests, Teams external access, shared channels, SharePoint links, cross-tenant sync: what each layer does, how they stack, and which to use when. - [Microsoft 365 vs Google Workspace](https://www.solvingmicrosoft365.com/guides/microsoft-365-vs-google-workspace): Microsoft 365 vs Google Workspace compared without marketing: feature by feature, where each wins, where it doesn't matter, and how the decision gets made. - [Windows 365 explained](https://www.solvingmicrosoft365.com/guides/windows-365-explained): What Windows 365 is: how Cloud PCs work, the licensing tiers, how it connects to Intune and Entra ID, and when it beats AVD or a physical laptop. - [Microsoft Fabric explained](https://www.solvingmicrosoft365.com/guides/microsoft-fabric-explained): What Microsoft Fabric actually is beyond "Power BI Premium rebranded" — OneLake, the workloads, F-SKU licensing vs the old P-SKUs, and where Azure Synapse fits. - [Setting up Microsoft 365 from scratch](https://www.solvingmicrosoft365.com/guides/setting-up-microsoft-365-from-scratch): The setup order for a brand-new Microsoft 365 tenant — tenant, domain, identity, security baseline, then data and clients. Sequence matters more than speed. - [Microsoft 365 backup and recovery](https://www.solvingmicrosoft365.com/guides/microsoft-365-backup-and-recovery): What Microsoft 365 protects natively, what it doesn't, and how to design backup for Exchange, OneDrive, SharePoint, and Teams — native Backup vs third party. - [Compromised Microsoft 365 account response runbook](https://www.solvingmicrosoft365.com/guides/entra-id-compromised-account-runbook): Compromised Microsoft 365 account runbook: what to run in the first fifteen minutes, what to check in the first hour, and when it is safe to hand it back. - [DMARC rollout from p=none to p=reject](https://www.solvingmicrosoft365.com/guides/dmarc-rollout): How to roll out DMARC enforcement progressively — the journey from monitoring to enforced anti-spoofing. ## Comparisons - [SharePoint vs Confluence](https://www.solvingmicrosoft365.com/guides/sharepoint-vs-confluence): SharePoint vs Confluence for the intranet and team knowledge base: Confluence's wiki editing and Jira integration against SharePoint's Microsoft 365 governance. - [Purview vs Varonis](https://www.solvingmicrosoft365.com/guides/purview-vs-varonis): Microsoft Purview vs Varonis: Purview's native labels and DLP against Varonis's permissions analytics, automated remediation, and data-access detection. - [Purview vs Netskope](https://www.solvingmicrosoft365.com/guides/purview-vs-netskope): Microsoft Purview vs Netskope for data protection: native labelling and DLP inside Microsoft 365 against SSE-based DLP across every cloud app and the web. - [OneDrive vs Dropbox](https://www.solvingmicrosoft365.com/guides/onedrive-vs-dropbox): OneDrive vs Dropbox for business file sync and sharing: Dropbox's sync engine and simplicity against OneDrive's Microsoft 365 integration and governance. - [Microsoft Teams vs Zoom](https://www.solvingmicrosoft365.com/guides/microsoft-teams-vs-zoom): Microsoft Teams vs Zoom for meetings, webinars, rooms, and phone: Zoom's simplicity and reliability against Teams' suite integration and bundled price. - [Microsoft Teams vs Slack](https://www.solvingmicrosoft365.com/guides/microsoft-teams-vs-slack): Microsoft Teams vs Slack compared honestly: Slack's chat experience and integrations against Teams' meetings, telephony, Microsoft 365 governance, and price. - [Microsoft 365 E3 vs E5 — what's worth the upgrade](https://www.solvingmicrosoft365.com/guides/microsoft-365-plan-comparison-e3-vs-e5): A practical comparison of Microsoft 365 E3 and E5 plans — what E5 adds, where the value sits, and step-up patterns. - [Intune vs Workspace ONE](https://www.solvingmicrosoft365.com/guides/intune-vs-workspace-one): Intune vs Omnissa Workspace ONE (ex-VMware): Workspace ONE's cross-platform and rugged-device depth against Intune's Microsoft 365 integration and price. - [Intune vs Kandji](https://www.solvingmicrosoft365.com/guides/intune-vs-kandji): Intune vs Kandji for Apple device management: Kandji's opinionated Mac automation and Blueprints against Intune's bundled price and Microsoft 365 integration. - [Intune vs Jamf](https://www.solvingmicrosoft365.com/guides/intune-vs-jamf): Intune vs Jamf for managing Macs: where Jamf's Apple depth still wins, where Intune's bundle price and Conditional Access integration win, and when to run both. - [Entra ID vs Ping Identity](https://www.solvingmicrosoft365.com/guides/entra-id-vs-ping-identity): Entra ID vs Ping Identity (PingOne, PingFederate, ForgeRock): federation depth, hybrid deployment, and CIAM against Entra's bundled workforce identity. - [Entra ID vs Okta](https://www.solvingmicrosoft365.com/guides/entra-id-vs-okta): Entra ID vs Okta as the identity provider: Okta's neutrality and app-integration depth against Entra's Microsoft 365 bundling and Conditional Access. - [Defender for Endpoint vs SentinelOne](https://www.solvingmicrosoft365.com/guides/defender-for-endpoint-vs-sentinelone): Defender for Endpoint vs SentinelOne Singularity: autonomous response and rollback vs Microsoft XDR correlation, platform coverage, MSP fit, and licensing. - [Defender for Endpoint vs CrowdStrike](https://www.solvingmicrosoft365.com/guides/defender-for-endpoint-vs-crowdstrike): Defender for Endpoint vs CrowdStrike Falcon: detection quality, platform coverage, the SOC experience, licensing, and what the July 2024 outage changed. - [Teams webinars vs meetings: differences and licensing](https://www.solvingmicrosoft365.com/guides/teams-webinars-vs-meetings-and-licensing): Teams webinars vs meetings: registration, the presenter and attendee model, capacity, the standard vs Premium split, and whether your event is a webinar at all. - [Teams town hall vs live events vs Stream](https://www.solvingmicrosoft365.com/guides/teams-town-hall-vs-live-events-vs-stream): Teams town hall vs live events vs Stream: what replaced Live Events, what a town hall adds over a large meeting, the Premium split, and choosing for all-hands. - [Teams shared channels vs standard channels](https://www.solvingmicrosoft365.com/guides/teams-shared-channels-vs-standard-channels): Shared channel vs standard channel in Teams: membership model, where files live, what's missing in shared channels, B2B direct connect, and a rule of thumb. - [Microsoft Planner premium vs Project for the web](https://www.solvingmicrosoft365.com/guides/microsoft-planner-premium-vs-project-for-the-web): How Project for the web became premium Planner: what a premium plan adds, Planner and Project Plan 1/3/5 licensing, and where Project Online still fits. - [Copilot grounding vs SharePoint search](https://www.solvingmicrosoft365.com/guides/copilot-grounding-vs-sharepoint-search): Why Copilot finds documents SharePoint search doesn't: the semantic index, how Copilot retrieval differs from Microsoft Search, oversharing, and the controls. - [New Outlook vs classic Outlook on Windows](https://www.solvingmicrosoft365.com/guides/outlook-new-vs-classic-on-windows): New Outlook vs classic Outlook on Windows: what actually changes, what still doesn't work, and how to run the migration without a user revolt. - [Entra Connect vs Entra Cloud Sync](https://www.solvingmicrosoft365.com/guides/entra-connect-vs-cloud-sync): The two ways to sync on-prem Active Directory to Entra ID — what each does, the scenarios that still force the old tool, and which to use today. - [Business Premium vs Microsoft 365 E3](https://www.solvingmicrosoft365.com/guides/microsoft-365-business-premium-vs-e3): Business Premium vs Microsoft 365 E3: Premium wins on security for less money, E3 wins on mailboxes, Windows, and scale. How to choose, and how to mix them. - [Windows 365 vs AVD: a real cost comparison](https://www.solvingmicrosoft365.com/guides/windows-365-vs-avd-cost): Windows 365 vs Azure Virtual Desktop cost, worked for task worker, knowledge worker, and developer patterns — with the assumptions behind the numbers. - [Microsoft 365 vs Google Workspace](https://www.solvingmicrosoft365.com/guides/microsoft-365-vs-google-workspace): Microsoft 365 vs Google Workspace compared without marketing: feature by feature, where each wins, where it doesn't matter, and how the decision gets made. - [Windows 365 vs Azure Virtual Desktop](https://www.solvingmicrosoft365.com/guides/windows-365-vs-azure-virtual-desktop): Microsoft's two cloud-hosted Windows products — what each is for and how to choose. - [SharePoint team sites vs communication sites](https://www.solvingmicrosoft365.com/guides/sharepoint-team-sites-vs-communication-sites): The two main SharePoint site types — what each is for, and how to pick. - [SharePoint Lists vs Microsoft Lists](https://www.solvingmicrosoft365.com/guides/sharepoint-lists-vs-microsoft-lists): SharePoint lists, Microsoft Lists, Dataverse, Excel — picking the right place for structured data. - [Purview eDiscovery — standard vs premium](https://www.solvingmicrosoft365.com/guides/purview-ediscovery-standard-vs-premium): How Purview eDiscovery finds, preserves, and exports content for legal cases — and what premium adds. - [Power BI Pro vs Premium Per User vs Fabric capacity](https://www.solvingmicrosoft365.com/guides/power-bi-pro-vs-ppu-vs-fabric): Choosing between Power BI licensing tiers — Pro, PPU, and Microsoft Fabric capacity for different scenarios. - [Power Apps — canvas vs model-driven](https://www.solvingmicrosoft365.com/guides/power-apps-canvas-vs-model-driven): The two main Power Apps types — what each is good at, and how to pick. - [OneDrive for Business vs OneDrive (personal)](https://www.solvingmicrosoft365.com/guides/onedrive-for-business-vs-personal): Two products, one name — the differences between work and consumer OneDrive, and why mixing them is a bad idea. - [Viva Engage vs Yammer](https://www.solvingmicrosoft365.com/guides/microsoft-viva-engage-vs-yammer): Viva Engage is the rebranded and refactored Yammer. Here's what changed and what didn't. - [Private vs shared channels in Microsoft Teams](https://www.solvingmicrosoft365.com/guides/microsoft-teams-private-vs-shared-channels): When to reach for a private channel versus a shared channel — the membership model, storage, and external-access trade-offs. - [Microsoft 365 vs on-premises Office](https://www.solvingmicrosoft365.com/guides/microsoft-365-vs-on-premises-office): Comparing Microsoft 365 to a traditional on-premises Office, Exchange, and SharePoint estate — and why the on-prem case is shrinking. - [Microsoft 365 vs Microsoft 365 Government](https://www.solvingmicrosoft365.com/guides/microsoft-365-vs-microsoft-365-government): Microsoft 365 Government (GCC, GCC High, DoD) is a separate sovereign cloud for US public sector. Here's the difference. - [Microsoft 365 Groups vs Teams vs SharePoint sites](https://www.solvingmicrosoft365.com/guides/m365-groups-vs-teams-vs-sharepoint): Three closely-related concepts that confuse a lot of users. Here's the model. - [Entra External ID vs Azure AD B2C](https://www.solvingmicrosoft365.com/guides/entra-external-id-vs-b2c): Microsoft has two products for customer identity. Here's the difference and which to pick today. - [Distribution lists vs Microsoft 365 Groups](https://www.solvingmicrosoft365.com/guides/distribution-lists-vs-microsoft-365-groups): How DLs, mail-enabled security groups, and Microsoft 365 Groups differ — and when to use each. ## How-to guides (Prerequisites → Steps → Verify → Roll back) - [How to set up PIM for the Global Administrator role](https://www.solvingmicrosoft365.com/guides/how-to-set-up-pim-for-global-administrator): How to set up Privileged Identity Management for Global Administrator in Entra ID: role settings, convert permanent admins to eligible, approvals, and alerts. - [How to set up DKIM for a custom domain in Microsoft 365](https://www.solvingmicrosoft365.com/guides/how-to-set-up-dkim-for-a-custom-domain-in-microsoft-365): How to set up DKIM signing for a custom domain in Microsoft 365: the two CNAME records, enabling it in Defender, key rotation, and checking headers. - [How to search the audit log in Microsoft Purview](https://www.solvingmicrosoft365.com/guides/how-to-search-the-audit-log-in-microsoft-purview): How to search the Microsoft 365 unified audit log in Purview: check it's on, search by activity, user, and date, export, and Search-UnifiedAuditLog at scale. - [How to restrict external sharing for a SharePoint site](https://www.solvingmicrosoft365.com/guides/how-to-restrict-external-sharing-for-a-sharepoint-site): How to restrict external sharing for a SharePoint site: tenant vs site levels, the four sharing settings, default link type, guest expiration, removing guests. - [How to restore a deleted user in Microsoft 365](https://www.solvingmicrosoft365.com/guides/how-to-restore-a-deleted-user-in-microsoft-365): How to restore a deleted user in Microsoft 365 within the 30-day window: admin center and Graph routes, UPN conflicts, what comes back, and after 30 days. - [How to reset MFA for a user in Entra ID](https://www.solvingmicrosoft365.com/guides/how-to-reset-mfa-for-a-user-in-entra-id): How to reset a user's MFA in Entra ID when they have a new phone or lost their authenticator: re-register, revoke sessions, and issue a Temporary Access Pass. - [How to require MFA for all users with Conditional Access](https://www.solvingmicrosoft365.com/guides/how-to-require-mfa-for-all-users-with-conditional-access): How to require MFA for all users in Entra ID with Conditional Access: the exclusions that matter, report-only rollout, registration campaign, enforcement. - [How to require compliant devices with Conditional Access](https://www.solvingmicrosoft365.com/guides/how-to-require-compliant-devices-with-conditional-access): How to require a compliant or hybrid-joined device with Conditional Access: the Intune compliance policy first, the grant control, exclusions, report-only. - [How to remote wipe a lost device with Intune](https://www.solvingmicrosoft365.com/guides/how-to-remote-wipe-a-lost-device-with-intune): How to remote wipe a lost device with Intune: Wipe vs Retire vs selective wipe, triggering the action, what happens while offline, and BitLocker recovery keys. - [How to register devices for Windows Autopilot](https://www.solvingmicrosoft365.com/guides/how-to-register-devices-for-windows-autopilot): How to register devices for Windows Autopilot: OEM registration, the hardware-hash CSV route, group tags, dynamic groups, and the deployment profile assignment. - [How to put a mailbox on litigation hold](https://www.solvingmicrosoft365.com/guides/how-to-put-a-mailbox-on-litigation-hold): How to put a mailbox on litigation hold in Exchange Online: licence check, enabling the hold with a duration, what it preserves, and releasing it correctly. - [How to publish sensitivity labels in Microsoft Purview](https://www.solvingmicrosoft365.com/guides/how-to-publish-sensitivity-labels-in-microsoft-purview): How to publish sensitivity labels in Microsoft Purview: create the label set, configure encryption and marking, publish a label policy, set defaults, pilot. - [How to offboard a user in Microsoft 365](https://www.solvingmicrosoft365.com/guides/how-to-offboard-a-user-in-microsoft-365): How to offboard a user in Microsoft 365: block sign-in, revoke sessions, handle the mailbox and OneDrive, wipe devices, remove licences, delete on schedule. - [How to enable self-service password reset in Entra ID](https://www.solvingmicrosoft365.com/guides/how-to-enable-self-service-password-reset-in-entra-id): How to enable self-service password reset in Entra ID: scope, methods, registration enforcement, password writeback for hybrid, and Windows lock-screen reset. - [How to enable Microsoft 365 Copilot for a pilot group](https://www.solvingmicrosoft365.com/guides/how-to-enable-microsoft-365-copilot-for-a-pilot-group): How to enable Microsoft 365 Copilot for a pilot group: licence prerequisites, the oversharing check, group-based assignment, Teams settings, what to measure. - [How to enable guest access in Microsoft Teams](https://www.solvingmicrosoft365.com/guides/how-to-enable-guest-access-in-microsoft-teams): How to enable guest access in Microsoft Teams: the four switches (Entra, Microsoft 365 groups, Teams, SharePoint), guest permissions, domain lists, testing. - [How to deploy a Win32 app with Intune](https://www.solvingmicrosoft365.com/guides/how-to-deploy-a-win32-app-with-intune): How to deploy a Win32 app with Intune: wrap the installer into an .intunewin, set install and uninstall commands, detection rules, requirements, and assign it. - [How to create a retention policy in Microsoft Purview](https://www.solvingmicrosoft365.com/guides/how-to-create-a-retention-policy-in-microsoft-purview): How to create a retention policy in Microsoft Purview: static or adaptive scope, locations, retain-then-delete settings, and rolling it out without surprises. - [How to create a DLP policy in Microsoft Purview](https://www.solvingmicrosoft365.com/guides/how-to-create-a-dlp-policy-in-microsoft-purview): How to create a DLP policy in Microsoft Purview for card and personal data: locations, sensitive info types, rules and actions, simulation mode, enforcement. - [How to create a break-glass account in Entra ID](https://www.solvingmicrosoft365.com/guides/how-to-create-a-break-glass-account-in-entra-id): How to create an emergency access (break-glass) account in Entra ID: cloud-only, permanent Global Admin, excluded from Conditional Access, FIDO2 keys, alerting. - [How to convert a user mailbox to a shared mailbox](https://www.solvingmicrosoft365.com/guides/how-to-convert-a-user-mailbox-to-a-shared-mailbox): How to convert a user mailbox to a shared mailbox in Exchange Online, when it's the right leaver move, the 50 GB and hold rules, and removing the licence. - [How to bulk-assign Intune configuration profiles](https://www.solvingmicrosoft365.com/guides/how-to-bulk-assign-intune-configuration-profiles): How to bulk-assign Intune configuration profiles: assignment groups, filters, All devices vs All users, exclusions, and a Graph script for many profiles. - [How to block legacy authentication with Conditional Access](https://www.solvingmicrosoft365.com/guides/how-to-block-legacy-authentication-with-conditional-access): How to block legacy authentication in Entra ID with Conditional Access: find who still uses it, build the block policy, run report-only, then enforce. - [How to block a compromised account in Microsoft 365](https://www.solvingmicrosoft365.com/guides/how-to-block-a-compromised-account-in-microsoft-365): How to block a compromised Microsoft 365 account in ten minutes: disable sign-in, revoke sessions, reset password and MFA, kill inbox rules and forwarding. - [Assigning licenses with group-based licensing in Entra ID](https://www.solvingmicrosoft365.com/guides/how-to-assign-licenses-with-group-based-licensing-in-entra-id): How to assign Microsoft 365 licences with group-based licensing in Entra ID: build the groups, set usage location, migrate direct assignments, fix errors. ## Learning paths - [Entra ID from scratch](https://www.solvingmicrosoft365.com/paths/entra-id-fundamentals): Identity is the plane every other Microsoft 365 decision runs through. This path walks the concepts, the join model, and the operational patterns. - [Microsoft 365 Copilot rollout](https://www.solvingmicrosoft365.com/paths/microsoft-365-copilot-rollout): The order of operations for a Copilot rollout that lands: data readiness first, licensing, permissions, adoption, and measurement. - [Microsoft Defender and XDR](https://www.solvingmicrosoft365.com/paths/defender-and-xdr): What each Defender product actually protects, how the XDR story ties them together, and where to hunt when something breaks. - [Purview information protection](https://www.solvingmicrosoft365.com/paths/purview-information-protection): Sensitivity labels, DLP, retention, records — the pieces that make information governance actually enforceable in Microsoft 365. - [Intune endpoint management](https://www.solvingmicrosoft365.com/paths/intune-endpoint-management): Enroll, secure and update Windows, macOS, Android and iOS devices with Intune. Application delivery and endpoint analytics included. - [SharePoint and OneDrive fundamentals](https://www.solvingmicrosoft365.com/paths/sharepoint-and-onedrive-fundamentals): How the content stack actually works — permissions, information architecture, sharing model, and the migration story. - [Teams admin foundations](https://www.solvingmicrosoft365.com/paths/teams-admin-foundations): The operational Teams stack — meeting and messaging policies, calling and Direct Routing, Rooms, external collaboration and premium features. - [Exchange Online admin foundations](https://www.solvingmicrosoft365.com/paths/exchange-online-admin-foundations): The Exchange half of every M365 tenant — mail flow, hybrid, protection, archiving, and the pieces that keep messages moving correctly. - [Choosing your Microsoft 365 licence](https://www.solvingmicrosoft365.com/paths/choosing-your-microsoft-365-licence): From the plan landscape to a defensible licensing decision — the SMB fork, the E3 vs E5 fork, Copilot, and the suites that change the maths. - [Power Platform governance from scratch](https://www.solvingmicrosoft365.com/paths/power-platform-governance): Power Platform grows in your tenant whether you govern it or not. This path goes from what the tools are to environments, DLP, licensing, and a CoE. - [Power BI for the M365 admin](https://www.solvingmicrosoft365.com/paths/power-bi-for-the-m365-admin): The Power BI decisions that land on the M365 admin's desk — licensing, workspaces, semantic models, row-level security, and deployment pipelines. ## Certification study paths - [MS-900: Microsoft 365 Fundamentals](https://www.solvingmicrosoft365.com/certifications/ms-900): Microsoft 365 Certified: Fundamentals; 25 guides in reading order - [MS-102: Microsoft 365 Administrator](https://www.solvingmicrosoft365.com/certifications/ms-102): Microsoft 365 Certified: Administrator Expert; 36 guides in reading order - [MD-102: Endpoint Administrator](https://www.solvingmicrosoft365.com/certifications/md-102): Microsoft 365 Certified: Endpoint Administrator Associate; 28 guides in reading order - [MS-700: Managing Microsoft Teams](https://www.solvingmicrosoft365.com/certifications/ms-700): Microsoft 365 Certified: Teams Administrator Associate; 24 guides in reading order - [MS-721: Collaboration Communications Systems Engineer](https://www.solvingmicrosoft365.com/certifications/ms-721): Microsoft 365 Certified: Collaboration Communications Systems Engineer Associate; 16 guides in reading order - [SC-900: Microsoft Security, Compliance, and Identity Fundamentals](https://www.solvingmicrosoft365.com/certifications/sc-900): Microsoft Certified: Security, Compliance, and Identity Fundamentals; 21 guides in reading order - [SC-300: Microsoft Identity and Access Administrator](https://www.solvingmicrosoft365.com/certifications/sc-300): Microsoft Certified: Identity and Access Administrator Associate; 37 guides in reading order - [SC-200: Microsoft Security Operations Analyst](https://www.solvingmicrosoft365.com/certifications/sc-200): Microsoft Certified: Security Operations Analyst Associate; 25 guides in reading order - [SC-401: Administering Information Security in Microsoft 365](https://www.solvingmicrosoft365.com/certifications/sc-401): Microsoft Certified: Information Security Administrator Associate; 21 guides in reading order - [SC-100: Microsoft Cybersecurity Architect](https://www.solvingmicrosoft365.com/certifications/sc-100): Microsoft Certified: Cybersecurity Architect Expert; 26 guides in reading order ## Topics - [Microsoft 365 Copilot](https://www.solvingmicrosoft365.com/guides/category/copilot): Rollout, prompt patterns, agents, and governance. (40 guides) - [Power Platform](https://www.solvingmicrosoft365.com/guides/category/power-platform): Power Apps, Power Automate, Power BI, Power Pages, and Dataverse. (27 guides) - [Microsoft Teams](https://www.solvingmicrosoft365.com/guides/category/teams): Meetings, channels, Teams Phone, Rooms, and policies. (40 guides) - [SharePoint & OneDrive](https://www.solvingmicrosoft365.com/guides/category/sharepoint-onedrive): File collaboration, sites, libraries, sync, and Syntex. (39 guides) - [Exchange & Outlook](https://www.solvingmicrosoft365.com/guides/category/exchange-outlook): Email, calendars, mail flow, and Outlook clients. (27 guides) - [Microsoft Entra (Identity)](https://www.solvingmicrosoft365.com/guides/category/identity): Identity, authentication, Conditional Access, PIM, and governance. (58 guides) - [Microsoft Defender (Security)](https://www.solvingmicrosoft365.com/guides/category/security): Defender XDR, Endpoint, Office 365, Identity, and Sentinel. (34 guides) - [Microsoft Purview (Compliance)](https://www.solvingmicrosoft365.com/guides/category/compliance): Labels, DLP, retention, eDiscovery, audit, and records management. (24 guides) - [Microsoft Intune (Devices)](https://www.solvingmicrosoft365.com/guides/category/intune-devices): Endpoint management, Autopilot, app deployment, mobile, and Cloud PC. (32 guides) - [Viva & Apps](https://www.solvingmicrosoft365.com/guides/category/viva-apps): Microsoft Viva, Loop, Bookings, Forms, Stream, Whiteboard, Planner. (24 guides) - [Developer & APIs](https://www.solvingmicrosoft365.com/guides/category/developer): Microsoft Graph, SPFx, Office add-ins, custom apps, and integrations. (5 guides) - [Migration & Tenants](https://www.solvingmicrosoft365.com/guides/category/migration): Migrations, M&A, multi-tenant, rebrands, and cross-tenant scenarios. (11 guides) - [Microsoft 365 essentials](https://www.solvingmicrosoft365.com/guides/category/microsoft-365): Plans, admin, governance, network, adoption, and strategy. (67 guides) ## Common questions - [Does Microsoft 365 Business Premium include Intune?](https://www.solvingmicrosoft365.com/q/does-business-premium-include-intune): Yes. Microsoft 365 Business Premium includes Microsoft Intune for device and app management, alongside Entra ID P1, Defender for Business, and the Office desktop apps. The 300-seat cap on the plan itself is the practical limit, not an Intune feature limit. - [Do I need Microsoft 365 E5 for Conditional Access?](https://www.solvingmicrosoft365.com/q/do-i-need-e5-for-conditional-access): No. Conditional Access needs Microsoft Entra ID P1, which is included in Microsoft 365 E3, Business Premium, and the F3 frontline plan. E5 adds Entra ID P2, which unlocks sign-in-risk and user-risk conditions via Identity Protection, plus Privileged Identity Management and access reviews. - [Is Defender for Endpoint included in Microsoft 365 E3?](https://www.solvingmicrosoft365.com/q/is-defender-for-endpoint-included-in-microsoft-365-e3): No. Microsoft 365 E3 does not include Defender for Endpoint. It is included in Microsoft 365 E5, in the E5 Security add-on that sits on top of E3, or as a Defender for Endpoint Plan 1 or Plan 2 standalone per-user licence. - [Does Microsoft 365 E5 include Power BI Pro?](https://www.solvingmicrosoft365.com/q/does-microsoft-365-e5-include-power-bi-pro): Yes. Microsoft 365 E5 includes a Power BI Pro licence per user. Microsoft 365 E3 does not — E3 users need a Power BI Pro or Power BI Premium Per User (PPU) add-on, or the workspace they consume must be backed by a Fabric F-SKU capacity that grants free-user consumption. - [How many external guests can I add to a Microsoft 365 tenant?](https://www.solvingmicrosoft365.com/q/how-many-external-guests-can-i-add-to-microsoft-365): Entra ID allows up to 50,000 external user objects per paid Entra ID licence assigned in the tenant, which puts the ceiling far above what most organisations ever need. The practical limit is governance — access packages, sponsors, reviews, and lifecycle — not the SKU. - [Can I mix Microsoft 365 E3 and E5 in the same tenant?](https://www.solvingmicrosoft365.com/q/can-i-mix-e3-and-e5-in-the-same-tenant): Yes. Microsoft 365 plans are per-user licences, not tenant-level SKUs, so E3, E5, F1, F3, and Business Premium can all coexist in the same tenant. Tenant-scoped services (Purview policies, Sentinel connectors, Defender features) run at the level supported by the licensed users touching them. - [Does Microsoft 365 Copilot need a separate Microsoft 365 licence?](https://www.solvingmicrosoft365.com/q/does-copilot-need-a-separate-microsoft-365-licence): Yes. Microsoft 365 Copilot is a per-user add-on that requires an eligible base licence: Microsoft 365 E3, E5, Business Standard, or Business Premium (Office 365 E3/E5 also qualify). It cannot be bought on its own or on frontline F1/F3 plans. - [Is Entra ID P2 worth it over P1?](https://www.solvingmicrosoft365.com/q/is-entra-id-p2-worth-it-over-p1): Entra ID P2 is worth it when Identity Protection risk-based Conditional Access, Privileged Identity Management for admin roles, access reviews, or Entitlement Management access packages are part of the operating model. Where those are not yet in scope, P1 covers the everyday Conditional Access, MFA, and self-service password reset needs. - [Can I use Intune without Entra ID P1?](https://www.solvingmicrosoft365.com/q/can-i-use-intune-without-entra-id-p1): Yes for basic Intune device management, no for the enforcement mechanism most deployments actually rely on. Intune enrollment and configuration profiles work with the free Entra ID tier that ships with any Microsoft 365 subscription, but Conditional Access — which is how Intune compliance signals gate access to Microsoft 365 — needs Entra ID P1. - [Does Microsoft Purview work with Google Workspace?](https://www.solvingmicrosoft365.com/q/does-purview-work-with-google-workspace): Partially. Microsoft Purview eDiscovery, DLP, and Insider Risk Management have connectors that ingest Google Workspace mail, drive, and chat as a third-party data source for discovery and DLP. Sensitivity labels only apply to Microsoft file formats and PDF; they do not label native Google Docs, Sheets, or Slides in place. - [What is the difference between Teams Essentials and Teams in Microsoft 365?](https://www.solvingmicrosoft365.com/q/whats-the-difference-between-teams-essentials-and-teams-in-microsoft-365): Teams Essentials is a standalone Teams subscription for small businesses — chat, meetings, calling, and file sharing without a full Microsoft 365 tenant. Teams inside Microsoft 365 Business or Enterprise is tenant-integrated: it runs on the tenant's Entra ID, uses SharePoint for files and Exchange for calendars, and honours Conditional Access, DLP, and every other tenant policy. - [Does Microsoft 365 back up my data?](https://www.solvingmicrosoft365.com/q/does-microsoft-365-backup-my-data): Not in the traditional backup sense. Microsoft 365 provides item retention, recycle bins, versioning, and preservation policies that recover from deletion or corruption inside the service, but it does not provide the point-in-time restore of a full mailbox, SharePoint site, or OneDrive that a backup product delivers. Microsoft 365 Backup is a Microsoft add-on that fills the gap for a per-GB fee; third parties (Veeam, Commvault, Barracuda, AvePoint, Rubrik, HYCU, Keepit, Redstor) do the same. - [Do I need Teams Premium for webinars?](https://www.solvingmicrosoft365.com/q/do-i-need-teams-premium-for-webinars): No. Standard Microsoft Teams supports webinars up to 1,000 attendees with registration, reminders, and reporting. Teams Premium adds advanced webinar features (custom registration pages, green room, RTMP-out, presenter bios, view-only broadcasts up to 10,000 attendees), plus meeting-side features like watermarking and end-to-end encryption. - [Does Microsoft 365 comply with GDPR?](https://www.solvingmicrosoft365.com/q/does-microsoft-365-comply-with-gdpr): Microsoft 365 provides the controls needed for a GDPR-compliant deployment and Microsoft signs the standard EU Data Protection Addendum as a data processor. Compliance itself is a shared responsibility: Microsoft runs the platform in line with its commitments, and the tenant is the data controller responsible for configuring retention, DSAR handling, DPIA records, and lawful basis for the data it stores. - [Can I block Copilot from specific users or content in Microsoft 365?](https://www.solvingmicrosoft365.com/q/can-i-block-copilot-for-specific-users-or-content): Yes on both counts. Copilot access is controlled per user by assigning or removing the Microsoft 365 Copilot licence. Content exclusion uses sensitivity labels that block Copilot processing, SharePoint Restricted Content Discovery, and specific Copilot-scoped exclusion controls in Purview. - [What is the difference between Microsoft 365 and Office 365?](https://www.solvingmicrosoft365.com/q/whats-the-difference-between-microsoft-365-and-office-365): Office 365 is the productivity workload — Exchange Online, SharePoint, OneDrive, Teams, and the Office apps. Microsoft 365 is Office 365 bundled with Windows 10/11 Enterprise use rights, Entra ID (P1 in E3, P2 in E5), Microsoft Intune, and the security and compliance add-ons (Defender for Endpoint, Purview premium, PIM, Identity Protection at the E5 tier). - [Do I need a third-party backup for Microsoft 365?](https://www.solvingmicrosoft365.com/q/do-i-need-a-third-party-backup-for-microsoft-365): Usually yes, either Microsoft 365 Backup (the Microsoft add-on) or a third-party backup product. Microsoft 365 provides retention, versioning, and 93-day recycle bins that recover from routine deletion; it does not provide the point-in-time restore of a full mailbox, site, or OneDrive that most compliance frameworks and ransomware playbooks require. - [Does Microsoft 365 E3 include Copilot?](https://www.solvingmicrosoft365.com/q/does-microsoft-365-e3-include-copilot): No. Microsoft 365 Copilot is licensed as a standalone per-user add-on layered on top of an existing Microsoft 365 E3, E5, Business Standard, or Business Premium seat — it is not bundled into any base plan. E3 gives you the eligibility to buy Copilot; it does not give you Copilot itself. - [How long does a Microsoft 365 tenant-to-tenant migration take?](https://www.solvingmicrosoft365.com/q/how-long-does-a-tenant-to-tenant-migration-take): Three to nine months for a mid-sized organisation, covering discovery and design, identity and domain planning, mailbox and file migration in waves, Teams and SharePoint migration, device re-enrolment, and cutover. Small tenants move faster; the domain move — which requires a real cutover window — is the fixed constraint no tooling removes entirely. - [Can I migrate from Google Workspace to Microsoft 365 without downtime?](https://www.solvingmicrosoft365.com/q/can-i-migrate-from-google-workspace-without-downtime): Not with zero disruption, but close. Mailbox and file content can be migrated ahead of time while Google Workspace stays live, so the actual cutover is just the MX record change and final delta sync — typically a window of minutes to a few hours, scheduled outside working hours, rather than a multi-day blackout. - [Can I roll out Microsoft 365 Copilot to only some users?](https://www.solvingmicrosoft365.com/q/can-i-roll-out-copilot-to-only-some-users): Yes. Copilot licences are assigned per user (directly or through a security group), and a pilot group is the recommended starting point rather than a tenant-wide switch-on. Restricting the rollout to a pilot group is standard practice, not a workaround. - [Does SharePoint Embedded need its own licence?](https://www.solvingmicrosoft365.com/q/does-sharepoint-embedded-need-its-own-licence): Yes. SharePoint Embedded is a separate, consumption-based offering for developers building file storage into their own applications — it is billed by usage (storage and API calls) through Azure, not included in standard Microsoft 365 or SharePoint Online per-user licensing. - [Is Defender for Office 365 Plan 1 enough, or do I need Plan 2?](https://www.solvingmicrosoft365.com/q/is-defender-for-office-365-plan-1-enough-or-do-i-need-plan-2): Plan 1 is the minimum any business tenant should run — it covers prevention: Safe Links, Safe Attachments, and advanced anti-phishing. Plan 2 adds the response layer — Automated Investigation and Response, Threat Explorer, Campaign Views, and Attack Simulation Training — and pays for itself wherever someone actually works a security queue. If nobody in the organisation will ever open Threat Explorer, Plan 1 is the right call. - [What's the fastest way to decommission the last on-prem Exchange server?](https://www.solvingmicrosoft365.com/q/whats-the-fastest-way-to-decommission-the-last-on-prem-exchange-server): There's no shortcut, but there is a defined sequence: confirm recipient attribute management has moved off the on-prem server (using the management-tools-only path Microsoft now supports), confirm nothing still relays mail through it, confirm public folders (if any) have migrated, then remove it. Skipping the check on any one of those is the most common cause of a decommission that has to be undone. - [What happens to shared mailboxes during a tenant-to-tenant migration?](https://www.solvingmicrosoft365.com/q/what-happens-to-shared-mailboxes-during-a-tenant-to-tenant-migration): Shared mailboxes migrate with the same tooling as user mailboxes — content and the mailbox object move across. What doesn't come along automatically is the web of delegate permissions (Send As, Send on Behalf, Full Access) and distribution-group memberships pointing at them; those have to be inventoried before cutover and rebuilt in the target tenant, or users lose access the moment the mailbox lands. - [Do I need Entra ID P2 for Privileged Identity Management?](https://www.solvingmicrosoft365.com/q/do-i-need-entra-id-p2-for-privileged-identity-management): Yes. Privileged Identity Management — just-in-time, time-bound activation of privileged roles with approval workflows and access reviews — requires Entra ID P2 (or Microsoft 365 E5, which includes it). Entra ID P1 covers Conditional Access and other baseline features, but not PIM. - [Does Microsoft 365 help with NIS2 compliance?](https://www.solvingmicrosoft365.com/q/does-microsoft-365-help-with-nis2-compliance): Microsoft 365 provides many of the technical controls NIS2 expects an organisation to have — Conditional Access and MFA, audit logging, incident detection through Defender and Sentinel, and a documented security posture via Compliance Manager — but NIS2 compliance is a legal and organisational obligation on the entity itself, not something a licence tier grants automatically. There is no NIS2 assessment template shipped for every tenant by default; check Compliance Manager's current template library for what's directly mapped. - [Do I need both Conditional Access and PIM?](https://www.solvingmicrosoft365.com/q/do-i-need-both-conditional-access-and-pim): For any admin directory role, yes, use both. Conditional Access decides what happens at sign-in — MFA, device compliance, location, risk. PIM decides whether the privileged role exists to sign in with at all, by making it eligible and time-bound instead of a standing assignment. A tenant with only CA can still have an admin role assigned permanently; a tenant with only PIM can still let an activated admin session in with weak authentication. - [Does labelling a Team or SharePoint site also label the files inside it?](https://www.solvingmicrosoft365.com/q/does-labeling-a-team-also-label-the-files-inside-it): No. A container label applied to a Team, Microsoft 365 Group, or SharePoint site controls the container itself — who can be invited, from which devices, its privacy setting — not the files stored inside it. Files and emails carry their own labels, set independently. A site labelled Confidential full of files labelled General is normal and correct, not a misconfiguration. - [What's the difference between DLP and sensitivity labels in Microsoft Purview?](https://www.solvingmicrosoft365.com/q/whats-the-difference-between-dlp-and-sensitivity-labels): A sensitivity label classifies content and can apply encryption, markings, and container controls — it's metadata that travels with the file. A DLP policy is a separate rule engine that inspects content and activity (sending, sharing, copying to USB) against a location, a condition, and an action, and a label is one of the conditions DLP can act on. Neither replaces the other: labels classify and protect the content itself, DLP watches what happens to it and can stop a risky action outright. - [Should I use Password Hash Sync or Pass-Through Authentication?](https://www.solvingmicrosoft365.com/q/should-i-use-password-hash-sync-or-pass-through-authentication): Password Hash Sync (PHS) for almost everyone. It has no on-premises dependency at sign-in time, supports Identity Protection's leaked-credential detection, and can act as a resilient fallback even alongside federation. Pass-Through Authentication (PTA) is for the specific case where regulatory or internal policy forbids storing password hashes in the cloud — accept that an on-premises outage then also stops cloud sign-in, since PTA authenticates against on-prem AD through an agent. - [How do MSPs manage DMARC rollout across multiple client tenants?](https://www.solvingmicrosoft365.com/q/how-do-msps-manage-dmarc-across-multiple-client-tenants): The DMARC journey itself doesn't change per client — publish p=none, fix legitimate senders, move to quarantine then reject — but at MSP scale, two things matter that don't come up managing a single domain: confirming which tenant a DNS record belongs to before touching it, and asking each client upfront for every marketing, helpdesk, invoicing, and HR-system integration that sends mail as their domain, since the client rarely remembers all of them unprompted. - [What should be in the Windows Autopilot must-install app list?](https://www.solvingmicrosoft365.com/q/what-should-be-in-the-autopilot-must-install-app-list): Keep the must-install (ESP-blocking) list to only what genuinely has to be on the device before the user starts working — most Autopilot complaints about slow provisioning or stalled Enrollment Status Pages trace back to an oversized must-install list, not a problem with Autopilot itself. Everything else should be assigned separately so it installs quietly in the background after the user is already at their desktop. ## Optional - [Books and reading list](https://www.solvingmicrosoft365.com/books) - [Resources](https://www.solvingmicrosoft365.com/resources) - [Sister site: Solving Dynamics 365](https://www.solvingdynamics365.com)