5 parts · about 26 minutes

Windows Autopilot, end to end

Set Autopilot up from nothing, then work through the errors that stop a deployment: the Enrollment Status Page, redeployments and enrollment blocks.

Intune
Start with part 1
  1. 1
    IntuneHow-to

    Windows Autopilot from scratch: register devices, build a user-driven profile and assign it

    Set up Windows Autopilot end to end: tenant prerequisites, collecting and importing hardware hashes, group tags and dynamic groups, a user-driven Entra join profile, an Enrollment Status Page and the first test device.

    6 min read
  2. 2
    IntuneTroubleshooting

    Enrollment Status Page timing out during Autopilot: a step-by-step troubleshooting guide

    Find the app or policy holding up the Enrollment Status Page, collect the right logs from OOBE, and fix the profile settings behind most Autopilot ESP timeouts.

    5 min read
  3. 3
    IntuneTroubleshooting

    Windows Autopilot error 0x80180014 when redeploying a device: cause and fix

    A reused Autopilot device fails MDM enrollment with 0x80180014. Why it happens, and the documented fixes: unblock or remove the stale Intune record and check enrollment restrictions.

    4 min read
  4. 4
    IntuneTroubleshooting

    Windows enrollment error 0x80180018 and its neighbours: what to check, and where

    Windows MDM enrollment fails with 0x80180018 or a nearby 0x8018 code. What Microsoft documents for each code, which tenant setting is behind it, and how to confirm the fix in the enrollment event log.

    5 min read
  5. 5
    IntuneTroubleshooting

    Intune device not checking in: diagnosing a Windows device that stopped syncing

    A Windows device shows a stale last check-in in Intune and policies stop arriving. How check-in works, what to inspect on the device (service, tasks, certificate, network) and when to re-enroll.

    6 min read
5 parts · about 26 minutes

Win32 apps and the Intune Management Extension

Package an app, understand how the IME installs and detects it, read its logs, and move on to scripts and remediations.

Intune
Start with part 1
  1. 1
    IntuneHow-to

    Packaging a Win32 app for Intune: .intunewin, install commands, detection and requirement rules

    How to wrap an installer with the Win32 Content Prep Tool, choose silent install and uninstall commands, set install behaviour, return codes, requirement and detection rules, and pilot the app.

    6 min read
  2. 2
    IntuneTroubleshooting

    Win32 app error 0x87D1041C: the app installed but Intune can't detect it

    0x87D1041C means the installer finished but the detection rule found nothing. The usual causes (bitness, install context, version drift) and how to test detection on the device.

    5 min read
  3. 3
    IntuneDeep dive

    Reading Intune Management Extension logs: IME, AppWorkload and AgentExecutor explained

    What each Intune Management Extension log records, how to read them with CMTrace, what to search for, how to force a check-in, and how to collect the logs remotely.

    4 min read
  4. 4
    IntuneTroubleshooting

    Intune PowerShell scripts not running: execution context, 64-bit, signing and where to look

    An Intune platform script reports Failed or never runs. How the Intune Management Extension executes scripts, what the three script settings change, how retries and re-runs work, and where to look.

    6 min read
  5. 5
    IntuneHow-to

    Intune Remediations: detect and fix common Windows issues at scale

    Set up Intune Remediations end to end: licensing and tenant attestation, the exit-code contract, run context, schedules, on-demand runs and reading the results.

    5 min read
5 parts · about 25 minutes

Securing Windows with Intune

Choose the right policy type, then roll out BitLocker, Windows LAPS and Defender settings without conflicts.

IntuneDefender
Start with part 1
  1. 1
    IntuneDeep dive

    Settings catalog, templates, baselines or endpoint security? Choosing the right Intune policy type

    What each Intune policy type is for, how conflicts between them are resolved and reported, a recommended layering for a new tenant, and naming and assignment hygiene with filters.

    6 min read
  2. 2
    IntuneTroubleshooting

    BitLocker silent encryption not starting on Intune-managed devices: causes and fixes

    Silent BitLocker not starting? Check TPM, UEFI, Secure Boot and WinRE, the required policy settings, startup authentication conflicts and recovery key backup to Microsoft Entra ID.

    5 min read
  3. 3
    IntuneHow-to

    Deploying Windows LAPS with Intune and backing up passwords to Microsoft Entra ID

    Set up Windows LAPS end to end: enable it in Microsoft Entra ID, build the Intune account protection profile, retrieve and rotate passwords, and check the LAPS event log.

    4 min read
  4. 4
    IntuneTroubleshooting

    Finding and fixing Intune policy conflicts with the MDM diagnostic report

    Settings stuck on Conflict in Intune? Find the competing policies, confirm what the device received with the MDM diagnostic report and event log, and rule out Group Policy.

    5 min read
  5. 5
    DefenderTroubleshooting

    Defender Antivirus settings not applying from Intune: a troubleshooting checklist

    Intune says the antivirus policy succeeded but the device disagrees. Check the management channel, conflicts, passive mode, tamper protection and exclusion behaviour to find out why.

    5 min read
5 parts · about 23 minutes

Conditional Access, from zero to enforced

Deploy a safe baseline, test it in report-only mode, then decode the sign-in errors users hit when a policy blocks them.

Entra IDIntune
Start with part 1
  1. 1
    Entra IDHow-to

    A Conditional Access baseline: the first policies every tenant should deploy

    The core Conditional Access policies to deploy first, how they map to Microsoft's templates and Microsoft-managed policies, and how to roll them out in report-only mode without locking anyone out.

    5 min read
  2. 2
    Entra IDHow-to

    Test before you enforce: Conditional Access What If and report-only mode

    Use report-only mode, the sign-in logs, the insights workbook and the What If tool to prove a Conditional Access policy behaves as expected before you turn it on.

    4 min read
  3. 3
    IntuneTroubleshooting

    Noncompliant on the Default Device Compliance Policy? The three built-in checks explained

    Why devices fail the built-in Is active, Enrolled user exists and Has a compliance policy assigned checks in Intune, and how to clear each one before Conditional Access blocks users.

    4 min read
  4. 4
    Entra IDTroubleshooting

    AADSTS53000 vs AADSTS53003: troubleshooting Conditional Access sign-in blocks

    What AADSTS53000, 53001 and 53003 actually mean, how to find the blocking policy in the sign-in logs, and how to fix compliance and browser device-identity gaps.

    4 min read
  5. 5
    Entra IDTroubleshooting

    AADSTS50076, AADSTS50079 and AADSTS50158: fixing MFA and authentication-strength sign-in errors

    What the MFA-related AADSTS codes mean, how to read the Authentication details and Conditional Access tabs of a sign-in, and how to fix legacy clients, unregistered users and authentication strength mismatches.

    6 min read
5 parts · about 22 minutes

Device identity: hybrid join, PRT and Windows Hello

The identity plumbing behind every Intune device — how to check it, fix it and build passwordless sign-in on top.

Entra ID
Start with part 1
  1. 1
    Entra IDTroubleshooting

    Troubleshooting Microsoft Entra hybrid join with dsregcmd /status

    Read dsregcmd /status for hybrid join failures, check the SCP and Entra Connect sync, use the User Device Registration log and clear devices stuck in Pending.

    4 min read
  2. 2
    Entra IDDeep dive

    Primary Refresh Token (PRT) explained: fixing SSO and repeated sign-in prompts

    How the Primary Refresh Token powers single sign-on on Windows, how to check it with dsregcmd and the AAD event logs, and how to fix a missing or stale PRT.

    4 min read
  3. 3
    Entra IDHow-to

    Deploying Windows Hello for Business with cloud Kerberos trust using Intune

    Why cloud Kerberos trust is the recommended Windows Hello for Business model for hybrid tenants, how to create the Entra Kerberos server object, configure the Intune policy, and verify with dsregcmd and klist.

    6 min read
  4. 4
    Entra IDHow-to

    Temporary Access Pass: onboarding users to passwordless and Windows Hello for Business

    Enable the Temporary Access Pass policy, issue passes in the portal or with Graph PowerShell, and use them to register passkeys, Authenticator and Windows Hello for Business.

    4 min read
  5. 5
    Entra IDHow-to

    Dynamic device groups for Intune: membership rules that actually work

    Working dynamic device rules for Autopilot, group tags, OS version, ownership and enrollment profiles, plus licensing, processing time, rule validation and when filters fit better.

    4 min read
6 parts · about 32 minutes

Defender for Endpoint with Intune

Onboard devices, fix the ones that don't report, manage settings everywhere, then roll out ASR rules and hunt across the fleet.

Defender
Start with part 1
  1. 1
    DefenderHow-to

    Onboarding Windows devices to Defender for Endpoint with Intune (and proving it worked)

    Connect Intune to Microsoft Defender for Endpoint, onboard Windows devices with an EDR policy, then prove it worked on the device, in the Defender portal and with a detection test.

    5 min read
  2. 2
    DefenderTroubleshooting

    Defender for Endpoint onboarding failures: SENSE event IDs, script errors and what they mean

    A field guide to Defender for Endpoint onboarding failures: onboarding script error codes, SENSE Operational event IDs, Intune error codes, and the registry and service checks that show where it broke.

    7 min read
  3. 3
    DefenderTroubleshooting

    Device shows "Inactive" or "No sensor data" in Microsoft Defender: how to troubleshoot

    What Inactive, Impaired communications and No sensor data mean in the Defender device inventory, and how to check the sensor, onboarding state, proxy and duplicate device records.

    4 min read
  4. 4
    DefenderHow-to

    Managing Defender settings on devices not enrolled in Intune: security settings management explained

    How Defender for Endpoint security settings management pushes Intune endpoint security policies to devices not enrolled in Intune: prerequisites, enforcement scope, synthetic registration and pitfalls.

    6 min read
  5. 5
    DefenderHow-to

    Rolling out ASR rules safely: audit mode, exclusions and advanced hunting

    A phased plan for attack surface reduction rules in Intune: standard rules straight to Block, the rest in Audit, measured with advanced hunting, narrow exclusions, then enforce.

    5 min read
  6. 6
    DefenderHow-to

    Advanced hunting for Intune admins: KQL queries that answer everyday device questions

    Eight short KQL queries for the Defender portal using documented tables: OS builds, sensor health, app versions, CVE exposure, antivirus posture, who ran a tool, ASR audit hits and network destinations.

    5 min read
6 parts · about 31 minutes

Email authentication and mail flow

Get SPF, DKIM and DMARC right, trace messages that never arrive, and fix the NDRs and relay problems admins see most.

Exchange Online
Start with part 1
  1. 1
    Exchange OnlineHow-to

    SPF, DKIM and DMARC for your Microsoft 365 custom domain: a practical setup guide

    Publish one correct SPF record, turn on DKIM signing in the Defender portal, then move DMARC from p=none to p=reject without blocking your own legitimate mail.

    5 min read
  2. 2
    Exchange OnlineHow-to

    Email never arrived? Using message trace in Exchange Online to find out why

    Run a message trace in the Exchange admin center or with Get-MessageTraceV2, read the delivery status and events, and pull older data from downloadable reports.

    5 min read
  3. 3
    Exchange OnlineTroubleshooting

    NDR 550 5.4.1 “Recipient address rejected: Access denied”: Directory-Based Edge Blocking

    Why Exchange Online rejects mail with 550 5.4.1 at the perimeter, how Directory-Based Edge Blocking and the accepted domain type cause it, and how to fix each common cause.

    5 min read
  4. 4
    Exchange OnlineTroubleshooting

    NDR 550 5.7.520: fixing “Your organization does not allow external forwarding”

    Why Exchange Online blocks automatic forwarding to external addresses with 5.7.520, and how to allow it only for the mailboxes that need it instead of for everyone.

    4 min read
  5. 5
    Exchange OnlineTroubleshooting

    Printers and apps can't send via Microsoft 365: SMTP AUTH, relay connectors and 5.7.57

    What error 5.7.57 means, how SMTP AUTH client submission, SMTP relay and Direct Send differ, how to fix each cause, and where Basic authentication for SMTP AUTH stands.

    6 min read
  6. 6
    Exchange OnlineHow-to

    Mail flow rules that don't backfire: external sender tagging, priorities and exceptions

    How Exchange Online evaluates mail flow rules, why the native External tag beats a subject-prefix rule, and how to test, order and audit rules without punching holes in EOP.

    6 min read
9 parts · about 52 minutes

Intune and Autopilot known issues, 2026 edition

The problems Microsoft has documented this year — what they look like on a device, how to confirm you're hitting them, and the fix or workaround.

Intune
Start with part 1
  1. 1
    IntuneTroubleshooting

    Windows Autopilot known issues in 2026: what's open, what's fixed and how to stay informed

    A walkthrough of the Windows Autopilot known issues page as of October 2026: open and fixed items, deeper guidance on the January 2026 entries, and how to subscribe so new issues reach you first.

    7 min read
  2. 2
    IntuneTroubleshooting

    Hybrid join Autopilot deployments time out with 0x80004005: the 2026 known issue and the fix

    Microsoft Entra hybrid join Autopilot deployments can time out with 0x80004005 on older Windows 11 builds. How to confirm the known issue, which KBs fix it and how to get devices onto a fixed build.

    5 min read
  3. 3
    IntuneTroubleshooting

    Pre-provisioning hybrid join fails when a policy needs a domain controller (0x800706FD)

    Autopilot pre-provisioning for hybrid join fails in the technician flow when a policy such as a User Rights setting needs a domain controller. How to read the 0x800706FD event and fix the scoping.

    6 min read
  4. 4
    IntuneTroubleshooting

    Intune Connector for AD fails with SeLogonAsServicePrivilege when you bring your own gMSA

    Configuring the Intune Connector for AD with your own gMSA can fail on the SeLogonAsServicePrivilege pre-check. The June 2026 known issue, the SkipByoMsaPrivilegeCheck fix and how to verify it.

    5 min read
  5. 5
    IntuneTroubleshooting

    Windows Autopilot device preparation: known issues and how to troubleshoot a failed run

    What trips admins up in Autopilot device preparation, the known issues and their status as of October 2026, how to read the deployment status report, and the documented steps for a failed deployment.

    7 min read
  6. 6
    IntuneTroubleshooting

    Domain trust failures after KB5124008: Machine Identity Isolation explained for Intune admins

    After the September 2026 Windows 11 updates some domain-joined devices lose their secure channel because Machine Identity Isolation is now honoured. How to find the policy, roll it back and verify.

    5 min read
  7. 7
    IntuneTroubleshooting

    Current Intune known issues that aren't your fault: Company Portal, Store apps, compliance messages

    Five items Microsoft currently lists as Active on the Intune known issues page, what each looks like, what to tell users, how to work around it, and how to track the page and escalate properly.

    5 min read
  8. 8
    IntuneTroubleshooting

    Macs unexpectedly unenrolled from Intune: the MDM certificate renewal issue and how to recover

    Why some Macs dropped out of Intune during MDM identity certificate renewal, Apple's fix in macOS 26.4, how to find and re-enroll affected devices, and how this differs from an expired Apple MDM push certificate.

    6 min read
  9. 9
    IntuneHow-to

    Is it me or is it Intune? Check service health, known issues and release notes first

    A 10-minute checklist to rule out a service incident, a documented known issue or a gradual service release before you troubleshoot your tenant, plus what to collect for a support case and how to subscribe.

    6 min read
5 parts · about 26 minutes

Compliance signals from Defender for Endpoint and health attestation

Why devices go noncompliant for reasons that have nothing to do with the user — risk scores, missing Sense clients and attestation endpoints — and how to fix each.

IntuneDefender
Start with part 1
  1. 1
    IntuneTroubleshooting

    Noncompliant on the Defender "machine risk score" setting: the end-to-end checklist

    Why a Windows device fails "Require the device to be at or under the machine risk score", and how to check the connector, onboarding, device identity and active alerts in the right order.

    5 min read
  2. 2
    IntuneTroubleshooting

    Windows 11 24H2 won't onboard to Defender for Endpoint: the missing Sense client (KB5043950)

    Some Windows 11 24H2 devices ship without the Sense client, so Intune's EDR policy errors and the device never reaches Defender. How to detect it at scale with Remediations and add the capability.

    5 min read
  3. 3
    IntuneTroubleshooting

    Intune health attestation is moving to Azure Attestation: prepare before compliance breaks

    Intune will evaluate BitLocker, Secure Boot and code integrity compliance through Microsoft Azure Attestation. Which endpoints to allow, how to test from a device, and how to find affected policies.

    5 min read
  4. 4
    IntuneTroubleshooting

    Noncompliant on the Default Device Compliance Policy? The three built-in checks explained

    Why devices fail the built-in Is active, Enrolled user exists and Has a compliance policy assigned checks in Intune, and how to clear each one before Conditional Access blocks users.

    4 min read
  5. 5
    DefenderTroubleshooting

    Security settings management enrollment errors: decoding SenseCM EnrollmentStatus codes

    A device is onboarded to Defender but never shows up as MDE-managed in Intune. Read HKLM\SOFTWARE\Microsoft\SenseCM\EnrollmentStatus, map the code to its cause and fix it.

    7 min read
7 parts · about 43 minutes

Deadlines you can't ignore: 2026–2027 changes

Secure Boot certificates, EWS retirement, Azure Attestation, Windows 11 26H2 and mandatory MFA — what changes, when, and what to do before the date.

IntuneExchange OnlineEntra ID
Start with part 1
  1. 1
    IntuneHow-to

    Rolling out the 2023 Secure Boot certificates with Intune before the last 2011 CA expires

    Which 2011 Secure Boot certificates expire and when, the Settings catalog Secure Boot settings, model-based filters for a staged rollout, and the Intune report and remediation that track progress.

    7 min read
  2. 2
    IntuneTroubleshooting

    Secure Boot certificate update not applying: registry values, event IDs and the Intune report

    Read UEFICA2023Status, the AvailableUpdates bitmask and TPM-WMI events 1795 to 1808 to see where a Secure Boot certificate update is stuck, interpret the Intune report, and clear the common blockers.

    7 min read
  3. 3
    Exchange OnlineTroubleshooting

    EWS switch-off in Exchange Online: EwsEnabled, the app allow list and finding EWS usage

    Exchange Web Services is being disabled in Exchange Online from October 2026. What changes, how EwsEnabled and EwsAllowedAppIDs work, how to find what still uses EWS and how to buy time safely.

    6 min read
  4. 4
    IntuneTroubleshooting

    Intune health attestation is moving to Azure Attestation: prepare before compliance breaks

    Intune will evaluate BitLocker, Secure Boot and code integrity compliance through Microsoft Azure Attestation. Which endpoints to allow, how to test from a device, and how to find affected policies.

    5 min read
  5. 5
    IntuneHow-to

    Rolling out Windows 11 26H2 with Intune: feature update policy, known issues, safeguard holds

    How 26H2 installs as an enablement package, the Intune feature update policy and rollout options to deploy it, the known issues listed at launch, how safeguard holds show up, and how to verify a device.

    7 min read
  6. 6
    Entra IDTroubleshooting

    Mandatory MFA for Azure and admin portals: fix scripts, service accounts and break-glass accounts

    What mandatory MFA enforcement covers, the failures it causes for user-based automation and admin sign-ins, how to verify who is ready, moving scripts to workload identities, and MFA-capable break-glass accounts.

    5 min read
  7. 7
    Entra IDTroubleshooting

    Conditional Access now evaluates OIDC-only sign-ins: the 2026 baseline scopes change

    Sign-ins requesting only openid, profile, email or User.Read are now subject to All resources policies with exclusions: who is affected, how to find the apps in sign-in logs, how to fix them, and the timeline.

    6 min read
6 parts · about 37 minutes

Intune Suite and advanced capabilities

Beyond the basics: the Enterprise App Catalog, Cloud PKI, Endpoint Privilege Management, Remote Help, custom compliance and phased deployments — set up and troubleshot.

Intune
Start with part 1
  1. 1
    IntuneHow-to

    Enterprise App Catalog in Intune: deploying third-party apps and keeping them updated

    Add a prepackaged Win32 app from the Enterprise App Catalog, understand the prefilled install and detection settings, choose between auto-update and guided supersedence, and troubleshoot failed installs.

    6 min read
  2. 2
    IntuneHow-to

    Microsoft Cloud PKI: issuing device certificates for Wi-Fi and VPN without NDES

    Build a two-tier Microsoft Cloud PKI hierarchy in Intune, deploy the trusted certificate and SCEP profiles, bind the certificate to Wi-Fi or VPN profiles, monitor and revoke, and fix the common SCEP errors.

    6 min read
  3. 3
    IntuneHow-to

    Endpoint Privilege Management in Intune: elevation settings, rules and user experience

    Deploy Intune Endpoint Privilege Management: the elevation settings policy, elevation rules by hash or certificate, the user experience, the elevation reports, and how to troubleshoot rules that don't match.

    7 min read
  4. 4
    IntuneHow-to

    Remote Help in Intune: licensing, setup, helper roles, deployment and troubleshooting

    Set up Remote Help end to end: check licensing, enable the tenant settings, grant least-privilege helper roles, deploy the Windows app, handle Conditional Access, and fix sessions that won't connect.

    6 min read
  5. 5
    IntuneHow-to

    Custom compliance in Intune: writing the discovery script and JSON rules

    Extend Intune compliance with your own checks: write a discovery script that returns compressed JSON, define rules in the JSON schema, upload both, and troubleshoot error codes 65007 to 65010.

    6 min read
  6. 6
    IntuneHow-to

    Intune deployments (preview): stage Win32 apps and policies across deployment rings

    Intune's new Deployments experience (preview): staging Win32 and Enterprise App Catalog apps, settings catalog and endpoint security policies across rings, permissions, how rings advance, and a ring design.

    6 min read
5 parts · about 30 minutes

Identity governance and protection

Least privilege with PIM, access reviews that people actually complete, risk policies without the false positives, SSPR that works — and how to read the sign-in logs when it doesn't.

Entra ID
Start with part 1
  1. 1
    Entra IDHow-to

    Privileged Identity Management: just-in-time Microsoft Entra roles done properly

    Set up PIM for Microsoft Entra roles: role settings, eligible assignments, activation and approvals, PIM for Groups, alerts, access reviews, and the activation problems you'll hit.

    6 min read
  2. 2
    Entra IDHow-to

    Access reviews and entitlement management basics: a starter plan for Entra ID Governance

    How access reviews and entitlement management fit together in Microsoft Entra ID Governance: licensing, creating reviews, catalogs and access packages, and a starter plan you can run this quarter.

    6 min read
  3. 3
    Entra IDTroubleshooting

    Microsoft Entra ID Protection: risk policies, self-remediation and false positives

    User risk vs sign-in risk, the detections behind them, risk-based Conditional Access that lets users fix their own risk, and how to investigate, dismiss or confirm the false positives.

    6 min read
  4. 4
    Entra IDTroubleshooting

    Self-service password reset and password writeback: fixing the usual failures

    SSPR prerequisites, password writeback through Connect Sync or Cloud Sync, the documented SSPR_00xx portal errors, the Windows sign-in screen Reset password link, and the event IDs behind writeback failures.

    6 min read
  5. 5
    Entra IDDeep dive

    Reading Microsoft Entra sign-in logs like an engineer

    The four sign-in log types, the fields that matter, how to trace one failed sign-in end to end, KQL against the SigninLogs table, export and retention by licence, and the misreads that waste hours.

    6 min read
5 parts · about 28 minutes

Hardening Windows endpoints with Defender and Intune

Close the gaps attackers use: vulnerability remediation through Intune, USB device control, tamper protection, web content filtering and attack surface reduction.

Defender
Start with part 1
  1. 1
    DefenderHow-to

    Defender Vulnerability Management: from security recommendation to Intune security task

    How exposure score, recommendations, software inventory and weaknesses fit together, and how a Request remediation in the Defender portal becomes a security task an Intune admin can close.

    6 min read
  2. 2
    DefenderHow-to

    Controlling USB and removable storage with Defender device control and Intune

    Device control concepts (groups, rules, entries, access masks), the Intune Device Control profile with reusable settings, audit before block, printers, hunting queries and fixes when a USB stick stays writable.

    6 min read
  3. 3
    DefenderTroubleshooting

    Tamper protection and Intune: why a Defender setting won't change, and how to fix it

    What tamper protection locks, the four places it can be managed and their precedence, how to see which one controls a device, and how to fix settings that won't apply or exclusions that aren't protected.

    5 min read
  4. 4
    DefenderHow-to

    Web content filtering in Defender for Endpoint: network protection, categories and indicators

    Enable network protection from Intune, turn on web content filtering, build category policies scoped to device groups, add allow indicators, and read blocks in reports, Event Viewer and advanced hunting.

    6 min read
  5. 5
    DefenderHow-to

    Rolling out ASR rules safely: audit mode, exclusions and advanced hunting

    A phased plan for attack surface reduction rules in Intune: standard rules straight to Block, the rest in Audit, measured with advanced hunting, narrow exclusions, then enforce.

    5 min read
6 parts · about 30 minutes

Exchange Online administration essentials

The recipient and retention decisions every Microsoft 365 admin makes — groups vs shared mailboxes, rooms, archives, holds — plus the Outlook connectivity issues behind most mailbox tickets.

Exchange Online
Start with part 1
  1. 1
    Exchange OnlineDeep dive

    Distribution groups vs Microsoft 365 Groups vs shared mailboxes: which one to use and how to convert

    A capability-by-capability comparison of distribution groups, dynamic groups, Microsoft 365 Groups and shared mailboxes, when to choose each, how to upgrade a DL and the PowerShell to answer the usual questions.

    6 min read
  2. 2
    Exchange OnlineDeep dive

    Shared mailbox automapping in Outlook: why it appears (or doesn't) and how to control it

    How automapping really works, why group-based Full Access never automaps, how to switch it off per user, and how to keep sent items in the shared mailbox.

    4 min read
  3. 3
    Exchange OnlineHow-to

    Room and equipment mailboxes in Exchange Online: creation, booking policies and Room Finder

    Create room and equipment mailboxes, tune Set-CalendarProcessing (auto-accept, conflicts, booking window, delegates), build room lists and Set-Place metadata for Room Finder, and fix the usual booking complaints.

    5 min read
  4. 4
    Exchange OnlineHow-to

    Retention policies, labels, MRM and litigation hold in Exchange Online: which one does what

    Purview retention policies vs retention labels vs Exchange MRM tags vs litigation hold: what each does, what wins in a conflict, licensing, how to set them up and how to prove a mailbox is really on hold.

    6 min read
  5. 5
    Exchange OnlineHow-to

    Enabling and troubleshooting auto-expanding archiving in Exchange Online

    Check licensing and the one-way switch, enable auto-expanding archiving org-wide or per user, make sure items actually move, and confirm extra storage was provisioned.

    4 min read
  6. 6
    Exchange OnlineTroubleshooting

    Outlook can't connect or set up the account: Autodiscover troubleshooting for Exchange Online

    How classic Outlook finds Exchange Online, how to read Test E-mail AutoConfiguration and the Remote Connectivity Analyzer, and the usual culprits: DNS, stale on-premises Autodiscover, old clients and broken profiles.

    5 min read
4 parts · about 24 minutes

Certification study plans

Stage-by-stage training paths for the Microsoft exams that matter to endpoint, identity, security and Microsoft 365 admins.

IntuneEntra IDDefenderExchange Online
Start with part 1
  1. 1
    IntuneTraining path

    Training path: becoming a Microsoft Intune administrator (MD-102 study plan)

    A five-stage plan for Exam MD-102 and the Endpoint Administrator Associate certification: the current skills-measured domains, the Microsoft Learn paths to follow, lab exercises and exam-day tips.

    6 min read
  2. 2
    Entra IDTraining path

    Training path: Microsoft Entra ID for administrators (SC-300 study plan)

    A six-stage study plan for exam SC-300, mapped to the official Microsoft Learn learning paths, with hands-on labs for Conditional Access, authentication methods, PIM, access reviews, apps and Entra Connect.

    6 min read
  3. 3
    DefenderTraining path

    Training path: SC-200 Security Operations Analyst study plan (Defender XDR and Sentinel)

    A stage-by-stage study plan for exam SC-200 (Security Operations Analyst Associate): the current skills-measured domains, the Microsoft Learn paths to follow, hands-on labs and exam-day tips.

    6 min read
  4. 4
    Exchange OnlineTraining path

    Training path: MS-102 Microsoft 365 Administrator study plan with Exchange Online depth

    A six-stage MS-102 study plan built on the official Microsoft Learn paths, with extra Exchange Online practice, lab ideas and what the November 2026 retirement of the exam means for you.

    6 min read
Suggest a topic

Want a series on something else?

Tell me which Microsoft 365 workload or problem area you'd like covered end to end, and it may become the next reading path.