Reading paths that build the full picture
Each series groups related guides in the order they're best read — from first setup, through the errors you'll meet, to verification. Pick a topic and start with part 1.
Windows Autopilot, end to end
Set Autopilot up from nothing, then work through the errors that stop a deployment: the Enrollment Status Page, redeployments and enrollment blocks.
-
1
IntuneHow-to
Windows Autopilot from scratch: register devices, build a user-driven profile and assign it
Set up Windows Autopilot end to end: tenant prerequisites, collecting and importing hardware hashes, group tags and dynamic groups, a user-driven Entra join profile, an Enrollment Status Page and the first test device.
-
2
IntuneTroubleshooting
Enrollment Status Page timing out during Autopilot: a step-by-step troubleshooting guide
Find the app or policy holding up the Enrollment Status Page, collect the right logs from OOBE, and fix the profile settings behind most Autopilot ESP timeouts.
-
3
IntuneTroubleshooting
Windows Autopilot error 0x80180014 when redeploying a device: cause and fix
A reused Autopilot device fails MDM enrollment with 0x80180014. Why it happens, and the documented fixes: unblock or remove the stale Intune record and check enrollment restrictions.
-
4
IntuneTroubleshooting
Windows enrollment error 0x80180018 and its neighbours: what to check, and where
Windows MDM enrollment fails with 0x80180018 or a nearby 0x8018 code. What Microsoft documents for each code, which tenant setting is behind it, and how to confirm the fix in the enrollment event log.
-
5
IntuneTroubleshooting
Intune device not checking in: diagnosing a Windows device that stopped syncing
A Windows device shows a stale last check-in in Intune and policies stop arriving. How check-in works, what to inspect on the device (service, tasks, certificate, network) and when to re-enroll.
Win32 apps and the Intune Management Extension
Package an app, understand how the IME installs and detects it, read its logs, and move on to scripts and remediations.
-
1
IntuneHow-to
Packaging a Win32 app for Intune: .intunewin, install commands, detection and requirement rules
How to wrap an installer with the Win32 Content Prep Tool, choose silent install and uninstall commands, set install behaviour, return codes, requirement and detection rules, and pilot the app.
-
2
IntuneTroubleshooting
Win32 app error 0x87D1041C: the app installed but Intune can't detect it
0x87D1041C means the installer finished but the detection rule found nothing. The usual causes (bitness, install context, version drift) and how to test detection on the device.
-
3
IntuneDeep dive
Reading Intune Management Extension logs: IME, AppWorkload and AgentExecutor explained
What each Intune Management Extension log records, how to read them with CMTrace, what to search for, how to force a check-in, and how to collect the logs remotely.
-
4
IntuneTroubleshooting
Intune PowerShell scripts not running: execution context, 64-bit, signing and where to look
An Intune platform script reports Failed or never runs. How the Intune Management Extension executes scripts, what the three script settings change, how retries and re-runs work, and where to look.
-
5
IntuneHow-to
Intune Remediations: detect and fix common Windows issues at scale
Set up Intune Remediations end to end: licensing and tenant attestation, the exit-code contract, run context, schedules, on-demand runs and reading the results.
Securing Windows with Intune
Choose the right policy type, then roll out BitLocker, Windows LAPS and Defender settings without conflicts.
-
1
IntuneDeep dive
Settings catalog, templates, baselines or endpoint security? Choosing the right Intune policy type
What each Intune policy type is for, how conflicts between them are resolved and reported, a recommended layering for a new tenant, and naming and assignment hygiene with filters.
-
2
IntuneTroubleshooting
BitLocker silent encryption not starting on Intune-managed devices: causes and fixes
Silent BitLocker not starting? Check TPM, UEFI, Secure Boot and WinRE, the required policy settings, startup authentication conflicts and recovery key backup to Microsoft Entra ID.
-
3
IntuneHow-to
Deploying Windows LAPS with Intune and backing up passwords to Microsoft Entra ID
Set up Windows LAPS end to end: enable it in Microsoft Entra ID, build the Intune account protection profile, retrieve and rotate passwords, and check the LAPS event log.
-
4
IntuneTroubleshooting
Finding and fixing Intune policy conflicts with the MDM diagnostic report
Settings stuck on Conflict in Intune? Find the competing policies, confirm what the device received with the MDM diagnostic report and event log, and rule out Group Policy.
-
5
DefenderTroubleshooting
Defender Antivirus settings not applying from Intune: a troubleshooting checklist
Intune says the antivirus policy succeeded but the device disagrees. Check the management channel, conflicts, passive mode, tamper protection and exclusion behaviour to find out why.
Conditional Access, from zero to enforced
Deploy a safe baseline, test it in report-only mode, then decode the sign-in errors users hit when a policy blocks them.
-
1
Entra IDHow-to
A Conditional Access baseline: the first policies every tenant should deploy
The core Conditional Access policies to deploy first, how they map to Microsoft's templates and Microsoft-managed policies, and how to roll them out in report-only mode without locking anyone out.
-
2
Entra IDHow-to
Test before you enforce: Conditional Access What If and report-only mode
Use report-only mode, the sign-in logs, the insights workbook and the What If tool to prove a Conditional Access policy behaves as expected before you turn it on.
-
3
IntuneTroubleshooting
Noncompliant on the Default Device Compliance Policy? The three built-in checks explained
Why devices fail the built-in Is active, Enrolled user exists and Has a compliance policy assigned checks in Intune, and how to clear each one before Conditional Access blocks users.
-
4
Entra IDTroubleshooting
AADSTS53000 vs AADSTS53003: troubleshooting Conditional Access sign-in blocks
What AADSTS53000, 53001 and 53003 actually mean, how to find the blocking policy in the sign-in logs, and how to fix compliance and browser device-identity gaps.
-
5
Entra IDTroubleshooting
AADSTS50076, AADSTS50079 and AADSTS50158: fixing MFA and authentication-strength sign-in errors
What the MFA-related AADSTS codes mean, how to read the Authentication details and Conditional Access tabs of a sign-in, and how to fix legacy clients, unregistered users and authentication strength mismatches.
Device identity: hybrid join, PRT and Windows Hello
The identity plumbing behind every Intune device — how to check it, fix it and build passwordless sign-in on top.
-
1
Entra IDTroubleshooting
Troubleshooting Microsoft Entra hybrid join with dsregcmd /status
Read dsregcmd /status for hybrid join failures, check the SCP and Entra Connect sync, use the User Device Registration log and clear devices stuck in Pending.
-
2
Entra IDDeep dive
Primary Refresh Token (PRT) explained: fixing SSO and repeated sign-in prompts
How the Primary Refresh Token powers single sign-on on Windows, how to check it with dsregcmd and the AAD event logs, and how to fix a missing or stale PRT.
-
3
Entra IDHow-to
Deploying Windows Hello for Business with cloud Kerberos trust using Intune
Why cloud Kerberos trust is the recommended Windows Hello for Business model for hybrid tenants, how to create the Entra Kerberos server object, configure the Intune policy, and verify with dsregcmd and klist.
-
4
Entra IDHow-to
Temporary Access Pass: onboarding users to passwordless and Windows Hello for Business
Enable the Temporary Access Pass policy, issue passes in the portal or with Graph PowerShell, and use them to register passkeys, Authenticator and Windows Hello for Business.
-
5
Entra IDHow-to
Dynamic device groups for Intune: membership rules that actually work
Working dynamic device rules for Autopilot, group tags, OS version, ownership and enrollment profiles, plus licensing, processing time, rule validation and when filters fit better.
Defender for Endpoint with Intune
Onboard devices, fix the ones that don't report, manage settings everywhere, then roll out ASR rules and hunt across the fleet.
-
1
DefenderHow-to
Onboarding Windows devices to Defender for Endpoint with Intune (and proving it worked)
Connect Intune to Microsoft Defender for Endpoint, onboard Windows devices with an EDR policy, then prove it worked on the device, in the Defender portal and with a detection test.
-
2
DefenderTroubleshooting
Defender for Endpoint onboarding failures: SENSE event IDs, script errors and what they mean
A field guide to Defender for Endpoint onboarding failures: onboarding script error codes, SENSE Operational event IDs, Intune error codes, and the registry and service checks that show where it broke.
-
3
DefenderTroubleshooting
Device shows "Inactive" or "No sensor data" in Microsoft Defender: how to troubleshoot
What Inactive, Impaired communications and No sensor data mean in the Defender device inventory, and how to check the sensor, onboarding state, proxy and duplicate device records.
-
4
DefenderHow-to
Managing Defender settings on devices not enrolled in Intune: security settings management explained
How Defender for Endpoint security settings management pushes Intune endpoint security policies to devices not enrolled in Intune: prerequisites, enforcement scope, synthetic registration and pitfalls.
-
5
DefenderHow-to
Rolling out ASR rules safely: audit mode, exclusions and advanced hunting
A phased plan for attack surface reduction rules in Intune: standard rules straight to Block, the rest in Audit, measured with advanced hunting, narrow exclusions, then enforce.
-
6
DefenderHow-to
Advanced hunting for Intune admins: KQL queries that answer everyday device questions
Eight short KQL queries for the Defender portal using documented tables: OS builds, sensor health, app versions, CVE exposure, antivirus posture, who ran a tool, ASR audit hits and network destinations.
Email authentication and mail flow
Get SPF, DKIM and DMARC right, trace messages that never arrive, and fix the NDRs and relay problems admins see most.
-
1
Exchange OnlineHow-to
SPF, DKIM and DMARC for your Microsoft 365 custom domain: a practical setup guide
Publish one correct SPF record, turn on DKIM signing in the Defender portal, then move DMARC from p=none to p=reject without blocking your own legitimate mail.
-
2
Exchange OnlineHow-to
Email never arrived? Using message trace in Exchange Online to find out why
Run a message trace in the Exchange admin center or with Get-MessageTraceV2, read the delivery status and events, and pull older data from downloadable reports.
-
3
Exchange OnlineTroubleshooting
NDR 550 5.4.1 “Recipient address rejected: Access denied”: Directory-Based Edge Blocking
Why Exchange Online rejects mail with 550 5.4.1 at the perimeter, how Directory-Based Edge Blocking and the accepted domain type cause it, and how to fix each common cause.
-
4
Exchange OnlineTroubleshooting
NDR 550 5.7.520: fixing “Your organization does not allow external forwarding”
Why Exchange Online blocks automatic forwarding to external addresses with 5.7.520, and how to allow it only for the mailboxes that need it instead of for everyone.
-
5
Exchange OnlineTroubleshooting
Printers and apps can't send via Microsoft 365: SMTP AUTH, relay connectors and 5.7.57
What error 5.7.57 means, how SMTP AUTH client submission, SMTP relay and Direct Send differ, how to fix each cause, and where Basic authentication for SMTP AUTH stands.
-
6
Exchange OnlineHow-to
Mail flow rules that don't backfire: external sender tagging, priorities and exceptions
How Exchange Online evaluates mail flow rules, why the native External tag beats a subject-prefix rule, and how to test, order and audit rules without punching holes in EOP.
Intune and Autopilot known issues, 2026 edition
The problems Microsoft has documented this year — what they look like on a device, how to confirm you're hitting them, and the fix or workaround.
-
1
IntuneTroubleshooting
Windows Autopilot known issues in 2026: what's open, what's fixed and how to stay informed
A walkthrough of the Windows Autopilot known issues page as of October 2026: open and fixed items, deeper guidance on the January 2026 entries, and how to subscribe so new issues reach you first.
-
2
IntuneTroubleshooting
Hybrid join Autopilot deployments time out with 0x80004005: the 2026 known issue and the fix
Microsoft Entra hybrid join Autopilot deployments can time out with 0x80004005 on older Windows 11 builds. How to confirm the known issue, which KBs fix it and how to get devices onto a fixed build.
-
3
IntuneTroubleshooting
Pre-provisioning hybrid join fails when a policy needs a domain controller (0x800706FD)
Autopilot pre-provisioning for hybrid join fails in the technician flow when a policy such as a User Rights setting needs a domain controller. How to read the 0x800706FD event and fix the scoping.
-
4
IntuneTroubleshooting
Intune Connector for AD fails with SeLogonAsServicePrivilege when you bring your own gMSA
Configuring the Intune Connector for AD with your own gMSA can fail on the SeLogonAsServicePrivilege pre-check. The June 2026 known issue, the SkipByoMsaPrivilegeCheck fix and how to verify it.
-
5
IntuneTroubleshooting
Windows Autopilot device preparation: known issues and how to troubleshoot a failed run
What trips admins up in Autopilot device preparation, the known issues and their status as of October 2026, how to read the deployment status report, and the documented steps for a failed deployment.
-
6
IntuneTroubleshooting
Domain trust failures after KB5124008: Machine Identity Isolation explained for Intune admins
After the September 2026 Windows 11 updates some domain-joined devices lose their secure channel because Machine Identity Isolation is now honoured. How to find the policy, roll it back and verify.
-
7
IntuneTroubleshooting
Current Intune known issues that aren't your fault: Company Portal, Store apps, compliance messages
Five items Microsoft currently lists as Active on the Intune known issues page, what each looks like, what to tell users, how to work around it, and how to track the page and escalate properly.
-
8
IntuneTroubleshooting
Macs unexpectedly unenrolled from Intune: the MDM certificate renewal issue and how to recover
Why some Macs dropped out of Intune during MDM identity certificate renewal, Apple's fix in macOS 26.4, how to find and re-enroll affected devices, and how this differs from an expired Apple MDM push certificate.
-
9
IntuneHow-to
Is it me or is it Intune? Check service health, known issues and release notes first
A 10-minute checklist to rule out a service incident, a documented known issue or a gradual service release before you troubleshoot your tenant, plus what to collect for a support case and how to subscribe.
Compliance signals from Defender for Endpoint and health attestation
Why devices go noncompliant for reasons that have nothing to do with the user — risk scores, missing Sense clients and attestation endpoints — and how to fix each.
-
1
IntuneTroubleshooting
Noncompliant on the Defender "machine risk score" setting: the end-to-end checklist
Why a Windows device fails "Require the device to be at or under the machine risk score", and how to check the connector, onboarding, device identity and active alerts in the right order.
-
2
IntuneTroubleshooting
Windows 11 24H2 won't onboard to Defender for Endpoint: the missing Sense client (KB5043950)
Some Windows 11 24H2 devices ship without the Sense client, so Intune's EDR policy errors and the device never reaches Defender. How to detect it at scale with Remediations and add the capability.
-
3
IntuneTroubleshooting
Intune health attestation is moving to Azure Attestation: prepare before compliance breaks
Intune will evaluate BitLocker, Secure Boot and code integrity compliance through Microsoft Azure Attestation. Which endpoints to allow, how to test from a device, and how to find affected policies.
-
4
IntuneTroubleshooting
Noncompliant on the Default Device Compliance Policy? The three built-in checks explained
Why devices fail the built-in Is active, Enrolled user exists and Has a compliance policy assigned checks in Intune, and how to clear each one before Conditional Access blocks users.
-
5
DefenderTroubleshooting
Security settings management enrollment errors: decoding SenseCM EnrollmentStatus codes
A device is onboarded to Defender but never shows up as MDE-managed in Intune. Read HKLM\SOFTWARE\Microsoft\SenseCM\EnrollmentStatus, map the code to its cause and fix it.
Deadlines you can't ignore: 2026–2027 changes
Secure Boot certificates, EWS retirement, Azure Attestation, Windows 11 26H2 and mandatory MFA — what changes, when, and what to do before the date.
-
1
IntuneHow-to
Rolling out the 2023 Secure Boot certificates with Intune before the last 2011 CA expires
Which 2011 Secure Boot certificates expire and when, the Settings catalog Secure Boot settings, model-based filters for a staged rollout, and the Intune report and remediation that track progress.
-
2
IntuneTroubleshooting
Secure Boot certificate update not applying: registry values, event IDs and the Intune report
Read UEFICA2023Status, the AvailableUpdates bitmask and TPM-WMI events 1795 to 1808 to see where a Secure Boot certificate update is stuck, interpret the Intune report, and clear the common blockers.
-
3
Exchange OnlineTroubleshooting
EWS switch-off in Exchange Online: EwsEnabled, the app allow list and finding EWS usage
Exchange Web Services is being disabled in Exchange Online from October 2026. What changes, how EwsEnabled and EwsAllowedAppIDs work, how to find what still uses EWS and how to buy time safely.
-
4
IntuneTroubleshooting
Intune health attestation is moving to Azure Attestation: prepare before compliance breaks
Intune will evaluate BitLocker, Secure Boot and code integrity compliance through Microsoft Azure Attestation. Which endpoints to allow, how to test from a device, and how to find affected policies.
-
5
IntuneHow-to
Rolling out Windows 11 26H2 with Intune: feature update policy, known issues, safeguard holds
How 26H2 installs as an enablement package, the Intune feature update policy and rollout options to deploy it, the known issues listed at launch, how safeguard holds show up, and how to verify a device.
-
6
Entra IDTroubleshooting
Mandatory MFA for Azure and admin portals: fix scripts, service accounts and break-glass accounts
What mandatory MFA enforcement covers, the failures it causes for user-based automation and admin sign-ins, how to verify who is ready, moving scripts to workload identities, and MFA-capable break-glass accounts.
-
7
Entra IDTroubleshooting
Conditional Access now evaluates OIDC-only sign-ins: the 2026 baseline scopes change
Sign-ins requesting only openid, profile, email or User.Read are now subject to All resources policies with exclusions: who is affected, how to find the apps in sign-in logs, how to fix them, and the timeline.
Intune Suite and advanced capabilities
Beyond the basics: the Enterprise App Catalog, Cloud PKI, Endpoint Privilege Management, Remote Help, custom compliance and phased deployments — set up and troubleshot.
-
1
IntuneHow-to
Enterprise App Catalog in Intune: deploying third-party apps and keeping them updated
Add a prepackaged Win32 app from the Enterprise App Catalog, understand the prefilled install and detection settings, choose between auto-update and guided supersedence, and troubleshoot failed installs.
-
2
IntuneHow-to
Microsoft Cloud PKI: issuing device certificates for Wi-Fi and VPN without NDES
Build a two-tier Microsoft Cloud PKI hierarchy in Intune, deploy the trusted certificate and SCEP profiles, bind the certificate to Wi-Fi or VPN profiles, monitor and revoke, and fix the common SCEP errors.
-
3
IntuneHow-to
Endpoint Privilege Management in Intune: elevation settings, rules and user experience
Deploy Intune Endpoint Privilege Management: the elevation settings policy, elevation rules by hash or certificate, the user experience, the elevation reports, and how to troubleshoot rules that don't match.
-
4
IntuneHow-to
Remote Help in Intune: licensing, setup, helper roles, deployment and troubleshooting
Set up Remote Help end to end: check licensing, enable the tenant settings, grant least-privilege helper roles, deploy the Windows app, handle Conditional Access, and fix sessions that won't connect.
-
5
IntuneHow-to
Custom compliance in Intune: writing the discovery script and JSON rules
Extend Intune compliance with your own checks: write a discovery script that returns compressed JSON, define rules in the JSON schema, upload both, and troubleshoot error codes 65007 to 65010.
-
6
IntuneHow-to
Intune deployments (preview): stage Win32 apps and policies across deployment rings
Intune's new Deployments experience (preview): staging Win32 and Enterprise App Catalog apps, settings catalog and endpoint security policies across rings, permissions, how rings advance, and a ring design.
Identity governance and protection
Least privilege with PIM, access reviews that people actually complete, risk policies without the false positives, SSPR that works — and how to read the sign-in logs when it doesn't.
-
1
Entra IDHow-to
Privileged Identity Management: just-in-time Microsoft Entra roles done properly
Set up PIM for Microsoft Entra roles: role settings, eligible assignments, activation and approvals, PIM for Groups, alerts, access reviews, and the activation problems you'll hit.
-
2
Entra IDHow-to
Access reviews and entitlement management basics: a starter plan for Entra ID Governance
How access reviews and entitlement management fit together in Microsoft Entra ID Governance: licensing, creating reviews, catalogs and access packages, and a starter plan you can run this quarter.
-
3
Entra IDTroubleshooting
Microsoft Entra ID Protection: risk policies, self-remediation and false positives
User risk vs sign-in risk, the detections behind them, risk-based Conditional Access that lets users fix their own risk, and how to investigate, dismiss or confirm the false positives.
-
4
Entra IDTroubleshooting
Self-service password reset and password writeback: fixing the usual failures
SSPR prerequisites, password writeback through Connect Sync or Cloud Sync, the documented SSPR_00xx portal errors, the Windows sign-in screen Reset password link, and the event IDs behind writeback failures.
-
5
Entra IDDeep dive
Reading Microsoft Entra sign-in logs like an engineer
The four sign-in log types, the fields that matter, how to trace one failed sign-in end to end, KQL against the SigninLogs table, export and retention by licence, and the misreads that waste hours.
Hardening Windows endpoints with Defender and Intune
Close the gaps attackers use: vulnerability remediation through Intune, USB device control, tamper protection, web content filtering and attack surface reduction.
-
1
DefenderHow-to
Defender Vulnerability Management: from security recommendation to Intune security task
How exposure score, recommendations, software inventory and weaknesses fit together, and how a Request remediation in the Defender portal becomes a security task an Intune admin can close.
-
2
DefenderHow-to
Controlling USB and removable storage with Defender device control and Intune
Device control concepts (groups, rules, entries, access masks), the Intune Device Control profile with reusable settings, audit before block, printers, hunting queries and fixes when a USB stick stays writable.
-
3
DefenderTroubleshooting
Tamper protection and Intune: why a Defender setting won't change, and how to fix it
What tamper protection locks, the four places it can be managed and their precedence, how to see which one controls a device, and how to fix settings that won't apply or exclusions that aren't protected.
-
4
DefenderHow-to
Web content filtering in Defender for Endpoint: network protection, categories and indicators
Enable network protection from Intune, turn on web content filtering, build category policies scoped to device groups, add allow indicators, and read blocks in reports, Event Viewer and advanced hunting.
-
5
DefenderHow-to
Rolling out ASR rules safely: audit mode, exclusions and advanced hunting
A phased plan for attack surface reduction rules in Intune: standard rules straight to Block, the rest in Audit, measured with advanced hunting, narrow exclusions, then enforce.
Exchange Online administration essentials
The recipient and retention decisions every Microsoft 365 admin makes — groups vs shared mailboxes, rooms, archives, holds — plus the Outlook connectivity issues behind most mailbox tickets.
-
1
Exchange OnlineDeep dive
Distribution groups vs Microsoft 365 Groups vs shared mailboxes: which one to use and how to convert
A capability-by-capability comparison of distribution groups, dynamic groups, Microsoft 365 Groups and shared mailboxes, when to choose each, how to upgrade a DL and the PowerShell to answer the usual questions.
-
2
Exchange OnlineDeep dive
Shared mailbox automapping in Outlook: why it appears (or doesn't) and how to control it
How automapping really works, why group-based Full Access never automaps, how to switch it off per user, and how to keep sent items in the shared mailbox.
-
3
Exchange OnlineHow-to
Room and equipment mailboxes in Exchange Online: creation, booking policies and Room Finder
Create room and equipment mailboxes, tune Set-CalendarProcessing (auto-accept, conflicts, booking window, delegates), build room lists and Set-Place metadata for Room Finder, and fix the usual booking complaints.
-
4
Exchange OnlineHow-to
Retention policies, labels, MRM and litigation hold in Exchange Online: which one does what
Purview retention policies vs retention labels vs Exchange MRM tags vs litigation hold: what each does, what wins in a conflict, licensing, how to set them up and how to prove a mailbox is really on hold.
-
5
Exchange OnlineHow-to
Enabling and troubleshooting auto-expanding archiving in Exchange Online
Check licensing and the one-way switch, enable auto-expanding archiving org-wide or per user, make sure items actually move, and confirm extra storage was provisioned.
-
6
Exchange OnlineTroubleshooting
Outlook can't connect or set up the account: Autodiscover troubleshooting for Exchange Online
How classic Outlook finds Exchange Online, how to read Test E-mail AutoConfiguration and the Remote Connectivity Analyzer, and the usual culprits: DNS, stale on-premises Autodiscover, old clients and broken profiles.
Certification study plans
Stage-by-stage training paths for the Microsoft exams that matter to endpoint, identity, security and Microsoft 365 admins.
-
1
IntuneTraining path
Training path: becoming a Microsoft Intune administrator (MD-102 study plan)
A five-stage plan for Exam MD-102 and the Endpoint Administrator Associate certification: the current skills-measured domains, the Microsoft Learn paths to follow, lab exercises and exam-day tips.
-
2
Entra IDTraining path
Training path: Microsoft Entra ID for administrators (SC-300 study plan)
A six-stage study plan for exam SC-300, mapped to the official Microsoft Learn learning paths, with hands-on labs for Conditional Access, authentication methods, PIM, access reviews, apps and Entra Connect.
-
3
DefenderTraining path
Training path: SC-200 Security Operations Analyst study plan (Defender XDR and Sentinel)
A stage-by-stage study plan for exam SC-200 (Security Operations Analyst Associate): the current skills-measured domains, the Microsoft Learn paths to follow, hands-on labs and exam-day tips.
-
4
Exchange OnlineTraining path
Training path: MS-102 Microsoft 365 Administrator study plan with Exchange Online depth
A six-stage MS-102 study plan built on the official Microsoft Learn paths, with extra Exchange Online practice, lab ideas and what the November 2026 retirement of the exam means for you.
Want a series on something else?
Tell me which Microsoft 365 workload or problem area you'd like covered end to end, and it may become the next reading path.