Microsoft 365 Interview Questions & Answers – Part 1: Administration, Tenant & Core Concepts

Microsoft 365 administration involves much more than creating users and assigning licenses.

Contents hide

A Microsoft 365 administrator needs to understand:

  • Microsoft 365 tenants
  • Subscriptions and licenses
  • Microsoft 365 admin center
  • Administrative roles
  • Custom domains
  • Users and groups
  • Exchange Online
  • SharePoint Online
  • OneDrive
  • Microsoft Teams
  • Service health
  • Message Center
  • Microsoft 365 administration and governance
  • PowerShell administration
  • Troubleshooting methodology

This part focuses on Microsoft 365 administration and core concepts.

Microsoft Entra ID is intentionally not covered in depth here because it is already covered separately in the existing 200 Microsoft Entra ID Interview Questions & Answers series.


1. Microsoft 365

Q1. What is Microsoft 365?

Microsoft 365 is a cloud-based productivity and collaboration platform that combines Microsoft productivity applications, cloud services and security/management capabilities.

Depending on the subscription, Microsoft 365 can include services such as:

  • Exchange Online
  • SharePoint Online
  • OneDrive
  • Microsoft Teams
  • Microsoft 365 Apps
  • Microsoft Entra ID capabilities
  • Microsoft Intune
  • Microsoft Defender capabilities
  • Microsoft Purview capabilities

The exact services and features available depend on the organization’s licensing and configuration.

A good interview answer is:

Microsoft 365 is Microsoft’s cloud productivity platform that provides services such as Exchange Online, SharePoint Online, OneDrive, Teams and Microsoft 365 Apps, with additional security and management capabilities depending on the subscription.


Q2. What is a Microsoft 365 tenant?

A Microsoft 365 tenant is an organization’s dedicated instance of Microsoft 365 services.

The tenant provides the organization’s cloud environment where administrators manage:

  • Users
  • Groups
  • Domains
  • Licenses
  • Microsoft 365 services
  • Policies
  • Service configurations
  • Administrative access

A tenant is associated with an initial Microsoft-managed domain, commonly in the form:

organization.onmicrosoft.com

An organization can subsequently add and verify its own custom domains.


Q3. What is an onmicrosoft.com domain?

When a Microsoft 365 organization is created, Microsoft provides an initial domain using the onmicrosoft.com namespace.

Example:

contoso.onmicrosoft.com

This initial domain is associated with the tenant and is used for various Microsoft 365 services and administration scenarios.

An organization can also add a custom domain such as:

contoso.com

The onmicrosoft.com domain should not simply be treated as a replacement for the organization’s public domain.


Q4. Can an organization use its own domain with Microsoft 365?

Yes.

For example:

company.com

can be added to Microsoft 365.

The domain must be verified and the appropriate DNS records configured.

Depending on the services being deployed, DNS records can include:

  • TXT
  • MX
  • CNAME
  • SRV
  • Autodiscover-related records
  • SPF-related records

The exact DNS records depend on the Microsoft 365 services and configuration being deployed.


Q5. How do you add and verify a custom domain in Microsoft 365?

A typical process is:

  1. Open the Microsoft 365 admin center.
  2. Go to the domain-management area.
  3. Add the domain.
  4. Microsoft provides a verification record.
  5. Add the required DNS verification record at the DNS hosting provider.
  6. Verify ownership.
  7. Configure the required DNS records for the Microsoft 365 workloads being used.

For example, Microsoft may provide a TXT record that must be added to the public DNS zone.

The important point is that domain verification proves ownership; it does not automatically configure every Microsoft 365 workload.


Q6. What is the Microsoft 365 admin center?

The Microsoft 365 admin center is the central administrative portal for many Microsoft 365 organization-level management tasks.

Administrators can use it to manage areas such as:

  • Users
  • Groups
  • Licenses
  • Billing
  • Service health
  • Reports
  • Microsoft 365 settings
  • Administrative roles
  • Access to workload-specific admin centers

Microsoft also provides dedicated admin centers for workloads such as Exchange, Teams, SharePoint and Microsoft Entra.


Q7. What is the difference between the Microsoft 365 admin center and workload-specific admin centers?

The Microsoft 365 admin center provides centralized organization-level administration.

Workload-specific admin centers provide more detailed configuration for individual services.

Examples:

Admin CenterPrimary workload
Microsoft 365 admin centerOrganization-wide Microsoft 365 administration
Exchange admin centerExchange Online
SharePoint admin centerSharePoint Online and OneDrive administration
Teams admin centerMicrosoft Teams
Microsoft Entra admin centerIdentity and access
Microsoft Intune admin centerDevice and endpoint management

For example, user administration can be performed from the Microsoft 365 admin center, while advanced Exchange configuration is normally performed through the Exchange admin center.

Microsoft documents separate workload-specific administration experiences.


Q8. What is a Microsoft 365 subscription?

A Microsoft 365 subscription represents the organization’s purchased service plan.

The subscription determines what products and services the organization is entitled to use.

Examples of services/features that may depend on licensing include:

  • Microsoft 365 Apps
  • Exchange Online
  • SharePoint
  • Teams
  • OneDrive
  • Intune
  • Security features
  • Compliance features

The exact entitlements depend on the specific plan.


Q9. What is the difference between a Microsoft 365 subscription, license and service?

These terms are related but should not be treated as identical.

Subscription

The organization’s purchased Microsoft cloud service plan.

License

An entitlement assigned to a user or otherwise consumed according to the licensing model.

Service

An individual cloud workload or service included in a license/subscription.

For example:

Microsoft 365 subscription
        ↓
Available product/license
        ↓
User assigned license
        ↓
Enabled services
        ↓
Exchange / SharePoint / Teams / OneDrive etc.

The exact licensing model varies by product and plan.


Q10. What happens if a user does not have the required Microsoft 365 license?

The user may not be able to use services that require the missing license.

For example, depending on the subscription and service:

  • Exchange Online mailbox access may not be available.
  • Microsoft 365 Apps entitlement may not be available.
  • Certain Teams capabilities may not be available.
  • Other licensed services may be unavailable.

Licensing should therefore be checked before troubleshooting an apparent service-access problem.


Q11. What is license assignment?

License assignment is the process of assigning an available product license to a user or using another supported licensing method.

Administrators can assign licenses through administrative portals and, depending on the environment, through PowerShell or automation.

After a license is assigned, individual service plans within that license can be enabled or disabled where supported.


Q12. What are service plans within a Microsoft 365 license?

A Microsoft 365 license can contain multiple service plans representing individual services or capabilities.

For example, a license may provide entitlements related to:

  • Exchange Online
  • SharePoint Online
  • Teams
  • OneDrive
  • Microsoft 365 Apps

Administrators may be able to disable specific service plans for a user when the licensing model supports it.

Therefore:

Assigning a license and enabling every service within that license are not necessarily the same thing.


Q13. What is group-based licensing?

Group-based licensing allows administrators to assign licenses to members of a group rather than manually assigning the license to every individual user.

For example:

Microsoft 365 E3 group
        ↓
Users added to group
        ↓
License assigned through group

This can simplify administration in larger environments.

It also makes licensing easier to manage when users join or leave departments.


Q14. A user has the correct Microsoft 365 license but still cannot use Exchange Online. What would you check?

I would not stop at checking the license name.

I would verify:

  1. License is actually assigned.
  2. Exchange Online service plan is enabled.
  3. User has a mailbox.
  4. Exchange provisioning has completed.
  5. User account is active.
  6. Sign-in/access policies are not blocking access.
  7. There are no service-health incidents.
  8. The user is accessing the correct account.
  9. Exchange Online configuration permits the requested operation.

This prevents confusing a licensing problem with a mailbox-provisioning or access problem.


Administrative Roles

Q15. Why should you avoid assigning Global Administrator unnecessarily?

Global Administrator is a highly privileged role.

It provides extensive administrative control across Microsoft cloud services.

Using Global Administrator for routine tasks increases the potential impact of:

  • Credential compromise
  • Accidental changes
  • Malicious activity
  • Administrative mistakes

Microsoft recommends using roles with the fewest permissions necessary. Microsoft specifically recommends limiting Global Administrator use and using lower-privileged roles where possible.


Q16. What is the principle of least privilege in Microsoft 365?

Least privilege means giving an administrator only the permissions required to perform their responsibilities.

For example:

A person responsible only for Exchange administration does not necessarily need Global Administrator permissions.

Microsoft 365 provides workload-specific administrator roles for this purpose.

Examples include:

  • Exchange Administrator
  • SharePoint Administrator
  • Teams Administrator
  • User Administrator
  • Global Reader

The goal is to reduce unnecessary administrative privilege.


Q17. What does the Exchange Administrator role allow?

The Exchange Administrator role provides administrative capabilities for Exchange Online.

Depending on the permissions model and current Microsoft implementation, it can allow administrators to manage areas such as:

  • Mailboxes
  • Mail flow
  • Exchange configuration
  • Distribution groups
  • Shared mailboxes
  • Anti-spam/anti-malware settings
  • Exchange-related administration

Microsoft documents Exchange Administrator as a dedicated role for Exchange administration rather than requiring Global Administrator for all Exchange tasks.


Q18. What does the SharePoint Administrator role do?

The SharePoint Administrator role provides administrative access to SharePoint Online.

Typical responsibilities include:

  • Creating sites
  • Deleting sites
  • Managing site settings
  • Managing sharing configuration
  • Managing site administrators
  • Managing storage settings
  • Managing SharePoint and OneDrive administration

Microsoft also notes that SharePoint Administrators do not automatically have access to all site content or every user’s OneDrive content simply because they hold the administrator role.


Q19. What is Global Reader?

Global Reader is a read-only administrative role intended for users who need visibility into Microsoft 365 administrative information without requiring broad modification permissions.

It is useful for:

  • Auditing
  • Monitoring
  • Reporting
  • Read-only administration

It is preferable to granting write-capable administrative roles when a user only needs visibility.


Q20. What is role-based access control in Microsoft 365?

Role-based access control, or RBAC, assigns permissions according to administrative roles.

Instead of individually granting every permission, an administrator is assigned a role that provides a defined set of capabilities.

For example:

Administrator
      ↓
Exchange Administrator
      ↓
Exchange management permissions

Microsoft 365 and its workloads use multiple role systems, so permissions can exist at the Microsoft 365/Entra level and within individual workloads such as Exchange Online.


Users and Groups

Q21. What is the difference between a user, security group, Microsoft 365 group and distribution group?

User

Represents an individual identity.

Security group

Primarily used for access control and permissions.

Microsoft 365 group

Provides group-based collaboration capabilities and can be associated with workloads such as Outlook, SharePoint and Teams.

Distribution group

Primarily distributes email to a group of recipients.

A simple comparison:

ObjectMain purpose
UserIndividual identity
Security groupAccess/authorization
Microsoft 365 groupCollaboration
Distribution groupEmail distribution

Microsoft documents distribution groups as email-distribution objects and Microsoft 365 groups as collaboration-oriented group objects.


Q22. When would you use a security group instead of a Microsoft 365 group?

Use a security group when the primary requirement is access control.

For example:

Finance-Users
       ↓
Access to application/resource

Use a Microsoft 365 group when the requirement is collaboration and associated Microsoft 365 resources.

The choice should be based on the business requirement rather than simply creating every group as a Microsoft 365 group.


Q23. What is a distribution group?

A distribution group is used primarily to distribute email to multiple recipients.

For example:

all-support@company.com
        ↓
User A
User B
User C
User D

The sender sends one message to the distribution group’s address, and Exchange distributes it to the group’s recipients.

Microsoft describes distribution groups as a way to send email to groups of people without entering each recipient individually.


Q24. What is the difference between a distribution group and a shared mailbox?

Distribution group

Primarily distributes incoming email to members.

Shared mailbox

Provides a common mailbox that multiple authorized users can access.

For example:

support@company.com

could be implemented as a shared mailbox when multiple users need to:

  • Read incoming messages
  • Send messages from the shared address
  • Maintain a common mailbox history

A distribution group is more appropriate when the main requirement is simply distributing messages to multiple recipients.


Q25. What is a Microsoft 365 group?

A Microsoft 365 group is a collaboration-oriented group that can provide shared resources for group members.

Depending on the workload and configuration, a Microsoft 365 group can be associated with resources such as:

  • Group mailbox/conversations
  • SharePoint site
  • Calendar
  • Files
  • Planner-related collaboration

Microsoft 365 Groups are also used as the membership foundation for many Teams scenarios.


Q26. What happens when a Microsoft 365 group is used with Microsoft Teams?

A Team is associated with a Microsoft 365 group.

The group provides the underlying membership and collaboration foundation, while Teams provides the chat, meeting and team/channel collaboration experience.

Conceptually:

Microsoft 365 Group
        ↓
Membership + collaboration resources
        ↓
Microsoft Teams
        ↓
Teams / Channels / Meetings

The exact resources exposed depend on the workload and configuration.


Microsoft 365 Service Health

Q27. What is Microsoft 365 Service Health?

Service Health provides information about incidents and advisories affecting Microsoft 365 services relevant to the organization.

It is one of the first places an administrator should check when multiple users report that a Microsoft 365 service is unavailable.

Microsoft provides Service Health through the Microsoft 365 admin center.


Q28. What is the difference between Service Health and Message Center?

Service Health

Used primarily for:

  • Active service incidents
  • Advisories
  • Service availability problems
  • Incident history

Message Center

Used primarily for:

  • Planned changes
  • New features
  • Product changes
  • Upcoming service changes
  • Administrative notifications

Therefore:

Service Health tells you what is currently going wrong; Message Center helps you understand what Microsoft is changing.

Microsoft documents both under the Health area of the Microsoft 365 admin center.


Q29. Multiple users suddenly report that Microsoft Teams is unavailable. What should you check first?

Before troubleshooting individual computers, I would check:

  1. Microsoft 365 Service Health.
  2. Teams service status.
  3. Scope of the incident.
  4. Whether users are affected across multiple locations.
  5. Internet connectivity.
  6. Authentication status.
  7. Microsoft service advisories/incidents.

If Microsoft has already identified an active service incident affecting Teams, troubleshooting every endpoint independently may waste time.


Q30. What is Message Center and why is it important for a Microsoft 365 administrator?

Message Center communicates information about upcoming Microsoft 365 changes.

Administrators can use it to identify:

  • New features
  • Feature changes
  • Retirement notices
  • Changes affecting users
  • Planned updates
  • Required administrative actions

This allows an administrator to prepare before a change affects production users.

Microsoft currently provides Message Center through the Microsoft 365 admin center and can also provide updates through the admin mobile app and other supported mechanisms.


Microsoft 365 Administration Scenarios

Q31. A newly created user cannot sign in to Microsoft 365. What would you check?

I would check:

  1. User account exists.
  2. Correct username/UPN.
  3. Account is enabled.
  4. Password is correct.
  5. Authentication requirements.
  6. Sign-in restrictions/policies.
  7. License assignment where required.
  8. Domain/UPN configuration.
  9. Service health.
  10. Whether the issue affects only one user or multiple users.

Because the user cannot sign in, I would investigate identity/authentication first rather than starting with Exchange or SharePoint.


Q32. A user can sign in but cannot access Outlook or another Microsoft 365 workload. What would you check?

I would separate:

Authentication

from:

Service entitlement/provisioning/access.

Check:

  • License assignment
  • Required service plan
  • Workload provisioning
  • Service-specific permissions
  • Account status
  • Service health
  • Workload configuration
  • Browser/client behavior

For example, successful authentication does not prove that the user has an Exchange Online mailbox.


Q33. A user has a Microsoft 365 license, but OneDrive is not available. What would you investigate?

I would check:

  1. Whether the assigned license includes the required SharePoint/OneDrive entitlement.
  2. Whether the service plan is enabled.
  3. Whether the user’s OneDrive has been provisioned.
  4. SharePoint/OneDrive service health.
  5. User account status.
  6. Organization-level OneDrive configuration.
  7. Any applicable sharing or access policies.

I would not assume that simply seeing a Microsoft 365 license name guarantees every service is enabled.


Q34. A user has an Exchange Online license but no mailbox. What would you investigate?

I would check:

  • License assignment
  • Exchange Online service plan
  • User provisioning status
  • Recipient type
  • Exchange Online configuration
  • Previous mailbox state
  • Hybrid configuration if applicable
  • Directory synchronization if the account is synchronized

The exact resolution depends on whether the environment is cloud-only or hybrid.


Q35. A distribution group is not delivering email. How would you troubleshoot it?

I would check:

  1. Is the object actually a distribution group?
  2. Are the expected members present?
  3. Is the group fully provisioned?
  4. Is the sender allowed to send to it?
  5. Are external senders allowed if required?
  6. Are there mail-flow restrictions?
  7. Is there a transport/mail-flow rule affecting the message?
  8. Is Exchange Online experiencing an incident?
  9. What does the message trace show?

Microsoft’s troubleshooting guidance specifically recommends checking whether the correct group type was created and whether external-sender settings are appropriate.


Q36. A user can send email but cannot send as a shared mailbox. What would you check?

I would verify:

  • The user has the required permission.
  • The permission is actually assigned to the correct mailbox.
  • The user is using the correct From address.
  • Outlook/client has refreshed the permissions.
  • There is no mail-flow or recipient restriction.
  • The operation is actually Send As rather than Send on Behalf.

These are different permission models.


Q37. What is the difference between Send As and Send on Behalf?

Send As

The recipient sees the message as being sent directly from the mailbox/group address.

Example:

From: support@company.com

Send on Behalf

The recipient sees that a user sent the message on behalf of another mailbox.

Example:

From: Zohaib on behalf of support@company.com

These permissions should not be treated as interchangeable.


Q38. A user says that Microsoft 365 is slow, but other users are working normally. How would you troubleshoot?

I would first determine whether the problem is:

  • User-specific
  • Device-specific
  • Network-specific
  • Workload-specific
  • Account-specific

I would check:

  1. Internet connectivity.
  2. Browser/client.
  3. Device health.
  4. User account.
  5. License/service entitlement.
  6. Workload performance.
  7. Service Health.
  8. Whether the same user experiences the issue from another device/network.

This helps distinguish a Microsoft service incident from a local problem.


Q39. All users in one office cannot access Microsoft 365, but users at another office can. What would you investigate?

The location-specific scope strongly suggests investigating the affected site’s infrastructure.

I would check:

  • Internet connectivity
  • Firewall
  • Proxy
  • DNS
  • Routing
  • ISP
  • TLS inspection
  • Network filtering
  • Microsoft 365 endpoint access

I would simultaneously check Microsoft 365 Service Health to ensure there is no service incident affecting the region.

The comparison between the working and non-working locations is extremely useful.


Q40. All users can access Microsoft 365 except users in one department. What would you investigate?

Because the scope is department-specific, I would compare:

  • Group membership
  • Licenses
  • Conditional access/access policies
  • User properties
  • Workload permissions
  • Network location if department-specific
  • Application configuration

I would select one affected user and one working user with otherwise similar roles and compare their effective configuration.


Microsoft 365 PowerShell

Q41. Why is PowerShell important for Microsoft 365 administration?

The Microsoft 365 portals are useful for interactive administration, but PowerShell is valuable for:

  • Bulk operations
  • Automation
  • Reporting
  • Repetitive administration
  • Configuration verification
  • Troubleshooting
  • Large-scale changes

For a senior administrator, PowerShell reduces the need to perform repetitive portal operations manually.


Q42. What is the Microsoft Graph PowerShell SDK?

Microsoft Graph PowerShell provides PowerShell access to Microsoft Graph APIs.

It can be used to manage and query many Microsoft cloud resources.

For example, Microsoft Graph PowerShell can be used for operations involving:

  • Users
  • Groups
  • Directory information
  • Licenses
  • Microsoft 365 resources

It is important to distinguish Microsoft Graph PowerShell from workload-specific PowerShell modules such as Exchange Online PowerShell.


Q43. How do you connect to Exchange Online PowerShell?

A common approach is:

Connect-ExchangeOnline

The command establishes an authenticated Exchange Online PowerShell session.

After connecting, administrators can use Exchange Online cmdlets to manage and troubleshoot Exchange configuration.

Always use a supported authentication method and the current Exchange Online PowerShell module.


Q44. How would you use PowerShell to investigate a Microsoft 365 administration problem?

I would first identify exactly what needs to be verified.

Examples:

Get-User

for Exchange Online user information.

Get-Mailbox

to retrieve Exchange Online mailbox information.

Get-DistributionGroup

to inspect distribution groups.

Get-DistributionGroupMember

to inspect distribution-group membership.

The exact cmdlet depends on the workload and the question being investigated.

For large environments, I would combine PowerShell with filtering and export/reporting rather than checking users individually.


Microsoft 365 Operational Best Practices

Q45. Why should Microsoft 365 administration be documented?

Because Microsoft 365 is a production service, configuration changes can affect many users.

Documentation should cover:

  • Administrative roles
  • Licensing
  • Domains
  • DNS
  • Workload configuration
  • Security settings
  • Mail flow
  • SharePoint/OneDrive configuration
  • Teams configuration
  • Major changes
  • Incident procedures

Good documentation reduces dependency on one administrator and makes troubleshooting faster.


Q46. How would you design Microsoft 365 administrator accounts?

I would avoid using a single Global Administrator account for all daily work.

A better approach is to:

  • Use separate privileged administrative identities where appropriate.
  • Assign workload-specific roles.
  • Protect privileged accounts with strong authentication and appropriate access controls.
  • Minimize Global Administrator assignments.
  • Monitor administrative activity.
  • Maintain emergency/break-glass procedures according to the organization’s security design.

The exact identity architecture should follow the organization’s security requirements.


Q47. What should you check before making a major Microsoft 365 configuration change?

I would check:

  1. Current configuration.
  2. Business impact.
  3. Affected users.
  4. Dependencies.
  5. Microsoft documentation.
  6. Current service health.
  7. Existing policies.
  8. Licensing.
  9. Change window.
  10. Rollback/recovery procedure.
  11. Communication requirements.
  12. Testing approach.

For a production change, I would test with a controlled group where practical before applying it broadly.


Real-World Senior Scenarios

Q48. A company has 2,000 users and administrators are manually assigning licenses. What would you recommend?

I would move toward standardized licensing management.

Depending on the organization’s requirements, this could include:

  • Group-based licensing
  • Standard license groups
  • Department-based assignment
  • Joiner/mover/leaver processes
  • Automated provisioning
  • Regular license-usage reporting

For example:

HR Department
      ↓
HR-M365-E3 group
      ↓
Group-based license assignment
      ↓
Eligible users receive license

This reduces manual administration and improves consistency.


Q49. A company wants help-desk staff to reset user passwords but does not want them to become Global Administrators. What would you do?

I would use an appropriate least-privileged administrative role rather than assigning Global Administrator.

The exact role should be selected based on the required help-desk capabilities.

The principle is:

Give help-desk administrators only the permissions required for their support tasks.

This follows Microsoft’s role-based administration and least-privilege approach.


Q50. You join an organization as the senior Microsoft 365 administrator. What would you review first?

I would perform an environment assessment rather than immediately changing configurations.

I would review:

Tenant

  • Tenant configuration
  • Custom domains
  • Subscriptions
  • Licensing

Identity

  • Administrative roles
  • Privileged accounts
  • User lifecycle
  • Authentication configuration

Exchange

  • Mail flow
  • Domains
  • Mailboxes
  • Shared mailboxes
  • Distribution groups
  • Connectors
  • Transport rules

SharePoint/OneDrive

  • Sites
  • Sharing
  • Storage
  • OneDrive configuration

Teams

  • Teams policies
  • Messaging
  • Meetings
  • External access/guest configuration

Security

  • Administrative security
  • Access policies
  • Security configuration
  • Monitoring

Operations

  • Service Health
  • Message Center
  • Monitoring
  • Reporting
  • Documentation
  • Backup/recovery strategy where applicable

Then I would identify configuration gaps, security risks, operational risks and areas for standardization.

I would prioritize changes based on business impact and risk rather than changing everything immediately.


Microsoft 365 Quick Command Reference

Exchange Online

Connect:

Connect-ExchangeOnline

Get a mailbox:

Get-Mailbox user@company.com

Get a user:

Get-User user@company.com

List distribution groups:

Get-DistributionGroup

Get distribution-group members:

Get-DistributionGroupMember -Identity "Group Name"

Quick Revision

Microsoft 365

  • Microsoft 365 = cloud productivity and collaboration platform.
  • A tenant is the organization’s dedicated Microsoft 365 environment.
  • onmicrosoft.com is the initial Microsoft-managed domain associated with the tenant.
  • Custom domains can be added and verified.
  • The Microsoft 365 admin center provides centralized administration.
  • Workload-specific admin centers provide deeper configuration.

Licensing

  • Subscription = purchased service plan.
  • License = entitlement assigned/consumed by users according to the licensing model.
  • Service plan = individual service/capability within a license.
  • Group-based licensing can simplify large-scale administration.

Administration

  • Use least privilege.
  • Do not use Global Administrator for routine tasks when a lower-privileged role is sufficient.
  • Exchange Administrator manages Exchange-specific administration.
  • SharePoint Administrator manages SharePoint/OneDrive administration.
  • Global Reader provides read-oriented administrative visibility.

Groups

  • Security group → access control.
  • Microsoft 365 group → collaboration.
  • Distribution group → email distribution.
  • Shared mailbox → common mailbox accessed by multiple authorized users.

Health

  • Service Health → current/recent service incidents and advisories.
  • Message Center → upcoming Microsoft 365 changes and announcements.

Troubleshooting

Always determine:

Scope → affected workload → affected users → timeline → recent changes → service health → configuration → logs/data → root cause


Exam Answer Summary

1. What is Microsoft 365?

Microsoft 365 is Microsoft’s cloud productivity and collaboration platform that provides services such as Exchange Online, SharePoint Online, OneDrive, Teams and Microsoft 365 Apps, with additional capabilities depending on licensing.

2. What is a Microsoft 365 tenant?

A tenant is an organization’s dedicated Microsoft 365 environment containing its users, groups, domains, subscriptions, services and administrative configuration.

3. What is the difference between a license and a service plan?

A license provides a set of service entitlements, while individual service plans represent specific services or capabilities within that license.

4. Why should Global Administrator not be used for everything?

Global Administrator is highly privileged. I would use the least-privileged role required for the task to reduce security and operational risk.

5. Service Health vs Message Center?

Service Health is primarily for active incidents and service advisories. Message Center is primarily for planned changes, new features and upcoming Microsoft 365 service changes.

6. Distribution group vs shared mailbox?

A distribution group primarily distributes email to multiple recipients, while a shared mailbox provides a common mailbox that multiple authorized users can access and use.

7. How would you troubleshoot a Microsoft 365 outage?

I would first determine the scope, check Microsoft 365 Service Health, identify the affected workload, compare affected and unaffected users/locations, then investigate identity, licensing, network and workload-specific configuration as appropriate.


Senior Interview Tip

For Microsoft 365 interviews, avoid answering every problem with:

“Check the admin center.”

A senior administrator should explain where to look and why.

For example:

“If multiple users suddenly cannot access Teams, I would first check Microsoft 365 Service Health because the issue may be service-wide. If only one user is affected, I would compare that user’s account, licensing, access policies and client behavior with a working user.”

That demonstrates troubleshooting methodology rather than portal memorization.

The most important Microsoft 365 administration principle is:

Identify the scope first. Then determine whether the problem is tenant-wide, workload-specific, user-specific, device-specific or network-specific.


Next Part: Microsoft 365 Interview Questions – Part 2: Exchange Online Administration & Troubleshooting

The next part will focus specifically on Exchange Online, without repeating the general Microsoft 365 administration questions covered here.

It will cover:

  • Exchange Online architecture
  • Mailboxes
  • Shared mailboxes
  • Distribution groups
  • Mail-enabled security groups
  • Mail flow
  • Accepted domains
  • Connectors
  • Transport rules
  • Message Trace
  • Send As
  • Send on Behalf
  • Mailbox permissions
  • Exchange Online troubleshooting
  • Mail delivery failures
  • NDR troubleshooting
  • Hybrid Exchange scenarios
  • Real-world Exchange Online incidents

Leave a Comment