Managing Roles in Microsoft 365
In the last chapter, you became familiar with provisioning and managing identities. This chapter will address how to grant those identities roles in the Microsoft 365 platform.
Each of these object types serves a distinct purpose, with one typically better suited to fulfill business requirements than the others.
In this chapter, we’re going to look at the following topics as they relate to the MS-102 exam objectives:
- Managing roles in Microsoft 365 and Azure AD
- Managing role groups for Microsoft Defender, Microsoft Purview, and Microsoft 365 workloads
- Managing administrative units
- Planning and implementing privileged identity management
By the end of this chapter, you should be able to describe Azure AD roles and other Microsoft 365 security management concepts. You should also understand how to assign roles.
Note
As has been mentioned elsewhere in this book, Microsoft has recently introduced the umbrella...