Staff Aug: 365

0.0(0)
studied byStudied by 0 people
0.0(0)
full-widthCall with Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/44

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No study sessions yet.

45 Terms

1
New cards

A user can’t access any M365 apps. What’s your Tier-3 triage flow?

Confirm scope (one user vs many) → check Microsoft Service Health → check Entra ID Sign-in logs → review Conditional Access result + MFA → verify account status/licenses → confirm device/time sync → isolate client vs identity vs service.

2
New cards

What’s the most important question before troubleshooting?

What changed recently (policy

3
New cards

Where do you start for most access failures?

Entra ID Sign-in Logs: look at status

4
New cards

How do you troubleshoot Conditional Access blocks quickly?

Identify user + app + time → sign-in log → Conditional Access tab to see which policy applied and what control failed → confirm exclusions (break-glass/admin) → validate named locations/device state.

5
New cards

What are common Conditional Access failure reasons?

MFA not satisfied

6
New cards

How do you confirm if MFA vs password is the issue?

Check Authentication Details in sign-in logs: “MFA required/satisfied”

7
New cards

User says MFA prompts loop or fail. What do you check?

Authenticator registration

8
New cards

How do you handle a multi-user outage due to policy change?

Stop/rollback recent change (or disable policy) → communicate status → validate sign-ins → reintroduce control with scoped pilot group and exclusions.

9
New cards

What’s a safe CA rollout approach?

Pilot group → monitor sign-in logs → expand in phases → keep break-glass accounts excluded → document rollback plan.

10
New cards

A user can access Outlook Web but not Outlook desktop. What do you suspect?

Client auth differences (modern auth vs legacy)

11
New cards

What’s your go-to for Outlook connectivity issues?

Microsoft Remote Connectivity Analyzer

12
New cards

Email not delivering to external recipients. What’s your Tier-3 flow?

Message trace → identify failure point → check connectors → transport rules → outbound spam policy/quarantine → DKIM/SPF/DMARC → check blocklists → verify accepted domains.

13
New cards

Internal user says “emails stuck in Outbox.” What do you check?

Client vs service: Outlook profile

14
New cards

How do you troubleshoot “NDR 550 5.7.1” rejected messages?

Check transport rule

15
New cards

What’s the fastest way to determine mail flow path?

Message trace with details: shows connector/rule actions

16
New cards

Phishing got through. What do you review in M365?

Defender quarantine policies

17
New cards

A mailbox has a suspicious auto-forwarding rule. What do you do?

Disable rule/forwarding

18
New cards

How do you revoke active sessions after suspected compromise?

Entra ID: revoke refresh tokens/sign out sessions; reset password; require MFA re-registration if needed; review sign-in logs after.

19
New cards

Teams: User can’t join meetings externally. What do you check?

Teams admin settings: external access/federation

20
New cards

Teams: Calls drop / audio issues for many users. What’s your approach?

Check Service Health + Teams admin center health

21
New cards

What is the quickest way to prove a Teams issue is network-related?

Teams Call Quality Dashboard/Call analytics showing packet loss/jitter correlated to a site/network.

22
New cards

Teams: User sees “We couldn’t sign you in.” What do you check?

Entra sign-in logs for Teams; Conditional Access blocks; device compliance; time sync; Office token refresh; clear Teams cache.

23
New cards

SharePoint: External user can’t access shared file. What do you check?

Sharing settings at tenant + site level

24
New cards

SharePoint: Users report “Access denied” after a change. What do you suspect?

Permission inheritance changes

25
New cards

OneDrive: Sync errors occur for one user. What’s Tier-3 flow?

Check client version

26
New cards

OneDrive: Sync failing for many users. What do you do first?

Check Service Health

27
New cards

Intune: Device shows compliant but access still blocked. What do you check?

Conditional Access requiring compliant device might be evaluating wrong device state; verify device in Entra (registered/joined)

28
New cards

What device states matter for CA “require compliant device”?

Device must be enrolled and reporting compliance to Intune

29
New cards

User can’t enroll device into Intune. What are common causes?

Enrollment restrictions

30
New cards

How do you confirm if a Windows device is Entra joined?

On device: dsregcmd /status → check AzureAdJoined/DomainJoined

31
New cards

What does “hybrid join issues” usually trace back to?

AAD Connect configuration

32
New cards

User is prompted to sign in repeatedly across apps. What do you suspect?

Token issues due to CA changes

33
New cards

How do you determine if it’s a licensing issue?

Confirm user has required service plan enabled (Exchange/Teams/SharePoint)

34
New cards

What’s the Tier-3 approach to “it worked yesterday” issues?

Ask what changed → check audit logs (CA/policy changes

35
New cards

Where do you look for “what changed” in Entra/365?

Audit logs in Entra

36
New cards

A policy broke access for a VIP. How do you respond?

Restore access safely (temporary exclusion or rollback) → communicate with director → root cause in sign-in logs → implement a phased fix.

37
New cards

How do you avoid becoming a bottleneck in escalations?

Resolve with the internal team present

38
New cards

What’s your default incident communication cadence?

Initial acknowledgement + impact

39
New cards

What makes a troubleshooting approach ‘senior’?

Hypothesis-driven

40
New cards

How do you know when to escalate to Microsoft Support?

When tenant config is verified

41
New cards

What evidence do you collect before engaging Microsoft Support?

Timestamps

42
New cards

What are top recurring causes of M365 incidents in SMB/midmarket?

Conditional Access mis-scoping

43
New cards

How do you validate a fix is stable?

Monitor sign-in logs/message trace/health for 24–48 hours

44
New cards

What is a “good rollback plan” for identity changes?

Document current policy state

45
New cards