Book Image

Microsoft 365 Security, Compliance, and Identity Administration

By : Peter Rising
5 (1)
Book Image

Microsoft 365 Security, Compliance, and Identity Administration

5 (1)
By: Peter Rising

Overview of this book

The Microsoft 365 Security, Compliance, and Identity Administration is designed to help you manage, implement, and monitor security and compliance solutions for Microsoft 365 environments. With this book, you’ll first configure, administer identity and access within Microsoft 365. You’ll learn about hybrid identity, authentication methods, and conditional access policies with Microsoft Intune. Next, you’ll discover how RBAC and Azure AD Identity Protection can be used to detect risks and secure information in your organization. You’ll also explore concepts such as Microsoft Defender for endpoint and identity, along with threat intelligence. As you progress, you’ll uncover additional tools and techniques to configure and manage Microsoft 365, including Azure Information Protection, Data Loss Prevention (DLP), and Microsoft Defender for Cloud Apps. By the end of this book, you’ll be well-equipped to manage and implement security measures within your Microsoft 365 suite successfully.
Table of Contents (25 chapters)
1
Part 1: Implementing and Managing Identity and Access
7
Part 2: Implementing and Managing Threat Protection
13
Part 3: Implementing and Managing Information Protection
17
Part 4: Managing Compliance Features in Microsoft 365

Planning and implementing adaptive scopes

As you have already seen in this chapter, when you create a retention policy or retention label policy, you are required to choose between adaptive and static scope types to define the scope of the policy. In previous examples, you have used static scopes wherein the administrator chooses the locations and the criteria for retention. Static scopes have more limited configuration options, such as including or excluding locations and instances within those locations.

With adaptive scopes, you can specify queries that enable the dynamic inclusion of users who should be targeted by the scope. Adaptive scopes run daily to pick up any changes that may apply, such as a new user account being added to Microsoft 365 that has a department field selection or a job title selection that matches an adaptive scope query. It is possible to use multiple adaptive scopes within a single policy.

Some advantages of using adaptive scopes include the following...