Identify the core features and objects of Microsoft 365 services
Identity Posture, Privilege, Auditing, and Applications
Use identity posture and activity evidence, limit standing privilege, and distinguish application definitions from tenant instances.
What you need to know
- Identity Secure Score measures alignment with Microsoft identity-security recommendations; it is not a breach probability.
- Audit logs record changes by users and administrators, while sign-in logs record authentication attempts and policy evaluation.
- PIM supports eligible, time-bound, approval- or MFA-gated activation for privileged roles.
- An app registration represents an application definition in its home tenant; an enterprise application represents its service principal in a tenant.
Objects and administrative surfaces
- Identity Secure Score, audit logs, sign-in logs, PIM, App registrations, and Enterprise applications — Microsoft Entra admin center.
- Unified audit search for supported Microsoft 365 workloads — Microsoft Purview.
How it works
- PIM replaces unnecessary standing role assignments with eligible activation and creates auditable activation history.
- The application object is the blueprint; a service principal is the local security identity governed in a consuming tenant.
When to use it
- Use Identity Secure Score to prioritize relevant improvement actions and PIM to reduce standing administrative access.
- Use App registrations for an app you develop and Enterprise applications to govern a tenant-local app instance, assignments, consent, and SSO.
Security and governance implications
- Do not chase a score without considering user impact and compensating controls.
- Review privileged role activation, consent, and application permissions regularly.
Troubleshooting signals
- Use sign-in logs for failed access, audit logs for configuration changes, and PIM history for role activation.
- If a SaaS app’s tenant assignment is wrong, inspect the enterprise application rather than changing a publisher’s app registration.
Exam traps
- Identity Secure Score is guidance, not a guarantee.
- App registration and enterprise application views expose related but different objects.
Key takeaways
- Posture → Secure Score; changes → audit logs; sign-ins → sign-in logs; temporary privilege → PIM.
- App object is a definition; service principal is the tenant instance.
Related objectives
- D1.3.f
- D1.3.g
- D1.3.h
- D1.3.i