GregLab | Exam Prep

Identify the core features and objects of Microsoft 365 services

Tenant Configuration and Licensing

Important

Learn what belongs at the tenant level, how licenses become usable services, and when a workload-specific admin center is the right destination.

Aligned to the current AB-900 guide, verified July 22, 2026.

Why this matters

AB-900 expects you to know which Microsoft 365 control plane, license, or organization setting fits a basic administration task before changing access.

Must Know

  • A Microsoft 365 tenant is the organization boundary for users, groups, subscriptions, domains, roles, and broad service settings.
  • A product license contains service plans. Licensing enables a service; permissions and roles determine access or administrative authority.
  • Direct licensing fits exceptions; group-based licensing scales standard assignments and requires administrators to resolve assignment errors.
  • Use least-privileged admin roles. Global Administrator should not be the routine answer for workload or licensing tasks.
  • The Microsoft 365 admin center is the cross-service hub; Exchange, SharePoint, Teams, Entra, and Purview admin centers handle specialized objects and policies.
  • Adding a custom domain requires ownership verification and DNS configuration; it does not automatically move mail or assign licenses.

Compare and Distinguish

  • Tenant-wide administration vs workload administration: Microsoft 365 admin center handles cross-service organization concerns; Exchange, SharePoint, Teams, Entra, and Purview handle their specialized objects and policies.
  • License vs permission: a license makes a service available to a person; a permission or role decides what that person can access or administer.
  • Organization setting vs user setting: an organization setting establishes tenant behavior or availability; a user setting affects one person’s experience.
  • Admin role vs group-based access: an admin role delegates management authority; ordinary group membership scales application, content, or license assignments.

Scenario examples

  • Scenario: A new employee sees Teams but not Exchange Online. Think: Confirm the assigned product and Exchange service plan before changing mailbox permissions.
  • Scenario: Every marketing hire needs the same Microsoft 365 bundle. Think: Assign the license to a supported group and monitor assignment errors instead of repeating direct assignments.
  • Scenario: The organization wants to restrict external sharing on one SharePoint site. Think: Move from tenant administration to the SharePoint admin center or site permissions.
  • Scenario: The company wants addresses ending in its new brand name. Think: Add and verify the custom domain, configure the required DNS records, and then update users or mail routing deliberately.

Exam traps

  • A license does not grant access to every site, mailbox, team, or agent; resource permissions still apply.
  • A disabled service plan can remove one workload while the parent product remains assigned.
  • The Microsoft 365 admin center can link to a workload admin center, but the linked task still requires the appropriate workload role.
  • Deleting or unlicensing a user is not a substitute for retention, legal hold, or a governed offboarding process.

Key takeaways

  • Tenant and organization settings set broad defaults; workload admin centers manage specialized objects and policies.
  • License → enabled service plan → provisioned feature; permission → accessible resource.
  • Groups scale assignments, roles delegate administration, and neither replaces the other.
How it works
  • License assignment supplies entitlement, the enabled service plan exposes a workload, and the workload provisions its objects. A security group can scale license or permission assignment, but group membership alone does not create an entitlement that was never assigned.
  • Group-based licensing responds to membership changes. A new member receives the assigned products; removal removes inherited assignments unless another assignment path remains. Insufficient seats, conflicting services, or missing usage location can create assignment errors.
  • Tenant settings establish organization defaults, while workload settings refine service behavior. A link from the Microsoft 365 admin center may open another admin center where a different role is required.
Objects and administrative surfaces
  • Users, groups, product licenses, service plans, subscriptions, billing, domains, organization profile/settings, service health, and admin roles — Microsoft 365 admin center.
  • Users, groups, directory roles, authentication, and access policies — Microsoft Entra admin center.
  • Recipients and mail flow — Exchange admin center; sites and sharing — SharePoint admin center; teams and policies — Teams admin center; compliance and data controls — Microsoft Purview portal.
When to use it
  • Use direct license assignment for a small exception and group-based licensing for stable role- or department-based populations.
  • Use Domains and DNS guidance when the organization needs its own sign-in or email suffix.
  • Start in Microsoft 365 admin center when the request spans the tenant; move to the specialized surface once the workload or control is clear.
Security and governance implications
  • Use the least-privileged role, keep emergency Global Administrator accounts protected, and separate billing, identity, and workload duties where practical.
  • Removing a license is not complete offboarding: block sign-in, preserve or transfer data as policy requires, remove privileged access, and handle retention separately.
  • Document group ownership and assignment purpose so automated licensing does not silently expand beyond the intended audience.
Troubleshooting signals
  • For missing features, check the user object, usage location, available seats, product assignment source, enabled service plan, provisioning status, and service health in that order.
  • For group-based licensing, inspect assignment errors and every direct or inherited license path before removing a product.
  • For custom domains, verify ownership status and service-specific DNS records; distinguish a DNS/mail-routing problem from a license or sign-in problem.
More detail
  • Tenant-wide administration covers organization profile and release preferences, subscriptions and billing, custom domains, users, groups, licenses, admin roles, service health, and broad service settings. Organization settings configure defaults or availability across the organization; they are not the same as a single user’s preferences.
  • A custom domain lets users sign in or receive mail with an organization-owned name. Microsoft first verifies domain ownership, then the administrator configures the DNS records required by the chosen services. Adding a domain does not automatically move mail or license users.
  • A Microsoft 365 product license is a bundle of service plans. The user needs an available license, a valid usage location where required, and the relevant plan enabled. Group-based licensing scales assignment through supported group membership and exposes assignment errors that administrators must resolve.
  • Admin roles delegate management authority. Choose a focused role such as License Administrator, User Administrator, Exchange Administrator, SharePoint Administrator, Teams Administrator, or AI Administrator instead of routinely using Global Administrator.
  • The Microsoft 365 admin center is a hub, not the only control plane. Use Exchange for recipients and mail flow, SharePoint for sites and sharing, Teams for Teams policies, Entra for identity and access, and Purview for information protection, lifecycle, risk, audit, and eDiscovery.

Ready for the quiz?

  • Why can a user have a license but still lack access to a file or admin task?
  • When is group-based licensing preferable to direct assignment?
  • Which clues tell you to leave the Microsoft 365 admin center for a workload-specific admin center?
  • What must happen before a custom domain can be used in Microsoft 365?

Related objectives

  • D1.1.a — Explain how license types assigned to users and groups affect access to Microsoft 365 features
  • D1.1.b — Explore the organization configurations by using the Microsoft 365 admin center (domain names and org settings)

Learn more

Free Microsoft 365 Copilot and Agent Administration Fundamentals prep

Build focused AB-900 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not identify the specific item types that will appear on an individual exam before delivery. This lane counts multiple-choice and multiple-response items as exam-style practice. Ordering and matching are supplemental learning exercises and do not count toward exam-style accuracy. Difficulty labels are calibrated to AB-900 Fundamentals, not a Microsoft-published question rating.

Reference

AB-900 topics and reference map

Study links

AB-900 resources