Browse all topics▾
Microsoft 365 Copilot
Power Platform
Microsoft Teams
SharePoint & OneDrive
Exchange & Outlook
Microsoft Entra (Identity)
- Adding a named location without breaking Conditional Access
- App consent policies and the admin consent workflow
- Assigning licenses with group-based licensing in Entra ID
- Cleaning up over-consented app permissions
- Cleaning up unused enterprise apps in Entra ID
- Compromised Microsoft 365 account response runbook
- + 52 more →
Microsoft Defender (Security)
Microsoft Purview (Compliance)
Microsoft Intune (Devices)
Viva & Apps
Developer & APIs
Migration & Tenants
Common Microsoft 365 questions
Short, direct answers to the Microsoft 365 licensing, capability, and coexistence questions admins actually type into search. Each links to the depth guide. 33 questions answered so far.
- Can I block Copilot from specific users or content in Microsoft 365?Yes on both counts. Copilot access is controlled per user by assigning or removing the Microsoft 365 Copilot licence. Content exclusion uses sensitivity labels that block Copilot processing, SharePoint Restricted Content Discovery, and specific Copilot-scoped exclusion controls in Purview.
- Can I migrate from Google Workspace to Microsoft 365 without downtime?Not with zero disruption, but close. Mailbox and file content can be migrated ahead of time while Google Workspace stays live, so the actual cutover is just the MX record change and final delta sync — typically a window of minutes to a few hours, scheduled outside working hours, rather than a multi-day blackout.
- Can I mix Microsoft 365 E3 and E5 in the same tenant?Yes. Microsoft 365 plans are per-user licences, not tenant-level SKUs, so E3, E5, F1, F3, and Business Premium can all coexist in the same tenant. Tenant-scoped services (Purview policies, Sentinel connectors, Defender features) run at the level supported by the licensed users touching them.
- Can I roll out Microsoft 365 Copilot to only some users?Yes. Copilot licences are assigned per user (directly or through a security group), and a pilot group is the recommended starting point rather than a tenant-wide switch-on. Restricting the rollout to a pilot group is standard practice, not a workaround.
- Can I use Intune without Entra ID P1?Yes for basic Intune device management, no for the enforcement mechanism most deployments actually rely on. Intune enrollment and configuration profiles work with the free Entra ID tier that ships with any Microsoft 365 subscription, but Conditional Access — which is how Intune compliance signals gate access to Microsoft 365 — needs Entra ID P1.
- Do I need a third-party backup for Microsoft 365?Usually yes, either Microsoft 365 Backup (the Microsoft add-on) or a third-party backup product. Microsoft 365 provides retention, versioning, and 93-day recycle bins that recover from routine deletion; it does not provide the point-in-time restore of a full mailbox, site, or OneDrive that most compliance frameworks and ransomware playbooks require.
- Do I need both Conditional Access and PIM?For any admin directory role, yes, use both. Conditional Access decides what happens at sign-in — MFA, device compliance, location, risk. PIM decides whether the privileged role exists to sign in with at all, by making it eligible and time-bound instead of a standing assignment. A tenant with only CA can still have an admin role assigned permanently; a tenant with only PIM can still let an activated admin session in with weak authentication.
- Do I need Entra ID P2 for Privileged Identity Management?Yes. Privileged Identity Management — just-in-time, time-bound activation of privileged roles with approval workflows and access reviews — requires Entra ID P2 (or Microsoft 365 E5, which includes it). Entra ID P1 covers Conditional Access and other baseline features, but not PIM.
- Do I need Microsoft 365 E5 for Conditional Access?No. Conditional Access needs Microsoft Entra ID P1, which is included in Microsoft 365 E3, Business Premium, and the F3 frontline plan. E5 adds Entra ID P2, which unlocks sign-in-risk and user-risk conditions via Identity Protection, plus Privileged Identity Management and access reviews.
- Do I need Teams Premium for webinars?No. Standard Microsoft Teams supports webinars up to 1,000 attendees with registration, reminders, and reporting. Teams Premium adds advanced webinar features (custom registration pages, green room, RTMP-out, presenter bios, view-only broadcasts up to 10,000 attendees), plus meeting-side features like watermarking and end-to-end encryption.
- Does labelling a Team or SharePoint site also label the files inside it?No. A container label applied to a Team, Microsoft 365 Group, or SharePoint site controls the container itself — who can be invited, from which devices, its privacy setting — not the files stored inside it. Files and emails carry their own labels, set independently. A site labelled Confidential full of files labelled General is normal and correct, not a misconfiguration.
- Does Microsoft 365 back up my data?Not in the traditional backup sense. Microsoft 365 provides item retention, recycle bins, versioning, and preservation policies that recover from deletion or corruption inside the service, but it does not provide the point-in-time restore of a full mailbox, SharePoint site, or OneDrive that a backup product delivers. Microsoft 365 Backup is a Microsoft add-on that fills the gap for a per-GB fee; third parties (Veeam, Commvault, Barracuda, AvePoint, Rubrik, HYCU, Keepit, Redstor) do the same.
- Does Microsoft 365 Business Premium include Intune?Yes. Microsoft 365 Business Premium includes Microsoft Intune for device and app management, alongside Entra ID P1, Defender for Business, and the Office desktop apps. The 300-seat cap on the plan itself is the practical limit, not an Intune feature limit.
- Does Microsoft 365 comply with GDPR?Microsoft 365 provides the controls needed for a GDPR-compliant deployment and Microsoft signs the standard EU Data Protection Addendum as a data processor. Compliance itself is a shared responsibility: Microsoft runs the platform in line with its commitments, and the tenant is the data controller responsible for configuring retention, DSAR handling, DPIA records, and lawful basis for the data it stores.
- Does Microsoft 365 Copilot need a separate Microsoft 365 licence?Yes. Microsoft 365 Copilot is a per-user add-on that requires an eligible base licence: Microsoft 365 E3, E5, Business Standard, or Business Premium (Office 365 E3/E5 also qualify). It cannot be bought on its own or on frontline F1/F3 plans.
- Does Microsoft 365 E3 include Copilot?No. Microsoft 365 Copilot is licensed as a standalone per-user add-on layered on top of an existing Microsoft 365 E3, E5, Business Standard, or Business Premium seat — it is not bundled into any base plan. E3 gives you the eligibility to buy Copilot; it does not give you Copilot itself.
- Does Microsoft 365 E5 include Power BI Pro?Yes. Microsoft 365 E5 includes a Power BI Pro licence per user. Microsoft 365 E3 does not — E3 users need a Power BI Pro or Power BI Premium Per User (PPU) add-on, or the workspace they consume must be backed by a Fabric F-SKU capacity that grants free-user consumption.
- Does Microsoft 365 help with NIS2 compliance?Microsoft 365 provides many of the technical controls NIS2 expects an organisation to have — Conditional Access and MFA, audit logging, incident detection through Defender and Sentinel, and a documented security posture via Compliance Manager — but NIS2 compliance is a legal and organisational obligation on the entity itself, not something a licence tier grants automatically. There is no NIS2 assessment template shipped for every tenant by default; check Compliance Manager's current template library for what's directly mapped.
- Does Microsoft Purview work with Google Workspace?Partially. Microsoft Purview eDiscovery, DLP, and Insider Risk Management have connectors that ingest Google Workspace mail, drive, and chat as a third-party data source for discovery and DLP. Sensitivity labels only apply to Microsoft file formats and PDF; they do not label native Google Docs, Sheets, or Slides in place.
- Does SharePoint Embedded need its own licence?Yes. SharePoint Embedded is a separate, consumption-based offering for developers building file storage into their own applications — it is billed by usage (storage and API calls) through Azure, not included in standard Microsoft 365 or SharePoint Online per-user licensing.
- How do MSPs manage DMARC rollout across multiple client tenants?The DMARC journey itself doesn't change per client — publish p=none, fix legitimate senders, move to quarantine then reject — but at MSP scale, two things matter that don't come up managing a single domain: confirming which tenant a DNS record belongs to before touching it, and asking each client upfront for every marketing, helpdesk, invoicing, and HR-system integration that sends mail as their domain, since the client rarely remembers all of them unprompted.
- How long does a Microsoft 365 tenant-to-tenant migration take?Three to nine months for a mid-sized organisation, covering discovery and design, identity and domain planning, mailbox and file migration in waves, Teams and SharePoint migration, device re-enrolment, and cutover. Small tenants move faster; the domain move — which requires a real cutover window — is the fixed constraint no tooling removes entirely.
- How many external guests can I add to a Microsoft 365 tenant?Entra ID allows up to 50,000 external user objects per paid Entra ID licence assigned in the tenant, which puts the ceiling far above what most organisations ever need. The practical limit is governance — access packages, sponsors, reviews, and lifecycle — not the SKU.
- Is Defender for Endpoint included in Microsoft 365 E3?No. Microsoft 365 E3 does not include Defender for Endpoint. It is included in Microsoft 365 E5, in the E5 Security add-on that sits on top of E3, or as a Defender for Endpoint Plan 1 or Plan 2 standalone per-user licence.
- Is Defender for Office 365 Plan 1 enough, or do I need Plan 2?Plan 1 is the minimum any business tenant should run — it covers prevention: Safe Links, Safe Attachments, and advanced anti-phishing. Plan 2 adds the response layer — Automated Investigation and Response, Threat Explorer, Campaign Views, and Attack Simulation Training — and pays for itself wherever someone actually works a security queue. If nobody in the organisation will ever open Threat Explorer, Plan 1 is the right call.
- Is Entra ID P2 worth it over P1?Entra ID P2 is worth it when Identity Protection risk-based Conditional Access, Privileged Identity Management for admin roles, access reviews, or Entitlement Management access packages are part of the operating model. Where those are not yet in scope, P1 covers the everyday Conditional Access, MFA, and self-service password reset needs.
- Should I use Password Hash Sync or Pass-Through Authentication?Password Hash Sync (PHS) for almost everyone. It has no on-premises dependency at sign-in time, supports Identity Protection's leaked-credential detection, and can act as a resilient fallback even alongside federation. Pass-Through Authentication (PTA) is for the specific case where regulatory or internal policy forbids storing password hashes in the cloud — accept that an on-premises outage then also stops cloud sign-in, since PTA authenticates against on-prem AD through an agent.
- What happens to shared mailboxes during a tenant-to-tenant migration?Shared mailboxes migrate with the same tooling as user mailboxes — content and the mailbox object move across. What doesn't come along automatically is the web of delegate permissions (Send As, Send on Behalf, Full Access) and distribution-group memberships pointing at them; those have to be inventoried before cutover and rebuilt in the target tenant, or users lose access the moment the mailbox lands.
- What is the difference between Microsoft 365 and Office 365?Office 365 is the productivity workload — Exchange Online, SharePoint, OneDrive, Teams, and the Office apps. Microsoft 365 is Office 365 bundled with Windows 10/11 Enterprise use rights, Entra ID (P1 in E3, P2 in E5), Microsoft Intune, and the security and compliance add-ons (Defender for Endpoint, Purview premium, PIM, Identity Protection at the E5 tier).
- What is the difference between Teams Essentials and Teams in Microsoft 365?Teams Essentials is a standalone Teams subscription for small businesses — chat, meetings, calling, and file sharing without a full Microsoft 365 tenant. Teams inside Microsoft 365 Business or Enterprise is tenant-integrated: it runs on the tenant's Entra ID, uses SharePoint for files and Exchange for calendars, and honours Conditional Access, DLP, and every other tenant policy.
- What should be in the Windows Autopilot must-install app list?Keep the must-install (ESP-blocking) list to only what genuinely has to be on the device before the user starts working — most Autopilot complaints about slow provisioning or stalled Enrollment Status Pages trace back to an oversized must-install list, not a problem with Autopilot itself. Everything else should be assigned separately so it installs quietly in the background after the user is already at their desktop.
- What's the difference between DLP and sensitivity labels in Microsoft Purview?A sensitivity label classifies content and can apply encryption, markings, and container controls — it's metadata that travels with the file. A DLP policy is a separate rule engine that inspects content and activity (sending, sharing, copying to USB) against a location, a condition, and an action, and a label is one of the conditions DLP can act on. Neither replaces the other: labels classify and protect the content itself, DLP watches what happens to it and can stop a risky action outright.
- What's the fastest way to decommission the last on-prem Exchange server?There's no shortcut, but there is a defined sequence: confirm recipient attribute management has moved off the on-prem server (using the management-tools-only path Microsoft now supports), confirm nothing still relays mail through it, confirm public folders (if any) have migrated, then remove it. Skipping the check on any one of those is the most common cause of a decommission that has to be undone.
Missing a question you searched for? The full catalogue lives under /guides.