🎓 Interview Preparation
Interview Preparation Guide
80+ real interview questions from actual Microsoft 365 administrator interviews — organised by topic with detailed model answers.
How to Use This Guide
Follow this approach to get the most out of your interview preparation
Study by Topic
Start with your strongest area to build confidence, then move to weaker topics.
Understand the “Why”
Don’t just memorize answers. Understand WHY things work the way they do.
Practice Scenarios
Use the STAR method: Situation, Task, Action, Result for behavioral questions.
Read the Articles
Each topic links to a detailed blog article for much deeper understanding.
Prepare Your Intro
Keep “Tell me about yourself” to 2-3 minutes with numbers and achievements.
Ask Great Questions
Always have 3-5 thoughtful questions ready to show genuine interest.
Interview Topics
Click any topic to explore the detailed guide and related articles
Microsoft Entra ID & Identity
- Hard match vs soft match in Entra Connect sync
- Password Hash Sync vs Pass-Through Authentication vs ADFS
- Conditional Access — configuring MFA and compliance-based policies
- Dynamic group membership rules and use cases
- Admin roles — least privilege, PIM, and administrative units
- Self-Service Password Reset (SSPR) setup and authentication methods
- Identity Protection — risky sign-ins and user risk policies
- B2B collaboration, external guest access, and lifecycle management
Exchange Online & Mail Flow
- Email flow from cloud to internet and back
- Hybrid mail flow with 100,000+ mailboxes
- Centralized mail flow configuration
- Mail-enabled security group vs security group
- MX record configuration and hybrid impact
- Troubleshooting email not being received
- Accepted domains and authoritative domains
- Hidden Outlook folders and mailbox scenarios
DLP & Compliance
- What is DLP and how to configure policies
- Creating DLP policy to block random numbers
- Sensitive Information Types and Custom SIT
- Sensitivity labels — creation and auto-labeling
- Microsoft Information Protection (MIP) overview
- Behavior of Internal, Confidential, Public labels
- Blocking emails to external users via transport rule
- PII dashboard in Microsoft Purview portal
Microsoft Defender XDR
- Microsoft 365 Defender portal — navigation and workloads overview
- Defender for Office 365 — Safe Links, Safe Attachments, anti-phishing
- Zero-Hour Auto Purge (ZAP) and how it retroactively removes threats
- Defender for Endpoint — device onboarding and threat detection
- Incident and alert management across all Defender workloads
- Microsoft Secure Score — measuring and improving security posture
- Advanced Hunting with KQL in the Defender portal
- Attack Simulation Training — phishing campaigns and user reporting
Complete Administration Guide →Defender for Office 365 Deep Dive →
Intune & Device Management
- Configuration policies vs compliance policies
- Device enrollment process and prerequisites
- Types of policies available in Intune
- Troubleshooting device enrollment failures
- Device diagnostics and log locations in Intune
- MDM vs MAM explained
- Conditional access with device compliance
- Enrollment methods (Autopilot, DEP, BYOD)
SharePoint Online
- Team sites vs Communication sites
- Blocking external sharing of a specific site
- Restricting sharing to specific external domains
- Permission model — Owners, Members, Visitors
- Broken permission inheritance troubleshooting
- Hub sites — purpose and administration
- Unmanaged device access restrictions
- SharePoint admin roles and access levels
Microsoft Teams
- Teams architecture — SharePoint & Exchange backbone
- Standard, Private, and Shared channel differences
- External access (federation) vs Guest access
- Teams policy types and assignment
- Teams + Exchange integration for meetings
- Teams admin roles and least-privilege access
- Teams lifecycle — creation, expiry, archival
- Preventing team sprawl with governance policies
OneDrive for Business
- OneDrive vs SharePoint architecture
- Data recovery — recycle bin, restore, version history
- Known Folder Move (KFM) — deployment and options
- Departed user OneDrive retention configuration
- Restricting sync to managed devices only
- Files On-Demand — purpose and behaviour
- Storage quota management per user
- Purview retention policies on OneDrive
Sample Interview Questions by Round
Real questions asked in actual Microsoft 365 administrator interviews — click any linked question to jump to its detailed answer
Common Questions in Round 1
- Introduce yourself — your experience and key technologies you work with daily
- What issues have you faced with AD Connect and how did you resolve them?
- What is hard match and soft match in Active Directory synchronization?
- What is the difference between Password Hash Sync and Pass-Through Authentication?
- What types of policies are there in Intune?
- What is DLP policy? Have you configured any? Can you walk me through it?
- What is the difference between a mail-enabled security group and a security group?
- What is ZAP in Microsoft Defender for Office 365 and how does it work?
- What are the uses of SPF, DKIM, and DMARC records?
- What does an SCL value of -1 mean?
Advanced Questions in Round 2
- Brief introduction about the technologies you use in your daily activities
- If MX is pointed to Exchange Online, how does centralized mail flow operate in hybrid?
- In an environment with 100,000+ mailboxes, how does inbound/outbound mail flow for cloud users?
- How many Azure AD Connect servers are required for 100,000+ users?
- How do you troubleshoot if an object is not syncing? What services do you check?
- How does encryption work for data at rest and data in transit in Microsoft 365?
- What is a Custom Sensitive Information Type (CustSIT) and when would you use it?
- How does device enrollment work in Intune and what are the prerequisites?
- How do you block external sharing of a specific SharePoint site?
- What is the difference between external access and guest access in Microsoft Teams?
Scenario Questions in Round 3
- Your organisation received 6,000 bulk phishing emails. Walk me through your response approach.
- We work with critical partners whose emails must be delivered. How do you ensure seamless delivery?
- If detection technology is “spam filter” and we don’t want it quarantined, where do you create the exception?
- What is the difference between soft fail and hard fail in SPF? Which should a new organisation use?
- A new organisation was acquired — what steps do you follow to allow email from their domain in M365?
- A user’s primary mailbox and in-place archive are both full with litigation hold enabled. How do you resolve this?
- A user permanently deleted all their files from OneDrive. What are the recovery options?
- Your organisation has 500+ Teams and no governance policy. How do you address the sprawl?
AI Mock Interview Call
Practice with a professional AI interviewer — voice-based, covers all M365 topics, 100% free, no login needed.
Alex — Senior M365 Interviewer
Alex will run a full 8-question mock interview covering Exchange, Intune, Defender, Teams, SharePoint, Azure AD and more. Speak your answers naturally — just like a real call.
⚡ Best on Chrome or Edge · Microphone permission required
Connecting to Alex…
Ready to Level Up Your M365 Skills?
Explore our free troubleshooting guides, PowerShell scripts, and real interview questions covering every Microsoft 365 service.