Courses Job Ready Program Fresher Trainings AI For Class 7 to 12 Corporate Training Placements Tutorials
Free Learning Resources

IT Tutorials & Interview Prep

Free guides, interview Q&As, and job responsibility breakdowns — curated by industry veterans to help you crack MNC interviews

206+
Tutorial Articles
14
Topic Categories
100%
Free to Read
← Back to Learning Hub

Microsoft 365 : day2 —Admin Roles & User Account States

Learning Hub Last Updated: Aug 07, 2026

Key Points, Definitions, Diagrams, Term Differences & Q&A

1. 25 Most Important Key Points

  • A new Microsoft 365 tenant automatically receives a default domain (tenantname.onmicrosoft.com), which remains usable but looks less professional.
  • Adding a Custom Domain lets users have professional email addresses like john@company.com instead of john@company.onmicrosoft.com.
  • Custom domain setup requires an active tenant, domain ownership, and Global Administrator (or domain management) permissions.
  • Domain ownership is verified using a unique TXT record that Microsoft generates and the admin adds to the domain's DNS zone.
  • After verification, additional DNS records (MX, CNAME, SRV) must be configured for email, Outlook AutoDiscover, and Teams to function correctly.
  • Once all required DNS records are validated, the domain status changes to "Healthy" and can be assigned to users, mailboxes, and groups.
  • Common domain setup issues include verification failure (bad TXT record), broken email (bad/missing MX), and AutoDiscover problems (bad/missing CNAME).
  • Microsoft 365 supports two user creation methods: Manual Creation (one at a time) and CSV Bulk Import (many at once).
  • Manual user creation is best for small organizations or a handful of new hires needing individual customization.
  • CSV Bulk Import lets administrators create hundreds of users at once by uploading a spreadsheet of user details, ideal for large-scale onboarding.
  • A CSV file organizes user data in rows and columns, with each row representing one user account (Username, First Name, Last Name, etc.).
  • After a CSV import, Microsoft 365 generates a report showing which accounts succeeded and which failed, along with error messages.
  • Common CSV import issues include invalid username formats, duplicate accounts, missing required fields, and insufficient available licenses.
  • A Group in Microsoft 365 is a collection of users managed as a single unit, so permissions can be assigned once to the group instead of per user.
  • Microsoft 365 supports four main group types: Microsoft 365 Group, Security Group, Distribution Group, and Mail-Enabled Security Group.
  • A Microsoft 365 Group is built for collaboration, bundling a shared mailbox, calendar, Teams integration, SharePoint site, and Planner.
  • A Security Group is used purely to assign permissions and control access — it has no collaboration features like shared mailboxes.
  • A Distribution Group exists solely for group email communication — sending one email reaches every member.
  • A Mail-Enabled Security Group combines permission assignment with group email capability in a single object.
  • Adding a user to a group instantly grants them all the access and resources tied to that group, without configuring individual permissions.
  • Users can be added to a group either during group creation or afterward at any time through the Microsoft 365 Admin Center.
  • Removing a user from a group automatically revokes the access that came with that group membership.
  • Best practices for group management include using meaningful names, following least privilege, and reviewing membership regularly.
  • Groups make onboarding faster: a new employee added to the right group(s) immediately gets all the access their role requires.
  • Consistent group-based permission management reduces administrative errors compared to configuring access user by user.

 

2. 20 Definitions with Day-to-Day Examples

Custom Domain

Definition: An organization-owned domain (like company.com) added to Microsoft 365 to replace the default onmicrosoft.com domain.

Day-to-Day Example: Like a business getting its own named storefront sign instead of using a generic shared mall directory listing.

Domain Registrar

Definition: A company (like GoDaddy or Namecheap) from which an organization purchases and manages its domain name.

Day-to-Day Example: Like the land registry office where you officially register ownership of a piece of property.

TXT Record

Definition: A DNS record storing text data, used by Microsoft 365 to verify that an organization actually owns a domain.

Day-to-Day Example: Like showing a secret verification code to prove you're the rightful owner before being granted a service.

MX Record

Definition: A DNS record specifying which mail server should receive email for a domain — points to Exchange Online in Microsoft 365.

Day-to-Day Example: Like the mailroom address on an envelope telling the postal service exactly where to deliver it.

CNAME Record

Definition: A DNS record that creates an alias, redirecting one domain name to another — used for Outlook AutoDiscover and service connectivity.

Day-to-Day Example: Like a forwarding notice at an old office directing visitors to the actual new location.

SRV Record

Definition: A DNS record used by communication services like Microsoft Teams to locate specific network services.

Day-to-Day Example: Like a directory sign in a large complex pointing you to exactly which department handles a specific service.

DNS Propagation

Definition: The time it takes for DNS record changes to update and become visible across the internet's DNS servers.

Day-to-Day Example: Like waiting for a change-of-address update to filter through to every post office before mail reliably follows the new route.

Manual User Creation

Definition: Creating individual Microsoft 365 user accounts one at a time through the Admin Center.

Day-to-Day Example: Like a hotel front desk checking in guests one at a time, filling out each registration by hand.

CSV Bulk Import

Definition: Creating many Microsoft 365 user accounts at once by uploading a spreadsheet file with user details.

Day-to-Day Example: Like a hotel processing an entire tour group's check-in from one pre-submitted passenger manifest instead of registering each guest individually.

CSV File

Definition: A spreadsheet file storing data in rows and columns, where each row typically represents one user record.

Day-to-Day Example: Like a class roster spreadsheet listing every student's name and details in neat rows, one row per student.

Group (Microsoft 365)

Definition: A collection of users managed as a single unit so permissions and resources can be assigned collectively.

Day-to-Day Example: Like a team roster — granting locker room access to the whole roster at once instead of issuing separate keys to each player.

Microsoft 365 Group

Definition: A group type providing shared collaboration resources like a mailbox, calendar, Teams integration, and SharePoint site.

Day-to-Day Example: Like giving a project team a shared office suite complete with a mailbox, meeting room, and filing cabinet, all bundled together.

Security Group

Definition: A group type used purely to assign permissions and control access to resources, with no collaboration features.

Day-to-Day Example: Like a keycard group that opens a specific set of doors, with no shared lounge or mailbox attached to it.

Distribution Group

Definition: A group type used for sending one email to every member of the group simultaneously.

Day-to-Day Example: Like a household mailing list — one letter addressed to "the Smith Family" that everyone in the house gets to read.

Mail-Enabled Security Group

Definition: A group type combining permission assignment with group email capability in one object.

Day-to-Day Example: Like a keycard group that also happens to share a group mailbox — access control and email rolled into one.

Group Membership

Definition: The state of a user being added to a group, which automatically grants them the group's associated access and resources.

Day-to-Day Example: Like joining a club — the moment you're a member, you automatically get access to everything the club offers.

Least Privilege (in Group Management)

Definition: The practice of only adding users to groups that are strictly necessary for their job responsibilities.

Day-to-Day Example: Like only handing out keys to the specific rooms an employee actually needs to enter, not the whole building.

Domain Status "Healthy"

Definition: The state indicating a custom domain's DNS records are all correctly configured and validated by Microsoft.

Day-to-Day Example: Like a building passing every safety inspection and finally being cleared for full occupancy.

Bulk Onboarding

Definition: The process of creating and provisioning many new user accounts at once, typically during large hiring waves or migrations.

Day-to-Day Example: Like an airline processing an entire chartered flight's passenger check-in as one batch instead of individually.

License Assignment

Definition: The process of granting a specific Microsoft 365 subscription plan to a user, determining which services they can access.

Day-to-Day Example: Like handing someone a specific gym membership card that unlocks only the facilities included in that particular plan.

 

3. Differences Between Key Technical Terms (10)

1. Default Domain vs. Custom Domain

FeatureDefault DomainCustom Domain
Formattenant.onmicrosoft.comcompany.com
Provided byMicrosoft automaticallyPurchased by the organization
Removable?Cannot be fully removedCan be added, changed, or removed
Professional appearanceLess professionalProfessional, brand-consistent



 

2. TXT Record vs. MX Record vs. CNAME Record vs. SRV Record

RecordPurpose in Microsoft 365
TXT RecordVerifies domain ownership
MX RecordRoutes incoming email to Exchange Online
CNAME RecordSupports service discovery, e.g., Outlook AutoDiscover
SRV RecordSupports Teams and other communication services



 

3. Manual User Creation vs. CSV Bulk Import

FeatureManual CreationCSV Import
Number of usersSingle userMultiple users
SpeedSlowFast
Administrative effortHighLow
Suitable forSmall organizationsMedium and large organizations
User customizationHighModerate



 

4. Microsoft 365 Group vs. Security Group

FeatureMicrosoft 365 GroupSecurity Group
PurposeCollaboration among usersManaging permissions and access
Includes shared mailbox/Teams?YesNo
Main use caseTeamwork and communicationSecurity and access management



 

5. Security Group vs. Distribution Group

FeatureSecurity GroupDistribution Group
Used forPermission/access controlGroup email communication
Grants app/resource access?YesNo
ExampleControlling access to a business apphr@company.com reaching all HR staff



 

6. Distribution Group vs. Mail-Enabled Security Group

FeatureDistribution GroupMail-Enabled Security Group
Sends group email?YesYes
Assigns permissions?NoYes
Best forSimple email distribution onlyCombining email + access control



 

7. Adding Members During Group Creation vs. After Creation

FeatureDuring CreationAfter Creation
When it happensAs part of the group setup wizardAnytime afterward via Admin Center
FlexibilityConvenient for initial setupNeeded for ongoing changes (new hires, transfers)



 

8. Domain Verification Failure vs. Email Delivery Failure

IssueCauseFix
Domain Verification FailureTXT record missing or incorrectRe-check DNS entry, wait for propagation
Email Not WorkingMX record missing or incorrectVerify Exchange Online MX record configuration



 

9. CSV Import Common Errors Compared

ErrorCauseFix
Invalid UsernamesIncorrect username/email formatVerify correct format before uploading
Duplicate AccountsUser already existsCheck existing users before import
Missing Required FieldsMandatory columns left blankComplete all required CSV columns
License Assignment ErrorsInsufficient available licensesPurchase or free up additional licenses



 

10. Group Membership Granted vs. Group Membership Removed

ActionEffect
User added to a groupAutomatically inherits that group's associated access and resources
User removed from a groupAutomatically loses the access tied to that group membership



 

4. Theoretical Questions (15)

Q1. Why do organizations add a custom domain to Microsoft 365 instead of using the default domain?

Answer: A custom domain gives users professional email addresses matching the company's brand, improving credibility and customer trust compared to the generic tenant.onmicrosoft.com address.

Q2. What is required before an organization can add a custom domain?

Answer: An active Microsoft 365 tenant, ownership of the domain (purchased from a registrar), and Global Administrator or domain management permissions.

Q3. What is the role of a TXT record in the custom domain setup process?

Answer: The TXT record proves domain ownership — Microsoft generates a unique value that must be added to the domain's DNS before Microsoft will allow the domain to be used.

Q4. What DNS records are typically configured after domain verification, and what does each support?

Answer: MX (email routing to Exchange Online), CNAME (service discovery like Outlook AutoDiscover), and SRV (Teams and communication services).

Q5. What does it mean when a domain's status becomes "Healthy" in Microsoft 365?

Answer: It means all required DNS records have been correctly configured and validated, and the domain is now fully ready to be assigned to users and services.

Q6. What is the difference between Manual User Creation and CSV Bulk Import?

Answer: Manual creation adds users one at a time through the Admin Center, suited to small numbers, while CSV Bulk Import creates many users at once from a spreadsheet, suited to large-scale onboarding.

Q7. What information does a CSV file typically contain for bulk user creation?

Answer: Each row represents one user, with columns like Username, First Name, Last Name, Display Name, Department, and Job Title.

Q8. What common errors can occur during CSV import, and what causes them?

Answer: Invalid usernames (wrong format), duplicate accounts (user already exists), missing required fields (blank mandatory columns), and license assignment errors (not enough available licenses).

Q9. Why do organizations use Groups instead of assigning permissions to individual users?

Answer: Groups let administrators assign permissions once to the group, and every member automatically inherits that access, which is far more efficient and consistent than configuring each user individually.

Q10. What is the difference between a Microsoft 365 Group and a Security Group?

Answer: A Microsoft 365 Group provides collaboration resources like a shared mailbox, calendar, and Teams integration, while a Security Group is used purely to manage permissions and access, without collaboration tools.

Q11. What is a Distribution Group used for?

Answer: A Distribution Group is used for group email communication — sending one email to the group's address delivers it to every member.

Q12. What is a Mail-Enabled Security Group, and how does it differ from a plain Security Group?

Answer: A Mail-Enabled Security Group combines the permission-assignment capability of a Security Group with the group email capability of a Distribution Group, in a single object.

Q13. What happens automatically when a user is added to a Microsoft 365 Group?

Answer: The user immediately gains access to the group's shared mailbox, calendar, Teams resources, SharePoint site, and OneDrive collaboration features, without any additional configuration.

Q14. What happens when a user is removed from a group?

Answer: The access associated with that group membership is automatically revoked for the user.

Q15. What best practices help keep group management secure and organized?

Answer: Using meaningful group names, following the principle of least privilege, reviewing membership regularly, using groups instead of individual permissions, and documenting each group's purpose.

5. Scenario-Based Questions (8)

Q1. ABC Technologies purchases abctech.com and wants employees to use professional email addresses instead of the default onmicrosoft.com domain. What are the first two steps in this process?

Answer: First, add the domain in the Microsoft 365 Admin Center and verify ownership using the TXT record Microsoft provides; second, configure the MX record so email correctly routes to Exchange Online.

Q2. After adding a custom domain, employees report that Outlook won't automatically configure their account settings. What DNS record is most likely missing or incorrect?

Answer: The CNAME record is most likely missing or incorrect, since it supports Outlook AutoDiscover and service connectivity.

Q3. A company is migrating 300 employees to Microsoft 365 as part of an onboarding project and wants to avoid creating each account by hand. What method should they use?

Answer: They should use CSV Bulk Import, uploading a spreadsheet with all 300 employees' details to create the accounts simultaneously instead of manually one at a time.

Q4. During a CSV import, several rows fail with a message indicating the account already exists. What is the likely cause, and what should be checked?

Answer: The likely cause is duplicate accounts — the administrator should check existing user accounts in the tenant before importing to avoid re-creating users who are already present.

Q5. An organization wants 30 HR employees to access a shared SharePoint site, shared mailbox, and Teams channel, without configuring each employee separately. What should they create?

Answer: They should create a Microsoft 365 Group (e.g., "HR Department"), which bundles shared collaboration resources like SharePoint, mailbox, and Teams access for all its members at once.

Q6. A company wants to control which employees can access a specific business application, without needing any shared mailbox or calendar features. What group type fits best?

Answer: A Security Group fits best, since it's designed purely for assigning permissions and controlling resource access, without unnecessary collaboration features.

Q7. An administrator wants all HR employees to receive announcements sent to hr@company.com, without needing to manage any application permissions through this group. What group type should be used?

Answer: A Distribution Group should be used, since its sole purpose is group email communication, without any permission-management capability.

Q8. A new employee named Raj joins the HR department. What is the fastest way to give him access to the HR SharePoint site, Teams channel, shared mailbox, and calendar all at once?

Answer: The fastest way is to add Raj to the existing HR Department Microsoft 365 Group — he will instantly inherit all the group's associated resources without any individual permission configuration.