Free guides, interview Q&As, and job responsibility breakdowns — curated by industry veterans to help you crack MNC interviews
Microsoft 365 (formerly Office 365) is a cloud-based subscription suite from Microsoft that bundles productivity applications (Word, Excel, Outlook, PowerPoint), cloud storage (OneDrive, SharePoint), collaboration tools (Teams), email/calendar services (Exchange Online), identity management (Microsoft Entra ID, formerly Azure AD), and security/compliance tools—all delivered over the internet instead of being installed and managed on a single local server. For a service desk or L2 support engineer, M365 is the environment where the majority of day-to-day user issues (login problems, mailbox issues, file sharing, Teams meetings, and license errors) actually occur.
Day-to-Day Example: When an employee opens Outlook on their laptop to check email, joins a Teams call, or saves a file to OneDrive so they can open it later from their phone, they are using Microsoft 365 — even though they may never consciously think about "the cloud" behind it.
Microsoft 365 support is essential because M365 is a complex, interconnected ecosystem—a single issue (like a blocked sign-in) can affect email, Teams, SharePoint, and OneDrive all at once, and end users rarely understand the underlying cause. L1/Service Desk handles simple, well-documented issues, but L2 engineers are needed for issues requiring deeper investigation—checking admin center logs, mail flow rules, licensing conflicts, or identity/sync problems—before escalating further to L3 or Microsoft Support if required.
Day-to-Day Example: Imagine an office building with a reception desk (L1) that can answer simple questions like "where is the washroom," but for anything involving the building's wiring or plumbing, a trained technician (L2) is called in to actually diagnose and fix the problem before involving the original contractor (Microsoft/L3).
L2/Service Desk support works by receiving tickets that L1 could not resolve, then using the Microsoft 365 admin center, Exchange admin center, and various diagnostic tools to investigate the root cause, apply a fix, and either resolve or escalate the ticket with clear notes.
M365 support is required continuously, since employees rely on email, chat, and file access throughout the entire working day, and issues can arise at any time—during login, mid-meeting, while syncing files, or during monthly license renewals.
Day-to-Day Example: The moment an employee's laptop tries to sign into Outlook first thing in the morning, M365's identity and licensing checks are already running in the background—and any failure there generates a support ticket before the workday even starts.
Microsoft 365 support is used across every type of organization that has adopted the M365 ecosystem, regardless of size or industry.
End users (employees, students, staff) use M365 apps daily, usually without understanding the backend. IT Administrators and Service Desk/L2 engineers configure, monitor, and troubleshoot the tenant using the Microsoft 365 admin center. Microsoft itself develops and maintains the underlying cloud infrastructure, releasing continuous updates. Additionally, L3 engineers and Microsoft Premier Support handle the most complex, infrastructure-level issues that L2 cannot resolve.

Fig 1.1 — Layered View of the Microsoft 365 Ecosystem
L2 and Service Desk teams perform several core functions to keep an organization's M365 tenant running smoothly. Each function targets a specific service or workload, and together they ensure users can communicate, collaborate, and access their data without disruption.
This involves managing user sign-ins through Microsoft Entra ID (Azure AD)—resolving MFA (Multi-Factor Authentication) lockouts, password reset issues, Conditional Access policy blocks, and account sync problems between on-premises Active Directory and the cloud (Azure AD Connect / Entra Connect).
Day-to-Day Example: When an employee travelling abroad suddenly can't sign in because a Conditional Access policy blocks logins from new countries, it is L2's job to review the sign-in logs and either approve an exception or guide the user through the correct verification step.
This function covers troubleshooting mailbox issues—full mailboxes, incorrect forwarding rules, delayed or bounced emails, distribution group problems, and spam/phishing filtering—using the Exchange Admin Center and Message Trace tool.
This involves resolving issues related to file sharing permissions, sync errors between OneDrive and local folders, Teams meeting/call quality problems, channel access issues, and SharePoint site permission conflicts.
Day-to-Day Example: When a user creates a "Project Files" folder in SharePoint and shares it with a colleague, but the colleague cannot open a specific document, this is only possible to fix because L2 understands SharePoint's permission inheritance model.
L2 support manages the assignment, removal, and troubleshooting of M365 licenses (e.g., Microsoft 365 E3, E5, Business Premium) to ensure users have access to the correct set of applications, and resolves conflicts when a user is assigned overlapping or insufficient licenses.
The support team helps enforce data protection through tools like Microsoft Purview (compliance), Defender for Office 365 (anti-phishing/anti-malware), and retention/DLP (Data Loss Prevention) policies, ensuring sensitive information is protected and regulatory requirements are met.
L2 and Service Desk monitor the Microsoft 365 Service Health Dashboard to identify ongoing Microsoft-side outages, communicate expected impact to end users, and avoid wasting time troubleshooting an issue that is actually a known Microsoft outage.
This section covers the key terminology every L2/Service Desk engineer must understand clearly before handling live tickets. Each term is explained in detail with a simple example so the concept sticks.
A Tenant is a dedicated, isolated instance of Microsoft 365 that belongs to a single organization, containing all of that organization's users, licenses, data, and configuration settings. No two organizations share the same tenant unless specifically configured (e.g., through B2B collaboration).
Day-to-Day Example: Just as each apartment in a building has its own locked door and belongings, each organization's tenant keeps its users, emails, and files completely separate from every other organization's tenant.
Microsoft Entra ID, formerly known as Azure Active Directory, is the cloud-based identity and access management service that stores user accounts, groups, and authentication policies for a Microsoft 365 tenant. It is responsible for verifying "who you are" every time a user signs in to any M365 service.
Day-to-Day Example: Just as a security guard at an office entrance checks an employee's ID badge before letting them in, Entra ID checks a user's credentials before granting access to email, Teams, or files.
A License in Microsoft 365 is a subscription entitlement assigned to a user account that determines which applications and services (Outlook, Teams, OneDrive storage limit, advanced security features) that user is allowed to use. Common plans include Microsoft 365 Business Basic, Business Premium, E3, and E5.
Day-to-Day Example: Just as a movie ticket only grants entry to the specific show you paid for, an M365 license only grants access to the specific set of apps and features included in that plan.
Exchange Online is the cloud-based email and calendaring service within Microsoft 365 that handles sending, receiving, and storing emails, along with calendar invites, contacts, and shared mailboxes — accessed through Outlook or Outlook Web Access (OWA).
Day-to-Day Example: Just as a post office sorts and delivers physical letters to the right address, Exchange Online sorts and delivers emails to the correct mailbox, applying spam filters and rules along the way.
SharePoint Online is a cloud-based platform for creating team sites, document libraries, and intranet pages where organizations store, organize, and collaboratively edit files with controlled permissions. OneDrive for Business actually runs on the same underlying technology as SharePoint.
Day-to-Day Example: Just as a shared office filing cabinet lets multiple employees access company documents (with some drawers locked for certain staff), SharePoint stores shared files with permission-based access.
OneDrive for Business is personal cloud storage assigned to each user within a Microsoft 365 tenant, allowing them to store, sync, and access their own files from any device, and optionally share specific files or folders with colleagues.
Day-to-Day Example: Just as a personal locker at a gym belongs only to one member (who can choose to lend a key to a friend), OneDrive files belong to one user by default, shareable only when explicitly permitted.
Microsoft Teams is the collaboration hub within Microsoft 365 that combines chat, video/audio meetings, file sharing (backed by SharePoint/OneDrive), and third-party app integrations into channels organized by team or project.
Day-to-Day Example: Just as a single meeting room can be used for a discussion, a whiteboard session, and document review all in one visit, Teams brings chat, calls, and files together in one channel.
Multi-Factor Authentication is a security feature that requires a user to verify their identity using two or more independent methods — typically a password plus a code from an authenticator app, SMS, or a phone call — before being granted access, significantly reducing the risk of unauthorized sign-in even if a password is stolen.
Day-to-Day Example: Just as an ATM requires both a physical card and a PIN before dispensing cash, MFA requires both a password and a second proof of identity before granting account access.
A Conditional Access Policy is a rule set in Microsoft Entra ID that grants or blocks access to M365 resources based on specific conditions such as the user's location, device compliance status, or sign-in risk level, allowing organizations to enforce security without blocking legitimate work.
Day-to-Day Example: Just as some office buildings only allow entry through the main gate during odd hours instead of the side entrance, Conditional Access allows normal sign-in under usual conditions but adds extra checks under risky conditions.
Message Trace is a diagnostic tool in the Exchange Admin Center that allows an L2 engineer to track the exact path and status of an email — whether it was delivered, delayed, quarantined as spam, or bounced back — by searching using the sender, recipient, and date range.
Day-to-Day Example: Just as a courier tracking number shows exactly where a parcel is stuck in transit, Message Trace shows exactly where an email got delayed or blocked.
An Incident is an unplanned interruption or reduction in the quality of a service (e.g., "Outlook keeps crashing"), while a Service Request is a formal request from a user for something new to be provided (e.g., "please give me access to the Marketing SharePoint site"). Distinguishing between the two determines the correct resolution process and SLA.
Day-to-Day Example: Reporting a leaking tap is an incident (something that was working is now broken), while asking the plumber to install a new tap in another room is a service request (something new being asked for).
An SLA is a defined commitment specifying the maximum time within which a ticket of a given priority (e.g., Critical, High, Medium, Low) must be responded to and resolved, used to measure and hold support teams accountable for timely service.
Day-to-Day Example: Just as a pizza delivery service promises "delivery within 30 minutes or it's free," an SLA promises a ticket will be resolved within a set time based on its priority.
Escalation is the process of transferring a ticket from one support level to a higher one (L1 → L2 → L3 → Microsoft Support) when the current level does not have the access, tools, or expertise required to resolve the issue, along with all diagnostic information already gathered.
Day-to-Day Example: Just as a general physician refers a patient to a specialist when the issue is beyond their expertise, an L1 engineer escalates a ticket to L2 (and L2 to L3) when deeper investigation is needed.
Onboarding a new employee onto Microsoft 365 is one of the most common Service Desk/L2 workflows. Understanding this process helps in troubleshooting access issues later and ensures a smooth first day for the user.
Fig 4.1 — Step-by-step User Onboarding Process
A support ticket, once raised by a user, moves through a set of well-defined states, tracked in the ITSM tool (e.g., ServiceNow, Freshservice, Jira Service Desk). Understanding these states is crucial to understanding how Service Desk/L2 teams manage workload and SLAs.
| State | Description |
|---|---|
| New | The ticket has just been raised by the user and is awaiting assignment to an engineer. |
| Assigned | The ticket has been picked up/assigned to a specific L1 or L2 engineer for investigation. |
| In Progress | The engineer is actively investigating or working on a fix for the issue. |
| Pending (On Hold) | The ticket is waiting on something outside the engineer's control — e.g., a response from the user, or a Microsoft Support case. |
| Resolved | The issue has been fixed and the engineer is awaiting user confirmation. |
| Closed | The user has confirmed the issue is fixed (or the resolution period has passed), and the ticket is closed permanently. |
Day-to-Day Example: Imagine reporting a broken office AC to building maintenance. "New" means you have just reported it; "Assigned" means a technician has been designated to look at it; "In Progress" means the technician is actively fixing it; "Pending" means the technician is waiting for a spare part to arrive; "Resolved" means the AC now works and you're asked to confirm; and "Closed" means you've confirmed all is well and the case is shut.

Fig 5.1 — Ticket Life Cycle Diagram
Microsoft 365 support engineers need to be comfortable across several distinct "workloads," each with its own admin center and troubleshooting approach.

Fig 6.1 — Major Microsoft 365 Workloads
| Workload | Definition & Use Case | Simple Example |
|---|---|---|
| Exchange Online | Cloud email, calendar, and contacts management. | A user's inbox, shared mailbox, or distribution list. |
| SharePoint Online | Team sites and document libraries for structured collaboration. | A department's shared "HR Policies" site. |
| OneDrive for Business | Personal cloud storage synced across devices. | An employee's personal "Documents" folder synced to their laptop. |
| Microsoft Teams | Chat, meetings, and calling combined with file collaboration. | A project team's dedicated Teams channel. |
| Microsoft Entra ID | Identity, authentication, and access control. | Managing MFA and sign-in policies for all staff. |
| Intune (Endpoint Manager) | Device management and compliance policies for laptops/phones. | Enforcing a PIN lock on all company-issued phones. |
| Microsoft Purview / Defender | Security, compliance, data loss prevention, and threat protection. | Blocking a phishing email tenant-wide. |
Comparison-based questions are very common in interviews and certification exams. These tables summarize the most important distinctions L2/Service Desk engineers must remember clearly.
| Basis | L1 (Service Desk) | L2 (Technical Support) | L3 (Expert/Engineering) |
|---|---|---|---|
| Scope | Basic, scripted troubleshooting (password resets, restarts). | Deeper investigation using admin tools and logs. | Complex, infrastructure-level or vendor-escalated issues. |
| Access Level | Limited admin access, mostly ticketing tools. | Broader admin center access (Exchange, SharePoint, Entra ID). | Full backend/infrastructure access, direct vendor contact. |
| Resolution Time | Fastest, for simple recurring issues. | Moderate, requires diagnosis. | Longest, for rare or systemic issues. |
| Example | "I forgot my password." | "My emails to external clients keep bouncing." | "Mail flow is failing tenant-wide due to a backend routing issue." |
| Basis | Incident | Service Request | Problem |
|---|---|---|---|
| Core Idea | Unplanned disruption to a working service. | A planned request for something new. | The underlying root cause behind one or more recurring incidents. |
| Urgency | Usually urgent — something is broken. | Usually non-urgent, scheduled work. | Investigated proactively to prevent future incidents. |
| Example | Teams keeps disconnecting during calls. | Requesting access to a new SharePoint site. | Recurring Teams disconnections traced to a faulty network switch. |
| Basis | Exchange Online (Cloud) | On-Premises Exchange (Legacy) |
|---|---|---|
| Hosting | Hosted and maintained by Microsoft in the cloud. | Hosted on the organization's own physical servers. |
| Maintenance | Microsoft handles updates, patches, and uptime. | The organization's own IT team must patch and maintain it. |
| Cost Model | Subscription-based (pay-per-user, per-month). | Upfront hardware + licensing cost, plus ongoing maintenance. |
| Scalability | Easily scales up/down by adjusting licenses. | Requires purchasing/provisioning additional hardware. |
| Access | Accessible from anywhere with internet. | Typically requires VPN or on-site network access. |
| Basis | OneDrive for Business | SharePoint Online |
|---|---|---|
| Ownership | Personal storage tied to one individual user. | Shared storage tied to a team, department, or project. |
| Default Access | Private by default; shared only when the owner chooses. | Structured around group-based/site-based permissions. |
| Typical Use | Personal working files, drafts, backups. | Team document libraries, intranet pages, project sites. |
| Underlying Tech | Built on the same technology as SharePoint. | The foundational platform that also powers OneDrive. |
| Basis | Microsoft 365 | Google Workspace |
|---|---|---|
| Core Apps | Outlook, Word, Excel, PowerPoint, Teams. | Gmail, Docs, Sheets, Slides, Meet. |
| Identity Platform | Microsoft Entra ID (deep integration with Windows). | Google Workspace Identity (deep integration with Chrome/Android). |
| File Collaboration | SharePoint/OneDrive with granular permission controls. | Google Drive with simpler, link-based sharing model. |
| Common Use Case | Enterprises already invested in the Windows ecosystem. | Startups and organizations preferring a lightweight, web-first suite. |
Day-to-Day Example: An enterprise IT admin managing Conditional Access policies in Entra ID, and a startup founder simply sharing a Google Doc link with a co-founder, are both solving the same "collaboration" problem using the platform best suited to their organization's size and habits.
These questions test your practical understanding of the concepts covered above. Try answering them yourself first, then check the given answer and reasoning.
Q1. A user reports that they can log into Outlook on their laptop but cannot access Teams or OneDrive, even though all three use the same Microsoft 365 account. What should L2 check first?
Answer: L2 should check the user's license assignment in the Microsoft 365 Admin Center.
Why / Reason: Since Outlook, Teams, and OneDrive access are each controlled by specific service plans within an assigned license, it's possible the user's license doesn't include Teams/OneDrive, or these specific service plans were manually disabled, even though the base license grants Outlook access.
Q2. An employee suddenly cannot sign in from home but could sign in fine yesterday from the office. No password was changed. What is the most likely cause?
Answer: A Conditional Access Policy is likely blocking the sign-in based on location or device compliance.
Why / Reason: Conditional Access policies often restrict sign-ins based on network location, device compliance, or risk level. Since the password hasn't changed, the block is likely condition-based rather than credential-based, and reviewing the sign-in logs in Entra ID would confirm the exact policy that triggered the block.
Q3. A manager says an important email from a client never arrived, but the client insists it was sent successfully. How can L2 confirm what actually happened?
Answer: L2 should use the Message Trace tool in the Exchange Admin Center.
Why / Reason: Message Trace shows the exact journey of the email — whether it was delivered, quarantined as spam, or bounced — allowing L2 to confirm the true status of the email without relying on either party's assumption.
Q4. Two team members are editing the same Word document stored on SharePoint at the same time, and both see each other's changes appear live. What feature makes this possible?
Answer: SharePoint's real-time co-authoring feature (powered by the same cloud storage that OneDrive uses).
Why / Reason: Files stored in SharePoint/OneDrive are saved centrally in the cloud rather than on a single local device, allowing Microsoft 365 apps to sync and merge multiple users' edits to the same file in near real-time.
Q5. A ticket comes in marked "Critical" because the entire Exchange Online service is down for all users organization-wide. What should L2 check before starting deep troubleshooting?
Answer: L2 should first check the Microsoft 365 Service Health Dashboard.
Why / Reason: A tenant-wide outage affecting all users simultaneously is often caused by a Microsoft-side incident rather than a tenant-specific misconfiguration. Checking Service Health first avoids wasted troubleshooting effort on an issue Microsoft is already resolving.
Q6. A newly onboarded employee's mailbox is not receiving any emails, even though their account and license were set up correctly two hours ago. What is the likely explanation?
Answer: Mailbox provisioning delay.
Why / Reason: After a license is assigned, Exchange Online can take some time (sometimes up to a few hours) to fully provision the mailbox and propagate it across Microsoft's systems. This is a known, expected delay rather than a misconfiguration.
Q7. A user forwards a ticket saying "I need access to the Finance SharePoint site for a new project." Is this an Incident or a Service Request?
Answer: This is a Service Request.
Why / Reason: The user is asking for something new to be provisioned (access to a site), not reporting something that was previously working and has now broken — which is the defining difference between a Service Request and an Incident.
Q8. An L2 engineer cannot resolve an issue because it requires backend changes to Microsoft's mail routing infrastructure, which is outside the organization's tenant. What should the engineer do?
Answer: Escalate the ticket to Microsoft Support (effectively L3/vendor level), attaching all diagnostic logs already gathered.
Why / Reason: Since the root cause lies within Microsoft's own infrastructure rather than the organization's tenant configuration, it is beyond L2's access and expertise, and must be escalated with full context so Microsoft's engineers can investigate efficiently.
1. What is Microsoft 365?
Microsoft 365 is a cloud-based subscription suite that bundles productivity apps (Word, Excel, Outlook), cloud storage (OneDrive, SharePoint), collaboration tools (Teams), and identity/security services into a single platform.
2. What is a tenant in Microsoft 365?
A tenant is a dedicated, isolated instance of Microsoft 365 belonging to one organization, containing all its users, licenses, data, and configuration.
3. What is the difference between OneDrive and SharePoint?
OneDrive is personal cloud storage owned by an individual user, while SharePoint is shared storage designed for team/department-level collaboration with structured permissions.
4. What is Microsoft Entra ID (Azure AD)?
It is the cloud-based identity and access management service that verifies user sign-ins and manages accounts, groups, and security policies for a Microsoft 365 tenant.
5. What is MFA and why is it important?
Multi-Factor Authentication requires two or more independent proofs of identity before granting access, greatly reducing the risk of unauthorized sign-in even if a password is compromised.
6. What is the difference between an Incident and a Service Request?
An Incident is an unplanned disruption to something that was working, while a Service Request is a planned request for something new to be provisioned.
7. What tool would you use to check why an email didn't reach its recipient?
Message Trace, in the Exchange Admin Center, shows the exact delivery path and status of an email.
8. What is a Conditional Access Policy?
It is a rule in Microsoft Entra ID that grants or blocks access based on specific conditions such as location, device compliance, or sign-in risk.
9. What are the major Microsoft 365 workloads an L2 engineer should know?
Exchange Online, SharePoint Online, OneDrive for Business, Microsoft Teams, Microsoft Entra ID, Intune, and Microsoft Purview/Defender.
10. What is an SLA in a support context?
An SLA (Service Level Agreement) defines the maximum time within which a ticket of a given priority must be responded to and resolved.
1. A user says Teams is "not working" — what is your first step as an L2 engineer?
The first step is to ask clarifying questions to understand exactly what "not working" means (can't sign in, can't join calls, messages not sending), then check Service Health for known outages before diving into tenant-specific troubleshooting.
2. How would you explain "license" to someone with no technical background, using a real-life analogy?
A license is like a subscription ticket — just as a gym membership tier determines which facilities you can use, an M365 license determines which apps and features a user can access.
3. Why might an organization use Conditional Access instead of simply blocking all remote access?
Conditional Access allows security to be applied intelligently based on risk (unusual location, non-compliant device) rather than blanket-blocking all remote work, balancing security with employee productivity.
4. A user's OneDrive files are not syncing to their laptop. What are some possible causes you would investigate?
Possible causes include the OneDrive sync client being signed out or outdated, insufficient local disk space, file path length limits being exceeded, network connectivity issues, or the account being over its storage quota.
5. Why is it important to check Microsoft's Service Health Dashboard before deeply troubleshooting a widespread issue?
Because if the issue originates from Microsoft's own infrastructure rather than the organization's tenant configuration, no amount of local troubleshooting will fix it — checking Service Health first saves time and sets correct expectations with affected users.