Across
- 3. Credential-harvesting email; report it, then check sign-in logs and revoke sessions
- 8. Holding pen where Defender parks suspected phish until it is released
- 9. Assign the right one or there's no mailbox; remove it at offboarding to stop the bill
- 10. DNS TXT record listing which servers are allowed to send as your domain
- 11. Chat, meeting and calling app whose channel files actually live elsewhere
- 14. Entra policy engine: if these signals, then grant, block, or require extra proof
- 15. Drive encryption whose recovery key you pull from Entra when a device won't boot
- 18. Cryptographic signature on outbound mail proving it wasn't altered in transit
- 19. What you do when a ticket exceeds your tier's scope or the SLA clock
- 21. DNS entry pointing a domain's inbound mail at the right host; wrong value means no mail at all
- 24. Basic authentication protocols that bypass modern controls; block them tenant-wide
- 25. Microsoft's identity platform, called Azure AD until 2023 — home of users, groups and sign-in logs
- 28. Scripting shell for the bulk changes the admin portals refuse to do
- 29. Zero-touch provisioning: ship the laptop straight to the user and it enrols and configures itself
- 30. ___ Online: the hosted service behind every mailbox in your ticket queue
- 33. Site-and-library platform that silently stores every file dropped in a Teams channel
- 36. Security brand behind Safe Links, Safe Attachments and endpoint EDR
- 37. Container for mail, calendar and contacts; may also be shared, room or resource
Down
- 1. Exchange admin centre report that answers "was it delivered, or did we drop it?"
- 2. Public list of features rolling out, so a change isn't logged as a fault
- 4. Cloud service that enrols devices and pushes compliance policies, apps and Wi-Fi profiles
- 5. AI assistant licensed per user; remember it inherits whatever SharePoint over-sharing already exists
- 6. Extra address on a mailbox that receives mail without a second license
- 7. User granted Send As or Full Access rights over someone else's mailbox
- 12. Second factor that turns a stolen password into a useless one (abbr.)
- 13. Per-user cloud storage; check both of its recycle bins before declaring a file gone
- 16. Mailbox setting that preserves everything, deleted items included, for legal purposes
- 17. Compliance home of retention policies, DLP and sensitivity labels
- 20. Time-bound, least-privilege delegated admin model MSPs use instead of blanket partner access
- 22. Record whose p= value tells receivers to none, quarantine or reject unauthenticated mail
- 23. Dashboard to check before spending an hour chasing a Microsoft-side outage
- 26. Policy that keeps or deletes content on a schedule — often mistaken for a backup
- 27. ___ rule: check this when external mail gets a banner or is silently redirected
- 31. Microsoft's single API surface for mail, users, devices and reporting automation
- 32. Session artifact thieves steal to ride past MFA — revoke it after any compromise
- 34. Mail in the browser (abbr.) — quickest way to prove a fault is client-side, not service-side
- 35. The isolated cloud instance you administer per customer, born with an .onmicrosoft.com name and a GUID
- 38. Client where a corrupt profile or OST is often the real cause of "email is broken"
