🔒 Guided

Pre-launch preview. Authorised access only.

Incorrect code

Guided by A Guide to Cloud
Explore AB-900 AI-901 aws-saa-c03 aws-aif-c01
Guided MS-700 Domain 1
Domain 1 — Module 7 of 13 54%
7 of 27 overall

MS-700 Study Guide

Domain 1: Configure and manage a Teams environment

  • Network Planning & Readiness
  • Security Roles, Alerts & Defender
  • Retention & Sensitivity Labels
  • DLP & Conditional Access
  • Information Barriers & Insider Risk
  • Update Policies & Policy Packages
  • Group Creation, Naming & Expiration
  • Archive, Restore & Access Reviews
  • Guest Access & External Sharing
  • Shared Channels & Cross-Tenant Access
  • Teams Phone & Resource Accounts
  • Teams Rooms & Device Management
  • PowerShell & Graph Automation

Domain 2: Manage teams, channels, chats, and apps

  • Teams Rollout & Creation Free
  • Membership, Roles & Team Settings Free
  • Channel Types & Policies Free
  • App Management & Permissions Free
  • App Extensibility & Store Free

Domain 3: Manage meetings and calling

  • Meeting Types & Settings
  • Webinars & Town Halls
  • Phone Numbers & Conferencing
  • Voice Policies & Voicemail
  • Auto Attendants & Call Routing

Domain 4: Monitor, report on, and troubleshoot Teams

  • Voice & Meeting Quality
  • Usage, Alerts & Diagnostics Tools
  • Client Logs & Diagnostics
  • Copilot & Meeting Troubleshooting

MS-700 Study Guide

Domain 1: Configure and manage a Teams environment

  • Network Planning & Readiness
  • Security Roles, Alerts & Defender
  • Retention & Sensitivity Labels
  • DLP & Conditional Access
  • Information Barriers & Insider Risk
  • Update Policies & Policy Packages
  • Group Creation, Naming & Expiration
  • Archive, Restore & Access Reviews
  • Guest Access & External Sharing
  • Shared Channels & Cross-Tenant Access
  • Teams Phone & Resource Accounts
  • Teams Rooms & Device Management
  • PowerShell & Graph Automation

Domain 2: Manage teams, channels, chats, and apps

  • Teams Rollout & Creation Free
  • Membership, Roles & Team Settings Free
  • Channel Types & Policies Free
  • App Management & Permissions Free
  • App Extensibility & Store Free

Domain 3: Manage meetings and calling

  • Meeting Types & Settings
  • Webinars & Town Halls
  • Phone Numbers & Conferencing
  • Voice Policies & Voicemail
  • Auto Attendants & Call Routing

Domain 4: Monitor, report on, and troubleshoot Teams

  • Voice & Meeting Quality
  • Usage, Alerts & Diagnostics Tools
  • Client Logs & Diagnostics
  • Copilot & Meeting Troubleshooting
Domain 1: Configure and manage a Teams environment Premium ⏱ ~12 min read

Group Creation, Naming & Expiration

Control who can create teams, enforce consistent naming conventions, set expiration policies for stale teams, and understand where Teams stores content.

Governing team creation and lifecycle

☕ Simple explanation

Imagine your office lets anyone book a meeting room. Within a month, there are 500 rooms booked — half are empty, names are confusing (“John’s thing,” “Test 123”), and nobody cleans up after themselves.

That’s what happens in Teams without governance. Group creation policies control who can create teams (not everyone needs to). Naming policies enforce consistent names (“Project-Phoenix” not “test123”). Expiration policies automatically clean up teams nobody uses — owners get a renewal notice, and if they ignore it, the team expires.

Every Teams team is backed by a Microsoft 365 Group. Governance policies for M365 Groups — creation restrictions, naming conventions, and expiration — apply directly to Teams. These policies are configured in Microsoft Entra ID (creation restrictions), Microsoft 365 admin center (naming and expiration), and require Entra ID Premium P1 licensing for group expiration and naming policies.

Understanding where Teams stores content is essential for governance — messages, files, recordings, and metadata are distributed across multiple services.

Where Teams stores content

Teams content is distributed across several Microsoft 365 services:

Content TypeStorage LocationGoverned By
Channel messagesMicrosoft 365 group mailbox (Exchange Online)Teams retention policies
Chat messages (1:1, group)Participants’ Exchange Online mailboxes (SubstrateHolds)Teams retention policies
Channel filesSharePoint document library (team site)SharePoint policies
Chat filesSender’s OneDriveOneDrive policies
Meeting recordingsOneDrive (non-channel) or SharePoint (channel meetings)SharePoint/OneDrive policies
Meeting transcriptsOneDrive (non-channel) or SharePoint (channel meetings)SharePoint/OneDrive policies
Wiki/Loop pagesSharePointSharePoint policies
Team membership and settingsMicrosoft 365 Group (Entra ID)Entra ID group policies
Planner tasksPlanner servicePlanner retention
OneNote notebookSharePointSharePoint policies

Key exam point: There’s no single “Teams storage.” Content is distributed. This means governance must span multiple services — a retention policy for Teams messages doesn’t cover files (that’s SharePoint), and a SharePoint sharing policy doesn’t cover chat text.

Restricting team creation

By default, every user can create a Microsoft 365 Group (and therefore a Teams team). In large organisations, this leads to sprawl — hundreds of unused teams with confusing names.

How to restrict creation

Restriction is configured in Microsoft Entra ID by limiting M365 Group creation to a specific security group:

  1. Create a security group (e.g., “Teams Creators”) containing users allowed to create teams
  2. Use Microsoft Graph PowerShell to update the Group.Unified directory setting:
    • Set EnableGroupCreation = false
    • Set GroupCreationAllowedGroupId = <security-group-object-id>
  3. Only members of the specified security group can create new teams

Important: This restricts creation of ALL Microsoft 365 Groups — not just Teams. Users outside the group also can’t create Groups in Outlook, SharePoint, Planner, or Yammer. Global Administrators can always create groups regardless.

Scenario: Kofi restricts team creation at Harbour University

Harbour University had 15,000 teams created in the first semester — 60% were duplicates or unused. Kofi restricts creation:

Security group “Teams Creators” members:

  • IT team (10 people) — can create any team
  • Department heads (50 people) — can create departmental teams
  • Faculty (5,000 people) — can create class teams

Who CANNOT create teams:

  • Students (50,000) — they join teams created by faculty
  • Admin staff (except department heads) — they request via IT

This reduces team creation from 3,000/month to ~200/month. Kofi still uses Entra ID Premium P1 for the expiration policies to clean up stale class teams after each semester.

Naming policies

Naming policies enforce consistent team names across the organisation. Configured in the Microsoft Entra admin center → Groups → Naming policy.

Two components

ComponentWhat It DoesExample
Prefix/suffixAutomatically adds text or attributes to group namesPrefix: “Team-” + Department → “Team-Finance-Budget Review”
Blocked wordsPrevents specific words in group namesBlock “CEO,” “HR-Confidential,” profanity

Prefix and suffix options

You can use fixed text or Entra ID attributes as prefixes/suffixes:

TypeExamples
Fixed text”Team-”, “Dept-”, “-archived”
Entra ID attributeDepartment, Company, Office, StateOrProvince, CountryOrRegion

Example naming policy: Prefix = “Team-” + Department attribute, Suffix = ”-” + CountryOrRegion

  • Result: “Team-Finance-Budget Review-AU” (for an Australian finance team)

Blocked words

Upload a CSV file of blocked words. If a user tries to create a team with a blocked word, they see an error message. This prevents:

  • Offensive or inappropriate team names
  • Misleading names (e.g., “Microsoft Official” created by a non-Microsoft team)
  • Reserved terms (e.g., “Executive Board,” “Legal-Privileged”)

Licensing: Naming policies require Entra ID Premium P1 for at least one member of the group being created.

Expiration policies

Expiration policies automatically clean up stale teams. Configured in Microsoft Entra admin center → Groups → Expiration.

How expiration works

  1. Set an expiration period: 180 days, 365 days, or custom (minimum 30 days)
  2. Apply to: All groups, Selected groups, or None
  3. When a group nears expiration, owners receive email notifications (30 days, 15 days, 1 day before)
  4. If no owner renews the group → it expires and is soft-deleted
  5. Soft-deleted groups can be restored within 30 days by an admin or owner
Group expiration lifecycle
FeatureBehaviourNotificationAdmin Action
Active team (used regularly)Auto-renewed — any activity resets the expiration clockNo notifications neededNone required
Inactive team (no activity)Owners get email at 30, 15, and 1 day before expirationOwner clicks 'Renew' in the emailIf owner ignores, team expires after the period
Expired teamSoft-deleted — can be restored within 30 daysAdmin gets notification (if configured)Admin or owner restores from Entra ID or PowerShell

What counts as ‘activity’? Visiting a channel, reading a message, using the team in any way. Activity auto-renews the expiration timer without any owner action.

Scenario: Kofi's semester expiration at Harbour University

Kofi configures expiration for class teams:

  • Expiration period: 180 days (roughly one semester)
  • Applied to: Security group “Class Teams” (all teams created from the class template)
  • Not applied to: IT teams, department teams (these are permanent)

At the end of each semester:

  1. Class teams that are still active (students accessing notes) → auto-renewed
  2. Class teams with no activity → faculty owners get renewal emails
  3. Faculty who don’t renew → teams expire and are soft-deleted
  4. If a professor realises they need last semester’s materials → Kofi restores the team within 30 days

This automatically cleans up ~2,000 stale class teams per semester without manual intervention.

🎬 Video walkthrough

🎬 Video coming soon

Group Creation, Naming & Expiration — MS-700 Module 7

Group Creation, Naming & Expiration — MS-700 Module 7

~10 min

Flashcards

Question

Where do you restrict who can create Microsoft 365 Groups (and therefore Teams)?

Click or press Enter to reveal answer

Answer

In Microsoft Entra ID — set EnableGroupCreation to false and specify a security group whose members can still create groups. This affects ALL M365 Group creation, not just Teams.

Click to flip back

Question

What licence is required for group naming and expiration policies?

Click or press Enter to reveal answer

Answer

Microsoft Entra ID Premium P1. At least one member of the group being created needs P1 for naming policy enforcement. P1 is also required for group expiration policies.

Click to flip back

Question

How long can a soft-deleted Microsoft 365 Group be restored?

Click or press Enter to reveal answer

Answer

30 days. After soft-deletion (expiration or manual deletion), the group and all its content (Teams, SharePoint, Planner, etc.) can be restored within 30 days. After 30 days, it's permanently deleted.

Click to flip back

Question

What counts as 'activity' for auto-renewing an expiring team?

Click or press Enter to reveal answer

Answer

Any activity: visiting a channel, reading a message, using the team. This resets the expiration clock automatically — owners don't need to manually renew active teams.

Click to flip back

Knowledge Check

Knowledge Check

Harbour University has 15,000 teams. Kofi wants to prevent students from creating new teams while allowing faculty and IT to create them. Where should Kofi configure this?

Knowledge Check

Sterling Financial configures a naming policy with prefix 'SF-' + Department attribute. Nadia, from the Compliance department, creates a team called 'Audit Review.' What will the team name become?


Next up: Archive, Restore & Access Reviews — how to archive inactive teams, restore deleted teams, and use access reviews to keep team membership current.

← Previous

Update Policies & Policy Packages

Next →

Archive, Restore & Access Reviews

Guided

I learn, I simplify, I share.

A Guide to Cloud YouTube Feedback

© 2026 Sutheesh. All rights reserved.

Guided is an independent study resource and is not affiliated with, endorsed by, or officially connected to Microsoft. Microsoft, Azure, and related trademarks are property of Microsoft Corporation. Always verify information against Microsoft Learn.