70-346 Exam Guide: Managing Office 365 Identities and Requirements
Exam 70-346 validated the ability to evaluate, plan, deploy, and operate Office 365 services and their dependencies, with particular attention to provisioning, networking, security, cloud identities, and directory synchronization. It served IT professionals working with the Office 365 Admin Center and related services. The important decision now is not how to book this exam: Microsoft retired it on March 31, 2019. Use its blueprint to understand legacy Office 365 administration, then choose the current Microsoft certification path that matches your goal.
Is 70-346 still available?
No. Microsoft 70-346 is a retired exam and cannot be scheduled as a current certification assessment. Microsoft stated that 70-346 and 70-347 retired on March 31, 2019. Its retirement policy says that retired exams cannot be taken and the associated certification or credential cannot be earned after the retirement date.
If you are researching 70-346 because an old training course, résumé, job listing, or practice-test page mentions it, check the publication date before investing time or money. A page that presents 70-346 as an available exam is not giving you a current scheduling option.
Microsoft explains that exams and certifications are retired when they no longer reflect the latest skills and technologies. That makes the exam outline useful as historical context, but it should not be treated as a current Microsoft skills blueprint. See the official retirement guidance at https://learn.microsoft.com/en-us/credentials/support/retired-certification-exams and https://learn.microsoft.com/en-us/credentials/support/credential-retirement.
What happens to an existing result?
If you earned the associated certification before retirement, Microsoft’s policy states that it remains on your transcript in the Active Certifications section until it expires. After the certification expires, it moves to the Historical Certifications section. Retirement prevents new attempts; it does not erase a credential that was previously earned.
What did 70-346 validate?
70-346, titled “Managing Office 365 Identities and Requirements,” focused on the administrative foundations needed to introduce and operate Office 365. The target candidate was an IT professional involved in evaluating, planning, deploying, and operating Office 365 services and their dependencies.
The published exam description expected experience with the Office 365 Admin Center and understanding of Exchange Online, Skype for Business Online, SharePoint Online, Office 365 ProPlus, and Microsoft Azure Active Directory. That combination indicates a broad administrator role rather than a narrow focus on one workload.
The exam was therefore relevant to administrators who needed to connect tenant planning, identity decisions, network readiness, licensing, and service operations. It was not simply a product-navigation test. Candidates had to understand how an organization’s identity and infrastructure choices affected Office 365 deployment.
Who was the intended audience?
The strongest fit was an IT professional responsible for Office 365 evaluation, planning, deployment, or operations. Someone familiar only with end-user productivity features would have needed substantial preparation in tenant administration, directory synchronization, networking dependencies, and identity security.
The historical Microsoft exam-preparation session also described its audience as people experienced with Microsoft Office 365 who were considering 70-346 or 70-347. That is useful context for judging the expected starting point, although it does not make the retired exam available today.
Which skills appeared in the blueprint?
The historical outline grouped 70-346 around four practical administration problems: provisioning Office 365, planning and implementing networking and security, managing cloud identities, and implementing identities through Azure Active Directory synchronization. The available outline assigns 15–20% to provisioning Office 365, 15–20% to planning and implementing networking and security in Office 365, and 15–20% to managing cloud identities.
These percentages describe the published historical outline. They are not a current exam weighting, and the supplied evidence does not establish the weighting for the synchronization area. Do not use the percentages as a prediction of a present-day Microsoft assessment.
A sensible study interpretation is to treat the domains as connected workstreams. Tenant and subscription choices affect licensing and pilots; network and security settings affect client access; cloud identity administration affects user lifecycle; synchronization connects the existing directory to the cloud.
Provisioning Office 365
The provisioning Office 365 domain carried 15–20% of the published outline. It included configuring tenants and subscriptions, managing licensing, adding custom domains, and planning a pilot.
Prepare this area as a sequence rather than a list of portal tasks. Start with the business and technical requirements for the tenant. Then consider subscription and licensing assignments, domain ownership and configuration, and the controlled pilot that would expose identity, connectivity, and user-experience issues before a wider rollout.
A common mistake is to study licensing independently from deployment planning. In practice, licensing decisions influence which users and services can participate in a pilot, while domain and tenant choices influence sign-in and administration arrangements. Use a written scenario and document the reason for each decision.
Planning and implementing networking and security
The planning and implementing networking and security in Office 365 domain carried 15–20% of the published outline. The listed subjects included DNS records, proxy and firewall configuration, client connectivity, Azure Rights Management, and Office 365 administrator roles.
Study the dependency chain. A user may have the correct license and credentials yet still experience failure if DNS, proxy, firewall, or client-connectivity requirements are not addressed. Separately, administrator roles and rights-management controls determine who can perform sensitive actions and how protected information is handled.
Avoid memorizing isolated settings. For each topic, ask what service depends on it, what symptom a misconfiguration would create, and which administrative boundary should control the change. That approach is more useful for legacy understanding and transfers better to current Microsoft 365 administration work.
Managing cloud identities
The managing cloud identities domain carried 15–20% of the published outline. It included password policies, user and security groups, bulk user operations, multifactor authentication, and Windows PowerShell administration.
Build a small identity-management matrix while studying. Record the task, the affected object, the control used, and whether the operation is individual or bulk. Then add the security consequence: for example, a password-policy change, group-membership change, or multifactor-authentication decision may affect many users at once.
Do not treat PowerShell as a separate memorization exercise. Relate commands to administrative outcomes such as creating users, changing attributes, managing groups, or performing repeatable bulk operations. The goal is to understand when automation is safer and more consistent than manual administration, not to reproduce question-bank answers.
Azure Active Directory synchronization
The synchronization content covered preparing for and managing identity synchronization through Azure AD Connect. The listed subjects included preparation, installation, filtering, password synchronization, and synchronization scheduling.
Study synchronization as a lifecycle. First identify what must be prepared in the existing directory and tenant. Next determine which objects and attributes should be included or filtered. Then examine authentication and password-synchronization choices, followed by the timing and operational consequences of synchronization schedules.
The main pitfall is assuming that synchronization is simply an installation task. Filtering and attribute decisions can affect which users appear in the cloud, while password and scheduling choices affect sign-in behavior and change propagation. Create a before-and-after diagram showing the source directory, synchronization process, cloud identity, and administrative responsibilities.
How should you prepare using the old outline?
Use the 70-346 outline only to build foundational Office 365 administration knowledge or to interpret a legacy credential. Do not use it to plan an exam booking. For current certification preparation, begin with Microsoft’s present certification catalogue and select the replacement or role-based path that matches your intended work.
A practical sequence is to study identity foundations first, then tenant and licensing decisions, then networking and security dependencies, and finally operational automation. This order mirrors the way many deployment decisions depend on one another: users and domains must be understood before synchronization and access controls can be evaluated meaningfully.
Use official documentation, controlled practice environments where available, and your own configuration notes. The evidence supplied here does not verify a current 70-346 delivery method, exam duration, language list, question count, passing score, price, or prerequisites. Do not rely on pages that supply those details without a current official source.
Step 1: Establish the identity model
Begin by distinguishing cloud-only identities from synchronized identities, then map users, groups, administrators, passwords, multifactor authentication, and bulk operations. Write down which identity source is authoritative in each scenario and what happens when an account or group changes.
Your checkpoint is not a vocabulary list. You should be able to explain the administrative effect of each choice, identify the likely dependency, and state what must be validated before applying the change broadly.
Step 2: Connect identity to tenant provisioning
Next, work through tenant and subscription configuration, licensing, custom domains, and pilot planning. Use one fictional organization with different user populations and service needs. Decide which users enter the pilot, which licenses they require, which domain is used, and how the pilot will be evaluated.
This exercise prevents a common error: treating the tenant as an empty portal rather than an environment that must be prepared for identity, service access, administration, and user adoption.
Step 3: Test network and security dependencies
Review DNS, proxy, firewall, client connectivity, rights management, and administrator roles against the same scenario. For every proposed change, record the prerequisite, the affected users or services, the security impact, and the rollback or verification step.
This is where passive reading often fails. Draw the traffic or access path and identify where authentication, name resolution, filtering, or authorization could interrupt the user experience.
Step 4: Automate repeatable administration
Finish by translating recurring identity tasks into PowerShell-oriented procedures or pseudocode. Include input validation, scope, logging, and a safe test against a limited group before a bulk operation. The objective is disciplined administration, not copying commands without understanding their effect.
If you cannot explain what an operation changes and how you would verify it, return to the identity model before attempting more syntax practice.
What study mistakes should you avoid?
The largest mistake is preparing for 70-346 as though it were an active exam. Confirm status first, then decide whether your goal is historical knowledge, a legacy-credential discussion, or a current Microsoft 365 certification. Only the last of these requires selecting a presently offered path.
A second mistake is treating old practice questions as authoritative. They may reflect an obsolete interface, retired product behavior, or an inaccurate reconstruction of the assessment. Dumps and leaked-question claims cannot establish current skill coverage or guarantee a pass, and memorization is a poor substitute for understanding identity and deployment dependencies.
A third mistake is studying domains in isolation. Provisioning, cloud identity, synchronization, networking, and security interact. A technically correct setting can still produce a failed deployment if the tenant, domain, directory, client, or administrator-role assumptions are inconsistent.
Finally, do not fill gaps with invented exam logistics. The supplied official research does not verify delivery details for 70-346 because the exam is retired. For any current replacement, read the live Microsoft exam page before making scheduling or budget decisions.
A useful readiness test
Take a scenario and produce four outputs without looking at notes: an identity diagram, a provisioning checklist, a network and security dependency list, and an operational runbook. Then review each output for assumptions about domains, licenses, synchronization scope, authentication, administration, and verification.
This is a practical recommendation, not an official Microsoft pass criterion. It helps reveal whether you can reason through a deployment rather than recognize familiar terminology.
What replaced 70-346?
Microsoft mapped 70-346 to the Microsoft 365 Enterprise Administrator certification path requiring MS-100 and MS-101. Microsoft also stated that MS-100 and MS-101 replaced 70-346 and 70-347, and that there was no transition exam from the older exams to the Microsoft 365 Enterprise Administrator Expert certification.
This mapping is historical guidance from Microsoft, not a guarantee that those exams remain the current route today. Certification programs change. Before choosing a replacement, open the current Microsoft Learn certification catalogue and verify the active exam names, requirements, retirement notices, and renewal rules.
The key decision is to choose based on the work you want to perform. A candidate focused on enterprise-wide Microsoft 365 identity and service design should investigate the current enterprise administration path. A candidate focused on messaging, teamwork, desktop, security, or another workload should compare the relevant current role-based option instead of automatically searching for an old 70-346 equivalent.
Why is there no one-for-one transition?
Microsoft explained that the newer Microsoft 365 Enterprise Administrator Expert certification was an expert-level credential, while the former MCSA: Office 365 was essentially at the associate level. Consequently, passing or taking 70-346 or 70-347 did not create a transition route into the newer expert certification.
If you already hold a legacy credential, check how it appears on your transcript and what current certification requirement you still need. Do not assume that an old exam automatically grants a current certification.
How do the historical skills inform current study?
The old outline still provides a useful mental model for Microsoft 365 administration: start with tenant and identity design, account for network and security dependencies, automate repeatable operations, and validate a pilot before expanding it. Those are study principles, not claims that the retired blueprint precisely matches a current exam.
For a current certification, replace each historical topic with the terminology and objectives on the live Microsoft Learn page. Keep the same decision-oriented method: identify the business requirement, choose an administrative design, test dependencies, apply controls, and document verification.
Microsoft’s description of the later Enterprise Administrator Expert path emphasized evaluating, planning, migrating, deploying, and managing Microsoft 365 services securely. That broader lifecycle helps explain why a candidate should study architecture and operational consequences rather than only portal navigation.
A scenario worksheet to reuse
Create a worksheet with these fields: organization requirement, identity source, tenant or subscription decision, license scope, domain dependency, network dependency, security control, administrator role, automation opportunity, pilot test, and success check. Complete it for a small pilot before attempting an organization-wide design.
Keep historical 70-346 labels in a separate column if you are documenting a legacy environment. This prevents old terminology from being confused with the objectives of a current certification.
What should you do next?
If your goal is to earn a certification now, stop looking for a 70-346 appointment and verify a current Microsoft 365 or workload certification through Microsoft Learn. If your goal is legacy knowledge, use the archived outline to structure hands-on study around identity, provisioning, networking, security, and synchronization.
For a current path, first identify the role you want to demonstrate. Second, read the live certification requirements and skills outline. Third, inventory your experience against each domain. Fourth, build a lab or scenario plan for weak areas. Finally, confirm current scheduling and retirement information immediately before booking.
If you already passed 70-346, preserve the credential record and check its status on your Microsoft transcript. If an employer asks for the exam, clarify whether the requirement is historical or whether the organization expects a current Microsoft 365 certification. That conversation can prevent you from presenting an unavailable exam as a present qualification.
A final decision checklist
Confirm that the exam is retired. Identify whether you need historical knowledge or a current credential. Review Microsoft’s mapping only as background. Select the active role-based path that matches your work. Replace legacy objectives with the current skills outline. Prepare through scenarios and controlled practice rather than dumps. Verify all live exam logistics on Microsoft Learn before scheduling.
Conclusion
70-346 remains useful as a record of the Office 365 administration skills Microsoft emphasized at the time: provisioning, networking and security, cloud identities, and Azure AD synchronization. It is not a current scheduling target. Treat the outline as historical context, preserve any credential you already earned, and move forward by checking Microsoft’s live certification catalogue for the role-based path that now matches your responsibilities.