🧭 MS-102 Microsoft 365 Administrator Practice Exam (100 Q&A)
🔹 Section 1: Microsoft 365 Tenant Management
- Which tool monitors Microsoft 365 service health and incidents?
✅ Microsoft 365 admin center - First step to add a custom domain in Microsoft 365?
✅ Add domain in Microsoft 365 admin center - Where do you configure sign-in branding?
✅ Microsoft Entra admin center - License required for Insider Risk Management?
✅ Microsoft 365 E5 - Role that can assign roles but not create new global admins?
✅ Privileged Role Administrator - Where to view billing and payment info?
✅ Microsoft 365 admin center → Billing - Role for password resets and license management?
✅ User Administrator - Can you rename the
.onmicrosoft.comdomain?
✅ No, it cannot be renamed - Where to view historical outages?
✅ Service Health dashboard - What must be done after adding a new domain?
✅ Verify via TXT record - Tool to sync on-prem AD users?
✅ Azure AD Connect - Maximum number of custom domains per tenant?
✅ 900 - Best way to document tenant settings?
✅ Export settings from M365 Admin Center - Default admin account in new tenant?
✅ Global Administrator - Where to configure organization’s contact preferences?
✅ Organization Profile in Microsoft 365 Admin Center - Prerequisite for assigning licenses to users?
✅ Verified domain - Fastest way to add 200 users?
✅ PowerShell Import-Csv + New-MgUser - Where to view license usage?
✅ License reports in Microsoft 365 Admin Center - Service controlling global branding?
✅ Entra ID Company Branding - Why might a user fail login after username change?
✅ Old UPN cached - Role to view message center posts?
✅ Message Center Reader - Report to find inactive users?
✅ Usage reports in Microsoft 365 Admin Center - Prevent admins from using personal accounts?
✅ Block external accounts at tenant level - Who manages billing alerts and payments?
✅ Billing Administrator - Tenant timezone setting affects:
✅ Report timestamps
🔹 Section 2: Identity & Access Management
- Most phishing-resistant authentication method?
✅ FIDO2 key - Conditional Access evaluates:
✅ User, location, and device compliance - Entra-registered devices are:
✅ Personal (BYOD) MAM-only devices - How to enforce MFA globally?
✅ Use Security Defaults or Conditional Access - License required for SSPR?
✅ Azure AD Premium P1 or higher - Repeated MFA prompts — cause?
✅ “Remember MFA” not configured - Block risky IPs via:
✅ Named Locations in Conditional Access - Allow access only from managed devices:
✅ Require compliant device - Conditional Access applies to:
✅ Cloud apps and sign-in context - Detect leaked credentials:
✅ Entra ID Protection - RBAC principle used by Entra:
✅ Least privilege - Helpdesk can reset passwords only:
✅ Password Administrator - Sign-in frequency controls:
✅ Reauthentication interval - Device join types in Entra:
✅ Registered, Joined, Hybrid Joined - Track admin role changes:
✅ Entra Audit Logs - Purpose of Privileged Identity Management (PIM):
✅ Just-in-time role activation - Limit persistent sessions:
✅ Conditional Access session control - Disable basic authentication:
✅ Conditional Access — block legacy auth - Admin approval before app consent:
✅ Admin consent workflow - View risky users:
✅ Entra ID Protection - Conditional Access evaluation order:
✅ All applicable policies evaluate - Force password reset after compromise:
✅ Reset password + mark user risk high - Purpose of Temporary Access Pass:
✅ Passwordless onboarding - Entra roles can be scoped to:
✅ Administrative Units - Delegate regional management:
✅ Administrative Units
🔹 Section 3: Security & Compliance
- DLP protects:
✅ Sensitive data in email, SharePoint, and Teams - Encrypt sensitive files:
✅ Sensitivity labels - Retention labels define:
✅ How long to keep or delete data - Compliance Manager provides:
✅ Compliance score and recommendations - Auto-labeling uses:
✅ Trainable classifiers or sensitivity conditions - Keep Teams chats for 30 days:
✅ Retention policy for Teams - Data lifecycle management is under:
✅ Microsoft Purview - Stop external sharing of sensitive info:
✅ DLP policy with block action - View insider risk alerts:
✅ Purview → Insider Risk Management - Monitor file activity:
✅ Audit log search - Default audit log retention (E3):
✅ 90 days - Detect suspicious email forwarding:
✅ Defender for Office 365 - Safe Links protects from:
✅ Malicious URLs - Safe Attachments scans:
✅ Emails and Teams attachments - Quarantine suspicious emails:
✅ Defender for Office 365 - Analyze security posture:
✅ Microsoft Secure Score - Classify data with predefined types:
✅ Sensitivity labels - Require approval before deletion:
✅ Retention policy with disposition review - License for Insider Risk:
✅ Microsoft 365 E5 - Prevent data copy/paste:
✅ Endpoint DLP or Intune App Protection - Encrypt and restrict printing:
✅ Sensitivity label with encryption - View eDiscovery cases:
✅ Purview → eDiscovery - Generate compliance alerts for data sharing:
✅ DLP alerts - Protect unmanaged devices accessing SharePoint:
✅ Conditional Access app control - Measure compliance progress:
✅ Compliance Score
🔹 Section 4: Device Management
- Intune enrollment types:
✅ Corporate, BYOD, Shared - Enforce PIN in Outlook for iOS:
✅ App Protection Policy - Limit devices per user:
✅ Enrollment restrictions - Co-management requires:
✅ SCCM client + Entra registration - Allow only corporate Androids:
✅ Enrollment restrictions - Supported app types:
✅ Win32, MSI, Store, and LOB - Wipe data but keep enrollment:
✅ Wipe (Keep enrollment data) - Compliance state used by:
✅ Conditional Access - Endpoint Security policies configure:
✅ Antivirus, BitLocker, Firewall, ASR - BitLocker recovery keys stored in:
✅ Entra ID - Requirement for Autopilot registration:
✅ Hardware hash - Purpose of Enrollment Status Page (ESP):
✅ Ensures required apps install before use - Temporary privilege elevation feature:
✅ Endpoint Privilege Management - Monitor update failures:
✅ Windows Update for Business reports - Device filters refine:
✅ Policy assignments by attributes - Restrict Microsoft Store access:
✅ Device Restrictions policy - Deploy Wi-Fi certificates:
✅ SCEP or PKCS + Wi-Fi profile - Shared PC Mode is for:
✅ Multi-user shared environments - Intune compliance reports by:
✅ Device, User, and Policy - Proactive Remediations use:
✅ Detection and remediation PowerShell scripts - Measure boot and performance:
✅ Endpoint Analytics - Encrypt macOS devices:
✅ FileVault - Manage Apple app licenses:
✅ Apple VPP token integration - Conditional Access device state comes from:
✅ Intune compliance signal - Collect logs during Autopilot setup:
✅ Shift+F10 → runmdmdiagnosticstool

