Microsoft 365MS-102

MS-102 Admin Playbook: Defender, Purview, and Intune Scenarios Explained (With Portal Steps)

MS-102 Admin Playbook: 5 Security and Intune Scenarios Explained

Below is a streamlined, “what an admin would actually do” walkthrough of the scenarios shown in your screenshot. I reshuffled the order, renumbered them, and added the practical steps, verification, pitfalls, and rollback guidance.


Question 1: Defender for Identity sensor updates after the cloud service updates

What this scenario is testing

Whether you understand how Microsoft Defender for Identity sensors update, including the Delayed update ring concept (staged rollout vs. immediate). (Microsoft Learn)

Correct approach

  • Sensors not set to Delayed update: update automatically after the service update (staged sensor-by-sensor).
  • Sensors set to Delayed update: update 72 hours after the official service update. (Microsoft Learn)

Note: Your screenshot’s answer key shows a different hour value. That can happen with older “Azure ATP” era exam items. In current Defender for Identity documentation, the delayed update is 72 hours. (Microsoft Learn)

Step-by-step (portal paths)

  1. Go to Microsoft Defender XDR: security.microsoft.com
  2. Navigate to SettingsIdentitiesSensors
  3. Select a sensor → Manage sensor
  4. Review or toggle Delayed update (Enabled/Disabled). (Microsoft Learn)

Verification

  • On SettingsIdentitiesSensors, confirm:
    • Version
    • Sensor status (Up to date / Updating)
    • Delayed update column state (Microsoft Learn)

Common pitfalls

  • Confusing service update timing with sensor update timing.
  • Assuming “Delayed update” is minutes or hours instead of a staged ring delay. (Microsoft Learn)

Rollback

  • If a new sensor build causes issues, move most sensors to Delayed update while you validate with a smaller pilot ring.
  • If a sensor fails to update, use the health alert details on the Sensors page and open a support case if needed. (Microsoft Learn)

Question 2: “Volume becomes unusual” alert policy baseline behavior

What this scenario is testing

Whether you know how Microsoft Purview alert policies build a baseline for “unusual” activity and what happens during that baseline window. (Microsoft Learn)

Correct approach

  • The baseline is established over 7 days.
  • Alerts are not triggered during baseline establishment. (Microsoft Learn)

Step-by-step (portal paths)

  1. Go to Microsoft Purview portal: compliance.microsoft.com
  2. Navigate to AlertsAlert policies
  3. Create or edit an alert policy
  4. Under trigger logic, select When the volume of matched activities becomes unusual
  5. Save the policy (baseline begins collecting). (Microsoft Learn)

Verification

  • After the 7-day baseline window, generate a known test pattern (within policy scope) and confirm an alert appears in:
    • PurviewAlertsAlerts
  • Confirm the alert matches the policy name and target activity.

Common pitfalls

  • Expecting alerts immediately after enabling “unusual” volume.
  • Changing scope frequently during baseline, which can make results less predictable.

Rollback

  • Temporarily switch the trigger mode to a static threshold (for immediate alerting) or disable the policy while tuning.
  • Re-enable “unusual volume” once your scope is stable.

Question 3: Finding ZAP removals and malicious URL click counts in Defender for Office 365 reports

What this scenario is testing

Whether you can pick the right report in Microsoft Defender for Office 365 to answer:

  1. “How many messages were affected by ZAP?”
  2. “How many malicious URL clicks occurred?”

Correct approach

  • ZAP-removed message counts: Use Mailflow status reportMailflow view, which shows “ZAP removed” in the flow and table. (Microsoft Learn)
  • URL click counts: Use the URL protection report, which shows the number of URL clicks and the click outcomes. (Microsoft Learn)

Step-by-step (portal paths)

  1. Go to security.microsoft.com
  2. Email & collaborationReports
  3. Open Mailflow status report
    • Switch to the Mailflow tab/view
    • Review ZAP removed in the flow and details table (Microsoft Learn)
  4. Back to Reports
  5. Open URL protection report
    • Use View data by URL click protection action to see click totals (Microsoft Learn)

Verification

  • Export both reports and confirm:
    • Mailflow report includes a ZAP removed metric (Microsoft Learn)
    • URL protection report includes URL click counts and action outcomes (Microsoft Learn)

Common pitfalls

  • Expecting URL click data without enabling Track user clicks in Safe Links. The report explicitly warns click data depends on that setting. (Microsoft Learn)
  • Confusing mailflow “processed outcomes” with post-delivery behavior. (ZAP is post-delivery and appears as its own outcome in the Mailflow view.) (Microsoft Learn)

Rollback

  • If you need to reduce user risk quickly:
    • Tighten Safe Links actions (block and remove click-through)
    • Increase Safe Attachments aggressiveness
    • Keep reporting enabled for evidence, then relax after the incident window.

Question 4: Which devices can receive Intune App Configuration Policies

What this scenario is testing

Whether you understand Intune App Configuration Policies scope: they can target mobile apps (iOS/iPadOS, Android) and can work in MAM (unenrolled) scenarios as well. (Microsoft Learn)

Correct approach (based on the device table in your screenshot)

In that table, the devices you can manage with app configuration policies are the Android and iOS devices, regardless of whether they are enrolled (because managed apps/MAM can apply without enrollment). (Microsoft Learn)

Step-by-step (portal paths)

  1. Go to Intune admin center: intune.microsoft.com
  2. Navigate to AppsApp configuration policies
  3. Create → choose:
    • Managed devices (for enrolled devices), or
    • Managed apps (MAM without requiring device enrollment)
  4. Select platform (Android/iOS), targeted app, then assign to users/groups.

Verification

  • On a test phone:
    • Launch the targeted app (first run often triggers config pickup)
    • Confirm settings are applied (account restrictions, server URLs, branding, etc.)
  • In Intune:
    • Check policy assignment status and app install/config status (where supported).

Common pitfalls

  • Trying to apply mobile app configuration logic to Windows devices in the same way as iOS/Android.
  • Using a device group when the policy is intended for user-based MAM targeting.

Rollback

  • Unassign the policy from the target group or exclude the pilot group.
  • If using managed apps (MAM), remove the app configuration policy assignment and allow the app to revert to default behavior.

Question 5: Which email threat policies support a customized quarantine retention period

What this scenario is testing

Whether you know which policy types can customize quarantine retention versus those that are fixed.

Correct approach

  • Custom quarantine retention is supported for spam and phishing via the Anti-spam policy setting “Retain spam in quarantine for this many days,” and that same setting also controls anti-phishing quarantine retention. (Microsoft Learn)
  • Anti-malware and Safe Attachments quarantines have 30 days retention and are not customizable. (Microsoft Learn)

So, in the policy list shown (Anti-phishing, Anti-spam, Anti-malware, Safe Attachments), the policies that support customized quarantine retention are:

Step-by-step (portal paths)

  1. Go to security.microsoft.com
  2. Email & collaborationPolicies & rulesThreat policies
  3. Open Anti-spam
  4. Edit the policy and set Retain spam in quarantine for this many days (1–30 days). (Microsoft Learn)

Verification

  • Confirm the policy value in the Anti-spam policy UI.
  • Check quarantine behavior over time (messages older than the configured period should no longer be recoverable).

Common pitfalls

  • Assuming Safe Attachments quarantine retention is adjustable (it is not). (Microsoft Learn)
  • Forgetting policy precedence (the first matching policy for the recipient controls the value).

Rollback

  • Reset the retention value back to your standard (many tenants default to 15 or 30 depending on how the policy was created).
  • If you need immediate reversibility, change the policy scope back to a pilot group first.

Leave a Reply

Your email address will not be published. Required fields are marked *