Microsoft MS-102 exam 365 administrator study guide
Free community-driven exam analysis for Microsoft. Based on 44 community-discussed topics.
Exam Overview
The MS-102: Microsoft 365 Administrator certification validates your expertise in managing and administering Microsoft 365 services and related products. It is designed for IT professionals who serve as administrators in a Microsoft 365 environment, focusing on the implementation, management, and monitoring of tenant resources.
This credential demonstrates that you can perform advanced administrative tasks across various Microsoft 365 workloads, ensuring that organizational data is secure, compliant, and efficiently managed. It proves your ability to handle complex scenarios involving identity, security, and compliance technologies within the Microsoft 365 ecosystem.
Exam Domains
- Manage identities and governance: Overseeing Azure AD integration, user lifecycle management, and role-based access control.
- Implement and manage security and compliance: Configuring threat protection, data loss prevention, and information protection policies.
- Manage voice solutions: Administering Teams phone system settings, calling plans, and audio conferencing features.
- Manage enterprise mobility and security: Deploying and managing Intune devices, conditional access policies, and endpoint security.
- Manage Microsoft 365 services: Handling service health, support tickets, and configuration for Exchange Online, SharePoint Online, and Teams.
Key Concepts & Common Difficulties
- Identity and Access Management: Candidates often struggle with the nuances of Azure AD Connect synchronization rules and hybrid identity scenarios. Focus on understanding how cloud-only vs. synced accounts behave and the implications of password hash sync versus pass-through authentication.
- Conditional Access Policies: Many test-takers find it difficult to prioritize overlapping policies or understand session controls. Remember that Conditional Access applies at sign-in time; ensure you distinguish between app-enforced restrictions and browser-based session controls correctly.
- Compliance Center Configuration: Understanding the difference between Information Protection (sensitivity labels) and Data Loss Prevention (DLP) policies is crucial. Sensitivity labels protect content at rest or in transit, while DLP policies monitor content in motion to prevent accidental sharing.
- Teams Phone System Administration: Managing resource accounts, auto attendants, and call queues can be tricky due to their interdependencies. Ensure you know how to assign emergency locations and configure routing rules for external calls accurately.
- Intune Device Compliance: Confusion often arises regarding compliance policy templates versus custom profiles. Understand that compliance policies define the 'what' (rules), while configuration profiles define the 'how' (settings applied to meet those rules).
Study Strategy
1. Prerequisites: Ensure you have hands-on experience with Microsoft 365 administration. Familiarity with Windows Server and Active Directory concepts is beneficial but not strictly required if you focus on cloud-native implementations. 2. Recommended Study Order: Start with Identity and Governance, as it underpins most other services. Move next to Security and Compliance, then Enterprise Mobility, and finally Voice and Service Management. 3. Practice Approach: Use the official Microsoft Learn paths to build foundational knowledge. Supplement this with scenario-based practice questions that mimic real-world admin tasks rather than simple recall queries. 4. Lab Environment: If possible, use a Microsoft 365 Developer Program tenant to experiment with setting up sensitivity labels, configuring Conditional Access policies, and managing Intune devices. Practical experience reinforces theoretical knowledge. 5. Exam-Day Tips: Read each question carefully, paying attention to keywords like "first," "best,
What You'll Find Here
- 16 highly debated topics with expert breakdown and analysis
- 28 community-verified topics with consensus explanations
- Debate ranking showing which concepts cause the most confusion
Study Recommendation
Focus on the debated topics first — these represent the areas where candidates most frequently struggle on the actual exam.
Featured Analysis
Most debated concepts with community insight
You have a Microsoft 365 E5 subscription. You need to assign a Microsoft Defende
The question tests where baseline profiles are authored and assigned for Defender for Endpoint; the trap is assuming the Microsoft Defender portal, wh
S-Grade · Deep AnalysisNote: This section contains one or more sets of questions with the same scenario
The exam tests whether you can map a stated protection intent (balanced baseline for most users) onto the correct preset profile, and the trap is trea
S-Grade · Deep AnalysisYou have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint
The question tests knowledge of how to bypass tamper protection locks on individual devices without disabling the feature globally.
S-Grade · Deep AnalysisYou have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 3
Tests whether you know that custom phishing email content is defined by a tenant payload, not by global payloads, landing pages, or end-user notificat
S-Grade · Deep AnalysisYou have a Microsoft 365 E5 subscription. You need to use Microsoft Defender for
The question tests the prerequisite for mailbox-visibility in MDCA — audit logging must be on before any activity exists; the trap is choosing a polic
S-Grade · Deep AnalysisReady to practice?
Access 111 MS-102 questions with instant feedback and detailed explanations.
View MS-102 Practice Questions →