MS-102 — Frequently Asked Questions
Community-vetted answers to 86 common questions about this exam.
Questions from real practice questions
Each Q&A comes from a specific community question — follow the link for its full analysis.
Which passwordless method works on Windows, Android, and iOS?
No. Passwordless phone sign-in with Microsoft Authenticator is limited to iOS and Android devices, so it cannot serve the Windows devices named in this scenario.
Windows Hello for Business is a device-bound Windows credential that relies on the PC's TPM plus PIN or biometrics, so it is unavailable on Android and iOS.
Enabling Passwordless Sign-in on Workgroup Devices
The Authenticator app works best when paired with a trusted device. Joining or registering the device ensures the system recognizes the hardware, enabling stronger security checks and Conditional Access policies.
No. Certificate-based auth is a credential type. To manage and deploy these certificates securely in an enterprise, you typically need the devices to be managed via Intune or joined to Entra ID.
Filtering Secure Score by Department
Administrative Units delegate permissions and management scope. They do not provide a filtering interface for viewing or prioritizing Secure Score recommendations.
Yes, you must assign the created tag to specific users or devices before it appears as an available filter option in the Secure Score view.
Microsoft 365 Passwordless Authentication Across Platforms
Windows Hello for Business is only supported on Windows devices and cannot authenticate Android or iOS users.
Standard MFA often uses passwords plus another factor. Passwordless MFA typically refers to methods like FIDO2 or the Authenticator app push.
Enabling Passwordless Sign-in for Workgroup Devices
The Authenticator app handles user verification, but passwordless methods like Windows Hello for Business require the device itself to be trusted and registered with Entra ID.
Workgroup devices can register for basic MFA, but advanced passwordless features like FIDO2 or Windows Hello for Business require the device to be joined to Entra ID.
How Do You Force a Password Change for Leaked Credentials in Entra ID Protection?
Sign-in risk evaluates the authentication attempt or session, such as an anonymous IP or atypical travel, not compromised stored credentials. Leaked credentials are user risk, and only a user risk policy applies the 'Require password change' remediation.
No. Password protection only blocks weak or banned passwords, and SSPR merely lets users reset their own password. Neither detects leaked credentials or forces a password change based on risk.
Which components configure a Defender for Cloud Apps log collector?
The receiver type (FTP, FTPS, Syslog UDP/TCP/TLS) is part of the data source definition on the Data sources tab, while the log collector record stores its name, host IP/FQDN, and associated data source(s).
Yes, but you configure it when creating the data source, not when creating the log collector; the question asks specifically about log collector components.
Which Cloud Discovery Report Identifies Most-Used Apps in 30 Days?
The executive report provides a broad, scheduled overview for management, while the snapshot report offers focused, date-range-specific detail needed to identify the most-used apps in the last 30 days.
The dashboard shows live data, but generating a snapshot report gives you a shareable, time-bound analysis specifically for the last 30 days, which directly answers the question.
Onboard iOS Devices to Microsoft Defender for Endpoint via Intune
Onboarding packages are scripts/configs for Windows and macOS sensors. iOS uses the Microsoft Defender for Endpoint app from the App Store.
It means adding the Microsoft Defender for Endpoint iOS store app in the Intune Admin Center and assigning it to user groups.
What Should You Do First for App1 Access Policy in Defender for Cloud Apps?
App connectors provide API-based activity and file visibility; access policies need real-time session control, which requires Conditional Access App Control instead.
No, Entra ID registration alone is not enough; you must deploy Conditional Access App Control to App1 before creating an access policy.
How Do You Monitor Mailbox Activities in Defender for Cloud Apps?
The app connector is how MDCA ingests Office 365 activity, but with mailbox audit logging off there is no Exchange mailbox activity for it to surface, so the mailbox setting is the required first step.
No. Activity policies only filter and alert on activity already logged in MDCA, so mailbox audit logging must be enabled before a policy can ever see mailbox events.
How to Configure a Custom Phishing Link in Attack Simulation Training?
A landing page controls the web page shown after a user clicks the simulated link; it does not compose the phishing email, its link, or the message branding.
No. Global payloads are Microsoft built-in templates that cannot be modified; create a tenant payload when you need a custom link, sender, or company terminology.
Configuring Antivirus with Tamper Protection Enabled
No, it is a temporary state that can be toggled on or off as needed for troubleshooting or configuration.
No, device groups manage policy assignments but do not bypass the runtime enforcement of tamper protection on individual endpoints.
Does a Strict Preset Security Policy Meet the Balanced Baseline Goal?
Strict protection does cover those workloads, but it is tuned aggressively for high-value or priority users, not as a balanced baseline. The scenario asks for the baseline profile, which is Standard protection.
Apply the Standard preset security policy, which Microsoft defines as the baseline profile suitable for most users and includes anti-spam, anti-phishing, anti-malware, Safe Links, and Safe Attachments.
Which Portal Assigns the Microsoft Defender for Endpoint Baseline?
The Defender portal is for incidents, alerts and advanced hunting; baseline profiles are created and targeted to device groups as Intune endpoint security profiles.
The Microsoft 365 E5 subscription in the scenario already includes Intune and Defender for Endpoint, so both the baseline templates and the Intune admin center are available.
Which Devices Can Endpoint DLP Policies Be Applied To?
No. Endpoint DLP applies to onboarded Windows 10 1809+, Windows 11, Windows Server 2019/2022 and macOS only; Android and iOS protection comes from the separate mobile DLP capability using the Defender for Endpoint app.
Yes, macOS is a supported Endpoint DLP platform, but since the question lists only Windows 11, Android and iOS, Windows 11 remains the single correct choice.
Least privilege role to review Identity Protection risky users
Reports Reader can view sign-in and audit reports but does not include the Identity Protection risky users list. Security Reader is the read-only security role for that data, so D is not correct.
Global Administrator grants full tenant control and far exceeds the review-only requirement. Security Administrator provides the needed Identity Protection access with fewer privileges.
What Compares Microsoft 365 Security Configurations to Best Practices?
Exposure score rates the attack surface risk of devices and identities in Defender Vulnerability Management. It never compares tenant configuration to Microsoft baselines or produces improvement actions.
Yes. Secure Score aggregates recommendations across Microsoft 365 services, including Defender for Cloud Apps, so some improvement actions relate to cloud app governance.
Which platform supports Microsoft Authenticator passwordless sign-in for two tenants?
The item was written when multi-account passwordless phone sign-in was documented for iOS only. Android parity came later, which is why some learners call the question obsolete.
Yes. Each work or school account can be added to the same Authenticator install, and passwordless phone sign-in can be enabled per account on a supported platform.
How to Modify city Attribute for AD-Synced Entra Users?
Synced users are mastered on-premises, so Entra attributes such as city are read-only in the cloud and any direct change is overwritten by the next synchronization cycle.
No, but the Active Directory PowerShell module must be installed. Option A's domain controller wording is still valid because only on-premises AD is authoritative for the synced city attribute.
Which DNS Record Is Needed to Add a Microsoft 365 Domain?
Microsoft 365 uses a TXT record to prove you own the public domain; NS records delegate DNS authority, which is not required for simple domain verification.
No. PTR records provide reverse DNS lookup from IP to hostname and are not used by Microsoft 365 to validate a custom domain.
Which devices support the Defender Update controls endpoint security template?
The template configures Microsoft Defender Antivirus protection update behavior, which is delivered only to supported Windows clients, so any non-Windows entry has no settings to receive.
It controls how Defender Antivirus protection updates (security intelligence) are obtained and applied, such as update source, frequency and channels, on managed Windows devices.
Which Source Appears on Microsoft Defender XDR Incidents Page?
Sentinel only appears on the Incidents page when explicitly connected to Defender XDR; Defender for Identity is a default integrated source in a Microsoft 365 tenant.
Defender for Cloud can integrate, but it is not a native Microsoft 365 Defender incident source by default, so it is not the expected answer for a standard tenant.
Which DLP Rule Condition Works Across the Policy Locations?
Keywords are not supported in every DLP workload; endpoint DLP and Teams chat do not offer the keyword condition, while sensitive info types are universal across the locations.
Sensitivity labels are a condition in some workloads like Exchange and SharePoint, but they are not available for all locations in the exhibit, so they are not the correct universal choice.
How to Notify HR Manager When SharePoint Files Are Shared?
SharePoint site alerts are scoped to a single site and usually notify the alert creator about item changes, so they cannot notify an HR manager whenever any department user shares a file or folder.
Use a Microsoft Defender for Cloud Apps activity policy, which can detect SharePoint and OneDrive sharing events and send an email alert to the manager.
First Step to Deploy an Auto-Labeling Policy for Encrypted Emails?
Simulation mode identifies which emails match the sensitive info type and would be encrypted, letting you validate the rule without enforcing encryption prematurely.
Simulation mode only reports matches and does not apply encryption; turning the policy on enforces the sensitivity label and encryption on matching emails.
Which DLP Policy Location Enables Endpoint Rule Actions?
Endpoint rule actions come from the DLP agent on Windows and macOS devices, not from cloud storage. OneDrive accounts only exposes file and sharing conditions for cloud files.
No. That location is for the information protection scanner discovering files on file shares, so it never surfaces USB, copy, or network-share endpoint actions.
What Does Semi-Require Approval for Non-Temp Folders Do in Defender XDR?
C:\Windows is a core, non-temporary folder, so only the Full – remediate threats automatically level cleans threats there without approval.
Yes. User download and temp paths count as temporary folders, so a threat there is auto-remediated at the non-temp folders level.
Which Devices Support Endpoint DLP Policies in Microsoft 365 E5?
Endpoint DLP only onboards Windows 10/11 and macOS devices. Android and iOS protection uses Intune app protection policies and Purview DLP for cloud apps such as Exchange Online, SharePoint and OneDrive.
No. Licensing enables the DLP service, but device support is defined by the platform list Microsoft publishes for Endpoint DLP, which does not include Android or iOS.
How to Purge Malicious Mail Already Delivered to a Mailbox in Defender?
Enhanced filtering only lets Exchange Online trust the last-hop IP and SPF handling of an on-premises connector so hybrid mail is filtered correctly. It never revisits or deletes messages that were already delivered.
Yes. Malware ZAP is controlled from the anti-malware policy family in the Microsoft Defender portal; spam and phishing ZAP live in the anti-spam policy. Malware ZAP is on by default but can be toggled.
How to block Office applications from creating child processes in Microsoft 365?
An EDR policy only onboards Windows 11 devices to Defender for Endpoint and configures investigation, remediation and tamper protection settings. Blocking process creation requires an ASR rule, which is delivered through an attack surface reduction policy.
No. Safe Documents opens untrusted files in Protected View in Defender for Office 365 and has no control over whether Word, Excel or Outlook spawn child processes on the endpoint, so the ASR recommendation stays open.
What Implements Social Engineering Awareness in Defender for Office 365?
Learning hub only provides security awareness content; it cannot create the password-reset phishing simulation or track users who click the link like attack simulation training does.
It records payload link clicks and can automatically assign or suggest follow-up training to users who interact with the simulated message.
Does a Standard Preset Security Policy Meet a Balanced Baseline Goal?
Yes. Standard is the preconfigured balanced profile in Defender for Office 365 preset security policies; Strict is the more aggressive profile that quarantines more.
The scenario asks for a balanced baseline, not maximum protection. Strict delivers stronger, quarantine-heavy settings, exceeding the stated requirement.
Does an Intune EDR Policy Auto-Onboard Devices to Defender for Endpoint?
Many learners believe automatic onboarding requires the Defender for Endpoint connector in Intune, but an assigned EDR policy also delivers the onboarding configuration to targeted devices.
Yes. The policy is assigned to a device group, so existing and newly enrolled Windows devices in that group receive the Defender for Endpoint onboarding settings.
Does Co-management Auto-Onboard Devices to Defender for Endpoint?
No. Co-management only lets Configuration Manager and Intune manage the same device and workload split; it does not push the Defender for Endpoint onboarding configuration.
An Endpoint Detection and Response (EDR) policy in Intune, together with the Defender for Endpoint connector, delivers the onboarding configuration when the device enrolls.
Does a Device Configuration Profile Onboard Devices to Defender for Endpoint?
Yes. Microsoft's MDM onboarding guidance lists both a custom configuration policy and an EDR policy, so the older custom OMA-URI profile method remains supported.
They assume only the EDR policy or the Defender for Endpoint connector can onboard devices. The question only requires automatic onboarding at Intune enrollment, which the configuration profile provides.
Which Defender for Cloud Apps Policy Blocks Printing from App1?
A session policy can enforce real-time controls like block printing inside the proxied App1 session, whereas an activity policy is for detecting or alerting on activities after they occur.
No. OAuth app policies govern app permissions and consent, while Cloud Discovery anomaly detection policies flag unusual shadow IT usage; neither blocks printing from a Conditional Access App Control session.
How to Track Audited Cloud Discovery Apps in Defender for Cloud Apps?
A snapshot report is a static, point-in-time export of discovery data. It adds no status field to the app itself, so the cloud app catalog cannot later display an audited-apps list from it.
Tag each app after its audit, for example "Audited", then filter or group the Cloud app catalog or discovered-app queries by that tag to show only the audited apps.
How Long Is Attack Simulation Training Available After the Simulation?
Fifteen days belongs to other simulation fields such as due-date or reminder counts, not to the maximum training availability window, which is 30 days after the simulation ends.
The training assignment simply expires for that user, so the simulation's failure record stands alone and no further training content is served from that campaign.
Which messages are phishing with anti-phishing threshold 3 applied?
The more-aggressive level lowers the bar: medium-confidence phishing detections are treated as very high confidence, so a medium-PCL message such as Mail2 is actioned by Policy1 as well.
Yes. That setting enables impersonation protection for User1, so messages that spoof her identity are classified as phishing on top of the PCL-based detections.
How to generate a Defender for Endpoint alert for malicious device activity?
C is not factually wrong, but D is the better answer because it fully specifies the Microsoft Defender portal and matches Microsoft's documented path for custom detection rules.
No. A Purview DLP policy governs data handling, and an alert suppression rule hides matching alerts; neither creates a new Defender for Endpoint alert for malicious device activity.
Which Role Lets a User Review Risky Users in Entra ID Protection?
Reports Reader only covers usage and sign-in/audit reporting surfaces. It does not include the Identity Protection risk detections permission, so the Risky users blade stays inaccessible.
No. User Administrator manages user objects and group membership but has no permission to read Identity Protection risk data, and it would exceed least privilege for a review task.
Which Defender for Office 365 Policy Quarantines .apk and .appx Attachments?
Safe Attachments detonates files in a sandbox and acts on malware verdicts or unknown-malware timeouts. It has no list where you can name .apk and .appx, so it cannot satisfy an extension-based quarantine requirement.
In the policy's Common attachment types filter, add each extension as a custom file type and set the action to Quarantine. Messages carrying those attachment types are then quarantined for review.
Ready to practice?
Access 111 MS-102 questions with instant feedback and detailed explanations.
View MS-102 Practice Questions →← Back to Microsoft MS-102 exam 365 administrator study guide