MS-102 — Microsoft 365 Administrator
Microsoft

Microsoft 365 Administrator (MS-102) Practice Questions

★★★★★★ 4.2 107 verified reviews
111 questions
2026-06-18 updated
✓ Online quiz simulator

Sample Questions (12 of 111 shown)

Q1 Deploy and manage a Microsoft 365 tenant (10-15%)
You have a Microsoft 365 subscription that contains a verified custom domain named contoso.com. You need to add a new domain named fabrikam.com. Which type of DNS record must be created in the public DNS zone to verify domain ownership?
  1. A (Host) record
  2. MX record
  3. TXT record
  4. CNAME record
✓ Correct Answer: C
To verify ownership of a custom domain in Microsoft 365, you must add a specific TXT record provided by Microsoft to your domain's public DNS zone. The TXT record contains a verification string that Microsoft checks to confirm you control the domain. While MX records are needed for mail flow and CNAME records for other services, TXT records are the standard method for domain ownership verification.
Q2 Deploy and manage a Microsoft 365 tenant (10-15%)
You need to identify all users in a Microsoft 365 subscription who obtain their Office 365 license through group-based licensing. The solution must include the group name used for license assignment. What should you use?
  1. Active users page in the Microsoft 365 admin center
  2. Reports in the Microsoft Purview compliance portal
  3. Licenses blade in the Microsoft Entra admin center
  4. Reports in the Microsoft 365 admin center
✓ Correct Answer: C
The Licenses blade in the Microsoft Entra admin center (formerly Azure AD) provides a detailed view of group-based licensing. You can select a specific license, view the "Licensed groups" tab, and see which groups are assigned that license along with member status. The Active users page only shows individual users, and reports don't show group-level license assignments.
Q3 Deploy and manage a Microsoft 365 tenant (10-15%)
You have a Microsoft 365 subscription. You need to ensure that only specific users in the IT department can access the Microsoft 365 admin center. What should you configure?
  1. Conditional Access policy targeting the Microsoft 365 admin center app
  2. Custom domain verification
  3. Role assignments in the Microsoft 365 admin center
  4. Azure AD Application Proxy
✓ Correct Answer: A
To restrict access to the Microsoft 365 admin center to specific users, you should create a Conditional Access policy in Microsoft Entra ID that targets the "Microsoft 365 admin center" cloud app and grants access only to users in the IT security group. This ensures only authorized users can access administrative functions, providing a more granular control than role assignments alone.
Q4 Deploy and manage a Microsoft 365 tenant (10-15%)
You are reviewing service health in the Microsoft 365 admin center. You need to ensure that notifications about service incidents are sent to the IT support team. What should you configure?
  1. An alert policy in the Microsoft 365 Defender portal
  2. Service health notifications in the Microsoft 365 admin center
  3. An Activity alert in the Microsoft Purview compliance portal
  4. A notification in Azure Monitor
✓ Correct Answer: B
The Microsoft 365 admin center provides a Service health dashboard where you can configure email notifications for service incidents and advisories. You can specify recipients (such as the IT support team) and choose which types of issues to be notified about. This is the built-in mechanism for receiving Microsoft 365 service health updates.
Q5 Deploy and manage a Microsoft 365 tenant (10-15%)
You have a Microsoft 365 subscription. You need to perform bulk user creation by importing a CSV file. Which tool should you use?
  1. Microsoft Graph PowerShell
  2. Microsoft 365 admin center bulk add users
  3. Azure CLI
  4. IdFix tool
✓ Correct Answer: B
The Microsoft 365 admin center provides a built-in "Bulk add users" feature that allows you to upload a CSV file with user information to create multiple users at once. While Microsoft Graph PowerShell can also be used for bulk operations, the admin center provides a simpler, GUI-based approach for one-time bulk user creation. The IdFix tool is used for preparing on-premises directories for synchronization, not for bulk user creation.
Q6 Deploy and manage a Microsoft 365 tenant (10-15%)
Your organization has a Microsoft 365 E5 subscription. You need to implement Privileged Identity Management (PIM) to enable just-in-time administrative access. What should you configure?
  1. Azure AD roles with PIM activation in Microsoft Entra admin center
  2. Custom roles in the Microsoft 365 admin center
  3. Management units for delegated administration
  4. Exchange admin roles
✓ Correct Answer: A
Privileged Identity Management (PIM) in Microsoft Entra ID enables just-in-time (JIT) access to Azure AD roles. To implement PIM, you configure Azure AD roles with activation requirements in the Microsoft Entra admin center. Users must activate their role assignment for a limited time when they need elevated permissions. JIT access is a key security requirement mentioned in the exam objectives, and PIM is the tool to achieve this.
Q7 Deploy and manage a Microsoft 365 tenant (10-15%)
You are a Microsoft 365 administrator. You need to delegate user management to a helpdesk team member who should only be able to manage users in the Sales department. You must follow the principle of least privilege. What should you use?
  1. Administrative units in Microsoft Entra ID
  2. Custom Microsoft 365 roles
  3. Group-based licensing
  4. Conditional Access policies
✓ Correct Answer: A
Administrative units in Microsoft Entra ID allow you to delegate administrative permissions scoped to a specific subset of users. By creating an administrative unit for the Sales department, you can assign the Helpdesk Administrator role scoped only to that unit. This follows the principle of least privilege by limiting the helpdesk member's management scope to just the Sales department users.
Q8 Deploy and manage a Microsoft 365 tenant (10-15%)
You have a Microsoft 365 subscription. You need to configure the organization profile, including the technical contact and preferred language. Where should you configure these settings?
  1. Microsoft 365 admin center, Organization settings
  2. Microsoft Entra admin center, Properties
  3. Microsoft Purview compliance portal
  4. Microsoft 365 Defender portal
✓ Correct Answer: A
Organization profile settings, including the technical contact, preferred language, and organization information, are configured in the Microsoft 365 admin center under Organization settings > Organization profile. This is the central location for managing your organization's identity in Microsoft 365.
Q9 Deploy and manage a Microsoft 365 tenant (10-15%)
You need to plan a Microsoft 365 tenant deployment and ensure that network connectivity is optimized for users in remote branch offices. Which tool should you use to analyze network connectivity insights?
  1. Microsoft 365 network connectivity test
  2. Azure Network Watcher
  3. Microsoft 365 admin center Network connectivity page
  4. Microsoft Entra Connect Health
✓ Correct Answer: C
The Microsoft 365 admin center provides a Network connectivity page (also known as Network Insights) under Health > Network connectivity. This tool analyzes network performance from user locations to Microsoft 365 services and provides recommendations for optimizing connectivity. It specifically measures metrics such as network latency, packet loss, and throughput from user locations to the nearest Microsoft 365 service entry points.
Q10 Deploy and manage a Microsoft 365 tenant (10-15%)
You need to delegate permissions to a user who will manage Microsoft Defender XDR policies but should NOT be able to manage user accounts. Which approach should you use?
  1. Assign the Security Administrator role in Microsoft Entra ID
  2. Create a custom role in the Microsoft 365 Defender portal
  3. Add the user to the Global Administrators group
  4. Assign the Compliance Administrator role
✓ Correct Answer: A
The Security Administrator role in Microsoft Entra ID grants permissions to manage security-related features, including Microsoft Defender XDR policies, while not granting permissions to manage user accounts. This aligns with the principle of least privilege. The Global Administrator has excessive permissions, and Compliance Administrator focuses on compliance rather than security.
Q11 Deploy and manage a Microsoft 365 tenant (10-15%)
You have a Microsoft 365 subscription. You need to configure Microsoft 365 backup for SharePoint sites. What should you use?
  1. Microsoft 365 admin center, Backup tab under Setup
  2. SharePoint Admin Center
  3. Microsoft Purview compliance portal
  4. Microsoft Entra admin center
✓ Correct Answer: A
Microsoft 365 Backup is configured from the Microsoft 365 admin center under Setup > Backup. This centralized backup management tool allows administrators to configure and manage backups for SharePoint, OneDrive, and Exchange Online data as part of Microsoft's built-in backup offering.
Q12 Deploy and manage a Microsoft 365 tenant (10-15%)
You are configuring a Microsoft 365 trial tenant for a proof of concept. After sign-up, you need to verify the environment and locate the tenant URL. Where should you look?
  1. Power Platform Admin Center
  2. Microsoft 365 admin center
  3. Azure Portal
  4. Microsoft Entra admin center
✓ Correct Answer: A
After creating a Microsoft 365 trial tenant, the Power Platform Admin Center (admin.powerplatform.microsoft.com) lists all environments including the trial tenant's environment with its URL. While the Microsoft 365 admin center is the primary admin interface, the Power Platform Admin Center specifically shows environment details including the environment URL.

You've viewed 3 of 111 questions. Start the free practice exam to answer all questions with instant feedback.

What Our Customers Say 107 verified reviews

4.2 ★★★★★★ Based on 107 reviews
★★★★★★
Highly recommended for Microsoft certification. The MS-102 practice questions are worth every penny.
— Andrew M.
★★★★★
I passed MS-102 on my first try thanks to these practice questions. The unlimited retakes were essential for building confidence.
— Nicole K.
★★★★★★
Comprehensive coverage for MS-102. Every domain is represented and the question difficulty ramps up nicely.
— Emma J.
★★★★★★
The MS-102 exam was tough but this resource made it manageable. Would definitely recommend to anyone studying for this cert.
— Mateo R.
★★★★★★
Straight to the point. No filler, just good MS-102 practice questions with clear explanations. Exactly what I needed.
— Paisley K.
★★★★★★
I bought access for the MS-102 exam as a gift for my brother. He passed on his first try and said the questions were spot-on.
— Cameron J.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

The primary pitfall is confusing the operational limitations of Microsoft Entra Cloud Sync versus the full Entra Connect client—specifically, Cloud Sync does not support pass-through authentication (PTA) or device writeback, while Entra Connect does. The second major struggle area is tracking the exact evaluation and precedence order when multiple nested Conditional Access policies apply to the same user and application. Our practice questions include scenario-based items on both topics, with detailed explanations that walk through the decision tree step by step.

The full searchable Microsoft Learn documentation library is accessible directly within the exam window via an integrated split-screen browser. However, time management is the critical constraint: using it extensively will deplete your 120 minutes rapidly. Treat it as a safety net to verify exact PowerShell cmdlet syntax or specific policy menu names, not as a substitute for preparation. Our practice questions are designed to be answered without external reference, building the recall speed you need on exam day.

Microsoft hosts a free, structured multi-module self-paced learning path directly on the official MS-102 exam page on Microsoft Learn. Additionally, Microsoft offers an official, un-timed free Practice Assessment engine on the same page, which mirrors the formatting and technical difficulty of the real proctored exam. Combining these official resources with our supplementary practice question bank gives you both the authoritative content and the repetition needed to build exam-day confidence.

If you do not pass on your first attempt, you must wait at least 24 hours before rescheduling a second try. For attempts 3 through 5, a strict 14-day cooling-off window is enforced between each registration, and you are capped at five total attempts per rolling 12-month period. Our practice tests help you identify domain-specific knowledge gaps before using an attempt, particularly in the heavily weighted Defender XDR domain where scenario-based case studies require both speed and accuracy.

The online mock exam replicates the MS-102 exam format with unreviewable case study sections, drag-and-drop sequencing, hot area configurations, and multiple-response questions that award partial credit for individually correct selections. The practice engine also simulates the split-screen workflow, presenting scenario-based questions that test whether you can quickly locate the correct PowerShell cmdlet or Microsoft Learn article reference without losing time—the same skill the real exam measures.

Yes, the full question bank is available as a downloadable PDF that packages all practice questions, answer explanations, and domain references in a portable format. The PDF gives special attention to Defender XDR incident response workflows and Purview Sensitivity Label deployment scenarios, which together account for up to 60% of the exam's weighted content. It is ideal for offline review during commutes, flights, or in environments without stable internet access.

The credential is valid for exactly one year from the date you pass the exam. Microsoft allows you to extend its validity annually for free by passing an online, unproctored renewal assessment on Microsoft Learn within the 6-month window prior to expiration. No additional exam fee is required for renewal, and the renewal assessment is open-book—though a solid understanding of Defender XDR and Purview updates from the past year is essential to pass efficiently.

Free Study Resources

Community-verified analysis of 94 topics from real test-taker discussions — 12 deep analyses and 0 FAQs.