nerdexam
Microsoft

MS-102 Real Exam Questions

Microsoft 365 Administrator. Everything you need to prepare, practice, and pass.

369

Questions

5

Exam Domains

Included

Explanations

Ready to practice?

369+ questions with detailed explanations

Start Now

From $49.99 USD · refund policy applies

Browse all 369 MS-102 questions

Certification Overview

MS-102 tests comprehensive Microsoft 365 tenant administration, centered on identity governance through Microsoft Entra ID and hybrid identity solutions, multi-layered security via Microsoft Defender XDR tools, and data protection through Microsoft Purview and DLP policies. Success requires understanding how these components integrate to secure and comply with enterprise requirements.

What This Certification Proves

The MS-102 certification validates expertise in deploying, configuring, and managing Microsoft 365 environments, with heavy emphasis on security, compliance, and identity management. This credential is essential for IT professionals responsible for Microsoft 365 tenant administration in enterprise environments and demonstrates competency in modern cloud-based identity and threat management.

Who Should Take This Exam

IT professionals with 1-2+ years of experience managing on-premises Active Directory or cloud infrastructure, transitioning to or already supporting Microsoft 365 environments. Ideal for system administrators, cloud administrators, or IT professionals seeking to specialize in Microsoft 365 administration and security.

Topic Breakdown

5 domains covering 369 questions

DomainQuestionsWeight
Manage Security And Threats By Using Microsoft Defender Xdr12434%
Implement And Manage Microsoft Entra Identity And Access10930%
Manage Compliance By Using Microsoft Purview7220%
Deploy And Manage A Microsoft 365 Tenant5715%
Implement And Manage Identity And Access72%

Study Plans

Choose a study plan that matches your schedule and experience level

30 Days

Intensive Sprint

Week 1-2

  • Master fundamentals: Manage Security And Threats By Using Microsoft Defender Xdr
  • Read Microsoft official documentation
  • Complete 13 questions daily

Week 3

  • Deep dive: Implement And Manage Microsoft Entra Identity And Access
  • Review weak areas from results
  • Take 2 full-length exams

Week 4

  • Review all flagged questions
  • Timed exams to build stamina
  • Final revision of key concepts

60 Days

Balanced Approach

Week 1-2

  • Survey all exam domains
  • Set up study environment
  • Begin with foundational topics

Week 3-4

  • Focus: Manage Security And Threats By Using Microsoft Defender Xdr
  • Focus: Implement And Manage Microsoft Entra Identity And Access
  • 7 questions daily

Week 5-6

  • Focus: Manage Compliance By Using Microsoft Purview
  • Hands-on labs if applicable
  • Review explanations for wrong answers

Week 7-8

  • Complete all 369 questions
  • Identify and eliminate weak areas
  • Take 3 full-length timed tests

90 Days

Comprehensive Study

Month 1

  • Learn all exam domains at a comfortable pace
  • Build strong foundational knowledge
  • 5 questions daily

Month 2

  • Deep dive into each domain
  • Hands-on practice and labs
  • Take weekly timed exams

Month 3

  • Work through all 369 questions
  • Identify and eliminate weak areas
  • Take 3 full-length timed exams

MS-102-Specific Tips

  • Prioritize Microsoft Entra ID (Azure AD) deeply—it's the foundation for the exam's identity and access domains; practice conditional access policies, MFA, and hybrid identity scenarios thoroughly
  • Focus hands-on labs on Microsoft Defender XDR components (Defender for Endpoint, Office 365, Cloud Apps)—the exam tests applied security knowledge, not just theory
  • Master Data Loss Prevention (DLP) and Microsoft Purview compliance workflows as practical exercises; these domains are compliance-heavy and scenario-based
  • Build a test Microsoft 365 tenant (use trial or developer tenant) and configure real policies—Azure AD Connect, tenant settings, and security policies are best learned by doing
  • Study the interaction between identity, security, and compliance; MS-102 tests how these components work together, not siloed knowledge
  • Review the exam's tenant deployment domain thoroughly (often overlooked)—understand provisioning, licensing, and initial security baselines
  • Practice DLP and Azure AD Connect troubleshooting scenarios; these are common exam topics with real-world depth

Relevant Career Roles

Microsoft 365 AdministratorCloud System AdministratorIdentity and Access AdministratorMicrosoft 365 Security AdministratorEnterprise Administrator

Sample Questions

Try 5 free questions from the MS-102 question bank

Q1Deploy and manage a Microsoft 365 tenant

Case Study 1 - Fabrikam, Inc Overview Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide. Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States. Existing Environment Active Directory Environment The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top- level organizational unit (OU) that contains several child OUs for user accounts and computer accounts. All users authenticate to on-premises applications by signing in to their device by using a UPN format of [email protected]. Fabrikam does NOT plan to implement identity federation. Network Infrastructure Each office has a high-speed connection to the Internet. Each office contains two domain controllers. All domain controllers are configured as DNS servers. The public zone for fabrikam.com is managed by an external DNS server. All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed. All shared company documents are stored on a Microsoft SharePoint Server farm. Requirements Planned Changes Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription. Fabrikam plans to implement two pilot projects: Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365. Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users. Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses. Technical Requirements Fabrikam identifies the following technical requirements: - All users must be able to exchange email messages successfully during Project1 by using their current email address. - Users must be able to authenticate to cloud services if Active Directory becomes unavailable. - A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal. - Microsoft 365 Apps for enterprise applications must be installed from a network share only. - Disruptions to email access must be minimized. Application Requirements Fabrikam identifies the following application requirements: - An on-premises web application named App1 must allow users to complete their expense reports online. - App1 must be available to users from the My Apps portal. - The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized. Security Requirements Fabrikam identifies the following security requirements: - After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN. - The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically. - After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically. - The principle of least privilege must be used. You are evaluating the required processes for Project1. You need to recommend which DNS record must be created while adding a domain name for the project. Which DNS record should you recommend?

Q2Deploy and manage a Microsoft 365 tenant

Case Study 1 - Fabrikam, Inc Overview Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide. Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States. Existing Environment Active Directory Environment The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top- level organizational unit (OU) that contains several child OUs for user accounts and computer accounts. All users authenticate to on-premises applications by signing in to their device by using a UPN format of [email protected]. Fabrikam does NOT plan to implement identity federation. Network Infrastructure Each office has a high-speed connection to the Internet. Each office contains two domain controllers. All domain controllers are configured as DNS servers. The public zone for fabrikam.com is managed by an external DNS server. All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed. All shared company documents are stored on a Microsoft SharePoint Server farm. Requirements Planned Changes Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription. Fabrikam plans to implement two pilot projects: Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365. Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users. Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses. Technical Requirements Fabrikam identifies the following technical requirements: - All users must be able to exchange email messages successfully during Project1 by using their current email address. - Users must be able to authenticate to cloud services if Active Directory becomes unavailable. - A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal. - Microsoft 365 Apps for enterprise applications must be installed from a network share only. - Disruptions to email access must be minimized. Application Requirements Fabrikam identifies the following application requirements: - An on-premises web application named App1 must allow users to complete their expense reports online. - App1 must be available to users from the My Apps portal. - The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized. Security Requirements Fabrikam identifies the following security requirements: - After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN. - The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically. - After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically. - The principle of least privilege must be used. Question You are evaluating the required processes for Project1. You need to recommend which DNS record must be created while adding a domain name to the tenant for the project. Which DNS record should you recommend?

Q3Manage compliance by using Microsoft Purview

You have a Microsoft 365 subscription that contains an Azure AD tenant named contoso.com. The tenant contains the users shown in the following table. You create and assign a data loss prevention (DLP) policy named Policy1. Policy1 is configured to prevent documents that contain Personally Identifiable Information (PII) from being emailed to users outside your organization. To which users can User1 send documents that contain PII?

Q4Implement and manage Microsoft Entra identity and access

Your company has three main offices and one branch office. The branch office is used for research. The company plans to implement a Microsoft 365 tenant and to deploy multi-factor authentication. You need to recommend a Microsoft 365 solution to ensure that multi-factor authentication is enforced only for users in the branch office. What should you include in the recommendation?

Q5Implement and manage Microsoft Entra identity and access

You have a Microsoft 365 E5 subscription. You plan to use Microsoft Entra ID Protection. You need to ensure that account passwords must be changed if account credentials are leaked. What should you configure?

Browse all 369 MS-102 questionsUnlock all 369 questions

MS-102 FAQ

Ready to pass MS-102?

Join thousands of professionals who passed their certification exam with NerdExam.

Get MS-102 Exam Questions