CertGrid
Microsoft Certification

MS-102: Microsoft 365 Administrator Practice Exam

Measures your ability to deploy and manage Microsoft 365 tenants, implement identity and access, manage security and compliance, and manage Microsoft 365 services.

Practice 713 exam-style MS-102 questions with full answer explanations, then take timed mock exams that score like the real thing.

713
Practice pool
40-60 qs
Real exam
100 min
Real exam time
Intermediate
Level
70%
Passing score

CertGrid runs a fixed 50-question timed mock, separate from the real exam format above. Microsoft seat time may be longer than exam answering time.

Objective-mapped practice, aligned to current exam objectives · Reviewed Jul 2026 · Independent practice platform.

What the MS-102 exam covers

Free MS-102 sample questions

A sample of 10 questions with answers and explanations. Sign up free to practice all 713.

  1. Question 1Deploy and manage a Microsoft 365 tenant

    You are the Microsoft 365 administrator for Contoso Ltd. A user reports that Outlook on the web is intermittently unavailable. Where should you first check for information about current service issues affecting your tenant?

    • AService health dashboard in the Microsoft 365 admin centerCorrect
    • BMicrosoft Defender portal
    • CMicrosoft Purview compliance portal
    • DMicrosoft Entra ID sign-in logs
    ✓ Correct answer: A

    The Service health dashboard is the primary resource for monitoring current service incidents and issues affecting your Microsoft 365 tenant. This dashboard displays real-time status information about all Microsoft 365 services, including Outlook on the web, and shows any ongoing incidents, advisories, or maintenance that might explain service interruptions. Administrators can subscribe to notifications for services they want to monitor and track the impact of incidents on their tenant.

    Why the other options are wrong
    • BMicrosoft Defender portal is incorrect because it focuses on security threats and malware detection, not service availability or infrastructure incidents.
    • CMicrosoft Purview compliance portal is incorrect because it addresses compliance and data governance features, not current service health or availability issues.
    • DMicrosoft Entra ID sign-in logs is incorrect because these logs track authentication events for users, not service infrastructure problems or platform-wide outages.
  2. Question 2Deploy and manage a Microsoft 365 tenantSelect all that apply

    You need to configure organizational settings in the Microsoft 365 admin center. Which TWO settings can be configured at the organization level? (Choose two.)

    • ASpecific user desktop wallpaper settings
    • BIndividual user mailbox sizes
    • CRelease preferences for feature updates (Targeted release or Standard release)Correct
    • DOrganization profile including name and technical contact informationCorrect
    ✓ Correct answer: C, D

    Org settings in the Microsoft 365 admin center configure tenant-wide properties that apply to the whole organization. Release preferences let you choose Standard release or Targeted release so you control how early the tenant receives new features, and the Organization profile holds the company name, address, and technical/contact information used across the service. Both are organization-level constructs administered centrally rather than per user. They are exactly the kinds of settings exposed under Org settings and Organization profile.

    Why the other options are wrong
    • ASpecific user desktop wallpaper is a client/endpoint setting managed through Intune or Group Policy, not an organization-level Microsoft 365 admin center setting.
    • BIndividual user mailbox sizes are a per-mailbox attribute configured in Exchange Online, not a tenant-wide organization setting in the admin center.
  3. Question 3Deploy and manage a Microsoft 365 tenant

    Adventure Works has users who work across multiple departments. The company wants to restrict administrative scope so that a Helpdesk Administrator can only reset passwords for users in the Marketing department. Which Microsoft Entra ID feature should be used?

    • ACustom security attributes
    • BAdministrative unitsCorrect
    • CEntitlement management
    • DManagement groups
    ✓ Correct answer: B

    Administrative units (AUs) enable administrators to limit the scope of administrative roles to specific subsets of users or departments. A Helpdesk Administrator assigned to an AU containing only Marketing department users will only have administrative permissions (such as password reset) over those specific users. This scoped role assignment prevents the administrator from affecting users outside the AU, implementing the principle of least privilege and enabling delegation of administrative tasks by department without requiring full tenant-wide administrative access. Administrative units are the feature specifically designed for this scenario of department-specific administrative authority.

    Why the other options are wrong
    • ACustom security attributes is incorrect because custom security attributes store organizational metadata on user accounts but do not restrict administrative role scope or grant scoped administrative permissions.
    • CEntitlement management is incorrect because entitlement management governs access to resources and applications through access packages and catalogs, not the scope of administrative role assignments.
    • DManagement groups is incorrect because management groups are an Azure resource organization feature for managing subscriptions and resources, not a Microsoft Entra ID feature for scoping administrative role authority.
  4. Question 4Implement and manage Microsoft Entra identity and access

    An organization wants to allow users to sign in to Microsoft 365 using their on-premises Active Directory credentials without deploying AD FS or Microsoft Entra Connect agents on-premises. The company uses Password Hash Synchronization. What additional feature should the administrator enable?

    • AAzure VPN Gateway
    • BWindows Hello for Business
    • CMicrosoft Entra Application Proxy
    • DMicrosoft Entra Seamless Single Sign-On (Seamless SSO)Correct
    ✓ Correct answer: D

    With Password Hash Synchronization providing cloud authentication, Seamless SSO adds automatic sign-in for users on domain-joined corporate devices: they reach Microsoft 365 without retyping credentials, using Kerberos against on-premises AD. It requires no additional servers in the perimeter (no AD FS) and only a lightweight one-time setup of a computer account, fitting the requirement to use on-premises credentials without deploying federation infrastructure. It complements PHS to deliver a smoother sign-in experience. Administrators enable it in the Entra Connect wizard.

    Why the other options are wrong
    • AAn Azure VPN Gateway provides network connectivity to Azure virtual networks and has nothing to do with single sign-on to Microsoft 365.
    • BWindows Hello for Business provides passwordless device sign-in credentials, but it is not the feature that delivers Seamless SSO for PHS-based authentication.
    • CMicrosoft Entra Application Proxy publishes on-premises web applications for remote access; it does not provide single sign-on for Microsoft 365 with PHS.
  5. Question 5Manage security and threats by using Microsoft Defender XDR

    You need to prevent users from forwarding emails to external recipients using Outlook client rules. Which approach should you use?

    • AConfigure an outbound spam filter policy
    • BDisable Outlook Web App for all users
    • CCreate a DLP policy in Microsoft Purview
    • DCreate a mail flow rule (transport rule) in Exchange OnlineCorrect
    ✓ Correct answer: D

    A mail flow (transport) rule is evaluated by Exchange Online on the server as messages pass through transport, so it enforces policy no matter what client or client-side rule a user creates. You can build a rule that detects messages headed to external recipients (or that match message properties indicating auto-forwarding) and block or redirect them, which stops users from forwarding outbound through Outlook rules. Because enforcement is server-side, users cannot bypass it by reconfiguring their client. This makes a transport rule the correct, targeted control for the requirement.

    Why the other options are wrong
    • AAn outbound spam filter policy governs spam and the auto-forwarding setting for spam protection but is designed to limit abuse and malware, not to selectively block legitimate-looking external forwarding driven by client rules.
    • BDisabling Outlook Web App for all users is an overly broad action that removes web mail access entirely and still would not stop forwarding configured in the desktop Outlook client, so it neither targets nor fully solves the problem.
    • CA DLP policy in Microsoft Purview is built to detect and protect sensitive information leaving the organization, not to block forwarding behavior in general, so it does not directly address Outlook client forwarding rules.
  6. Question 6Manage compliance by using Microsoft Purview

    Adventure Works has both a retention policy set to retain Exchange emails for 5 years and a retention label set to delete emails after 3 years applied to the same content. What happens when these two policies conflict?

    • AThe shortest retention period applies, so content is deleted after 3 years
    • BThe retention label always takes precedence over the policy
    • CRetention wins over deletion, so the content is retained for 5 yearsCorrect
    • DThe retention policy always takes precedence over the label
    ✓ Correct answer: C

    When a retention policy and a retention label conflict, Microsoft 365 applies the principles of retention precedence. Retention always wins over deletion, so if one rule retains and another deletes, the content is preserved. When multiple rules specify different retention durations, the longest period applies, meaning the 5-year retention overrides the 3-year deletion and the email is kept for 5 years.

    Why the other options are wrong
    • AThe shortest retention period applies, so content is deleted after 3 years describes the opposite of how Microsoft 365 resolves conflicts, which prioritizes the longest retention period, not the shortest.
    • BThe retention label always takes precedence over the policy is wrong because conflicts are resolved by the retention-wins and longest-period principles, not by ranking labels above policies.
    • DThe retention policy always takes precedence over the label is wrong because no blanket policy-over-label rule exists; the retention precedence principles decide the outcome.
  7. Question 7Implement and manage Microsoft Entra identity and access

    Microsoft Entra Conditional Access supports the 'What If' tool, which allows administrators to test the impact of policies before enabling them.

    • AFalse
    • BTrueCorrect
    ✓ Correct answer: B

    This statement is true. Microsoft Entra Conditional Access provides a 'What If' tool that simulates how policies would apply to a specified sign-in scenario before you enforce them. You supply parameters such as the user, target app or user action, IP/location, device platform, client app, and sign-in risk, and the tool lists the policies that would apply and the resulting grant or session controls. This lets administrators validate complex policy combinations and avoid unintended lockouts without changing live access. The tool is available in the Conditional Access section of the Microsoft Entra admin center.

    Why the other options are wrong
    • AFalse is incorrect. The statement is true. This statement is true. Microsoft Entra Conditional Access provides a 'What If' tool that simulates how policies would apply to a specified sign-in scenario before you enforce them.
  8. Question 8Manage security and threats by using Microsoft Defender XDR

    Anti-spam policies is a supported feature when implementing solutions for organizations like Litware Inc.

    • TrueTrueCorrect
    • FalseFalse
    ✓ Correct answer: True

    This statement is true. Anti-spam policies are a supported and standard feature, delivered through Exchange Online Protection, that any organization such as Litware Inc can implement. These policies filter inbound (and outbound) mail using spam confidence, bulk-mail thresholds, sender/domain reputation, and phishing and spoofing signals, and let administrators set actions like moving messages to Junk Email, quarantining, or blocking, along with allowed/blocked sender and domain lists. Outbound spam policies also help prevent compromised accounts from sending spam. Managed in the Microsoft Defender portal, anti-spam policies are foundational to reducing unwanted and malicious email.

    Why the other options are wrong
    • FalseFalse is incorrect. The statement is true. This statement is true. Anti-spam policies are a supported and standard feature, delivered through Exchange Online Protection, that any organization such as Litware Inc can implement.
  9. Question 9Deploy and manage a Microsoft 365 tenant

    Contoso uses Microsoft Entra Privileged Identity Management (PIM) to govern the Global Administrator role. The CISO requires that activation of Global Administrator always requires approval, the activation be limited to 4 hours, and that the security team be able to review all eligible Global Administrators every 90 days, removing anyone no longer needing the role. Which combination of PIM capabilities should you configure to meet ALL of these requirements?

    • AConfigure the Global Administrator role setting to require approval to activate with a 4-hour maximum activation duration, and create a PIM access review scoped to eligible assignments of Global Administrator on a recurring 90-day scheduleCorrect
    • BCreate a Conditional Access policy requiring approval for the Global Administrator role and a separate Entra access review of all members of the role on a 4-hour cadence
    • CAssign Global Administrator as a permanent active assignment with a 90-day expiration and enable approval in the role's authentication context
    • DConfigure entitlement management access packages for the Global Administrator role with a 4-hour lifecycle policy and quarterly access recertification
    ✓ Correct answer: A

    PIM role settings define per-role activation behavior, including whether approval is required, the maximum activation duration (which can be set to 4 hours), and whether MFA or justification is required. Eligible assignments mean the user must activate just-in-time rather than holding standing access. PIM access reviews can be scoped specifically to eligible (or active) assignments of a directory role and run on a recurring schedule such as every 90 days, with options to auto-apply results and remove users who are no longer approved. Together these satisfy approval, time-bound activation, and periodic recertification without granting standing access.

    Why the other options are wrong
    • BConditional Access cannot require approval for role activation, and access reviews cannot run on a 4-hour cadence; that interval describes activation duration, not review frequency.
    • CPermanent active assignment defeats just-in-time elevation, and an authentication context does not provide an approval-on-activation workflow.
    • DEntitlement management governs access packages of groups/apps/sites, not direct activation of a built-in directory role like Global Administrator.
  10. Question 10Manage security and threats by using Microsoft Defender XDRSelect all that apply

    A mailbox has been compromised and used to launch an internal phishing campaign. As part of your Microsoft Defender XDR response, which TWO actions directly help contain the compromised identity and remove the delivered malicious mail? (Choose two.)

    • AForce sign-out and require the user to reset their password (disable or suspend the account)Correct
    • BUse Threat Explorer to soft-delete the phishing messages from recipient mailboxesCorrect
    • CRaise the organization's Microsoft Secure Score target percentage so the tenant is measured against a higher posture goal
    • DCreate a Safe Documents policy for Office files
    • EAdd the sender's internal domain to the anti-spam allowed domains list
    ✓ Correct answer: A, B

    Containing a compromised identity involves forcing sign-out, resetting the password, and disabling or confirming the account as compromised so active sessions are revoked. Removing the harm involves using Threat Explorer (or Take action) to soft-delete the delivered phishing messages from recipients' mailboxes. Together these contain the account and clean up the campaign.

    Why the other options are wrong
    • CRaising a Secure Score target is a posture goal; it does nothing to contain the active incident.
    • DSafe Documents scans Office files in Protected View on endpoints; it does not contain a compromised mailbox or remove sent mail.
    • EAllow-listing the internal domain would weaken filtering and could let more of the malicious mail through, the opposite of containment.

Related Microsoft resources

MS-102 practice exam FAQ

How many questions are in the MS-102 practice exam on CertGrid?

CertGrid has 713 practice questions for MS-102: Microsoft 365 Administrator, covering 4 exam domains. The real MS-102 exam is 40-60 qs in 100 min. CertGrid's timed mock is a fixed 50 questions.

What is the passing score for MS-102?

The MS-102 exam passing score is 70%, and you have about 100 min to complete it. CertGrid scores your practice attempts the same way so you know when you are ready.

Are these official MS-102 exam questions?

No. CertGrid is an independent practice platform. We do not provide real or leaked exam questions. Our questions are original and designed to help you practice the concepts, scenarios, and difficulty style of the MS-102: Microsoft 365 Administrator exam.

Can I practice MS-102 for free?

Yes. You can start practicing MS-102: Microsoft 365 Administrator for free with daily practice and sample questions. Paid plans unlock full timed exams, complete explanations, and domain analytics.

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Microsoft. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.