CertGrid
Microsoft Certification

MS-102: Microsoft 365 Administrator Practice Exam

Measures your ability to deploy and manage Microsoft 365 tenants, implement identity and access, manage security and compliance, and manage Microsoft 365 services.

Start with a free MS-102 practice test, then work through 740 exam-style questions with full answer explanations, and take timed mock exams that score like the real thing.

740
Practice pool
40-60 qs
Real exam (typical)
120 min
Real exam time
Intermediate
Level
700 / 1000
Passing score

CertGrid runs a fixed 50-question timed mock, separate from the real exam format above.

Objective-mapped practice, aligned to current exam objectives · Reviewed Aug 2026 · Independent practice platform.

Note: Microsoft retires MS-102 on 30 November 2026. It remains live and schedulable until then; check the official exam page for the recommended replacement path before booking.

What the MS-102 exam covers

Free MS-102 practice test questions

A sample of 10 questions with answers and explanations. Sign up free to practice all 740.

  1. Question 1Deploy and manage a Microsoft 365 tenant

    You are the Microsoft 365 administrator for Contoso Ltd. A user reports that Outlook on the web is intermittently unavailable. Where should you first check for information about current service issues affecting your tenant?

    • AService health dashboard in the Microsoft 365 admin centerCorrect
    • BMicrosoft Defender portal for threat and malware alerts
    • CMicrosoft Purview compliance portal for data governance
    • DMicrosoft Entra ID sign-in and audit logs for authentication event history
    ✓ Correct answer: A

    The Service health dashboard is the primary resource for monitoring current service incidents and issues affecting your Microsoft 365 tenant. This dashboard displays real-time status information about all Microsoft 365 services, including Outlook on the web, and shows any ongoing incidents, advisories, or maintenance that might explain service interruptions. Administrators can subscribe to notifications for services they want to monitor and track the impact of incidents on their tenant.

    Why the other options are wrong
    • BMicrosoft Defender portal is incorrect because it focuses on security threats and malware detection, not service availability or infrastructure incidents.
    • CMicrosoft Purview compliance portal is incorrect because it addresses compliance and data governance features, not current service health or availability issues.
    • DMicrosoft Entra ID sign-in and audit logs is incorrect because these logs track authentication events for users, not service infrastructure problems or platform-wide outages.
  2. Question 2Deploy and manage a Microsoft 365 tenant

    You are implementing Microsoft FastTrack to assist with your Microsoft 365 deployment. What is the minimum license requirement to qualify for FastTrack assistance?

    • A10 eligible licenses
    • B150 eligible licensesCorrect
    • C50 eligible licenses
    • D500 eligible licenses
    ✓ Correct answer: B

    Microsoft FastTrack provides deployment and adoption guidance at no additional cost to eligible customers, and the program requires a minimum of 150 eligible licenses in a qualifying subscription to receive FastTrack assistance. Below that threshold the benefit is not available, while customers at or above 150 can request remote help with onboarding and migration. The exact eligible plans vary, but the 150-seat minimum is the well-known gate for the service. Administrators planning a deployment confirm they meet this seat count before requesting FastTrack engagement.

    Why the other options are wrong
    • A10 eligible licenses is far below the FastTrack minimum, so customers with this many seats do not qualify for the benefit.
    • C50 eligible licenses still falls short of the documented 150-license threshold required to receive FastTrack assistance.
    • D500 eligible licenses exceeds the requirement and would qualify, but it is not the minimum; the qualifying floor is 150 licenses.
  3. Question 3Implement and manage Microsoft Entra identity and access

    Alpine Ski House has a hybrid identity infrastructure. The IT team needs to ensure that users can reset their passwords from the Microsoft 365 cloud portal and have the new password synchronized back to the on-premises Active Directory. Which feature must be enabled?

    • APassword hash synchronization only
    • BPassword writebackCorrect
    • CDirectory synchronization
    • DAccount writeback
    ✓ Correct answer: B

    Password writeback is the feature that enables bidirectional password synchronization in hybrid environments. When enabled in Microsoft Entra Connect, it allows password resets performed in the cloud (Microsoft 365 portal) to be written back to the on-premises Active Directory, keeping both directories synchronized with the latest password. This is essential for users who perform password resets through the cloud interface.

    Why the other options are wrong
    • APassword hash synchronization only copies initial password hashes from on-premises to the cloud and does not handle cloud-initiated password resets.
    • CDirectory synchronization is a general term referring to user and object synchronization, not password changes.
    • DAccount writeback is not a standard Microsoft Entra feature for password synchronization and does not address this specific requirement.
  4. Question 4Implement and manage Microsoft Entra identity and access

    An organization wants to allow users from a partner company to collaborate in Microsoft Teams without creating guest accounts. The partner company also uses Microsoft 365. What should the administrator configure?

    • AMicrosoft Entra ID cross-tenant access settings for direct B2B collaboration (Teams Connect shared channels)Correct
    • BMerge both organizations into a single consolidated Microsoft 365 tenant to enable collaboration
    • CCreate licensed internal member accounts in your own tenant for every partner company user
    • DShare public Teams meeting join links with all partner company users to allow collaboration
    ✓ Correct answer: A

    Microsoft Entra cross-tenant access settings enable direct collaboration between organizations using Microsoft Entra ID's B2B integration capabilities. Teams Connect shared channels specifically allow users from one organization to participate in channels without being added as guest users. This approach uses the user's native identity in their own tenant rather than creating external guest accounts, providing a more seamless and secure collaboration experience.

    Why the other options are wrong
    • BMerging tenants is a massive migration and is not how cross-organization Teams collaboration is enabled.
    • CInternal accounts consume licenses and grant directory access rather than using B2B collaboration.
    • DPublic meeting links allow anonymous join but do not provide persistent shared-channel collaboration.
  5. Question 5Manage security and threats by using Microsoft Defender XDR

    You are configuring email authentication to prevent spoofing of your organization's domain. You need to implement DKIM signing for outbound emails from Exchange Online. What must you configure?

    • AConfigure an Exchange Online transport rule that stamps DKIM signatures onto outbound mail
    • BInstall a DKIM signing X.509 certificate onto the Exchange Online mail transport servers
    • CPublish CNAME records for DKIM selectors in your domain's DNS and enable DKIM signing in Exchange OnlineCorrect
    • DEnable DKIM signing for the custom domain from within the Microsoft Entra admin center
    ✓ Correct answer: C

    DKIM in Exchange Online uses two CNAME records (selector1 and selector2) in the custom domain's DNS that point to Microsoft-hosted keys, after which you enable DKIM signing for the domain in the Defender/Exchange settings. Microsoft then signs outbound mail with the rotating keys referenced by those selectors, letting recipients verify the message. So the configuration is: publish the selector CNAMEs and turn on signing. This is the documented procedure for outbound DKIM in Microsoft 365.

    Why the other options are wrong
    • AA transport rule cannot generate valid DKIM cryptographic signatures; DKIM is enabled natively in EOP.
    • BExchange Online is a managed service, so admins cannot install certificates on its servers.
    • DDKIM for Exchange Online is configured in the Defender portal, not the Entra admin center.
  6. Question 6Manage compliance by using Microsoft Purview

    In Microsoft Purview, retention labels can be applied automatically to content based on sensitive information types, keywords, or trainable classifiers.

    • AFalse
    • BTrueCorrect
    ✓ Correct answer: B

    This is true. Microsoft Purview supports auto-apply retention label policies that automatically label content based on matching conditions, including sensitive information types (for example credit card or Social Security numbers), keyword or KQL query matches, and trainable classifiers. These auto-labeling policies can target content in Exchange, SharePoint, OneDrive, and Microsoft 365 Groups, applying the correct retention and, where configured, records declaration without user intervention. This ensures consistent lifecycle governance at scale and reduces reliance on end users to label content manually. Because retention labels can be auto-applied using SITs, keywords, and trainable classifiers, the statement is correct. Note that auto-labeling typically requires Microsoft 365 E5/E5 Compliance licensing.

    Why the other options are wrong
    • AFalse is incorrect. The statement is true. This is true. Microsoft Purview supports auto-apply retention label policies that automatically label content based on matching conditions, including sensitive information types (for example credit card or Social Security numbers), keyword or KQL query matches, and trainable classifiers.
  7. Question 7Implement and manage Microsoft Entra identity and access

    When implementing Access practices in Implement and Manage Identity and Access, which approach is recommended?

    • AConfigure each control independently without a common baseline
    • BFollow documented best practices and vendor guidelinesCorrect
    • CAdopt whichever settings a third-party blog recommends most recently
    • DEnable every available access feature to maximize capability
    ✓ Correct answer: B

    Documented best practices and vendor guidelines provide proven approaches for implementing identity and access solutions that meet security requirements and industry compliance standards. These guidelines account for Microsoft's identity platform capabilities, security best practices, and architectural patterns that have been validated across thousands of organizations. Following established guidance ensures consistent, secure implementations.

    Why the other options are wrong
    • AConfiguring controls independently with no shared baseline produces inconsistent, drift-prone settings instead of the validated consistency vendor guidance provides.
    • CChasing the latest blog recommendation adopts unvalidated advice that may be wrong for this environment, unlike tested vendor guidelines.
    • DTurning on every access feature increases the attack surface and complexity rather than applying the measured configuration documented guidance recommends.
  8. Question 8Deploy and manage a Microsoft 365 tenant

    Your security team requires that browser sessions to Microsoft 365 web apps automatically sign users out after one hour of inactivity, and they want this enforced consistently from the admin center for all users rather than per-app. Which configuration achieves this with the LEAST administrative overhead?

    • AEnable 'Idle session timeout' in the Microsoft 365 admin center Org settings (Security & privacy) and set the timeout to 1 hour.Correct
    • BCreate a Conditional Access policy with a sign-in frequency of 1 hour applied to all cloud apps.
    • CConfigure each SharePoint Online and Exchange Online web app individually with a custom session token lifetime.
    • DSet the Microsoft Entra refresh token lifetime to 1 hour using a token lifetime policy.
    ✓ Correct answer: A

    Idle session timeout, configured under Org settings > Security & privacy, signs users out of Microsoft 365 web apps (such as Outlook on the web, SharePoint, OneDrive, and the admin center) after a defined period of inactivity, and is the purpose-built control for exactly this requirement. It is set once at the tenant level and applies broadly, satisfying the 'least overhead' and 'consistent for all users' criteria. Conditional Access sign-in frequency enforces reauthentication on an interval but is not an inactivity (idle) timeout, so it does not match the stated requirement precisely. Per-app session configuration and custom token lifetime policies add complexity and are not the supported, centralized mechanism for idle web-session sign-out.

    Why the other options are wrong
    • BSign-in frequency forces periodic reauthentication regardless of activity; it is not an idle/inactivity timeout, so it does not satisfy the 'after one hour of inactivity' requirement.
    • CPer-app session token configuration is not supported as a simple toggle and would be high-overhead and inconsistent, contradicting the least-overhead goal.
    • DRefresh token lifetime policies are deprecated/limited for this purpose and govern token renewal, not inactivity-based web sign-out; this would not deliver the intended idle behavior.
  9. Question 9Manage security and threats by using Microsoft Defender XDR

    After a phishing wave, malicious emails were delivered to mailboxes before signatures existed. Hours later, Microsoft updated its threat intelligence and the messages are now recognized as malware/phishing. You want the already-delivered messages to be automatically moved out of users' inboxes without administrator action. Which Microsoft 365 capability provides this behavior?

    • AZero-hour auto purge (ZAP) in Exchange Online Protection / Defender for Office 365.Correct
    • BSafe Attachments protection with the dynamic delivery option enabled.
    • CExchange Online mailbox litigation hold with an auto-expiration period.
    • DA scheduled eDiscovery Content Search purge that runs every single hour.
    ✓ Correct answer: A

    ZAP continuously monitors updated spam, phishing, and malware verdicts and acts on messages that were already delivered, moving them to Junk or quarantine depending on the policy and verdict. This addresses exactly the gap where messages slipped through before signatures existed. ZAP requires Exchange Online mailboxes and works for messages still in the mailbox; it is enabled by default in anti-spam and anti-malware policies. Because it is automatic, no admin remediation step is required.

    Why the other options are wrong
    • BDynamic delivery scans attachments at delivery time; it cannot retroactively remove already-delivered mail.
    • CLitigation hold preserves mailbox items for legal cases and does not remove malicious delivered email.
    • DA manual Content Search purge is admin-driven and scheduled, not the automatic post-delivery removal ZAP provides.
  10. Question 10Manage security and threats by using Microsoft Defender XDR

    You want to reduce the risk of ransomware encrypting user documents on Defender for Endpoint-managed devices by preventing untrusted applications from modifying files in protected folders such as Documents and Pictures. Which capability should you enable?

    • AControlled folder accessCorrect
    • BWeb content filtering scoped to the affected device group
    • CDevice control for removable storage and peripherals
    • DLive Response sessions initiated by the security operations team
    ✓ Correct answer: A

    Controlled folder access, part of Defender's exploit/attack surface protections, guards default and custom folders. Only apps on an allow list may write to them; untrusted processes attempting to change files are blocked and logged. It is a targeted anti-ransomware control.

    Why the other options are wrong
    • BWeb content filtering blocks website categories, not local file modification.
    • CDevice control governs removable-media and peripheral access, not folder write protection.
    • DLive Response is an investigation/remediation shell for responders, not a preventive folder control.

Who this MS-102 practice exam is for

This practice set is for anyone preparing for the MS-102: Microsoft 365 Administrator exam at the intermediate level - from first-time candidates building a foundation to experienced Microsoft practitioners doing a final review before test day. If you learn best by working through realistic questions and reading why each answer is right or wrong, it is built for you.

How to use this MS-102 practice exam

  1. Start with the free sample questions above to gauge your current baseline.
  2. Read the full explanation on every question, including why each wrong option is wrong.
  3. Track your weak domains and focus your study where you are losing the most marks.
  4. Once you are scoring consistently well, take a timed, full-length mock exam.
  5. Use your readiness score to decide when you are ready to book the real MS-102 exam.

Related Microsoft resources

MS-102 practice exam FAQ

How many questions are in the MS-102 practice exam on CertGrid?

CertGrid has 740 practice questions for MS-102: Microsoft 365 Administrator, covering 4 exam domains. The real MS-102 exam runs 120 min, typically with 40-60 questions. Microsoft publishes 40-60 questions as a typical range across its exams and states the number varies by exam; it does not publish a count for this one. CertGrid's timed mock is a fixed 50 questions.

What is the passing score for MS-102?

The MS-102 exam passing score is 700 / 1000, and you have about 120 min to complete it. CertGrid scores your practice attempts the same way so you know when you are ready.

Are these official MS-102 exam questions?

No. CertGrid is an independent practice platform. We do not provide real or leaked exam questions. Our questions are original and designed to help you practice the concepts, scenarios, and difficulty style of the MS-102: Microsoft 365 Administrator exam.

Is there a free MS-102 practice test?

Yes. You can take a free MS-102: Microsoft 365 Administrator practice test straight away: a fixed set of 20 practice questions for this exam, retryable as often as you like, with no credit card required. You get readiness scoring and a weak-domain breakdown on those questions. Paid plans unlock the full 740-question bank, timed mock exams and full-bank domain analytics.

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Microsoft. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.