Microsoft MS-102 Practice Exam Questions & Answers

5 Free Questions · Last reviewed: September 12, 2026 · Prepared & Reviewed by the ValidExamDumps Editorial Team

Exam Facts

Microsoft MS-102 Exam Details

Key details for this exam, checked against the published exam outline

570 Practice Questions (Our Bank)
120 minutes Exam Duration
700 out of 1000 Passing Score
Exam Code
MS-102
Full Name
Microsoft 365 Administrator
Issuing Body
Microsoft
Question Format (Our Bank)
Multiple Choice, Hotspot, Drag & Drop, Order List, Case Studies
Delivery
Pearson VUE or PSI at a testing center or online proctored
Eligibility
Functional experience with all Microsoft 365 workloads and Microsoft Entra ID. must have a qualifying Microsoft 365 Certified: Associate level certification such as Endpoint Administrator Associate, Messaging Administrator Associate, Teams Administrator A
Validity
Does not expire, but certification validity is 1 year from date earned
Practice Questions

Free MS-102 Practice Questions

Each question shows the correct answer and an explanation of why it is right

VA
ValidExamDumps Editorial Team Every question and its answer is checked by our MS-102 exam preparation team, who also write the explanation shown with each one. How we research and review these pages

You have a Microsoft 365 E5 subscription that has Microsoft Defender for Endpoint integrated with Microsoft Endpoint Manager.

Devices are onboarded by using Microsoft Defender for Endpoint.

You plan to block devices based on the results of the machine risk score calculated by Microsoft Defender for Endpoint.

What should you create first?

Correct Answer: B
Explanation

https://docs.microsoft.com/en-us/mem/intune/protect/advanced-threat-protection-configure

You have an Microsoft Entra tenant that contains the users shown in the following table

You need to compare the permissions of each role. The solution must minimize administrative effort.

Which portal should you use?

Correct Answer: A

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goats. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain.

You deploy a Microsoft Entra tenant.

Another administrator configures the domain to synchronize to the Microsoft Entra tenant.

You discover that 10 user accounts in an organizational unit (OU) are NOT synchronized to the Microsoft Entra tenant. All the other user accounts synchronized successfully.

You review Microsoft Entra Connect Health and discover that all the user account synchronizations completed successfully.

You need to ensure that the 10 user accounts are synchronized to the Microsoft Entra tenant.

Solution: From Microsoft Entra Connect, you modify the filtering settings.

Does this meet the goal?

Correct Answer: B
Explanation Shared mailboxes in Microsoft 365 can only have user accounts and mail-enabled security groups added as members. User1 is a standard user account so it works. Group2 is a mail-enabled security group so it works. Guest users cannot be added directly to shared mailboxes. Distribution groups are not mail-enabled security groups so they cannot be added. Only the combination of User1 and Group2 meets the requirements.

You have a Microsoft 365 E5 subscription.

You plan to implement Microsoft Purview policies to meet the following requirements:

Identify documents that are stored in Microsoft Teams and SharePoint that contain Personally Identifiable Information (PII).

Report on shared documents that contain PII.

What should you create?

Correct Answer: A
Explanation

Demonstrate data protection

Protection of personal information in Microsoft 365 includes using data loss prevention (DLP) capabilities. With DLP policies, you can automatically protect sensitive information across Microsoft 365.

There are multiple ways you can apply the protection. Educating and raising awareness to where EU resident data is stored in your environment and how your employees are permitted to handle it represents one level of information protection using Office 365 DLP.

In this phase, you create a new DLP policy and demonstrate how it gets applied to the IBANs.docx file you stored in SharePoint Online in Phase 2 and when you attempt to send an email containing IBANs.

From the Security & Compliance tab of your browser, click Home.

Click Data loss prevention > Policy.

Click + Create a policy.

In Start with a template or create a custom policy, click Custom > Custom policy > Next.

In Name your policy, provide the following details and then click Next: a. Name: EU Citizen PII Policy b. Description: Protect the personally identifiable information of European citizens

Etc.


https://learn.microsoft.com/en-us/compliance/regulatory/gdpr-discovery-protection-reporting-in-office365-dev-test-environment

: 240

You have a Microsoft 365 E5 tenant that contains the devices shown in the following table.

You plan to implement attack surface reduction (ASR) rules. Which devices will support the ASR rules?

Correct Answer: C
Explanation

https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/enable-attack-surface-reduction?view=o365-worldwide#requirements

Get Full Access

570 questions covering all exam domains, starting from $20

Study Guide

What the Microsoft MS-102 Exam Covers

Exam domains verified against: Official Microsoft MS-102 exam guide, last checked September 2026.

Domain 1: Deploy and manage a Microsoft 365 tenant 15% - 20%

Understand how to configure your Microsoft 365 tenant, including organizational profile, subscription options, and component services. Set up and manage user accounts, licenses, security groups, and administrative roles to establish foundational governance.

Sample questions from this domain above: Q1Q3

Domain 2: Implement and manage Microsoft Entra identity and access 25% - 30%

Plan and execute identity synchronization using Azure Active Directory Connect and Connect Cloud Sync. Implement authentication mechanisms including multifactor authentication and self-service password reset, plus conditional access policies for secure access control.

Sample questions from this domain above: Q4Q5

Domain 3: Manage security and threats by using Microsoft Defender XDR 35% - 40%

Monitor and respond to security alerts and incidents within the Microsoft 365 Defender portal. Deploy and configure Microsoft Defender for Office 365 for email and collaboration protection, Microsoft Defender for Endpoint for device security, and Microsoft Defender for Cloud Apps for cloud application monitoring.

Sample question from this domain above: Q2

Domain 4: Manage compliance by using Microsoft Purview 15% - 20%

Implement information protection through sensitivity labels and encryption. Configure data lifecycle management and retention policies. Deploy and manage data loss prevention (DLP) rules to identify and protect sensitive information across the organization.

FAQ

MS-102 Exam FAQ

Common questions about the exam itself

What experience do I need before taking MS-102?
MS-102 is not an entry-level exam. You need functional experience with all Microsoft 365 workloads and Microsoft Entra ID, plus you must hold at least one qualifying associate-level certification such as Endpoint Administrator Associate, Messaging Administrator Associate, Teams Administrator Associate, or Identity and Access Administrator before earning the Expert credential.
How does MS-102 relate to the Microsoft 365 Administrator Expert certification?
MS-102 is the required capstone exam for the Microsoft 365 Certified: Administrator Expert credential. Passing MS-102 alone does not award the certification - you must also hold one of the prerequisite associate certifications, and both components must be active within a one-year window.
What makes MS-102 harder than other Microsoft 365 exams?
MS-102 consolidates three older exams (MS-100, MS-101, and elements of MS-500) into one broad assessment that expects you to manage multiple security and compliance tools simultaneously. The security and threats domain alone accounts for 35-40% of the exam and requires deep knowledge of Microsoft Defender for Office 365, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud Apps working together.
Is the Microsoft Entra identity domain the hardest part of MS-102?
Many candidates find the security and threats section (35-40% of the exam) more challenging than identity, because it spans multiple Microsoft Defender products and requires understanding how to respond to incidents, not just configure tools. The identity domain (25-30%) is large but more structured and predictable than the incident response aspects of security.
How long should I prepare for MS-102?
Realistic preparation typically takes 2-3 months if you have solid hands-on experience with Microsoft 365 administration already. If you are still building practical experience with the workloads and security tools, allow 3-6 months to gain confidence in all four objective domains.
How does the MS-102 exam day work?
You have a fixed amount of time (typically around 2 hours, though the exact duration varies by region) to answer approximately 60 questions in an online proctored or test-centre environment. The test is closed-book with no access to external resources, and a live proctor monitors you either remotely or in person to ensure integrity.
Can I retake MS-102 if I fail?
Yes, you can retake MS-102, but there is typically a 24-hour waiting period between the first attempt and the second, and a 10-day waiting period before a third attempt. Each retake requires a separate exam fee and registration with the test provider.
How long does the MS-102 certification stay valid?
The MS-102 exam result itself does not expire, but the Microsoft 365 Certified: Administrator Expert certification earned by combining MS-102 with a prerequisite associate certification remains valid for 1 year from the date it is issued. After that you can renew it for free by passing a related exam or completing a renewal assessment.
Which job roles does MS-102 prepare you for?
MS-102 is designed for IT administrators, system engineers, and technology professionals who manage Microsoft 365 tenants across organizations of all sizes. It suits people whose role as a Microsoft 365 administrator requires them to coordinate security, compliance, identity, and tenant management across the entire platform.
Is MS-102 being retired?
Yes, MS-102 will retire on November 30, 2026. If you plan to take this exam, you must complete it before that date. After retirement you will not be able to earn the credential through this exam path, though existing certifications will remain valid.