The MS-102 exam validates your ability to manage and administer Microsoft 365 environments at an expert level. This certification, part of the Microsoft 365 Enterprise Administrator Expert path, is designed for IT professionals who deploy, configure, and maintain Microsoft 365 services. This page provides a structured overview of the exam content, question formats, and practical preparation strategies to help you study effectively and build confidence before test day.
Use this topic map to guide your study for Microsoft MS-102 (Microsoft 365 Administrator) within the Microsoft 365 Enterprise Administrator Expert path.
The MS-102 exam measures both foundational knowledge and applied reasoning through a mix of question types. Each format tests your ability to understand concepts and apply them to realistic scenarios.
Questions progress in difficulty and emphasize practical decision-making over memorization, reflecting the actual challenges you will face as a Microsoft 365 administrator.
Efficient preparation involves mapping the four core topics to a structured study schedule, practicing with realistic questions, and simulating exam conditions. Dedicate focused time to each domain while building connections between tenant deployment, identity management, security operations, and compliance workflows.
Explore other Microsoft certifications: view all Microsoft exams.
Strengthen your preparation with up-to-date resources from validexamdumps.com. These materials align to MS-102 and cover practical scenarios with clear explanations.
Visit the exam page to download the PDF, Online Practice Test, or get a bundle discount for both formats: Microsoft 365 Administrator.
Identity and access management (Azure AD) and security threat management (Microsoft Defender XDR) typically represent larger portions of the exam. However, all four domains are tested, so balanced preparation across tenant deployment, identity, security, and compliance is essential for a strong score.
In practice, these domains work together: you deploy a tenant and configure identity (Azure AD), then layer security policies (Defender XDR) and compliance controls (Purview) on top. For example, a data breach response involves investigating alerts in Defender XDR, applying conditional access to limit access, and using Purview to preserve and review relevant data. Understanding these connections helps you answer scenario questions correctly.
Hands-on experience with Microsoft 365 administration is valuable but not required if you study effectively. Prioritize labs for Azure AD user and group management, conditional access policy configuration, Defender XDR alert investigation, and Purview retention policy setup. These core tasks appear frequently in exam scenarios and build confidence in real-world application.
Frequent errors include confusing Azure AD roles with Microsoft 365 admin roles, overlooking the scope of security policies (tenant-wide vs. user-specific), misunderstanding Purview retention behavior, and choosing theoretically correct but operationally impractical solutions. Read scenario questions carefully, consider organizational impact, and review explanations for practice questions to avoid these pitfalls.
In the final week, shift from learning new content to reinforcing weak areas and building decision confidence. Review high-level concept maps for each domain, complete one full-length timed practice test, and spend time on scenario-based questions in your weakest topic. The night before the exam, review key definitions and decision trees rather than attempting new material.
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a computer that runs Windows 10.
You need to verify which version of Windows 10 is installed.
Solution: From the Settings app, you select System, and then you select About to view information about the system.
Does this meet the goal?
https://support.microsoft.com/en-us/windows/which-version-of-windows-operating-system-am-i-running-628bec99-476a-2c13-5296-9dd081cdd808
You have a Microsoft 365 E5 subscription.
You create the users shown in the following table.

You plan to use Microsoft Entra ID Protection.
Which users will be added automatically to the Users at risk detected alerts list?
You have a Microsoft 365 tenant.
You plan to enable BitLocker Disk Encryption (BitLocker) automatically for all Windows 10 devices that enroll in Microsoft Intune.
What should you use?
https://docs.microsoft.com/en-us/mem/intune/protect/encrypt-devices
You have a Microsoft 365 E5 subscription that contains a user named User1.
User1 exceeds the default daily limit of allowed email messages and is on the Restricted entities list.
You need to remove User1 from the Restricted entities list.
What should you use?
Admins can remove user accounts from the Restricted entities page in the Microsoft Defender XDR portal or in Exchange Online PowerShell.
Remove a user from the Restricted entities page in the Microsoft Defender XDR portal
In the Microsoft Defender XDR portal at https://security.microsoft.com, go to Email & collaboration > Review > Restricted entities. Or, to go directly to the Restricted entities page, use https://security.microsoft.com/restrictedentities.
https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/removing-user-from-restricted-users-portal-after-spam
Youi network contains an Active Directory domain.
You have a Microsoft Entra tenant that has Security defaults disabled.
Microsoft Entra Connect Sync is configured for directory synchronization. Password hash synchronization and pass-through authentication are disabled.
You need to enable Microsoft Entra ID Protection to detect leaked credentials.
What should you do first?