Skip to content

M365 Administrator Practice Questions

Prepare for MS-102 with more than an answer.

241 questions in the full set19 sample questionsUpdated Jan 25, 2026

Unlock the full exam and previous versions

  • v1Version 1 241 questions Current
  • MS-100Legacy Microsoft 365 Identity and Services 50 questions Locked
  • MS-101Legacy Microsoft 365 Mobility and Security 47 questions Locked
Exam fee
$165 USD
Time limit
180 minutes
Questions on the exam
40-60
Passing score
700 (scale 0-1000)
Level
Expert
Valid for
1 year
Domains covered on the exam 4
  1. Deploy and manage a Microsoft 365 tenant27.5%
  2. Implement and manage Microsoft Entra identity and access27.5%
  3. Manage security and threats by using Microsoft Defender XDR32.5%
  4. Manage compliance by using Microsoft Purview12.5%
  1. 1

    A Microsoft 365 administrator needs to create a custom sensitive information type (SIT) to detect employee ID numbers that follow a specific format: a fixed two-letter prefix RG followed by exactly six digits (e.g., RG123456). Which method should be used to define this custom SIT?

    Show answer details

    Correct answer: B

    A regular expression (regex) is the ideal method for defining patterns. A regex like RG\d{6} can precisely match the specified format: the literal characters RG followed by exactly six digits (\d{6}). This is efficient and scalable for detecting any ID that fits the pattern.

  2. 2

    The PowerShell cmdlet to create a new administrative unit in Microsoft Entra ID is New-AzureADAdministrativeUnit. To add a user to this new administrative unit, you must use the cmdlet ____ -ObjectId -RefObjectId .

    Show answer details

    Correct answer: D

    The correct PowerShell cmdlet to add a member (like a user or group) to an existing administrative unit is Add-AzureADAdministrativeUnitMember. It requires the ObjectID of the administrative unit and the ObjectID of the member being added.

  3. 3

    Case Study: Omni Consumer Products (OCP)

    Company Background:
    OCP is a technology corporation with a newly deployed Microsoft 365 E3 tenant. They have approximately 5,000 users synchronized from an on-premises Active Directory. All corporate devices are Windows 11 and hybrid Microsoft Entra joined. OCP has a strict policy that all Microsoft 365 Apps for enterprise must be deployed and updated from a central, on-premises network location to ensure version consistency and to manage network bandwidth.

    Current Situation:
    OCP is preparing for the first major deployment of Microsoft 365 Apps. The IT team has downloaded the installation files using the Office Deployment Tool (ODT) and placed them on a network share accessible to all users. They have created a configuration.xml file for the installation. However, they are unsure how to manage future updates to ensure they also come from the on-premises network share and not directly from the Microsoft CDN.

    Requirements:

    1. Initial installation of Microsoft 365 Apps must be from the \\server\share\M365Apps location.
    2. All subsequent updates (feature and security) must also be sourced from the same network share.
    3. Updates should be applied automatically without user intervention.
    4. The solution must be configured within the configuration.xml file used by the ODT.

    Problem:
    Which XML configuration element and attribute must be included in the configuration.xml file to ensure that updates are sourced from the specified on-premises network share?

    Show answer details

    Correct answer: C

    The element controls how Microsoft 365 Apps are updated after installation. To specify an on-premises location as the source for updates, you must set the UpdatePath attribute to the network share path. The SourcePath attribute in the element is only used for the initial installation. Setting UpdatePath ensures that clients will check that specific location for new updates instead of the default Microsoft CDN.

  4. 4

    A user reports being unable to sign in. A Microsoft 365 administrator reviews the Microsoft Entra sign-in logs and finds the entry shown below:

    ┌──────────────────┬───────────────────────────────────────┐
    │ Field │ Value │
    ├──────────────────┼───────────────────────────────────────┤
    │ User │ [email protected] │
    │ Application │ Office 365 SharePoint Online │
    │ Status │ Failure │
    │ Failure reason │ Conditional Access policy │
    │ Conditional │ Block access from untrusted locations │
    │ Access Policy │ │
    │ Location │ France (IP: 1.2.3.4) │
    │ Device │ Not Compliant │
    └──────────────────┴───────────────────────────────────────┘
    

    Based on this log, what is the most likely cause of the sign-in failure?

    Show answer details

    Correct answer: C

    The sign-in log explicitly states the failure reason is a 'Conditional Access policy' and names the policy as 'Block access from untrusted locations'. It also shows the user's location as France. This is direct evidence that the sign-in was blocked because it originated from a location defined as untrusted in the specified policy. While the device is also not compliant, the explicit failure reason points to the location policy.

  5. 5

    A user who is enabled for Self-Service Password Reset (SSPR) reports that they are unable to reset their password. The user is synchronized from an on-premises Active Directory via Microsoft Entra Connect Sync. An administrator reviews the Microsoft Entra audit logs and finds an SSPR failure event with the error code 'PasswordWritebackNotEnabled'. Which action will resolve this issue?

    graph TD A[User attempts SSPR] --> B{Is Password Writeback Enabled?}; B -->|Yes| C[Password reset in Entra ID]; C --> D[Password written back to on-premises AD]; D --> E[Success]; B -->|No| F[Failure: 'PasswordWritebackNotEnabled'];

    Show answer details

    Correct answer: B

    The error code 'PasswordWritebackNotEnabled' directly indicates the root cause. For synchronized users to reset their passwords via SSPR and have it update their on-premises Active Directory password, the Password writeback feature must be explicitly enabled in the Microsoft Entra Connect Sync configuration. This requires re-running the wizard and checking the corresponding option under 'Customize synchronization options'. The other options relate to different aspects of SSPR or MFA, but do not address the specific error.

  6. 6

    A financial services firm is deploying Microsoft 365 E5 and needs to secure access to an on-premises legacy application that uses header-based authentication. The firm wants to leverage Microsoft Entra ID for modern authentication (MFA, Conditional Access) and provide single sign-on (SSO) for users. The on-premises network is connected to Azure via a site-to-site VPN. Which Microsoft Entra service should be deployed to meet these requirements?

    Show answer details

    Correct answer: C

    Microsoft Entra application proxy is the correct service for publishing on-premises web applications externally and integrating them with Microsoft Entra ID. It can translate modern authentication from Entra ID into legacy authentication methods, including header-based authentication, required by the on-premises app. This allows the firm to enforce Conditional Access policies and MFA while providing SSO.

  7. 7

    A global logistics company uses Microsoft 365 and has offices in regions with strict data residency requirements. They have deployed Microsoft Entra Cloud Sync to synchronize identities from multiple disconnected on-premises Active Directory forests. An administrator needs to prevent the synchronization of users from a specific organizational unit (OU) in their German forest that contains temporary service accounts. How can this be achieved with the least administrative effort using Microsoft Entra Cloud Sync?

    Show answer details

    Correct answer: D

    Microsoft Entra Cloud Sync is managed primarily from the cloud. To filter objects based on OU, the administrator should edit the specific Cloud Sync configuration profile associated with the German forest directly within the Microsoft Entra admin center. This interface allows for defining the scope of synchronization by selecting or deselecting specific OUs.

  8. 8

    A healthcare organization is using Microsoft Defender for Endpoint P2. To minimize the attack surface, they want to prevent unsigned or untrusted processes from running from USB removable drives on all clinical workstations. Which Microsoft Defender for Endpoint feature should be configured to enforce this policy?

    Show answer details

    Correct answer: C

    Attack Surface Reduction (ASR) rules are designed to target specific software behaviors that are often abused by malware. The rule 'Block untrusted and unsigned processes that run from USB' directly addresses the organization's requirement. While Device Control can block USBs entirely, ASR provides more granular control over the behavior of processes originating from them.

  9. 9

    True or False: When configuring a Microsoft 365 retention policy for a SharePoint site, applying the policy at the site level prevents individual users from deleting items within a document library if the policy has a retention period.

    Show answer details

    Correct answer: B

    This statement is false. A retention policy does not prevent users from deleting items. Instead, when a user deletes an item from a location subject to a retention policy, the item is moved to the Preservation Hold library. It is preserved there for the duration of the retention period, but from the user's perspective, the item is deleted.

Create an account to continue.