Skip to content

MS-203 Practice Questions

Prepare for MS-203 with more than an answer.

214 questions in the full set17 sample questionsUpdated Jan 25, 2026
Exam fee
$165 USD
Time limit
120 minutes
Questions on the exam
40-60
Passing score
700 (scale 100-1000)
Level
Associate
Valid for
2 years
Domains covered on the exam 3
  1. Manage Microsoft Exchange Online settings and resources45%
  2. Plan and manage the mail transport architecture30%
  3. Secure the messaging environment25%
  1. 1

    You are designing a Role Based Access Control (RBAC) model. You need to create a custom management role that allows a helpdesk team to modify user properties but ONLY for users in the 'London' Organizational Unit (OU). You have already created the Role Group. What must you create next to limit where the permissions apply?

    Show answer details

    Correct answer: C

    A Management Scope defines the set of objects (in this case, users in the London OU) that a role assignee is allowed to manage. You would use 'New-ManagementScope -RecipientRoot "contoso.com/London"'.

  2. 2

    True or False: A 'Role Assignment Policy' in Exchange Online allows administrators to define which settings end-users can modify on their own mailboxes (such as contact information or distribution group membership).

    Show answer details

    Correct answer: A

    True. Role Assignment Policies are specifically designed to control end-user permissions (MyBaseOptions, MyContactInformation, etc.) on their own mailboxes.

  3. 3

    You have a requirement to block a specific model of Android device from synchronizing with Exchange Online via ActiveSync. However, you want to allow the Outlook for Android app on that same device model to connect. Which feature should you use?

    Show answer details

    Correct answer: D

    Device Access Rules (ABQ list) can block devices based on device family or model. Since Outlook for Android uses a different connection architecture (Microsoft Cloud architecture) and user agent than native ActiveSync, blocking the native ActiveSync model ID will not necessarily block the Outlook app if configured correctly via Conditional Access or simply because Outlook app identifies differently.

  4. 4

    You need to prevent a specific group of users from using Instant Messaging (IM) features within Outlook on the Web (OWA). You have created a new OWA Mailbox Policy named 'NoIM'. What is the next step?

    Show answer details

    Correct answer: D

    After creating and configuring the OWA Mailbox Policy (Set-OwaMailboxPolicy -InstantMessagingEnabled $false), you must apply it to the specific mailboxes using Set-CASMailbox -OwaMailboxPolicy.

  5. 5

    Your security team requires that all legacy authentication protocols (like POP3, IMAP4, and legacy SMTP) be blocked for all users in Exchange Online to prevent password spray attacks. Which method is the most effective way to enforce this tenant-wide?

    Show answer details

    Correct answer: B

    Security Defaults or Conditional Access policies in Entra ID are the modern and recommended way to block legacy authentication across the entire tenant.

  6. 6

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft Exchange Server 2019 organization that contains 200 mailboxes.You need to add a second email address to each mailbox. The address must have a syntax that uses the first letter of each user's last name, followed by the user's first name, and then @fabrikam.com.Solution: You convert all the mailboxes to shared mailboxes, and then you run theSet-Mailbox cmdlet and specify the -EmailAddressPolicyEnabled $false parameter.Does this meet the goal?

    Show answer details

    Correct answer:

  7. 7

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft Exchange Server 2019 organization that contains 200 mailboxes.You need to add a second email address to each mailbox. The address must have a syntax that uses the first letter of each user's last name, followed by the user's first name, and then @fabrikam.com.Solution: You create an email address policy that uses the %1s%[email protected] email address format.Does this meet the goal?

    Show answer details

    Correct answer: A

  8. 8

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft Exchange Server 2019 organization that contains 200 mailboxes.You need to add a second email address to each mailbox. The address must have a syntax that uses the first letter of each user's last name, followed by the user's first name, and then @fabrikam.com.Solution: You convert all the mailboxes to shared mailboxes, and then you run theSet-Mailbox cmdlet and specify the -EmailAddressPolicyEnabled $true parameter.Does this meet the goal?

    Show answer details

    Correct answer:

Create an account to continue.