DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft MS-102 Practice Questions & Answers 2026 Part1 | Microsoft 365 Administrator

Are you preparing for the Microsoft MS-102 certification exam? SPOTO offers the Microsoft MS-102 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
OverviewFabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide.Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States.Existing EnvironmentActive Directory EnvironmentThe network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts.All users authenticate to on-premises applications by signing in to their device by using a UPN format of[email protected].Fabrikam does NOT plan to implement identity federation.Network InfrastructureEach office has a high-speed connection to the Internet.Each office contains two domain controllers. All domain controllers are configured as DNS servers.The public zone for fabrikam.com is managed by an external DNS server.All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed.All shared company documents are stored on a Microsoft SharePoint Server farm.RequirementsPlanned ChangesFabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription.Fabrikam plans to implement two pilot projects:Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365.Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users.Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses.Technical RequirementsFabrikam identifies the following technical requirements:All users must be able to exchange email messages successfully during Project1 by using their current email address.Users must be able to authenticate to cloud services if Active Directory becomes unavailable.A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal.Microsoft 365 Apps for enterprise applications must be installed from a network share only.Disruptions to email access must be minimized.Application RequirementsFabrikam identifies the following application requirements:An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal.The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized.Security RequirementsFabrikam identifies the following security requirements:After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN.The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically.After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically.The principle of least privilege must be used.You are evaluating the required processes for Project1.You need to recommend which DNS record must be created while adding a domain name for the project.Which DNS record should you recommend?
A. host (A)
B. host information (HINFO)
C. text (TXT)
D. pointer (PTR)
View answer
Correct Answer: C
Question #2
You have a Microsoft 365 E5 subscription. You plan to ingest syslog data from a supported firewall device to Microsoft Defender for Cloud Apps. You need to configure automatic log upload. Which two components should you configure for the log collector? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
A. Aa connection string
B. Bthe receiver type
C. Cthe data source
D. Dthe username and password
E. Ethe host IP address or FQDN
View answer
Correct Answer: CE
Question #3
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft 365 E5 subscription.You create an account for a new security administrator named SecAdmin1.You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive.Solution: From the Microsoft 365 admin center, you assign SecAdmin1 the Exchange Administrator role. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #4
You need to protect the U.S. PII data to meet the technical requirements.What should you create?
A. a data loss prevention (DLP) policy that contains a domain exception
B. a Security & Compliance retention policy that detects content containing sensitive data
C. a Security & Compliance alert policy that contains an activity
D. a data loss prevention (DLP) policy that contains a user override
View answer
Correct Answer: A
Question #5
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint. All the devices in your organization are onboarded to Microsoft Defender for Endpoint. You need to ensure that an alert is generated if malicious activity was detected on a device during the last 24 hours. What should you do?
A. From the Microsoft Purview compliance portal, create a data loss prevention (DLP) policy
B. From Alerts queue, create a suppression rule and assign an alert
C. From Advanced hunting, create a query and a detection rule
D. From the Microsoft Purview compliance portal, create an audit log search
View answer
Correct Answer: C
Question #6
You have a Microsoft 365 E5 tenant that contains the devices shown in the following table.You add custom apps to the private store in Microsoft Store Business.You plan to create a policy to show only the private store in Microsoft Store for Business.To which devices can the policy be applied?
A. evice2, Device3, and Device5 only
B. evice2 and Device4 only
C. evice2 only
D. evice1 and Device3 only
E. evice1, Device2, Device3, Device4, and Device5
View answer
Correct Answer: B
Question #7
You have a Microsoft 365 subscription that contains the users shown in the following table.You plan to use Microsoft 365 Backup.Which users can enable Microsoft 365 Backup?
A. Admin1 only
B. Admin3 only
C. Admin1 and Admin3 only
D. Admin1, Admin2 and Admin3 only
E. Admin1, Admin2, Admin3, and Admin4
View answer
Correct Answer: C
Question #8
You are evaluating the required processes for Project1.You need to recommend which DNS record must be created while adding a domain name for the project. Which DNS record should you recommend?
A. mail exchanger (MX)
B. alias (CNAME)
C. host information (HINFO)
D. host (AAAA)
View answer
Correct Answer: A
Question #9
You have a Microsoft 365 E5 subscription. You need to create a mail-enabled contact. Which portal should you use?
A. the Microsoft Defender portal
B. the SharePoint admin center
C. the Microsoft Purview portal
D. the Exchange admin center
View answer
Correct Answer: D
Question #10
Overview -Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide.Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States.Existing Environment -Active Directory Environment -The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts.All users authenticate to on-premises applications by signing in to their device by using a UPN format of[email protected].Fabrikam does NOT plan to implement identity federation.Network Infrastructure -Each office has a high-speed connection to the Internet.Each office contains two domain controllers. All domain controllers are configured as DNS servers.The public zone for fabrikam.com is managed by an external DNS server.All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed.All shared company documents are stored on a Microsoft SharePoint Server farm.Requirements -Planned Changes -Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription.Fabrikam plans to implement two pilot projects:Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365.Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users.Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses.Technical Requirements -Fabrikam identifies the following technical requirements:All users must be able to exchange email messages successfully during Project1 by using their current email address.Users must be able to authenticate to cloud services if Active Directory becomes unavailable.A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal.Microsoft 365 Apps for enterprise applications must be installed from a network share only.Disruptions to email access must be minimized.Application Requirements -Fabrikam identifies the following application requirements:An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal.The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized.Security Requirements -Fabrikam identifies the following security requirements:After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN.The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically.After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically.The principle of least privilege must be used.Which role should you assign to User1?
A. ygiene Management
B. ecurity Reader
C. ecurity Administrator
D. ecords Management
View answer
Correct Answer: B
Question #11
You have a Microsoft 365 subscription. You add a domain named contoso.com.When you attempt to verify the domain, you are prompted to send a verification email to admin@contoso.com. You need to change the email address used to verify the domain.What should you do?
A. Add a TXT record to the DNS zone of the domain
B. From the domain registrar, modify the contact information of the domain
C. From the Microsoft 365 admin center, change the global administrator of the Microsoft 365 subscription
D. Modify the NS records for the domain
View answer
Correct Answer: B
Question #12
You purchase a new computer that has Windows 10, version 2004 preinstalled.You need to ensure that the computer is up-to-date. The solution must minimize the number of updates installed.What should you do on the computer?
A. Install all the feature updates released since version 2004 and all the quality updates released since version 2004 only
B. install the West feature update and the latest quality update only
C. install all the feature updates released since version 2004 and the latest quality update only
D. install the latest feature update and all the quality updates released since version 2004
View answer
Correct Answer: B
Question #13
OverviewFabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide.Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States.Existing EnvironmentActive Directory EnvironmentThe network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts.All users authenticate to on-premises applications by signing in to their device by using a UPN format of[email protected].Fabrikam does NOT plan to implement identity federation.Network InfrastructureEach office has a high-speed connection to the Internet.Each office contains two domain controllers. All domain controllers are configured as DNS servers.The public zone for fabrikam.com is managed by an external DNS server.All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed.All shared company documents are stored on a Microsoft SharePoint Server farm.RequirementsPlanned ChangesFabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription.Fabrikam plans to implement two pilot projects:Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365.Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users.Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses.Technical RequirementsFabrikam identifies the following technical requirements:All users must be able to exchange email messages successfully during Project1 by using their current email address.Users must be able to authenticate to cloud services if Active Directory becomes unavailable.A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal.Microsoft 365 Apps for enterprise applications must be installed from a network share only.Disruptions to email access must be minimized.Application RequirementsFabrikam identifies the following application requirements:An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal.The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized.Security RequirementsFabrikam identifies the following security requirements:After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN.The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically.After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically.The principle of least privilege must be used.You need to ensure that all the sales department users can authenticate successfully during Project1 and Project2.Which authentication strategy should you implement for the pilot projects?
A. pass-through authentication
B. pass-through authentication and seamless SSO
C. password hash synchronization and seamless SSO
D. password hash synchronization
View answer
Correct Answer: C
Question #14
Your on-premises network contains an Active Directory domain.You have a Microsoft 365 subscription.You need to sync the domain with the subscription. The solution must meet the following requirements:On-premises Active Directory password complexity policies must be enforced.Users must be able to use self-service password reset (SSPR) in Azure AD.What should you use?
A. assword hash synchronization
B. zure AD Identity Protection
C. zure AD Seamless Single Sign-On (Azure AD Seamless SSO)
D. ass-through authentication
View answer
Correct Answer: D
Question #15
You have a Microsoft 365 E5 subscription. The subscription contains users that have the following types of devices: * Windows 10 * Android * iOS On which devices can you configure the Endpoint DLP policies?
A. AWindows 10 only
B. BWindows 10 and Android only
C. CWindows 10 and macO Sonly
D. DWindows 10, Android, and iOS
View answer
Correct Answer: A
Question #16
You have a Microsoft 365 subscription.You need to add additional domains with the onmicrosoft.com suffix to the subscription. The additional domains must be assignable as email addresses for users.What is the maximum number of onmicrosoft.com domains the subscription can contain?
A. 1
B. 2
C. 5
D. 10
View answer
Correct Answer: A
Question #17
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 E5 subscription.You integrate Microsoft Defender for Endpoint with Microsoft Intune.You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune.Solution: You configure a device configuration profile. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #18
You have a Microsoft 365 subscription that uses a Microsoft Entra tenant named contoso.com. The tenant contains the users shown in the following table.You add another user named User5 to the User Administrator role. You need to identify which two management tasks User5 can perform.Which two tasks should you identify? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
A. Delete User2 and User4 only
B. Reset the password of User4 only
C. Reset the password of any Microsoft Entra user
D. Delete User1, User2, and User4 only
E. Reset the password of User2 and User4 only
View answer
Correct Answer: AE
Question #19
Your network contains an on-premises Active Directory domain named contoso.local. The domain contains five domain controllers.Your company purchases Microsoft 365 and creates an Azure AD tenant named contoso.onmicrosoft.com.You plan to install Azure AD Connect on a member server and implement pass-through authentication.You need to prepare the environment for the planned implementation of pass-through authentication.Which three actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. rom a domain controller, install an Authentication Agent
B. rom the Microsoft Entra admin center, configure an authentication method
C. rom Active Directory Domains and Trusts, add a UPN suffix
D. odify the email address attribute for each user account
E. rom the Microsoft Entra admin center, add a custom domain name
F. odify the User logon name for each user account
View answer
Correct Answer: ABE
Question #20
You have a Microsoft 365 E5 subscription that contains the following user:Name: User1UPN:[email protected]Email address:[email protected]MFA enrollment status: DisabledWhen User1 attempts to sign in to Outlook on the web by using the[email protected]email address, the user cannot sign in.You need to ensure that User1 can sign in to Outlook on the web by using[email protected].What should you do?
A. dd an alternate email address for User1
B. eset the password of User1
C. ssign an MFA registration policy to User1
D. odify the UPN of User1
View answer
Correct Answer: D
Question #21
You have a Microsoft 365 E5 subscription that contains a user named User1. You need to ensure that User1 can send a maximum of 50 email messages per day. What should you configure in the Microsoft 365 Defender portal?
A. anti-spam policy
B. anti-phishing policy
C. advanced delivery rule
D. Tenant Allow/Block List rule
View answer
Correct Answer: A
Question #22
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft 365 E5 subscription.You create an account for a new security administrator named SecAdmin1.You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive.Solution: From the Microsoft 365 admin center, you assign SecAdmin1 the SharePoint Administrator role. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #23
You are evaluating the required processes for Project1.You need to recommend which DNS record must be created while adding a domain name for the project. Which DNS record should you recommend?
A. host (A)
B. alias (CNAME)
C. text (TXT)
D. host (AAAA)
View answer
Correct Answer: C
Question #24
You have a Microsoft 365 E5 subscription. You need to set the default privacy setting of a Microsoft SharePoint Online site to Private. What should you use?
A. a data loss prevention (DLP) policy
B. a retention policy
C. an information barrier (IB) policy
D. a sensitivity label
View answer
Correct Answer: D
Question #25
You have a Microsoft 365 subscription that contains a user named User1. You need to ensure that User1 can search the Microsoft 365 audit logs from the Security & Compliance admin center. Which role should you assign to User1? https://docs.microsoft.com/en-us/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance?view=o365-worldwide
A. View-Only Audit Logs in the Security & Compliance admin center
B. View-Only Audit Logs in the Exchange admin center
C. Security reader in the Microsoft Entra ID admin center
D. Security Reader in the Security & Compliance admin center
View answer
Correct Answer: B
Question #26
You have a Microsoft 365 E5 tenant.You need to ensure that when a document containing a credit card number is added to the tenant, the document is encrypted.Which policy should you use?
A. a retention policy
B. a retention label policy
C. an auto-labeling policy
D. an insider risk policy
View answer
Correct Answer: C
Question #27
You need to configure Microsoft Entra Connect Sync to support the planned changes for the Montreal Users and Seattle Users OUs.What should you do?
A. From PowerShell, run the Add-ADSyncConnectorAttributeInclusion cmdlet
B. From the Microsoft Entra Connect wizard, select Manage federation
C. From the Microsoft Entra Connect wizard, select Customize synchronization options
D. From PowerShell, run the Start-ADSyncSyncCycle cmdlet
View answer
Correct Answer: C
Question #28
You have a Microsoft 365 E5 subscription that contains a user named Admin1. You need to ensure that Admin1 can turn on role-based access control (RBAC) in Microsoft Defender for Endpoint. The solution must follow the principle of least privilege. Which role should you assign to Admin1?
A. Global Administrator
B. Privileged Role Administrator
C. Security Administrator
D. Security Operator
View answer
Correct Answer: C
Question #29
You have a Microsoft 365 tenant that contains the groups shown in the following table. You plan to create a new Windows 10 Security Baseline profile. To which groups can you assign to the profile? https://docs.microsoft.com/en-us/mem/intune/protect/security-baselines-configure#create-the-profile https://docs.microsoft.com/en-us/microsoft-365/admin/create-groups/compare-groups?view=o365-worldwide
A. Group3 only
B. Group1 and Group3 only
C. Group2 and Group3 only
D. Group1
View answer
Correct Answer: A
Question #30
You are evaluating the required processes for Project1.You need to recommend which DNS record must be created while adding a domain name for the project. Which DNS record should you recommend?
A. host (A)
B. host information (HINFO)
C. text (TXT)
D. pointer (PTR)
View answer
Correct Answer: C
Question #31
You have a Microsoft 365 subscription.You view the Service health Overview as shown in the following exhibit.You need to ensure that a user named User1 can view the advisories to investigate service health issues.Which role should you assign to User1?
A. Message Center Reader
B. Reports Reader
C. Service Support Administrator
D. Compliance Administrator
View answer
Correct Answer: C
Question #32
You have a Microsoft 365 subscription.You view the Service health Overview as shown in the following exhibit.You need to ensure that a user named User1 can view the advisories to investigate service health issues.Which role should you assign to User1?
A. essage Center Reader
B. eports Reader
C. ervice Support Administrator
D. ompliance Administrator
View answer
Correct Answer: C
Question #33
You need to meet the compliance requirements for the Windows 10 devices. What should you create from the Intune admin center?
A. a device compliance policy
B. a device configuration profile
C. an application policy
D. an app configuration policy
View answer
Correct Answer: C
Question #34
Your company has a Microsoft 365 E5 subscription. Users in the research department work with sensitive data. You need to prevent the research department users from accessing potentially unsafe websites by using hyperlinks embedded in email messages and documents. Users in other departments must not be restricted. What should you do?
A. ACreate a data loss prevention (DLP) policy that has a Content is shared condition
B. BModify the safe links policy Global settings
C. CCreate a data loss prevention (DLP) policy that has a Content contains condition
D. DCreate a new safe links policy
View answer
Correct Answer: D
Question #35
You have a Microsoft 365 subscription.You need to add additional domains with the onmicrosoft.com suffix to the subscription. The additional domains must be assignable as email addresses for users.What is the maximum number of onmicrosoft.com domains the subscription can contain?
A. 1
B. 2
C. 5
D. 10
View answer
Correct Answer: C

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us