DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft MS-102 Practice Questions & Answers 2026 Part2 | Microsoft 365 Administrator

Are you preparing for the Microsoft MS-102 certification exam? SPOTO offers the Microsoft MS-102 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft 365 E5 subscription.You create an account for a new security administrator named SecAdmin1.You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive.Solution: From the Microsoft Entra admin center, you assign SecAdmin1 the Teams Administrator role. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #2
OverviewFabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide.Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States.Existing EnvironmentActive Directory EnvironmentThe network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts.All users authenticate to on-premises applications by signing in to their device by using a UPN format of[email protected].Fabrikam does NOT plan to implement identity federation.Network InfrastructureEach office has a high-speed connection to the Internet.Each office contains two domain controllers. All domain controllers are configured as DNS servers.The public zone for fabrikam.com is managed by an external DNS server.All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed.All shared company documents are stored on a Microsoft SharePoint Server farm.RequirementsPlanned ChangesFabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription.Fabrikam plans to implement two pilot projects:Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365.Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users.Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses.Technical RequirementsFabrikam identifies the following technical requirements:All users must be able to exchange email messages successfully during Project1 by using their current email address.Users must be able to authenticate to cloud services if Active Directory becomes unavailable.A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal.Microsoft 365 Apps for enterprise applications must be installed from a network share only.Disruptions to email access must be minimized.Application RequirementsFabrikam identifies the following application requirements:An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal.The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized.Security RequirementsFabrikam identifies the following security requirements:After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN.The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically.After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically.The principle of least privilege must be used.Which role should you assign to User1?
A. Hygiene Management
B. Security Reader
C. Security Administrator
D. Records Management
View answer
Correct Answer: B
Question #3
Your network contains an Active Directory forest named contoso.local. You purchase a Microsoft 365 subscription.You plan to move to Microsoft 365 and to implement a hybrid deployment solution for the next 12 months. You need to prepare for the planned move to Microsoft 365.What is the best action to perform before you implement directory synchronization? More than one answer choice may achieve the goal. Select the BEST answer.
A. Purchase a third-party X
B. Create an external forest trust
C. Rename the Active Directory forest
D. Purchase a custom domain name
View answer
Correct Answer: D
Question #4
You have a Microsoft 365 subscription that uses Microsoft Defender for Office 365.You need to ensure that users are prevented from opening or downloading malicious files from Microsoft Teams, OneDrive, or SharePoint Online.What should you do?
A. Create a newAnti-malware policy
B. Configure the Safe Links global settings
C. Create a new Anti-phishing policy
D. Configure the Safe Attachments global settings
View answer
Correct Answer: D
Question #5
Your company has a Microsoft 365 subscription.You need to identify all the users in the subscription who are licensed for Office 365 through a group membership. The solution must include the name of the group used to assign the license.What should you use?
A. Active users in the Microsoft 365 admin center
B. Reports in Microsoft Purview compliance portal
C. the Licenses blade in the Microsoft Entra admin center
D. Reports in the Microsoft 365 admin center
View answer
Correct Answer: C
Question #6
You have a Microsoft 365 subscription.You need to be notified to your personal email address when a Microsoft Exchange Online service issue occurs.What should you do?
A. From the Exchange admin center, create a contact
B. From the Microsoft Outlook client, configure an Inbox rule
C. From the Microsoft 365 admin center, update the technical contact details
D. From the Microsoft 365 admin center, customize the Service health settings
View answer
Correct Answer: D
Question #7
You plan to delete several user accounts that are assigned Microsoft 365 licenses. How soon after deleting the accounts will you be able to re-assign the licenses to other users?
A. 24 hours
B. 7 days
C. 30 days
D. immediately
View answer
Correct Answer: D
Question #8
You have a Microsoft 365 E5 subscription.You create an account tor a new security administrator named SecAdmin1.You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint and OneDrive.Solution: From the Microsoft Entra ID admin center, you assign SecAdmin1 the Teams Administrator role.Does this meet the goal?
A. Yes
B. no
View answer
Correct Answer: B
Question #9
You have Microsoft 365 E5 subscription that contains the identities shown in the following table.You create a shared mailbox named Shared1.Which identities can you add to Shared1 as a member?
A. User1 only
B. User1 and Group1 only
C. User1 and Group2 only
D. User1 and Group3 only
E. User1, Group2, and Group3 only
View answer
Correct Answer: D
Question #10
You have a Microsoft 365 E5 subscription. You need to create a mail-enabled contact. Which portal should you use?
A. the Microsoft Defender portal
B. the SharePoint admin center
C. the Microsoft Purview portal
D. the Exchange admin center
View answer
Correct Answer: D
Question #11
Overview -Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide.Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States.Existing Environment -Active Directory Environment -The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts.All users authenticate to on-premises applications by signing in to their device by using a UPN format of[email protected].Fabrikam does NOT plan to implement identity federation.Network Infrastructure -Each office has a high-speed connection to the Internet.Each office contains two domain controllers. All domain controllers are configured as DNS servers.The public zone for fabrikam.com is managed by an external DNS server.All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed.All shared company documents are stored on a Microsoft SharePoint Server farm.Requirements -Planned Changes -Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription.Fabrikam plans to implement two pilot projects:Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365.Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users.Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses.Technical Requirements -Fabrikam identifies the following technical requirements:All users must be able to exchange email messages successfully during Project1 by using their current email address.Users must be able to authenticate to cloud services if Active Directory becomes unavailable.A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal.Microsoft 365 Apps for enterprise applications must be installed from a network share only.Disruptions to email access must be minimized.Application Requirements -Fabrikam identifies the following application requirements:An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal.The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized.Security Requirements -Fabrikam identifies the following security requirements:After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN.The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically.After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically.The principle of least privilege must be used.You are evaluating the required processes for Project1.You need to recommend which DNS record must be created while adding a domain name for the project.Which DNS record should you recommend?
A. ost (A)
B. ost information (HINFO)
C. ext (TXT)
D. ointer (PTR)
View answer
Correct Answer: C
Question #12
You have a Microsoft 365 subscription that contains the users shown in the following table.You need to configure group-based licensing to meet the following requirements:To all users, deploy an Office 365 E3 license without the Power Automate license option.To all users, deploy an Enterprise Mobility + Security E5 license.To the users in the research department only, deploy a Power BI Pro license.To the users in the marketing department only, deploy a Visio Plan 2 license.What is the minimum number of deployment groups required?
A. 1
B. 2
C. 3
D. 4
E. 5
View answer
Correct Answer: C
Question #13
You have a Microsoft 365 E5 subscription that uses Endpoint security. You need to create a group and assign the Endpoint Security Manager role to the group. Which type of group can you use?
A. AMicrosoft 365 only
B. Bsecurity only
C. Cmail-enabled security and security only
D. Dmail-enabled security, Microsoft 365, and security only
E. Edistribution, mail-enabled security, Microsoft 365, and security
View answer
Correct Answer: D
Question #14
You have a Microsoft 365 E5 subscription.You need to recommend a solution for monitoring and reporting application access. The solution must meet the following requirements:Support KQL for querying data.Retain report data for at least one year.What should you include in the recommendation?
A. a security report in Microsoft Defender XDR
B. Endpoint analytics
C. Microsoft 365 usage analytics
D. Azure Monitor workbooks
View answer
Correct Answer: D
Question #15
Which role should you assign to User1?
A. Hygiene Management
B. Security Reader
C. Security Administrator
D. Records Management
View answer
Correct Answer: B
Question #16
You have a Microsoft 365 E5 subscription that contains the groups shown in the following exhibit.To which groups can you assign Microsoft 365 E5 licenses?
A. Group1 and Group2 only
B. Group2 and Group3 only
C. Group3 and Group4 only
D. Group1, Group2, and Group3 only
E. Group2, Group3, and Group4 only
View answer
Correct Answer: E
Question #17
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an on-premises Active Directory domain. The domain contains domain controllers that run Windows Server 2019. The functional level of the forest and the domain is Windows Server 2012 R2. The domain contains 100 computers that run Windows 10 and a member server named Server1 that runs Windows Server 2012 R2. You plan to use Server1 to manage the domain and to configure Windows 10 Group Policy settings. You install the Group Policy Management Console (GPMC) on Server1. You need to configure the Windows Update for Business Group Policy settings on Server1. Solution: You copy the Group Policy Administrative Templates from a Windows 10 computer to Server1. Does this meet the goal?
A. yes
B. No
View answer
Correct Answer: A
Question #18
You have a Microsoft 365 E5 subscription. You need to create a mail-enabled contact. Which portal should you use?
A. the Microsoft Defender portal
B. the SharePoint admin center
C. the Microsoft Purview portal
D. the Exchange admin center
View answer
Correct Answer: D
Question #19
You have a Microsoft 365 E5 subscription and use Microsoft Intune for managing mobile devices. You need to access service health alerts from a mobile phone.What should you use?
A. the Microsoft Authenticator app
B. the Microsoft 365 Admin mobile app
C. Intune Company Portal
D. the Intune app
View answer
Correct Answer: B
Question #20
Your company has a Microsoft 365 E5 subscription.You onboard a device on the company's network to Microsoft Defender for Endpoint.In the Microsoft Defender portal, you notice that the device inventory displays many devices that have an Onboarding status of Can be onboarded.You need to ensure that onboarded devices are prevented from polling the network for device discovery but can still discover devices with which they communicate directly.What should you configure in the Microsoft Defender portal?
A. standard discovery
B. device discovery exclusions
C. basic discovery
D. a network assessment job
View answer
Correct Answer: C
Question #21
You have a Microsoft 365 subscription that contains the users shown in the following table.You need to configure group-based licensing to meet the following requirements:To all users, deploy an Office 365 E3 license without the Power Automate license option. To all users, deploy an Enterprise Mobility + Security E5 license.To the users in the research department only, deploy a Power BI Pro license. To the users in the marketing department only, deploy a Visio Plan 2 license.What is the minimum number of deployment groups required?
A. 1
B. 2
C. 3
D. 4
E. 5
View answer
Correct Answer: C
Question #22
You have a Microsoft Microsoft Entra ID (Microsoft Entra ID) tenant named Contoso.com.You create a Microsoft Defender for identity instance Contoso.The tenant contains the users shown in the following table.You need to modify the configuration of the Defender for identify sensors.Solutions: You instruct User3 to modify the Defender for identity sensor configuration.Does this meet the goal?
A. o
B. es
View answer
Correct Answer: B
Question #23
You have a Microsoft 365 E5 tenant that uses Microsoft Intune. You need to ensure that users can select a department when they enroll their device in Intune. What should you create?
A. scope tags
B. device configuration profiles
C. device categories
D. device compliance policies
View answer
Correct Answer: C
Question #24
You have a Microsoft 365 E5 subscription. You need to create a mail-enabled contact. Which portal should you use?
A. the Microsoft Entra admin center
B. the Exchange admin center
C. the Intune admin center
D. the SharePoint admin center
View answer
Correct Answer: B
Question #25
You have a Microsoft Microsoft Entra ID (Microsoft Entra ID) tenant named Contoso.com.You create a Microsoft Defender for identity instance Contoso.The tenant contains the users shown in the following table.You need to modify the configuration of the Defender for identify sensors.Solutions: You instruct User1 to modify the Defender for identity sensor configuration.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #26
You have a Microsoft 365 subscription and use Microsoft Defender for Office 365. You need to recommend a solution to educate users on topics that relate to social engineering risks. The users must receive a weekly reminder to complete a learning task. What should you use in the Microsoft Defender portal?
A. ACampaigns
B. BAttack simulation training
C. CThreat tracker
D. DLearning hub
View answer
Correct Answer: B
Question #27
You have a Microsoft 365 E3 subscription that uses Microsoft Defender for Endpoint Plan 1. Which two Defender for Endpoint features are available to the subscription? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
A. security reports
B. advanced hunting
C. digital certificate assessment
D. device discovery
E. attack surface reduction (ASR)
View answer
Correct Answer: AE
Question #28
You have a Microsoft 365 subscription.You view the Service health Overview as shown in the following exhibit.You need to ensure that a user named User1 can view the advisories to investigate service health issues. Which role should you assign to User1?
A. Message Center Reader
B. Reports Reader
C. Service Support Administrator
D. Compliance Administrator
View answer
Correct Answer: C
Question #29
You have a Microsoft 365 E5 tenant.You plan to create a custom Compliance Manager assessment template based on the ISO 27001:2013 template.You need to export the existing template.Which file format should you use for the exported template?
A. SON
B. SV
C. LSX
D. ML
View answer
Correct Answer: C
Question #30
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft 365 E5 subscription.You create an account for a new security administrator named SecAdmin1.You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive.Solution: From the Microsoft Entra admin center, you assign SecAdmin1 the Security Administrator role. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #31
You have a Microsoft 365 E5 subscription.You need to assign a Microsoft Defender for Endpoint baseline. Which portal should you use?
A. the Microsoft Intune admin center
B. the Microsoft Purview compliance portal
C. the Microsoft Defender portal
D. the Microsoft 365 admin center
View answer
Correct Answer: A
Question #32
Your company has a Microsoft 365 subscription.You need to identify all the users in the subscription who are licensed for Microsoft 365 through a group membership. The solution must include the name of the group used to assign the license.What should you use?
A. Active users in the Microsoft 365 admin center
B. Reports in Microsoft Purview compliance portal
C. the Licenses blade in the Microsoft Entra admin center
D. Reports in the Microsoft 365 admin center
View answer
Correct Answer: C
Question #33
You have a Microsoft 365 tenant. You plan to implement Endpoint Protection device configuration profiles. Which platform can you manage by using the profile? Intune device configuration profiles can be applied to Windows 10 devices and macOS devices Note: There are several versions of this question in the exam. The question has two possible correct answers: Windows 10 macOS Other incorrect answer options you may see on the exam include the following: Android Enterprise Windows 8.1 https://docs.microsoft.com/en-us/mem/intune/protect/endpoint-protection-configure
A. Ubuntu Linux
B. macOS
C. iOS
D. Android
View answer
Correct Answer: B
Question #34
Your company has on-premises servers and a Microsoft Entra tenant.Several months ago, the Microsoft Entra Connect Health agent was installed on all the servers. You review the health status of all the servers regularly.Recently, you attempted to view the health status of a server named Server1 and discovered that the server isNOT listed on the Microsoft Entra Connect Servers list.You suspect that another administrator removed Server1 from the list. You need to ensure that you can view the health status of Server1.What are two possible ways to achieve the goal? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
A. From Windows PowerShell, run the Register-AzureADConnectHealthSyncAgent cmdlet
B. From Azure Cloud shell, run the Connect-AzureAD cmdlet
C. From Server1, reinstall the Microsoft Entra Connect Health agent
D. From Server1, change the Microsoft Entra Connect Health services Startup type to Automatic
E. From Server1, change the Microsoft Entra Connect Health services Startup type to Automatic (Delayed Start)
View answer
Correct Answer: AC

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us