DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft MS-102 Practice Questions & Answers 2026 Part3 | Microsoft 365 Administrator

Are you preparing for the Microsoft MS-102 certification exam? SPOTO offers the Microsoft MS-102 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You have a Microsoft 365 subscription that contains the users shown in the following table.You need to configure group-based licensing to meet the following requirements:To all users, deploy an Office 365 E3 license without the Power Automate license option.To all users, deploy an Enterprise Mobility + Security E5 license.To the users in the research department only, deploy a Power BI Pro license.To the users in the marketing department only, deploy a Visio Plan 2 license.What is the minimum number of deployment groups required?
A.
B.
C.
D.
E.
View answer
Correct Answer: C
Question #2
You have a Microsoft 365 E5 subscription.You need to create Conditional Access policies to meet the following requirements:All users must use multi-factor authentication (MFA) when they sign in from outside the corporate network.Users must only be able to sign in from outside the corporate network if the sign-in originates from a compliant device.All users must be blocked from signing in from outside the United States and Canada.Only users in the R&D department must be blocked from signing in from both Android and iOS devices.Only users in the finance department must be able to sign in to an Azure AD enterprise application named App1. All other users must be blocked from signing in to App1.What is the minimum number of Conditional Access policies you should create?
A.
B.
C.
D.
E.
F.
View answer
Correct Answer: B
Question #3
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 E5 subscription.You integrate Microsoft Defender for Endpoint with Microsoft Intune.You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune.Solution: You create an endpoint detection and response (EDR) policy. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #4
You need to notify the manager of the human resources department when a user in the department shares a file or folder from the department's Microsoft SharePoint site.What should you do?
A. rom the SharePoint admin center, modify the sharing settings
B. rom the SharePoint site, create an alert
C. rom the Microsoft Purview compliance portal, create a data loss prevention (DLP) policy
D. rom the Microsoft 365 Defender portal, create an alert policy
View answer
Correct Answer: C
Question #5
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft 365 E5 subscription that contains a user named User1.You need to enable User1 to create Compliance Manager assessments.Solution: From the Microsoft 365 compliance center, you add User1 to the Compliance Manager Assessors role group.Does this meet the goal?
A. o
B. es
View answer
Correct Answer: B
Question #6
You have a Microsoft 365 subscription that contains the users shown in the following table.You plan to use Microsoft 365 Backup.Which users can enable Microsoft 365 Backup?
A. Admin1 only
B. Admin3 only
C. Admin1 and Admin3 only
D. Admin1, Admin2 and Admin3 only
E. Admin1, Admin2, Admin3, and Admin4
View answer
Correct Answer: C
Question #7
You have a Microsoft 365 subscription. An administrator accidentally deletes a user account. How many days do you have to recover the account before it is permanently deleted?
A. 14
B. 30
C. 93
D. 365
View answer
Correct Answer: B
Question #8
You have a Microsoft 365 subscription.You suspect that several Microsoft Office 365 applications or services were recently updated. You need to identify which applications or services were recently updated.What are two possible ways to achieve the goal? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
A. From the Microsoft 365 admin center, review the Service health blade
B. From the Microsoft 365 admin center, review the Message center blade
C. From the Microsoft 365 admin center, review the Products blade
D. From the Microsoft 365 Admin mobile app, review the messages
View answer
Correct Answer: BD
Question #9
You have a Microsoft 365 subscription.You register two applications named App1 and App2 to Azure AD.You need to ensure that users who connect to App1 require multi-factor authentication (MFA). MFA is required only for App1. What should you do?
A. rom the Microsoft Entra admin center, create a conditional access policy
B. rom the Microsoft 365 admin center, configure the Modem authentication settings
C. rom the Enterprise applications blade of the Microsoft Entra admin center, configure the Users settings
D. rom Multi-Factor Authentication, configure the service settings
View answer
Correct Answer: A
Question #10
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an on-premises Active Directory domain. The domain contains domain controllers that run Windows Server 2019. The functional level of the forest and the domain is Windows Server 2012 R2.The domain contains 100 computers that run Windows 10 and a member server named Server1 that runs Windows Server 2012 R2.You plan to use Server1 to manage the domain and to configure Windows 10 Group Policy settings.You install the Group Policy Management Console (GPMC) on Server1.You need to configure the Windows Update for Business Group Policy settings on Server1.Solution: You raise the forest functional level to Windows Server 2016. You copy the Group Policy Administrative Templates from a Windows 10 computer to the Netlogon share on all the domain controllers.Does this meet the goal?
A. o
B. es
View answer
Correct Answer: A
Question #11
You have a Microsoft 365 E5 subscription that uses Endpoint security. You need to create a group and assign the Endpoint Security Manager role to the group. Which type of group can you use?
A. Microsoft 365 only
B. security only
C. mail-enabled security and security only
D. mail-enabled security, Microsoft 365, and security only
E. distribution, mail-enabled security, Microsoft 365, and security
View answer
Correct Answer: B
Question #12
On which server should you install the Azure ATP sensor?
A. Server 1
B. Server 2
C. Server 3
D. Server 4
E. Server 5
View answer
Correct Answer: A
Question #13
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft 365 E5 subscription.You create an account for a new security administrator named SecAdmin1.You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive.Solution: From the Microsoft 365 admin center, you assign SecAdmin1 the Teams Administrator role. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #14
You have a Microsoft 365 E5 subscription that is linked to a Microsoft Entra tenant named contoso.com. You purchase 100 Microsoft 365 Business Voice add-on licenses.You need to ensure that the members of a group named Voice are assigned a Microsoft 365 Business Voice add-on license automatically.What should you do?
A. From the Licenses page of the Microsoft 365 admin center, assign the licenses
B. From the Microsoft Entra admin center, modify the settings of the Voice group
C. From the Microsoft 365 admin center, modify the settings of the Voice group
View answer
Correct Answer: B
Question #15
Overview -Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide.Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States.Existing Environment -Active Directory Environment -The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts.All users authenticate to on-premises applications by signing in to their device by using a UPN format of[email protected].Fabrikam does NOT plan to implement identity federation.Network Infrastructure -Each office has a high-speed connection to the Internet.Each office contains two domain controllers. All domain controllers are configured as DNS servers.The public zone for fabrikam.com is managed by an external DNS server.All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed.All shared company documents are stored on a Microsoft SharePoint Server farm.Requirements -Planned Changes -Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription.Fabrikam plans to implement two pilot projects:Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365.Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users.Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses.Technical Requirements -Fabrikam identifies the following technical requirements:All users must be able to exchange email messages successfully during Project1 by using their current email address.Users must be able to authenticate to cloud services if Active Directory becomes unavailable.A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal.Microsoft 365 Apps for enterprise applications must be installed from a network share only.Disruptions to email access must be minimized.Application Requirements -Fabrikam identifies the following application requirements:An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal.The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized.Security Requirements -Fabrikam identifies the following security requirements:After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN.The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically.After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically.The principle of least privilege must be used.You need to ensure that all the sales department users can authenticate successfully during Project1 and Project2.Which authentication strategy should you implement for the pilot projects?
A. ass-through authentication
B. ass-through authentication and seamless SSO
C. assword hash synchronization and seamless SSO
D. assword hash synchronization
View answer
Correct Answer: C
Question #16
You have a Microsoft 365 subscription that contains the users shown in the following table.You plan to use Microsoft 365 Backup.Which users can enable Microsoft 365 Backup?
A. Admin1 only
B. Admin3 only
C. Admin1 and Admin3 only
D. Admin1, Admin2 and Admin3 only
E. Admin1, Admin2, Admin3, and Admin4
View answer
Correct Answer: C
Question #17
You are evaluating the required processes for Project1.You need to recommend which DNS record must be created while adding a domain name to the tenant for the project.Which DNS record should you recommend?
A. alias (CNAME)
B. host information (HINFO)
C. host (A)
D. text (TXT)
View answer
Correct Answer: D
Question #18
You are evaluating the required processes for Project1.You need to recommend which DNS record must be created while adding a domain name for the project. Which DNS record should you recommend?
A. name server (NS)
B. host information (HINFO)
C. text (TXT)
D. pointer (PTR)
View answer
Correct Answer: C
Question #19
You have a Microsoft 365 subscription that contains the domains shown in the following exhibit.Which domain name suffixes can you use when you create users?
A. only Sub1
B. onlycontoso221018
C. only contoso221018
D. all the domains in the subscription
View answer
Correct Answer: D
Question #20
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 E5 subscription.You integrate Microsoft Defender for Endpoint with Microsoft Intune.You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune.Solution: You create a compliance policy. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #21
You have a Microsoft 365 E5 subscription. Administrators are issued FID02 security keys.You need to create a Conditional Access policy that will use a FID02 security key as an authentication method. Which Access controls option should you select for the policy?
A. equire authentication strength
B. equire token protection for sign-in sessions
C. equire multifactor authentication
D. equire approved client app
View answer
Correct Answer: A
Question #22
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 E5 subscription.You integrate Microsoft Defender for Endpoint with Microsoft Intune.You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune.Solution: You enable co-management. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #23
You have a Microsoft 365 subscription.All users are assigned Microsoft 365 Apps for enterprise licenses.You need to ensure that reports display the names of users that have activated Microsoft 365 apps and on how many devices.What should you modify in the Microsoft 365 admin center?
A. the Reports reader role
B. Organization information
C. Org settings for Privacy profile
D. Org settings for Reports
View answer
Correct Answer: D
Question #24
Your company has a Microsoft Entra tenant named contoso.com that includes the users shown in the following table.Group2 is a member of Group1.You assign a Microsoft 365 Enterprise E3 license to Group1. How many Microsoft 365 E3 licenses are assigned?
A. 1
B. 2
C. 3
D. 4
View answer
Correct Answer: C
Question #25
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. You need to be notified when a user shares a file or folder from Site1. What should you do?
A. From the Microsoft Purview compliance portal, create a data loss prevention (DLP) policy
B. From the Microsoft Purview compliance portal, create an alert policy
C. From the SharePoint admin center, modify the sharing settings
D. From Site1, create an alert
View answer
Correct Answer: B
Question #26
You have a Microsoft 365 E5 subscription that uses Endpoint security.You need to create a group and assign the Endpoint Security Manager role to the group. Which type of group can you use?
A. Microsoft 365 only
B. security only
C. mail-enabled security and security only
D. mail-enabled security, Microsoft 365, and security only
E. distribution, mail-enabled security, Microsoft 365, and security
View answer
Correct Answer: D
Question #27
Your company has digitally signed applications. You need to ensure that Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) considers the digitally signed applications safe and never analyzes them. What should you create in the Microsoft Defender Security Center?
A. a custom detection rule
B. an allowed/blocked list rule
C. an indicator
D. an alert suppression rule
View answer
Correct Answer: C
Question #28
You have a Microsoft 365 E5 tenant.You need to evaluate compliance with European Union privacy regulations for customer data.What should you do in the Microsoft 365 compliance center?
A. reate an assessment based on the Data Protection Baseline assessment template
B. reate an assessment based on the EU GDPR assessment template
C. reate a data loss prevention (DLP) policy for General Data Protection Regulation (GDPR) data
D. reate a Data Subject Request (DSR)
View answer
Correct Answer: B
Question #29
Your company has a Microsoft 365 subscription.You need to identify all the users in the subscription who are licensed for Office 365 through a group membership. The solution must include the name of the group used to assign the license.What should you use?
A. ctive users in the Microsoft 365 admin center
B. eports in Microsoft Purview compliance portal
C. he Licenses blade in the Microsoft Entra admin center
D. eports in the Microsoft 365 admin center
View answer
Correct Answer: C

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us