Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Microsoft
Exam Format
120 min
40-60
700
Expert
Registration
$165 USD
Pearson VUE or online proctoring
Validity
3 years
Exam retired - see MS-102 for current certification path
Exam Guide
MS-101 Exam Topics and Domains
MS-101 is organized into 3 weighted domains. Expect to work with Intune, Microsoft Purview, Azure AD, Microsoft Endpoint Manager, and more.
1
Plan and implement device services
37.5%
Plan and implement device management by using Microsoft Endpoint Manager
Plan co-management between Endpoint Configuration Manager and IntunePlan and implement configuration profiles for Windows and MacOS clientsPlan and implement configuration profiles for iOS and AndroidReview and respond to issues identified in Microsoft Endpoint Manager
- Design co-management solutions combining ConfigMgr and Intune
- Create and deploy configuration profiles for all supported platforms
- Monitor and troubleshoot device management issues
Plan and implement device security and compliance by using Microsoft Endpoint Manager
Plan and implement device compliance policiesPlan and implement attack surface reduction policiesImplement and manage security baselinesPlan and configure conditional access policies for device compliance
- Implement comprehensive device compliance policies
- Deploy attack surface reduction to minimize security risks
- Configure conditional access based on device compliance state
Deploy and manage applications by using Microsoft Endpoint Manager
Plan and implement application deploymentPublish public and private applications by using Microsoft Endpoint ManagerPlan and implement application protection policiesPlan and implement application configuration policiesMonitor and troubleshoot application deployment
- Deploy applications across all supported platforms
- Implement app protection policies for data security
- Configure and troubleshoot app deployment issues
Plan for Windows client deployment and management
Choose Windows client deployment methods and toolsPlan and implement Windows subscription-based activationPlan for Windows updatesPlan and implement additional Windows client security features
- Design Windows deployment strategies using modern tools
- Implement subscription-based Windows activation
- Configure Windows update management and security features
Plan and implement device enrollment
Plan and implement device join or hybrid join to Azure ADPlan and implement device registration to Azure ADPlan and implement manual and automated device enrollment into Intune
- Implement Azure AD device join strategies
- Configure automated device enrollment into Intune
- Troubleshoot device enrollment issues
2
Manage security and threats by using Microsoft 365 Defender
27.5%
Manage security reports and alerts by using the Microsoft 365 Defender portal
Review and respond to the Microsoft 365 Secure ScoreReview and respond to security alerts in Microsoft 365 DefenderReview and respond to issues identified in security and compliance reports
- Monitor and improve Microsoft 365 Secure Score
- Investigate and respond to security alerts
- Utilize security and compliance reports for decision-making
Plan, implement, and manage email and collaboration protection by using Microsoft Defender for Office 365
Plan and implement policies and rules in Microsoft Defender for Office 365Review and respond to issues identified in Microsoft Defender for Office 365Unblock users
- Configure comprehensive email protection policies
- Investigate email-based threats and campaigns
- Manage quarantined items and unblock users
Plan, implement, and manage endpoint protection by using Microsoft Defender for Endpoint
Plan Microsoft Defender for EndpointOnboard devices to Microsoft Defender for EndpointConfigure Microsoft Defender for Endpoint settingsReview and respond to endpoint vulnerabilitiesReview and respond to risks on devicesReview and respond to exposure score
- Deploy and configure Microsoft Defender for Endpoint
- Manage endpoint vulnerabilities and risks
- Respond to security incidents on endpoints
Plan, implement, and manage Microsoft Defender for Cloud Apps
Configure the application connector for Office 365Plan and configure Microsoft Defender for Cloud Apps policiesReview and respond to Microsoft Defender for Cloud Apps alertsReview and respond to activity logConfigure Cloud App DiscoveryReview and respond to issues identified in Cloud App Discovery
- Configure and manage cloud app connectors
- Implement and manage cloud app protection policies
- Discover and govern shadow IT usage
3
Manage Microsoft 365 compliance
32.5%
Plan and implement information governance
Plan and implement retention labels and label policiesRecover deleted data in Exchange Online and SharePoint OnlineImplement records management
- Implement retention labels and policies for information governance
- Recover deleted content from Microsoft 365 services
- Configure records management for regulatory compliance
Plan and implement information protection
Plan and implement data classificationPlan and implement sensitivity labels and policiesOptimize label usage by using Content explorer, Activity explorer, and label reports
- Implement data classification strategies
- Deploy and manage sensitivity labels
- Monitor and optimize label usage
Plan and implement data loss prevention (DLP)
Plan and implement DLP for workloadsPlan and implement Microsoft 365 Endpoint DLPReview and respond to DLP alerts, events, and reports
- Design and implement DLP policies across workloads
- Configure Endpoint DLP to prevent data exfiltration
- Monitor and respond to DLP incidents
Manage search and investigation
Configure auditing in Azure AD, including diagnostic settingsPlan and configure audit retention policies for Microsoft 365Retrieve and interpret audit logs for workloadsPlan and configure eDiscovery and Advanced eDiscoverySpecify a Content Search based on requirements
- Configure and manage audit logging in Microsoft 365 and Azure AD
- Implement eDiscovery solutions for legal and compliance investigations
- Perform content searches across Microsoft 365 workloads
Who should take this exam?
- Experience with Microsoft 365 services
- Understanding of security and compliance concepts
- Familiarity with mobile device management
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.