Microsoft 365 Administrator Free Sample Questions

19 free sample questions241 in the full practice test Other versions: MS-100(50),MS-101(47)

Try simulator

MS-102 Sample Questions

  1. Question 1

    A financial services firm is deploying Microsoft 365 E5 and needs to secure access to an on-premises legacy application that uses header-based authentication. The firm wants to leverage Microsoft Entra ID for modern authentication (MFA, Conditional Access) and provide single sign-on (SSO) for users. The on-premises network is connected to Azure via a site-to-site VPN. Which Microsoft Entra service should be deployed to meet these requirements?

    Answer and explanation

    Correct answer: C

    Microsoft Entra application proxy is the correct service for publishing on-premises web applications externally and integrating them with Microsoft Entra ID. It can translate modern authentication from Entra ID into legacy authentication methods, including header-based authentication, required by the on-premises app. This allows the firm to enforce Conditional Access policies and MFA while providing SSO.

  2. Question 2

    A global logistics company uses Microsoft 365 and has offices in regions with strict data residency requirements. They have deployed Microsoft Entra Cloud Sync to synchronize identities from multiple disconnected on-premises Active Directory forests. An administrator needs to prevent the synchronization of users from a specific organizational unit (OU) in their German forest that contains temporary service accounts. How can this be achieved with the least administrative effort using Microsoft Entra Cloud Sync?

    Answer and explanation

    Correct answer: D

    Microsoft Entra Cloud Sync is managed primarily from the cloud. To filter objects based on OU, the administrator should edit the specific Cloud Sync configuration profile associated with the German forest directly within the Microsoft Entra admin center. This interface allows for defining the scope of synchronization by selecting or deselecting specific OUs.

  3. Question 3

    A healthcare organization is using Microsoft Defender for Endpoint P2. To minimize the attack surface, they want to prevent unsigned or untrusted processes from running from USB removable drives on all clinical workstations. Which Microsoft Defender for Endpoint feature should be configured to enforce this policy?

    Answer and explanation

    Correct answer: C

    Attack Surface Reduction (ASR) rules are designed to target specific software behaviors that are often abused by malware. The rule 'Block untrusted and unsigned processes that run from USB' directly addresses the organization's requirement. While Device Control can block USBs entirely, ASR provides more granular control over the behavior of processes originating from them.

  4. Question 4

    True or False: When configuring a Microsoft 365 retention policy for a SharePoint site, applying the policy at the site level prevents individual users from deleting items within a document library if the policy has a retention period.

    Answer and explanation

    Correct answer: B

    This statement is false. A retention policy does not prevent users from deleting items. Instead, when a user deletes an item from a location subject to a retention policy, the item is moved to the Preservation Hold library. It is preserved there for the duration of the retention period, but from the user's perspective, the item is deleted.

  5. Question 5

    Case Study: Weyland-Yutani Corporation

    Company Background:
    Weyland-Yutani Corporation is a multinational conglomerate with a significant investment in off-world colony development. They have 50,000 employees globally and a hybrid Active Directory environment. Their on-premises Active Directory (AD) is named weyland.corp and they have a verified domain w-y.com in their Microsoft 365 E5 tenant. Identity synchronization is managed by Microsoft Entra Connect Sync, with Password Hash Synchronization enabled.

    Current Situation:
    The corporation's security team has detected suspicious sign-in activity. Analysis of Microsoft Entra sign-in logs shows multiple failed login attempts from anonymous IP addresses targeting high-privilege accounts, followed by a successful sign-in from an unfamiliar location for one of the accounts. The successful sign-in occurred for a user who is a member of the 'Colony Admin' role-assignable security group. This group is used to grant administrative permissions to a critical Azure application.

    Security Requirements:

    1. Administrators must only be able to activate their privileged roles when needed, and for a limited duration.
    2. Activation of a privileged role must require justification and an optional approval workflow.
    3. High-risk sign-ins detected by Microsoft Entra ID Protection must automatically trigger a requirement for multi-factor authentication and force a password reset.
    4. Membership in the 'Colony Admin' group must be reviewed quarterly by the group owners.

    Problem:
    You are a Microsoft 365 administrator tasked with implementing a solution that meets all the security requirements to prevent a similar incident in the future. Which combination of services and configurations provides the most comprehensive solution?

    Answer and explanation

    Correct answer: B

    This option correctly addresses all four security requirements. PIM for Groups provides just-in-time membership with justification and approval workflows (Reqs 1 & 2). The user risk policy in ID Protection enforces password resets for high-risk users (Req 3). Access Reviews for the group ensures quarterly validation of membership (Req 4). The sign-in risk policy in ID Protection (which can be configured alongside the user risk policy) can enforce MFA for high-risk sign-ins.

  6. Question 6

    A new Microsoft 365 administrator is reviewing the organization's network connectivity to Microsoft 365 services. In the Microsoft 365 admin center, they navigate to Health > Network connectivity. They observe a low network connectivity score for the Chicago office, with specific issues related to high TCP latency. The administrator needs to identify the recommended network egress point for optimal connectivity from the Chicago office. What should the administrator check in the Network connectivity tool?

    Answer and explanation

    Correct answer: B

    The Network connectivity tool in the Microsoft 365 admin center specifically identifies the 'Optimal service front door' for a given location. This is the closest entry point into Microsoft's global network. The tool compares the user's actual egress point to this optimal location and provides recommendations. High latency often indicates that traffic is not egressing from the network optimally.

  7. Question 7

    A manufacturing company uses Microsoft 365. The legal department requires that all email communications related to a specific project, codenamed 'Project Titan', be preserved for 10 years, regardless of user actions. The project involves members from multiple departments. The solution must ensure that the preserved data is discoverable. What is the most appropriate tool to meet this requirement?

    Answer and explanation

    Correct answer: C

    For legal matters like preserving data for a specific project or investigation, an eDiscovery case with a hold is the most appropriate tool. It allows you to place a hold on specific content locations (like mailboxes) based on keywords (like 'Project Titan'). This preserves the data in place for discovery and legal purposes, which directly aligns with the legal department's requirements.

  8. Question 8

    A consultant is reviewing a company's Microsoft Secure Score. They notice a significant number of points can be gained by implementing an improvement action titled 'Enable policy to block legacy authentication'. The company is concerned this will break an essential on-premises line-of-business application that uses SMTP AUTH to send email notifications. What is the recommended approach to implement the improvement action while maintaining application functionality?

    Answer and explanation

    Correct answer: D

    The best practice is to block legacy authentication broadly using Conditional Access. However, since Conditional Access policies do not apply to SMTP AUTH for Exchange Online, you must also manage this protocol at the service level. The correct method is to disable it tenant-wide and then create a specific Exchange Online authentication policy to re-enable SMTP AUTH only for the specific service account that needs it. This follows the principle of least privilege.

  9. Question 9

    During a tenant-to-tenant migration, an administrator needs to invite a large number of users from the source tenant (source.com) as guests into the destination tenant (dest.com). To streamline the process, the administrator wants to use the bulk invite feature in Microsoft Entra ID. The PowerShell command to initiate this is New-AzureADMSInvitation. Which file format is required to upload the user information for the bulk invite?

    Invite-User -InvitedUserEmailAddress -InviteRedirectUrl -SendInvitationMessage $true -InvitedUserDisplayName

    Wait, the question is asking about bulk invites, not a single user invite. Let me re-evaluate the question and cmdlet. The PowerShell cmdlet for bulk operations is different. The portal uses a specific file format. The question is about the file format for the portal's bulk invite feature.

    Let me correct the question context. The administrator is using the Microsoft Entra admin center's bulk user invite feature. What is the required format for the file containing the user data to be uploaded?

    Answer and explanation

    Correct answer: D

    The bulk invite feature in the Microsoft Entra admin center requires a .CSV file. The portal provides a template that specifies the required columns, such as the guest's email address, the redirect URL after they accept the invitation, and a custom invitation message.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 338 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon