dc dotCreds
MS-102 Microsoft 365 Administrator Practice Test

MS-102 Practice Test

Start today’s free 10-question MS-102 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 26, 2026, 10:47 PM CDT

Go Pro - One Time Unlock

Unlock the full MS-102 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 MS-102 questions

Use this MS-102 practice test to review Microsoft MS-102 Microsoft 365 Administrator. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Manage users and groups Deploy and manage a Microsoft 365 tenant (25–30%)

A provisioning workflow must create and update thousands of users every week from an HR system with repeatable logic and error handling. The process should be automated rather than driven by a portal upload each time. Which action should you take?

Concept tested:
Question 2 of 10
Objective Implement and manage a Microsoft 365 tenant Deploy and manage a Microsoft 365 tenant (25–30%)

After opening a new office, the administrator wants to compare its Microsoft 365 connectivity characteristics with expected service networking practices before blaming an application outage. What should you do next?

Concept tested:
Question 3 of 10
Objective Manage roles and role groups Deploy and manage a Microsoft 365 tenant (25–30%)

A compliance investigator needs Purview investigation permissions without being made a Microsoft 365 Global Administrator. Which configuration best meets the requirement?

Concept tested:
Question 4 of 10
Objective Implement Microsoft Purview information protection and data lifecycle management Manage compliance by using Microsoft Purview (10–15%)

A data protection team needs to detect a proprietary account identifier that is not covered by a built-in sensitive information type. The format is consistent and a supporting keyword should raise confidence. Which configuration best meets the requirement?

Concept tested:
Question 5 of 10
Objective Implement and manage email and collaboration protection by using Microsoft Defender for Office 365 Manage security and threats by using Microsoft Defender XDR (30–35%)

A company wants Microsoft-recommended email protection settings for most users without manually recreating every anti-phishing, anti-spam, Safe Links, and Safe Attachments setting. Which action should you take?

Concept tested:
Question 6 of 10
Objective Implement and manage secure access Implement and manage Microsoft Entra identity and access (25–30%)

Administrators accessing a privileged application must use phishing-resistant authentication, not merely any method that satisfies generic MFA. Which administrative action is most appropriate?

Concept tested:
Question 7 of 10
Objective Implement Microsoft Purview data loss prevention (DLP) Manage compliance by using Microsoft Purview (10–15%)

A user claims a DLP block was a false positive. The investigator must review the event details and matched sensitive-content context for the policy violation, subject to the required permissions. Which action should you take?

Concept tested:
Question 8 of 10
Objective Implement and manage Microsoft Defender for Cloud Apps Manage security and threats by using Microsoft Defender XDR (30–35%)

A policy is generating too many alerts for routine cloud activity. The administrator needs to narrow the activity filters and use a threshold that represents suspicious repetition. What should you do next?

Concept tested:
Question 9 of 10
Objective Implement and manage authentication Implement and manage Microsoft Entra identity and access (25–30%)

Several users claim MFA is being requested unexpectedly. The identity team needs to inspect the relevant sign-in events and determine which authentication and policy details were evaluated. What is the best way to meet this requirement?

Concept tested:
Question 10 of 10
Objective Implement Microsoft Purview information protection and data lifecycle management Manage compliance by using Microsoft Purview (10–15%)

A security team created a Confidential sensitivity label with encryption settings, but no users can see it in Office apps. The label has never been added to a publishing policy. Which administrative action is most appropriate?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
MS-102 Pro $4.99 one-time

Best if you only need this one certification.

50 Exam Practice Test $1.99 one-time

A 50-question MS-102 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full MS-102 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily MS-102 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily MS-102 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A provisioning workflow must create and update thousands of users every week from an HR system with repeatable logic and error handling. The process should be automated rather than driven by a portal upload each time. Which action should you take?

Answer choices

  1. A. Create one shared mailbox and add all employees as delegates since delegates automatically become individually licensed Microsoft 365 users.
  2. B. Use Entra bulk operations for file-based batches or Microsoft Graph for repeatable programmatic user lifecycle management, while preserving the intended access model.
  3. C. Create a Microsoft 365 service-health incident because Microsoft support automatically provisions the users listed in an incident attachment.
  4. D. Use Microsoft Defender XDR advanced hunting because KQL query results can be committed directly as new Microsoft Entra user objects.

Correct answer

Use Entra bulk operations for file-based batches or Microsoft Graph for repeatable programmatic user lifecycle management, while preserving the intended access model.

Microsoft Entra supports bulk user creation for batch imports and Microsoft Graph for repeatable programmatic identity lifecycle operations, avoiding fragile manual account creation.

Wrong-answer review

  • A. Create one shared mailbox and add all employees as delegates since delegates automatically become individually licensed Microsoft 365 users.: Incorrect. Delegating a shared mailbox does not create or license individual employee identities.
  • C. Create a Microsoft 365 service-health incident because Microsoft support automatically provisions the users listed in an incident attachment.: Incorrect. Service health is for operational cloud-service status and does not provision customer identities.
  • D. Use Microsoft Defender XDR advanced hunting because KQL query results can be committed directly as new Microsoft Entra user objects.: Incorrect. Advanced hunting queries security telemetry and is not an identity-provisioning write API.

Extra learning features

Why candidates miss this

The provided distractor, ‘Create one shared mailbox and add all employees as delegates since delegates automatically become individually licensed Microsoft 365 users,’ is tempting because it offers a seemingly simple solution. However, it fails to address the core requirement of automated user creation and management at scale. The decisive clue is the emphasis on ‘repeatable programmatic user lifecycle management,’ which highlights the need for a robust, automated solution, not a manual workaround. Likely wrong answer: Create one shared mailbox and add all employees as delegates since delegates automatically become individually licensed Microsoft 365 users. Review focus: Bulk create users in Microsoft Entra ID

Interview question

Q: Microsoft Entra supports bulk user operations for batch imports and Microsoft Graph for repeatable programmatic identity lifecycle operations, avoiding fragile manual account creation. Strong answer: Microsoft Entra supports bulk user operations for batch imports and Microsoft Graph for repeatable programmatic identity lifecycle operations, avoiding fragile manual account creation.

  • bulk user operations
  • Microsoft Graph
  • identity lifecycle operations

Caution: Do not restate the multiple-choice stem or ask the learner merely to name a product, rule, or term.

Objective/domain: Deploy and manage a Microsoft 365 tenant (25–30%)

Source: Bulk create users in Microsoft Entra ID

Question 2 After opening a new office, the administrator wants to compare its Microsoft 365 connectivity characteristics with expected service networking practices before blaming an application outage. What should you do next?

Answer choices

  1. A. Create a Defender for Cloud Apps activity policy because activity thresholds calculate WAN latency and recommend the nearest Microsoft edge location.
  2. B. Review Microsoft 365 Network Insights for the affected location and follow its detected issues and recommendations, and verify the resulting tenant state.
  3. C. Change the organization profile country so Microsoft 365 automatically moves this tenant's data plane to the branch office region.
  4. D. Reassign Microsoft 365 licenses for the branch because license assignment determines the network path used to reach Microsoft cloud services.

Correct answer

Review Microsoft 365 Network Insights for the affected location and follow its detected issues and recommendations, and verify the resulting tenant state.

Objective/domain: Deploy and manage a Microsoft 365 tenant (25–30%)

Source: Microsoft 365 Network Insights

Question 3 A compliance investigator needs Purview investigation permissions without being made a Microsoft 365 Global Administrator. Which configuration best meets the requirement?

Answer choices

  1. A. Assign ownership of the Microsoft 365 tenant domain because domain ownership automatically grants all Defender and Purview investigation permissions.
  2. B. Assign the appropriate Microsoft Purview role group with only the permissions and scope required for the compliance task.
  3. C. Use group-based licensing as the authorization model because assigning a Defender or Purview license also grants the user all administrative permissions for that product.
  4. D. Assign Global Administrator because Defender and Purview administrative tasks cannot be delegated through product-specific roles or role groups.

Correct answer

Assign the appropriate Microsoft Purview role group with only the permissions and scope required for the compliance task.

Objective/domain: Deploy and manage a Microsoft 365 tenant (25–30%)

Source: Permissions in the Microsoft Purview portal

Question 4 A data protection team needs to detect a proprietary account identifier that is not covered by a built-in sensitive information type. The format is consistent and a supporting keyword should raise confidence. Which configuration best meets the requirement?

Answer choices

  1. A. Create a sensitivity label named after each identifier since label names are automatically scanned as regular expressions inside documents.
  2. B. Create a retention label with a five-year period because retention settings also define custom content-matching patterns for DLP and labeling.
  3. C. Create a custom sensitive information type with the needed pattern, supporting evidence, proximity, and confidence.
  4. D. Create a Defender for Cloud Apps activity policy because cloud-activity thresholds are the Purview classifier for structured identifiers.

Correct answer

Create a custom sensitive information type with the needed pattern, supporting evidence, proximity, and confidence.

Objective/domain: Manage compliance by using Microsoft Purview (10–15%)

Source: Create custom sensitive information types

Question 5 A company wants Microsoft-recommended email protection settings for most users without manually recreating every anti-phishing, anti-spam, Safe Links, and Safe Attachments setting. Which action should you take?

Answer choices

  1. A. Assign Standard or Strict preset security protection to the intended recipients and verify its effective scope.
  2. B. Enable every Defender XDR alert policy because alert policies automatically apply Strict email protection to their notification recipients.
  3. C. Configure Conditional Access authentication strength because stronger sign-in controls replace Defender for Office 365 threat policies for email content.
  4. D. Create a Microsoft 365 retention policy because retention presets also configure anti-phishing, Safe Links, and Safe Attachments settings.

Correct answer

Assign Standard or Strict preset security protection to the intended recipients and verify its effective scope.

Objective/domain: Manage security and threats by using Microsoft Defender XDR (30–35%)

Source: Preset security policies in EOP and Microsoft Defender for Office 365

Question 6 Administrators accessing a privileged application must use phishing-resistant authentication, not merely any method that satisfies generic MFA. Which administrative action is most appropriate?

Answer choices

  1. A. Use a retention label that requires justification because label downgrade justification is equivalent to an MFA or authentication-strength grant control.
  2. B. Use Conditional Access grant controls to require MFA or the required authentication strength for the targeted access, while preserving emergency access.
  3. C. Use Microsoft Entra Password Protection because banned-password rules are the policy surface for requiring phishing-resistant MFA during application sign-in.
  4. D. Use a Defender for Office 365 Strict preset policy because Strict email protection satisfies MFA requirements for every Microsoft 365 application.

Correct answer

Use Conditional Access grant controls to require MFA or the required authentication strength for the targeted access, while preserving emergency access.

Objective/domain: Implement and manage Microsoft Entra identity and access (25–30%)

Source: Conditional Access overview

Question 7 A user claims a DLP block was a false positive. The investigator must review the event details and matched sensitive-content context for the policy violation, subject to the required permissions. Which action should you take?

Answer choices

  1. A. Use Microsoft 365 Service health because every DLP policy violation is posted as a tenant service incident with the matched content.
  2. B. Use Microsoft Secure Score since DLP alerts are security recommendations and their underlying events are stored only in score history.
  3. C. Use Entra sign-in logs because sign-in events contain the full DLP rule match, sensitive content, and policy action for each file operation.
  4. D. Use the Purview DLP Alerts dashboard to inspect the alert, associated events, metadata, policy details, and permitted content context.

Correct answer

Use the Purview DLP Alerts dashboard to inspect the alert, associated events, metadata, policy details, and permitted content context.

Objective/domain: Manage compliance by using Microsoft Purview (10–15%)

Source: Get started with the Data Loss Prevention Alerts dashboard

Question 8 A policy is generating too many alerts for routine cloud activity. The administrator needs to narrow the activity filters and use a threshold that represents suspicious repetition. What should you do next?

Answer choices

  1. A. Configure a Cloud Apps activity policy with the needed filters, activity threshold, alert settings, and governance action, after reviewing the relevant activity context.
  2. B. Create a DLP retention label since retention labels count repeated cloud activities and generate Defender for Cloud Apps alerts when thresholds are exceeded.
  3. C. Create a Microsoft 365 usage report because usage reports can enforce governance actions when a user crosses an activity threshold.
  4. D. Create an Entra dynamic group rule because dynamic group membership is the supported engine for detecting repeated downloads in connected cloud applications.

Correct answer

Configure a Cloud Apps activity policy with the needed filters, activity threshold, alert settings, and governance action, after reviewing the relevant activity context.

Objective/domain: Manage security and threats by using Microsoft Defender XDR (30–35%)

Source: Create activity policies in Microsoft Defender for Cloud Apps

Question 9 Several users claim MFA is being requested unexpectedly. The identity team needs to inspect the relevant sign-in events and determine which authentication and policy details were evaluated. What is the best way to meet this requirement?

Answer choices

  1. A. Use Defender for Cloud Apps Cloud Discovery since discovery logs are the authoritative source for all Microsoft Entra authentication failures.
  2. B. Use Entra sign-in logs to inspect the affected event, authentication details, failure, resource, client, and Conditional Access result.
  3. C. Use Purview Activity explorer because data-classification activities include the complete authentication trace for each Microsoft Entra sign-in.
  4. D. Use Microsoft 365 usage reports because usage reports contain the full authentication failure code and Conditional Access decision for every sign-in.

Correct answer

Use Entra sign-in logs to inspect the affected event, authentication details, failure, resource, client, and Conditional Access result.

Objective/domain: Implement and manage Microsoft Entra identity and access (25–30%)

Source: Sign-in logs in Microsoft Entra ID

Question 10 A security team created a Confidential sensitivity label with encryption settings, but no users can see it in Office apps. The label has never been added to a publishing policy. Which administrative action is most appropriate?

Answer choices

  1. A. Assign a Microsoft 365 Apps license directly to the label because licensing automatically publishes every unpublished sensitivity label.
  2. B. Create a retention policy that references the sensitivity label because retention policies are the only mechanism that makes labels visible in Office.
  3. C. Add the label name to a custom sensitive information type because matching the label name causes Office clients to download the label.
  4. D. Publish the required sensitivity labels to the intended audience through a sensitivity label policy, before publishing or enforcing it more broadly.

Correct answer

Publish the required sensitivity labels to the intended audience through a sensitivity label policy, before publishing or enforcing it more broadly.

Objective/domain: Manage compliance by using Microsoft Purview (10–15%)

Source: Create and configure sensitivity labels and their policies

Where to go after the daily web set

How are MS-102 questions generated?

dotCreds builds MS-102 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start MS-102 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.