MS-102 - Deploy and Manage a Microsoft 365 Tenant (30% of the exam) - Section 1.3

Manage roles and role groups across Microsoft 365 services.

Describe the built-in Microsoft 365 admin roles and Exchange admin roles, and assign them to users following the principle of least privilege. Distinguish between role groups that grant broad admin rights and those scoped to a single service.

Microsoft 365 admin rolesExchange admin rolesrole groupsprivileged admin accountsleast privilege

Practice question for this objective

Free sampleDeploy and Manage a Microsoft 365 Tenantmedium

Which administrative role grants access to view the Service health page in the Microsoft 365 admin center while following least privilege?

  • AUser Administrator role assigned at the tenant scope
  • BDomain Name Administrator role assigned at the tenant scope
  • CService Support Administrator role assigned at the tenant scope Correct
  • DReports Reader role assigned at the tenant scope
Service Support Administrator is the least-privilege role for viewing Microsoft 365 service health. Microsoft Learn states that users assigned Service Support Administrator and Helpdesk Administrator can view service health. Service Support Administrator is the canonical least-privilege role purpose-built for this view.

Why A is wrong: User Administrator manages user accounts and licenses, not service health visibility.

Why B is wrong: Domain Name Administrator is scoped to DNS and domain changes, not health monitoring.

Why C is correct: Correct. Microsoft Learn states that users assigned Service Support Administrator and Helpdesk Administrator can view service health.

Why D is wrong: Reports Reader sees usage reports, not service health incidents or advisories.

See more MS-102 practice questions, answers explained.

Exam traps in Deploy and Manage a Microsoft 365 Tenant

Answers that look right on this material and are not. Each one is a distractor from a different question in the MS-102 bank for this domain.

  • Permanent active assignment

    Why it is wrong: Permanent active gives standing privileges with no expiration and no activation step, defeating both the time-bound and on-demand requirements.

  • Users > Active users > Add a user

    Why it is wrong: Active users adds individual user accounts, not distribution lists.

  • Global Reader

    Why it is wrong: Global Reader is read-only and cannot manage roles or permissions in Defender unified RBAC.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.