MS-102 domain - 28% of the exam

Manage Security and Threats by Using Microsoft Defender XDR

Manage Security and Threats by Using Microsoft Defender XDR is 28% of the Microsoft 365 Administrator (MS-102) (MS-102) exam. These are the objectives it covers, each with practice questions and worked explanations.

Objectives in this domain

Sample question from this domain

Free sampleManage Security and Threats by Using Microsoft Defender XDRmedium

You sign in to the Microsoft Defender portal as a Defender for Office 365-only customer. Why do you not see device protection features or the Defender for Endpoint device inventory in the portal?

  • AThe portal hides features for products you have not licensed and provisioned. Correct
  • BDevice protection requires a separate browser session at the Endpoint portal.
  • CDefender XDR has not been turned on for the tenant from the Settings page.
  • DThe Microsoft Entra ID role assigned is missing the Endpoint operator scope.
Apply the documented Microsoft 365 / Microsoft Entra ID behaviour to the scenario. In the Microsoft Defender portal customers see only the security features their subscription includes. With Defender for Office 365 but no Defender for Endpoint license, device protection features are not surfaced.

Why A is correct: Correct. In the Microsoft Defender portal customers see only the security features their subscription includes.

Why B is wrong: There is no separate Endpoint portal; the Defender portal at security.microsoft.com is the unified surface.

Why C is wrong: Turning on Defender XDR does not provision Defender for Endpoint; licensing is the gating factor.

Why D is wrong: Roles control access to surfaced features, not whether unlicensed product features appear at all.

Other domains in this exam

See also the MS-102 cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.