12 real MS-102 sample questions, each with a worked explanation and a rationale for every option, right and wrong. No account, no card. This is the reasoning the MS-102 tests: knowing why the tempting answer is wrong, not just spotting the right one.
The real MS-102 is Typically 40 to 60 questions questions in 120 minutes, pass mark 700 / 1000. For a domain-by-domain breakdown and a study plan, read the MS-102 study guide. The full bank has 199 questions.
lock_openFree sampleDeploy and Manage a Microsoft 365 Tenantmedium
A new administrator wants to add the contoso.com custom domain to your Microsoft 365 tenant. Which directory role grants the minimum permissions required to add, modify, or remove a domain?
- AUser Administrator role in the Microsoft 365 admin center
- BDomain Name Administrator role in the Microsoft 365 admin centercheck_circle Correct
- CService Support Administrator role in the Microsoft 365 admin center
- DHelpdesk Administrator role in the Microsoft 365 admin center
Adding or removing a Microsoft 365 domain requires the Domain Name Administrator role, not generic helpdesk or user roles. Microsoft Learn explicitly requires the Domain Name Administrator role to add, modify, or remove a domain because the change affects the whole tenant. Customized administrators or regular users cannot make this change.
Why A is wrong: User Administrator manages user accounts and licenses but cannot add tenant-scoped domains.
Why B is correct: Correct. Microsoft Learn explicitly requires the Domain Name Administrator role to add, modify, or remove a domain because the change affects the whole tenant.
Why C is wrong: Service Support Administrator views service health and creates service requests, not domain configuration.
Why D is wrong: Helpdesk Administrator resets passwords and views service health but cannot manage domains.
lock_openFree sampleDeploy and Manage a Microsoft 365 Tenanteasy
From which navigation path in the Microsoft 365 admin center do you configure release preferences for the tenant?
- ASetup > Sign-in and security > Manage feature updates page
- BSettings > Org settings > Organization profile > Release preferencescheck_circle Correct
- CHealth > Message center > Preferences > Release ring selector
- DSettings > Integrated apps > Release preferences page for tenant
Release preferences live under Settings > Org settings > Organization profile in the Microsoft 365 admin center. The release ring selector lives on the Organization profile tab under Settings > Org settings, where you choose Standard release, Targeted release for everyone, or Targeted release for selected users.
Why A is wrong: Setup hosts wizards for security and onboarding tasks, not the release ring selector.
Why B is correct: Correct. The release ring selector lives on the Organization profile tab under Settings > Org settings, where you choose Standard release, Targeted release for everyone, or Targeted release for selected users.
Why C is wrong: Message center preferences control digest emails, not which release ring the tenant is on.
Why D is wrong: Integrated apps manages third-party app deployment, not the Microsoft 365 release schedule.
lock_openFree sampleDeploy and Manage a Microsoft 365 Tenanthard
You are adding a custom domain to Microsoft 365 using a registrar that does not support Domain Connect. Which tasks must you perform manually? (Select 2 answers)
- AVerify domain ownership at the registrar using DNS or a filecheck_circle Correct
- BAdd the DNS records required by Microsoft 365 servicescheck_circle Correct
- CRegister the domain name through the Microsoft 365 admin center
- DTransfer the registrar of record to Microsoft for the domain
Without Domain Connect, both ownership verification and DNS record publication are manual steps at the registrar. Microsoft Learn lists exactly two manual tasks for non-Domain-Connect registrars: verify domain ownership using DNS records or an uploaded verification file, and manually add the DNS records for Microsoft 365 services. Microsoft 365 does not perform either step automatically.
Why A is correct: Correct. Verify domain ownership at the registrar using DNS or a file is one of the keyed answers. Microsoft Learn lists exactly two manual tasks for non-Domain-Connect registrars: verify domain ownership using DNS records or an uploaded verification file, and manually add the DNS records for Microsoft 365 services.
Why B is correct: Correct. Add the DNS records required by Microsoft 365 services is one of the keyed answers. Microsoft Learn lists exactly two manual tasks for non-Domain-Connect registrars: verify domain ownership using DNS records or an uploaded verification file, and manually add the DNS records for Microsoft 365 services.
Why C is wrong: The admin center does not register new domains; you bring an already-registered domain to the tenant.
Why D is wrong: Domain transfer to Microsoft is not a step in the add-domain wizard; the existing registrar continues to host the domain.
lock_openFree sampleManage Security and Threats by Using Microsoft Defender XDRmedium
You sign in to the Microsoft Defender portal as a Defender for Office 365-only customer. Why do you not see device protection features or the Defender for Endpoint device inventory in the portal?
- AThe portal hides features for products you have not licensed and provisioned.check_circle Correct
- BDevice protection requires a separate browser session at the Endpoint portal.
- CDefender XDR has not been turned on for the tenant from the Settings page.
- DThe Microsoft Entra ID role assigned is missing the Endpoint operator scope.
Apply the documented Microsoft 365 / Microsoft Entra ID behaviour to the scenario. In the Microsoft Defender portal customers see only the security features their subscription includes. With Defender for Office 365 but no Defender for Endpoint license, device protection features are not surfaced.
Why A is correct: Correct. In the Microsoft Defender portal customers see only the security features their subscription includes.
Why B is wrong: There is no separate Endpoint portal; the Defender portal at security.microsoft.com is the unified surface.
Why C is wrong: Turning on Defender XDR does not provision Defender for Endpoint; licensing is the gating factor.
Why D is wrong: Roles control access to surfaced features, not whether unlicensed product features appear at all.
lock_openFree sampleManage Security and Threats by Using Microsoft Defender XDRmedium
A SOC analyst needs to view, but not modify, alert tuning rules and assigned incidents in the Microsoft Defender portal. Which Microsoft Entra ID built-in role grants the least privilege required?
- ASecurity Readercheck_circle Correct
- BSecurity Operator
- CSecurity Administrator
- DGlobal Reader
Apply the documented Microsoft 365 / Microsoft Entra ID behaviour to the scenario. Security Reader provides read-only access to security data and configuration in the Microsoft Defender portal, including viewing alert tuning rules and incident assignments.
Why A is correct: Correct. Security Reader provides read-only access to security data and configuration in the Microsoft Defender portal, including viewing alert tuning rules and incident assignments.
Why B is wrong: Security Operator allows acting on alerts and incidents; that exceeds read-only need.
Why C is wrong: Security Administrator can manage policies and is more than required for a viewer.
Why D is wrong: Global Reader is a broad cross-service read role and grants more than required for the Defender portal task.
lock_openFree sampleManage Security and Threats by Using Microsoft Defender XDRmedium
An analyst resolves an incident in the Microsoft Defender portal. What happens to the alerts that were linked to that incident?
- AAll linked active alerts are also resolved automatically.check_circle Correct
- BLinked alerts remain Active until each is closed manually.
- CLinked alerts are merged into a new resolved incident container.
- DOnly alerts from Defender for Office 365 in the incident are resolved.
Apply the documented Microsoft 365 / Microsoft Entra ID behaviour to the scenario. Resolving an incident also resolves all the linked and active alerts related to the incident.
Why A is correct: Correct. Resolving an incident also resolves all the linked and active alerts related to the incident.
Why B is wrong: Manual per-alert closure is not required; resolution cascades from incident to its alerts.
Why C is wrong: Resolution does not move alerts into a new container; they stay in the same incident.
Why D is wrong: The behaviour is not source-specific; all linked active alerts resolve regardless of source product.
lock_openFree sampleImplement and Manage Identity and Accessmedium
You need to turn on self-service password reset for a pilot group in the Microsoft Entra admin center. Which role grants the least privilege required to complete the configuration on the Password reset blade?
- AAssign the Authentication Policy Administrator role to the operator.check_circle Correct
- BAssign the Authentication Administrator role to the SSPR operator.
- CAssign the User Administrator role to the SSPR pilot operator.
- DAssign the Global Administrator role to the SSPR pilot operator.
Authentication Policy Administrator is the minimum role to enable SSPR via the Microsoft Entra admin center. The enable-SSPR tutorial states the configuring account needs at least the Authentication Policy Administrator role. That role can open Entra ID > Password reset and change Properties, Authentication methods, Registration, Notifications, and Customization without granting broader directory or user-management rights.
Why A is correct: Correct. The enable-SSPR tutorial states the configuring account needs at least the Authentication Policy Administrator role.
Why B is wrong: This role manages user authentication methods and credentials but does not own the tenant SSPR configuration on the Password reset blade.
Why C is wrong: User Administrator can manage users and reset passwords, but the SSPR enablement steps call out Authentication Policy Administrator as the minimum role.
Why D is wrong: Global Administrator works, but it is not the least-privileged role; the tutorial explicitly names Authentication Policy Administrator as the minimum.
lock_openFree sampleImplement and Manage Identity and Accesshard
Your tenant is on a 60-day-old Microsoft Entra ID P1 trial. Which conditions force the strong two-gate password reset policy onto administrator accounts? (Select 3 answers)
- AThe trial subscription has been active beyond 30 days under Microsoft Entra ID P1.check_circle Correct
- BA custom verified domain has replaced the onmicrosoft.com routing for the tenant.check_circle Correct
- CMicrosoft Entra Connect is actively syncing identities from on-premises AD.check_circle Correct
- DSelf-service password reset is scoped to a selected pilot group of users.
- EThe reconfirm interval on the Registration page is set to 730 days for the tenant.
Any one of trial>30 days, custom domain, or Entra Connect syncing forces two-gate admin SSPR. The administrator reset policy flips to two-gate when any one of three conditions is true: the trial has run beyond 30 days, a custom domain is configured, or Microsoft Entra Connect is synchronizing identities. Holding an affected admin role independently also enforces two-gate.
Why A is correct: Correct. The trial subscription has been active beyond 30 days under Microsoft Entra ID P1 is one of the keyed answers. The administrator reset policy flips to two-gate when any one of three conditions is true: the trial has run beyond 30 days, a custom domain is configured, or Microsoft Entra Connect is synchronizing identities.
Why B is correct: Correct. A custom verified domain has replaced the onmicrosoft.com routing for the tenant is one of the keyed answers. The administrator reset policy flips to two-gate when any one of three conditions is true: the trial has run beyond 30 days, a custom domain is configured, or Microsoft Entra Connect is synchronizing identities.
Why C is correct: Correct. Microsoft Entra Connect is actively syncing identities from on-premises AD is one of the keyed answers. The administrator reset policy flips to two-gate when any one of three conditions is true: the trial has run beyond 30 days, a custom domain is configured, or Microsoft Entra Connect is synchronizing identities.
Why D is wrong: Scoping SSPR to a Selected group only changes which users can register and reset; it does not flip the admin policy from one-gate to two-gate.
Why E is wrong: The reconfirm interval governs how often users re-verify their methods; it has no bearing on whether admins are forced onto the two-gate policy.
lock_openFree sampleImplement and Manage Identity and Accesshard
A compliance lead asks you to weaken the administrator SSPR policy so admins can use one method and security questions like end users. Configuring the SSPR Authentication methods page can relax the strong two-gate admin policy for your tenant. Is this statement correct?
- AYes
- BNocheck_circle Correct
The two-gate admin SSPR policy cannot be changed; admin SSPR can only be disabled wholesale via AllowedToUseSspr. The strong two-gate administrator policy enforces two pieces of authentication data and prohibits security questions, and the documentation states this policy cannot be changed. The user-facing Authentication methods page does not relax it.
Why A is wrong: Tenants that want admins out of SSPR entirely must set the AllowedToUseSspr tenant authorization-policy flag to false; that disables admin SSPR but still does not loosen the two-gate rules while they apply.
Why B is correct: Correct. The strong two-gate administrator policy enforces two pieces of authentication data and prohibits security questions, and the documentation states this policy cannot be changed.
lock_openFree sampleManage Compliance by Using Microsoft Purviewmedium
You are creating a custom sensitive information type in the Microsoft Purview portal to detect a proprietary employee ID format. You need to define the core element that triggers detection and an optional element that increases confidence when found nearby. Which two element categories must you configure?
- APrimary element and supporting elementcheck_circle Correct
- BDefault classifier and trainable classifier
- CAdaptive scope and policy filter
- DAuto-label condition and manual override
Apply the documented Microsoft 365 / Microsoft Entra ID behaviour to the scenario. When you create a custom SIT in Information Protection > Classifiers > Sensitive info types > Create sensitive info type, each pattern requires a Primary element and may include one or more Supporting elements, each with their own character proximity.
Why A is correct: Correct. When you create a custom SIT in Information Protection > Classifiers > Sensitive info types > Create sensitive info type, each pattern requires a Primary element and may include one or more Supporting elements, each with their own character proximity.
Why B is wrong: Trainable classifiers are a separate Purview content-classification mechanism; they are not components of a SIT pattern.
Why C is wrong: Adaptive scopes are used by retention and DLP policy targeting, not by SIT pattern definitions.
Why D is wrong: Auto-labelling consumes a SIT as a condition; it is not part of how the SIT itself is structured.
lock_openFree sampleManage Compliance by Using Microsoft Purviewhard
You author a regex for a custom SIT and include the anchors ^ and $ to bound the match. After deployment, the SIT behaves unpredictably across long documents. What does Microsoft Purview guidance say about this pattern?
- APositional regex anchors must not be used because the start and end of scanned content are not fixedcheck_circle Correct
- BAnchors are mandatory in custom SITs; the actual issue is character proximity which must be set to zero
- CThe Boost.Regex engine only requires positional anchors when the pattern uses a lookbehind clause
- DAnchors must be replaced with explicit word boundaries when working with double-byte character sets
Apply the documented Microsoft 365 / Microsoft Entra ID behaviour to the scenario. Microsoft's custom SIT guidance states explicitly: do not use positional regex anchors like ^ and $, because there are no guarantees about where in scanned content corresponds to the starting and ending anchors.
Why A is correct: Correct. Microsoft's custom SIT guidance states explicitly: do not use positional regex anchors like ^ and $, because there are no guarantees about where in scanned content corresponds to the starting and ending anchors.
Why B is wrong: Anchors are not mandatory; the guidance is the opposite, and proximity 0 does not solve the anchor ambiguity.
Why C is wrong: There is no such requirement; this misrepresents the engine's behaviour with custom SITs.
Why D is wrong: DBCS handling is a separate topic about word boundaries and spaces; it does not address the positional anchor problem.
lock_openFree sampleManage Compliance by Using Microsoft Purvieweasy
Microsoft Purview ships built-in sensitive information types for common patterns such as credit card numbers and national identifiers, which you can use directly in DLP and auto-labelling policies without first copying them. Is this statement correct?
- AYescheck_circle Correct
- BNo
Apply the documented Microsoft 365 / Microsoft Entra ID behaviour to the scenario. The keyed answer follows the documented behaviour. No would be incorrect because Microsoft Purview includes a large library of preconfigured (built-in) SITs that can be selected as conditions in DLP policies, auto-labelling policies, and Content Explorer without being copied. Copying is only required when you want to modify a built-in SIT into a custom variant.
Why A is correct: Correct. The keyed answer follows the documented behaviour.
Why B is wrong: No would be incorrect because Microsoft Purview includes a large library of preconfigured (built-in) SITs that can be selected as conditions in DLP policies, auto-labelling policies, and Content Explorer without being copied. Copying is only required when you want to modify a built-in SIT into a custom variant.
Examworthy is not affiliated with or endorsed by Microsoft. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. MS-102 and related marks belong to their respective owners.