EnglishDeutschFrançaisEspañolPortuguês

Microsoft · MS-102 · Expert

Microsoft 365 Administrator (MS-102) — Practice Questions and Mock Exam

Prepare for MS-102 with original practice questions and clear answer explanations. Ask Alex, your AI tutor, when you need more detail, use your results to identify topics to review, and practice your pacing with timed mock exams.

50Mock exam questions
100minTime limit
700/ 1000Passing score

Checked against Microsoft · August 2026 · Current exam version

About the exam

The MS-102 certification validates expertise in deploying and managing Microsoft 365 tenant services, including identity synchronization, security and compliance, and Microsoft 365 workload management. It covers Microsoft Entra ID configuration, Exchange Online, SharePoint Online, Teams administration, Microsoft Defender XDR, data loss prevention, and compliance solutions across the Microsoft 365 ecosystem.

This expert-level certification is designed for Microsoft 365 administrators who serve as the integrating hub for all Microsoft 365 workloads. Candidates should have working knowledge of networking, server administration, DNS, and Active Directory, along with experience managing Microsoft 365 tenants, identity, and security configurations.

Try five MS-102 questions

Try five practice questions from the app’s current Microsoft 365 Administrator question bank, with answers and explanations.

Implement and manage Microsoft Entra identity and access1 / 5

True or False: Microsoft Entra Conditional Access can evaluate device compliance status from Microsoft Intune as a condition for granting or blocking access.

AlexFull explanation from Alex

True. Microsoft Entra Conditional Access evaluates device compliance from Intune as a grant control. When 'Require device to be marked as compliant' is configured, Entra ID checks the device's Intune compliance status before granting access. Intune evaluates devices against compliance policies (encryption, OS version, antivirus) and reports status to Entra ID. Non-compliant or unregistered devices are blocked across Windows, iOS, Android, and macOS. Distractor: False is incorrect — this is a core Conditional Access + Intune integration. Ref: learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-grant

Sourcelearn.microsoft.com

Manage security and threats by using Microsoft Defender XDR2 / 5

You need to configure the Microsoft 365 Defender app connector for Microsoft 365 in Defender for Cloud Apps. What does this connector provide?

AlexFull explanation from Alex

The M365 app connector in Defender for Cloud Apps provides API-based visibility into Office 365 activities, files, and user accounts. It pulls audit logs from Exchange Online, SharePoint, OneDrive, and Teams via Microsoft Graph APIs for threat detection and policy enforcement. Distractors: Endpoint protection is Defender for Endpoint's role. Network traffic analysis uses network tools, not API connectors. Real-time session control requires Conditional Access App Control with a reverse proxy. App connectors operate at the API layer, polling activity data rather than intercepting traffic inline. Ref: learn.microsoft.com/en-us/defender-cloud-apps/protect-office-365

Sourcelearn.microsoft.com

Deploy and manage a Microsoft 365 tenant3 / 5

You need to restrict who can create Microsoft 365 groups and Teams in your tenant. What should you configure?

AlexFull explanation from Alex

By default, users can create Microsoft 365 groups and Teams. If the organization must restrict creation, admins configure Microsoft 365 group creation so only members of a specified group can create groups. This control affects Microsoft Teams and other group-backed services. A Teams policy controls Teams features, a naming policy controls names, and Conditional Access controls sign-in and access conditions.

Sourcelearn.microsoft.com

Manage compliance by using Microsoft Purview4 / 5

You need to monitor how sensitivity labels are being used across your organization. Which Microsoft Purview tool shows the volume and distribution of labeled content across Exchange, SharePoint, and OneDrive?

AlexFull explanation from Alex

Content Explorer shows a current snapshot of items with sensitivity labels, retention labels, or sensitive information types across Exchange, SharePoint, and OneDrive (learn.microsoft.com/purview/data-classification-content-explorer). Admins can drill down to specific items and locations. Why others are wrong: Activity Explorer tracks actions performed on labeled content (label applied, changed, removed, files shared) rather than content inventory. The DLP alerts dashboard shows policy violations, not label distribution. Compliance Manager tracks regulatory compliance posture against frameworks, not labeled content. Requires Content Explorer List Viewer or Content Viewer roles. Exam tip: Content Explorer = what is labeled and where; Activity Explorer = what actions were taken on labeled content.

Sourcelearn.microsoft.com

Implement and manage Microsoft Entra identity and access5 / 5

You need to choose between Microsoft Entra Connect Sync and Microsoft Entra Cloud Sync for identity synchronization. Your organization has a single Active Directory forest with 50,000 users and requires pass-through authentication. Which solution should you choose?

AlexFull explanation from Alex

Connect Sync is required because Cloud Sync does not support pass-through authentication (PTA). Microsoft's feature comparison confirms PTA Config: Connect Sync ✓, Cloud Sync ✗. Cloud Sync is lightweight and cloud-managed, ideal for disconnected forests but lacks PTA, device sync, ADFS integration, and advanced sync rules. Distractors: Cloud Sync cannot fulfill the PTA requirement. Manual Graph API provisioning doesn't support PTA. 'Either solution' is wrong since Cloud Sync explicitly lacks PTA. Ref: learn.microsoft.com/en-us/entra/identity/hybrid/cloud-sync/connect-to-cloud-sync-decision-guide

Sourcelearn.microsoft.com

429 practice questions

The Pass-IT question pool gives you material to practice for MS-102. A Pass-IT mock exam uses 50 questions and a 100-minute time limit; these are practice settings.

Pool details: MS-102

Exam details checked against MicrosoftAugust 28, 2026

date of the last check against the official Microsoft source

Passing score700 / 1,000

as published by Microsoft

Objectives in the guide66 objectives listed in the official guide

across 4 domains in the official exam guide

Pool size429 questions

= The pool size is equivalent to 8 sets of 50 questions; this does not mean that each mock exam uses a separate set.

Blueprint domains4 domains in the exam blueprint

Deploy and manage a Microsoft 365 tenant 114 · Implement and manage Microsoft Entra identity and access 121 · Manage security and threats by using Microsoft Defender XDR 128 · Manage compliance by using Microsoft Purview 66

Recorded as checked against sources429 of 429

questions recorded as having their answer, options, and explanation checked against official Microsoft documentation

What's on the exam

Managing security and threats with Microsoft Defender XDR is the largest area at 30–35%, covering incidents and advanced hunting, Defender for Office 365 threat policies and attack simulations, Defender for Endpoint onboarding and vulnerability management, and Defender for Cloud Apps. Tenant administration and Entra identity and access follow at 25–30% each; compliance with Microsoft Purview closes the guide at 10–15%.

Two-thirds of the exam is therefore security and identity rather than tenant setup, which is where administrators who learned Microsoft 365 through the admin center tend to lose points. Purview is the smallest area but not a rounding error: sensitivity and retention labels plus DLP across Exchange, SharePoint, OneDrive, Teams and endpoints can still account for as much as one question in seven.

Exam blueprint: MS-102

Deploy and manage a Microsoft 365 tenant25–30%

Implement and manage a Microsoft 365 tenant, manage users and groups, and manage roles and role groups

≈ 15 h
Implement and manage Microsoft Entra identity and access25–30%

Implement and manage identity synchronization, implement and manage authentication, and implement and manage secure access

≈ 15 h
Manage security and threats by using Microsoft Defender XDR30–35%

Review and respond to security reports and alerts, implement email and collaboration protection, implement endpoint protection, and implement and manage Microsoft Defender for Cloud Apps

≈ 18 h
Manage compliance by using Microsoft Purview10–15%

Implement information protection and data lifecycle management, and implement data loss prevention (DLP)

≈ 7 h

Exam format and question types

The exam consists of 40–60 questions to be completed in 100 minutes. Question types include multiple-choice, multiple-select, drag-and-drop, hot area, and case study formats. Questions span the entire Microsoft 365 ecosystem including identity, security, compliance, and workload management. Budget extra time for case studies that present complex multi-tenant administration scenarios.

Question types: MS-102

Multiple Choice41%

Select the single answer that best meets the question’s requirements.

Drag & Drop17%

Move items into the slots, groups, or sequence specified by the task.

Ordering11%

Arrange the steps in the sequence needed to complete the process.

Multiple Response11%

Select multiple answers. Follow the question’s instructions on how many to choose.

Dropdown11%

Choose options from dropdown menus to complete a statement or configuration.

True / False9%

Decide whether a statement is true or false, paying attention to its conditions and wording.

See Microsoft for official question-format information. The shares shown describe the Pass-IT practice pool; they do not establish the proportions on the official exam.

Preparing for MS-102

Delivered via Pearson VUE online or at testing centers. Available in English, German, French, Spanish, Portuguese, Japanese, and Chinese. The certification is valid for 1 year with a free renewal assessment on Microsoft Learn. Microsoft retires this exam and the Microsoft 365 Certified: Administrator Expert certification on 31 October 2026.

Preparation and logistics: MS-102

Preparation

Illustrative study time35–85 h

illustrative planning range: 35 h with relevant experience to 85 h when starting out; your needs may fall outside this range

LevelExpert

Taking and maintaining the certification

DeliveryPearson VUE online proctored or at authorized testing centers worldwide
Retake policy24-hour wait after the first attempt, 14 days between subsequent attempts, maximum 5 attempts per exam within a 12-month period
Certification validity1 year

Free renewal assessment on Microsoft Learn, available starting 6 months before expiration. Must be completed before the certification expires.

Common pitfalls

Topics to review: MS-102

  1. 01Identity Sync

    Not understanding Microsoft Entra Connect, cloud sync, and hybrid identity configurations including pass-through authentication.

  2. 02Threat Protection

    Confusing Microsoft Defender for Office 365, Defender for Endpoint, and Defender for Identity capabilities and configurations.

  3. 03DLP Policies

    Struggling with Data Loss Prevention policy creation, sensitive information types, and DLP rules across Microsoft 365 workloads.

  4. 04Compliance Features

    Overlooking retention policies, sensitivity labels, eDiscovery, and information barriers across Exchange, SharePoint, and Teams.

  5. 05Tenant Management

    Not knowing organizational settings, domain management, and Microsoft 365 subscription and license management details.

Frequently asked questions

How long is the Microsoft 365 Administrator exam?

The MS-102 exam has 50 questions and a 100-minute time limit.

What is the passing score for Microsoft 365 Administrator?

The passing score for the MS-102 exam is 700 / 1000.

Which pitfalls should I review when preparing for Microsoft 365 Administrator?

Topics to review include Identity Sync, Threat Protection, DLP Policies, Compliance Features, Tenant Management. Work through examples to check that you understand the distinctions and can explain your answer.

Is MS-102 being retired?

Yes. The exam stops being offered after 30 November 2026. A certification you have already earned stays valid for its normal term, but if you are planning a first attempt you have a fixed window rather than an open one.

How often do you renew MS-102?

Every year, through the free renewal assessment on Microsoft Learn, which opens six months before expiry. That renewal path is unaffected by the exam itself being withdrawn for new candidates.

Which MS-102 topics carry the most marks?

Managing security and threats with Microsoft Defender XDR is the heaviest area at roughly 32%, with tenant deployment and Entra identity and access at about 28% each. Purview compliance makes up the remaining 12%. Nearly a third of the exam is therefore Defender XDR.

What happens if you fail MS-102?

You can retake after 24 hours, then after 14 days for subsequent attempts, up to five per 12-month period. With the exam retiring at the end of November 2026, those waits eat into a closing window.

One certification, 12 months

Practice for MS-102

Focus your practice on one certification, or choose Pro to practice across all certifications.

Start a free practice sessionTry the first 20 questions without a card to see whether the practice suits you.

For eligible purchases: money-back guarantee if you fail your exam.

View guarantee terms →