๐ŸŽ„

CertoMetrics - 9% OFF Special Discount Offer - Ends In:

0d 00h 00m 00s
Coupon code: SALE2026

Microsoft 365 Administrator (MS-102)

Get full access to the updated question bank and confidently prepare for your exam.

Vendor

Microsoft

Certification

Modern Work

Content

341 Qs

Status

Verified

Updated

4 days ago

Test the Practice Engine

Experience our interactive testing environment with free demo questions

Launch Free Demo
Best Value Bundle

Premium Bundle

Complete Success Suite

$68 $59

Save $9 Instantly

  • โœ“
    Full PDF + Interactive Engine Everything you need to pass
  • โœ“
    All Advanced Question Types Drag & Drop, Hotspots, Case Studies
  • โœ“
    Priority 24/7 Expert Support Direct line to certification leads
  • โœ“
    90 Days Free Priority Updates Stay current as exams change

Success Metric

98.4% Pass Rate

Verified by 15k+ Students
Secure Checkout
Popular

Standard Simulation

Practice Engine

$39

One-Time Payment

  • Web-Based (Zero Install)
  • Real Testing Environment Virtual & Practice Modes
  • Interactive Engine Drag & Drop, Hotspots
  • 60 Days Free Updates

Compatible with All Devices

Chrome
Verified Secure Checkout

Basic Tier

PDF Study Guide

$29

Digital Access

  • โœ“ Exam Questions (PDF)
  • โœ“ Mobile Friendly
  • โœ“ 60 Days Updates
Download Free Sample PDF

Verified 69-Question Preview (MS-102)

Secure Checkout

Verified Community

The CertoMetrics Standard.

Recommend the #1 platform for verified Microsoft certification resources.

Success Network

Help a Colleague Succeed.

Invite a peer to get their own updated MS-102 prep kit.

Exam Overview

The Microsoft 365 Administrator (MS-102) exam is a pivotal step for IT professionals aiming to validate their expertise in managing and optimizing Microsoft 365 environments. This certification signifies a deep understanding of deploying, configuring, and maintaining the full suite of Microsoft 365 services, including identity, security, compliance, and tenant management. Earning the Microsoft 365 Certified: Administrator Expert credential, for which MS-102 is a core requirement, demonstrates your ability to drive organizational productivity, enhance collaboration, and ensure robust data protection. It's an invaluable credential for career advancement, proving your capability to lead and implement strategic cloud initiatives within complex enterprise settings, making you an indispensable asset in today's digital workforce.

Questions

40-60

Passing Score

700/1000

Duration

120 Minutes

Difficulty

Expert

Level

Expert

Skills Measured

Implement and Manage Microsoft 365 Governance and Compliance
Implement and Manage Microsoft 365 Identities and Access
Manage Microsoft 365 Services and Tenant Health
Implement and Manage Microsoft 365 Threat Protection
Plan and Implement Microsoft 365 Migration

Career Path

Target Roles

Microsoft 365 Administrator Enterprise Administrator Cloud Administrator

Common Questions

Is the material up to date?

Yes. We update our question bank weekly to match the latest Microsoft standards. You get free updates for 90 days.

What format do I get?

You get instant access to both the **PDF** (for reading) and our **Premium Test Engine** (for exam simulation).

Is there a guarantee?

Absolutely. If you fail the MS-102 exam using our materials, we offer a full money-back guarantee.

When do I get the download?

Instantly. The download link is available in your dashboard immediately after payment is confirmed.

Free Study Guide Samples

Previewing updated MS-102 bank (69 Questions).

QUESTION 1

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1 and the users shown in the following table.

 

 

The devices are configured as shown in the following table.

 

 

You have a Conditional Access policy named CAPolicy1 that has the following settings:

Assignments -

Users or workload identities: Group1

Cloud apps or actions: Office 365 SharePoint Online

Conditions -

Filter for devices: Exclude filtered devices from the policy

Rule syntax: device.displayName -startsWith "Device"

Access controls -

Grant -

Grant: Block access -

Session: 0 controls selected -

Enable policy: On -

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Answer Canvas

Official explanation included in the full bundle.

QUESTION 2

You need to configure Microsoft Entra Connect Sync to support the planned changes for the Montreal Users and Seattle Users OUs.

What should you do?

A
From PowerShell, run the Start-ADSyncSyncCycle cmdlet.
B
From Microsoft Entra Connect Sync, select Manage federation.
C
From Microsoft Entra Connect Sync, select Customize synchronization options.
D
From PowerShell, run the Add-ADSyncConnectorAttributeInc1usion cmdlet.

Correct Option: C

QUESTION 3

You have a Microsoft 365 E5 subscription.

Conditional Access is configured to block high-risk sign-ins for all users.

All users are in France and are registered for multi-factor authentication (MFA).

Users in the media department will travel to various countries during the next month.

You need to ensure that if the media department users are blocked from signing in while traveling, the users can remediate the issue without administrator intervention.

What should you configure?

A
an exclusion group
B
the MFA registration policy
C
named locations
D
self-service password reset (SSPR)

Correct Option: D

QUESTION 4

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365.

You need to create a policy that will quarantine messages containing attachments that match .apk and .appx extensions.

Which type of policy should you configure?

A
Safe Attachments
B
anti-malware
C
anti-spam

Correct Option: B

QUESTION 5

You have a Microsoft 365 E5 subscription that contains the following user:

Name: User1 -

UPN: user1@contoso.com -

Email address: user1@marketmg.contoso.com

MFA enrollment status: Disabled -

When User1 attempts to sign in to Outlook on the web by using the user1@marketing.contoso.com email address, the user cannot sign in.

You need to ensure that User1 can sign in to Outlook on the web by using user1@marketing.contoso.com.

What should you do?

A
Assign an MFA registration policy to User1.
B
Reset the password of User1.
C
Add an alternate email address for User1.
D
Modify the UPN of User1.

Correct Option: D

QUESTION 6

You have a Microsoft 365 subscription that uses a third-party multifactor authentication (MFA) product.

While reviewing Microsoft Secure Score, you discover that there are no points listed for the Ensure multifactor authentication is enabled for all users recommendation.

You need to ensure that you receive all the points for the recommendation. The solution must minimize administrative effort

What should you do?

A
Deploy a Microsoft Defender for Identity sensor.
B
Configure a data connector.
C
Modify the status of the recommendation.
D
Modify the recommendation tags.

Correct Option: C

QUESTION 7

Your network contains an Active Directory domain named fabrikam.com. The domain contains the objects shown in the following table.

 

 

The groups have the members shown in the following table.

 

 

You are configuring synchronization between fabrikam.com and an Azure AD tenant.

You configure the Domain/OU Filtering settings in Azure AD Connect as shown in the Domain/OU Filtering exhibit (Click the Domain/OU Filtering tab.)

You configure the Filtering settings in Azure AD Connect as shown in the Filtering exhibit. (Click the Filtering tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

 

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Answer Canvas

Official explanation included in the full bundle.

QUESTION 8

You have a Microsoft 365 E5 subscription that contains a group named Groupl. The subscription uses Microsoft Defender for Cloud Apps.

You configure cloud discovery.

You need to ensure that you can create a custom report that details shadow IT usage by the members of Groupl.

What should you do first?

A
Configure user enrichment.
B
Disable anonymization.
C
Configure user monitoring.
D
Add an app connector.

Correct Option: A

QUESTION 9

You have a Microsoft 365 E5 subscription.

From Azure AD Identity Protection on August 1, you configure a Multifactor authentication registration policy that has the following settings:

Assignments: All users -

Controls: Require Azure AD multifactor authentication registration

Enforce Policy: On -

On August 3, you create two users named User1 and User2.

Users authenticate by using Azure Multi-Factor Authentication (MFA) for the first time on the dates shown in the following table.

 

 

By which dates will User1 and User2 be forced to complete their Azure MFA registration? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Answer Canvas

Official explanation included in the full bundle.

QUESTION 10

Your company has a Microsoft Entra tenant named contoso.com and a Microsoft 365 subscription.

All users use Windows 1 1 devices to access Microsoft 365 apps.

All the devices are in a workgroup.

You plan to implement passwordless sign-in to contoso.com.

You need to recommend changes to the infrastructure for the planned implementation.

What should you include in the recommendation?

A
Deploy the Microsoft Authenticator app.
B
Deploy Microsoft Entra Application Proxy.
C
Deploy the Microsoft Entra provisioning agent.
D
Join all the devices to contoso.com.

Correct Option: D

QUESTION 11

Your on-premises network contains an Active Directory domain.

You have a Microsoft 365 subscription.

You need to sync the domain with the subscription. The solution must meet the following requirements:

On-premises Active Directory password complexity policies must be enforced.

Users must be able to use self-service password reset (SSPR) in Azure AD.

What should you use?

A
password hash synchronization
B
Azure AD Identity Protection
C
Azure AD Seamless Single Sign-On (Azure AD Seamless SSO)
D
pass-through authentication

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 12

You have a Microsoft 365 E5 subscription that has Microsoft Defender for Endpoint integrated with Microsoft Intune. Devices are enrolled to Microsoft Intune and onboarded to Microsoft Defender for Endpoint.

You plan to block devices based on the results of the machine risk score calculated by Microsoft Defender for Endpoint.

What should you create first?

A
a device compliance policy
B
an endpoint detection and response policy
C
a device configuration policy

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 13

You have a Microsoft 365 E5 subscription.

Users access Microsoft 365 from both their laptop and a corporate Virtual Desktop Infrastructure (VDI) solution.

From Azure AD Identity Protection, you enable a sign-in risk policy.

Users report that when they use the VDI solution, they are regularly blocked when they attempt to access Microsoft 365.

What should you configure?

A
the Tenant restrictions settings in Azure AD
B
a trusted location
C
a Conditional Access policy exclusion
D
the Microsoft 365 network connectivity settings

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 14

You have a Microsoft 365 E5 subscription that contains a user named Userl and the administrators shown in the following table.

 

 

User1 reports that after sending 1,000 email messages in the morning. the user is blocked from sending additional emails.

You need to identify the following:

โ€ข Which administrators can unblock Userl

โ€ข What to configure to allow Userl to send at least 2,000 emails per day without being blocked

What should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 15

You have a Microsoft 365 E5 subscription that contains a user named User1.

Azure AD Password Protection is configured as shown in the following exhibit.

 

 

User1 attempts to update their password to the following passwords:

F@lcon -

Project22 -

T4il$pin45dg4 -

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 16

You have a hybrid deployment of Microsoft 365 that contains the users shown in the following table.

Azure AD Connect has the following settings:

Password Hash Sync: Enabled -

Pass-through authentication: Enabled

You need to identify which users will be able to authenticate by using Azure AD if connectivity between on-premises Active Directory and the internet is lost.

Which users should you identify?

A
none
B
User1 only
C
User1 and User2 only
D
User1, User2, and User3

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 17

Your network contains an on-premises Active Directory domain named contoso.com.

For all user accounts, the Logon Hours settings are configured to prevent sign-ins outside of business hours.

You plan to sync contoso.com to an Azure AD tenant

You need to recommend a solution to ensure that the logon hour restrictions apply when synced users sign in to Azure AD.

What should you include in the recommendation?

A
pass-through authentication
B
conditional access policies
C
password synchronization
D
Azure AD Identity Protection policies

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 18

Your network contains three Active Directory forests. There are forests trust relationships between the forests.

You create an Azure AD tenant.

You plan to sync the on-premises Active Directory to Azure AD.

You need to recommend a synchronization solution. The solution must ensure that the synchronization can complete successfully and as quickly as possible if a single server fails.

What should you include in the recommendation?

A
one Azure AD Connect sync server and one Azure AD Connect sync server in staging mode.
B
three Azure AD Connect sync servers and one Azure AD Connect sync server in staging mode.
C
six Azure AD Connect sync servers and three Azure AD Connect sync servers in staging mode.
D
three Azure AD Connect sync servers and three Azure AD Connect sync servers in staging mode.

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 19

You have a Microsoft 365 subscription.

You have the retention policies shown in the following table.

Both policies are applied to a Microsoft SharePoint site named Site1 that contains a file named File1.docx.

File1.docx was created on January 1, 2022 and last modified on January 31,2022. The file was NOT modified again.

When will File1.docx be deleted automatically?

A
January 1, 2023
B
January 1, 2024
C
January 31, 2023
D
January 31, 2024
E
never

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 20

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.

You plan to publish a sensitivity label named Label1.

To which groups can you publish Label1?

A
Group1 only
B
Group1 and Group2 only
C
Group1 and Group4 only
D
Group1, Group2, and Group3 only
E
Group1, Group2, Group3, and Group4

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 21

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint site named Site1 and a data loss prevention (DLP) policy named DLP1. DLP1 contains the rules shown in the following table.

 

Site1 contains the files shown in the following table.

 

 

 

Which policy tips are shown for each file? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 22

You have a Microsoft 365 subscription.

You configure a data loss prevention (DLP) policy.

You discover that users are incorrectly marking content as false positive and bypassing the DLP policy.

You need to prevent the users from bypassing the DLP policy.

What should you configure?

A
actions
B
incident reports
C
exceptions
D
user overrides

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 23

You have a Microsoft 365 E5 tenant.

You create a retention label named Retention1 as shown in the following exhibit.

When users attempt to apply Retention1, the label is unavailable.

You need to ensure that Retention1 is available to all the users.

What should you do?

A
Create a new label policy.
B
Modify the Authority type setting for Retention1.
C
Modify the Business function/department setting for Retention1.
D
Use a file plan CSV template to import Retention1.

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 24

You have a Microsoft 365 E5 subscription that has published sensitivity labels shown in the following exhibit.

Which labels can users apply to content?

A
Label1, Label2, and Label5 only
B
Label3, Label4, and Label6 only
C
Label1, Label3, Label4, and Label6 only
D
Label1, Label2, Label3, Label4, Label5, and Label6

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 25

Your company has a Microsoft 365 E5 tenant

Users at the company use the following versions of Microsoft Office:

  • Microsoft 365 Apps for enterprise
  • Office for the web -
  • Office 2016 -
  • Office 2019 -

The company currently uses the following Office file types:

  • .docx
  • .xlsx
  • .doc
  • .xls

You plan to use sensitivity labels.

You need to identify the following:

Which versions of Office require an add-in to support the sensitivity labels.

Which file types support the sensitivity labels.

What should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 26

You have a Microsoft 365 tenant.

You create a retention label as shown in the Retention Label exhibit. (Click the Retention Label tab.)

 

You create a label policy as shown in the Label Policy exhibit. (Click the Label Policy tab.)

 

 

The label policy is configured as shown in the following table.

 

 

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

 

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 27

You have a Microsoft 365 subscription.

Your company has a customer ID associated to each customer. The customer IDs contain 10 numbers followed by 10 characters. The following is a sample customer ID: 12-456-7890-abc-de-fghij.

You plan to create a data loss prevention (DLP) policy that will detect messages containing customer IDs.

What should you create to ensure that the DLP policy can detect the customer IDs?

A
a PowerShell script
B
a sensitivity label
C
a sensitive information type
D
a retention label

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 28

You have a Microsoft 365 E5 subscription.

You define a retention label that has the following settings:

Retention period: 7 years -

Start the retention period based on: When items were created

You need to prevent the removal of the label once the label is applied to a file.

What should you select in the retention label settings?

A
Retain items forever or for a specific period
B
Mark items as a regulatory record
C
Mark items as a record
D
Retain items even if users delete

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 29

You configure a data loss prevention (DLP) policy named DLP1 with a rule configured as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

 

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 30

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the users shown in the following table.

The domain syncs to an Azure AD tenant named contoso.com as shown in the exhibit. (Click the Exhibit tab.)

User2 fails to authenticate to Azure AD when signing in as user2@fabrikam.com.

You need to ensure that User2 can access the resources in Azure AD.

Solution: From the on-premises Active Directory domain, you assign User2 the Allow logon locally user right. You instruct User2 to sign in as user2@fabrikam.com.

Does this meet the goal?

A
Yes
B
No

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 31

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 E5 subscription.

You create an account for a new security administrator named SecAdmin1.

You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive.

Solution: From the Microsoft 365 admin center, you assign SecAdmin1 the SharePoint Administrator role.

Does this meet the goal?

A
Yes
B
No

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 32

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 E5 subscription.

You create an account for a new security administrator named SecAdmin1.

You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive.

Solution: From the Microsoft Entra admin center, you assign SecAdmin1 the Security Administrator role.

Does this meet the goal?

A
Yes
B
No

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 33

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 E5 subscription.

You create an account for a new security administrator named SecAdmin1.

You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive.

Solution: From the Microsoft 365 admin center, you assign SecAdmin1 the Exchange Administrator role.

Does this meet the goal?

A
Yes
B
No

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 34

You need to configure the Office 365 service status notifications and limit access to the service and feature updates. The solution must meet the technical requirements.

What should you configure in the Microsoft 365 admin center? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 35

You need to configure Azure AD Connect to support the planned changes for the Montreal Users and Seattle Users OUs.

What should you do?

A
From PowerShell, run the Add-ADSyncConnectorAttributeInclusion cmdlet.
B
From the Microsoft Azure AD Connect wizard, select Manage federation.
C
From the Microsoft Azure AD Connect wizard, select Customize synchronization options.
D
From PowerShell, run the Start-ADSyncSyncCycle cmdlet.

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 36

You are evaluating the required processes for Project1.

You need to recommend which DNS record must be created while adding a domain name for the project.

Which DNS record should you recommend?

A
B
alias (CNAME)
C
text (TXT)
D
host (AAAA)

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 37

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 E5 subscription.

You create an account for a new security administrator named SecAdmin1.

You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive.

Solution: From the Microsoft 365 admin center, you assign SecAdmin1 the Teams Administrator role.

Does this meet the goal?

A
Yes
B
No

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 38

Your network contains an on-premises Active Directory domain named contoso.com.

Your company purchases Microsoft 365 subscription and establishes a hybrid deployment of Azure AD by using password hash synchronization. Password writeback is disabled in Azure AD Connect.

You create a new user named User10 on-premises and a new user named User20 in Azure AD.

You need to identify where an administrator can reset the password of each new user.

What should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 39

You have an Azure AD tenant that contains the groups shown in the following exhibit.

 

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 40

You have a Microsoft 365 E5 subscription that is linked to an Azure AD tenant named contoso.com.

You purchase 100 Microsoft 365 Business Voice add-on licenses.

You need to ensure that the members of a group named Voice are assigned a Microsoft 365 Business Voice add-on license automatically.

What should you do?

A
From the Licenses page of the Microsoft 365 admin center, assign the licenses.
B
From the Microsoft Entra admin center, modify the settings of the Voice group.
C
From the Microsoft 365 admin center, modify the settings of the Voice group.

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 41

You have a Microsoft 365 E5 subscription that uses Endpoint security.

You need to create a group and assign the Endpoint Security Manager role to the group. Which type of group can you use?

A
Microsoft 365 only
B
security only
C
mail-enabled security and security only
D
mail-enabled security, Microsoft 365, and security only
E
distribution, mail-enabled security, Microsoft 365, and security

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 42

You have a Microsoft 365 subscription that contains the users shown in the following table.

You create a new administrative unit named AU1 and configure the following AU1 dynamic membership rule. (user.department -eq "Engineering") and (user.jobTitle -notContains "Executive")

The subscription contains the role assignments shown in the following table.

 

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 43

You have a Microsoft 365 subscription.

You need to be notified to your personal email address when a Microsoft Exchange Online service issue occurs.

What should you do?

A
From the Exchange admin center, create a contact.
B
From the Microsoft Outlook client, configure an Inbox rule.
C
From the Microsoft 365 admin center, update the technical contact details.
D
From the Microsoft 365 admin center, customize the Service health settings.

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 44

Your company has an Azure AD tenant that contains the users shown in the following table.

 

The tenant includes a security group named Admin1. Admin1 will be used to manage administrative accounts. External collaboration settings have default configuration.

You need to identify which users can perform the following administrative tasks:

โ€ข Create guest user accounts.

โ€ข Add User3 to Admin1.

Which users should you identify for each task? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 45

You have a Microsoft 365 subscription.

All users are assigned Microsoft 365 Apps for enterprise licenses.

You need to ensure that reports display the names of users that have activated Microsoft 365 apps and on how many devices.

What should you modify in the Microsoft 365 admin center?

A
the Reports reader role
B
Organization information
C
Org settings for Privacy profile
D
Org settings for Reports

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 46

You have a Microsoft 365 E5 subscription.

You need to configure the Org settings to meet the following requirements:

โ€ข Sign users out of Microsoft Office 365 web apps after one hour of inactivity.

โ€ข Integrate an internal support tool with Office.

Which settings should you configure for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 47

You have a Microsoft 365 subscription.

You add a domain named contoso.com.

When you attempt to verify the domain, you are prompted to send a verification email to admin@contoso.com.

You need to change the email address used to verify the domain.

What should you do?

A
Add a TXT record to the DNS zone of the domain.
B
From the domain registrar, modify the contact information of the domain.
C
From the Microsoft 365 admin center, change the global administrator of the Microsoft 365 subscription.
D
Modify the NS records for the domain.

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 48

Your company uses Microsoft Defender for Endpoint. Microsoft Defender for Endpoint contains the device groups shown in the following table.

 

You onboard computers to Microsoft Defender for Endpoint as shown in the following table.

 

 

Of which groups are Computer1 and Computer2 members? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 49

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

 

 

You are implementing Microsoft Defender for Endpoint.

You need to enable role-based access control (RBAC) to restrict access to the Microsoft 365 Defender portal.

Which users can enable RBAC, and which users will no longer have access to the Microsoft 365 Defender portal after RBAC is enabled? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 50

Your company has a Microsoft 365 ES subscription.

You onboard a device on the company's network to Microsoft Defender for Endpoint.

In the Microsoft 365 Defender portal, you notice that the device inventory displays many devices that have an Onboarding status of Can be onboarded.

You need to ensure that onboarded devices are prevented from polling the network for device discovery but can still discover devices with

they communicate directly.

What should you configure in the Microsoft 365 Defender portal?

A
standard discovery
B
device discovery exclusions
C
basic discovery
D
a network assessment job

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 51

You have a Microsoft 365 E5 subscription that uses Microsoft Intune and contains the devices shown in the following table.

 

You need to onboard Device1 and Device2 to Microsoft Defender for Endpoint.

What should you use to onboard each device? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 52

You have a Microsoft 365 subscription.

You need to create two groups named Group1 and Group2. The solution must meet the following requirements:

โ€ข Group1 must be mail-enabled and have an associated Microsoft SharePoint Online site.

โ€ข Group2 must support dynamic membership and role assignments but must NOT be mail-enabled.

Which types of groups should you create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 53

You have a Microsoft 365 subscription.

You need to meet the following requirements:

โ€ข Report a Microsoft 365 service issue.

โ€ข Request help on how to add a new user to an Azure AD tenant.

What should you use in the Microsoft 365 admin center? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 54

You have a Microsoft 365 E5 subscription that contains the groups shown in the following exhibit.

To which groups can you assign Microsoft 365 E5 licenses?

A
Group1 and Group2 only
B
Group2 and Group3 only
C
Group3 and Group4 only
D
Group1, Group2, and Group3 only
E
Group2, Group3, and Group4 only

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 55

You have a Microsoft 365 subscription.

From the Microsoft 365 admin center, you open the Microsoft 365 Apps usage report as shown in the following exhibit.

 

 

You need ensure that the report meets the following requirements:

โ€ข The Username column must display the actual name of each user.

โ€ข Usage of the Microsoft Teams mobile app must be displayed.

What should you modify for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 56

Your company has on-premises servers and an Azure AD tenant.

Several months ago, the Azure AD Connect Health agent was installed on all the servers. You review the health status of all the servers regularly.

Recently, you attempted to view the health status of a server named Server1 and discovered that the server is NOT listed on the Azure AD Connect Servers list.

You suspect that another administrator removed Server1 from the list. You need to ensure that you can view the health status of Server1.

What are two possible ways to achieve the goal? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A
From Windows PowerShell, run the Register-AzureADConnectHealthSyncAgent cmdlet.
B
From Azure Cloud shell, run the Connect-AzureAD cmdlet.
C
From Server1, reinstall the Azure AD Connect Health agent.
D
From Server1, change the Azure AD Connect Health services Startup type to Automatic.
E
From Server1, change the Azure AD Connect Health services Startup type to Automatic (Delayed Start).

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 57

Your company has an Azure AD tenant named contoso.onmicrosoft.com.

You purchase a domain named contoso.com from a registrar and add all the required DNS records.

You create a user account named User1. User1 is configured to sign in as user1@contoso.onmicrosoft.com. You need to configure User1 to sign in as user1@contoso.com.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 58

You have a Microsoft 365 E5 subscription that uses Microsoft Intune.

You need to access service health alerts from a mobile phone.

What should you use?

A
the Microsoft Authenticator app
B
the Microsoft 365 Admin mobile app
C
Intune Company Portal
D
the Intune app

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 59

Your company has a Microsoft 365 subscription that contains the domains shown in the following exhibit.

 

 

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 60

You have a Microsoft 365 subscription.

You need to review reports to identify the following:

โ€ข The storage usage of files stored in Microsoft Teams

โ€ข The number of active users per team

Which report should you review for each requirement? To answer, drag the appropriate reports to the correct requirements. Each report may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 61

You work at a company named Contoso, Ltd.

Contoso has a Microsoft 365 subscription that is configured to use the DNS domains shown in the following table.

 

 

Contoso purchases a company named Fabrikam, Inc.

Contoso plans to add the following domains to the Microsoft 365 subscription:

โ€ข fabrikam.com

โ€ข east.fabrikam.com

โ€ข west.contoso.com

You need to ensure that the devices in the new domains can register by using Autodiscover.

How many domains should you verify, and what is the minimum number of enterprise registration DNS records you should add? To answer, select the appropriate options in the answer area.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 62

You have a Microsoft 365 E5 subscription.

You need to recommend a solution for monitoring and reporting application access. The solution must meet the following requirements:

โ€ข Support KQL for querying data.

โ€ข Retain report data for at least one year.

What should you include in the recommendation?

A
a security report in Microsoft 365 Defender
B
Endpoint analytics
C
Microsoft 365 usage analytics
D
Azure Monitor workbooks

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 63

You have a Microsoft 365 E5 subscription.

You need to configure a group naming policy.

Which portal should you use, and to which types of groups will the policy apply?

To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 64

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.

 

Which groups can be members of Group1 and Group4? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 65

Your company has a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com that includes the users shown in the following table.

Group2 is a member of Group1.

You assign a Microsoft Office 365 Enterprise E3 license to Group1. How many Office 365 E3 licenses are assigned?

A
1
B
2
C
3
D
4

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 66

You have a Microsoft 365 subscription that contains the administrative units shown in the following table.

 

 

The groups contain the members shown in the following table.

 

 

The users are assigned the roles shown in the following table.

 

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 67

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

Which users can review the Adoption Score in the Microsoft 365 admin center?

A
User1 only
B
User2 only
C
User1 and User2 only
D
User1 and User3 only
E
User1, User2, and User3

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 68

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.

 

 

The subscription contains the users shown in the following table.

 

 

In Azure AD, you configure the External collaboration settings as shown in the following exhibit.

 

 

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

QUESTION 69

You have a Microsoft 365 E5 subscription.

You have an Azure AD tenant named contoso.com that contains the following users:

โ€ข Admin1

โ€ข Admin2

โ€ข User1

Contoso.com contains an administrative unit named AU1 that has no role assignments.

User1 is a member of AU1.

You create an administrative unit named AU2 that does NOT have any members or role assignments.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 341 answers & explanations

Full Question Bank Locked

You have reached the end of the free study guide preview. Upgrade now to unlock all 341 questions and the full simulation engine.

Customer Reviews

5 / 5
(15,000+ verified)
5
100%
4
0%
3
0%
2
0%
1
0%

Global Community Feedback

DM

David M.

Verified Student

"The practice engine is incredible. It feels exactly like the real testing environment and helped me build so much confidence."

SJ

Sarah J.

Premium Member

"The PDF is very well organized and the explanations for the answers are actually helpful, not just random text."

MC

Michael C.

Verified Buyer

"I was skeptical, but the content is high quality and definitely worth the price. I passed on my first try!"

Need Assistance?

Our expert support team is available to assist you with any inquiries about our exam materials.

Contact Support
Average response: < 24 Hours

Get Exam Updates

Subscribe to receive instant notifications on new questions and exclusive flash sales.

* Join 5,000+ students getting weekly updates

Support Chat โ— Active Now

๐Ÿ‘‹ Hi! How can we help you pass your exam?

Enter email to start chatting