Microsoft · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
28% of exam · 6 sample questions below
A company is planning to migrate from on-premises Exchange to Exchange Online and needs to ensure that mail flow can coexist between the two environments during the transition. Which tool should the administrator use to configure this hybrid deployment?
Azure AD Connect
Exchange Hybrid Configuration Wizard
This wizard guides through the steps to establish a hybrid relationship between on-premises Exchange and Exchange Online, including mail flow and free/busy sharing.
Microsoft 365 Admin Center
Exchange Admin Center
A company has recently signed up for Microsoft 365 Business Premium. They want to change the default domain from onmicrosoft.com to a custom domain they own. Which step must be completed first before the custom domain can be used for user email addresses?
Add the custom domain in the Microsoft 365 admin center
Adding the custom domain in the Microsoft 365 admin center is the mandatory first step to associate your existing DNS namespace with your tenant. From Domains > Add domain, you enter the domain name, which triggers Microsoft's verification wizard and generates the exact DNS records you must publish. Until this addition is completed, no downstream tasks like verification or user provisioning can begin.
Verify domain ownership by adding a TXT record to the domain's DNS
Create user accounts with the new domain as their primary email
Configure email exchange records (MX)
An administrator is managing a Microsoft 365 tenant and needs to delegate the ability to reset user passwords to a group of helpdesk staff. The helpdesk staff should not have any other administrative privileges. Which built-in role should the administrator assign?
Global Administrator
Password Administrator
Password Administrator can reset passwords for non-administrator users and does not include other administrative capabilities.
User Administrator
Helpdesk Administrator
An organization has just purchased Microsoft 365 subscriptions and wants to add their custom domain 'fabrikam.com' to the tenant. Which record must they add to their DNS provider to verify domain ownership?
MX record
TXT record
A TXT record is the standard method Microsoft 365 uses to verify domain ownership because it can hold an arbitrary text string. Microsoft gives you a unique verification token during the domain setup wizard; when you publish it as a TXT record, Microsoft queries your DNS zone and confirms the exact token exists. This proves you control the domain without affecting existing services, and you can remove the record after verification succeeds.
CNAME record
SRV record
A company plans to migrate their email from an on-premises Exchange server to Exchange Online. They want to ensure that during the migration, mail sent to users who have already been migrated is delivered to Exchange Online, while mail for non-migrated users is delivered to on-premises. Which type of domain configuration should they use?
Coexistence domain
Shared domain
Split domain
Split domain (also called shared SMTP address space) is the correct configuration when a single accepted domain has mailboxes both on-premises and in Exchange Online, as in this migration scenario. In an Exchange hybrid deployment, you configure the on-premises organization and Exchange Online to recognize the same domain as authoritative, and then create a send connector and a receiving connector (or use the Hybrid Configuration Wizard) to route messages based on the mailbox location. This allows mail for recipients with the same domain suffix to be delivered correctly to either environment, which is exactly the requirement when migrating mailboxes from on-premises to the cloud.
Forwarding domain
A new helpdesk administrator needs to be able to reset user passwords and manage user account properties, but should not be able to manage licenses or assign administrative roles. Which built-in role should be assigned?
Global Administrator
User Administrator
The User Administrator can manage users and groups, reset passwords, and manage user licenses, but not administrative roles. This matches the requirement.
License Administrator
Helpdesk Administrator
Want more Deploy and manage a Microsoft 365 tenant practice?
Practice this domain28% of exam · 6 sample questions below
Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM) to manage administrative roles. You need to ensure that when a user activates the Global Administrator role, they must provide a justification and the activation is time-bound. Additionally, you want to require approval from the security team for this activation. What should you configure?
Configure an Identity Protection user risk policy for Global Administrators
Create an Access Review for Global Administrator role
Configure a Conditional Access policy requiring MFA for Global Administrator activation
Modify the PIM role settings for Global Administrator to require justification, set maximum activation duration, and require approval
PIM settings allow these configurations.
Your organization uses Microsoft Entra ID and has strict security requirements. You need to implement a Zero Trust security model. Which THREE of the following are foundational principles of Zero Trust that should be implemented?
Assume trust based on location
Segment access
Use least privilege access
Limit user access with Just-In-Time and Just-Enough-Access (JIT/JEA).
Assume breach
Assume that breaches have happened and will happen, and design accordingly.
Verify explicitly
Always authenticate and authorize based on all available data points.
You are reviewing the following Conditional Access policy JSON in Microsoft Entra ID. What does this policy do?
Requires MFA for all users accessing all apps from any client type
Blocks access for all users except Admin@contoso.com when accessing from mobile apps
Requires MFA for all users except Admin@contoso.com when accessing any app from mobile apps or desktop clients
Matches the policy conditions and grant controls.
Requires MFA for all users accessing all apps from any device
Your company uses Microsoft Entra ID and has a custom line-of-business application that supports SAML-based SSO. You need to configure the application to use Microsoft Entra ID as the identity provider. Which enterprise application configuration should you use?
Linked Sign-on
SAML-based Sign-on
SAML-based Sign-on is correct because it enables true federated single sign-on between Microsoft Entra ID and a custom application that supports the SAML 2.0 standard. Entra ID acts as the identity provider, authenticates the user, and sends a digitally signed SAML assertion to the app's ACS (Assertion Consumer Service) URL, allowing the app to trust the assertion without prompting for credentials again. This is the recommended SSO method for non-gallery enterprise applications, especially older line-of-business apps that lack support for modern OAuth/OIDC protocols.
Password-based Sign-on
OpenID Connect-based Sign-on
Your organization uses Microsoft Entra ID to manage user identities. You need to ensure that users can sign in using their existing social media accounts, such as Microsoft, Google, or Facebook. What should you configure?
Configure Conditional Access policies for social identity providers
Configure External Identities and add identity providers for social networks
External Identities supports adding social identity providers like Google and Facebook.
Configure Microsoft Entra Connect to sync social account attributes
Configure self-service password reset (SSPR)
Your organization uses Microsoft Entra Conditional Access. You need to block access from countries where your company does not operate. The list of blocked countries changes frequently. What is the most efficient way to manage this?
Enable Microsoft Entra multifactor authentication for all users from blocked countries
Create a Conditional Access policy that blocks all locations except the allowed countries
Use IP ranges in Conditional Access to block specific country IPs
Create Named Locations for blocked countries and use them in Conditional Access
Named Locations can be easily updated with new countries.
Want more Implement and manage Microsoft Entra identity and access practice?
Practice this domain32% of exam · 6 sample questions below
A security administrator needs a single console to investigate and respond to a complex incident involving alerts from endpoints, email, and identities. Which Microsoft portal should they use?
Microsoft 365 Defender portal
This portal provides a unified incident management view across Microsoft Defender XDR products, correlating alerts from multiple domains.
Microsoft Sentinel
Microsoft Defender for Cloud
Microsoft 365 compliance center
An organization uses Microsoft Defender for Cloud Apps to monitor shadow IT. They want to enforce policies that block downloads from risky cloud apps. Which Microsoft Defender XDR component provides this capability?
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that discovers sanctioned and unsanctioned cloud apps, assesses risk via the Cloud App Catalog, and enforces real-time session and access policies. It can restrict risky app usage using conditional access app controls, block downloads, or apply DLP checks across thousands of third-party SaaS services — capabilities no workload-specific Defender product can provide.
Microsoft Defender for Endpoint
Microsoft Defender for Identity
Microsoft Defender for Office 365
An organization wants to prevent users from running executable files from the Windows Temp folder. Which Microsoft Defender for Endpoint capability should be configured?
Attack surface reduction rules
Attack surface reduction (ASR) rules are a Windows Defender Exploit Guard capability that can specifically block process creation from common temporary folders (such as %Temp% and %AppData%) using a predefined rule like 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' or the explicit temp-folder rule, preventing malware from launching from file paths where droppers commonly execute. ASR rules are client-side, configured via Microsoft Intune, Configuration Manager, or GPO, and operate before the executable is allowed to spawn by intercepting process creation in the kernel and user-mode. This makes ASR the correct choice because it directly restricts executable execution based on file location and reputation, rather than merely restricting network or data access.
Network protection
Exploit protection
Controlled folder access
A security team wants to automatically investigate and respond to security incidents across endpoints, email, and identities without manual intervention. Which Microsoft Defender XDR capability provides this automation?
Automated investigation and response (AIR)
AIR uses automation to investigate alerts and take predefined remediation actions, such as isolating devices or deleting malicious emails.
Advanced hunting
Threat analytics
Attack surface reduction rules
A security administrator notices that users are receiving phishing emails that evade built-in anti-spam filters. The administrator wants to enable users to report these suspicious emails from Outlook and have them automatically trigger an investigation and block the sender. Which feature should be configured in Microsoft Defender for Office 365?
Attack simulation training
Threat Explorer
User reported settings in the Microsoft 365 Defender portal
User reported settings in the Microsoft 365 Defender portal, found under Settings > Email & collaboration, are the native control plane that connects end-user report actions to backend automation. An admin can route reported messages to Microsoft for analysis, to a custom mailbox, or directly into automated investigation and response, and can enable the automatically block sender rule so that confirmed phishing verdicts instantly update the tenant block list. This is precisely the kind of correlated, report-initiated blocking that the other options lack, making it the correct choice for this scenario.
Safe Links
A security administrator wants to automatically block malicious IP addresses from sending email to Exchange Online mailboxes. Which Microsoft Defender component should be configured?
Exchange Online Protection (EOP)
Exchange Online Protection (EOP) is the correct answer because its connection filtering feature evaluates the source IP address of every inbound SMTP connection against Microsoft's default and tenant-specific IP allow/block lists and real-time reputation data. Malicious IPs are rejected at the transport layer before the message is accepted, and admins can explicitly add IPs to the block list in the anti-spam policy to enforce a custom allow/deny set for inbound mail flow.
Microsoft Defender for Endpoint
Microsoft Defender for Identity
Microsoft Defender for Cloud Apps
Want more Manage security and threats by using Microsoft Defender XDR practice?
Practice this domain12% of exam · 6 sample questions below
A compliance officer needs to automatically retain emails that contain personally identifiable information (PII) for 10 years and then permanently delete them. Which Microsoft Purview feature should be configured?
Auto-apply retention labels based on sensitive information types
Auto-apply retention labels are content-aware and can be configured to trigger whenever a sensitive information type—such as a credit card number, passport number, or other PII—is detected in an email. Once the label is applied, its retention settings enforce the 10-year retention period and, at the end of that period, automatically dispose of the item. This satisfies the requirement to selectively retain emails based on content, not just location or folder.
Data Lifecycle Management retention policy
Data classification
eDiscovery
A compliance officer needs to prevent external users from printing or copying content from documents stored in a SharePoint Online site. Which Microsoft Purview feature should be configured to enforce this restriction?
Sensitivity labels with encryption and usage rights
Sensitivity labels with encryption and usage rights directly enforce document-level restrictions by applying Azure Rights Management (RMS) protection. When an external user opens the document, the RMS client enforces usage rights that explicitly deny actions such as printing, copying, and editing, regardless of where the file is stored or how it is shared. These restrictions travel with the file itself, making them effective even after the file leaves your tenant, and they can be scoped to specific external users or groups.
Data Loss Prevention (DLP) policy
Information Barriers
Microsoft Purview Information Protection without encryption
A compliance administrator needs to ensure that all documents in a SharePoint library are retained for exactly 7 years and then allow users to manually dispose of them sooner after a review. What should they configure in Microsoft Purview?
Create a retention label with a retention period of 7 years and enable disposition review
A retention label with a 7-year period and disposition review is the correct choice because it retains the document for the full regulatory period, yet the disposition review step triggers a manual approval workflow at the end of the retention period. During that review, an authorized user can approve early disposal, satisfying the requirement that documents be manually dispose-able if approved, rather than being automatically deleted or locked indefinitely.
Create a retention label with a retention period of 7 years and no additional action
Create a sensitivity label that restricts access
Create a record label
A legal department needs to preserve all communications related to an ongoing lawsuit. They identify specific users and require that their mailbox items and OneDrive files are not altered or deleted. Which Microsoft Purview feature should be used?
Litigation Hold
Litigation Hold is the correct mechanism because it places a preservation hold on an entire mailbox and OneDrive for Business site in-place, preventing items from being permanently deleted or altered. Every version of a document and every mailbox item, including deleted items and items edited by users, is retained in the Recoverable Items folder until the hold is released. Deletion by users, as well as cleanup by retention policies, is blocked for held content, ensuring all communications related to the legal matter remain discoverable in their original location.
Retention Policy
Data Loss Prevention (DLP)
eDiscovery
A compliance officer needs to ensure that all emails containing sensitive information (e.g., passport numbers) are automatically encrypted when sent to external recipients. The encryption should be enforced without requiring users to manually select an option. Which Microsoft Purview feature should they configure?
Data Loss Prevention (DLP) policy with encryption action
Data Loss Prevention (DLP) policies in Microsoft Purview can directly apply an encryption action to outgoing email by leveraging Azure Rights Management. When a DLP policy detects a sensitive information type (e.g., credit card numbers or personally identifiable information) in the message body or attachments, it automatically wraps the message with the 'Encrypt' action, enforcing transport-level protection without user intervention. This policy-based approach is purpose-built for compliance scenarios where data exfiltration must be prevented at the email boundary.
Sensitivity labels with auto-labeling
Message Encryption (OME) policies
Communication Compliance
A compliance administrator needs to automatically apply a retention label to all documents in a SharePoint Online site that contain Social Security numbers. The label should retain the documents for 5 years and then automatically delete them. Which feature should they configure?
Data Loss Prevention (DLP) policy
sensitivity label with auto-labeling
retention label with auto-labeling
Retention labels, when combined with auto-labeling policies, can automatically apply based on sensitive info types and enforce retention and deletion actions.
An information barrier policy
Want more Manage compliance by using Microsoft Purview practice?
Practice this domainThe MS-102 exam has 50 questions and must be completed in 120 minutes. The passing score is 700/1000.
Microsoft 365 administration scenario questions covering tenant management, compliance, security, messaging, and collaboration services.
The exam covers 4 domains: Deploy and manage a Microsoft 365 tenant, Implement and manage Microsoft Entra identity and access, Manage security and threats by using Microsoft Defender XDR, Manage compliance by using Microsoft Purview. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Microsoft MS-102 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.