Your organization uses Microsoft Defender XDR. You want to create a custom detection rule that triggers an alert when a specific process is created on multiple endpoints. Which advanced hunting table should you use?
A.DeviceNetworkEvents
B.DeviceFileEvents
C.DeviceLogonEvents
D.DeviceRegistryEvents
E.DeviceProcessEvents
AnswerE
DeviceProcessEvents records process creation events with process, command-line and device details across endpoints, so filtering on a specific process name triggers alerts when it appears on multiple devices. This matches the stem's requirement for process-creation detection across endpoints.
Why this answer
DeviceProcessEvents. This table captures process creation events, which is the required data for a detection rule on a specific process being created.
Option A (DeviceNetworkEvents) is incorrect because it logs network connections, not process creation.
Option B (DeviceFileEvents) is incorrect because it logs file operations.
Option C (DeviceLogonEvents) is incorrect because it logs logon events.
Option D (DeviceRegistryEvents) is incorrect because it logs registry changes.
You are planning a migration from on-premises Active Directory to Microsoft Entra ID using cloud sync. You need to synchronize user passwords so that users can authenticate using their existing passwords. Which feature should you enable?
A.Pass-through Authentication
B.Password Hash Synchronization
C.Federation with AD FS
D.Seamless Single Sign-On
AnswerB
Password Hash Synchronization (PHS) synchronizes a hash of the on-premises Active Directory password to Azure AD, enabling users to sign in to Microsoft 365 and Azure AD with the same password without any on-premises infrastructure at the moment of authentication. PHS also supports advanced security features like leaked credential detection and Identity Protection, making it the correct choice when the goal is to have password hashes available in the cloud.
Why this answer
Password Hash Synchronization (PHS) is the correct feature because it synchronizes the hash of a user's on-premises Active Directory password to Microsoft Entra ID, allowing users to authenticate with the same password without any additional on-premises infrastructure. Cloud sync specifically relies on PHS to replicate password hashes from AD to Entra ID, enabling seamless authentication for cloud-based services.
Exam trap
The trap here is that candidates often confuse Pass-Through Authentication with password synchronization, but PTA does not synchronize hashes—it only validates passwords in real time against on-premises AD, which is not the same as synchronizing passwords for cloud sync.
How to eliminate wrong answers
Option A is wrong because Pass-Through Authentication (PTA) validates passwords directly against on-premises AD without synchronizing password hashes, requiring agents and network connectivity, and does not meet the requirement of synchronizing passwords for cloud sync. Option C is wrong because Federation with AD FS relies on a federated trust and on-premises AD FS servers for authentication, not password synchronization, and adds complexity beyond cloud sync's scope. Option D is wrong because Seamless Single Sign-On (SSO) only provides automatic sign-in for domain-joined devices on corporate networks, but does not synchronize password hashes or enable password-based authentication from non-domain-joined devices.
A compliance officer needs to prevent users from sharing documents that have been labeled 'Highly Confidential' with external users. When a user attempts to share such a document externally, the action should be blocked and the user should see a policy tip. Which Microsoft Purview solution should the officer configure?
A.Data Loss Prevention (DLP) policy
B.Sensitivity label encryption
C.Retention policy
D.Records management
AnswerA
A Microsoft Purview DLP policy can use sensitivity labels as conditions, and its actions can block sharing both via email (Exchange, Outlook) and external sharing in SharePoint/OneDrive. For example, when a condition like 'content contains a Confidential label' is met, the policy can block the sharing action and display a policy tip to the user before the block occurs. This directly enforces the compliance officer's requirement to prevent users from sharing content with a specific label, while the other mechanisms do not intercept the sharing action.
Why this answer
A Data Loss Prevention (DLP) policy is the correct solution because it can inspect content and context (including sensitivity labels) to enforce rules that block external sharing of documents labeled 'Highly Confidential' and display a policy tip to the user. DLP policies in Microsoft Purview are specifically designed to prevent accidental or intentional data leakage by monitoring and controlling sharing actions in real time.
Exam trap
The trap here is that candidates often confuse sensitivity label encryption (which protects the file) with DLP (which controls the sharing action), leading them to choose encryption when the requirement explicitly involves blocking the share and showing a policy tip.
How to eliminate wrong answers
Option B is wrong because sensitivity label encryption protects the document at rest and in transit by encrypting it, but it does not block the sharing action itself or show a policy tip; it only controls access after the file is shared. Option C is wrong because a retention policy is used to preserve or delete content after a specified period, not to block real-time sharing actions or display policy tips. Option D is wrong because records management marks content as a record to prevent deletion or modification, but it does not block external sharing or provide policy tips during sharing attempts.
You are designing an incident response plan using Microsoft Defender XDR. You want to automate the containment of compromised devices when a high-severity incident is detected. What should you configure?
A.Configure custom detection rules in Microsoft Defender for Endpoint
B.Configure device groups in Microsoft Defender for Endpoint
C.Enable automated investigation and response (AIR) in Microsoft Defender XDR
D.Create a playbook in Microsoft Sentinel
AnswerC
AIR can automatically contain devices based on incident severity.
Why this answer
C is correct because automated investigation and response (AIR) in Microsoft Defender XDR can automatically contain devices when a high-severity incident is detected. A is incorrect because custom detection rules in Microsoft Defender for Endpoint only create alerts; they do not automatically contain devices. B is incorrect because device groups are used for management and policy assignment, not for automated containment.
D is incorrect because playbooks in Microsoft Sentinel require manual triggering or other automation; they are not configured within Defender XDR.
Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that automatically alerts when a user downloads more than 100 files from SharePoint Online in 10 minutes. What type of policy should you create?
An anomaly detection policy in Microsoft Defender for Cloud Apps is designed to identify unusual user behavior, such as a user downloading over 100 files from SharePoint Online within 10 minutes. This policy type uses machine learning and predefined thresholds to detect deviations from baseline activity, making it the correct choice for this scenario.
Exam trap
The trap here is that candidates often confuse anomaly detection policies with session policies, mistakenly thinking session policies can alert on cumulative activity, when in fact session policies only enforce real-time controls during an active session.
How to eliminate wrong answers
Option A is wrong because a session policy controls real-time user actions during a session (e.g., blocking downloads or requiring MFA) but does not automatically alert based on aggregate file download counts over time. Option B is wrong because an app discovery policy identifies shadow IT by analyzing traffic logs to discover cloud apps in use, not user-specific download behavior in SharePoint Online. Option D is wrong because an OAuth app policy governs permissions granted to third-party OAuth apps, not user file download activities.
Which TWO of the following are valid conditions that can be used in a Microsoft Entra ID conditional access policy? (Choose two.)
Select 2 answers
A.Network location
B.Sign-in risk
C.Application sensitivity label
D.User risk
E.Device manufacturer
AnswersB, D
Sign-in risk is a valid condition in Azure AD Conditional Access. It evaluates the probability that the current authentication attempt is compromised, based on real-time risk detections from Identity Protection (such as impossible travel, anonymous IP, or leaked credentials). Administrators can configure policies to block access or require additional controls when the sign-in risk level is Low, Medium, or High.
Why this answer
Sign-in risk (B) and user risk (D) are both valid conditions in Microsoft Entra ID Conditional Access policies. These risk levels are calculated by Microsoft Entra ID Protection using real-time signals such as anonymous IP addresses, atypical travel, or leaked credentials, and can be used to trigger policies like requiring multi-factor authentication or blocking access.
Exam trap
The trap here is that candidates may confuse 'Network location' with the valid 'Locations' condition, or assume that application sensitivity labels (which are part of Microsoft Purview) can be used directly in Conditional Access policies, when in fact they are not a supported condition.
A company wants to implement just-in-time (JIT) privileged access for the Global Administrator role in Microsoft Entra ID. Users must request activation and provide a business justification. The request must be approved by a separate group of approvers, and the role activation should expire after 4 hours. Which Microsoft Entra feature should the administrator configure?
A.Privileged Identity Management (PIM)
B.Identity Protection
C.Conditional Access
D.Access Reviews
AnswerA
Privileged Identity Management (PIM) provides just-in-time activation for Azure AD roles and Azure resources, allowing administrators to activate eligible roles for a limited time, usually with approval from designated approvers and a business justification. This is the core mechanism for JIT privileged access because it directly addresses the need for on-demand, time-bound, and audited elevation in contrast to standing access. PIM also offers multi-factor authentication enforcement and audit logs to monitor activations.
Why this answer
Privileged Identity Management (PIM) in Microsoft Entra ID provides just-in-time (JIT) privileged access by allowing users to activate roles like Global Administrator with a business justification, requiring approval from a designated group of approvers, and setting a configurable activation duration (e.g., 4 hours). This directly matches the company's requirements for time-bound, approved role activation.
Exam trap
The trap here is that candidates confuse PIM's JIT activation with Conditional Access policies, thinking that Conditional Access can enforce time-based access, but Conditional Access cannot manage role activation, approval workflows, or expiration of privileged roles.
How to eliminate wrong answers
Option B (Identity Protection) is wrong because it focuses on detecting and remediating identity risks (e.g., compromised credentials, anomalous sign-ins) and does not provide JIT role activation or approval workflows. Option C (Conditional Access) is wrong because it enforces access policies based on conditions like location or device state, but it cannot manage role activation, approval, or expiration. Option D (Access Reviews) is wrong because it automates periodic recertification of group memberships or role assignments, not on-demand activation with approval and expiration.
An administrator has created a new user account in Microsoft Entra ID. To ensure the user has a mailbox in Exchange Online, what is the next step?
A.Assign an Exchange Online license to the user
B.Create an Exchange mailbox manually
C.Run the Microsoft 365 Setup wizard
D.Configure DNS records for the domain
AnswerA
In Microsoft Entra ID (Azure AD), a user object does not automatically have an Exchange Online mailbox until a license that contains the Exchange Online service plan (e.g., Microsoft 365 E3/E5, Exchange Online Plan 1/2) is assigned. Once assigned, the Exchange Online provisioning service creates the mailbox automatically, usually within minutes to a few hours, and the user can log in to Outlook or Outlook on the web. This is the only supported, self-service method for creating a mailbox for a standard user in a cloud-only environment.
Why this answer
In Microsoft 365, a user must be assigned an Exchange Online license (part of an E3, E5, or standalone plan) before a mailbox is automatically provisioned in Exchange Online. Without a license, the user object exists in Entra ID but has no mailbox; the license assignment triggers the mailbox creation process within 24 hours.
Exam trap
The trap here is that candidates often think creating the user in Entra ID or configuring DNS automatically provisions a mailbox, but Microsoft 365 requires an explicit license assignment to enable the Exchange Online service plan for that user.
How to eliminate wrong answers
Option B is wrong because Exchange Online does not support manually creating a mailbox; mailboxes are automatically provisioned when a license is assigned, and manual creation is only possible in on-premises Exchange Server. Option C is wrong because the Microsoft 365 Setup wizard is used for initial tenant configuration (e.g., adding a domain or setting up admin accounts), not for provisioning a mailbox for an existing user. Option D is wrong because DNS records (MX, SPF, etc.) are required for mail routing to the tenant, but they do not create a mailbox; the mailbox must exist first via license assignment.
You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a hybrid identity environment with Microsoft Entra Connect Sync. You need to implement Microsoft Entra Password Protection to prevent users from using weak passwords. You must ensure that the on-premises Active Directory Domain Services (AD DS) environment enforces the same password policies as Microsoft Entra ID. What should you do? (Choose two.)
Select 2 answers
A.Install the Microsoft Entra Password Protection proxy service on a server in the on-premises network.
B.Enable password hash synchronization in Microsoft Entra Connect.
C.Configure the on-premises domain controllers to use the Microsoft Entra Password Protection proxy service as a forwarder.
D.Install the Microsoft Entra Password Protection proxy service on a domain controller.
E.Install the Microsoft Entra Password Protection DC agent on all domain controllers.
AnswersA, E
The Microsoft Entra Password Protection proxy service is required to enable on-premises domain controllers to communicate with Microsoft Entra ID for password policy enforcement. The proxy service acts as a bridge between the on-premises environment and Microsoft Entra ID, forwarding password validation requests. Without the proxy, the domain controllers cannot access the global banned password list or custom banned lists. This component is essential for the on-premises enforcement of Microsoft Entra Password Protection.
Why this answer
To enforce Microsoft Entra Password Protection on-premises, you must deploy both the proxy service and the DC agent. The proxy service enables communication with Microsoft Entra ID to retrieve the password policies, and the DC agent on each domain controller enforces those policies during password changes. Password hash synchronization is not required, and the proxy service must not be installed on a domain controller.
These two components work together to extend Microsoft Entra Password Protection to the on-premises AD DS environment.
Exam trap
The trap here is assuming that password hash synchronization is required or that the proxy service should be installed on a domain controller, which are common misconceptions.
You are configuring Microsoft Entra ID for your organization. You need to enable passwordless authentication for users. Which TWO authentication methods are passwordless and supported by Microsoft Entra ID?
Select 2 answers
A.SMS-based one-time passcode (OTP)
B.Hardware OATH tokens
C.Microsoft Authenticator app
D.OAuth 2.0 device authorization grant
E.FIDO2 security keys
AnswersC, E
Microsoft Authenticator supports true passwordless phone sign-in by using a cryptographic key pair stored in the device's secure enclave, where the user simply confirms a number shown on the sign-in screen or approves a notification to authenticate. This flow does not require entering a password or a one-time code, because the device proves possession and the user proves presence via the approval action, making it a valid passwordless Microsoft Entra ID authentication method.
Why this answer
The Microsoft Authenticator app supports passwordless authentication by allowing users to approve sign-in requests via a notification or a number match on their mobile device, eliminating the need for a password. FIDO2 security keys are also a passwordless method, using public-key cryptography to authenticate users without a password, and are fully supported by Microsoft Entra ID for both Azure AD joined and hybrid joined devices.
Exam trap
The trap here is that candidates often confuse multi-factor authentication methods (like SMS OTP or OATH tokens) with passwordless methods, but passwordless requires the primary authentication factor to be something you have or are, not something you know (a password), and both SMS OTP and OATH tokens still require a password as the first factor in most configurations.
A company uses Microsoft Entra ID P2 licenses. They want to create a Conditional Access policy that requires MFA for all users, but the policy should only be enforced when the sign-in risk is medium or higher. Additionally, they need to exclude a group named 'Emergency Access' from this policy. Which configuration is correct?
A.Assign policy to 'All users', exclude 'Emergency Access' group, set 'Sign-in risk' condition to 'High and Medium'
B.Assign policy to 'All users', exclude 'Emergency Access' group, set 'User risk' condition to 'High and Medium'
C.Assign policy to 'Emergency Access' group, set 'Device state' condition to 'All device states'
D.Assign policy to 'All users', exclude 'Emergency Access' group, set 'Locations' condition to 'All trusted locations'
AnswerA
The correct configuration targets every user except the Emergency Access group, and the Sign-in risk condition set to 'High and Medium' ensures the policy only triggers when the authentication attempt itself has been flagged as medium or high risk by Microsoft Entra ID Protection. This matches the requirement precisely: the policy is scoped broadly, the break-glass accounts are excluded to guarantee availability, and the control (such as requiring MFA or blocking access) is enforced based on the risk score of that specific sign-in event.
Why this answer
It assigns the Conditional Access policy to 'All users' (ensuring universal coverage), excludes the 'Emergency Access' group (to prevent lockout of break-glass accounts), and sets the 'Sign-in risk' condition to 'High and Medium' — which matches the requirement to enforce MFA only when sign-in risk is medium or higher. Sign-in risk is the correct condition for real-time risk during authentication, while user risk tracks historical compromise likelihood.
Exam trap
The trap here is confusing 'Sign-in risk' with 'User risk' — candidates often pick Option B because both terms sound similar, but only sign-in risk applies to the current authentication session and matches the requirement for risk-based MFA enforcement during sign-in.
How to eliminate wrong answers
Option B is wrong because it uses 'User risk' instead of 'Sign-in risk'; user risk reflects the likelihood that an account is compromised based on past activity, not the risk of the current sign-in session, so it does not meet the requirement to enforce MFA based on sign-in risk. Option C is wrong because it assigns the policy to the 'Emergency Access' group rather than excluding them, which would force MFA on emergency accounts and defeat their purpose; it also uses 'Device state' condition which is irrelevant to risk-based MFA enforcement. Option D is wrong because it uses 'Locations' condition with 'All trusted locations', which would enforce MFA only from trusted locations (or the opposite depending on configuration), not based on sign-in risk level, and thus does not address the risk-based requirement.
A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a user receives a phishing email (delivered to inbox) and later clicks a link from that email that leads to a known malicious domain. The rule will be based on an advanced hunting query. Which two tables should the analyst join in the query to capture both the email delivery event and the link click event? (Choose two.)
Select 2 answers
A.EmailEvents
B.UrlClickEvents
C.DeviceEvents
D.IdentityLogonEvents
AnswersA, B
EmailEvents records the delivery outcome of each message, including whether it reached the inbox, satisfying the phishing-delivery half of the correlation. Joining it to UrlClickEvents on the NetworkMessageId links that delivered message to the subsequent click on the malicious URL, giving the advanced hunting query both required events.
Why this answer
EmailEvents contains records of email delivery events, including phishing emails that were delivered to the inbox. UrlClickEvents captures user clicks on URLs in emails, including the target domain. Joining these two tables on the email's network message ID allows the analyst to correlate the specific phishing email delivery with the subsequent link click to a known malicious domain, which is the exact scenario described.
Exam trap
The trap here is that candidates may confuse UrlClickEvents with DeviceEvents, thinking that a link click is a device-level action, but in Microsoft Defender XDR, URL clicks from emails are specifically tracked in the UrlClickEvents table, not in endpoint event tables.
A compliance officer needs to block users from sharing emails that contain credit card numbers with external recipients. When a user attempts to send such an email, it should be blocked immediately, and a policy tip should notify the user. Which Microsoft Purview solution should the officer configure?
A.Data Loss Prevention (DLP) policy.
B.Sensitivity label with encryption.
C.Microsoft Defender for Office 365 Safe Attachments policy.
D.Communication compliance policy.
AnswerA
DLP policies inspect email content for sensitive data types such as credit card numbers, block transmission to external recipients, and display policy tips to the sender. This directly satisfies the requirement to stop the email immediately while notifying the user.
Why this answer
A Data Loss Prevention (DLP) policy is the correct solution because it is specifically designed to detect sensitive information types (e.g., credit card numbers via predefined rule patterns matching the Luhn algorithm) in transit and enforce actions such as blocking the email and displaying a policy tip to the sender. This meets the compliance officer's requirement to block external sharing of credit card data immediately with user notification.
Exam trap
The trap here is that candidates often confuse the real-time blocking and notification capability of DLP with sensitivity labels (which only apply protection after classification) or communication compliance (which is a review-based solution, not a real-time enforcement mechanism).
How to eliminate wrong answers
Option B is wrong because a sensitivity label with encryption can protect content by restricting access or applying encryption, but it does not actively scan outbound email content for credit card numbers or block messages in transit with a policy tip. Option C is wrong because Microsoft Defender for Office 365 Safe Attachments policy focuses on scanning email attachments for malware and malicious content, not on detecting sensitive data patterns like credit card numbers. Option D is wrong because a communication compliance policy is designed to monitor and review internal/external communications for policy violations (e.g., harassment, insider trading) and typically requires manual review, not real-time blocking with a policy tip based on sensitive data patterns.
A compliance officer needs to automatically classify documents in SharePoint Online that contain credit card numbers. The classification should apply a label that restricts access and adds a header. Which two Microsoft Purview features must be configured? (Choose two.)
Select 2 answers
A.Sensitivity labels
B.Retention labels
C.Data Loss Prevention (DLP) policies
D.Auto-labeling policies
AnswersA, D
Sensitivity labels are the core classification mechanism in Microsoft Purview Information Protection. When applied, they embed metadata into the document and enforce protection settings such as encryption, rights management restrictions, and visual markings like headers, footers, or watermarks. The label persists with the content even when it leaves the organization, ensuring classification and protection follow the file. This directly satisfies the compliance officer's need to classify documents, especially when combined with auto-labeling for full automation.
Why this answer
Sensitivity labels are correct because they are the Microsoft Purview feature that applies classification markings (such as headers and footers) and encryption or access restrictions to documents. For this scenario, a sensitivity label must be configured to enforce the required header and access restrictions on content containing credit card numbers.
Exam trap
The trap here is that candidates often confuse DLP policies with auto-labeling, but DLP policies do not apply labels or headers—they only enforce actions like blocking or notification, whereas auto-labeling policies are required to automatically assign the sensitivity label.
Your organization plans to migrate from on-premises Exchange to Exchange Online. You need to ensure minimal disruption during the migration. Which approach should you recommend?
A.Deploy a hybrid configuration and migrate mailboxes in batches.
B.Perform a cutover migration during a weekend.
C.Use IMAP migration to migrate all mailboxes in parallel.
D.Use a third-party migration tool for a one-time bulk migration.
AnswerA
Hybrid configuration preserves coexistence between on-premises Exchange and Exchange Online, letting mailboxes move in controlled batches while mail flow and free/busy sharing continue uninterrupted. This directly satisfies the minimal-disruption constraint, since users keep working throughout and rollback remains possible until each batch completes.
Why this answer
A hybrid configuration with batch migration is the recommended approach for minimal disruption because it allows coexistence between on-premises Exchange and Exchange Online, enabling gradual mailbox moves while maintaining free/busy, calendar sharing, and mail flow. Batch migration lets you schedule and control the pace, reducing user impact and allowing rollback if issues arise.
Exam trap
MS-102 often tests migration strategies; candidates may choose cutover for simplicity, ignoring that it causes downtime and lacks coexistence, which is critical for minimal disruption.
How to eliminate wrong answers
Option B is wrong because a cutover migration is a one-time, all-at-once move that causes significant downtime and is only suitable for small organizations with no coexistence needs. Option C is wrong because IMAP migration only migrates email data, not calendars, contacts, or tasks, and lacks coexistence features; it is also not designed for parallel migration of all mailboxes without throttling issues. Option D is wrong because third-party tools may not provide native coexistence or integrated management, and a one-time bulk migration can cause disruption and lacks the flexibility of a phased approach.
A security analyst identifies a malicious file hash on one endpoint. They need to ensure that file is blocked from executing on all other endpoints in the organization immediately. Which Microsoft Defender for Endpoint feature should be used?
A.Indicators of compromise (IOCs)
B.Attack surface reduction rules
C.Automated investigation and response
D.Custom detection rules
AnswerA
Indicators of compromise let analysts submit a file hash as a custom indicator, and Defender for Endpoint enforces block or allow actions across all onboarded endpoints. This satisfies the requirement to block the file organisation-wide immediately.
Why this answer
Indicators of compromise (IOCs) in Microsoft Defender for Endpoint allow security analysts to create custom indicators (e.g., file hashes, IPs, URLs) that are enforced across all endpoints in near real-time. By adding the malicious file hash as an IOC with an 'Alert and Block' action, the file is immediately prevented from executing on any managed device, providing a rapid, organization-wide block without waiting for signature updates.
Exam trap
The trap here is that candidates confuse 'Indicators of compromise (IOCs)' with 'Custom detection rules,' because both involve custom definitions, but IOCs are for immediate blocking of known artifacts while custom detection rules are for behavioral detection over time.
How to eliminate wrong answers
Option B is wrong because Attack surface reduction rules are pre-configured policies that reduce common attack vectors (e.g., blocking Office apps from creating child processes), but they cannot block a specific file hash on demand. Option C is wrong because Automated investigation and response (AIR) automatically investigates and remediates alerts after detection, but it does not proactively block a known malicious hash from executing; it reacts to incidents already triggered. Option D is wrong because Custom detection rules use Advanced Hunting queries to detect suspicious behavior over time, but they are not designed for immediate, hash-based execution blocking across all endpoints.
An organization wants to allow only specific company-approved USB devices (e.g., those with a specific hardware ID) on managed Windows devices. All other USB devices must be blocked. Which Microsoft 365 Defender feature should be configured?
A.Attack surface reduction rules
B.Microsoft Defender for Endpoint device control
C.Microsoft Defender for Cloud Apps session policy
D.Conditional Access device compliance
AnswerB
Microsoft Defender for Endpoint device control is the correct capability because it is purpose-built to enforce flexible policies on peripheral devices, especially USB storage. Device control policies define rules based on device instance IDs, hardware IDs, or device classes, and support actions such as allow, deny, or audit. This allows an administrator to create a policy that permits only company-approved USB devices (matched by their hardware IDs) while blocking all other USB devices, meeting the stated requirement directly.
Why this answer
Microsoft Defender for Endpoint device control is the correct feature because it provides granular control over peripheral devices, including USB devices, based on hardware IDs. It allows administrators to create allow/block policies that enforce restrictions on managed Windows devices, ensuring only company-approved USB devices can be used.
Exam trap
The trap here is that candidates often confuse Attack surface reduction rules with device control because both are part of Microsoft Defender for Endpoint, but ASR rules focus on process behaviors, not hardware device access.
How to eliminate wrong answers
Option A is wrong because Attack surface reduction rules are designed to mitigate common malware behaviors (e.g., blocking Office apps from creating child processes) and do not include USB device control capabilities. Option C is wrong because Microsoft Defender for Cloud Apps session policies are used to monitor and control user sessions in cloud apps (e.g., blocking downloads from SharePoint) and have no effect on local USB device access. Option D is wrong because Conditional Access device compliance policies evaluate device health (e.g., requiring BitLocker or antivirus) for cloud app access but do not enforce USB device restrictions on the endpoint itself.
You are a security administrator for a company that uses Microsoft 365 E5. The security team wants to automatically block malicious files and URLs in email attachments and links based on Microsoft's threat intelligence, without manual intervention. You need to configure this in Microsoft Defender for Office 365. What should you do?
A.Enable Safe Attachments and Safe Links policies with the 'Block' action.
B.Set up a Data Loss Prevention (DLP) policy to block emails containing sensitive information.
C.Configure an Exchange Online mail flow rule to reject messages with attachments.
D.Create a transport rule to prepend a warning banner to external emails.
AnswerA
Safe Attachments and Safe Links with Block action automatically block malicious content based on real-time threat intelligence. Safe Attachments detonates attachments in a sandbox, and Safe Links checks URLs at time of click, blocking access if malicious. This provides automatic protection without manual intervention, directly meeting the requirement.
Why this answer
Safe Attachments and Safe Links are Microsoft Defender for Office 365 features that use Microsoft's threat intelligence to automatically block malicious attachments and URLs. They provide real-time protection without manual intervention, aligning with the requirement to automatically block based on threat intelligence.
Exam trap
The trap here is assuming that any email filtering rule can block malicious content, but only Safe Attachments and Safe Links leverage threat intelligence for automatic blocking.
You are a Microsoft 365 administrator for Contoso, Ltd. The security team uses Microsoft Defender XDR. They want to be alerted when a user's Microsoft Entra ID account is disabled but the user still has an active session on a device. You need to configure a custom detection rule that triggers on this condition. Which data source and query approach should you use?
A.Use the IdentityDirectoryEvents table in Microsoft Defender XDR advanced hunting with a query that filters for 'AccountDisabled' actions and joins with DeviceLogonEvents.
B.Use the AlertInfo table and filter for alerts with a severity of 'High' and a category of 'Credential Access'.
C.Use the CloudAppEvents table and filter for 'DisableAccount' operations performed by an administrator.
D.Use the DeviceEvents table in Microsoft Defender for Endpoint with a query that filters for 'UserAccountDisabled' actions.
AnswerA
IdentityDirectoryEvents captures directory-level changes, including account disablement, from Microsoft Defender for Identity. By joining with DeviceLogonEvents, you can correlate the disabled account with active sessions on devices. This combination directly addresses the scenario's requirement to detect when a disabled user still has an active device session, making it the correct approach for the custom detection rule.
Why this answer
The requirement is to detect a disabled Microsoft Entra ID account that still has an active device session. IdentityDirectoryEvents in Microsoft Defender XDR advanced hunting records directory changes such as account disabling, and DeviceLogonEvents tracks logon activity on devices. Joining these tables allows you to identify sessions that remain active after the account is disabled.
Other tables lack either the identity event or the device session context, so they cannot satisfy the scenario.
Exam trap
The trap here is assuming that endpoint event tables like DeviceEvents contain identity-related actions, when account disablement is actually captured in identity-focused tables such as IdentityDirectoryEvents.
Refer to the exhibit. You run the KQL query in advanced hunting. What is the primary purpose of this query?
A.Identify devices with outbound connections to malicious IPs
B.Identify devices with PowerShell execution policy set to bypass
C.Identify devices where a user deleted system files using cmd
D.Identify devices with high use of encoded commands, which may indicate malicious activity
AnswerD
The query aggregates encoded command usage per device, so its purpose is surfacing endpoints whose PowerShell or shell activity is heavily encoded. High encoded-command counts frequently indicate obfuscated malicious execution, making this a threat-hunting signal rather than a compliance or inventory check.
Why this answer
The KQL query filters for DeviceProcessEvents where the command line contains 'powershell' and the process command line includes '-EncodedCommand', which is a known technique used by attackers to obfuscate malicious scripts. The query then counts such events per device and filters for devices with more than 10 occurrences, indicating a high volume of encoded PowerShell commands that may signal malicious activity.
Exam trap
The trap here is that candidates may confuse 'encoded commands' with 'execution policy bypass' or focus on the presence of PowerShell without recognizing that the specific '-EncodedCommand' parameter is the key indicator of obfuscation and potential malicious activity.
How to eliminate wrong answers
Option A is wrong because the query does not reference any network events (e.g., DeviceNetworkEvents) or IP addresses; it only examines process command lines. Option B is wrong because the query does not check for PowerShell execution policy settings (e.g., 'Set-ExecutionPolicy Bypass'); it focuses on encoded commands, not policy configurations. Option C is wrong because the query does not look for 'cmd' or deletion of system files; it specifically targets PowerShell with '-EncodedCommand', not cmd.exe or file deletion events.
Your company recently acquired a subsidiary that uses a different Microsoft 365 tenant. You are tasked with merging the two tenants into one. The subsidiary has 1,500 users with unique email domains. You need to migrate all users, mailboxes, and SharePoint data while minimizing downtime and preserving data integrity. You have access to both tenants as global admin. What should you do first?
A.Add the subsidiary's domain to the primary tenant, then delete the subsidiary tenant and recreate users
B.Use the Microsoft 365 Merger Center in the admin portal
C.Use a third-party migration tool such as BitTitan MigrationWiz to perform the migration
D.Use Microsoft's native tenant-to-tenant migration by moving mailboxes via PowerShell and exporting SharePoint content
AnswerC
BitTitan MigrationWiz is an established third-party platform that performs cross-tenant mailbox, OneDrive, SharePoint, and Teams migrations by connecting to both tenants and running staged delta-sync batches. It minimizes downtime by pre-staging content and then synchronizing only changes during the cutover window, preserving item-level fidelity, metadata, and permissions. This is the standard recommended approach for consolidating two Microsoft 365 tenants after an acquisition.
Why this answer
Microsoft does not provide a native tool for merging two tenants; third-party tools like BitTitan MigrationWiz are designed specifically for cross-tenant migrations, supporting mailbox, SharePoint, and user data migration with minimal downtime and data integrity. These tools handle directory synchronization, mailbox rehydration, and SharePoint content mapping, which are critical for a 1,500-user migration with unique domains.
Exam trap
The trap here is that candidates assume Microsoft provides a native 'merger' tool or that PowerShell alone can handle a full tenant merge, overlooking the lack of built-in cross-tenant SharePoint migration capabilities and the need for specialized third-party solutions.
How to eliminate wrong answers
Option A is wrong because deleting the subsidiary tenant and recreating users would cause permanent data loss (mailboxes, SharePoint content) and cannot preserve data integrity; domain addition alone does not migrate data. Option B is wrong because there is no 'Microsoft 365 Merger Center' in the admin portal; this is a fabricated feature that does not exist. Option D is wrong because native tenant-to-tenant migration via PowerShell is limited to mailbox moves (using New-MoveRequest with cross-tenant prerequisites) and does not support SharePoint data migration; exporting and importing SharePoint content via PowerShell is complex, error-prone, and not designed for large-scale migrations with minimal downtime.
An organization with Microsoft Entra ID P2 licenses wants to require multi-factor authentication (MFA) for all users but allow them to register their authentication methods before being forced to use MFA. Which configuration should they implement?
A.Conditional Access policy with MFA grant and a registration campaign
B.Security defaults
C.Per-user MFA
D.Identity Protection user risk policy
AnswerA
Conditional Access with the MFA grant and an authentication registration campaign is correct because the registration campaign prompts users to enroll their MFA methods before the MFA requirement is actually enforced. This phased approach lets administrators schedule a grace period, target specific groups, and ensure users have security info registered, so the MFA challenge is not a blocking first-time event. Thus, it directly matches the scenario's need for pre-registration.
Why this answer
A Conditional Access policy with an MFA grant control enforces MFA for all users, and a registration campaign (or the combined registration experience) allows users to register their authentication methods before enforcement kicks in. This satisfies both the requirement to require MFA and the requirement to let users register first. Entra ID P2 licensing supports Conditional Access and the registration campaign feature.
Exam trap
MS-102 often tests the difference between Security Defaults, per-user MFA, and Conditional Access — candidates pick Security Defaults because it 'requires MFA', but it lacks the registration campaign and granular control the scenario demands.
How to eliminate wrong answers
Option B is wrong because Security Defaults enforce MFA but do not provide the granular registration campaign or the ability to exclude users during a registration window — and they are designed for tenants without Conditional Access. Option C is wrong because per-user MFA is a legacy setting that forces MFA at sign-in without a modern registration experience and does not support Conditional Access-style controls. Option D is wrong because an Identity Protection user risk policy responds to detected risk (e.g., leaked credentials) rather than enforcing MFA for all users as a baseline.
A company uses Azure AD Connect with password hash synchronization. They want to enable Azure AD Seamless Single Sign-On (SSO) for users accessing Microsoft 365 from domain-joined devices on the corporate network. Which configuration is required on the on-premises Active Directory?
A.Create a computer account named AZUREADSSOACC in each AD forest
B.Install Azure AD Connect on a separate server
C.Enable Passthrough Authentication
D.Set the service connection point in Active Directory
AnswerA
Seamless SSO requires a dedicated computer account named AZUREADSSOACC to be created in each Active Directory forest that is synchronized to Azure AD. This account is registered with Azure AD Connect during feature enablement, and its Kerberos decryption key is used to validate user sign-in requests without prompting for passwords. Without this account, the silent authentication flow cannot complete, so it is the essential prerequisite for Seamless SSO with password hash sync.
Why this answer
Azure AD Seamless SSO requires a computer account named AZUREADSSOACC to be created in each on-premises AD forest. This account is used by Azure AD to sign Kerberos tickets for users accessing Microsoft 365 resources, enabling automatic sign-in without password prompts. The account must be created in the root domain of each forest and its password is managed automatically by Azure AD Connect.
Exam trap
The trap here is that candidates often confuse Seamless SSO with Passthrough Authentication or think a separate server is required, but the key requirement is the specific computer account AZUREADSSOACC in each forest, which is a unique Kerberos-based mechanism.
How to eliminate wrong answers
Option B is wrong because installing Azure AD Connect on a separate server is not a specific requirement for Seamless SSO; Azure AD Connect can be installed on any server, but the Seamless SSO feature itself does not mandate a separate server. Option C is wrong because Passthrough Authentication is an alternative authentication method that does not use password hash synchronization; enabling it would conflict with the stated requirement of using password hash synchronization. Option D is wrong because setting a service connection point in Active Directory is used for discovering Azure AD Connect or other services, not for enabling Seamless SSO; Seamless SSO relies on the AZUREADSSOACC computer account and Kerberos delegation, not an SCP.
A company uses Microsoft Entra ID P1 licenses. They want to allow access to a sensitive cloud application only from the company's trusted office IP ranges (10.0.0.0/24). However, the executive team (group "Execs") must be able to access the app from any location. Which Conditional Access policy configuration should the administrator use?
A.A: Include all users, exclude Execs group, and grant access with condition 'Location not in trusted locations'.
B.B: Include all users, exclude Execs group, and block access with condition 'Location not in trusted locations'.
C.C: Include Execs group, exclude all others, and grant access with condition 'Location in trusted locations'.
D.D: Include all users, include Execs group as an additional condition, and grant access with condition 'Location in trusted locations'.
AnswerB
B is correct: scoping to All users with the Execs group excluded means every non-Executive user is evaluated by the policy, and applying the Block access control when the Location condition matches 'not in trusted locations' denies those users if they try to access the app from an unrecognized or untrusted IP address. Because the Execs group is placed in the exclusion list, executives remain completely exempt and can still access the app from any location, including outside trusted networks. This creates the exact intended split: non-Execs are restricted, Execs are not.
Why this answer
The requirement is to block access from untrusted locations for all users except the Execs group. By including all users, excluding the Execs group, and setting a block control with the condition 'Location not in trusted locations', the policy ensures that only non-Exec users are blocked when accessing from outside the trusted IP range, while Execs remain unrestricted. This aligns with the principle of explicitly blocking unwanted access rather than granting access with conditions that could be bypassed.
Exam trap
The trap here is that candidates often confuse 'grant access with a condition' with 'block access with a condition', mistakenly thinking that granting access from trusted locations will automatically block access from untrusted locations, but in Conditional Access, grant controls only allow access when conditions are met—they do not implicitly deny access when conditions are not met unless a block control is explicitly configured.
How to eliminate wrong answers
Option A is wrong because granting access with a condition 'Location not in trusted locations' would allow access from untrusted locations, which is the opposite of the requirement to block such access. Option C is wrong because including only the Execs group and granting access from trusted locations would allow Execs to access the app only from trusted locations, contradicting the requirement that Execs must be able to access from any location. Option D is wrong because including Execs as an additional condition (not as an exclusion) and granting access from trusted locations would force Execs to also be restricted to trusted locations, again failing the requirement for Execs to have unrestricted access.
You are the Microsoft 365 administrator for a large enterprise. You need to ensure that only users with a valid business justification can access sensitive data stored in SharePoint Online. The solution must enforce access reviews and provide detailed reports for auditors. Which TWO actions should you take?
Select 2 answers
A.Configure access reviews in Microsoft Entra ID Governance for the SharePoint site.
B.Deploy Microsoft Defender for Cloud Apps and create a session policy to monitor access.
C.Enable audit logging in Microsoft Purview and generate detailed access reports.
D.Apply a sensitivity label to the SharePoint site and require justification for label change.
E.Create a data loss prevention (DLP) policy to block unauthorized sharing.
AnswersA, C
Configuring access reviews in Microsoft Entra ID Governance automates a recurring certification workflow in which site owners or designated reviewers must explicitly confirm each user's continued need to access the SharePoint site. Every approval response is logged with a timestamp and reviewer identity, generating the audit trail required by internal policy or external auditors. This directly satisfies the business-justification and periodic-attestation requirements because access is not simply recorded; it is actively revalidated on a fixed schedule.
Why this answer
Option A is correct because Microsoft Entra ID Governance access reviews are the native mechanism to periodically attest who still needs access to a SharePoint site, enforcing the requirement that only users with a valid business justification retain access. Option C is correct because enabling audit logging in Microsoft Purview captures SharePoint Online access and activity events, and the resulting audit log search and reports provide the detailed evidence auditors require. Option B is not correct because Defender for Cloud Apps session policies monitor and control sessions but do not enforce access reviews or produce the required auditor-facing access attestation reports.
Option D is not correct because sensitivity labels with justification for label changes govern classification and labeling actions, not recurring access justification or review. Option E is not correct because a DLP policy prevents sharing of sensitive content but does not enforce access reviews or generate the detailed access reports for auditors.
Exam trap
The trap here is that candidates often confuse access control mechanisms like DLP or sensitivity labels with identity-based access reviews, failing to recognize that access reviews in Entra ID Governance enforce periodic attestation, while audit logging in Purview provides the detailed access reports for auditors.
Your organization uses Microsoft Purview Information Protection. You need to ensure that when users manually apply a 'Confidential' label to a document in Word, the document is automatically marked with a footer 'CONFIDENTIAL' and encrypted. What must you configure?
A.Modify the sensitivity label policy to include the footer.
B.Create a DLP rule that applies the footer and encryption.
C.Set up auto-labeling to apply the footer and encryption.
D.Configure the sensitivity label's settings to include the footer and encryption.
AnswerD
Configuring the sensitivity label itself with footer and encryption settings satisfies the manual-labelling requirement. Label-scoped content marking and encryption apply automatically when a user selects 'Confidential' in Word, with no separate policy or client configuration needed. Microsoft Purview Information Protection enforces both directly at label application.
Why this answer
Sensitivity labels in Microsoft Purview Information Protection can be configured with content marking (headers, footers, watermarks) and encryption settings directly in the label definition. When a user manually applies the 'Confidential' label in Word, the label's configured footer and encryption are applied automatically to the document. This is the core behavior of sensitivity labels — the label itself carries the protection settings.
Exam trap
MS-102 often tests the confusion between label policies (which control label availability and default/mandatory settings) and label settings (which define the actual protection and marking) — candidates pick the policy option thinking it configures the footer.
How to eliminate wrong answers
Option A is wrong because a sensitivity label policy controls which users see which labels and whether labeling is mandatory or default, but it does not define the footer or encryption settings. Option B is wrong because DLP rules can detect and act on sensitive content but are not the mechanism that applies footer marking and encryption when a label is manually applied; DLP is for policy enforcement, not label content marking. Option C is wrong because auto-labeling applies labels automatically based on content inspection, whereas the scenario specifies the user manually applies the label — auto-labeling is not needed and would not configure the footer/encryption anyway.
Your organization is migrating from on-premises Exchange to Exchange Online. You need to ensure that users can access their mailboxes during the migration with minimal interruption. Which migration method should you use?
A.Minimal hybrid migration.
B.Cutover migration.
C.Staged migration.
D.IMAP migration.
AnswerA
Minimal hybrid migration establishes a lightweight coexistence by synchronizing identities with Azure AD Connect and configuring an Exchange hybrid endpoint, allowing you to move mailboxes in controlled batches through the Migration Dashboard. Because users retain their passwords via single sign-on and mail flow continues to work on both sides, the move has minimal user impact and can be performed incrementally, which is exactly why it is the correct approach for an Exchange-to-Exchange Online migration.
Why this answer
A minimal hybrid migration is the correct choice because it allows you to synchronize on-premises mailboxes with Exchange Online using the Hybrid Configuration Wizard (HCW) and then move mailboxes in batches with minimal downtime. Users retain access to their existing mailboxes during the migration, and once a mailbox is moved, Outlook automatically reconfigures via Autodiscover, ensuring a seamless transition.
Exam trap
The trap here is that candidates often confuse 'minimal hybrid' with 'cutover migration,' assuming cutover is simpler, but the question explicitly requires minimal interruption, which cutover cannot provide due to its all-at-once nature.
How to eliminate wrong answers
Option B (Cutover migration) is wrong because it requires migrating all mailboxes at once within a limited time window, causing significant downtime and disruption for users. Option C (Staged migration) is wrong because it is only supported for migrating from on-premises Exchange 2003 or 2007, not newer versions, and requires provisioning mail-enabled users in advance, which adds complexity. Option D (IMAP migration) is wrong because it only migrates email data (not calendar, contacts, or tasks) and does not provide a unified global address list or coexistence features, leading to a poor user experience.
Your organization uses Microsoft Defender XDR. You are configuring a custom detection rule to detect a specific behavior: a user runs a PowerShell script that connects to a known malicious IP address. Which TWO advanced hunting tables should you use in your KQL query to detect this behavior?
Select 2 answers
A.DeviceProcessEvents
B.DeviceRegistryEvents
C.DeviceLogonEvents
D.DeviceFileEvents
E.DeviceNetworkEvents
AnswersA, E
DeviceProcessEvents captures process creation, including PowerShell command lines, satisfying the requirement to detect script execution. However, it does not record network connections, so pairing it with DeviceNetworkEvents is necessary to identify the connection to the known malicious IP address.
Why this answer
To detect a user running a PowerShell script that connects to a known malicious IP address, you need to correlate process creation events (to capture the PowerShell script execution) with network connection events (to capture the outbound connection to the IP address). DeviceProcessEvents tracks process creation, including PowerShell.exe. DeviceNetworkEvents tracks network connections to remote IP addresses.
Therefore, the correct tables are DeviceProcessEvents (A) and DeviceNetworkEvents (E).
Your organization uses Microsoft 365 Business Premium. You need to ensure that all Windows 10 devices are enrolled in Microsoft Intune and comply with a device compliance policy that requires BitLocker encryption and a minimum OS version. What should you do first?
A.Configure automatic enrollment in Microsoft Entra ID for Windows 10 devices.
B.Install the Intune Connector for Active Directory on a domain controller.
C.Deploy a configuration profile to enable BitLocker.
D.Create a device compliance policy in Microsoft Intune.
AnswerA
Configure automatic enrollment in Microsoft Entra ID for Windows 10 devices: This is the correct approach. In Microsoft Entra ID (formerly Azure AD), you can enable Windows automatic enrollment as part of the MDM/MAM integration with Intune. When a Windows 10/11 device performs an Azure AD join or registers with Azure AD, it automatically and silently enrolls into Intune, requiring no user interaction and eliminating the need for manually deploying enrollment scripts or connectors. This must be set before you can apply device configuration profiles or compliance policies.
Why this answer
To enforce Intune compliance policies on Windows 10 devices, the devices must first be enrolled in Intune. Automatic enrollment in Microsoft Entra ID (formerly Azure AD) is the prerequisite step that enables Windows 10 devices to automatically enroll in Intune when they join or are registered with Entra ID. Without this enrollment configured, no Intune policies—including compliance policies—can be applied to the devices.
Exam trap
The trap here is that candidates often jump to creating a compliance policy or deploying a configuration profile first, forgetting that without automatic enrollment enabled, Intune has no management relationship with the devices to apply those policies.
How to eliminate wrong answers
Option B is wrong because the Intune Connector for Active Directory is used for on-premises AD-joined devices to synchronize with Entra ID and enable hybrid Azure AD join, but it is not the first step required for Intune enrollment and compliance; automatic enrollment must be configured first. Option C is wrong because deploying a configuration profile to enable BitLocker is a subsequent step that can only be applied after devices are enrolled in Intune; it does not cause enrollment itself. Option D is wrong because creating a device compliance policy is also a later step that requires devices to already be enrolled in Intune; the policy cannot be assigned or evaluated until enrollment is established.
A compliance officer needs to ensure that all emails containing sensitive information (e.g., passport numbers) are automatically encrypted when sent to external recipients. The encryption should be enforced without requiring users to manually select an option. Which Microsoft Purview feature should they configure?
A.Data Loss Prevention (DLP) policy with encryption action
B.Sensitivity labels with auto-labeling
C.Message Encryption (OME) policies
D.Communication Compliance
AnswerA
Data Loss Prevention (DLP) policies in Microsoft Purview can directly apply an encryption action to outgoing email by leveraging Azure Rights Management. When a DLP policy detects a sensitive information type (e.g., credit card numbers or personally identifiable information) in the message body or attachments, it automatically wraps the message with the 'Encrypt' action, enforcing transport-level protection without user intervention. This policy-based approach is purpose-built for compliance scenarios where data exfiltration must be prevented at the email boundary.
Why this answer
A Data Loss Prevention (DLP) policy with encryption action is correct because it automatically detects sensitive information (e.g., passport numbers) using sensitive info types and enforces encryption via Microsoft Purview Message Encryption (OME) as a rule action. This ensures that when an email containing such data is sent to an external recipient, the email is automatically encrypted without requiring user intervention, meeting the compliance officer's requirement.
Exam trap
The trap here is that candidates often confuse sensitivity labels with auto-labeling as the solution for automatic encryption, but auto-labeling only applies labels based on conditions and does not enforce encryption unless the label itself is configured for encryption and the DLP policy triggers the action.
How to eliminate wrong answers
Option B is wrong because sensitivity labels with auto-labeling can classify and protect content but do not directly enforce encryption on outbound emails based on content detection; they require a DLP policy to trigger the encryption action. Option C is wrong because Message Encryption (OME) policies define encryption rules but are typically configured within DLP policies or mail flow rules; standalone OME policies do not automatically detect sensitive data and enforce encryption without additional conditions. Option D is wrong because Communication Compliance is designed to detect and investigate policy violations (e.g., harassment, insider trading) and does not provide automatic encryption of emails based on sensitive content.
Which TWO are valid methods for adding custom domains to Microsoft 365?
Select 2 answers
A.Using the New-MsolDomain PowerShell cmdlet.
B.Using the Exchange admin center (EAC).
C.Using the Azure AD B2C tenant configuration.
D.Using the 'Add domain' wizard in the Microsoft 365 admin center.
E.Using the Windows DNS Manager console.
AnswersA, D
The New-MsolDomain cmdlet comes from the legacy MSOnline module and directly invokes Azure AD's domain registration API, creating an unverified domain object in the tenant's directory. After that, you run New-MsolDomainVerificationDns to obtain the TXT record and New-MsolDomain to re-verify once the record is live. It is a valid, scriptable method, though Microsoft now deprecates MSOnline in favor of Microsoft Graph.
Why this answer
Option A is correct because the New-MsolDomain cmdlet from the MSOnline PowerShell module is a supported programmatic way to add a custom domain to a Microsoft 365/Azure AD tenant, specifying parameters such as -Name for the domain. Option D is correct because the 'Add domain' wizard in the Microsoft 365 admin center is the primary GUI method for adding a custom domain, after which it provides the required DNS TXT or MX records for verification. Option B is incorrect because the Exchange admin center manages Exchange Online recipients, mailboxes, and accepted domains for mail flow, but it is not the supported tool for adding a new custom domain to the tenant.
Option C is incorrect because Azure AD B2C is a separate customer identity service with its own tenant configuration and is unrelated to adding domains to a standard Microsoft 365 tenant. Option E is incorrect because Windows DNS Manager only manages DNS zones and records on a DNS server; it cannot add a domain to Microsoft 365, though it may be used to create the verification records if the domain is hosted on that DNS server.
Exam trap
The trap here is that candidates confuse the Exchange admin center's ability to manage 'accepted domains' with the initial domain addition process, or they mistakenly think on-premises DNS tools like Windows DNS Manager can directly add domains to Microsoft 365, when in fact they only handle the DNS verification records after the domain is registered in the tenant.
An administrator wants to add custom branding to the Microsoft 365 sign-in page, including company logo and colors. Which section of the Microsoft 365 admin center should they navigate to?
A.Users > Active users
B.Settings > Org settings > Organization profile
C.Admin centers > Azure Active Directory
D.Billing > Licenses
AnswerB
In the Microsoft 365 admin center, the correct path is Settings > Org settings > Organization profile, which contains the 'Custom branding' section. This is where you upload a logo, choose a background image, and customize the sign-in page text for your organization's Microsoft 365 sign-in experience. The Organization profile settings consolidate tenant-wide identity and branding configurations under one management area.
Why this answer
The custom branding for the Microsoft 365 sign-in page, including company logo and colors, is configured under Settings > Org settings > Organization profile in the Microsoft 365 admin center. This section provides a dedicated 'Custom branding' tab where administrators can upload a logo, set a background image, and choose accent colors that are applied to the sign-in page for all users in the tenant.
Exam trap
The trap here is that candidates often confuse the Microsoft 365 admin center path with the Azure Active Directory admin center path, both of which have branding settings, but the question explicitly asks for the Microsoft 365 admin center navigation, making the Azure AD path (Option C) a distractor.
How to eliminate wrong answers
Option A is wrong because Users > Active users is used for managing individual user accounts, passwords, and licenses, not for tenant-wide branding settings. Option C is wrong because Admin centers > Azure Active Directory opens the Azure AD portal, which does contain branding settings (under 'Company branding'), but the question specifically asks for the Microsoft 365 admin center navigation path, not the Azure AD portal. Option D is wrong because Billing > Licenses is used to assign and manage subscription licenses, not to configure sign-in page branding.
Your organization uses Microsoft Defender for Cloud Apps. You need to be alerted when a user accesses a cloud app from an anonymous IP address. Which type of policy should you create?
A.Session policy
B.File policy
C.Activity policy
D.App discovery policy
AnswerC
Activity policies in Microsoft Defender for Cloud Apps inspect user activity events and raise alerts on matching conditions. Configuring one with an anonymous IP filter detects access from anonymising proxies or Tor, satisfying the stem's requirement to alert on anonymous IP access.
Why this answer
An activity policy in Microsoft Defender for Cloud Apps can detect access from anonymous IP addresses by monitoring user activities. Option A is incorrect because a session policy controls user sessions in real-time but does not specifically alert on anonymous IP access. Option B is incorrect because a file policy focuses on monitoring and protecting files, not on access from anonymous IPs.
Option D is incorrect because an app discovery policy is used to discover shadow IT and unsanctioned apps, not to alert on anonymous IP access.
A Microsoft 365 administrator needs to add a new verified domain named tailspintoys.com to the tenant and then configure it as the default domain for new user principal names. Which sequence of actions should the administrator perform in the Microsoft 365 admin center?
A.Add the domain, verify it by signing in with a global administrator account from that domain, then set it as default.
B.Set the domain as default first, then add the verification TXT record so Microsoft can confirm ownership afterward.
C.Add the domain, create the required TXT or MX verification record at the DNS host, verify ownership, then set the domain as default.
D.Create the verification record at the DNS host, then add the domain and set it as default in a single step.
AnswerC
Adding a domain in the Microsoft 365 admin center generates a verification record that must be published at the public DNS provider. After Microsoft confirms the record, ownership is verified and the domain can be designated as the default, which makes it the suffix used for new user principal names and new email addresses.
Why this answer
Adding a custom domain requires proving DNS ownership through a TXT or MX record generated by the admin center. Only after verification succeeds can the domain be marked as default, which controls the suffix applied to new user principal names and email addresses. Setting default first, pre-creating records, or attempting account-based verification all fail because Microsoft requires DNS proof before the namespace is usable.
Exam trap
The trap here is reversing the order and assuming the default designation can be applied before Microsoft verifies DNS ownership of the domain.
Your company has a Microsoft 365 E5 tenant with Microsoft Entra ID P2. You are the security administrator. You need to implement a solution that automatically detects and remediates identity risks. Requirements:
- Risky sign-ins (e.g., from anonymous IP addresses) should be automatically blocked.
- Users with confirmed compromised credentials should be forced to reset their password at next sign-in.
- You need to receive alerts when high-risk events occur.
- The solution must minimize false positives.
Which Microsoft Entra ID features should you combine?
A.Set up Microsoft Entra Identity Governance access reviews and enable self-service password reset.
B.Configure Conditional Access policies to block sign-ins from anonymous IP addresses and require password reset for all users.
C.Enable Microsoft Entra Identity Protection, configure a sign-in risk policy to block high-risk sign-ins, and a user risk policy to require password reset for high-risk users. Set up alerts for risk events.
D.Deploy Microsoft Defender for Cloud Apps to detect risky sign-ins and configure session policies.
AnswerC
Microsoft Entra Identity Protection continuously evaluates sign-in and user risk using detections like leaked credentials, impossible travel, and unfamiliar properties. A sign-in risk policy can block high-risk sign-ins, and a user risk policy can require a secure password reset for high-risk users. Configuring alerts for risk events enables investigation. This provides the adaptive, real-time protection the company needs.
Why this answer
The correct combination is Microsoft Entra Identity Protection with a sign-in risk policy to block high-risk sign-ins and a user risk policy to require password reset for high-risk users, plus alerts for risk events. Identity Protection uses machine learning to detect risky sign-ins and compromised credentials, and the risk policies automatically remediate based on risk level. This minimizes false positives by using risk-based conditional access.
Exam trap
MS-102 often tests the difference between Identity Protection and other security features like Defender for Cloud Apps or Conditional Access alone, and candidates may incorrectly choose a solution that does not include risk-based policies.
How to eliminate wrong answers
Option A is wrong because Identity Governance access reviews and self-service password reset do not automatically detect and remediate identity risks; they are for access certification and password management, not risk detection. Option B is wrong because configuring Conditional Access to block sign-ins from anonymous IP addresses and require password reset for all users is too broad and does not use risk detection; it would cause many false positives and is not automated based on risk. Option D is wrong because Microsoft Defender for Cloud Apps is for cloud app security and session policies, not for identity risk detection and remediation; it does not provide the required user risk and sign-in risk policies.
You are a Microsoft 365 administrator for Tailspin Toys. The security team wants to reduce the number of alerts generated by Microsoft Defender for Endpoint on Windows 10 devices that run a custom line-of-business application. The application performs many legitimate network connections that trigger the 'Suspicious network connection' alert. You need to suppress these alerts while still investigating all other alerts. What should you create in the Microsoft 365 Defender portal?
A.An automated investigation and response (AIR) playbook that closes the alert automatically.
B.An alert suppression rule for the 'Suspicious network connection' alert scoped to the affected devices or application.
C.An indicator of compromise (IoC) for the application's executable hash with the action Allow.
D.A custom detection rule that queries DeviceNetworkEvents and marks the connections as benign.
AnswerB
Alert suppression rules in Microsoft Defender for Endpoint let you suppress specific alerts for defined scopes, such as a device group, file hash, IP address, or URL. Scoping the rule to the custom application and the affected devices stops the noisy alert while leaving all other detections active, which matches the requirement to keep investigating other alerts.
Why this answer
Alert suppression rules in Microsoft Defender for Endpoint are designed to reduce alert noise by suppressing specific alerts within a defined scope, such as a device group, file hash, IP address, or URL. Scoping the rule to the line-of-business application and its devices silences the known false positive while preserving visibility into all other alerts. Indicators of compromise change block or allow behavior, and AIR or custom detections act after or alongside alerts rather than suppressing them.
Exam trap
The trap here is confusing an allow indicator of compromise with alert suppression, when an allow IoC changes blocking behavior but does not stop behavioral alerts from being generated.
Your organization uses Microsoft Entra ID and has a hybrid identity setup with password hash synchronization. You need to ensure that when a user's on-premises Active Directory account is disabled, their Microsoft Entra ID account is also disabled within 30 minutes. What should you do?
A.Enable Azure AD Connect cloud sync.
B.Configure password hash synchronization to run every 30 minutes.
C.Configure Azure AD Connect to sync the 'userAccountControl' attribute and set the sync frequency to 30 minutes.
D.Enable password writeback.
AnswerC
The userAccountControl attribute stores bit flags such as UF_ACCOUNTDISABLE, which directly determines whether the account is enabled. Synchronizing this attribute through Azure AD Connect propagates on-premises account status changes to Microsoft Entra ID. By explicitly setting the synchronization frequency to 30 minutes, you ensure that the next sync cycle will reflect the updated account state, making the current configuration the correct method to address the requirement.
Why this answer
Disabling an on-premises Active Directory account sets the 'userAccountControl' attribute (specifically the ACCOUNTDISABLE flag, bit 2). By configuring Azure AD Connect to sync this attribute and setting the sync frequency to 30 minutes, the disabled state is replicated to Microsoft Entra ID within that interval, ensuring the cloud account is also disabled.
Exam trap
The trap here is that candidates often confuse password hash synchronization (which handles password changes) with account status synchronization, mistakenly thinking that disabling an on-premises account automatically disables the cloud account without configuring attribute sync and schedule.
How to eliminate wrong answers
Option A is wrong because Azure AD Connect cloud sync is a separate synchronization service for syncing objects from multiple disconnected forests, not for controlling the sync frequency or attribute-level changes like userAccountControl. Option B is wrong because password hash synchronization only syncs password hashes for authentication, not user account status or the userAccountControl attribute; it does not disable accounts. Option D is wrong because password writeback enables password changes from the cloud to on-premises, not the synchronization of account disabled status.
A development team builds a background service that needs to read all users' calendars via Microsoft Graph without a signed-in user. The service will run on a server with a client secret. Which OAuth 2.0 grant flow should the application use?
A.Authorization code grant
B.Device authorization grant
C.Client credentials grant
D.Implicit grant
AnswerC
Client credentials grant is the OAuth 2.0 flow designed for confidential client applications acting as themselves. The daemon authenticates directly to the Microsoft identity platform token endpoint using its client ID and a secret or certificate, and receives an application token containing scopes that were pre-configured as application permissions (app roles). No user consent prompt or redirect is involved, enabling fully unattended execution for a server-hosted background service.
Why this answer
The client credentials grant is designed for server-to-server, non-interactive scenarios where an application authenticates as itself (not on behalf of a user) to access resources. Since the background service runs with a client secret and needs to read all users' calendars without a signed-in user, this flow is the correct choice because it uses the application's own identity to obtain an access token from Microsoft Entra ID.
Exam trap
The trap here is that candidates often confuse delegated permissions with application permissions and incorrectly choose the authorization code grant, thinking a user context is always required for accessing user data, but the client credentials grant bypasses the user entirely by using app-only permissions.
How to eliminate wrong answers
Option A is wrong because the authorization code grant requires a signed-in user to authenticate and consent, which contradicts the requirement of no signed-in user. Option B is wrong because the device authorization grant is intended for devices with limited input capabilities (e.g., smart TVs, IoT) and still requires user interaction via a separate browser to sign in. Option D is wrong because the implicit grant is deprecated and was designed for single-page applications (SPAs) using browser-based flows; it also requires a signed-in user and does not support client secrets.
Refer to the exhibit. You are reviewing a Conditional Access policy in Microsoft Entra ID. What is the effect of this policy?
A.All users accessing all cloud apps are required to use MFA
B.Access to Office 365 from iOS and Android is blocked
C.All users on iOS or Android devices accessing Office 365 must use MFA and a compliant device
D.Users on mobile devices are required to use hybrid Azure AD joined devices
AnswerC
The policy targets all users, with device platforms restricted to iOS and Android, and cloud apps restricted to Office 365. Both grant controls, require multifactor authentication and require device to be marked as compliant, are selected with the AND operator, so both must be satisfied before access is granted.
Why this answer
The policy shown in the exhibit explicitly targets 'All users' and 'Office 365' as the cloud app, with conditions for 'iOS' and 'Android' device platforms. The grant controls require both 'Require multi-factor authentication' and 'Require device to be marked as compliant', meaning any user on an iOS or Android device accessing Office 365 must satisfy both MFA and device compliance. This is a common Conditional Access policy to enforce secure access from mobile devices.
Exam trap
The trap here is that candidates may misinterpret 'Require device to be marked as compliant' as requiring hybrid Azure AD join, but compliance is a separate concept managed by Intune and does not mandate hybrid join.
How to eliminate wrong answers
Option A is wrong because the policy does not apply to 'All cloud apps' — it is scoped specifically to 'Office 365' cloud app, not all cloud apps. Option B is wrong because the policy does not block access; it grants access only if MFA and device compliance are satisfied, which is a conditional grant, not a block. Option D is wrong because the policy does not require hybrid Azure AD joined devices; it requires the device to be marked as compliant, which can be achieved through Intune enrollment and compliance policies, not necessarily hybrid join.
A company uses Azure AD Identity Protection. The security team wants to automatically block sign-ins that are detected as coming from a known malicious IP address. Which policy should be configured?
A.User risk policy
B.Sign-in risk policy
C.MFA registration policy
D.Identity Protection vulnerabilities policy
AnswerB
The sign-in risk policy evaluates real-time risk for each authentication request and is the correct control to block access from known malicious IP addresses or other high-risk sign-in indicators, such as anonymous IP addresses or unfamiliar properties. You configure conditional thresholds (for example, Low, Medium, High) and choose an action like 'Block access' or 'Allow with MFA' based on the evaluated risk level. Since the question targets IP-based threats, this policy directly assesses the IP address reputation at sign-in time, unlike user-level risk policies that focus on the account's history.
Why this answer
The Sign-in risk policy in Azure AD Identity Protection is specifically designed to respond to risks detected during the authentication attempt, such as sign-ins from known malicious IP addresses. When a sign-in is flagged as having a high risk level (e.g., from a known malicious IP), the policy can be configured to automatically block the sign-in. This directly addresses the security team's requirement to block sign-ins from malicious IPs.
Exam trap
The trap here is that candidates often confuse the User risk policy (which deals with account compromise) with the Sign-in risk policy (which deals with session-level threats like IP reputation), leading them to select the User risk policy instead of the correct Sign-in risk policy.
How to eliminate wrong answers
Option A is wrong because the User risk policy responds to risks associated with a user's account (e.g., leaked credentials or anomalous behavior), not to risks detected during a specific sign-in attempt like IP reputation. Option C is wrong because the MFA registration policy enforces that users register for multifactor authentication, but it does not evaluate or block sign-ins based on IP address risk. Option D is wrong because there is no 'Identity Protection vulnerabilities policy' in Azure AD Identity Protection; vulnerabilities are managed via other tools like Microsoft Secure Score, not a policy that blocks sign-ins.
Your organization has Microsoft Defender for Office 365 Plan 2. You need to ensure that when a user reports a phishing email using the Report Message add-in, the email is automatically submitted to Microsoft for analysis and the user is notified of the result. What should you configure?
A.Create a Safe Links policy to block the reported email
B.Configure an anti-phishing policy to automatically submit reported emails
C.Use a mail flow rule to send reported emails to a custom mailbox
D.Configure a submission policy in the Microsoft 365 Defender portal
AnswerD
A submission policy in the Microsoft 365 Defender portal defines how user-reported messages are handled, including automatic submission to Microsoft for analysis and configuring notifications back to the reporting user. This directly satisfies the requirement to submit reported phishing emails and notify users of the verdict.
Why this answer
In Microsoft 365 Defender, user-reported messages are handled through the Submissions page, governed by a user submission policy. Configuring this policy in the Defender portal lets you route reported phish to Microsoft for analysis, set the user-reported mailbox, and enable result notifications back to the reporting user. This is the native mechanism for the Report Message/Report Phishing add-ins.
Exam trap
MS-102 often tests the misconception that anti-phishing or Safe Links policies handle user-reported messages; candidates pick those because they sound security-related, missing that submissions are governed by a dedicated submission policy.
How to eliminate wrong answers
Option A is wrong because Safe Links rewrites and detonates URLs at click time; it does not process user-reported messages or notify reporters. Option B is wrong because anti-phishing policies define impersonation and spoof intelligence thresholds, not the user-reporting submission workflow. Option C is wrong because a mail flow (transport) rule can redirect mail to a mailbox but does not submit to Microsoft for analysis or generate user notifications.
A security administrator needs to block executable files (e.g., .exe, .ps1) from running from the %TEMP% folder on Windows devices to prevent common malware execution. Which attack surface reduction (ASR) rule should be enabled?
A.Block executable files from running unless they meet a prevalence, age, or trusted list criterion
B.Block executable content from email client and webmail
C.Block Office applications from creating child processes
D.Block credential stealing from the Windows local security authority subsystem (lsass.exe)
AnswerA
This ASR rule blocks executables from running in common writable folders, including %TEMP%, unless the executable is prevalent, old enough, or on an allowlist. It uses cloud-based reputation to evaluate the file's prevalence and age, allowing trusted files while blocking unknown or untrusted ones. Since the scenario requires blocking .exe and .ps1 files from launching in the temporary folder, this reputation-based filter is the correct mitigation.
Why this answer
ASR rule 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25) is designed specifically to block executables (including .exe, .ps1, .scr, .dll) from launching from locations like %TEMP%, %APPDATA%, and the Windows folder, which are common malware staging areas. This rule uses cloud-delivered reputation (prevalence and age) and a Microsoft-managed trusted list to allow legitimate files while blocking unknown or suspicious ones, directly addressing the requirement to prevent malware execution from %TEMP%.
Exam trap
The trap here is that candidates confuse ASR rules by their generic names — they might pick 'Block executable content from email client and webmail' because it mentions 'executable content,' but the question specifically targets execution from the %TEMP% folder, not email delivery.
How to eliminate wrong answers
Option B is wrong because 'Block executable content from email client and webmail' targets executable attachments and scripts in email/webmail clients (e.g., Outlook, Gmail) to prevent phishing-based malware delivery, not execution from local folders like %TEMP%. Option C is wrong because 'Block Office applications from creating child processes' prevents Office apps (Word, Excel, etc.) from spawning child processes (e.g., cmd.exe, powershell.exe), which stops macro-based attacks but does not restrict executables already in %TEMP%. Option D is wrong because 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' specifically protects LSASS memory from being dumped or accessed by tools like Mimikatz, addressing credential theft, not executable execution from %TEMP%.
A security team wants to automatically investigate and remediate alerts generated from Microsoft Defender for Endpoint, Office 365, and Microsoft Entra ID. Which Microsoft Defender XDR capability should be configured?
A.Threat Analytics
B.Automated Investigation and Response
C.Advanced Hunting
D.Secure Score
AnswerB
Automated Investigation and Response (AIR) in Microsoft 365 Defender orchestrates security playbooks across endpoints, email, and identity signals, automatically collecting evidence, initiating investigations, and executing remediation actions such as quarantining files, suspending accounts, and blocking URLs. AIR leverages AI and predefined automation rules to contain low-impact threats in real time, with optional human approval for destructive actions.
Why this answer
Automated Investigation and Response (AIR) in Microsoft Defender XDR is the correct capability because it automatically triggers playbooks to investigate and remediate alerts across Microsoft Defender for Endpoint, Office 365, and Microsoft Entra ID. AIR uses predefined or custom automation rules to correlate signals from these sources, run investigations, and apply remediation actions like isolating devices or blocking accounts without manual intervention.
Exam trap
The trap here is that candidates often confuse Threat Analytics (which provides threat intelligence) with Automated Investigation and Response (which executes automated remediation), leading them to select A when the question explicitly asks for a capability that 'automatically investigates and remediates' alerts.
How to eliminate wrong answers
Option A is wrong because Threat Analytics is a reporting and intelligence feature that provides threat actor profiles, attack techniques, and recommended mitigations, but it does not perform automated investigation or remediation actions. Option C is wrong because Advanced Hunting is a query-based tool using Kusto Query Language (KQL) to manually search for threats across raw data tables, not an automated response mechanism. Option D is wrong because Secure Score is a security posture measurement tool that tracks configuration improvements and recommendations, not a capability for investigating or responding to active alerts.
Which TWO actions can you perform using Microsoft Entra ID Governance? (Choose two.)
Select 2 answers
A.Manage device compliance policies
B.Automate user access reviews
C.Configure single sign-on for SaaS apps
D.Delegate administrative roles
E.Manage entitlement management
AnswersB, E
Automating user access reviews is a core feature of Microsoft Entra ID Governance, allowing organizations to schedule recurring attestation for access to groups, applications, and roles. Reviews can include automatic reminders and apply decisions like removing dormant access when a reviewer does not act. This transforms a manual audit process into an ongoing control, ensuring access remains appropriate and compliant over time.
Why this answer
Microsoft Entra ID Governance includes automated user access reviews, which allow organizations to periodically certify that users still need access to applications, groups, and roles. These reviews can be scheduled, recurring, and delegated to reviewers, with automated actions like removing access when a reviewer does not respond. This directly supports compliance and least-privilege principles.
Exam trap
The trap here is that candidates confuse general Entra ID features (like SSO and role delegation) with the specific governance capabilities of Entra ID Governance, which focuses on access lifecycle, reviews, and entitlement management.
You are a Microsoft 365 administrator for a multinational company. The security team reports that a large number of failed sign-in attempts are originating from unexpected IP ranges. The company uses Microsoft Entra ID for identity. What should you configure to automatically block these malicious sign-ins?
A.Enable Security defaults in the tenant
B.Configure Identity Protection user risk policy to block high-risk users
C.Enable Azure AD Multi-Factor Authentication for all users
D.Create a Conditional Access policy to block access from those IP ranges
AnswerD
Create a Conditional Access policy that targets the relevant users and cloud apps, and then add a Locations condition using a named location containing the specific IP ranges. Set the access control to 'Block' and enable the policy to enforce a hard deny for sign-ins originating from those ranges. Because Conditional Access evaluates network location at authentication time, this directly addresses the requirement for blocking specific IP addresses.
Why this answer
A Conditional Access policy can explicitly block sign-ins from specific IP ranges. By creating a policy that targets all users or specific users and includes a condition for the named location (the unexpected IP ranges), you can automatically deny authentication requests from those addresses at the Entra ID level, effectively blocking malicious sign-ins before they reach any application.
Exam trap
The trap here is that candidates often confuse Identity Protection risk policies (which block based on user risk) with Conditional Access location-based blocking, or they assume Security defaults or MFA alone can block specific IP ranges, when in fact only a Conditional Access policy with an IP location condition can achieve that granular control.
How to eliminate wrong answers
Option A is wrong because Security defaults enforces baseline security (like MFA for all users) but does not allow you to block specific IP ranges; it is a tenant-wide setting with no granular IP-based conditions. Option B is wrong because the Identity Protection user risk policy blocks users based on risk level (e.g., high-risk users), not based on originating IP addresses; it addresses compromised accounts, not IP-based attacks. Option C is wrong because enabling MFA for all users adds an authentication factor but does not block sign-ins from specific IP ranges; an attacker from those IPs could still attempt MFA prompts or bypass them.
You are investigating a potential security incident in Microsoft Defender XDR. The incident involves a user who received a phishing email and clicked a link that executed a PowerShell script. You need to perform a detailed investigation of the PowerShell script's behavior across all affected devices. Which feature should you use?
A.Advanced hunting in Microsoft Defender XDR.
B.The Action Center in Microsoft Defender XDR.
C.Live Response from Microsoft Defender for Endpoint.
D.The device timeline in the Microsoft 365 Defender portal.
AnswerA
Advanced hunting in Microsoft Defender XDR is a KQL-based query tool that gives you access to raw telemetry stored in a structured schema, including tables such as DeviceProcessEvents, DeviceNetworkEvents, and EmailAttachmentInfo. You can run a query on a suspicious script hash, process name, or command line to identify every endpoint and mailbox where that script may have appeared, enabling cross-domain threat hunting. This direct access to historical, correlated data makes it the correct choice for a cross-device investigation.
Why this answer
Advanced hunting in Microsoft Defender XDR allows you to run KQL queries across all affected devices, enabling detailed investigation of the PowerShell script's behavior. It provides access to raw event data from multiple sources, including device process events, network connections, and file operations, which are essential for understanding script execution and impact.
Exam trap
MS-102 often tests the distinction between advanced hunting (proactive, cross-device querying) and live response (reactive, single-device remediation), causing candidates to confuse investigation with remediation.
How to eliminate wrong answers
Option B is wrong because the Action Center is used to manage remediation actions, not for proactive investigation. Option C is wrong because Live Response is designed for remote interactive remediation on a single device, not for querying across all affected devices. Option D is wrong because the device timeline shows events for a single device, not across all devices, and lacks the query flexibility of advanced hunting.
Which THREE steps are required to enable group-based licensing?
Select 3 answers
A.Configure Azure AD Connect
B.Add members to the group
C.Create a security group
D.Ensure group is mail-enabled
E.Assign a license to the group
AnswersB, C, E
Members inherit license.
Why this answer
Group-based licensing in Azure AD requires that you add members to the security group that will have the license assigned. Without members, the license assignment has no effect, as the license is applied to all users in the group. This step ensures that the intended users receive the license automatically based on group membership.
Exam trap
The trap here is that candidates often think Azure AD Connect is required for any group-based operation, but group-based licensing is a cloud-native feature that does not require hybrid synchronization; the only prerequisites are an Azure AD tenant, a security group, and a valid license SKU.
You are a Microsoft 365 administrator for a company that uses Microsoft Entra ID P1. The company wants to allow users to register for self-service password reset (SSPR) and require them to use two methods for authentication. You need to configure SSPR to require two methods. What should you do?
A.In the Microsoft Entra admin center, go to Users > Password reset > Properties, and enable 'Require two methods'.
B.Enable security defaults in Microsoft Entra ID.
C.Configure a Conditional Access policy that requires MFA for all users.
D.In the Microsoft Entra admin center, go to Password reset > Authentication methods, and set 'Number of methods required to reset' to 2.
AnswerD
The SSPR settings include an option for 'Number of methods required to reset'. Setting it to 2 requires users to register and use two authentication methods to reset their password. This directly meets the requirement. This setting is available in the Microsoft Entra admin center under Password reset > Authentication methods.
Why this answer
Self-service password reset settings in Microsoft Entra ID allow you to specify the number of authentication methods required to reset a password. By navigating to Password reset > Authentication methods and setting 'Number of methods required to reset' to 2, users must register and use two methods. This fulfills the requirement directly without affecting sign-in MFA.
Exam trap
The trap here is confusing Conditional Access MFA with SSPR authentication methods, which are configured separately.
You are a Microsoft 365 administrator. Your organization uses Microsoft Entra ID and Microsoft Intune for device management. You need to ensure that only compliant devices can access corporate email via Microsoft Outlook on mobile devices. What should you configure?
A.Create a Conditional Access policy with 'Require device to be marked as compliant'
B.Deploy app protection policies (MAM) for Outlook
C.Enable Microsoft Entra device registration
D.Create a device compliance policy in Intune
AnswerA
A Conditional Access policy with 'Require device to be marked as compliant' is the correct enforcement mechanism because Conditional Access acts as the real-time policy engine in Microsoft Entra ID (Azure AD) that evaluates the device's compliance state at the moment of sign-in. It checks the compliance status that Intune has reported for the device and blocks or allows access based on that report, applying to all selected cloud apps. Without this Conditional Access grant control, a device could be non-compliant yet still access resources, because the compliance check is not enforced elsewhere. This policy is what translates 'device must be compliant' from a status label into an access decision.
Why this answer
Conditional Access policies in Microsoft Entra ID can enforce 'Require device to be marked as compliant' as a grant control. This ensures that only devices meeting your Intune compliance policies (e.g., encryption, OS version, threat level) are allowed to access corporate email via Outlook on mobile devices. The policy evaluates device compliance status reported by Intune and blocks access if the device is non-compliant.
Exam trap
The trap here is that candidates often confuse device compliance policies (which define rules) with Conditional Access policies (which enforce access decisions), or they assume MAM policies alone can block non-compliant devices, but MAM does not evaluate device compliance status.
How to eliminate wrong answers
Option B is wrong because app protection policies (MAM) manage data protection at the app level (e.g., prevent copy-paste, require PIN) but do not enforce device-level compliance; they can be applied to unmanaged devices but do not check Intune compliance status. Option C is wrong because enabling Microsoft Entra device registration is a prerequisite for device-based Conditional Access but alone does not enforce compliance; it merely creates a device identity in Entra ID. Option D is wrong because a device compliance policy in Intune defines the compliance rules (e.g., require BitLocker, minimum OS) but does not enforce access control; it must be paired with a Conditional Access policy to block non-compliant devices.
An administrator wants to add a custom domain 'contoso.com' to a new Microsoft 365 tenant. The domain is already registered and available. What is the first step the administrator should perform in the Microsoft 365 admin center?
A.Add the domain and verify ownership by creating a TXT record
B.Create user accounts with the new domain
C.Configure email routing with MX records
D.Set up SharePoint Online with the new domain
AnswerA
Adding the domain and proving ownership via a TXT record is the mandatory first step; Microsoft 365 cannot create mail-enabled objects or DNS-dependent services until the tenant confirms the administrator controls contoso.com. Verification must precede any user, mailbox or DNS configuration.
Why this answer
The first step when adding a custom domain to a Microsoft 365 tenant is to add the domain in the admin center and then verify ownership by creating a TXT record in the domain's DNS zone. This proves you control the domain before any services (like email or SharePoint) can be configured. Without verification, Microsoft 365 will not allow further domain-related setup.
Exam trap
The trap here is that candidates may think MX record configuration is the first step because they associate domains primarily with email, but Microsoft 365 requires ownership verification via TXT record before any service-specific DNS changes are allowed.
How to eliminate wrong answers
Option B is wrong because user accounts cannot be created with the new domain until the domain is verified; attempting to do so will fail. Option C is wrong because configuring email routing with MX records is a later step that requires the domain to be verified first. Option D is wrong because setting up SharePoint Online with the new domain also depends on prior domain verification and is not the initial step.
A company uses Microsoft Entra ID P1 licenses. They want to enforce multi-factor authentication (MFA) for all users when accessing any cloud application from networks that are not trusted corporate locations. A group named 'Emergency' must be excluded from MFA requirements. Which Conditional Access policy configuration should the administrator use?
A.Assign the policy to all users, exclude the Emergency group, include all cloud apps, grant access (not MFA), and set location condition to trusted networks only.
B.Assign the policy to all users, exclude the Emergency group, include all cloud apps, grant MFA, and set location condition to any network or location.
C.Assign the policy to all users, exclude the Emergency group, include all cloud apps, grant MFA, and set location condition to any network or location except trusted networks.
D.Assign the policy to all users, exclude the Emergency group, include all cloud apps, grant MFA, and set location condition to trusted networks only.
AnswerC
By targeting all users except the Emergency group, applying to all cloud apps, requiring MFA as a grant control, and using the location condition 'any network or location except trusted networks', this policy ensures MFA is enforced exactly when a user accesses resources from an untrusted location. Users on trusted corporate networks are exempt from MFA, while remote or external connections are challenged, and the emergency group remains available to bypass MFA in break-glass scenarios.
Why this answer
The requirement is to enforce MFA for all users from untrusted networks, while excluding the Emergency group. The Conditional Access policy must be assigned to all users, exclude the Emergency group, include all cloud apps, require MFA as a grant control, and use a location condition set to 'any network or location except trusted networks' to target only untrusted locations. This configuration ensures MFA is triggered only when access originates from networks not defined as trusted corporate locations.
Exam trap
The trap here is that candidates often confuse the location condition logic, mistakenly selecting 'trusted networks only' (Option D) thinking it applies MFA to trusted networks, when in fact it applies the policy only when the user is on a trusted network, which is the opposite of the requirement.
How to eliminate wrong answers
Option A is wrong because it grants access without MFA and sets the location condition to trusted networks only, which would allow access from trusted networks without MFA but would not enforce MFA from untrusted networks, completely missing the requirement. Option B is wrong because it sets the location condition to 'any network or location', which would require MFA even from trusted corporate locations, violating the requirement to enforce MFA only from untrusted networks. Option D is wrong because it sets the location condition to trusted networks only, which would require MFA only when users access from trusted networks, the opposite of the requirement to enforce MFA from untrusted networks.
A compliance officer needs to prevent users from sharing protected health information (PHI) with external users in Microsoft Teams chat messages. When a user attempts to send a message containing a known PHI data type (e.g., medical record numbers), the message should be blocked and the sender should see a policy tip. Which Microsoft Purview solution should the officer configure?
A.Communication compliance policy
B.Data Loss Prevention (DLP) policy for Teams
C.Sensitivity labels applied to Teams
D.Information barriers
AnswerB
A Data Loss Prevention (DLP) policy for Teams can enforce real-time protection on chat and channel messages by scanning content for sensitive information types, including protected health information (PHI). When a match is detected, the policy blocks the message and shows the sender a policy tip, with options to allow override based on policy configuration. This directly prevents users from sharing PHI, making it the appropriate solution.
Why this answer
A Data Loss Prevention (DLP) policy for Microsoft Teams can be configured to detect and block sensitive information types, such as medical record numbers (a PHI data type), in chat messages. When a match occurs, the policy can block the message and display a policy tip to the sender, meeting the compliance officer's requirement.
Exam trap
The trap here is that candidates often confuse Communication compliance (which reviews sent messages) with DLP (which blocks messages in transit), leading them to select Option A despite the requirement for real-time blocking and policy tips.
How to eliminate wrong answers
Option A is wrong because Communication compliance policies are designed to detect and review inappropriate or policy-violating communications (e.g., harassment, insider trading) after they are sent, not to block messages in real-time or enforce data loss prevention rules. Option C is wrong because sensitivity labels applied to Teams control access and protection (e.g., encryption, visual markings) at the container or file level, not the content of individual chat messages. Option D is wrong because Information barriers are used to prevent specific groups of users from communicating with each other (e.g., to avoid conflicts of interest), not to scan message content for sensitive data types like PHI.
You are configuring Microsoft Defender for Identity to monitor on-premises Active Directory. You need to ensure that honeytoken accounts are configured to detect attackers attempting to use them. What is a honeytoken account?
A.A service account used for application authentication
B.A disabled user account that cannot be used for sign-in
C.A fake user account created to attract attackers
D.A real user account with high privileges used for monitoring
AnswerC
A honeytoken account is a decoy identity with no legitimate purpose, so any authentication attempt against it signals malicious reconnaissance or credential misuse. Defender for Identity alerts on such activity, exposing attackers probing Active Directory without generating false positives from real users.
Why this answer
A honeytoken account is a fake user account created to lure attackers. When an attacker tries to use it, Defender for Identity triggers an alert. Option A is incorrect because honeytoken accounts are not real service accounts.
Option B is incorrect because they are not necessarily disabled; they can be enabled but with no real privileges. Option D is incorrect because they are not real high-privilege accounts, but fake decoys.
Your organization is implementing Microsoft Purview Data Loss Prevention (DLP) policies to protect sensitive data in Microsoft Teams. You need to ensure that DLP policies apply to both chat and channel messages. What should you configure?
A.Configure a DLP policy for Exchange Online to cover Teams messages.
B.Assign a sensitivity label to the Teams with a DLP policy attached.
C.Create two separate DLP policies: one for chat and one for channels.
D.Create a single DLP policy with the Teams location selected.
AnswerD
Creating a single DLP policy and selecting the Teams location is the correct approach because that location applies to all Teams messages, including 1:1 chats, group chats, and messages or conversations in standard and private channels. The policy will evaluate content in real time and can block or report violations consistently across every Teams conversation surface. This one selection removes the need for any separate policies for chat or channel content.
Why this answer
Microsoft Purview DLP policies can be configured to include the Teams location, which automatically covers both chat and channel messages. When you select the Teams location in a single DLP policy, it applies to all Teams communications, including 1:1 chats, group chats, and channel conversations, without needing separate policies.
Exam trap
The trap here is that candidates often think chat and channel messages require separate DLP policies due to their different storage locations, but Microsoft Purview abstracts this complexity by allowing a single Teams location selection that covers both.
How to eliminate wrong answers
Option A is wrong because Exchange Online DLP policies only cover email and Teams messages that are stored in Exchange mailboxes (e.g., chat messages), but they do not cover channel messages, which are stored in SharePoint and OneDrive. Option B is wrong because sensitivity labels can be used to classify and protect content, but they are not directly attached to DLP policies; DLP policies can use sensitivity labels as conditions, but assigning a label to a team does not enforce DLP. Option C is wrong because creating two separate DLP policies for chat and channels is unnecessary and inefficient; a single DLP policy with the Teams location selected covers both chat and channel messages automatically.
Refer to the exhibit. You have a DLP policy in test mode as shown. A user reports that they received a notification that sharing credit card numbers is blocked, but they were still able to share them. What is the most likely reason?
A.The rule action 'BlockAccess' is not included in the policy.
B.The policy is in test mode, which does not enforce actions.
C.The condition 'SensitiveInformation' is not configured correctly.
D.The notification is not enabled in the policy.
AnswerB
DLP policies have a policy-level mode setting: 'Enforce', 'Test with policy tips', or 'Test without policy tips'. In 'Test' mode, Microsoft 365 processes the policy's conditions to identify sensitive content and generate incident reports, but all rule actions — including BlockAccess — are effectively disabled. The exhibit explicitly shows the policy is in test mode, which fully explains why nothing is blocked and no access restriction occurs. This is the designed behavior for validating rules before enforcement.
Why this answer
A DLP policy in test mode (also called simulation mode) evaluates rules and generates alerts, notifications, and activity reports, but it does not enforce the configured actions such as BlockAccess or Block. Therefore the user sees the policy tip/notification indicating the content is sensitive, yet the sharing is still allowed because the block action is not applied. This is the intended behavior for validating a policy before turning it on.
Exam trap
MS-102 often tests the confusion between 'policy tip shown' and 'action enforced' — candidates assume a notification means the block happened, forgetting that test/simulation mode only surfaces tips and alerts without enforcing actions.
How to eliminate wrong answers
Option A is wrong because even if BlockAccess were missing, the user would not receive a 'blocked' notification — the notification itself is generated by the rule, and the question states the notification appeared, implying the rule matched. Option C is wrong because if SensitiveInformation were misconfigured, the rule would not match credit card numbers at all and no notification would fire. Option D is wrong because the user did receive a notification, proving user notifications are enabled; the issue is enforcement, not notification.
Your organization has a hybrid identity with Microsoft Entra Connect. You need to migrate from federation to password hash synchronization with seamless single sign-on (SSO). The migration must have minimal user impact. Which tool should you use?
A.Microsoft Entra Connect migration tool (Convert domain from federated to managed)
B.IdFix tool
C.AD FS Management console
D.Azure AD Connect wizard
AnswerA
The Microsoft Entra Connect migration tool's 'Convert domain from federated to managed' function is the purpose-built operation to switch a domain's sign-in method from federation to cloud authentication. It performs the conversion with minimal user impact because it updates the domain's authentication type in Microsoft Entra ID while leaving users and directory objects in place. During the process, it can use staged rollback or gradual deployment, ensuring that any authentication failures can be addressed without locking all users out. This makes it the correct choice for decommissioning AD FS.
Why this answer
The Microsoft Entra Connect migration tool (Convert domain from federated to managed) is the correct choice because it automates the conversion of federated domains to managed domains while enabling password hash synchronization (PHS) and seamless SSO. This tool minimizes user impact by allowing a staged migration where users can continue authenticating via federation until the conversion is complete, and it handles the necessary configuration changes in Azure AD and on-premises Active Directory.
Exam trap
The trap here is that candidates may confuse the Azure AD Connect wizard (which can enable PHS) with the dedicated migration tool, not realizing that the wizard lacks the specific domain conversion and staged rollback capabilities needed for a low-impact migration from federation.
How to eliminate wrong answers
Option B is wrong because IdFix is a data cleanup tool for synchronizing on-premises Active Directory objects to Azure AD, not a tool for converting authentication methods from federation to PHS. Option C is wrong because the AD FS Management console is used to manage and configure AD FS servers and trusts, not to convert a federated domain to managed authentication in Azure AD. Option D is wrong because the Azure AD Connect wizard (now Microsoft Entra Connect wizard) is used for initial setup and configuration of synchronization, including enabling PHS, but it does not provide a dedicated migration path from federation to managed domains with minimal user impact; the separate migration tool is designed specifically for that purpose.
A company has recently acquired a smaller organization and needs to consolidate both Microsoft 365 tenants. They want to minimize user disruption and retain existing email addresses. Which approach should they use?
A.Configure a hybrid deployment with Exchange Server
B.Perform a cross-tenant mailbox migration
C.Delete all users from the acquired tenant and recreate them in the parent tenant
D.Set up a federation trust between the tenants
AnswerB
Cross-tenant mailbox migration is the correct approach because it uses the Cross-Tenant migration API or Enable-CrossTenantMailboxMigration cmdlets to move mailbox content, settings, and sometimes Office 365 groups between two AAD tenants. This process preserves the mailbox's ExchangeGuid, is silent to end users, and allows for redirection of the primary SMTP address so email continues to arrive without interruption. It is the only option that both consolidates data and retains user identity while minimizing disruption.
Why this answer
Cross-tenant mailbox migration allows you to move mailboxes between two Microsoft 365 tenants while preserving the users' existing email addresses and minimizing disruption. This approach uses the Microsoft 365 native migration capabilities, specifically the cross-tenant mailbox migration feature, which supports moving mailboxes with their primary SMTP addresses and associated data without requiring on-premises Exchange Server.
Exam trap
The trap here is that candidates often confuse cross-tenant mailbox migration with federation trust or hybrid deployment, assuming that any inter-tenant connectivity solution can consolidate mailboxes, but only the cross-tenant migration feature directly moves mailbox data while preserving email addresses.
How to eliminate wrong answers
Option A is wrong because configuring a hybrid deployment with Exchange Server is unnecessary and adds complexity; it is designed for integrating on-premises Exchange with a single tenant, not for migrating mailboxes between two separate Microsoft 365 tenants. Option C is wrong because deleting all users from the acquired tenant and recreating them in the parent tenant would cause significant user disruption, loss of mailbox data, and require new email addresses unless manually reassigned, which contradicts the goal of minimizing disruption and retaining existing email addresses. Option D is wrong because setting up a federation trust between tenants enables authentication and sharing features but does not migrate mailboxes or consolidate tenants; it is used for cross-tenant collaboration, not for moving user data.
A compliance officer needs to automatically apply a 'Highly Confidential' sensitivity label to any email in Exchange Online that contains social security numbers. The labeling must happen automatically without user interaction. Which two Microsoft Purview components must be configured? (Select the option that correctly identifies both required components.)
Select 1 answer
A.sensitivity label with auto-labeling rule and a Data Loss Prevention policy
B.retention label and a Communication Compliance policy
C.sensitivity label and an auto-labeling policy
D.unified labeling client and a custom sensitive info type
AnswersC
Correct. A sensitivity label with an auto-labeling rule defines what to label and when, and an auto-labeling policy triggers the automatic application without user interaction. This pair fulfills the requirement.
Why this answer
To automatically apply a 'Highly Confidential' sensitivity label to emails containing social security numbers in Exchange Online, you must configure a sensitivity label (which defines the label and its protection settings) and an auto-labeling policy (which scans Exchange Online for the sensitive info type and applies the label automatically without user interaction). Data Loss Prevention (DLP) policies can detect sensitive information and take actions such as blocking or alerting, but they cannot directly apply sensitivity labels. Therefore, only option C correctly identifies both required components.
Exam trap
The trap is that candidates may incorrectly believe DLP policies can automatically apply sensitivity labels. In reality, DLP policies do not support this action; automatic labeling requires an auto-labeling policy or a retention label policy with auto-labeling, but for sensitivity labels, it must be an auto-labeling policy.
As a Microsoft 365 administrator, you need to manage tenant health and adoption effectively. Which three of the following tools or features should you use to monitor and improve your Microsoft 365 tenant's performance and user engagement? (Choose three.)
Select 3 answers
.Microsoft 365 admin center dashboard to view service health, message center posts, and usage reports.
.Microsoft 365 usage analytics in Power BI to gain deeper insights into adoption trends.
.Azure AD Identity Protection to detect sign-in risks and block compromised accounts.
.Microsoft 365 network connectivity test tool to evaluate network performance for Microsoft 365 services.
.Microsoft 365 Adoption Score (formerly Productivity Score) to track user engagement with Microsoft 365 apps.
.Microsoft Purview compliance portal to enforce data loss prevention policies.
Why this answer
The Microsoft 365 admin center dashboard provides a centralized view of service health, message center posts, and usage reports, enabling administrators to monitor service availability, planned changes, and user activity. This is a core tool for maintaining tenant health and tracking adoption.
Exam trap
The trap here is that candidates may confuse security or compliance tools (like Azure AD Identity Protection or Purview) with health and adoption monitoring tools, or select the network connectivity test tool thinking it measures overall tenant performance rather than just network latency.
Your organization uses Microsoft Purview Records Management. You need to ensure that records are marked as regulatory records and cannot be deleted or modified by any user, including administrators. The records must be retained for 10 years. What should you do?
A.Use a retention label marked as a regulatory record.
B.Create a retention policy with a preservation lock.
C.Use a retention label marked as a record.
D.Apply a default retention label to the SharePoint library.
AnswerA
A regulatory record label enforces immutability at the platform level: once applied, the item cannot be modified or deleted by anyone, including administrators, satisfying the stem's absolute protection requirement. It also supports a 10-year retention period, unlike standard records, which administrators can still remove.
Why this answer
A retention label configured as a regulatory record provides the highest level of immutability: it prevents any user, including administrators, from deleting or modifying the item, and the label itself cannot be removed or changed once applied. This meets the requirement that records cannot be deleted or modified by anyone. The 10-year retention period is set on the label.
Exam trap
MS-102 often tests the difference between a record and a regulatory record; candidates often pick 'record' because it sounds strict, but only 'regulatory record' prevents administrators from removing the label.
How to eliminate wrong answers
Option B is wrong because a retention policy with a preservation lock prevents the policy from being turned off or modified, but it does not prevent users from deleting items; it only ensures the policy remains in effect. Option C is wrong because a retention label marked as a record allows administrators to remove the label and then delete the item, so it does not provide the same level of protection as a regulatory record. Option D is wrong because a default retention label applied to a SharePoint library does not prevent deletion or modification by administrators; it only applies retention settings.
You are configuring Microsoft Defender for Identity (MDI) to monitor for lateral movement attacks. Which of the following activities would MDI alert on as a potential lateral movement?
A.A user logging into multiple servers using a compromised account.
B.A user performing a DCSync attack.
C.A user conducting a password spray attack.
D.A user executing a privilege escalation tool on their workstation.
E.A user performing a brute force attack on a domain controller.
AnswerA
Logging into multiple servers with one compromised account is classic lateral movement; Microsoft Defender for Identity detects this via its account reconnaissance and lateral movement detections, correlating authentication events across domain controllers to flag abnormal spread that satisfies the monitoring scenario.
Why this answer
Microsoft Defender for Identity (MDI) can detect lateral movement when a compromised account is used to log into multiple servers, which indicates an attacker moving laterally within the network. Option B is incorrect because DCSync is a domain replication attack that targets the domain controller to extract credentials, not lateral movement. Option C is incorrect because password spray is a type of brute force attack that tries common passwords against many accounts, not lateral movement.
Option D is incorrect because executing a privilege escalation tool on a workstation is a local privilege escalation attempt, not lateral movement between systems. Option E is incorrect because brute force attacks on a domain controller are authentication attacks, not lateral movement.
Your organization plans to use Microsoft Entra ID as the identity provider for a third-party SaaS application that supports SAML 2.0. You need to configure single sign-on (SSO) for the application. What should you create in Microsoft Entra ID?
A.An enterprise application with SAML-based sign-on
B.An Application Proxy connector group
C.A service principal for Microsoft Graph
D.An app registration with OpenID Connect
AnswerA
In Microsoft Entra ID, an enterprise application is a service principal created from a gallery or non-gallery app template, which supports SAML 2.0 federation for SSO. For an on-premises app like the IDE, you register an enterprise application, configure SAML-based sign-on, and assign users/groups. The SAML assertions are exchanged to authenticate users, and this is the designated method for federating an on-premises application with Microsoft Entra ID.
Why this answer
To configure SSO for a third-party SaaS application that supports SAML 2.0, you must create an enterprise application in Microsoft Entra ID and configure it with SAML-based sign-on. Enterprise applications are designed for integrating third-party applications, and SAML-based sign-on allows Entra ID to act as the identity provider, exchanging SAML assertions for authentication.
Exam trap
The trap here is that candidates often confuse app registrations (used for OIDC/OAuth apps) with enterprise applications (used for SAML-based SSO), leading them to choose Option D, even though SAML 2.0 requires the enterprise application gallery or custom enterprise app configuration.
How to eliminate wrong answers
Option B is wrong because an Application Proxy connector group is used for publishing on-premises applications to external users via reverse proxy, not for configuring SSO with a cloud-based SaaS application that supports SAML. Option C is wrong because a service principal for Microsoft Graph is used to grant permissions for programmatic access to Microsoft Graph APIs, not for configuring SAML-based SSO with a third-party SaaS app. Option D is wrong because an app registration with OpenID Connect is used for applications that use OIDC (an OAuth 2.0 extension) for authentication, not for SAML 2.0, which requires a different protocol and configuration in enterprise applications.
A compliance officer needs to automatically detect documents in SharePoint Online that contain a custom pattern (e.g., employee ID in the format EMP-12345). The pattern will be used to apply a sensitivity label. Which Microsoft Purview feature should the officer use to define the pattern?
A.Sensitive information types
B.Data Loss Prevention (DLP) policies
C.Content search
D.Data classification reports
AnswerA
Sensitive information types define the detection logic itself, using built-in or custom regex patterns, keywords, and confidence thresholds to identify data like employee IDs. After you define a custom sensitive information type, it becomes a reusable condition that purge policies, auto-labeling, and DLP rules rely on. This is the correct answer because the compliance officer's requirement to 'automatically detect' a specific pattern starts with creating that type, not with a policy that merely consumes it.
Why this answer
Sensitive information types (SITs) in Microsoft Purview are specifically designed to define custom patterns, such as regular expressions for employee IDs like EMP-12345. Once defined, these SITs can be used in sensitivity labels to automatically classify and protect documents in SharePoint Online. This is the correct feature because it directly supports pattern-based detection for labeling.
Exam trap
The trap here is that candidates often confuse DLP policies with pattern definition, but DLP policies only consume pre-defined sensitive information types and cannot create them.
How to eliminate wrong answers
Option B is wrong because Data Loss Prevention (DLP) policies enforce rules to prevent data exfiltration but do not define the pattern itself; they use existing sensitive information types. Option C is wrong because Content Search is a query tool for finding content based on keywords or metadata, not for defining reusable patterns for automatic labeling. Option D is wrong because Data classification reports provide visibility into classified data but do not allow creation of custom patterns.
A company has an on-premises Active Directory environment and wants to sync user identities to Microsoft Entra ID while avoiding storing password hashes in the cloud. The company wants to provide seamless single sign-on (SSO) for domain-joined devices. Which authentication method should be chosen?
A.Password Hash Synchronization (PHS)
B.Pass-Through Authentication (PTA) with Seamless SSO
C.Federation with Active Directory Federation Services (AD FS)
D.Cloud-only authentication
AnswerB
Pass-Through Authentication (PTA) with Seamless SSO is correct because PTA uses an on-premises connector agent to validate user passwords directly against Active Directory; the password hash is never persisted in Azure AD. Seamless SSO complements this by enabling domain-joined computers to authenticate transparently using Kerberos tickets, so users don't have to re-enter passwords. This meets both the sync requirement and the constraint of keeping password hashes on-premises.
Why this answer
Pass-Through Authentication (PTA) with Seamless SSO is the correct choice because it validates user passwords directly against on-premises Active Directory without storing any password hashes in the cloud. Seamless SSO provides automatic sign-in for domain-joined devices using Kerberos delegation, meeting the requirement for a seamless SSO experience without password hash storage.
Exam trap
The trap here is that candidates often choose Password Hash Synchronization (PHS) because it is simpler and supports Seamless SSO, but they overlook the explicit requirement to avoid storing password hashes in the cloud, which PHS inherently does.
How to eliminate wrong answers
Option A is wrong because Password Hash Synchronization (PHS) stores password hashes in Microsoft Entra ID, which directly violates the requirement to avoid storing password hashes in the cloud. Option C is wrong because Federation with AD FS requires storing a federation trust and typically involves password hash synchronization or a separate identity store, and it introduces unnecessary complexity and infrastructure overhead compared to PTA with Seamless SSO for this specific requirement. Option D is wrong because cloud-only authentication does not integrate with on-premises Active Directory, so it cannot sync user identities or provide SSO for domain-joined devices.
Which TWO of the following are benefits of using Microsoft Entra ID Provisioning for cloud HR applications like Workday? (Choose two.)
Select 2 answers
A.Automatic license assignment
B.Support for attribute-based provisioning
C.Automatic password reset for new users
D.Automated user lifecycle management based on HR events
E.Automatic creation of user mailboxes in Exchange Online
AnswersB, D
Support for attribute-based provisioning is a core benefit because Entra ID provisioning lets you map HR source attributes to target Entra ID user attributes using attribute-mapping rules and expression functions. You can also define scoping filters that include or exclude users based on attribute values, and transform values before they are written to the cloud user object. This makes HR data such as title, department, and cost center authoritative within Microsoft Entra ID.
Why this answer
Microsoft Entra ID Provisioning for cloud HR applications like Workday supports attribute-based provisioning, which allows mapping of HR attributes (e.g., department, location) to Entra ID user attributes using an expression-based mapping engine. This enables dynamic filtering and transformation of user data during synchronization, ensuring that only users meeting specific criteria (e.g., employment status) are provisioned.
Exam trap
The trap here is that candidates often confuse the capabilities of Entra ID Provisioning with those of Microsoft Identity Manager (MIM) or Exchange Online hybrid management, assuming provisioning handles tasks like license assignment or mailbox creation, which are separate downstream processes.
A compliance officer wants to automatically apply a retention label to documents that contain SWIFT codes (financial identifiers) when uploaded to SharePoint Online. Which two Microsoft Purview features are required for this configuration? (Choose two.)
Select 2 answers
A.Sensitivity label
B.Trainable classifier
C.Auto-apply retention label policy
D.Data Loss Prevention (DLP) policy
AnswersB, C
A trainable classifier is an AI-based content detection model in Microsoft Purview that you train with seed documents to recognize specific patterns, such as SWIFT codes. Once published, the classifier can be used as a condition inside an auto-apply retention label policy; when documents match the classifier's model, the policy automatically assigns the appropriate retention label. It is the detection component that identifies the content, not the policy that performs the actual label assignment.
Why this answer
A trainable classifier is required to identify content containing SWIFT codes based on pattern recognition and machine learning. Option C is correct because an auto-apply retention label policy is the mechanism that automatically assigns the retention label to documents when the classifier detects SWIFT codes in SharePoint Online.
Exam trap
The trap here is that candidates often confuse sensitivity labels with retention labels, or mistakenly think a DLP policy can directly apply retention labels, when in fact DLP policies only trigger alerts or block actions, not label assignment.
A compliance officer needs to retain all documents in a SharePoint Online site associated with the Finance department for 10 years, after which the documents must be automatically deleted. During the retention period, users must be allowed to edit the documents but not delete them. Which Microsoft Purview solution should the officer configure?
A.retention policy with a retention period of 10 years and an action to delete at the end of the period
B.retention label auto-applied to all documents in the site
C.Litigation hold on the site
D.Data Loss Prevention (DLP) policy with a retention action
AnswerA
A retention policy applied to the SharePoint site works at the container level, automatically covering every document and version without needing per-item labels or rules. Users can continue editing during the 10-year period, but deletion is blocked until the disposition action permanently deletes the files at period end. This directly satisfies both the preservation and the 10-year deletion requirement.
Why this answer
A retention policy can be applied to a SharePoint site to enforce a 10-year retention period with a deletion action at the end, while allowing users to edit documents during that period. This meets the compliance requirement because retention policies preserve content from deletion by users, but still permit editing. The 'delete at end of retention period' action ensures automatic removal after 10 years.
Exam trap
The trap here is that candidates often confuse retention labels with retention policies, thinking labels are required for site-wide retention, but policies are the correct tool for applying uniform retention and deletion to an entire site without manual labeling.
How to eliminate wrong answers
Option B is wrong because a retention label auto-applied to all documents would also work for retention and deletion, but the question asks for a 'solution' that is simpler and more appropriate for a site-wide requirement; retention labels are typically used for granular, item-level classification rather than blanket site-wide retention. Option C is wrong because Litigation hold preserves content indefinitely (no automatic deletion) and prevents editing in some configurations, which does not meet the 10-year deletion requirement. Option D is wrong because Data Loss Prevention (DLP) policies are designed to prevent data leakage and enforce security rules, not to manage retention or deletion of documents.
A compliance administrator needs to ensure that all documents in a SharePoint library are retained for exactly 7 years and then allow users to manually dispose of them sooner after a review. What should they configure in Microsoft Purview?
A.Create a retention label with a retention period of 7 years and enable disposition review
B.Create a retention label with a retention period of 7 years and no additional action
C.Create a sensitivity label that restricts access
D.Create a record label
AnswerA
A retention label with a 7-year period and disposition review is the correct choice because it retains the document for the full regulatory period, yet the disposition review step triggers a manual approval workflow at the end of the retention period. During that review, an authorized user can approve early disposal, satisfying the requirement that documents be manually dispose-able if approved, rather than being automatically deleted or locked indefinitely.
Why this answer
The requirement specifies a fixed 7-year retention period followed by user-initiated disposal after a review. A retention label with a retention period of 7 years and disposition review enabled allows content to be retained for exactly 7 years, after which a disposition review triggers a manual approval process for disposal. This matches the need for both mandatory retention and manual disposal after review.
Exam trap
The trap here is that candidates often confuse retention labels with record labels, assuming that any label with a retention period automatically supports manual disposal, but only retention labels with disposition review enabled provide the specific workflow for user-initiated disposal after review.
How to eliminate wrong answers
Option B is wrong because a retention label with no additional action will automatically delete the content after 7 years without any user review or manual disposal option, which violates the requirement to allow users to manually dispose of items sooner after a review. Option C is wrong because a sensitivity label is designed to classify and protect data through encryption or access restrictions, not to enforce retention or disposition workflows; it does not provide any retention period or disposal review capability. Option D is wrong because a record label marks content as a record (immutable) and typically prevents deletion or modification, which contradicts the requirement to allow manual disposal after review; records require a disposition review but are not designed for flexible user-initiated disposal.
Which TWO actions can you perform using Microsoft Defender XDR's Advanced Hunting? (Choose two.)
Select 2 answers
A.Deploy EDR sensors to endpoints.
B.Configure data retention policies for logs.
C.Create custom detection rules based on query results.
D.Manage the status of incidents.
E.Run KQL queries to hunt for threats across email, endpoints, identities, and apps.
AnswersC, E
Advanced Hunting's Kusto Query Language results can be saved as custom detection rules, which run on a schedule and trigger alerts or automated response actions. This satisfies the stem's requirement for an action available directly within Microsoft Defender XDR, rather than relying on a separate portal or service.
Why this answer
Advanced Hunting in Microsoft Defender XDR allows you to run KQL queries across data from various Defender services, so option E is correct. You can also create custom detection rules based on query results, making option C correct. Option A (deploy EDR sensors) is done via group policy or Intune, not in Advanced Hunting.
Option B (configure data retention) is a tenant-level setting. Option D (manage incident status) is performed in the Incidents queue, not in Advanced Hunting.
Your organization uses Microsoft Purview to enforce data loss prevention (DLP) policies. Users report that a DLP policy blocks legitimate sharing of a document containing sensitive financial data. You need to allow the sharing while still protecting the data. What should you do?
A.Disable the DLP policy and create a new one with broader conditions.
B.Add the user to the DLP policy's super user group.
C.Modify the DLP policy to exclude the specific document type.
D.Configure a policy tip to allow override with a business justification.
AnswerD
Policy tips with override let users supply a business justification to bypass the block, satisfying the need to permit legitimate sharing while retaining protection. The override is logged and auditable, so sensitive financial data remains governed rather than simply unblocked.
Why this answer
Configuring a policy tip to allow override with a business justification enables users to legitimately share the document while still being audited. Policy tips notify users when their action violates a DLP policy and allow them to override with a justification, which is logged for review. Option A is wrong because disabling the policy removes protection entirely.
Option B is wrong because adding a user to a super user group bypasses all DLP checks, which is not appropriate. Option C is wrong because excluding the document type could weaken protection for all similar documents.
An organization uses Microsoft Defender for Cloud Apps to monitor shadow IT. They want to enforce policies that block downloads from risky cloud apps. Which Microsoft Defender XDR component provides this capability?
A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Identity
D.Microsoft Defender for Office 365
AnswerA
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that discovers sanctioned and unsanctioned cloud apps, assesses risk via the Cloud App Catalog, and enforces real-time session and access policies. It can restrict risky app usage using conditional access app controls, block downloads, or apply DLP checks across thousands of third-party SaaS services — capabilities no workload-specific Defender product can provide.
Why this answer
Microsoft Defender for Cloud Apps is the correct component because it is specifically designed to provide visibility into shadow IT and enforce policies on cloud applications. Its 'Governance' actions include blocking downloads from risky apps by integrating with the cloud app's API to prevent data exfiltration, which directly addresses the requirement.
Exam trap
The trap here is that candidates often confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Office 365, assuming that Office 365's data loss prevention (DLP) covers all cloud apps, but DLP in Office 365 is limited to Microsoft 365 services, not third-party shadow IT apps.
How to eliminate wrong answers
Option B is wrong because Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR), antivirus, and vulnerability management on devices, not on controlling downloads from cloud apps. Option C is wrong because Microsoft Defender for Identity monitors on-premises Active Directory for identity-based attacks (e.g., lateral movement, privilege escalation) and does not manage cloud app policies. Option D is wrong because Microsoft Defender for Office 365 protects email and collaboration tools (Exchange Online, SharePoint, Teams) from threats like phishing and malware, but it does not enforce download blocks across a broad set of cloud apps discovered via shadow IT.
An organization has a legal requirement to preserve certain contracts as immutable records. Once a contract is declared as a record, it must not be editable or deletable by users, including administrators. Which Microsoft Purview solution should be configured?
A.Data Loss Prevention
B.eDiscovery (Premium)
C.Communication Compliance
D.Records Management
AnswerD
Records Management, a feature of Microsoft Purview, uses retention labels with the 'Mark as a record' action to make content immutable: the item cannot be edited, renamed, or deleted, and a full audit trail is recorded. Once a contract is labeled as a record, users—and in the case of regulatory records, even system administrators—cannot alter or purge it before the specified retention period expires. This exactly addresses the legal requirement to preserve contracts in a tamper-proof form, unlike the other three options.
Why this answer
Records Management in Microsoft Purview is designed to declare items as immutable records, locking them against editing or deletion by any user, including administrators. This satisfies the legal requirement for preserving contracts as unchangeable records by applying retention labels that enforce strict regulatory compliance.
Exam trap
The trap here is that candidates confuse Records Management with eDiscovery holds, thinking a legal hold provides immutability, but eDiscovery holds only prevent deletion during litigation and do not prevent editing or permanent record locking.
How to eliminate wrong answers
Option A is wrong because Data Loss Prevention (DLP) policies prevent unauthorized sharing or leakage of sensitive data but do not enforce immutability or prevent editing/deletion of records. Option B is wrong because eDiscovery (Premium) is used for legal hold, search, and export of content for litigation, not for making records permanently immutable. Option C is wrong because Communication Compliance monitors and analyzes communications for policy violations (e.g., harassment, insider trading) and does not provide record locking or immutability features.
Your organization uses Microsoft Defender XDR and Microsoft 365 E5 licenses. You need to ensure that when a user reports a phishing email using the Microsoft Report Message add-in, the email is automatically submitted to Microsoft for analysis and the user is notified of the analysis result. You want to minimize administrative effort. What should you do?
A.Create a mail flow rule that forwards reported messages to a security team mailbox.
B.Configure the Microsoft Report Message add-in for all users.
C.Use the Microsoft 365 Defender portal to manually submit the email for analysis whenever a user reports it.
D.In Microsoft Defender XDR, go to Settings > Email & collaboration > User reported messages, and enable 'Send reported messages to Microsoft' and 'Notify users when analysis completes'.
AnswerD
Enabling 'Send reported messages to Microsoft' and 'Notify users when analysis completes' in the User reported messages settings routes reports automatically and returns verdicts to users, satisfying the minimal administrative effort constraint without custom flows or policies.
Why this answer
The user-reported messages settings in Microsoft Defender XDR (Settings > Email & collaboration > User reported messages) allow you to automatically send reported messages to Microsoft for analysis and notify users when analysis completes, minimizing administrative effort. Option A is wrong because a mail flow rule would only forward messages to a security team mailbox, not to Microsoft, and would not provide automatic analysis or user notification. Option B is wrong because simply configuring the Report Message add-in for all users enables reporting but does not by itself automatically submit to Microsoft or notify users; the Defender XDR settings are required for those actions.
Option C is wrong because manually submitting each reported email via the Microsoft 365 Defender portal defeats the goal of minimizing administrative effort and does not automatically notify the user of results.
Which THREE conditions can be used in a dynamic group rule for a device?
Select 3 answers
A.deviceModel
B.deviceCategory
C.deviceOSVersion
D.lastLogonTimestamp
E.passwordLastSet
AnswersA, B, C
deviceModel is a valid device attribute representing the manufacturer-assigned model name (e.g., 'Surface Pro 8' or 'iPhone 13'). Dynamic group rules can reference it directly with the syntax (device.deviceModel -eq "Surface Pro 8") to automatically include or exclude devices by hardware model. It is populated during device enrollment or via management tools like Microsoft Intune and is frequently used to target specific device lines for configuration or access policies.
Why this answer
`deviceModel` is a valid attribute that can be used in a dynamic group rule for devices in Microsoft Entra ID (formerly Azure AD). Dynamic group rules for devices support attributes such as `deviceModel`, `deviceCategory`, and `deviceOSVersion` to automatically include or exclude devices based on their hardware or software characteristics.
Exam trap
The trap here is that candidates confuse user attributes (like `lastLogonTimestamp` and `passwordLastSet`) with device attributes, leading them to incorrectly select options that are valid only for user-based dynamic groups.
You are a Microsoft 365 administrator. You need to allow external users to access a SharePoint Online site without requiring them to sign in. Which sharing setting should you enable?
A.Set the sharing option to 'Existing guests' and send an invitation.
B.Set the sharing option to 'Only people in your organization' and use a direct link.
C.Set the sharing option to 'New and existing guests' and require guest sign-in.
D.Set the sharing option to 'Anyone' (Anonymous) for the site.
AnswerD
The 'Anyone' (Anonymous) sharing link allows anyone who has the link to access the site or item without being required to sign in as a guest or internal user. This link type is the only option that permits external access with no authentication, exactly matching the stated business requirement. Because these links are the most permissive, they should be used with caution and ideally paired with expiration dates and password protection.
Why this answer
Setting the SharePoint Online site sharing option to 'Anyone' (Anonymous) allows external users to access the site without signing in. This creates an anonymous access link that bypasses authentication, meeting the requirement of no sign-in for external users.
Exam trap
The trap here is that candidates often confuse 'Anyone' (anonymous) sharing with guest sharing options, mistakenly thinking that 'New and existing guests' allows anonymous access, but it actually requires sign-in for all external users.
How to eliminate wrong answers
Option A is wrong because 'Existing guests' requires recipients to have a guest account and sign in, which contradicts the 'without requiring them to sign in' requirement. Option B is wrong because 'Only people in your organization' restricts access to internal users only, blocking external users entirely. Option C is wrong because 'New and existing guests' requires all external users to sign in with a Microsoft account or Azure AD guest identity, which does not meet the no-sign-in condition.