Courseiva

CCNA Deploy and manage a Microsoft 365 tenant Questions

75 of 196 questions · Page 1/3 · Deploy and manage a Microsoft 365 tenant · Answers revealed

1
MCQmedium

A company has a Microsoft 365 tenant with the domain contoso.com. They acquire a subsidiary with the domain fabrikam.com and want to add it as an additional domain to the same tenant. The domain is already purchased and DNS management is available. What is the first step the administrator should take in the Microsoft 365 admin center?

A.Add the domain and verify ownership by adding a TXT record
B.Create a new tenant for fabrikam.com
C.Set up email forwarding from contoso.com to fabrikam.com
D.Convert fabrikam.com to a federated domain
AnswerA

Adding the domain and verifying ownership via a TXT record is the mandatory first step; Microsoft 365 cannot use fabrikam.com until DNS proof of ownership succeeds. Only after verification can you create users, assign licences, or set fabrikam.com as default.

Why this answer

To add an existing domain like fabrikam.com to a Microsoft 365 tenant, the first step is to add the domain in the Microsoft 365 admin center and then verify ownership by adding a TXT record to the domain's DNS zone. This verification proves the administrator controls the domain, which is a prerequisite for using it with Microsoft 365 services such as Exchange Online or SharePoint.

Exam trap

The trap here is that candidates may confuse the order of operations and attempt to configure advanced features like federation or email routing before completing the mandatory domain verification step, which is always the first action required when adding a new domain to a tenant.

How to eliminate wrong answers

Option B is wrong because creating a new tenant for fabrikam.com would isolate the subsidiary's users and resources from the existing contoso.com tenant, defeating the purpose of consolidating domains under one tenant. Option C is wrong because email forwarding from contoso.com to fabrikam.com is a post-verification routing configuration, not a domain addition step, and it does not establish domain ownership. Option D is wrong because converting fabrikam.com to a federated domain requires the domain to first be added and verified in the tenant; federation is an advanced authentication configuration that cannot be performed as the initial step.

2
Multi-Selectmedium

Your organization is implementing Microsoft Purview Data Loss Prevention (DLP). You need to ensure that sensitive data such as credit card numbers cannot be shared externally via email. Which THREE components should you configure?

Select 3 answers
A.Define sensitive information types for credit card numbers
B.Enable Microsoft Purview Insider Risk Management
C.Configure DLP rule actions to block external sharing
D.Configure a retention policy for email
E.Create a DLP policy in Microsoft Purview
AnswersA, C, E

Sensitive information types are the detection backbone of a Microsoft Purview DLP policy. Built-in SITs such as "Credit Card Number" use pattern matching, checksum validation, and keyword evidence to identify card data in Exchange, SharePoint, OneDrive, and Teams. Defining or fine-tuning these SITs (e.g., confidence levels or custom patterns) ensures that the DLP policy accurately detects credit card numbers before rules and actions can act on them.

Why this answer

A is correct because sensitive information types (SITs) are predefined or custom patterns that detect specific data like credit card numbers (e.g., regex matching major credit card formats). Defining the SIT for credit card numbers allows the DLP policy to identify this sensitive content in emails, which is the first step before any action can be taken.

Exam trap

The trap here is that candidates may confuse Insider Risk Management (a behavior-based tool) with DLP (a content-based policy), or think a retention policy is needed to block sharing, when in fact DLP policies alone handle detection and enforcement via SITs and rule actions.

3
MCQeasy

A company has purchased Microsoft 365 Business Premium and added a custom domain 'contoso.com' to the tenant. They want all new users to have email addresses like user@contoso.com instead of the default onmicrosoft.com domain. What should the administrator do in the Microsoft 365 admin center?

A.Set the custom domain as the default domain in the Domains settings.
B.Add a DNS TXT record for the custom domain.
C.Change the primary domain in the tenant's organization profile.
D.Update the MX record for the custom domain to point to Exchange Online.
AnswerA

Setting the custom domain as the default domain in the Microsoft 365 Domains settings is the correct action because the default domain is directly assigned to newly created user mailboxes and email addresses. When you select a verified custom domain and mark it as default, all new users will automatically receive email addresses ending with that domain, such as user@yourdomain.com, instead of the initial onmicrosoft.com domain. This configuration is managed under Admin > Domains, where the 'Default' indicator appears on the domain that will be used for new user creation. Note that this does not change the tenant's primary domain, which is fixed for the initial Azure AD organization.

Why this answer

Setting the custom domain as the default domain in the Domains settings ensures that any new user created in the Microsoft 365 admin center automatically receives an email address ending with @contoso.com instead of the default @<tenant>.onmicrosoft.com. This is the correct administrative action because the default domain setting controls the domain suffix applied to new user principal names (UPNs) and email addresses during user creation.

Exam trap

The trap here is that candidates confuse the default domain for new users with domain verification (TXT records) or mail routing (MX records), leading them to select options that are necessary for domain setup but not for controlling the email address assigned to new users.

How to eliminate wrong answers

Option B is wrong because adding a DNS TXT record is used for domain ownership verification, not for setting the default email domain for new users. Option C is wrong because changing the primary domain in the tenant's organization profile affects the initial onmicrosoft.com domain used for the tenant itself, not the default domain for new user email addresses. Option D is wrong because updating the MX record controls mail routing for the domain, not the default domain assigned to new users' email addresses.

4
MCQmedium

A company with 200 on-premises Exchange mailboxes plans to migrate to Exchange Online. They want to use a Microsoft-provided tool that supports granular control over mailbox migrations, allows batch migrations, and provides detailed reporting. Which migration method should the administrator choose?

A.Azure AD Connect
B.Exchange Admin Center (EAC) migration dashboard
C.Third-party migration tool (e.g., BitTitan MigrationWiz)
D.IMAP migration
AnswerB

The Exchange Admin Center (EAC) migration dashboard is the correct native Microsoft tool for a 200-mailbox on-premises Exchange environment. It uses the Mailbox Replication Service (MRS) to move entire mailboxes into Exchange Online, supporting cutover, staged, and hybrid migration models. The dashboard provides batch creation, incremental sync, status reporting, per-mailbox error logs, and the ability to schedule and manage multiple batches, making it purpose-built for mailbox migration.

Why this answer

The Exchange Admin Center (EAC) migration dashboard is the correct choice because it is a Microsoft-provided tool that supports granular control over mailbox migrations (e.g., selecting specific users, setting migration endpoints, and configuring throttling), allows batch migrations with the ability to start, stop, and monitor multiple batches simultaneously, and provides detailed reporting on migration status, errors, and sync progress. This method is specifically designed for migrating on-premises Exchange mailboxes to Exchange Online in a controlled, staged manner, making it ideal for the scenario described.

Exam trap

The trap here is that candidates often confuse Azure AD Connect (identity sync) with a migration tool, or they assume any Microsoft tool (like IMAP migration) is sufficient, but the question specifically requires granular control, batch support, and detailed reporting, which only the EAC migration dashboard provides for on-premises Exchange to Exchange Online migrations.

How to eliminate wrong answers

Option A is wrong because Azure AD Connect is a directory synchronization tool that syncs on-premises Active Directory objects to Azure AD, but it does not perform mailbox migration, provide granular control over mailbox moves, or offer batch migration reporting; it handles identity only. Option C is wrong because while third-party tools like BitTitan MigrationWiz can offer granular control and reporting, the question explicitly asks for a 'Microsoft-provided tool,' so a third-party solution does not meet that requirement. Option D is wrong because IMAP migration only migrates email data (folders, messages) from an IMAP-enabled source, not full mailbox items like calendar, contacts, or tasks, and it lacks granular control over individual mailboxes, batch management, and detailed reporting; it is a basic cutover method, not suitable for a controlled, staged migration from on-premises Exchange.

5
MCQmedium

An administrator has configured group-based licensing in Azure AD. After adding users to the group, some users do not receive licenses. The users are in the group and have an assigned usage location. What is a possible reason?

A.The group is a mail-enabled security group, which is not supported for group-based licensing
B.The license product name in the group setting does not match the available licenses in the tenant
C.The users have conflicting license assignments from another source
D.The users have not accepted the Microsoft Online Service Terms
AnswerC

Conflicting license assignments are a common cause of partial group-based licensing failures. When a user already holds a license assigned directly or through another group that contains the same or conflicting service plans, Azure AD group-based licensing detects the conflict and places that user in an error state rather than applying the group license. The affected users will appear with an error status such as 'Conflicting service plans' in the Azure AD licensing blade, while other users without such conflicts get the license successfully.

Why this answer

Group-based licensing in Azure AD can fail when a user already has a license assigned from another source, such as direct assignment or another group. Azure AD's group-based licensing processes assignments in a deterministic order, and if a conflict arises (e.g., different service plans or SKUs), the system may skip the user and log an error in the audit logs. This is a common scenario when users are migrated from direct licensing to group-based licensing without removing the existing assignments.

Exam trap

The trap here is that candidates often assume group-based licensing always works if the user is in the group and has a usage location, overlooking the common real-world scenario where pre-existing direct license assignments cause silent failures that require manual conflict resolution.

How to eliminate wrong answers

Option A is wrong because mail-enabled security groups are fully supported for group-based licensing in Azure AD, as long as the group is a security group (mail-enabled or not). Option B is wrong because if the license product name in the group setting does not match an available license in the tenant, the group-based licensing assignment would fail for all users, not just some, and the administrator would receive a clear error during configuration. Option D is wrong because Microsoft Online Service Terms acceptance is a tenant-wide prerequisite that must be completed before any licensing can be applied; if it were not accepted, no users in the tenant would receive licenses at all, not just some users in a group.

6
MCQhard

You are configuring Microsoft Purview Information Protection for your tenant. You need to ensure that documents containing credit card numbers are automatically labeled as 'Highly Confidential' and encrypted. Which two components must you configure?

A.A data loss prevention (DLP) policy.
B.A sensitive info type for credit card numbers.
C.An auto-labeling policy for sensitivity labels.
D.A retention label.
AnswerB, C

A sensitive info type detects credit card numbers using pattern matching and validation, supplying the condition an auto-labelling policy needs. Without it, Microsoft Purview cannot identify the content to classify, so the label would never be applied automatically.

Why this answer

To automatically label and encrypt documents containing credit card numbers, you need a sensitive info type that detects credit card numbers and an auto-labeling policy for sensitivity labels that applies the 'Highly Confidential' label with encryption. The sensitive info type defines what to look for, and the auto-labeling policy defines the label to apply and the conditions.

Exam trap

MS-102 often tests the confusion between DLP policies and auto-labeling policies — candidates must remember that DLP enforces actions like block or warn, while auto-labeling applies sensitivity labels with encryption.

How to eliminate wrong answers

Option A is wrong because a DLP policy can block or warn on sensitive content but does not automatically apply sensitivity labels with encryption — that is the role of auto-labeling policies. Option D is wrong because a retention label governs how long content is kept or deleted, not how it is classified or encrypted.

7
MCQmedium

A company wants to display a custom help desk phone number and email on the Microsoft 365 sign-in page so that users can contact support easily. Which area of the Microsoft 365 admin center should the administrator use to configure this?

A.Settings > Org settings > Security & privacy
B.Settings > Org settings > Organization profile
C.Billing > Licenses
D.Health > Service Health
AnswerB

The correct path is Settings > Org settings > Organization profile, which contains a 'Custom branding' tab (or 'Sign-in and branding' section) where administrators can configure the sign-in page's logo, text, and support information. Under 'Custom branding', you can specify a support email address, phone number, and support URL that will be shown to users when they access the sign-in page. This is the only location in the Microsoft 365 admin center that maps directly to the help desk contact info on the sign-in page.

Why this answer

The custom help desk contact information (phone number and email) for the Microsoft 365 sign-in page is configured under Settings > Org settings > Organization profile, specifically in the 'Custom branding' section. This setting allows administrators to add custom support contact details that appear on the sign-in page, enhancing user self-service and support accessibility.

Exam trap

The trap here is that candidates often confuse the 'Security & privacy' settings (Option A) with branding customization, mistakenly thinking that support contact details are a security-related configuration rather than a branding and user experience setting.

How to eliminate wrong answers

Option A is wrong because Settings > Org settings > Security & privacy is used for configuring security policies, data loss prevention, and privacy-related settings, not for customizing the sign-in page branding or support contact information. Option C is wrong because Billing > Licenses is used to manage user licenses, subscriptions, and billing details, not for tenant-wide branding or support contact configuration. Option D is wrong because Health > Service Health provides real-time service status and incident information, but does not allow customization of the sign-in page or support contact details.

8
MCQmedium

A user reports that they cannot access Microsoft Teams from their mobile device. Other Microsoft 365 services work fine. You verify that the device is compliant with Intune policies. What is the most likely cause?

A.The user's authentication method is not registered for Microsoft Entra ID
B.The Microsoft Teams service is degraded
C.A Conditional Access policy requires an approved client app for Teams
D.The device is not enrolled in Microsoft Intune
AnswerC

A Conditional Access policy requires an approved client app for Teams. If the policy is configured under Conditional Access > Grant > 'Require approved client app' for the Microsoft Teams cloud app, access is allowed only when the requesting app is in the approved list and is protected by an Intune app protection policy (APP). The user is likely using a non-approved client (e.g., a web browser or a third-party Teams client) or an app that has not received the required APP policy, so the Conditional Access engine blocks the session even though sign-in succeeded. This is an app-level access control, which exactly matches the symptom of a single user (if other users are on compliant clients) or a device-specific gap.

Why this answer

A Conditional Access policy requiring an approved client app for Microsoft Teams would block access from a mobile device even if the device is Intune-compliant, as the policy specifically checks for the use of an approved app (e.g., the official Microsoft Teams app) rather than just device compliance. Since the user can access other Microsoft 365 services, the issue is isolated to Teams, and the device compliance status rules out broader device-level blocks.

Exam trap

The trap here is that candidates assume device compliance alone guarantees access, overlooking that Conditional Access policies can impose app-level requirements that are separate from device health checks.

How to eliminate wrong answers

Option A is wrong because authentication method registration for Microsoft Entra ID affects sign-in capabilities across all services, not just Teams, and the user can access other Microsoft 365 services, indicating authentication is functional. Option B is wrong because a degraded Microsoft Teams service would impact all users and devices, not just a single user on a mobile device, and the user can access other services, ruling out a widespread service issue. Option D is wrong because the device is explicitly stated to be compliant with Intune policies, which implies it is enrolled in Microsoft Intune; non-enrollment would prevent compliance evaluation entirely.

9
Multi-Selecteasy

You are configuring Microsoft 365 tenant-to-tenant migration. Which THREE tasks must be completed before migrating users?

Select 3 answers
A.Change MX records to point to the target tenant
B.Obtain tenant consent for data migration (e.g., via admin consent)
C.Delete source tenant user mailboxes
D.Verify domain ownership in the target tenant
E.Set up directory synchronization between tenants (if needed)
AnswersB, D, E

Before commencing a tenant-to-tenant migration, the migration application (often a third-party tool) requires explicit authorisation to access user data within both the source and target Microsoft Entra ID tenants. This authorisation is typically granted through admin consent, where an administrator approves the application's requested API permissions to read and write user data, mailboxes, and OneDrive files. Without this consent, the migration service cannot legally or technically access the necessary resources to facilitate the transfer of user identities and data.

Why this answer

Option B is correct because tenant-to-tenant migrations require explicit authorization between the source and target tenants, typically granted through an admin consent URL that creates an enterprise application/service principal in the source tenant so the migration tool can read and write data. Option D is correct because you must add and verify the source domain (via a TXT record) in the target Microsoft 365 tenant before you can pre-stage or map users, mailboxes, and domains during migration. Option E is correct because directory synchronization (for example, using Microsoft Entra Connect or cross-tenant synchronization/Identity Manager) is needed to establish matching user identities and mail-enabled objects between tenants so migrated users retain proper object references.

Option A is not required before migrating users; MX record changes are part of the final cutover and should occur only after mailboxes and mail flow are ready, otherwise mail delivery breaks. Option C is wrong because deleting source mailboxes before migration would destroy the data being migrated; source mailboxes must remain intact until the migration and cutover are complete.

Exam trap

The trap here is that candidates confuse the order of operations, thinking MX record changes (Option A) must happen early, when in fact they are a cutover step performed after migration is complete to avoid email disruption.

10
MCQhard

The exhibit shows the output of a PowerShell command for a user. The user reports that they cannot access Microsoft Teams, although they have an E3 license (ENTERPRISEPACK). What is the most likely cause?

A.The Teams service plan is disabled in the user's license.
B.The user's license is suspended.
C.The user's license has expired.
D.The user does not have a license assigned.
AnswerA

The PowerShell output, such as from `Get-MsolUser -LicenseDetails`, would display a ServicePlan entry for Teams with a `ProvisioningStatus` of `Disabled` or a `CapabilityStatus` of `Disabled`. This indicates the Teams service plan is present in the user's assigned license but has been explicitly turned off, so the user is licensed but cannot access Teams. The `IsLicensed` property remains True because other service plans in the same license, like Exchange Online or SharePoint Online, are still active.

Why this answer

The PowerShell output shows the user has an E3 license (ENTERPRISEPACK) assigned, but the Teams service plan is disabled. Even with an active E3 license, if the Teams service plan is explicitly turned off in the license assignment, the user cannot access Microsoft Teams. This is a common configuration where an admin disables specific service plans to control feature access.

Exam trap

The trap here is that candidates assume an assigned E3 license grants access to all included services by default, overlooking that individual service plans can be disabled within the license, which is a common configuration tested in MS-102.

How to eliminate wrong answers

Option B is wrong because a suspended license would typically show a status of 'Suspended' or 'Disabled' in the output, and the user would lose access to all licensed services, not just Teams. Option C is wrong because an expired license would also affect all services under that license, and the output would likely show an expiration date or a 'Disabled' status; the E3 license shown is still active. Option D is wrong because the output clearly shows the user has an ENTERPRISEPACK license assigned, so they do have a license.

11
MCQeasy

You are a Microsoft 365 administrator. Users report that they cannot access Microsoft Teams. You check the Microsoft 365 admin center and see that the service health for Microsoft Teams shows a 'Service degradation' incident. What is the most appropriate initial action?

A.Contact the Microsoft regional escalation engineer immediately.
B.Open a support request with Microsoft to report the outage.
C.Review the incident details in the service health dashboard for an estimated resolution time and workaround.
D.Restart the Microsoft Teams service on all client machines.
AnswerC

The Service Health Dashboard is the designated place to see live incident status, the affected workload, the problem statement, the estimated time for restoration, and any Microsoft-issued workaround. By reviewing the incident details, you can quickly correlate user reports with a known root cause and then set accurate expectations with your organization. The dashboard also provides an incident history timeline and the option to get email alerts, making it the best evidence-based first action.

Why this answer

The most appropriate initial action when a service degradation incident is already visible in the Microsoft 365 admin center is to review the incident details in the service health dashboard. This provides the estimated resolution time, current status, and any available workarounds published by Microsoft, allowing you to inform users and mitigate impact without immediately escalating or opening a support request.

Exam trap

The trap here is that candidates assume a service degradation requires immediate escalation or a support ticket, but the correct first step is to check the service health dashboard for existing incident details and workarounds before taking any further action.

How to eliminate wrong answers

Option A is wrong because contacting a Microsoft regional escalation engineer is a premature escalation step; this should only be done after reviewing the incident details and if the issue is critical and not being addressed. Option B is wrong because opening a support request to report the outage is redundant when Microsoft has already acknowledged the incident in the service health dashboard; support requests are for issues not yet recognized or requiring tenant-specific troubleshooting. Option D is wrong because restarting the Microsoft Teams service on client machines is a client-side action that cannot resolve a service-wide degradation incident that originates from Microsoft's infrastructure.

12
MCQeasy

An administrator is setting up a new Microsoft 365 tenant and has added the custom domain 'contoso.com'. The domain status shows 'Pending verification'. Which type of DNS record must the administrator add to the public DNS zone to complete domain ownership verification?

A.MX record
B.TXT record
C.CNAME record
D.SPF record
AnswerB

A TXT record proves ownership without affecting mail flow, unlike MX records which route email. Microsoft Entra ID reads the unique value at the zone apex, so adding it to the public DNS zone resolves the 'Pending verification' status and confirms the tenant controls contoso.com.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record containing the unique verification string provided by the Microsoft 365 admin center to the public DNS zone. The TXT record proves you control the domain by allowing Microsoft to query the DNS and match the value. This is the standard method defined by RFC 1035 for domain validation.

Exam trap

The trap here is that candidates often confuse the TXT record used for domain verification with the SPF record, which is also a TXT record but serves a completely different purpose, leading them to select SPF instead of the generic TXT record option.

How to eliminate wrong answers

Option A is wrong because an MX record specifies the mail exchange server for the domain and is not used for domain ownership verification; it would be added later for mail routing. Option C is wrong because a CNAME record maps an alias to a canonical name and is not used for verification; it is typically used for services like autodiscover. Option D is wrong because an SPF record is a TXT record that specifies authorized mail servers to prevent spoofing, but it is not the specific record type used for domain verification; the verification requires a unique TXT record with a specific value, not an SPF policy.

13
Multi-Selecteasy

Your organization is deploying Microsoft 365 Copilot. You need to ensure that data security is maintained. Which THREE actions should you take?

Select 3 answers
A.Disable Microsoft 365 Copilot for all users.
B.Block all external sharing for SharePoint and OneDrive.
C.Enable audit logging in Microsoft 365.
D.Configure data loss prevention (DLP) policies.
E.Create sensitivity labels to classify and protect data.
AnswersC, D, E

Enable audit logging in Microsoft 365 so that Copilot user prompts and responses, along with related file access events, are recorded in the unified audit log. This telemetry is essential for security teams to detect abnormal Copilot usage, investigate data exfiltration attempts, and produce evidence for compliance. Without audit logging, administrators lack the visibility needed to confirm whether Copilot is being used appropriately.

Why this answer

Enabling audit logging in Microsoft 365 is essential for tracking user interactions with Microsoft 365 Copilot, including prompts, responses, and data access events. This provides a forensic trail to detect unauthorized data exposure or misuse, which is a foundational requirement for maintaining data security in AI-powered workloads.

Exam trap

The trap here is that candidates often assume blocking external sharing (Option B) is a primary security control for Copilot, when in fact Copilot's data security risks are more about internal data leakage through AI processing, which requires audit logging, DLP, and sensitivity labels to mitigate.

14
Multi-Selecthard

Which THREE factors are considered when Microsoft Entra ID evaluates a conditional access policy?

Select 3 answers
A.User or group membership
B.Mailbox size
C.User's department attribute in Microsoft Entra ID
D.Location (IP range or country)
E.Device platform (e.g., Windows, iOS)
AnswersA, D, E

User or group membership is the fundamental assignment in a Microsoft Entra Conditional Access policy, defining the exact identities that will be evaluated. You can target All users, specific users, or groups, and you should always exclude at least one emergency access account. Group membership can be static or dynamic, with dynamic groups enabling attribute-based inclusion, but the policy condition itself evaluates membership rather than arbitrary directory attributes.

Why this answer

Microsoft Entra ID evaluates conditional access policies based on signals from the user, device, and location. User or group membership (Option A) is a primary signal because policies are typically assigned to specific users or groups to control access. Location (Option D) is evaluated using IP ranges or country codes to enforce restrictions like blocking access from untrusted networks.

Device platform (Option E) allows policies to target specific operating systems (e.g., Windows, iOS) to enforce compliance requirements like requiring Intune enrollment.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID attributes (like department) with actual conditional access conditions, but Microsoft only supports specific signals (user/group, location, device platform, risk, client apps, and sign-in risk) and not arbitrary directory attributes.

15
Multi-Selectmedium

An administrator needs to open a Microsoft 365 support request because all users are experiencing intermittent service outages for Exchange Online. Before contacting support, which two pieces of information should the administrator have ready to ensure efficient troubleshooting? (Choose two.)

Select 2 answers
A.Tenant ID (or Microsoft 365 tenant domain name)
B.Number of affected users
C.Detailed description of the problem and troubleshooting steps attempted
D.Network bandwidth graph from the past 24 hours
AnswersA, C

Tenant ID (or the Microsoft 365 tenant domain name such as contoso.onmicrosoft.com) is the primary key Microsoft Support uses to locate your specific tenancy in their backend systems. It lets support immediately verify service health, tenant-level configurations, and any recent changes or incidents affecting that environment. Without this identifier, they cannot authenticate the tenant context, route the request correctly, or correlate your issue with backend telemetry.

Why this answer

The Tenant ID (or Microsoft 365 tenant domain name) is required by Microsoft Support to uniquely identify your tenant in their systems, enabling them to pull up your service configuration, subscription details, and relevant health data. This identifier is essential for routing the support request to the correct engineering team and for correlating the issue with backend telemetry.

Exam trap

The trap here is that candidates often confuse 'nice-to-have' diagnostic data (like the number of affected users or network graphs) with the mandatory identification and problem description that Microsoft Support requires to initiate a case.

16
MCQeasy

Your organization has a Microsoft 365 E5 subscription. You want to enable Microsoft Defender for Office 365 to protect against malicious attachments in email. Which policy should you configure?

A.Anti-phishing policy
B.Anti-malware policy
C.Safe Attachments policy
D.Safe Links policy
AnswerC

Safe Attachments policy is the correct answer because it routes each email attachment to an isolated Microsoft detonation chamber, where the file is opened and executed in a virtualized environment to observe its run-time behavior. It can block or replace the attachment if unknown malware or zero-day exploit activity is detected, and it can also redirect the message for admin review. This is the Defender for Office 365 mechanism specifically built to protect against malicious attachments that evade classic signature-based scanning.

Why this answer

Safe Attachments policy is the correct choice because Microsoft Defender for Office 365's Safe Attachments feature specifically protects against malicious attachments in email by detonating them in a virtual sandbox environment before delivery. This policy allows you to configure actions for detected malware, such as blocking, replacing, or dynamically delivering attachments based on threat analysis.

Exam trap

The trap here is that candidates often confuse the basic Anti-malware policy (which uses signature-based detection) with the advanced Safe Attachments policy (which uses sandbox detonation), leading them to select Option B incorrectly.

How to eliminate wrong answers

Option A is wrong because Anti-phishing policy protects against phishing attempts by analyzing sender reputation, impersonation, and spoofing, not by scanning attachments for malware. Option B is wrong because Anti-malware policy provides basic malware protection using the built-in malware engine but does not include the advanced sandboxing and detonation capabilities of Safe Attachments. Option D is wrong because Safe Links policy protects users from malicious URLs in email and Office documents by checking links at time of click, not by scanning attachments.

17
MCQhard

You are deploying Microsoft 365 for a new subsidiary. The subsidiary has a single domain subsidiary.com. You need to configure a hybrid identity solution with Microsoft Entra ID. The on-premises Active Directory has a single domain and all user accounts are synchronized using Microsoft Entra Connect. You want to ensure that users can sign in to Microsoft 365 using their on-premises credentials without exposing the password hash to Microsoft. What should you do?

A.Configure password hash synchronization.
B.Create cloud-only user accounts and disable on-premises authentication.
C.Implement Active Directory Federation Services (AD FS) with Microsoft Entra ID.
D.Enable pass-through authentication (PTA) with Microsoft Entra Connect.
AnswerD

Pass-through authentication validates passwords directly against on-premises Active Directory via a lightweight agent, so credentials are never stored in Microsoft Entra ID and no password hash is synchronised to the cloud, satisfying the requirement to avoid exposing password hashes to Microsoft.

Why this answer

Pass-through authentication (PTA) allows users to sign in to Microsoft 365 using their on-premises credentials without storing password hashes in Microsoft Entra ID. PTA validates passwords directly against on-premises Active Directory via an agent, ensuring no password hash is exposed to Microsoft, which meets the stated requirement.

Exam trap

The trap here is that candidates often confuse pass-through authentication with password hash synchronization, assuming both expose credentials, but PTA avoids any hash storage while still enabling cloud authentication.

How to eliminate wrong answers

Option A is wrong because password hash synchronization stores a hash of the on-premises password in Microsoft Entra ID, which directly exposes the password hash to Microsoft, violating the requirement. Option B is wrong because creating cloud-only user accounts and disabling on-premises authentication would break the hybrid identity requirement, as users would no longer use their on-premises credentials for sign-in. Option C is wrong because while AD FS also avoids storing password hashes in the cloud, it introduces additional infrastructure complexity and is not the simplest solution; PTA is the recommended choice for this specific scenario where password hash exposure must be avoided without deploying federation servers.

18
MCQmedium

A company wants to ensure that all new users created in Microsoft 365 are automatically assigned a specific set of licenses based on their department. The company has 200 users across Sales, Marketing, and IT departments. Each department uses different Microsoft 365 license plans. Which approach should the administrator use?

A.A: Create a PowerShell script that runs on a schedule to assign licenses based on department attribute.
B.B: Use group-based licensing and assign each department's users to a security group with the appropriate license.
C.C: Use Azure AD Dynamic Groups to automatically add users to groups based on department, and then assign licenses to those groups.
D.D: Manually assign licenses to each user after creation.
AnswerC

To meet the requirement, combine Azure AD dynamic groups with group-based licensing: define a dynamic membership rule such as "user.department -eq 'Sales'" so Azure AD automatically adds and removes users as their department attribute changes. When a new user is created with the department attribute set, Azure AD evaluates the rule, adds the user to the matching group, and group-based licensing automatically assigns the appropriate license to that user without any manual or scripted intervention. This is a declarative, natively supported solution that scales to thousands of users and works in near real time for new directory objects.

Why this answer

Azure AD Dynamic Groups can automatically add users to groups based on their department attribute (e.g., using a rule like `user.department -eq "Sales"`), and group-based licensing can then assign the appropriate Microsoft 365 license plan to each dynamic group. This ensures that any new user created with the correct department attribute is automatically added to the corresponding group and receives the license without manual intervention or scheduled scripts.

Exam trap

The trap here is that candidates often confuse 'group-based licensing' (which requires groups to be populated) with 'dynamic groups' (which automate group membership), leading them to choose Option B because they think group-based licensing alone is sufficient, but without dynamic groups, the groups must be manually maintained.

How to eliminate wrong answers

Option A is wrong because a scheduled PowerShell script introduces latency (users may not get licenses until the script runs), requires maintenance, and is less reliable than Azure AD's native automatic licensing engine. Option B is wrong because it suggests manually assigning users to security groups, which does not automate the process for new users; group-based licensing requires the groups to be populated automatically (via dynamic groups) to achieve the stated goal. Option D is wrong because manual assignment is not scalable for 200 users and does not meet the requirement of automatic license assignment for new users.

19
MCQeasy

A user reports that they cannot access their Microsoft 365 mailbox from the Outlook desktop client, but they can access it via Outlook on the web. Other users in the same tenant are not experiencing issues. What is the most likely cause?

A.There is a service incident affecting only the Outlook desktop client.
B.The user's Outlook profile is corrupted or needs to be re-created.
C.The user's account has been disabled.
D.The user's Microsoft 365 license has expired.
AnswerB

A corrupted Outlook profile is the most plausible cause when a user cannot access their mailbox from the Outlook desktop client but can still access it via Outlook on the web. The Outlook profile contains local configuration data, cache files (.ost), and authentication tokens; if this data becomes corrupted, the client may fail to start, hang, or repeatedly prompt for credentials. Re-creating the profile forces Outlook to rebuild the local cache and re-fetch the server-side mailbox, which resolves the issue without any impact on the server data.

Why this answer

If a user can access their mailbox via Outlook on the web but not the desktop client, while other users are unaffected, the issue is isolated to the local Outlook profile or client configuration. A corrupted Outlook profile is the most common cause and is resolved by creating a new profile. This scenario rules out tenant-wide service incidents, account disablement, or license expiry because those would also block OWA access.

Exam trap

MS-102 often tests the distinction between client-side and service-side failures — candidates may jump to service incidents or licensing, but the key differentiator is that OWA works, which points to a local client issue.

How to eliminate wrong answers

Option A is wrong because a service incident affecting only the Outlook desktop client would impact multiple users, not just one, and would not spare OWA for that same user. Option C is wrong because a disabled account would prevent all access, including OWA, and would typically show a sign-in error. Option D is wrong because an expired Microsoft 365 license would also block OWA access and would affect the user's ability to authenticate to the service entirely.

20
MCQeasy

You are a Microsoft 365 administrator for a small business with 50 users. The company is using Microsoft 365 Business Basic. You need to configure email for the custom domain contoso.com. You have added the domain in the Microsoft 365 admin center and verified ownership. Users currently have onmicrosoft.com email addresses. You need to change the primary email address for all users to their custom domain (e.g., user@contoso.com). What should you do?

A.Remove the onmicrosoft.com domain from the tenant.
B.Convert all mailboxes to shared mailboxes and reassign licenses.
C.Change the primary email address for each user to user@contoso.com in the admin center.
D.Configure the MX record for contoso.com to point to Exchange Online.
AnswerC

After contoso.com is added and verified in the tenant, you open Users > Active users, select a user, choose Manage username and email, and set user@contoso.com as the primary email address. This updates the primary SMTP proxy address in Exchange Online, giving each mailbox a valid address on the custom domain while optionally keeping the onmicrosoft.com address as a proxy alias for continuity.

Why this answer

In Microsoft 365, after adding and verifying a custom domain, you must manually update each user's primary email address (User Principal Name and primary SMTP address) from the default onmicrosoft.com domain to the custom domain. This is done in the Microsoft 365 admin center under Users > Active Users, by editing the username and email fields. Simply adding the domain does not automatically change existing user addresses.

Exam trap

The trap here is that candidates assume adding and verifying a custom domain automatically updates existing user email addresses, when in fact it only makes the domain available for use, requiring manual or scripted updates per user.

How to eliminate wrong answers

Option A is wrong because removing the onmicrosoft.com domain is not possible—it is a reserved default domain that cannot be deleted, and doing so would break authentication and routing for users still using it. Option B is wrong because converting mailboxes to shared mailboxes and reassigning licenses does not change the primary email address; shared mailboxes have their own SMTP addresses and are not a mechanism for domain migration. Option D is wrong because configuring the MX record for contoso.com to point to Exchange Online is a DNS step for mail routing, but it does not change the primary email address of existing users; that requires explicit user attribute updates.

21
MCQmedium

An administrator wants to receive real-time notifications for service incidents in Microsoft 365. The notifications must be sent to a Microsoft Teams channel instead of email. Which configuration should the administrator set up?

A.Configure a webhook connector in Microsoft Teams to subscribe to the Office 365 Service Communications API.
B.Configure an email notification rule in the Microsoft 365 admin center and forward it to a Teams email address.
C.Use Power Automate to check service health and post to Teams every 5 minutes.
D.Configure a message center alert to email and then use a third-party integration to post to Teams.
AnswerA

The Office 365 Service Communications API publishes webhook subscriptions that deliver service incident updates to a Teams channel via an incoming webhook connector. Once you register the Teams webhook URL and subscribe to relevant incidents, Microsoft pushes notifications as they occur, eliminating polling intervals. This is the only option that gives zero-latency, event-driven delivery without intermediaries or unsupported email forwarding.

Why this answer

The Office 365 Service Communications API provides real-time webhook-based notifications for service incidents. By configuring a webhook connector in Microsoft Teams, the administrator can subscribe to this API and receive incident alerts directly in a Teams channel without polling or email forwarding.

Exam trap

The trap here is that candidates may assume Power Automate or email forwarding is sufficient for real-time needs, but the exam specifically tests the understanding that webhook subscriptions to the Service Communications API are the only method that guarantees real-time, push-based notifications to a Teams channel.

How to eliminate wrong answers

Option B is wrong because forwarding an email notification to a Teams email address does not provide real-time delivery; Teams email integration is asynchronous and subject to delays, and the admin center email rules do not support direct Teams channel posting. Option C is wrong because Power Automate polling every 5 minutes introduces latency and is not real-time; the requirement specifies real-time notifications, which the Service Communications API webhook delivers instantly. Option D is wrong because it adds unnecessary complexity and delay by relying on email as an intermediary and a third-party integration, whereas a native webhook connector directly subscribes to the API for immediate delivery.

22
MCQeasy

A company recently acquired another company and needs to allow users from the acquired tenant to access its SharePoint Online sites as guest users, but only if those users already have accounts in the acquired Azure AD tenant. Which Microsoft 365 feature should be configured?

A.Cross-tenant access settings for B2B collaboration
B.B2B direct connect
C.Multi-Geo
D.Tenant Restrictions
AnswerA

Cross-tenant access settings for B2B collaboration are the correct method for controlling and enabling guest access across Microsoft 365 tenants. These settings let you configure inbound and outbound access policies, apply cross-tenant trust for Multi-factor Authentication and device compliance, and set specific automatic redemption options. They govern SharePoint external sharing by controlling which external Azure AD tenants can authenticate and how their guest identities are treated, making this the correct tool for the scenario.

Why this answer

Cross-tenant access settings for B2B collaboration allow you to configure inbound and outbound access between two Azure AD tenants. By enabling B2B collaboration with the acquired tenant and setting the appropriate cross-tenant access policies, you can invite users who already have accounts in that tenant as guest users to access SharePoint Online sites. This ensures that only authenticated users from the acquired tenant are granted access, meeting the requirement.

Exam trap

The trap here is that candidates confuse B2B direct connect with B2B collaboration, assuming both provide guest access to SharePoint, but B2B direct connect is limited to Teams shared channels and does not support SharePoint guest invitations.

How to eliminate wrong answers

Option B (B2B direct connect) is wrong because it is designed for Teams Connect shared channels, not for granting guest access to SharePoint Online sites, and it does not support inviting users as guests with Azure AD accounts. Option C (Multi-Geo) is wrong because it addresses data residency and geographic location of tenant data, not cross-tenant user access or guest invitations. Option D (Tenant Restrictions) is wrong because it controls access to SaaS apps based on tenant ID via HTTP headers, but it does not enable inviting external users from another tenant as guests.

23
MCQeasy

You are the Microsoft 365 administrator for a company that uses Microsoft 365 E3. The company has a single Microsoft 365 tenant. The IT manager asks you to create a new user account for a temporary employee who will start next week and will need access to Exchange Online and SharePoint Online. The employee will leave after three months. You need to create the user account with the minimum required licenses. What should you do?

A.Create a new user in the Microsoft 365 admin center and assign a Microsoft 365 Business Premium license.
B.Create a new user in the Microsoft 365 admin center and assign a Microsoft 365 E3 license, then disable all services except Exchange Online and SharePoint Online.
C.Create a new user in the Microsoft 365 admin center and assign an Exchange Online (Plan 1) license and a SharePoint Online (Plan 1) license.
D.Create a new user in the Microsoft 365 admin center and assign a Microsoft 365 E3 license.
AnswerC

Assigning Exchange Online (Plan 1) and SharePoint Online (Plan 1) licenses provides exactly the services required by the temporary employee: Exchange Online and SharePoint Online. This meets the minimum required licenses because it does not include unnecessary services. These licenses are available as standalone subscriptions and can be assigned individually. This is the most cost-effective and precise solution for the scenario, ensuring the user has access only to what they need.

Why this answer

The requirement is to provide access to Exchange Online and SharePoint Online with the minimum required licenses. Assigning standalone Exchange Online (Plan 1) and SharePoint Online (Plan 1) licenses achieves this by providing exactly the needed services without the extra cost and features of a suite license. Using a suite license like Microsoft 365 E3 or Business Premium would grant more services than necessary and does not meet the minimum license requirement.

Disabling services within a suite license still consumes the full license.

Exam trap

The trap here is assuming that a suite license like Microsoft 365 E3 is required for Exchange Online and SharePoint Online access, when standalone service licenses are available and more cost-effective for specific needs.

24
MCQeasy

A user account was accidentally deleted 10 days ago. The administrator needs to restore the user's mailbox and OneDrive for Business content. Which method should the administrator use?

A.Recreate the user account with the same name, and the data will be automatically restored.
B.Restore the user from the 'Deleted users' page in the Microsoft 365 admin center.
C.Use the Exchange admin center to recover the mailbox only.
D.Submit a support request to Microsoft to recover the deleted data.
AnswerB

In the Microsoft 365 admin center, navigate to Users > Deleted users, locate the accidentally deleted user, and choose Restore. This is the supported self-service recovery path for soft-deleted user objects within the 30-day retention period, and it re-associates the user's existing Exchange Online mailbox, OneDrive for Business, and other workload data with the restored account.

Why this answer

Microsoft 365 retains deleted user objects, including their Exchange Online mailbox and OneDrive for Business data, for 30 days in the 'Deleted users' list. Restoring the user from this page within the retention period automatically recovers the associated mailbox and OneDrive content without requiring separate tools or support requests.

Exam trap

The trap here is that candidates often confuse the 30-day soft-delete retention with the ability to simply recreate the user account, or they assume that separate admin centers are required for mailbox and OneDrive recovery, when in fact the unified 'Deleted users' restore handles both.

How to eliminate wrong answers

Option A is wrong because simply recreating a user account with the same name does not automatically restore the original mailbox or OneDrive data; the new account receives a fresh mailbox and OneDrive, and the deleted user's data remains in the recycle bin only if the original object is restored. Option C is wrong because the Exchange admin center can recover a soft-deleted mailbox only if the user object still exists or was recently deleted, but it cannot recover OneDrive for Business content, which requires the full user restoration from the Microsoft 365 admin center. Option D is wrong because Microsoft support is not needed for this scenario; the administrator can self-service restore the user from the 'Deleted users' page within the 30-day retention period without submitting a support request.

25
MCQeasy

An administrator has created a new user account in Microsoft Entra ID. To ensure the user has a mailbox in Exchange Online, what is the next step?

A.Assign an Exchange Online license to the user
B.Create an Exchange mailbox manually
C.Run the Microsoft 365 Setup wizard
D.Configure DNS records for the domain
AnswerA

In Microsoft Entra ID (Azure AD), a user object does not automatically have an Exchange Online mailbox until a license that contains the Exchange Online service plan (e.g., Microsoft 365 E3/E5, Exchange Online Plan 1/2) is assigned. Once assigned, the Exchange Online provisioning service creates the mailbox automatically, usually within minutes to a few hours, and the user can log in to Outlook or Outlook on the web. This is the only supported, self-service method for creating a mailbox for a standard user in a cloud-only environment.

Why this answer

In Microsoft 365, a user must be assigned an Exchange Online license (part of an E3, E5, or standalone plan) before a mailbox is automatically provisioned in Exchange Online. Without a license, the user object exists in Entra ID but has no mailbox; the license assignment triggers the mailbox creation process within 24 hours.

Exam trap

The trap here is that candidates often think creating the user in Entra ID or configuring DNS automatically provisions a mailbox, but Microsoft 365 requires an explicit license assignment to enable the Exchange Online service plan for that user.

How to eliminate wrong answers

Option B is wrong because Exchange Online does not support manually creating a mailbox; mailboxes are automatically provisioned when a license is assigned, and manual creation is only possible in on-premises Exchange Server. Option C is wrong because the Microsoft 365 Setup wizard is used for initial tenant configuration (e.g., adding a domain or setting up admin accounts), not for provisioning a mailbox for an existing user. Option D is wrong because DNS records (MX, SPF, etc.) are required for mail routing to the tenant, but they do not create a mailbox; the mailbox must exist first via license assignment.

26
Multi-Selecthard

You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a hybrid identity environment with Microsoft Entra Connect Sync. You need to implement Microsoft Entra Password Protection to prevent users from using weak passwords. You must ensure that the on-premises Active Directory Domain Services (AD DS) environment enforces the same password policies as Microsoft Entra ID. What should you do? (Choose two.)

Select 2 answers
A.Install the Microsoft Entra Password Protection proxy service on a server in the on-premises network.
B.Enable password hash synchronization in Microsoft Entra Connect.
C.Configure the on-premises domain controllers to use the Microsoft Entra Password Protection proxy service as a forwarder.
D.Install the Microsoft Entra Password Protection proxy service on a domain controller.
E.Install the Microsoft Entra Password Protection DC agent on all domain controllers.
AnswersA, E

The Microsoft Entra Password Protection proxy service is required to enable on-premises domain controllers to communicate with Microsoft Entra ID for password policy enforcement. The proxy service acts as a bridge between the on-premises environment and Microsoft Entra ID, forwarding password validation requests. Without the proxy, the domain controllers cannot access the global banned password list or custom banned lists. This component is essential for the on-premises enforcement of Microsoft Entra Password Protection.

Why this answer

To enforce Microsoft Entra Password Protection on-premises, you must deploy both the proxy service and the DC agent. The proxy service enables communication with Microsoft Entra ID to retrieve the password policies, and the DC agent on each domain controller enforces those policies during password changes. Password hash synchronization is not required, and the proxy service must not be installed on a domain controller.

These two components work together to extend Microsoft Entra Password Protection to the on-premises AD DS environment.

Exam trap

The trap here is assuming that password hash synchronization is required or that the proxy service should be installed on a domain controller, which are common misconceptions.

27
MCQmedium

Your organization plans to migrate from on-premises Exchange to Exchange Online. You need to ensure minimal disruption during the migration. Which approach should you recommend?

A.Deploy a hybrid configuration and migrate mailboxes in batches.
B.Perform a cutover migration during a weekend.
C.Use IMAP migration to migrate all mailboxes in parallel.
D.Use a third-party migration tool for a one-time bulk migration.
AnswerA

Hybrid configuration preserves coexistence between on-premises Exchange and Exchange Online, letting mailboxes move in controlled batches while mail flow and free/busy sharing continue uninterrupted. This directly satisfies the minimal-disruption constraint, since users keep working throughout and rollback remains possible until each batch completes.

Why this answer

A hybrid configuration with batch migration is the recommended approach for minimal disruption because it allows coexistence between on-premises Exchange and Exchange Online, enabling gradual mailbox moves while maintaining free/busy, calendar sharing, and mail flow. Batch migration lets you schedule and control the pace, reducing user impact and allowing rollback if issues arise.

Exam trap

MS-102 often tests migration strategies; candidates may choose cutover for simplicity, ignoring that it causes downtime and lacks coexistence, which is critical for minimal disruption.

How to eliminate wrong answers

Option B is wrong because a cutover migration is a one-time, all-at-once move that causes significant downtime and is only suitable for small organizations with no coexistence needs. Option C is wrong because IMAP migration only migrates email data, not calendars, contacts, or tasks, and lacks coexistence features; it is also not designed for parallel migration of all mailboxes without throttling issues. Option D is wrong because third-party tools may not provide native coexistence or integrated management, and a one-time bulk migration can cause disruption and lacks the flexibility of a phased approach.

28
MCQhard

Your company recently acquired a subsidiary that uses a different Microsoft 365 tenant. You are tasked with merging the two tenants into one. The subsidiary has 1,500 users with unique email domains. You need to migrate all users, mailboxes, and SharePoint data while minimizing downtime and preserving data integrity. You have access to both tenants as global admin. What should you do first?

A.Add the subsidiary's domain to the primary tenant, then delete the subsidiary tenant and recreate users
B.Use the Microsoft 365 Merger Center in the admin portal
C.Use a third-party migration tool such as BitTitan MigrationWiz to perform the migration
D.Use Microsoft's native tenant-to-tenant migration by moving mailboxes via PowerShell and exporting SharePoint content
AnswerC

BitTitan MigrationWiz is an established third-party platform that performs cross-tenant mailbox, OneDrive, SharePoint, and Teams migrations by connecting to both tenants and running staged delta-sync batches. It minimizes downtime by pre-staging content and then synchronizing only changes during the cutover window, preserving item-level fidelity, metadata, and permissions. This is the standard recommended approach for consolidating two Microsoft 365 tenants after an acquisition.

Why this answer

Microsoft does not provide a native tool for merging two tenants; third-party tools like BitTitan MigrationWiz are designed specifically for cross-tenant migrations, supporting mailbox, SharePoint, and user data migration with minimal downtime and data integrity. These tools handle directory synchronization, mailbox rehydration, and SharePoint content mapping, which are critical for a 1,500-user migration with unique domains.

Exam trap

The trap here is that candidates assume Microsoft provides a native 'merger' tool or that PowerShell alone can handle a full tenant merge, overlooking the lack of built-in cross-tenant SharePoint migration capabilities and the need for specialized third-party solutions.

How to eliminate wrong answers

Option A is wrong because deleting the subsidiary tenant and recreating users would cause permanent data loss (mailboxes, SharePoint content) and cannot preserve data integrity; domain addition alone does not migrate data. Option B is wrong because there is no 'Microsoft 365 Merger Center' in the admin portal; this is a fabricated feature that does not exist. Option D is wrong because native tenant-to-tenant migration via PowerShell is limited to mailbox moves (using New-MoveRequest with cross-tenant prerequisites) and does not support SharePoint data migration; exporting and importing SharePoint content via PowerShell is complex, error-prone, and not designed for large-scale migrations with minimal downtime.

29
Multi-Selectmedium

You are the Microsoft 365 administrator for a large enterprise. You need to ensure that only users with a valid business justification can access sensitive data stored in SharePoint Online. The solution must enforce access reviews and provide detailed reports for auditors. Which TWO actions should you take?

Select 2 answers
A.Configure access reviews in Microsoft Entra ID Governance for the SharePoint site.
B.Deploy Microsoft Defender for Cloud Apps and create a session policy to monitor access.
C.Enable audit logging in Microsoft Purview and generate detailed access reports.
D.Apply a sensitivity label to the SharePoint site and require justification for label change.
E.Create a data loss prevention (DLP) policy to block unauthorized sharing.
AnswersA, C

Configuring access reviews in Microsoft Entra ID Governance automates a recurring certification workflow in which site owners or designated reviewers must explicitly confirm each user's continued need to access the SharePoint site. Every approval response is logged with a timestamp and reviewer identity, generating the audit trail required by internal policy or external auditors. This directly satisfies the business-justification and periodic-attestation requirements because access is not simply recorded; it is actively revalidated on a fixed schedule.

Why this answer

Option A is correct because Microsoft Entra ID Governance access reviews are the native mechanism to periodically attest who still needs access to a SharePoint site, enforcing the requirement that only users with a valid business justification retain access. Option C is correct because enabling audit logging in Microsoft Purview captures SharePoint Online access and activity events, and the resulting audit log search and reports provide the detailed evidence auditors require. Option B is not correct because Defender for Cloud Apps session policies monitor and control sessions but do not enforce access reviews or produce the required auditor-facing access attestation reports.

Option D is not correct because sensitivity labels with justification for label changes govern classification and labeling actions, not recurring access justification or review. Option E is not correct because a DLP policy prevents sharing of sensitive content but does not enforce access reviews or generate the detailed access reports for auditors.

Exam trap

The trap here is that candidates often confuse access control mechanisms like DLP or sensitivity labels with identity-based access reviews, failing to recognize that access reviews in Entra ID Governance enforce periodic attestation, while audit logging in Purview provides the detailed access reports for auditors.

30
MCQeasy

Your organization is migrating from on-premises Exchange to Exchange Online. You need to ensure that users can access their mailboxes during the migration with minimal interruption. Which migration method should you use?

A.Minimal hybrid migration.
B.Cutover migration.
C.Staged migration.
D.IMAP migration.
AnswerA

Minimal hybrid migration establishes a lightweight coexistence by synchronizing identities with Azure AD Connect and configuring an Exchange hybrid endpoint, allowing you to move mailboxes in controlled batches through the Migration Dashboard. Because users retain their passwords via single sign-on and mail flow continues to work on both sides, the move has minimal user impact and can be performed incrementally, which is exactly why it is the correct approach for an Exchange-to-Exchange Online migration.

Why this answer

A minimal hybrid migration is the correct choice because it allows you to synchronize on-premises mailboxes with Exchange Online using the Hybrid Configuration Wizard (HCW) and then move mailboxes in batches with minimal downtime. Users retain access to their existing mailboxes during the migration, and once a mailbox is moved, Outlook automatically reconfigures via Autodiscover, ensuring a seamless transition.

Exam trap

The trap here is that candidates often confuse 'minimal hybrid' with 'cutover migration,' assuming cutover is simpler, but the question explicitly requires minimal interruption, which cutover cannot provide due to its all-at-once nature.

How to eliminate wrong answers

Option B (Cutover migration) is wrong because it requires migrating all mailboxes at once within a limited time window, causing significant downtime and disruption for users. Option C (Staged migration) is wrong because it is only supported for migrating from on-premises Exchange 2003 or 2007, not newer versions, and requires provisioning mail-enabled users in advance, which adds complexity. Option D (IMAP migration) is wrong because it only migrates email data (not calendar, contacts, or tasks) and does not provide a unified global address list or coexistence features, leading to a poor user experience.

31
MCQeasy

Your organization uses Microsoft 365 Business Premium. You need to ensure that all Windows 10 devices are enrolled in Microsoft Intune and comply with a device compliance policy that requires BitLocker encryption and a minimum OS version. What should you do first?

A.Configure automatic enrollment in Microsoft Entra ID for Windows 10 devices.
B.Install the Intune Connector for Active Directory on a domain controller.
C.Deploy a configuration profile to enable BitLocker.
D.Create a device compliance policy in Microsoft Intune.
AnswerA

Configure automatic enrollment in Microsoft Entra ID for Windows 10 devices: This is the correct approach. In Microsoft Entra ID (formerly Azure AD), you can enable Windows automatic enrollment as part of the MDM/MAM integration with Intune. When a Windows 10/11 device performs an Azure AD join or registers with Azure AD, it automatically and silently enrolls into Intune, requiring no user interaction and eliminating the need for manually deploying enrollment scripts or connectors. This must be set before you can apply device configuration profiles or compliance policies.

Why this answer

To enforce Intune compliance policies on Windows 10 devices, the devices must first be enrolled in Intune. Automatic enrollment in Microsoft Entra ID (formerly Azure AD) is the prerequisite step that enables Windows 10 devices to automatically enroll in Intune when they join or are registered with Entra ID. Without this enrollment configured, no Intune policies—including compliance policies—can be applied to the devices.

Exam trap

The trap here is that candidates often jump to creating a compliance policy or deploying a configuration profile first, forgetting that without automatic enrollment enabled, Intune has no management relationship with the devices to apply those policies.

How to eliminate wrong answers

Option B is wrong because the Intune Connector for Active Directory is used for on-premises AD-joined devices to synchronize with Entra ID and enable hybrid Azure AD join, but it is not the first step required for Intune enrollment and compliance; automatic enrollment must be configured first. Option C is wrong because deploying a configuration profile to enable BitLocker is a subsequent step that can only be applied after devices are enrolled in Intune; it does not cause enrollment itself. Option D is wrong because creating a device compliance policy is also a later step that requires devices to already be enrolled in Intune; the policy cannot be assigned or evaluated until enrollment is established.

32
Multi-Selecteasy

Which TWO are valid methods for adding custom domains to Microsoft 365?

Select 2 answers
A.Using the New-MsolDomain PowerShell cmdlet.
B.Using the Exchange admin center (EAC).
C.Using the Azure AD B2C tenant configuration.
D.Using the 'Add domain' wizard in the Microsoft 365 admin center.
E.Using the Windows DNS Manager console.
AnswersA, D

The New-MsolDomain cmdlet comes from the legacy MSOnline module and directly invokes Azure AD's domain registration API, creating an unverified domain object in the tenant's directory. After that, you run New-MsolDomainVerificationDns to obtain the TXT record and New-MsolDomain to re-verify once the record is live. It is a valid, scriptable method, though Microsoft now deprecates MSOnline in favor of Microsoft Graph.

Why this answer

Option A is correct because the New-MsolDomain cmdlet from the MSOnline PowerShell module is a supported programmatic way to add a custom domain to a Microsoft 365/Azure AD tenant, specifying parameters such as -Name for the domain. Option D is correct because the 'Add domain' wizard in the Microsoft 365 admin center is the primary GUI method for adding a custom domain, after which it provides the required DNS TXT or MX records for verification. Option B is incorrect because the Exchange admin center manages Exchange Online recipients, mailboxes, and accepted domains for mail flow, but it is not the supported tool for adding a new custom domain to the tenant.

Option C is incorrect because Azure AD B2C is a separate customer identity service with its own tenant configuration and is unrelated to adding domains to a standard Microsoft 365 tenant. Option E is incorrect because Windows DNS Manager only manages DNS zones and records on a DNS server; it cannot add a domain to Microsoft 365, though it may be used to create the verification records if the domain is hosted on that DNS server.

Exam trap

The trap here is that candidates confuse the Exchange admin center's ability to manage 'accepted domains' with the initial domain addition process, or they mistakenly think on-premises DNS tools like Windows DNS Manager can directly add domains to Microsoft 365, when in fact they only handle the DNS verification records after the domain is registered in the tenant.

33
MCQeasy

An administrator wants to add custom branding to the Microsoft 365 sign-in page, including company logo and colors. Which section of the Microsoft 365 admin center should they navigate to?

A.Users > Active users
B.Settings > Org settings > Organization profile
C.Admin centers > Azure Active Directory
D.Billing > Licenses
AnswerB

In the Microsoft 365 admin center, the correct path is Settings > Org settings > Organization profile, which contains the 'Custom branding' section. This is where you upload a logo, choose a background image, and customize the sign-in page text for your organization's Microsoft 365 sign-in experience. The Organization profile settings consolidate tenant-wide identity and branding configurations under one management area.

Why this answer

The custom branding for the Microsoft 365 sign-in page, including company logo and colors, is configured under Settings > Org settings > Organization profile in the Microsoft 365 admin center. This section provides a dedicated 'Custom branding' tab where administrators can upload a logo, set a background image, and choose accent colors that are applied to the sign-in page for all users in the tenant.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 admin center path with the Azure Active Directory admin center path, both of which have branding settings, but the question explicitly asks for the Microsoft 365 admin center navigation, making the Azure AD path (Option C) a distractor.

How to eliminate wrong answers

Option A is wrong because Users > Active users is used for managing individual user accounts, passwords, and licenses, not for tenant-wide branding settings. Option C is wrong because Admin centers > Azure Active Directory opens the Azure AD portal, which does contain branding settings (under 'Company branding'), but the question specifically asks for the Microsoft 365 admin center navigation path, not the Azure AD portal. Option D is wrong because Billing > Licenses is used to assign and manage subscription licenses, not to configure sign-in page branding.

34
MCQeasy

A Microsoft 365 administrator needs to add a new verified domain named tailspintoys.com to the tenant and then configure it as the default domain for new user principal names. Which sequence of actions should the administrator perform in the Microsoft 365 admin center?

A.Add the domain, verify it by signing in with a global administrator account from that domain, then set it as default.
B.Set the domain as default first, then add the verification TXT record so Microsoft can confirm ownership afterward.
C.Add the domain, create the required TXT or MX verification record at the DNS host, verify ownership, then set the domain as default.
D.Create the verification record at the DNS host, then add the domain and set it as default in a single step.
AnswerC

Adding a domain in the Microsoft 365 admin center generates a verification record that must be published at the public DNS provider. After Microsoft confirms the record, ownership is verified and the domain can be designated as the default, which makes it the suffix used for new user principal names and new email addresses.

Why this answer

Adding a custom domain requires proving DNS ownership through a TXT or MX record generated by the admin center. Only after verification succeeds can the domain be marked as default, which controls the suffix applied to new user principal names and email addresses. Setting default first, pre-creating records, or attempting account-based verification all fail because Microsoft requires DNS proof before the namespace is usable.

Exam trap

The trap here is reversing the order and assuming the default designation can be applied before Microsoft verifies DNS ownership of the domain.

35
MCQhard

Refer to the exhibit. You are reviewing a Conditional Access policy in Microsoft Entra ID. What is the effect of this policy?

A.All users accessing all cloud apps are required to use MFA
B.Access to Office 365 from iOS and Android is blocked
C.All users on iOS or Android devices accessing Office 365 must use MFA and a compliant device
D.Users on mobile devices are required to use hybrid Azure AD joined devices
AnswerC

The policy targets all users, with device platforms restricted to iOS and Android, and cloud apps restricted to Office 365. Both grant controls, require multifactor authentication and require device to be marked as compliant, are selected with the AND operator, so both must be satisfied before access is granted.

Why this answer

The policy shown in the exhibit explicitly targets 'All users' and 'Office 365' as the cloud app, with conditions for 'iOS' and 'Android' device platforms. The grant controls require both 'Require multi-factor authentication' and 'Require device to be marked as compliant', meaning any user on an iOS or Android device accessing Office 365 must satisfy both MFA and device compliance. This is a common Conditional Access policy to enforce secure access from mobile devices.

Exam trap

The trap here is that candidates may misinterpret 'Require device to be marked as compliant' as requiring hybrid Azure AD join, but compliance is a separate concept managed by Intune and does not mandate hybrid join.

How to eliminate wrong answers

Option A is wrong because the policy does not apply to 'All cloud apps' — it is scoped specifically to 'Office 365' cloud app, not all cloud apps. Option B is wrong because the policy does not block access; it grants access only if MFA and device compliance are satisfied, which is a conditional grant, not a block. Option D is wrong because the policy does not require hybrid Azure AD joined devices; it requires the device to be marked as compliant, which can be achieved through Intune enrollment and compliance policies, not necessarily hybrid join.

36
MCQhard

You are a Microsoft 365 administrator for a multinational company. The security team reports that a large number of failed sign-in attempts are originating from unexpected IP ranges. The company uses Microsoft Entra ID for identity. What should you configure to automatically block these malicious sign-ins?

A.Enable Security defaults in the tenant
B.Configure Identity Protection user risk policy to block high-risk users
C.Enable Azure AD Multi-Factor Authentication for all users
D.Create a Conditional Access policy to block access from those IP ranges
AnswerD

Create a Conditional Access policy that targets the relevant users and cloud apps, and then add a Locations condition using a named location containing the specific IP ranges. Set the access control to 'Block' and enable the policy to enforce a hard deny for sign-ins originating from those ranges. Because Conditional Access evaluates network location at authentication time, this directly addresses the requirement for blocking specific IP addresses.

Why this answer

A Conditional Access policy can explicitly block sign-ins from specific IP ranges. By creating a policy that targets all users or specific users and includes a condition for the named location (the unexpected IP ranges), you can automatically deny authentication requests from those addresses at the Entra ID level, effectively blocking malicious sign-ins before they reach any application.

Exam trap

The trap here is that candidates often confuse Identity Protection risk policies (which block based on user risk) with Conditional Access location-based blocking, or they assume Security defaults or MFA alone can block specific IP ranges, when in fact only a Conditional Access policy with an IP location condition can achieve that granular control.

How to eliminate wrong answers

Option A is wrong because Security defaults enforces baseline security (like MFA for all users) but does not allow you to block specific IP ranges; it is a tenant-wide setting with no granular IP-based conditions. Option B is wrong because the Identity Protection user risk policy blocks users based on risk level (e.g., high-risk users), not based on originating IP addresses; it addresses compromised accounts, not IP-based attacks. Option C is wrong because enabling MFA for all users adds an authentication factor but does not block sign-ins from specific IP ranges; an attacker from those IPs could still attempt MFA prompts or bypass them.

37
MCQeasy

An administrator wants to add a custom domain 'contoso.com' to a new Microsoft 365 tenant. The domain is already registered and available. What is the first step the administrator should perform in the Microsoft 365 admin center?

A.Add the domain and verify ownership by creating a TXT record
B.Create user accounts with the new domain
C.Configure email routing with MX records
D.Set up SharePoint Online with the new domain
AnswerA

Adding the domain and proving ownership via a TXT record is the mandatory first step; Microsoft 365 cannot create mail-enabled objects or DNS-dependent services until the tenant confirms the administrator controls contoso.com. Verification must precede any user, mailbox or DNS configuration.

Why this answer

The first step when adding a custom domain to a Microsoft 365 tenant is to add the domain in the admin center and then verify ownership by creating a TXT record in the domain's DNS zone. This proves you control the domain before any services (like email or SharePoint) can be configured. Without verification, Microsoft 365 will not allow further domain-related setup.

Exam trap

The trap here is that candidates may think MX record configuration is the first step because they associate domains primarily with email, but Microsoft 365 requires ownership verification via TXT record before any service-specific DNS changes are allowed.

How to eliminate wrong answers

Option B is wrong because user accounts cannot be created with the new domain until the domain is verified; attempting to do so will fail. Option C is wrong because configuring email routing with MX records is a later step that requires the domain to be verified first. Option D is wrong because setting up SharePoint Online with the new domain also depends on prior domain verification and is not the initial step.

38
MCQhard

Your organization is implementing Microsoft Purview Data Loss Prevention (DLP) policies to protect sensitive data in Microsoft Teams. You need to ensure that DLP policies apply to both chat and channel messages. What should you configure?

A.Configure a DLP policy for Exchange Online to cover Teams messages.
B.Assign a sensitivity label to the Teams with a DLP policy attached.
C.Create two separate DLP policies: one for chat and one for channels.
D.Create a single DLP policy with the Teams location selected.
AnswerD

Creating a single DLP policy and selecting the Teams location is the correct approach because that location applies to all Teams messages, including 1:1 chats, group chats, and messages or conversations in standard and private channels. The policy will evaluate content in real time and can block or report violations consistently across every Teams conversation surface. This one selection removes the need for any separate policies for chat or channel content.

Why this answer

Microsoft Purview DLP policies can be configured to include the Teams location, which automatically covers both chat and channel messages. When you select the Teams location in a single DLP policy, it applies to all Teams communications, including 1:1 chats, group chats, and channel conversations, without needing separate policies.

Exam trap

The trap here is that candidates often think chat and channel messages require separate DLP policies due to their different storage locations, but Microsoft Purview abstracts this complexity by allowing a single Teams location selection that covers both.

How to eliminate wrong answers

Option A is wrong because Exchange Online DLP policies only cover email and Teams messages that are stored in Exchange mailboxes (e.g., chat messages), but they do not cover channel messages, which are stored in SharePoint and OneDrive. Option B is wrong because sensitivity labels can be used to classify and protect content, but they are not directly attached to DLP policies; DLP policies can use sensitivity labels as conditions, but assigning a label to a team does not enforce DLP. Option C is wrong because creating two separate DLP policies for chat and channels is unnecessary and inefficient; a single DLP policy with the Teams location selected covers both chat and channel messages automatically.

39
MCQhard

Your organization has a hybrid identity with Microsoft Entra Connect. You need to migrate from federation to password hash synchronization with seamless single sign-on (SSO). The migration must have minimal user impact. Which tool should you use?

A.Microsoft Entra Connect migration tool (Convert domain from federated to managed)
B.IdFix tool
C.AD FS Management console
D.Azure AD Connect wizard
AnswerA

The Microsoft Entra Connect migration tool's 'Convert domain from federated to managed' function is the purpose-built operation to switch a domain's sign-in method from federation to cloud authentication. It performs the conversion with minimal user impact because it updates the domain's authentication type in Microsoft Entra ID while leaving users and directory objects in place. During the process, it can use staged rollback or gradual deployment, ensuring that any authentication failures can be addressed without locking all users out. This makes it the correct choice for decommissioning AD FS.

Why this answer

The Microsoft Entra Connect migration tool (Convert domain from federated to managed) is the correct choice because it automates the conversion of federated domains to managed domains while enabling password hash synchronization (PHS) and seamless SSO. This tool minimizes user impact by allowing a staged migration where users can continue authenticating via federation until the conversion is complete, and it handles the necessary configuration changes in Azure AD and on-premises Active Directory.

Exam trap

The trap here is that candidates may confuse the Azure AD Connect wizard (which can enable PHS) with the dedicated migration tool, not realizing that the wizard lacks the specific domain conversion and staged rollback capabilities needed for a low-impact migration from federation.

How to eliminate wrong answers

Option B is wrong because IdFix is a data cleanup tool for synchronizing on-premises Active Directory objects to Azure AD, not a tool for converting authentication methods from federation to PHS. Option C is wrong because the AD FS Management console is used to manage and configure AD FS servers and trusts, not to convert a federated domain to managed authentication in Azure AD. Option D is wrong because the Azure AD Connect wizard (now Microsoft Entra Connect wizard) is used for initial setup and configuration of synchronization, including enabling PHS, but it does not provide a dedicated migration path from federation to managed domains with minimal user impact; the separate migration tool is designed specifically for that purpose.

40
MCQeasy

A company has recently acquired a smaller organization and needs to consolidate both Microsoft 365 tenants. They want to minimize user disruption and retain existing email addresses. Which approach should they use?

A.Configure a hybrid deployment with Exchange Server
B.Perform a cross-tenant mailbox migration
C.Delete all users from the acquired tenant and recreate them in the parent tenant
D.Set up a federation trust between the tenants
AnswerB

Cross-tenant mailbox migration is the correct approach because it uses the Cross-Tenant migration API or Enable-CrossTenantMailboxMigration cmdlets to move mailbox content, settings, and sometimes Office 365 groups between two AAD tenants. This process preserves the mailbox's ExchangeGuid, is silent to end users, and allows for redirection of the primary SMTP address so email continues to arrive without interruption. It is the only option that both consolidates data and retains user identity while minimizing disruption.

Why this answer

Cross-tenant mailbox migration allows you to move mailboxes between two Microsoft 365 tenants while preserving the users' existing email addresses and minimizing disruption. This approach uses the Microsoft 365 native migration capabilities, specifically the cross-tenant mailbox migration feature, which supports moving mailboxes with their primary SMTP addresses and associated data without requiring on-premises Exchange Server.

Exam trap

The trap here is that candidates often confuse cross-tenant mailbox migration with federation trust or hybrid deployment, assuming that any inter-tenant connectivity solution can consolidate mailboxes, but only the cross-tenant migration feature directly moves mailbox data while preserving email addresses.

How to eliminate wrong answers

Option A is wrong because configuring a hybrid deployment with Exchange Server is unnecessary and adds complexity; it is designed for integrating on-premises Exchange with a single tenant, not for migrating mailboxes between two separate Microsoft 365 tenants. Option C is wrong because deleting all users from the acquired tenant and recreating them in the parent tenant would cause significant user disruption, loss of mailbox data, and require new email addresses unless manually reassigned, which contradicts the goal of minimizing disruption and retaining existing email addresses. Option D is wrong because setting up a federation trust between tenants enables authentication and sharing features but does not migrate mailboxes or consolidate tenants; it is used for cross-tenant collaboration, not for moving user data.

41
Multi-Selectmedium

As a Microsoft 365 administrator, you need to manage tenant health and adoption effectively. Which three of the following tools or features should you use to monitor and improve your Microsoft 365 tenant's performance and user engagement? (Choose three.)

Select 3 answers
.Microsoft 365 admin center dashboard to view service health, message center posts, and usage reports.
.Microsoft 365 usage analytics in Power BI to gain deeper insights into adoption trends.
.Azure AD Identity Protection to detect sign-in risks and block compromised accounts.
.Microsoft 365 network connectivity test tool to evaluate network performance for Microsoft 365 services.
.Microsoft 365 Adoption Score (formerly Productivity Score) to track user engagement with Microsoft 365 apps.
.Microsoft Purview compliance portal to enforce data loss prevention policies.

Why this answer

The Microsoft 365 admin center dashboard provides a centralized view of service health, message center posts, and usage reports, enabling administrators to monitor service availability, planned changes, and user activity. This is a core tool for maintaining tenant health and tracking adoption.

Exam trap

The trap here is that candidates may confuse security or compliance tools (like Azure AD Identity Protection or Purview) with health and adoption monitoring tools, or select the network connectivity test tool thinking it measures overall tenant performance rather than just network latency.

42
MCQmedium

You are a Microsoft 365 administrator. You need to allow external users to access a SharePoint Online site without requiring them to sign in. Which sharing setting should you enable?

A.Set the sharing option to 'Existing guests' and send an invitation.
B.Set the sharing option to 'Only people in your organization' and use a direct link.
C.Set the sharing option to 'New and existing guests' and require guest sign-in.
D.Set the sharing option to 'Anyone' (Anonymous) for the site.
AnswerD

The 'Anyone' (Anonymous) sharing link allows anyone who has the link to access the site or item without being required to sign in as a guest or internal user. This link type is the only option that permits external access with no authentication, exactly matching the stated business requirement. Because these links are the most permissive, they should be used with caution and ideally paired with expiration dates and password protection.

Why this answer

Setting the SharePoint Online site sharing option to 'Anyone' (Anonymous) allows external users to access the site without signing in. This creates an anonymous access link that bypasses authentication, meeting the requirement of no sign-in for external users.

Exam trap

The trap here is that candidates often confuse 'Anyone' (anonymous) sharing with guest sharing options, mistakenly thinking that 'New and existing guests' allows anonymous access, but it actually requires sign-in for all external users.

How to eliminate wrong answers

Option A is wrong because 'Existing guests' requires recipients to have a guest account and sign in, which contradicts the 'without requiring them to sign in' requirement. Option B is wrong because 'Only people in your organization' restricts access to internal users only, blocking external users entirely. Option C is wrong because 'New and existing guests' requires all external users to sign in with a Microsoft account or Azure AD guest identity, which does not meet the no-sign-in condition.

43
Multi-Selecthard

Which TWO settings must be configured to set up a hybrid identity deployment using password hash synchronization?

Select 2 answers
A.Install and configure Microsoft Entra Connect.
B.Configure Seamless Single Sign-On (SSO).
C.Enable password hash synchronization in Entra Connect.
D.Deploy Active Directory Federation Services (AD FS).
E.Configure Pass-Through Authentication.
AnswersA, C

Microsoft Entra Connect provides the sync engine that hashes on-premises Active Directory passwords and writes the resulting hash to Microsoft Entra ID, which is the mechanism password hash synchronization depends on. Without this component, no directory objects or password hashes reach the cloud tenant.

Why this answer

Option A is correct because Microsoft Entra Connect is the required synchronization tool that connects your on-premises Active Directory to Microsoft Entra ID and provides the wizard where directory synchronization and sign-in methods are configured. Option C is correct because password hash synchronization is a sign-in method that must be explicitly enabled in Entra Connect (on the "User sign-in" page, select "Password Hash Synchronization") for the hybrid identity deployment to work as described. Option B is not required because Seamless SSO is an optional feature that can be enabled alongside password hash synchronization but is not necessary to set up the deployment itself.

Option D is incorrect because AD FS is a separate federated authentication method, not part of a password hash synchronization deployment. Option E is incorrect because Pass-Through Authentication is an alternative sign-in method that validates passwords directly against on-premises AD and is mutually exclusive with password hash synchronization as the primary sign-in method.

Exam trap

The trap here is that candidates often include Seamless SSO as a required component for password hash synchronization, when in fact it is optional. The minimal requirements for PHS are simply installing Entra Connect and enabling the PHS feature. SSO enhances the user experience but is not necessary for the synchronization of password hashes.

44
MCQeasy

A company recently added the custom domain 'contoso.com' to their Microsoft 365 tenant. Users report that they cannot receive external email sent to their new domain addresses. The administrator confirmed that the domain status shows 'Active' in the Microsoft 365 admin center. What is the most likely cause of this issue?

A.The domain was not verified with a TXT record.
B.The MX record for the domain is missing or points to an incorrect mail server.
C.The SPF record for the domain is missing or incorrectly configured.
D.The custom domain was not added to the user's primary email address.
AnswerB

The MX record is the authoritative DNS resource that specifies the mail exchanger for a domain. When an external sender tries to deliver to contoso.com, their mail server queries DNS for the MX record to discover which host accepts inbound messages. If this record is absent or points to an incorrect mail server, delivery to Exchange Online cannot occur, causing non-delivery reports or messages routed to the wrong destination. Microsoft 365 requires the MX record to point to contoso-com.mail.protection.outlook.com with the correct priority.

Why this answer

The domain status 'Active' in the Microsoft 365 admin center indicates that the domain has been successfully verified and added to the tenant. However, for external email to be delivered to users at that domain, the public MX record in DNS must point to Microsoft 365's mail servers (e.g., contoso-com.mail.protection.outlook.com). If the MX record is missing or points to an incorrect server, external senders cannot route email to the tenant, even though the domain is verified and active.

Exam trap

The trap here is that candidates see 'Active' domain status and assume all DNS configurations are correct, but Microsoft 365 separates domain verification (TXT record) from mail routing (MX record), so a verified domain can be 'Active' yet still unreachable for inbound email if the MX record is misconfigured.

How to eliminate wrong answers

Option A is wrong because the domain status shows 'Active', which means the TXT verification record was successfully validated; a missing TXT record would prevent the domain from reaching 'Active' status. Option C is wrong because an SPF record affects sender authentication and deliverability of outbound email, but does not prevent inbound email from being received; missing or incorrect SPF would not block external email from arriving at the mailbox. Option D is wrong because adding the custom domain to a user's primary email address is a separate step that affects the user's email address format, but even if not yet assigned, the domain can still receive email for any alias or accepted domain; the core issue is DNS routing, not user assignment.

45
MCQeasy

A company plans to migrate their email from an on-premises Exchange server to Exchange Online. They want to ensure that during the migration, mail sent to users who have already been migrated is delivered to Exchange Online, while mail for non-migrated users is delivered to on-premises. Which type of domain configuration should they use?

A.Coexistence domain
B.Shared domain
C.Split domain
D.Forwarding domain
AnswerC

Split domain (also called shared SMTP address space) is the correct configuration when a single accepted domain has mailboxes both on-premises and in Exchange Online, as in this migration scenario. In an Exchange hybrid deployment, you configure the on-premises organization and Exchange Online to recognize the same domain as authoritative, and then create a send connector and a receiving connector (or use the Hybrid Configuration Wizard) to route messages based on the mailbox location. This allows mail for recipients with the same domain suffix to be delivered correctly to either environment, which is exactly the requirement when migrating mailboxes from on-premises to the cloud.

Why this answer

A split domain configuration is required when some mailboxes reside on-premises and others in Exchange Online during a migration. It uses MX records pointing to Exchange Online Protection (EOP) and internal mail flow connectors to route messages for migrated users to Exchange Online and non-migrated users to on-premises, ensuring each mailbox receives mail at its current location.

Exam trap

The trap here is that candidates confuse 'split domain' with 'hybrid deployment' or 'coexistence,' but the question specifically asks for the domain configuration type, not the overall migration method; Microsoft often tests the exact terminology for mail flow scenarios during phased migrations.

How to eliminate wrong answers

Option A is wrong because a coexistence domain is not a standard Exchange domain type; coexistence is a state achieved through hybrid configuration, not a specific domain configuration. Option B is wrong because a shared domain is not a recognized Exchange domain configuration; it might be confused with a shared mailbox or shared namespace, but it does not describe the routing logic needed for a phased migration. Option D is wrong because a forwarding domain is not a valid Exchange domain type; forwarding is a mailbox-level or transport rule action, not a domain-level configuration for split mail flow.

46
MCQeasy

You need to ensure that only users from your organization's on-premises Active Directory can access Microsoft 365 services. You have Microsoft Entra Connect configured. What is the simplest way to prevent cloud-only user accounts from signing in?

A.Configure a conditional access policy that blocks all users.
B.Delete the cloud-only users from Microsoft Entra ID.
C.Set the 'Block sign in' option to 'Yes' for all cloud-only users in the Microsoft Entra admin center.
D.Remove all licenses from cloud-only users.
AnswerC

Setting 'Block sign in' to Yes in Microsoft Entra ID directly prevents cloud-only accounts from authenticating, satisfying the requirement that only on-premises Active Directory users access Microsoft 365. Because Microsoft Entra Connect already synchronises those on-premises identities, blocking the cloud-only accounts leaves synced users unaffected, and it is the simplest per-account control available.

Why this answer

Setting the 'Block sign in' option to 'Yes' for cloud-only users in the Microsoft Entra admin center directly prevents those accounts from signing in without deleting them or affecting licensed users. This is the simplest and most targeted method. It does not require conditional access policies or license changes.

Exam trap

MS-102 often tests the difference between blocking sign-in for specific users versus conditional access policies; candidates may incorrectly choose a broad conditional access policy that blocks all users.

How to eliminate wrong answers

Option A is wrong because a conditional access policy that blocks all users would also block on-premises synchronized users, which is not the goal. Option B is wrong because deleting cloud-only users is destructive and may cause data loss; it is not the simplest or recommended approach. Option D is wrong because removing licenses does not prevent sign-in; users can still sign in to services that do not require a license, and it may cause unintended service disruptions.

47
MCQeasy

You need to configure Microsoft Teams to allow external access for federation with another organization. The other organization uses a different domain. Which setting must you enable in the Teams admin center?

A.Network roaming policy for the external users.
B.Guest access in Teams settings.
C.Emergency calling policies.
D.External access with the domain of the other organization.
AnswerD

External access (federation) is the correct mechanism to let users in your organization communicate with users from a different organization in Teams. In the Teams admin center, under External access, you can allow federation globally or restrict it to specific domains by adding the other organization's domain to the allowed list. This setting enables chat and calls between your users and those in the external tenant, while keeping each user in their own organization's identity.

Why this answer

To enable federation with another organization that uses a different domain, you must configure External access (also known as federation) in the Teams admin center. Specifically, you need to add the external domain to the allowed domain list under Teams > External access. This allows users in your tenant to communicate with users in the other organization via Teams, using the Session Initiation Protocol (SIP) federation protocol.

Exam trap

The trap here is that candidates often confuse Guest access (Azure AD B2B) with External access (federation), leading them to select Option B, but Guest access is for individual external users, not for domain-level federation with another organization.

How to eliminate wrong answers

Option A is wrong because Network roaming policy controls network configuration settings (such as bandwidth and IP ranges) for users when they are on different networks; it does not control cross-tenant federation. Option B is wrong because Guest access is for inviting external users as guests within your tenant (using Azure AD B2B), not for federating with another organization's entire domain. Option C is wrong because Emergency calling policies define how emergency calls (e.g., to 911) are handled and are unrelated to external federation settings.

48
Multi-Selectmedium

Which TWO actions are required to configure a custom domain for your Microsoft 365 tenant?

Select 2 answers
A.Add an SPF TXT record in the public DNS zone.
B.Add a CNAME record for autodiscover.
C.Add an MX record in the public DNS zone.
D.Add the domain name in the Microsoft 365 admin center.
E.Verify domain ownership by adding a TXT record provided by Microsoft.
AnswersD, E

The first required action is to register the domain with your tenant by navigating to Settings > Domains > Add domain and typing the fully qualified domain name, such as contoso.com. This initiates the Microsoft 365 domain provisioning workflow, enabling you to confirm that you are not using a domain already claimed by another tenant and to receive the verification token. Without this admin-center entry, no verification or DNS setup can proceed.

Why this answer

Adding the custom domain name in the Microsoft 365 admin center is the first step to register the domain with the tenant. Option E is correct because Microsoft requires you to prove ownership of the domain by adding a specific TXT record (or sometimes a CNAME or MX record) to the public DNS zone; this verification step ensures only the domain owner can configure it for the tenant.

Exam trap

The trap here is that candidates often confuse optional service-specific DNS records (like SPF, MX, or autodiscover CNAME) with the mandatory domain ownership verification record, leading them to select A, B, or C instead of the correct verification TXT record option.

49
MCQeasy

Your organization wants to use Microsoft Defender for Office 365 to protect against malicious links and attachments in email. Which Defender plan is required?

A.Microsoft Defender for Office 365 Plan 1.
B.Exchange Online Protection.
C.Microsoft Defender for Endpoint.
D.Microsoft Defender for Office 365 Plan 2.
AnswerA

Microsoft Defender for Office 365 Plan 1 is correct because it includes Safe Attachments and Safe Links, which are the core advanced email protection features. Safe Attachments detonates email attachments in a sandbox to detect malicious behavior, while Safe Links checks URLs at click time against real-time reputation data. Plan 1 also includes enhanced anti-phishing policies and anti-spam capabilities beyond the baseline EOP layer. This makes Plan 1 the minimum license that fulfills the organization's requirement to use Defender for Office 365 for email protection.

Why this answer

Microsoft Defender for Office 365 Plan 1 includes Safe Links and Safe Attachments, which are the specific features required to protect against malicious links and attachments in email. These features scan URLs and attachments in real time to block malicious content before it reaches users.

Exam trap

The trap here is that candidates often assume Plan 2 is required for any advanced protection, but Microsoft specifically designed Plan 1 to cover Safe Links and Safe Attachments, while Plan 2 adds post-breach investigation and automation features.

How to eliminate wrong answers

Option B is wrong because Exchange Online Protection (EOP) provides baseline anti-malware and anti-spam protection but does not include Safe Links or Safe Attachments, which are the advanced protections needed for malicious links and attachments. Option C is wrong because Microsoft Defender for Endpoint is designed to protect devices (endpoints) from threats, not to scan email links and attachments within Microsoft 365. Option D is wrong because Microsoft Defender for Office 365 Plan 2 includes all features of Plan 1 plus additional capabilities like threat investigation and automated response, but Plan 1 alone is sufficient for the stated requirement of protecting against malicious links and attachments.

50
MCQeasy

An administrator wants to configure the company's organization profile in Microsoft 365, including the display name, technical contact, and privacy settings. Where should the administrator go in the Microsoft 365 admin center?

A.User management > Active users
B.Org settings > Organization profile
C.Setup > Onboarding
D.Billing > Licenses
AnswerB

Org settings > Organization profile is the dedicated location in the Microsoft 365 admin center for configurating the identity of the organization itself, not individual users. Here you can edit the organization display name, address, technical contact, privacy contact, and release preferences, and these values are used across Microsoft 365 services such as Teams, Exchange, and compliance. As the central repository for these tenant-level attributes, this page satisfies the requirement to configure the company's organization profile.

Why this answer

The organization profile, which includes the display name, technical contact, and privacy settings, is managed under 'Org settings' in the Microsoft 365 admin center. Specifically, the 'Organization profile' tab within 'Org settings' provides the interface to update these tenant-wide properties, such as the organization's display name (used in Microsoft 365 services and notifications) and the technical contact email (used for service communications). This is the correct location because these settings are tenant-level configurations, not user-specific or billing-related.

Exam trap

The trap here is that candidates often confuse 'Org settings' with 'Setup' or 'User management', mistakenly thinking that tenant-wide profile settings are part of user management or initial onboarding wizards, when in fact they are a distinct configuration area under 'Org settings'.

How to eliminate wrong answers

Option A is wrong because 'User management > Active users' is for managing individual user accounts, passwords, and licenses, not tenant-wide organization profile settings like the display name or technical contact. Option C is wrong because 'Setup > Onboarding' provides guided wizards for initial tenant setup and migration tasks, but does not include the organization profile settings; those are under 'Org settings'. Option D is wrong because 'Billing > Licenses' is for managing subscription licenses and billing details, not for configuring the organization's display name, technical contact, or privacy settings.

51
MCQmedium

Your organization's Microsoft Intune environment enforces device compliance policies for iOS devices. You need to ensure that only devices with a passcode that is at least 6 characters and have jailbreak detection enabled are considered compliant. What should you configure?

A.Configure a conditional access policy to require compliant devices.
B.Create a device configuration profile for iOS with the required settings.
C.Create an app protection policy for iOS to require passcode.
D.Create a device compliance policy for iOS with required passcode length and jailbreak detection.
AnswerD

A device compliance policy in Microsoft Intune is specifically designed to define the rules and settings that devices must meet to be considered compliant. By configuring passcode length and jailbreak detection for iOS, the policy evaluates these conditions and reports a compliant or noncompliant status. This compliance state can then be consumed by conditional access policies to enforce access controls. Therefore, this is the correct mechanism to define the required security conditions.

Why this answer

Device compliance policies in Microsoft Intune define the rules that devices must meet to be considered compliant, such as minimum OS version, passcode length, and jailbreak detection. Option D correctly specifies creating a compliance policy for iOS that requires a passcode of at least 6 characters and enables jailbreak detection, which directly enforces the stated requirements. Compliance policies are evaluated before granting access, and non-compliant devices can be blocked or marked for remediation.

Exam trap

The trap here is that candidates often confuse device compliance policies (which enforce device-level security requirements) with conditional access policies (which use compliance results to control access) or device configuration profiles (which push settings but do not evaluate compliance).

How to eliminate wrong answers

Option A is wrong because a conditional access policy requires compliant devices but does not define the compliance rules themselves; it references an existing compliance policy. Option B is wrong because a device configuration profile manages device settings (e.g., Wi-Fi, VPN, restrictions) but does not enforce compliance checks like passcode length or jailbreak detection. Option C is wrong because an app protection policy manages data protection at the app level (e.g., requiring a PIN for app access) and does not evaluate device-level compliance attributes such as jailbreak status or system passcode length.

52
Multi-Selectmedium

Your organization has a Microsoft 365 E5 tenant with Microsoft Defender for Cloud Apps. You need to discover and control the use of unsanctioned cloud apps. Which TWO actions should you take? (Choose two.)

Select 2 answers
A.Define sanctioned and unsanctioned app categories in Microsoft Defender for Cloud Apps
B.Deploy Microsoft Purview Data Loss Prevention policies
C.Configure Microsoft Entra ID App Registrations to log app usage
D.Use Cloud Discovery in Microsoft Defender for Cloud Apps to analyze traffic logs
E.Create a Conditional Access policy to block all unsanctioned apps
AnswersA, D

Sanctioned and unsanctioned app tags let Defender for Cloud Apps apply governance actions such as blocking or unsanctioning, converting discovery data into enforcement. Without these categories, discovered apps cannot be controlled, which the scenario explicitly requires.

Why this answer

Option D is correct because Cloud Discovery in Microsoft Defender for Cloud Apps is the feature that ingests and analyzes traffic logs (from firewalls, proxies, or Defender for Endpoint) to identify which cloud apps are being used in the organization, which is the required first step for discovering unsanctioned apps. Option A is correct because after discovery, you use the app catalog to tag apps as Sanctioned or Unsanctioned (and assign categories/risk scores), which is how Defender for Cloud Apps enforces the governance decision and drives downstream controls like blocking or alerting. Option B is not correct because Microsoft Purview DLP policies protect sensitive data in sanctioned workloads; they do not discover or sanction/unsanction cloud apps.

Option C is not correct because Entra ID App Registrations are for registering and permissioning your own applications with the identity platform, not for logging or discovering third-party cloud app usage. Option E is not correct because Conditional Access cannot target 'all unsanctioned apps' generically; enforcement against unsanctioned apps is done via Defender for Cloud Apps app governance and Conditional Access App Control (session/access policies) after apps are tagged, not by a blanket CA policy.

Exam trap

The trap here is that candidates often confuse Conditional Access policies with the ability to block unsanctioned apps, but Conditional Access requires the app to be registered in Entra ID and cannot discover or block apps that are not already known to the tenant.

53
MCQeasy

Your company is implementing Microsoft 365 Copilot for Microsoft 365. You need to ensure that Copilot can access data from across the organization, but only for users who have the appropriate permissions. What is the primary security boundary for Copilot data access?

A.Microsoft 365 permissions and sensitivity labels
B.A dedicated Copilot security group in Microsoft Entra ID
C.Microsoft Purview Information Protection labels
D.The geographic location of the data
AnswerA

Copilot honours the signed-in user's existing Microsoft 365 permissions and sensitivity labels, so it only surfaces content that user can already access. This permission-trimming model is the primary boundary, ensuring no oversharing occurs beyond each user's granted entitlements.

Why this answer

Microsoft 365 Copilot respects the existing Microsoft 365 permissions and sensitivity labels as its primary security boundary. Copilot only surfaces data that the signed-in user already has permission to access, and sensitivity labels govern how that data can be used or shared. This means Copilot inherits the tenant's existing security model rather than introducing a separate one.

Exam trap

MS-102 often tests the misconception that Copilot requires a new security group or that Purview labels alone define access — the correct answer is that Copilot inherits existing Microsoft 365 permissions and sensitivity labels.

How to eliminate wrong answers

Option B is wrong because there is no dedicated Copilot security group in Microsoft Entra ID that acts as the data-access boundary — Copilot uses the user's existing Microsoft 365 permissions. Option C is wrong because Microsoft Purview Information Protection labels are a subset of the broader permissions and sensitivity label model; they are not the primary boundary by themselves, and the question asks for the primary boundary which includes Microsoft 365 permissions. Option D is wrong because geographic location of data affects data residency and compliance, not the per-user access boundary that Copilot enforces.

54
MCQhard

Refer to the exhibit. You are reviewing an app registration in Microsoft Entra ID for the Microsoft Teams Admin Center. The permission shown is for another resource. What is the consequence of this permission configuration?

A.The app can access Microsoft Graph data without a signed-in user, and admin consent is required
B.The app can only be used by users who have consented to the permission
C.The app can access Teams data but not other Microsoft 365 data
D.The app can access Microsoft Graph on behalf of the signed-in user only
AnswerA

Application permissions (indicated by the Role type) allow the app to authenticate as its own identity, not any user, and call Microsoft Graph for tenant-wide data such as Exchange mail or Teams resources. Because these permissions are not restricted to a single user, AAD requires a tenant administrator to grant consent, effectively pre-approving the app for the entire organization, and each such permission exposes broad, high-privilege capabilities that should be vetted carefully.

Why this answer

The exhibit shows an application permission (not a delegated permission) for Microsoft Graph, which means the app can access data without a signed-in user. Admin consent is required because application permissions grant tenant-wide access and cannot be consented to by individual users. This is why option A is correct.

Exam trap

Microsoft often tests the distinction between delegated permissions (requiring user consent and acting on behalf of a user) and application permissions (requiring admin consent and acting without a user), and the trap here is that candidates may confuse the 'signed-in user' requirement with delegated permissions, incorrectly assuming the app needs user consent or can only run with a user present.

How to eliminate wrong answers

Option B is wrong because application permissions do not require per-user consent; they require tenant-wide admin consent, and the app can be used by any user once admin consent is granted. Option C is wrong because the permission is for Microsoft Graph, which provides access to a broad range of Microsoft 365 data beyond just Teams, including Exchange, SharePoint, and more. Option D is wrong because application permissions are not delegated; they allow the app to act as itself without any signed-in user context, unlike delegated permissions which operate on behalf of the signed-in user.

55
Multi-Selecthard

Which THREE conditions must be met for a tenant-to-tenant migration of SharePoint Online content?

Select 3 answers
A.The destination site collection or OneDrive must already exist in the target tenant.
B.Cross-tenant trust must be established or a third-party migration tool must be used.
C.The source user performing the migration must be a global admin in the target tenant.
D.The target tenant must have an active Microsoft 365 subscription.
E.Both tenants must have at least one user with PowerShell access.
AnswersA, B, D

The destination site collection or OneDrive container must be provisioned and exist in the target tenant before the migration runs. Content is copied into an existing container; neither SharePoint nor OneDrive migration creates the target site automatically. For OneDrive, the destination user must have a licensed OneDrive site, and for SharePoint the target site collection must already be created in the appropriate location.

Why this answer

SharePoint Online tenant-to-tenant migration requires the destination site collection or OneDrive to already exist in the target tenant. The migration process copies content into a pre-provisioned container; it does not create the site or OneDrive automatically. This ensures that the target structure is ready to receive the migrated data without requiring dynamic provisioning during the migration.

Exam trap

The trap here is that candidates often assume global admin privileges are required across both tenants for migration, but in reality, SharePoint admin or site collection admin permissions suffice, and PowerShell access is not a prerequisite.

56
MCQhard

You manage a Microsoft 365 tenant for a multinational corporation. You need to implement Microsoft Purview Information Protection to automatically classify and protect documents containing credit card numbers. The solution must apply encryption automatically when a document is saved to SharePoint Online. What should you do?

A.Create an auto-labeling policy in Microsoft Purview that uses a sensitivity label configured with encryption.
B.Create a DLP policy in Microsoft Purview that blocks sharing of documents containing credit card numbers.
C.Configure client-side labeling via Microsoft 365 Apps to prompt users to label documents.
D.Set a default sensitivity label for SharePoint Online document libraries.
AnswerA

Auto-labelling policies scan SharePoint Online content and apply sensitivity labels automatically, satisfying the requirement that encryption be applied on save. The label's encryption setting enforces protection, while the policy's condition detects credit card numbers via a sensitive info type, removing any need for manual user action.

Why this answer

To automatically classify and protect documents containing credit card numbers with encryption when saved to SharePoint Online, you should create an auto-labeling policy in Microsoft Purview that uses a sensitivity label configured with encryption. Auto-labeling policies can detect sensitive information types (e.g., credit card numbers) and automatically apply the label, which enforces encryption.

Exam trap

MS-102 often tests the confusion between DLP policies (which block actions) and auto-labeling policies (which classify and protect), leading candidates to choose DLP when encryption is required.

How to eliminate wrong answers

Option B is wrong because a DLP policy blocks sharing but does not apply encryption or classification; it only prevents certain actions. Option C is wrong because client-side labeling prompts users to label manually, which is not automatic and relies on user action. Option D is wrong because setting a default sensitivity label for SharePoint document libraries applies the label to all documents in the library, not based on content, and may not enforce encryption for specific sensitive data.

57
MCQhard

You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a Microsoft Entra tenant with 10,000 users. You need to ensure that when users sign in to Microsoft 365 from unmanaged devices, they are required to use multi-factor authentication (MFA) and cannot download files from SharePoint Online. Users on managed devices should not be prompted for MFA and should be able to download files. What should you configure?

A.Create a conditional access policy that targets all users and SharePoint Online, set the device state condition to 'Include: Unmanaged', and grant access with 'Require multifactor authentication' and 'Require device to be marked as compliant'.
B.Create a conditional access policy that targets all users and SharePoint Online, set the device state condition to 'Exclude: Unmanaged', and grant access with 'Require multifactor authentication' and 'Require app enforced restrictions'.
C.Create a conditional access policy that targets all users and SharePoint Online, set the device state condition to 'Include: Unmanaged', and grant access with 'Require device to be marked as compliant' and 'Require app enforced restrictions'.
D.Create a conditional access policy that targets all users and SharePoint Online, set the device state condition to 'Include: Unmanaged', and grant access with 'Require multifactor authentication' and 'Require app enforced restrictions'.
AnswerD

This policy applies to unmanaged devices and requires MFA while enabling app enforced restrictions. App enforced restrictions allow SharePoint Online to provide limited access, such as blocking downloads, on unmanaged devices. This meets the requirement for MFA and no downloads on unmanaged devices.

Why this answer

A conditional access policy targeting unmanaged devices with MFA and app enforced restrictions ensures that users on unmanaged devices must use MFA and are subject to restrictions that prevent downloads from SharePoint Online. Managed devices are not targeted by this policy, so they are not prompted for MFA and can download files.

Exam trap

The trap here is confusing app enforced restrictions with device compliance, or incorrectly excluding unmanaged devices when the policy should target them.

58
MCQhard

Your Microsoft 365 tenant contains sensitive financial data that must be retained for 7 years. You configure a retention policy in Microsoft Purview compliance portal. After 7 years, the data is still accessible to users. What is the most likely reason?

A.The retention policy does not include a deletion action.
B.A litigation hold is applied to the data.
C.The retention policy is configured to retain data for 7 years and then delete it.
D.The data is marked as a record and requires disposition review.
AnswerA

A retention policy without a deletion action is configured to only retain content for a specified period. In Microsoft 365, when a policy has only a retention action (no 'Delete items automatically' option selected), items remain indefinitely after the retention period expires. Because the policy never schedules a purge, the sensitive data persists in the tenant even after the retention timeframe elapses. This directly matches the scenario in the question.

Why this answer

A retention policy in Microsoft Purview can be configured to only retain data without a deletion action. If the policy lacks a deletion action, data will be preserved for the specified period but will not be automatically removed after that period expires, leaving it accessible to users. The scenario describes data still being accessible after 7 years, which directly indicates that no deletion action was configured to remove the data at the end of the retention period.

Exam trap

The trap here is that candidates often assume a retention policy automatically deletes data after the retention period ends, but Microsoft Purview requires an explicit deletion action to be configured for automatic removal; otherwise, the data is retained indefinitely.

How to eliminate wrong answers

Option B is wrong because a litigation hold preserves data indefinitely and prevents deletion, but it does not cause data to remain accessible after a retention period ends if the retention policy itself lacks a deletion action; the hold would keep the data, but the core issue is the missing deletion action. Option C is wrong because if the retention policy were configured to retain data for 7 years and then delete it, the data would be automatically removed after 7 years and would not remain accessible to users. Option D is wrong because marking data as a record and requiring disposition review means the data must be manually reviewed and approved before deletion, but this does not automatically keep the data accessible after the retention period; disposition review can delay deletion but does not explain why data remains accessible without any deletion action.

59
MCQeasy

You need to ensure that only users from your organization can access a SharePoint Online site. Which setting should you configure?

A.Set the SharePoint Online external sharing setting to 'Only people in your organization'
B.Create a Conditional Access policy to block external users
C.Configure the Microsoft Entra ID external collaboration settings
D.Modify the site permissions to remove external users
AnswerA

Setting the SharePoint Online external sharing option to 'Only people in your organization' disables all tenant-level external sharing, preventing internal users from creating external sharing links and removing access for any external users via existing links. This tenant-wide setting overrides site-level configurations and is the only way to proactively guarantee that only authenticated users within your Microsoft Entra ID can access sites. This restriction is enforced at the SharePoint service level, so it covers all sites, including those previously configured to allow external access.

Why this answer

The SharePoint Online external sharing setting 'Only people in your organization' explicitly restricts all sharing and access to users who have a valid identity in your Microsoft Entra ID tenant. This setting prevents any external user (including guests) from accessing the site, regardless of how they were invited or authenticated. It is the most direct and effective control for limiting access to internal users only.

Exam trap

The trap here is that candidates often confuse tenant-level external collaboration settings (Microsoft Entra ID) with site-level external sharing settings (SharePoint Online), assuming that blocking external users in Entra ID automatically restricts access to SharePoint sites, which is not the case because SharePoint has its own independent sharing controls.

How to eliminate wrong answers

Option B is wrong because a Conditional Access policy can block external users from signing in, but it does not prevent external users who are already guests from accessing the site if they have been granted permissions through sharing. Option C is wrong because configuring the Microsoft Entra ID external collaboration settings controls the overall guest invitation behavior for the tenant, but it does not override the per-site external sharing setting; a site could still be shared externally if its own sharing setting allows it. Option D is wrong because modifying site permissions to remove external users is a manual, reactive approach that does not prevent future external sharing or access; it does not enforce a policy that blocks external users from being added or accessing the site.

60
MCQeasy

A new employee has been hired and their account already exists in the on-premises Active Directory. The administrator needs to provide the employee with access to Microsoft 365 services as quickly as possible. What is the most efficient way to enable the user?

A.Create a new cloud-only user in the Microsoft 365 admin center and assign a license.
B.Sync the on-premises user using Azure AD Connect and then assign the license.
C.Manually create a user in Microsoft Entra ID with the same name and assign license.
D.Use Azure AD B2B collaboration to invite the on-premises user as a guest.
AnswerB

Synchronize the existing on-premises user using Microsoft Entra Connect (formerly Azure AD Connect), which creates a user object in Microsoft Entra ID with the correct sourceAnchor for a stable, immutable link. This ensures the cloud identity is the same as the on-premises identity, enabling password hash sync or pass-through authentication for unified credentials. After the user is synced and visible in the portal, assign the required Microsoft 365 license to activate services like Exchange Online and Teams, preserving a single source of identity authority.

Why this answer

The user already exists in on-premises Active Directory, and the fastest way to enable Microsoft 365 access is to synchronize that identity using Azure AD Connect. Once synchronized, the user object appears in Microsoft Entra ID (formerly Azure AD), and the administrator can immediately assign a license without re-creating the account. This avoids the delays of manual creation or guest invitations and leverages the existing identity lifecycle.

Exam trap

The trap here is that candidates often confuse the speed of creating a new cloud user (Option A) with the efficiency of leveraging an existing synchronized identity, failing to recognize that synchronization is the intended and fastest path for hybrid environments.

How to eliminate wrong answers

Option A is wrong because creating a new cloud-only user would result in a duplicate identity that is not linked to the on-premises AD account, breaking password sync and future management. Option C is wrong because manually creating a user in Microsoft Entra ID with the same name does not establish a source-of-authority connection to the on-premises object, leading to conflicts and no automatic attribute synchronization. Option D is wrong because Azure AD B2B collaboration is designed for external guest access, not for enabling an internal employee with full Microsoft 365 services; it would create a separate guest identity without proper license assignment or directory integration.

61
Multi-Selectmedium

You are planning the initial deployment of a new Microsoft 365 tenant for Contoso Ltd. Which three of the following actions are required or recommended as part of the tenant provisioning and initial configuration process? (Choose three.)

Select 3 answers
.Register a custom domain name (e.g., contoso.com) and verify ownership via DNS TXT record.
.Assign Microsoft 365 licenses to all user accounts before creating the accounts.
.Configure the default tenant-level password expiration policy to 90 days using the Microsoft 365 admin center.
.Create the initial global administrator account with a strong, unique password and enable multi-factor authentication.
.Set up a secondary domain as the default email domain to avoid conflicts with the initial onmicrosoft.com domain.
.Configure tenant-wide service settings such as external sharing for SharePoint and OneDrive.

Why this answer

Registering and verifying a custom domain (e.g., contoso.com) via a DNS TXT record is a required step to use your own domain for email and user identities instead of the default onmicrosoft.com domain. Creating the initial global administrator account with a strong password and enabling multi-factor authentication (MFA) is a critical security best practice and is recommended by Microsoft to protect the highest-privileged role. Configuring tenant-wide service settings, such as external sharing for SharePoint and OneDrive, is recommended during initial setup to align with organizational security and collaboration policies before users begin working.

Exam trap

The trap here is that candidates may think password expiration policies are still relevant in Microsoft 365, but Microsoft deprecated them in favor of modern authentication and MFA, making the 90-day policy option a distractor.

62
MCQeasy

An organization has just signed up for Microsoft 365 E3 with the initial domain 'contoso.onmicrosoft.com'. They need to create the first user accounts. What will be the default email address format for these new users if no custom domain is added yet?

A.user@contoso.onmicrosoft.com
B.user@contoso.com
C.user@microsoft.com
D.user@contoso.microsoft.com
AnswerA

The initial domain created when a Microsoft 365 tenant is provisioned always uses the <tenantname>.onmicrosoft.com namespace, and contoso.onmicrosoft.com is the default UPN and email domain for all new users. This domain is automatically reserved for your tenant and cannot be used by any other tenant, so assigning user@contoso.onmicrosoft.com is the only valid option listed without additional configuration.

Why this answer

When a new Microsoft 365 tenant is created with the initial domain 'contoso.onmicrosoft.com' and no custom domain has been added, the default email address format for new users is user@contoso.onmicrosoft.com. This is because the onmicrosoft.com domain is the default tenant domain provisioned by Azure AD, and all user principal names (UPNs) and email addresses are automatically assigned this suffix until a custom domain is verified and set as the primary domain.

Exam trap

The trap here is that candidates assume the email address will automatically match the organization's public domain name (e.g., contoso.com) without realizing that a custom domain must be explicitly added and verified in the Microsoft 365 admin center before it can be used for user email addresses.

How to eliminate wrong answers

Option B is wrong because 'contoso.com' is a custom domain that must be purchased and verified via DNS TXT records before it can be used for email addresses; it is not automatically available. Option C is wrong because 'microsoft.com' is Microsoft's own corporate domain and cannot be used by any tenant. Option D is wrong because 'contoso.microsoft.com' is not a valid domain format for any Microsoft 365 tenant; the default tenant domain always uses the pattern <tenantname>.onmicrosoft.com.

63
Multi-Selectmedium

Which TWO actions are required to enable Microsoft 365 Copilot for all users in your tenant?

Select 2 answers
A.Run a PowerShell script to enable Copilot in the tenant.
B.Ensure the tenant is on a Microsoft 365 E5 plan.
C.Ensure users have a qualifying Microsoft 365 license (e.g., E3, E5, Business Standard).
D.Assign a Microsoft 365 Copilot license to each user.
E.Provision an Azure subscription for Copilot services.
AnswersC, D

A qualifying base Microsoft 365 license is a foundational prerequisite for Microsoft 365 Copilot because Copilot is an add-on that builds on existing Microsoft 365 services and data. Without a valid base license—such as E3, E5, or Business Standard—a user cannot receive Copilot features, as the add-on license is dependent on the underlying qualifying plan being present and active. Administrators must therefore verify each target user has an eligible base license before assigning the Copilot add-on license.

Why this answer

Microsoft 365 Copilot requires users to have a qualifying base license such as Microsoft 365 E3, E5, or Business Standard. Without one of these base licenses, the Copilot add-on license cannot be assigned or function properly, as Copilot relies on the underlying Microsoft 365 services (e.g., Exchange Online, SharePoint, Teams) that these plans provide.

Exam trap

The trap here is that candidates assume a tenant-wide setting or a specific plan (like E5) is required, when in fact the key requirement is a qualifying base license per user combined with individual Copilot license assignment.

64
MCQhard

Your organization has a Microsoft 365 tenant with 10,000 users. You are configuring Microsoft Entra ID Identity Protection to detect risky sign-ins. You need to ensure that when a sign-in risk level of 'High' is detected, the user is blocked from signing in and an administrator is notified. What should you configure?

A.Create a Conditional Access policy with 'Sign-in risk' condition set to 'High' and 'Block access', and configure alert notifications in Identity Protection
B.Create a user risk policy in Identity Protection to block high-risk users
C.Create an MFA registration policy in Identity Protection
D.Enable Security defaults and configure notifications
AnswerA

A Conditional Access policy with a Sign-in risk condition evaluates the risk score that Azure AD Identity Protection assigns to each authentication attempt in real time. Setting the condition to 'High' and the access control to 'Block access' prevents compromised credentials from being used before a session is established. Separately configuring alert notifications in Identity Protection ensures that administrators are immediately notified when such high-risk sign-ins are attempted, providing both remediation and visibility.

Why this answer

It combines a Conditional Access policy that blocks access when the sign-in risk level is 'High' with an alert notification configured in Identity Protection. The Conditional Access policy enforces the block at the authentication level, while the Identity Protection alert ensures administrators are notified of the high-risk sign-in event. This directly meets the requirement to both block the user and notify an admin.

Exam trap

The trap here is that candidates often confuse user risk policies (which target compromised accounts) with sign-in risk policies (which target risky authentication sessions), leading them to select Option B instead of the correct combination of Conditional Access and alert notifications.

How to eliminate wrong answers

Option B is wrong because a user risk policy in Identity Protection targets user accounts that have been compromised (e.g., leaked credentials) and can block sign-ins or require password reset, but it does not address sign-in risk from a specific session (e.g., anonymous IP address, atypical travel). Option C is wrong because an MFA registration policy in Identity Protection only enforces that users register for multifactor authentication, not that high-risk sign-ins are blocked or that admins are notified. Option D is wrong because Security defaults enforce baseline security policies (like requiring MFA for all users) but do not allow granular control to block only high-risk sign-ins or send targeted admin notifications for such events.

65
MCQhard

You are the Microsoft 365 administrator for a company with a hybrid identity configuration using Azure AD Connect. The company has a custom domain 'contoso.com' federated with Active Directory Federation Services (ADFS). All users are synced from on-premises Active Directory. The security team wants to implement Microsoft Entra ID Protection to detect risky sign-ins. However, they are concerned that federated authentication bypasses some risk detection capabilities. You need to ensure that Microsoft Entra ID Protection can evaluate risk for all sign-ins, including federated ones. What should you do?

A.Switch from federated authentication to Pass-through Authentication (PTA) or Password Hash Sync (PHS).
B.Configure the federated trust in Microsoft Entra ID to use the new claims.
C.Configure ADFS to send the ipaddr and xms_ep claims to Azure AD.
D.Enable Azure AD Application Proxy to publish ADFS internally.
AnswerA

With federated authentication, Azure AD redirects authentication to ADFS, so Azure AD never performs or observes the actual password validation and cannot compute sign-in risk for that exchange. Switching to Pass-through Authentication (PTA) or Password Hash Sync (PHS) makes Azure AD the authentication authority: PTA validates against on-prem AD through an agent, while PHS validates against synced hashes. Because the token is issued by Azure AD after credential verification, Identity Protection can evaluate risk before the user receives access.

Why this answer

Microsoft Entra ID Protection relies on signals such as IP addresses, device information, and sign-in patterns to calculate risk. In a federated setup with ADFS, the authentication happens on-premises, and Azure AD only receives a token—not the raw sign-in details needed for real-time risk evaluation. Switching to Pass-through Authentication (PTA) or Password Hash Sync (PHS) ensures that the authentication process flows through Azure AD directly, allowing Entra ID Protection to capture and analyze all sign-in events, including those from federated users.

Exam trap

The trap here is that candidates may think adding claims (Option C) or changing the trust configuration (Option B) can compensate for the architectural limitation, but only moving the authentication flow to Azure AD (Option A) gives Entra ID Protection the raw sign-in data it needs for real-time risk evaluation.

How to eliminate wrong answers

Option B is wrong because configuring the federated trust to use new claims does not change the fundamental architecture—ADFS still performs authentication, and Azure AD still lacks the raw sign-in data (e.g., IP address, user agent) required for real-time risk detection. Option C is wrong because while sending ipaddr and xms_ep claims can provide some additional context, it does not enable Entra ID Protection to evaluate risk in real time; the authentication still occurs on-premises, and risk evaluation is limited to post-authentication token analysis. Option D is wrong because enabling Azure AD Application Proxy to publish ADFS internally only changes the access method to ADFS, not the authentication flow—federated authentication still bypasses Azure AD's direct sign-in event collection.

66
MCQhard

You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a hybrid deployment with Exchange Server 2019 on-premises and Exchange Online. You need to configure a mail flow rule that adds a disclaimer to all emails sent from on-premises mailboxes to external recipients. The disclaimer must be applied only to messages that originate from on-premises and are sent to external domains. What should you do?

A.Create a mail flow rule in the EAC in Exchange Online. Set the rule to apply to messages sent to 'Outside the organization'. Add a condition 'The sender is located' and select 'Inside the organization'. Add an action to prepend a disclaimer. Then create a second rule that applies to messages sent from on-premises mailboxes using a header condition, and block the first rule.
B.Create a mail flow rule in the EAC on the on-premises Exchange Server. Set the rule to apply to messages sent to 'Outside the organization'. Add an action to prepend a disclaimer. Enable the rule.
C.Create a mail flow rule in the EAC in Exchange Online. Set the rule to apply to messages sent to 'Outside the organization'. Add a condition 'The sender is located' and select 'Inside the organization'. Add an action to prepend a disclaimer. Enable the rule.
D.Create a mail flow rule in the Exchange admin center (EAC) in Exchange Online. Set the rule to apply to messages sent to 'Outside the organization'. Add a condition 'The sender is located' and select 'Outside the organization'. Add an action to prepend a disclaimer. Enable the rule.
AnswerC

In a hybrid deployment, on-premises mailboxes are treated as 'Inside the organization' by Exchange Online. Therefore, a rule that applies to messages sent to 'Outside the organization' and has a condition that the sender is located 'Inside the organization' will correctly match messages sent from on-premises mailboxes to external recipients. The action to prepend a disclaimer will add the disclaimer to those messages. This configuration meets the requirement precisely and is the standard method for applying disclaimers to outbound mail from on-premises senders in a hybrid setup.

Why this answer

In a hybrid deployment, on-premises mailboxes are considered part of the organization by Exchange Online. Therefore, a mail flow rule in Exchange Online that applies to messages sent to 'Outside the organization' and has a condition that the sender is located 'Inside the organization' will correctly match messages originating from on-premises mailboxes and sent to external recipients. The disclaimer action then adds the required text.

This is the standard and most reliable method for applying disclaimers to outbound mail from on-premises senders in a hybrid environment.

Exam trap

The trap here is assuming that on-premises mailboxes are considered 'Outside the organization' in Exchange Online, when in fact they are treated as 'Inside the organization' due to the hybrid configuration.

67
MCQeasy

You are the Microsoft 365 administrator for a company that has a Microsoft 365 E3 tenant. The company wants to ensure that users can only access Microsoft 365 services from compliant devices. You need to configure a policy that enforces this requirement. What should you create?

A.A Microsoft 365 compliance policy in the Microsoft Purview compliance portal that restricts access to SharePoint Online.
B.An Intune device compliance policy that blocks access to Exchange Online.
C.A Microsoft Entra Conditional Access policy that requires the device to be marked as compliant.
D.A Microsoft Defender for Cloud Apps session policy that blocks downloads from non-compliant devices.
AnswerC

Conditional Access policies in Microsoft Entra ID can enforce that devices must be marked as compliant by Intune or another MDM solution before granting access to Microsoft 365 services. This directly meets the requirement by evaluating device compliance at sign-in and blocking non-compliant devices.

Why this answer

To enforce that users can only access Microsoft 365 services from compliant devices, you must use a Microsoft Entra Conditional Access policy. This policy evaluates device compliance status at sign-in and grants or blocks access accordingly. Intune compliance policies alone do not enforce access; they only determine compliance status.

Exam trap

The trap here is assuming that an Intune compliance policy alone can block access, when it only reports compliance and requires Conditional Access to enforce.

68
MCQeasy

Your organization uses Microsoft 365 Business Premium. You need to ensure that when a user is assigned an Intune license, the device automatically enrolls in Microsoft Intune. What should you configure?

A.Configure Microsoft Entra ID device settings to enable MDM automatic enrollment
B.Create a device compliance policy to require enrollment
C.Create a device enrollment restriction in Intune to block personal devices
D.Deploy a device configuration profile with enrollment settings
AnswerA

In Microsoft Entra ID, under Device settings, the 'Enable automatic enrollment for MDM' option (also known as MDM user scope) directs the identity provider to register and enroll devices into the configured MDM authority, Intune, as part of the user sign-in flow. Because every user in the organization holds a Microsoft 365 Business Premium license that includes Intune, toggling this setting causes their devices to automatically enroll upon authentication and license assignment. This is the only option that actively triggers enrollment; the other options are post-enrollment or pre-enrollment controls that do not initiate the enrollment process.

Why this answer

Microsoft Entra ID (formerly Azure AD) device settings include an option to enable automatic MDM enrollment for users assigned an Intune license. When enabled, any device that signs in with a licensed user account will automatically enroll in Microsoft Intune, satisfying the requirement without additional configuration.

Exam trap

The trap here is that candidates often confuse device compliance policies or configuration profiles with the enrollment trigger, but only the Microsoft Entra ID device settings control the automatic MDM enrollment behavior.

How to eliminate wrong answers

Option B is wrong because a device compliance policy checks compliance after enrollment, it does not trigger automatic enrollment. Option C is wrong because enrollment restrictions control which devices can enroll (e.g., blocking personal devices), but they do not enable automatic enrollment. Option D is wrong because a device configuration profile applies settings to already enrolled devices, it does not initiate the enrollment process.

69
Multi-Selecthard

You are designing a Microsoft 365 tenant for a multinational organization. You need to ensure compliance with data residency requirements. Which THREE actions should you take?

Select 3 answers
A.Set data location preferences in the Microsoft 365 admin center.
B.Disable cross-region replication in Exchange Online.
C.Use compliance boundaries for eDiscovery.
D.Create data loss prevention policies for each region.
E.Configure Microsoft 365 Multi-Geo.
AnswersA, C, E

During initial tenant provisioning, the Microsoft 365 admin center's data location setting lets you choose the main geographic region (for example, Europe, Asia Pacific) where core Microsoft 365 data for the tenant will be stored at rest. This selection determines the primary residency for Exchange Online mailboxes, SharePoint/OneDrive content, and Teams data. Because the choice is made at tenant creation and is largely immutable for existing tenants, it must be aligned with the multinational's data-residency requirements before provisioning begins.

Why this answer

Setting data location preferences in the Microsoft 365 admin center (under Settings > Org Settings > Organization Information) allows you to specify the primary data residency region for your tenant. This ensures that core data at rest, such as Exchange Online mailboxes and SharePoint sites, is stored in the selected geographic location to meet compliance requirements.

Exam trap

The trap here is that candidates often confuse data residency (where data is stored) with data protection (DLP policies) or replication settings, leading them to select DLP policies or disabling replication instead of the correct Multi-Geo and compliance boundary options.

70
MCQeasy

A user reports that they cannot access their Microsoft 365 mailbox via Outlook on the web. Other users can access their mailboxes. What is the most likely cause?

A.The user's password has expired
B.The Exchange Online service is experiencing an outage
C.The user's browser cache needs to be cleared
D.The user does not have an Exchange Online license assigned
AnswerD

Exchange Online licenses are assigned per user through the Microsoft 365 admin center or Azure AD, and each user needs an active license with the Exchange Online service plan before a mailbox is provisioned. Without that license, the user remains able to authenticate to Microsoft 365 and use other services, but Outlook on the web will fail with a 'no mailbox' or 'license' error because Exchange does not find a recipient object. This exactly matches the reported scenario: one user cannot access their Exchange Online mailbox while other functionality may still work.

Why this answer

The most likely cause is that the user does not have an Exchange Online license assigned. Without a valid license, the user's mailbox is not provisioned, and Outlook on the Web (OWA) cannot access it. Other users can access their mailboxes because they have licenses, ruling out a service-wide issue.

Exam trap

The trap here is that candidates confuse authentication issues (password expired) with authorization or licensing issues, assuming that if a user can log in to the Microsoft 365 portal, they automatically have a mailbox.

How to eliminate wrong answers

Option A is wrong because an expired password would prevent authentication entirely, but the user would see a login prompt or password error, not a mailbox access issue after login. Option B is wrong because an Exchange Online outage would affect all users, not just one. Option C is wrong because clearing browser cache resolves display or rendering issues, not access to the mailbox itself; if the mailbox is unlicensed, no amount of cache clearing will help.

71
MCQmedium

Your organization uses Microsoft 365 and has strict compliance requirements. The compliance officer has noticed that some users are able to access sensitive documents from unmanaged devices. You need to ensure that all access to sensitive data from unmanaged devices is blocked, while still allowing access from managed devices. The solution must be implemented using Microsoft Entra ID and Microsoft Intune. You have already deployed Microsoft Intune for mobile device management. What should you do?

A.Enable device compliance rules in Microsoft Entra ID and assign them to all users.
B.Create a device compliance policy in Microsoft Intune that requires a PIN and encryption.
C.Create an app protection policy in Microsoft Intune that requires managed apps to be used on unmanaged devices.
D.Create a conditional access policy in Microsoft Entra ID that requires device to be marked as compliant, and apply it to all cloud apps.
AnswerD

A conditional access policy requiring compliant devices blocks unmanaged devices while permitting Intune-managed ones, since compliance state is evaluated per device. Applying it to all cloud apps enforces this across Microsoft 365 workloads, satisfying the strict compliance requirement.

Why this answer

A Conditional Access policy that requires the device to be marked as compliant enforces that only Intune-managed, compliant devices can access cloud apps. This blocks unmanaged devices because they cannot satisfy the compliance requirement, while managed devices that meet the compliance policy are allowed. This directly satisfies the requirement to block unmanaged device access using Entra ID and Intune.

Exam trap

The trap is confusing app protection policies (which protect data but allow access) with device compliance Conditional Access (which blocks access from non-compliant/unmanaged devices).

How to eliminate wrong answers

Option A is wrong because device compliance rules alone do not enforce access; they must be referenced in a Conditional Access policy to have effect. Option B is wrong because a compliance policy defines what makes a device compliant but does not block access by itself. Option C is wrong because app protection policies (MAM) protect data within apps on unmanaged devices but do not block access to sensitive documents from unmanaged devices.

72
MCQhard

Your organization uses Microsoft 365 E5 licenses. You need to implement a secure score improvement plan. After reviewing the Secure Score, you notice a recommendation to 'Enable sign-in risk policy' in Microsoft Entra ID. However, you want to ensure that users who sign in from trusted locations are not challenged. What should you configure?

A.Configure named locations in Microsoft Entra ID for trusted IPs.
B.Enable the 'Sign-in risk' policy in Identity Protection and set 'Exclude trusted locations'.
C.Enable the 'Require MFA for all users' conditional access policy.
D.Create a conditional access policy that targets sign-in risk: medium and above, require MFA, and exclude trusted named locations.
AnswerD

This policy applies the 'Grant' control 'Require MFA' only when the 'Sign-in risk' condition is evaluated as medium or higher, and it explicitly excludes users who sign in from a named location marked as trusted. When a sign-in originates from an excluded trusted location, the policy is not evaluated, allowing seamless access without MFA. For risky sign-ins coming from any other IP, the policy triggers MFA, thereby satisfying the requirement to require MFA for medium+ risk while exempting trusted locations.

Why this answer

It creates a Conditional Access policy that targets sign-in risk at medium and above, requiring MFA, while excluding trusted named locations. This ensures users from trusted IPs are not challenged, directly addressing the requirement to avoid unnecessary prompts for trusted sign-ins while still enforcing risk-based policies.

Exam trap

The trap here is that candidates confuse Identity Protection's risk policies with Conditional Access policies, assuming exclusions are set directly in Identity Protection rather than through Conditional Access, leading them to select Option B.

How to eliminate wrong answers

Option A is wrong because configuring named locations alone does not enforce a sign-in risk policy; it only defines trusted IPs, which must be referenced in a Conditional Access policy to have effect. Option B is wrong because the 'Sign-in risk' policy in Identity Protection does not have an 'Exclude trusted locations' setting; exclusions are handled via Conditional Access policies, not within Identity Protection itself. Option C is wrong because 'Require MFA for all users' is a blanket policy that does not consider sign-in risk or trusted locations, so it would challenge users from trusted locations unnecessarily.

73
MCQmedium

Your organization has a Microsoft 365 tenant configured with a custom domain. You need to verify domain ownership using a TXT record. Where in the Microsoft 365 admin center would you initiate this process?

A.Settings > Domains
B.Setup > Org-wide settings
C.Users > Active Users
D.Admin centers > Azure Active Directory
AnswerA

Settings > Domains is the correct location in the Microsoft 365 admin center for adding, verifying, and managing custom domains. From this blade, you can initiate domain verification via a DNS TXT record or MX record, designate a primary domain, set the domain for services like Exchange Online, and monitor domain health. This is the unified domain management interface that most administrators use for day-to-day domain lifecycle tasks.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record provided by Microsoft to your domain's DNS zone. The process is initiated in the Microsoft 365 admin center under Settings > Domains, where you select the domain and click 'Start setup' to receive the verification TXT record value. This is the only location in the admin center that directly manages domain verification and DNS record validation for custom domains.

Exam trap

The trap here is that candidates may confuse domain verification with other domain-related tasks (like setting up email routing or managing user accounts) and select Setup > Org-wide settings or Users > Active Users, but only Settings > Domains provides the guided wizard for adding and verifying a custom domain via TXT records.

How to eliminate wrong answers

Option B is wrong because Setup > Org-wide settings contains organization-wide configuration options like security policies, profiles, and external sharing settings, but does not include domain management or DNS verification tasks. Option C is wrong because Users > Active Users is for managing user accounts, licenses, and permissions, not for domain ownership verification which is a DNS-level process. Option D is wrong because Admin centers > Azure Active Directory opens the Azure AD portal, which can manage custom domains but is not the primary or recommended path in the Microsoft 365 admin center for initiating TXT record verification; the correct path is Settings > Domains within the M365 admin center itself.

74
MCQeasy

An administrator wants to verify ownership of a custom domain 'adatum.com' in their Microsoft 365 tenant. They have already added the domain and received the TXT record value. However, the administrator's DNS hosting provider does not support adding a TXT record. Which alternative record type can be used for domain verification?

A.record
B.MX record
C.SRV record
D.NS record
AnswerB

Microsoft 365 permits two common verification methods: a TXT record containing 'MS=msXXXXXX' or an MX record pointing to 'msXXXXXX.adatum.com'. The MX verification record is a valid alternative that works by having you create a mail exchanger record with the exact verification token as the mail host. This record is non-authoritative and does not affect mail routing because it points to a Microsoft verification endpoint that only checks for the token. Once the token is confirmed, the MX record can be safely removed.

Why this answer

When a DNS hosting provider does not support TXT records, Microsoft 365 allows the use of an MX record as an alternative for domain verification. The administrator creates an MX record with a specific subdomain (e.g., 'adatum-com.mail.protection.outlook.com') and a custom priority value provided in the TXT record value, which Microsoft's verification system checks to confirm domain ownership. This method is supported because MX records are widely available and can carry the necessary verification data in their format.

Exam trap

The trap here is that candidates may assume only TXT records can verify domain ownership, overlooking that Microsoft 365 explicitly supports MX records as an alternative when TXT records are unavailable, which is a common scenario in restrictive DNS environments.

How to eliminate wrong answers

Option A is wrong because 'A record' maps a domain to an IPv4 address and cannot carry the verification string required by Microsoft 365; it is not a supported alternative for domain verification. Option C is wrong because 'SRV record' specifies the location of services (like SIP or LDAP) and is not used for domain ownership verification in Microsoft 365. Option D is wrong because 'NS record' delegates a domain to a set of name servers and does not support embedding a verification token; it would change the domain's authoritative servers rather than prove ownership.

75
MCQmedium

An organization plans to automatically assign Microsoft 365 E3 licenses to all users in the 'Finance' department. The Finance department is identified by the 'Department' attribute in Azure AD. Which method should the administrator use to minimize manual effort?

A.Group-based licensing using a dynamic group with the rule 'user.department -eq "Finance"'
B.Manual assignment using PowerShell
C.Bulk assignment using a CSV file
D.Self-service licensing portal
AnswerA

In this solution, Azure AD group-based licensing is combined with a dynamic group whose membership rule filters users where user.department equals 'Finance'. As new Finance employees are created, they automatically become group members based on their department attribute, and Azure AD evaluates membership to provision the Microsoft 365 E3 license within minutes. If a user's department changes, membership is recalculated and the license is automatically removed, providing fully automatic, attribute-driven lifecycle management.

Why this answer

Dynamic group licensing in Azure AD uses attribute-based membership rules, so a rule like 'user.department -eq "Finance"' automatically adds all Finance users to the group. Assigning the Microsoft 365 E3 license to that group means every current and future Finance user receives the license without manual intervention, which is the lowest-effort, most scalable approach.

Exam trap

The trap is choosing a one-time bulk method (CSV or PowerShell) when the requirement is ongoing automation — dynamic group licensing is the only option that handles future users automatically.

How to eliminate wrong answers

Option B is wrong because manual PowerShell assignment requires scripting and re-running whenever users join or leave Finance, which is not minimal effort. Option C is wrong because bulk CSV assignment is a one-time operation that does not automatically handle future users. Option D is wrong because a self-service portal shifts the work to users and does not guarantee correct license assignment.

Page 1 of 3 · 196 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Deploy and manage a Microsoft 365 tenant questions.