Drag a concept onto its matching description — or click a concept then click the description.
Full access to all admin features
Resets passwords for non-admins
Manages Exchange Online
Manages users and groups
Manages security policies
Match each Microsoft 365 role to its administrative scope.
Drag a concept onto its matching description — or click a concept then click the description.
Full access to all admin features
Resets passwords for non-admins
Manages Exchange Online
Manages users and groups
Manages security policies
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Global Administrator: Full access to all administrative features
These roles are part of Azure AD role-based access control. The correct matches are: Global Administrator (full access), User Administrator (users/groups), Exchange Administrator (Exchange settings). Common confusions include mixing Global and User Administrator scopes, or User and Exchange Administrator scopes.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
Global Administrator: Full access to all administrative features
Why this is correct
Global Administrator possesses unrestricted access to every Microsoft 365 administrative feature, including user and group management, Exchange, SharePoint, security, compliance, billing, and role assignment. It can reset passwords for all users and manage other administrators' roles. This role is the highest-privilege built-in role and should be protected with conditional access and MFA.
User Administrator: Manage users and groups, including password reset
Why this is correct
User Administrator can create and modify user accounts, reset passwords for non-privileged users, manage groups, and assign licenses. However, this role cannot manage Exchange Online mailboxes, security policies, or global admin roles. Its scope is limited to identity and directory-level administration, making it appropriate for helpdesk staff.
Exchange Administrator: Manage Exchange Online mailboxes and settings
Why this is correct
Exchange Administrator is a workload-scoped built-in role that grants management rights to Exchange Online mailboxes, recipient objects, anti-spam policies, mail flow rules, and organization settings in the Exchange admin center. It cannot reset passwords for users or manage Entra ID user accounts beyond mailbox-related properties. This role is ideal for delegated messaging administration without broader tenant access.
Global Administrator: Manage only user accounts and licenses
Why it's wrong here
This statement incorrectly constrains the Global Administrator role to only user accounts and licenses. In reality, Global Administrator has full, unrestricted access to all administrative features across the tenant, including security, compliance, billing, Exchange, SharePoint, and role assignments. The described limited scope belongs to the User Administrator role, not Global Administrator.
User Administrator: Manage email settings and policies
Why it's wrong here
This statement misidentifies the User Administrator's scope because managing email settings and policies is the function of the Exchange Administrator role. User Administrator is limited to user accounts, group memberships, password resets for ordinary users, and license assignments. It does not have permissions for mail flow, anti-spam, or mailbox configuration in the Exchange admin center.
Billing Administrator: Manage security and compliance policies
Why it's wrong here
This statement inaccurately assigns security and compliance policy management to the Billing Administrator. Billing Administrator is restricted to invoicing, subscription purchases, payment methods, and billing communications. Security and compliance policies, such as conditional access, DLP, and retention, are managed by Security Administrator, Compliance Administrator, or Global Administrator.
Quick reference
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Learn chapter
Microsoft 365 Tenant Setup
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.