Courseiva

MS-102 Manage compliance by using Microsoft Purview Practice Question

Match each Microsoft 365 role to its administrative scope.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Full access to all admin features

Resets passwords for non-admins

Manages Exchange Online

Manages users and groups

Manages security policies

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Global Administrator: Full access to all administrative features

These roles are part of Azure AD role-based access control. The correct matches are: Global Administrator (full access), User Administrator (users/groups), Exchange Administrator (Exchange settings). Common confusions include mixing Global and User Administrator scopes, or User and Exchange Administrator scopes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Global Administrator: Full access to all administrative features

    Why this is correct

    Global Administrator possesses unrestricted access to every Microsoft 365 administrative feature, including user and group management, Exchange, SharePoint, security, compliance, billing, and role assignment. It can reset passwords for all users and manage other administrators' roles. This role is the highest-privilege built-in role and should be protected with conditional access and MFA.

  • User Administrator: Manage users and groups, including password reset

    Why this is correct

    User Administrator can create and modify user accounts, reset passwords for non-privileged users, manage groups, and assign licenses. However, this role cannot manage Exchange Online mailboxes, security policies, or global admin roles. Its scope is limited to identity and directory-level administration, making it appropriate for helpdesk staff.

  • Exchange Administrator: Manage Exchange Online mailboxes and settings

    Why this is correct

    Exchange Administrator is a workload-scoped built-in role that grants management rights to Exchange Online mailboxes, recipient objects, anti-spam policies, mail flow rules, and organization settings in the Exchange admin center. It cannot reset passwords for users or manage Entra ID user accounts beyond mailbox-related properties. This role is ideal for delegated messaging administration without broader tenant access.

  • Global Administrator: Manage only user accounts and licenses

    Why it's wrong here

    This statement incorrectly constrains the Global Administrator role to only user accounts and licenses. In reality, Global Administrator has full, unrestricted access to all administrative features across the tenant, including security, compliance, billing, Exchange, SharePoint, and role assignments. The described limited scope belongs to the User Administrator role, not Global Administrator.

  • User Administrator: Manage email settings and policies

    Why it's wrong here

    This statement misidentifies the User Administrator's scope because managing email settings and policies is the function of the Exchange Administrator role. User Administrator is limited to user accounts, group memberships, password resets for ordinary users, and license assignments. It does not have permissions for mail flow, anti-spam, or mailbox configuration in the Exchange admin center.

  • Billing Administrator: Manage security and compliance policies

    Why it's wrong here

    This statement inaccurately assigns security and compliance policy management to the Billing Administrator. Billing Administrator is restricted to invoicing, subscription purchases, payment methods, and billing communications. Security and compliance policies, such as conditional access, DLP, and retention, are managed by Security Administrator, Compliance Administrator, or Global Administrator.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.