Courseiva
Back to Microsoft 365 Administrator MS-102 questions

Scenario-based practice

Hard Difficulty Questions

Practise Microsoft 365 Administrator MS-102 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
MS-102
exam code
Microsoft
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related MS-102 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Your company is migrating from on-premises Active Directory to Microsoft Entra ID. You plan to use Microsoft Entra Connect Sync to synchronize user accounts. The security team requires that all cloud-only users must be blocked from syncing to on-premises AD. What should you do to meet this requirement?

Question 2hardmultiple choice
Full question →

Your organization has a Microsoft 365 tenant with 10,000 users. You are configuring Microsoft Entra ID Identity Protection to detect risky sign-ins. You need to ensure that when a sign-in risk level of 'High' is detected, the user is blocked from signing in and an administrator is notified. What should you configure?

Question 3hardmultiple choice
Full question →

Your company uses Microsoft Entra ID and has a hybrid identity with PHS. You need to ensure that when an on-premises user account is disabled, the corresponding cloud user is also blocked from signing in within 5 minutes. What should you configure?

Question 4hardmultiple choice
Full question →

Refer to the exhibit. You run the PowerShell command to check the authentication method policy registration campaign. Which of the following is true?

Exhibit

Refer to the exhibit.

PS C:\> (Get-MgPolicyAuthenticationMethodPolicy).RegistrationCampaign.Email
Value   : enabled
IncludeTargets : [{"targetType":"group","id":"all_users","isSystemTarget":true}]
ExcludeTargets : []
State : enabled
Question 5hardmultiple choice
Full question →

Your company recently acquired a subsidiary that uses a different Microsoft 365 tenant. You are tasked with merging the two tenants into one. The subsidiary has 1,500 users with unique email domains. You need to migrate all users, mailboxes, and SharePoint data while minimizing downtime and preserving data integrity. You have access to both tenants as global admin. What should you do first?

Question 6hardmulti select
Full question →

Which THREE steps are required to enable group-based licensing?

Question 7hardmultiple choice
Full question →

Refer to the exhibit. The Contoso tenant has a cross-tenant access policy configured for Fabrikam. Users from Fabrikam are unable to access resources in Contoso via B2B collaboration. What is the most likely reason?

Exhibit

Refer to the exhibit.

```powershell
Get-MgPolicyCrossTenantAccessPolicy

Id           : /policies/crossTenantAccessPolicy
DisplayName   : Default policy
DefaultPolicy : Microsoft.Graph.PowerShell.Models.MicrosoftGraphCrossTenantAccessPolicyDefault

(DefaultPolicy properties)
B2BCollaborationInbound : @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BCollaborationOutbound: @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BDirectConnectInbound : @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BDirectConnectOutbound: @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
OfficeSyncInbound        : @{AllowedTenants=}
OfficeSyncOutbound       : @{AllowedTenants=}
IsServiceDefault         : True

Get-MgPolicyCrossTenantAccessPolicyPartner -CrossTenantAccessPolicyId "/policies/crossTenantAccessPolicy"

Id                   : /policies/crossTenantAccessPolicy/partners/contoso.com
TenantId             : contoso.com
B2BCollaborationInbound : @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BCollaborationOutbound: @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BDirectConnectInbound : @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BDirectConnectOutbound: @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
OfficeSyncInbound        : @{AllowedTenants=}
OfficeSyncOutbound       : @{AllowedTenants=}
IsServiceDefault         : False
AutomaticUserConsentSettings: @{InboundAllowed=; OutboundAllowed=}
```
Question 8hardmultiple choice
Study the full multicast explanation →

A company wants to require approval for any activation of the Global Administrator role in Privileged Identity Management (PIM). The approvers are predefined as members of a security group named 'GA-Approvers'. Activations must require a business justification and expire after 4 hours. Which PIM configuration should the administrator modify to meet these requirements?

Question 9hardmultiple choice
Full question →

Your organization has Microsoft Defender for Cloud Apps (MCAS) deployed. You need to create a policy that automatically blocks downloads of files classified as 'Highly Confidential' from SharePoint Online to unmanaged devices. Which policy type should you use?

Question 10hardmultiple choice
Full question →

Your organization uses Microsoft Entra ID and has a hybrid identity setup with password hash synchronization. You need to ensure that when a user's on-premises Active Directory account is disabled, their Microsoft Entra ID account is also disabled within 30 minutes. What should you do?

Question 11hardmultiple choice
Full question →

A company has a Microsoft 365 E5 tenant with 10,000 users. You need to delegate the ability to manage Microsoft Entra ID roles to a group of support engineers. The solution must follow the principle of least privilege and allow engineers to assign only specific roles to users. What should you do?

Question 12hardmultiple choice
Full question →

A company uses Microsoft Entra ID with group-based licensing. You assign a license to a group, but some members do not receive the license. There are no error messages in the audit logs. What is the most likely cause?

Question 13hardmultiple choice
Full question →

You are a Microsoft 365 administrator. Your tenant has a Microsoft Entra ID P2 license. You need to create a dynamic group for all users whose department is 'Engineering' and who are located in the United States. Which rule syntax should you use?

Question 14hardmultiple choice
Full question →

Your company is deploying Microsoft Defender for Office 365. The security team wants to automatically remove messages identified as malware from all mailboxes after delivery. What should you configure?

Question 15hardmultiple choice
Full question →

Your organization uses Microsoft Entra ID and has a custom role that grants 'microsoft.directory/applications/credentials/update' permission. A security audit reveals that a user assigned this role has modified credentials for an application. You need to prevent such actions while allowing other application updates. What should you do?

Question 16hardmultiple choice
Full question →

You are the Microsoft 365 administrator for a large enterprise with 50,000 users. The company is deploying Microsoft 365 Copilot for all users. You need to ensure that the data used by Copilot is protected and that Copilot does not inadvertently expose sensitive information. The company has strict data residency requirements: all data must remain within the European Union (EU). You have already configured data boundaries in Microsoft 365 to keep data in the EU. However, you are concerned about Copilot's AI model training. You need to implement additional controls. The company uses Microsoft Purview Information Protection with sensitivity labels. You have created a sensitivity label "Highly Confidential" that applies encryption and a "Confidential" label that applies visual markings. You also have a DLP policy that prevents sharing of "Highly Confidential" data externally. You need to ensure that when a user uses Copilot with a document labeled "Highly Confidential", the Copilot response does not include any of the sensitive content from that document. What should you do?

Question 17hardmulti select
Full question →

Your organization uses Microsoft Sentinel for security operations. You need to ensure that Sentinel can ingest logs from Microsoft 365 Defender (XDR) and Microsoft Entra ID. Which THREE data connectors should you enable? (Choose three.)

Question 18hardmultiple choice
Full question →

You are reviewing directory settings for Microsoft 365 Groups. Based on the exhibit, which statement is true?

Exhibit

Refer to the exhibit.

PowerShell output:

Get-AzureADDirectorySetting | Select-Object *

Id                                   : 1234-...
DisplayName                          : Group.Unified
TemplateId                           : 62375ab9-...
Values                               : {[EnableGroupCreation, true], [GroupCreationAllowedGroupId, ], [UsageGuidelinesUrl, ], [ClassificationDescriptions, ], [DefaultClassification, ], [PrefixSuffixNamingRequirement, ], [CustomBlockedWordsList, ], [EnableMSStandardBlockedWords, false]}
Question 19hardmultiple choice
Full question →

You are the Microsoft 365 administrator for a company with a hybrid identity configuration using Azure AD Connect. The company has a custom domain 'contoso.com' federated with Active Directory Federation Services (ADFS). All users are synced from on-premises Active Directory. The security team wants to implement Microsoft Entra ID Protection to detect risky sign-ins. However, they are concerned that federated authentication bypasses some risk detection capabilities. You need to ensure that Microsoft Entra ID Protection can evaluate risk for all sign-ins, including federated ones. What should you do?

Question 20hardmultiple choice
Full question →

Your organization uses Microsoft Entra ID P2 and Microsoft Defender for Cloud Apps. You need to protect a custom SaaS application that uses SAML-based SSO. The application does not support Conditional Access. You want to enforce session controls such as blocking downloads of sensitive files. What should you implement?

These MS-102 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style MS-102 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.