Courseiva
← Back to Microsoft 365 Administrator MS-102 questions

Scenario-based practice

Hard Difficulty Questions

Practise Microsoft 365 Administrator MS-102 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
MS-102
exam code
Microsoft
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related MS-102 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Your company uses Microsoft Entra ID and has a hybrid identity with PHS. You need to ensure that when an on-premises user account is disabled, the corresponding cloud user is also blocked from signing in within 5 minutes. What should you configure?

Question 2hardmultiple choice
Full question →

Your company recently acquired a subsidiary that uses a different Microsoft 365 tenant. You are tasked with merging the two tenants into one. The subsidiary has 1,500 users with unique email domains. You need to migrate all users, mailboxes, and SharePoint data while minimizing downtime and preserving data integrity. You have access to both tenants as global admin. What should you do first?

Question 3hardmulti select
Full question →

A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a user receives a phishing email and later clicks a link to a known malicious domain from their device. The rule will use advanced hunting queries. Which two tables should be joined to detect the click event from the device?

Question 4hardmultiple choice
Full question →

You are the Microsoft 365 administrator for a large enterprise with 50,000 users. The company is deploying Microsoft 365 Copilot for all users. You need to ensure that the data used by Copilot is protected and that Copilot does not inadvertently expose sensitive information. The company has strict data residency requirements: all data must remain within the European Union (EU). You have already configured data boundaries in Microsoft 365 to keep data in the EU. However, you are concerned about Copilot's AI model training. You need to implement additional controls. The company uses Microsoft Purview Information Protection with sensitivity labels. You have created a sensitivity label "Highly Confidential" that applies encryption and a "Confidential" label that applies visual markings. You also have a DLP policy that prevents sharing of "Highly Confidential" data externally. You need to ensure that when a user uses Copilot with a document labeled "Highly Confidential", the Copilot response does not include any of the sensitive content from that document. What should you do?

Question 5hardmultiple choice
Full question →

You are the Microsoft 365 administrator for a company with a hybrid identity configuration using Azure AD Connect. The company has a custom domain 'contoso.com' federated with Active Directory Federation Services (ADFS). All users are synced from on-premises Active Directory. The security team wants to implement Microsoft Entra ID Protection to detect risky sign-ins. However, they are concerned that federated authentication bypasses some risk detection capabilities. You need to ensure that Microsoft Entra ID Protection can evaluate risk for all sign-ins, including federated ones. What should you do?

Question 6hardmultiple choice
Full question →

Your organization uses Microsoft Entra ID P2 and Microsoft Defender for Cloud Apps. You need to protect a custom SaaS application that uses SAML-based SSO. The application does not support Conditional Access. You want to enforce session controls such as blocking downloads of sensitive files. What should you implement?

Question 7hardmultiple choice
Full question →

Refer to the exhibit. You are reviewing the service principal for Microsoft Graph in your tenant. The passwordCredentials array is empty. What does this indicate?

Exhibit

Refer to the exhibit.

{
  "appId": "00000003-0000-0000-c000-000000000000",
  "displayName": "Microsoft Graph",
  "passwordCredentials": []
}
Question 8hardmultiple choice
Full question →

Your Microsoft 365 tenant has 50,000 users. You are planning to migrate mailboxes from on-premises Exchange Server 2019 to Exchange Online using a full hybrid configuration. During the migration, you must ensure that free/busy information is synchronized between on-premises and Exchange Online. Which component is required for free/busy synchronization in a hybrid deployment?

Question 9hardmultiple choice
Full question →

Your organization uses Microsoft Defender for Office 365 and Microsoft Defender for Endpoint. A user receives an email with a link that leads to a malicious website. The user clicks the link, but the browser is protected by Microsoft Defender SmartScreen. However, the user is still able to download a file from the site. What should you configure to prevent this?

Question 10hardmultiple choice
Full question →

Your company uses Microsoft Entra ID and has enabled Microsoft Entra ID Protection. You notice that a user's sign-in was blocked due to a medium user risk. However, the user claims the sign-in was legitimate. What should you do to allow future sign-ins without lowering security?

Question 11hardmulti select
Full question →

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that detects when a user signs in from an unknown IP address and then downloads a large number of files. Which THREE components should you configure?

Question 12hardmultiple choice
Full question →

You are a security administrator for a company that uses Microsoft Defender XDR. You need to integrate Microsoft Defender XDR with Microsoft Sentinel to create a unified incident view. You want to ensure that incidents from Defender XDR are automatically created in Sentinel. What should you do?

Question 13hardmultiple choice
Full question →

Refer to the exhibit. You are configuring an auto-labeling policy in Microsoft Purview. The policy is set to apply the 'Confidential' label to documents that contain a specific sensitive info type. However, when a document is auto-labeled, users report that the footer and header are not applied. The label 'Confidential' itself does not have marking configurations. What is the most likely reason?

Exhibit

{
  "InformationProtection": {
    "LabelPolicy": {
      "Id": "IP_LabelPolicy_1234",
      "Labels": [
        {"Id": "General", "DisplayName": "General"},
        {"Id": "Confidential", "DisplayName": "Confidential"}
      ],
      "Settings": {
        "DefaultLabelId": "General",
        "RemoveLabelingOnExit": false,
        "MarkingDefaults": {
          "Footer": "This document is confidential - Do not share",
          "Header": "Confidential"
        }
      }
    }
  }
}
Question 14hardmulti select
Full question →

Which THREE are features of Microsoft Entra ID Governance? (Choose three.)

Question 15hardmulti select
Full question →

Which THREE conditions can be used in a dynamic group rule for a device?

Question 16hardmultiple choice
Full question →

A security analyst needs to create a custom detection rule in Microsoft 365 Defender that triggers when a suspicious PowerShell process (e.g., using -EncodedCommand) is detected on a device, and within 5 minutes, an outbound network connection to a known malicious IP address occurs. Which two advanced hunting tables must be joined?

Question 17hardmultiple choice
Full question →

A compliance officer needs to automatically identify and label content that is conceptually similar to existing sensitive documents, such as internal strategy memos or proprietary technical specifications, without relying on explicit keywords or recognized sensitive information types. Which Microsoft Purview solution should the officer use to achieve this?

Question 18hardmulti select
Full question →

A compliance officer needs to ensure that all emails containing payment card information (PCI) are automatically encrypted when sent to external recipients. The encryption should occur without user intervention. Which two features should be configured together? (Choose two.)

Question 19hardmultiple choice
Full question →

An organization has multiple Microsoft Entra ID tenants and wants to allow partner users to access internal applications using their own corporate credentials. Which feature should be used to enable this?

Question 20hardmultiple choice
Full question →

A company uses Microsoft Entra ID P2 licenses and wants to implement just-in-time (JIT) privileged access for administrators. Security requirements state that Global Administrator role members must request approval and provide a business justification before their role activation expires after 4 hours. Which Microsoft Entra feature should be configured?

These MS-102 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style MS-102 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.