Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Which TWO are valid methods for adding custom domains to Microsoft 365?

⚠ Common exam trap

Many exam-takers confuse the Exchange admin center's ability to manage 'accepted domains' with the initial domain addition process, or they mistakenly think on-premises DNS tools like Windows DNS Manager can directly add domains to Microsoft 365, when in fact they only handle the DNS verification records after the domain is registered in the tenant.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using the New-MsolDomain PowerShell cmdlet.

Option A is correct because the New-MsolDomain cmdlet from the MSOnline PowerShell module is a supported programmatic way to add a custom domain to a Microsoft 365/Microsoft Entra ID tenant, specifying parameters such as -Name for the domain. Option D is correct because the 'Add domain' wizard in the Microsoft 365 admin center is the primary GUI method for adding a custom domain, after which it provides the required DNS TXT or MX records for verification. Option B is incorrect because the Exchange admin center manages Exchange Online recipients, mailboxes, and accepted domains for mail flow, but it is not the supported tool for adding a new custom domain to the tenant. Option C is incorrect because Azure AD B2C is a separate customer identity service with its own tenant configuration and is unrelated to adding domains to a standard Microsoft 365 tenant. Option E is incorrect because Windows DNS Manager only manages DNS zones and records on a DNS server; it cannot add a domain to Microsoft 365, though it may be used to create the verification records if the domain is hosted on that DNS server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Using the New-MsolDomain PowerShell cmdlet.

    Why this is correct

    The New-MsolDomain cmdlet comes from the legacy MSOnline module and directly invokes Microsoft Entra ID's domain registration API, creating an unverified domain object in the tenant's directory. After that, you run New-MsolDomainVerificationDns to obtain the TXT record and New-MsolDomain to re-verify once the record is live. It is a valid, scriptable method, though Microsoft now deprecates MSOnline in favor of Microsoft Graph.

  • ✗

    Using the Exchange admin center (EAC).

    Why it's wrong here

    The Exchange admin center (EAC) is scoped exclusively to Exchange Online workloads such as mailboxes, mail flow rules, and connectors. It does not expose any controls for tenant-level domain registration or verification because Exchange Online's accepted domains are derived from the directory's existing verified domain list. You must add and verify the domain at the tenant level first; only then does it appear in EAC as a routable SMTP namespace.

  • ✗

    Using the Azure AD B2C tenant configuration.

    Why it's wrong here

    Azure AD B2C is a separate identity service for external customer sign-in and its tenant configuration is entirely isolated from your organization's Microsoft 365 tenant. While you can add custom domains to a B2C tenant to brand its authentication endpoints, that action does not register the domain in the Microsoft 365 directory, nor does the B2C portal offer any way to modify the parent tenant's domain collection. B2C's domain settings are for its own policy and token endpoints only.

  • ✓

    Using the 'Add domain' wizard in the Microsoft 365 admin center.

    Why this is correct

    The 'Add domain' wizard in the Microsoft 365 admin center, located under Setup > Domains, is the primary guided GUI method for adding a custom domain. It walks you through entering the domain name, selecting how you will verify it, and then prompts you to create the required DNS record (typically TXT or MX) at your registrar. After verification, the wizard can also help configure default DNS records for Exchange, SharePoint, and Teams, making it the recommended user-friendly option.

  • ✗

    Using the Windows DNS Manager console.

    Why it's wrong here

    The Windows DNS Manager console (dnsmgmt.msc) is an MMC snap-in used to administer DNS zones on Windows servers or domain controllers. It operates only against the local DNS server database and has no API, management channel, or integration with the Microsoft 365 directory that maintains your tenant's domain list. It can only be used to create the public DNS verification record after the domain is already added to Microsoft 365, so it cannot be the method that adds the domain.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.