Microsoft

MS-102 Free Practice Questions

This is the free Microsoft MS-102 practice question bank — 220 of 430 total questions, each with a full explanation, free to read with no signup required. Updated 2026-08-05.

Every answer is verified against official Microsoft documentation — see our methodology.

Question 1

You have a Microsoft 365 subscription. The Microsoft Secure Score for the subscription is 60, and the achievable score is 75. You need to apply a Conditional Access policy that will require users to use multifactor authentication (MFA) when they connect from an untrusted device. How will the policy affect the scores?

A. The Secure Score and the achievable score will increase.
B. The Secure Score and the achievable score will remain unchanged.
C. The Secure Score will decrease, and the achievable score will increase.
D. The Secure Score will increase, and the achievable score will decrease.
Show Answer
Correct Answer: D
Explanation:
Implementing a Conditional Access policy that requires MFA satisfies a Microsoft Secure Score improvement, so the current Secure Score increases. The achievable score represents the remaining score available from recommendations not yet implemented, so after completing one recommendation, the remaining achievable score decreases.

Question 2

HOTSPOT - Your company has a Microsoft 365 E5 tenant. Users at the company use the following versions of Microsoft Office: • Microsoft 365 Apps for enterprise • Office for the web • Office 2021 • Office 2024 The company currently uses the following Office file types: • .docx • .xlsx • .doc • .xls You plan to use sensitivity labels. You need to identify the following: • Which versions of Office support the sensitivity labels. • Which file types support the sensitivity labels. What should you identify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 2
Show Answer
Correct Answer: Office versions: Microsoft 365 Apps for enterprise and Office for the web only File types: .docx and .xlsx
Explanation:
Built-in sensitivity labeling is supported in Microsoft 365 Apps and Office for the web. Sensitivity labels apply to modern Office Open XML formats (.docx, .xlsx), not the legacy binary .doc and .xls formats.

Question 3

You have a Microsoft 365 E5 subscription that contains a Windows 11 device named Device1 and a user named User1. User1 works at a branch office and reports slow connections to Microsoft 365 services. You need to ensure that User1 can test the connections by running the Microsoft 365 network connectivity test tool on Device1. The solution must follow the principle of least privilege To which group should you add User1 for Device1?

A. Power Users
B. Network Configuration Operators
C. Users
D. Administrators
Show Answer
Correct Answer: D
Explanation:
The Microsoft 365 Network Connectivity Test Tool documentation states that the person running the advanced test on a Windows machine should have administrative permissions. Membership in the local Administrators group provides the required rights. Although Network Configuration Operators has limited networking privileges, it does not satisfy the documented requirement. Therefore, based on the documented prerequisite, the correct choice is Administrators.

Question 4

HOTSPOT - Your network contains an on-premises Active Directory Domain Services (AD DS) domain. The domain contains a user named User1. You have a Microsoft Entra tenant that contains a user named User2. You plan to use Microsoft Entra Cloud Sync to sync the AD DS domain and the Microsoft Entra tenant. You need to ensure that User1 can install Microsoft Entra Cloud Sync in the domain, and User2 can configure Microsoft Entra Cloud Sync in the tenant. The solution must follow the principle of least privilege. To which group should you add User1, and which role should you assign to User2? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 4
Show Answer
Correct Answer: User1: Administrators User2: Hybrid Identity Administrator
Explanation:
Installing the Microsoft Entra Cloud Sync provisioning agent requires local administrator rights on the server (Administrators group), not Domain Admins. Configuring Cloud Sync in Microsoft Entra follows least privilege by assigning the Hybrid Identity Administrator role rather than Global Administrator.

Question 5

Your network contains an on-premises Active Directory Domain Services (AD DS) domain. The domain contains two organizational units (OUs) named OU1 and OU2 and the users shown in the following table. You have a Microsoft Entra tenant. You plan to sync the domain with the Microsoft Entra tenant by using Microsoft Entra Connect Sync. You need to ensure that only users in the sales and marketing departments sync with the tenant. The solution must minimize administrative effort. What should you configure in Microsoft Entra Connect?

A. OU-based filtering
B. domain-based filtering
C. group-based filtering
D. attribute-based filtering
Show Answer
Correct Answer: D
Explanation:
Use attribute-based filtering because the requirement is to synchronize only users whose department is Sales or Marketing regardless of their OU. Filtering on the Department attribute minimizes ongoing administration compared to maintaining groups, and OU-based or domain-based filtering cannot selectively include only those departments if users are mixed within OUs.

Question 6

Your network contains an on-premises Active Directory Domain Services (AD DS) forest. You have a Microsoft Entra tenant. You implement Microsoft Entra Connect Sync. The synchronization fails to complete. You review the logs and discover the following error message: "We found an issue with the service account that is used to run Microsoft Entra Connect Sync". You need to ensure that the synchronization completes successfully. The solution must minimize administrative effort. What should you do?

A. From the Microsoft Entra admin center, reset the password of the Microsoft Entra Connect Sync account.
B. From PowerShell, run the Repair-AADCloudSyncToolsAccount cmdlet.
C. From Active Directory Users and Computers, reset the password or the ADSync service account.
D. From PowerShell, run the Set-ADSyncScheduler cmdlet.
Show Answer
Correct Answer: C
Explanation:
The error indicates a problem with the on-premises service account used to run Microsoft Entra Connect Sync (the ADSync service account). Resetting or repairing that service account in Active Directory is the appropriate fix. The Repair-AADCloudSyncToolsAccount cmdlet applies to Microsoft Entra Cloud Sync, not Entra Connect Sync. Resetting the cloud sync account in Entra does not address the local service account, and Set-ADSyncScheduler only configures scheduling, not service account authentication.

Question 7

Your on-premises network contains an Active Directory Domain Services (AD DS) domain. You have a Microsoft 365 E5 subscription. You plan to implement Microsoft Entra Connect Sync and use Microsoft Entra ID Protection. You need to configure Microsoft Entra Connect Sync to ensure that Microsoft Entra ID Protection can detect leaked credentials. What should you select?

A. Password writeback
B. Password Hash Synchronization
C. Configure Hybrid Microsoft Entra join
D. Pass-through authentication
E. Enable single sign-on
Show Answer
Correct Answer: B
Explanation:
Microsoft Entra ID Protection's leaked credentials detection for hybrid identities requires Password Hash Synchronization (PHS). Entra Connect synchronizes a hash of the on-premises password hash to Microsoft Entra ID, enabling Microsoft to compare it against known compromised credentials. Password writeback is for resetting passwords from the cloud to on-premises, pass-through authentication and seamless SSO do not provide the password hash needed for leaked credential detection, and Hybrid Entra join is unrelated.

Question 8

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the devices shown in the following table. All the devices are onboarded to Microsoft Defender for Endpoint. You plan to use Microsoft Defender Vulnerability Management to meet the following requirements: • Detect operating system vulnerabilities. • Perform a configuration assessment of the operating system. Which devices support each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 8 Illustration for MS-102 question 8
Show Answer
Correct Answer: Detect operating system vulnerabilities: Device1, Device2, and Device3 Perform a configuration assessment of the operating system: Device1 only
Explanation:
Microsoft Defender Vulnerability Management detects OS vulnerabilities across supported Windows, Android, and iOS devices onboarded to Defender for Endpoint. OS configuration assessment is supported for Windows devices, not Android or iOS.

Question 9

HOTSPOT - You have a Microsoft 365 subscription that contains two groups named Group1 and Group2. The subscription contains the users shown in the following table. The users are directly assigned licenses as shown in the following table. The groups are assigned licenses as shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 9 Illustration for MS-102 question 9 Illustration for MS-102 question 9 Illustration for MS-102 question 9
Show Answer
Correct Answer: Yes Yes Yes
Explanation:
A disabled service in one license assignment does not block the same service from another direct or group-based assignment. User1 has a direct E5 with Planner enabled. User2 receives E5 from both groups, and Group2 enables Planner. User3 has a direct E5 with Planner disabled but also inherits an enabled E5 from Group2, so Planner is enabled.

Question 10

You have a Microsoft 365 subscription. You create a Microsoft Defender Threat Intelligence (Defender TI) project named Project1. You need to add artifacts to Project1. Which type of artifact can you add to Project1?

A. Microsoft SharePoint Online sites
B. network segments
C. IP addresses
D. Microsoft Entra users
Show Answer
Correct Answer: C
Explanation:
Microsoft Defender Threat Intelligence projects are used to organize and track threat intelligence artifacts such as IP addresses, domains, and hosts. Among the options provided, only IP addresses are supported project artifacts. SharePoint Online sites, network segments, and Microsoft Entra users are not supported artifact types for Defender TI projects.

$19

Get all 430 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.