MS-100 Cheat Sheet 2026
The 30 highest-yield MS-100 facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
50 questions
120 min time limit
70.00% to pass
- When a new Microsoft 365 tenant is created, what is the format of the initial domain that Microsoft automatically assigns? → .onmicrosoft.com
- Stakeholders need a single communication channel to track Microsoft 365 incidents and planned maintenance. Which configuration achieves this with minimal setup? → Configure Service Health email notifications in the Microsoft 365 admin center
- An organization needs to enforce a minimum password length of 14 characters for all cloud-only Azure AD accounts. Where should this policy be configured? → Microsoft 365 admin center password policy
- Which professional competency is most critical when an MS-100 administrator communicates a planned maintenance window to business stakeholders? → Clear communication of impact, duration, and rollback plan
- An organization wants to require additional verification when a sign-in risk level is 'High'. Which Identity Protection policy type should be configured? → Sign-in risk policy
- What is the importance of data security in MS-100 digital applications? → Protecting sensitive information from unauthorized access, breaches, and loss is essential
- Which Microsoft 365 tool allows administrators to monitor the adoption of Microsoft 365 services across their organization? → Microsoft 365 Usage Analytics
- Which Microsoft 365 competency involves ensuring that data loss prevention policies align with organizational regulatory requirements? → Compliance management
- An MS-100 exam candidate is unsure whether a specific Azure AD feature was recently deprecated. What is the most reliable way to verify current feature status? → Check the Azure AD 'What's new' documentation and release notes on learn.microsoft.com
- Which Microsoft 365 feature enables organizations to create custom workflows that automate repetitive business processes without writing code? → Power Automate
- How are Microsoft 365 tenant subscription licenses billed? → Per user, on a monthly or annual basis
- What is reflective practice in MS-100 - Microsoft 365 Identity and Services professional development? → Systematically examining experiences to gain insight and improve future practice
- Which on-premises Active Directory attribute is used as the primary matching anchor between on-premises users and their corresponding Azure AD objects? → ms-DS-ConsistencyGuid (sourceAnchor)
- What is the purpose of Microsoft 365 Usage Analytics? → To track service adoption and usage patterns across the organization
- How do MS-100 professionals build trust with clients or stakeholders? → Through consistent competence, transparency, reliability, and ethical behavior
- A compliance officer needs to notify specific stakeholders when sensitive data is detected in emails. Which Microsoft 365 feature handles this communication? → Data Loss Prevention incident reports
- In Microsoft 365 terminology, what is a 'vanity domain'? → A custom domain added to replace .onmicrosoft.com in user email addresses
- What role does peer review play in MS-100 - Microsoft 365 Identity and Services practice? → It provides quality assurance and professional development through collegial evaluation
- Which feature in Microsoft Teams allows persistent, topic-based conversations that remain available to all channel members? → Channel posts
- A Microsoft 365 administrator wants to verify that all user sign-ins are being audited. Which portal provides the Unified Audit Log for sign-in events? → Microsoft 365 compliance center
- Which tool should be used to diagnose Azure AD Connect synchronization errors, such as objects not appearing in Azure AD? → All of the above
- Which SharePoint Online permission level allows a user to view pages and list items but not edit them? → Read
- Which Azure AD Identity Protection risk detection identifies sign-ins from anonymous IP addresses such as Tor browsers? → Anonymous IP address
- Which Microsoft 365 feature allows administrators to classify and protect documents with visual markings and encryption based on content sensitivity? → Sensitivity labels
- An admin wants to ensure that no user can consent to third-party apps accessing Microsoft 365 data without admin approval. Which setting controls this? → User consent settings in Microsoft Entra Enterprise applications
- How should an MS-100 professional handle a situation outside their scope of competency? → Recognize limitations and refer to or consult with appropriate specialists
- What happens to a synchronized user account in Azure AD when the corresponding on-premises Active Directory account is deleted? → The Azure AD account is soft-deleted and placed in the recycle bin for 30 days
- An administrator is trying to determine root cause of recurring Azure AD user account lockouts. What evidence-based investigation step should come first? → Review the Azure AD Sign-in logs filtered by 'Failure' status for the affected user
- Under GDPR, what is the maximum fine for the most serious violations, such as failure to obtain valid consent for data processing? → €20 million or 4% of global annual turnover
- When evaluating Azure AD Identity Protection risk detections in your tenant, which report provides real evidence of compromised credentials being used? → Risky sign-ins report in Azure AD Identity Protection
Turn these facts into recall:
Was this helpful?