Microsoft 365 Identity and Services (MS-100) — Questions and Answers
Question 1: An administrator needs to verify that a user's Azure AD password is synchronized correctly from on-premises Active Directory. Which tool should be used?
- Active Directory Users and Computers
- Azure AD Connect Health (Correct answer)
- ADFS Event Viewer
- Microsoft 365 Connectivity Analyzer
Correct answer: Azure AD Connect Health
Azure AD Connect Health monitors the synchronization health of on-premises AD with Azure AD, including password hash synchronization status.
Question 2: Which Azure AD Connect staging mode feature is used for?
- Both A and B (Correct answer)
- Testing synchronization rules without writing changes to Azure AD
- Running Azure AD Connect on multiple servers simultaneously
- Providing a failover server that can be promoted to active
Correct answer: Both A and B
Staging mode allows an Azure AD Connect server to import and sync data without exporting to Azure AD, useful for testing rule changes and as a warm standby for failover.
Question 3: A Microsoft 365 administrator needs to allow a partner organization's users to access a SharePoint site without creating accounts in their tenant. Which feature enables this?
- Azure AD External Identities B2C
- Guest access via Microsoft Accounts only
- Azure AD B2B collaboration (Correct answer)
- Federation trust
Correct answer: Azure AD B2B collaboration
Azure AD B2B collaboration lets external users from partner organizations access resources using their own organizational credentials.
Question 4: Which dashboard in the Microsoft 365 admin center provides metrics such as active users, email activity, and OneDrive storage consumption?
- Reports Dashboard (Correct answer)
- Security Dashboard
- Service Health Dashboard
- Compliance Dashboard
Correct answer: Reports Dashboard
The Reports Dashboard aggregates usage data across Microsoft 365 workloads including active user counts, email activity, Teams usage, and OneDrive storage trends.
Question 5: Which Microsoft 365 tool provides a centralized dashboard for managing and reviewing regulatory compliance posture across multiple frameworks?
- Microsoft Purview Compliance Manager (Correct answer)
- Azure Security Center
- Microsoft Secure Score
- Microsoft Defender for Cloud
Correct answer: Microsoft Purview Compliance Manager
Microsoft Purview Compliance Manager provides a central dashboard with assessments, improvement actions, and scores across compliance frameworks like ISO 27001 and GDPR.
Question 6: What is the primary purpose of regulatory compliance in MS-100 - Microsoft 365 Identity and Services practice?
- To create bureaucratic burden
- To benefit regulators only
- To limit competition
- To protect public safety, ensure quality standards, and maintain professional accountability (Correct answer)
Correct answer: To protect public safety, ensure quality standards, and maintain professional accountability
This is fundamental to MS-100 - Microsoft 365 Identity and Services practice. To protect public safety, ensure quality standards, and maintain professional accountability represents the professional standard for regulatory in the MS-100 certification framework.
Question 7: Which Microsoft 365 compliance feature allows an organization to place a mailbox on hold so that emails cannot be permanently deleted even by the user?
- In-Place Archive
- Retention labels
- Litigation Hold (Correct answer)
- eDiscovery case hold
Correct answer: Litigation Hold
Litigation Hold preserves all mailbox content indefinitely, preventing users or admins from permanently deleting items.
Question 8: A multinational company must comply with Brazil's LGPD data protection law. Which Microsoft Purview capability helps discover where Brazilian citizen data is stored across Microsoft 365?
- Content Search with sensitive information types for Brazilian data (Correct answer)
- Azure AD user attribute reports
- Microsoft Defender for Cloud Apps OAuth app inventory
- Compliance Manager LGPD assessment only
Correct answer: Content Search with sensitive information types for Brazilian data
Content Search using Brazil-specific sensitive information types (like CPF numbers) identifies where Brazilian personal data resides across Exchange, SharePoint, and Teams.
Question 9: An organization needs to enforce a minimum password length of 14 characters for all cloud-only Azure AD accounts. Where should this policy be configured?
- Azure AD Password Protection
- Azure AD Smart Lockout
- Azure AD Custom Banned Passwords
- Microsoft 365 admin center password policy (Correct answer)
Correct answer: Microsoft 365 admin center password policy
Cloud-only Azure AD account password policies (minimum length, complexity) are configured in the Microsoft 365 admin center under Security settings.
Question 10: Which Microsoft 365 identity feature allows users to register once and access all Microsoft 365 applications without repeated sign-in prompts?
- Azure AD B2C
- Seamless Single Sign-On (SSO) (Correct answer)
- Federation Services
- Pass-through Authentication
Correct answer: Seamless Single Sign-On (SSO)
Azure AD Seamless SSO automatically signs in users on corporate devices connected to the corporate network without requiring additional credentials.
Question 11: Why is documentation important in MS-100 risk management?
- It is optional paperwork
- It creates an audit trail, supports decision-making, and demonstrates due diligence (Correct answer)
- It slows down operations
- It only benefits legal teams
Correct answer: It creates an audit trail, supports decision-making, and demonstrates due diligence
This is fundamental to MS-100 - Microsoft 365 Identity and Services practice. It creates an audit trail, supports decision-making, and demonstrates due diligence represents the professional standard for risk management in the MS-100 certification framework.
Question 12: Which Azure AD authentication method generates a time-based one-time password (TOTP) that changes every 30 seconds?
- SMS text message
- Microsoft Authenticator app TOTP (Correct answer)
- Password hash synchronization
- Phone call verification
Correct answer: Microsoft Authenticator app TOTP
The Microsoft Authenticator app (and compatible TOTP apps) generates a 6-digit code that refreshes every 30 seconds as a second authentication factor.
Question 13: Which Microsoft 365 admin center report shows the number of active users per service over the last 7, 30, 90, or 180 days?
- Microsoft 365 active users report (Correct answer)
- Exchange message trace
- Azure AD sign-in logs
- Secure Score report
Correct answer: Microsoft 365 active users report
The Microsoft 365 active users report in the admin center tracks how many users are actively using each service over selectable time periods.
Question 14: Which Microsoft 365 service enables organizations to create external-facing websites and intranets using a no-code approach?
- Microsoft Forms
- SharePoint Communication Sites (Correct answer)
- Microsoft Stream
- Viva Connections
Correct answer: SharePoint Communication Sites
SharePoint Communication Sites allow organizations to build intranet portals and external-facing websites with minimal coding.
Question 15: What is the role of professional journals in MS-100 - Microsoft 365 Identity and Services practice?
- They are outdated by publication time
- They disseminate current research, best practices, and professional developments (Correct answer)
- They are optional reading
- They only benefit academics
Correct answer: They disseminate current research, best practices, and professional developments
This is fundamental to MS-100 - Microsoft 365 Identity and Services practice. They disseminate current research, best practices, and professional developments represents the professional standard for research in the MS-100 certification framework.
Question 16: How should an MS-100 professional respond to a compliance violation?
- Report it promptly, investigate the root cause, and implement corrective actions (Correct answer)
- Blame the regulatory framework
- Conceal it if minor
- Wait for an external audit to find it
Correct answer: Report it promptly, investigate the root cause, and implement corrective actions
This is fundamental to MS-100 - Microsoft 365 Identity and Services practice. Report it promptly, investigate the root cause, and implement corrective actions represents the professional standard for regulatory in the MS-100 certification framework.
Question 17: Which Microsoft 365 service provides real-time co-authoring capabilities that allow multiple users to edit a Word document simultaneously?
- Office Online (Microsoft 365 Apps for the web) (Correct answer)
- OneDrive for Business
- SharePoint Online
- Microsoft Teams
Correct answer: Office Online (Microsoft 365 Apps for the web)
Office Online (Microsoft 365 Apps for the web) enables real-time co-authoring so multiple users can edit documents simultaneously in a browser.
Question 18: When planning an Exchange migration to Exchange Online, what is the recommended approach for selecting the migration method?
- Always use a certified third-party migration tool
- Assess size, complexity, and timeline to choose cutover, staged, or hybrid migration (Correct answer)
- Always perform a cutover migration regardless of organization size
- Migrate all mailboxes simultaneously during a single maintenance window
Correct answer: Assess size, complexity, and timeline to choose cutover, staged, or hybrid migration
The appropriate migration method depends on factors such as the number of mailboxes, coexistence requirements, and migration timeline, making assessment essential before choosing between cutover, staged, or hybrid approaches.
Question 19: An organization wants to require additional verification when a sign-in risk level is 'High'. Which Identity Protection policy type should be configured?
- Sign-in risk policy (Correct answer)
- MFA registration policy
- User risk policy
- Conditional Access named location policy
Correct answer: Sign-in risk policy
A sign-in risk policy in Identity Protection evaluates real-time risk signals during authentication and can enforce MFA or block access based on the detected risk level.
Question 20: Which Microsoft 365 feature allows an IT admin to create and enforce acceptable use policies for end users?
- Microsoft Purview DLP
- Intune Compliance policies
- Azure AD Terms of Use (Correct answer)
- Conditional Access policies
Correct answer: Azure AD Terms of Use
Azure AD Terms of Use requires users to accept a policy before accessing applications, enforcing acceptable use standards.
Question 21: Which Azure AD Identity Protection risk detection identifies sign-ins from anonymous IP addresses such as Tor browsers?
- Malware-linked IP address
- Impossible travel
- Leaked credentials
- Anonymous IP address (Correct answer)
Correct answer: Anonymous IP address
The Anonymous IP address risk detection flags sign-ins originating from anonymous proxies or Tor network exit nodes.
Question 22: Which feature in Azure AD Connect allows selective synchronization of specific attributes from on-premises AD to Azure AD without syncing all attributes?
- Object exclusion rules
- Attribute flow customization in sync rules (Correct answer)
- Attribute-based filtering
- Delta synchronization
Correct answer: Attribute flow customization in sync rules
Custom synchronization rules in Azure AD Connect allow administrators to configure which specific attributes flow from on-premises AD to Azure AD and how they are transformed.
Question 23: Which Microsoft 365 service allows organizations to host and share recorded video content internally, similar to an enterprise version of YouTube?
- Microsoft Sway
- SharePoint Pages
- Microsoft Stream (Correct answer)
- Viva Learning
Correct answer: Microsoft Stream
Microsoft Stream is the enterprise video service within Microsoft 365 that allows uploading, sharing, and viewing of video recordings internally.
Question 24: An organization is deploying Microsoft 365 Apps for Enterprise. Which deployment method gives IT the most control over update channels and installation configurations?
- Office Deployment Tool (ODT) with a configuration XML (Correct answer)
- Direct download from Office.com by end users
- Microsoft Intune with default settings only
- Microsoft Store deployment
Correct answer: Office Deployment Tool (ODT) with a configuration XML
The Office Deployment Tool (ODT) with a custom configuration XML gives administrators full control over which apps are installed, update channels, languages, and settings.
Question 25: Which Microsoft 365 admin center section provides a readiness check and guided setup for deploying new Microsoft 365 services?
- Reports > Usage
- Setup > Guided setup (Correct answer)
- Health > Service health
- Settings > Org settings
Correct answer: Setup > Guided setup
The Setup section of the Microsoft 365 admin center offers guided, step-by-step deployment wizards for services like Teams, Exchange, and security features.
Question 26: What is the purpose of the Microsoft 365 Message Center in the admin center?
- To track phishing reports from users
- To notify admins of upcoming service changes and new features (Correct answer)
- To send email announcements to all users
- To manage user message rules in Exchange Online
Correct answer: To notify admins of upcoming service changes and new features
The Message Center publishes planned changes, new features, and actionable advisories that admins need to be aware of.
Question 27: What does the Azure AD 'Sign-in risk' policy in Identity Protection evaluate?
- The probability that a specific authentication request was not initiated by the account owner (Correct answer)
- Whether the user is accessing from a named location
- Whether the device is compliant with Intune policies
- Whether the user account has been compromised
Correct answer: The probability that a specific authentication request was not initiated by the account owner
Sign-in risk evaluates the likelihood that a specific sign-in request was not made by the legitimate account owner based on behavioral and threat intelligence signals.
Question 28: TPT Limited has a Microsoft 365 subscription and a testpreptraining.com Azure Active Directory (Azure AD) tenant with Azure AD Identity Protection enabled. The tenant has a user named User1 who should be able to check the list of users who have been flagged for risk in Azure AD Identity Protection. <br> <br? According to the concept of least privilege, which role should be provided to User1?
- Compliance administrator
- Security reader (Correct answer)
- Global administrator
- Reports reader
Correct answer: Security reader
To allow User1 to check the list of users flagged for risk in Azure AD Identity Protection while adhering to the principle of least privilege, the Security Reader role should be assigned. This role provides read-only access to security-related information, including identity protection reports and risk detections, without granting any permissions to modify settings or user accounts.
Question 29: Which Microsoft 365 feature allows administrators to set policies that automatically classify and label documents based on sensitive content like credit card numbers?
- Auto-labeling policies using sensitivity labels (Correct answer)
- Communication compliance
- Data Loss Prevention (DLP) policies
- Retention policies
Correct answer: Auto-labeling policies using sensitivity labels
Auto-labeling policies apply sensitivity labels automatically when documents or emails contain sensitive information types like credit card numbers.
Question 30: What is the purpose of Microsoft 365 Message Encryption (OME)?
- Encrypts data at rest in Exchange Online
- Allows sending encrypted emails to any recipient regardless of their email provider (Correct answer)
- Enforces S/MIME certificates for internal email
- Prevents external email forwarding
Correct answer: Allows sending encrypted emails to any recipient regardless of their email provider
OME (Office Message Encryption) allows users to send encrypted emails to any external recipient including Gmail or Yahoo addresses without requiring special software.
Question 31: What distinguishes a peer-reviewed study in MS-100 - Microsoft 365 Identity and Services literature?
- It was published quickly
- It was published in any format
- It was written by multiple authors
- Independent experts in the field evaluated the methodology and conclusions before publication (Correct answer)
Correct answer: Independent experts in the field evaluated the methodology and conclusions before publication
This is fundamental to MS-100 - Microsoft 365 Identity and Services practice. Independent experts in the field evaluated the methodology and conclusions before publication represents the professional standard for research in the MS-100 certification framework.
Question 32: Adatum Corporation wants to ensure that devices must be compliant with Intune policies before accessing Exchange Online. Users on non-compliant devices should be blocked. What should be configured?
- Exchange Online mobile device mailbox policies
- Intune app protection policies for Outlook Mobile
- Azure AD Conditional Access policy requiring device compliance (Correct answer)
- Microsoft Defender for Endpoint device risk-based access
Correct answer: Azure AD Conditional Access policy requiring device compliance
A Conditional Access policy with a device compliance grant condition blocks access to Exchange Online from devices not marked compliant by Intune.
Question 33: An organization's quality review finds that the Microsoft 365 Message Center has hundreds of unread items. What is the recommended practice for managing Message Center communications?
- Delegate all messages to the help desk team
- Enable automatic message dismissal after 7 days
- Archive all messages older than 30 days
- Assign Message Center readers and use Planner integration to track action items (Correct answer)
Correct answer: Assign Message Center readers and use Planner integration to track action items
Assigning dedicated Message Center readers and using the built-in Planner integration helps track which messages require action and ensures service change communications are not missed.
Question 34: A team is assessing whether Microsoft 365 meets GDPR requirements for their EU operations. Which Microsoft resource provides evidence-based compliance documentation?
- The Microsoft 365 Message Center
- Microsoft 365 usage analytics reports
- Bing search results for 'Microsoft GDPR'
- Microsoft Trust Center at microsoft.com/trust-center (Correct answer)
Correct answer: Microsoft Trust Center at microsoft.com/trust-center
The Microsoft Trust Center hosts compliance documentation, audit reports, and certifications including GDPR, ISO, and SOC to support evidence-based compliance decisions.
Question 35: What is the purpose of Microsoft 365 Usage Analytics?
- To analyze email flow and delivery statistics
- To monitor real-time service performance and latency
- To generate regulatory compliance audit reports
- To track service adoption and usage patterns across the organization (Correct answer)
Correct answer: To track service adoption and usage patterns across the organization
Microsoft 365 Usage Analytics provides Power BI-based insights into how the organization is adopting and using Microsoft 365 workloads, helping administrators drive adoption.
Question 36: Northwind Traders acquires a subsidiary running its own Azure AD tenant. Employees from the subsidiary need read-only access to SharePoint Online sites in the parent tenant without creating new accounts. What should you configure?
- Azure AD Connect cloud sync between the two tenants
- Cross-tenant synchronization with bidirectional writeback
- Azure AD B2B collaboration with guest accounts (Correct answer)
- Azure AD B2C external identities
Correct answer: Azure AD B2B collaboration with guest accounts
Azure AD B2B collaboration allows external users from another tenant to access resources as guests without creating duplicate internal accounts.
Question 37: An administrator runs a report and finds that Microsoft Secure Score dropped by 15 points. Which action is most appropriate?
- Disable all third-party app integrations
- Enable Conditional Access for all users
- Immediately reset all user passwords
- Review the score breakdown to identify which controls regressed (Correct answer)
Correct answer: Review the score breakdown to identify which controls regressed
A drop in Secure Score should trigger a review of the score breakdown to find which specific recommended controls are no longer in place before taking corrective action.
Question 38: What is the key advantage of Password Hash Synchronization (PHS) over Pass-through Authentication (PTA) in Azure AD Connect?
- PHS is required for Conditional Access policies
- PHS is more secure because passwords never leave the on-premises network
- PHS supports smarter password policies
- PHS provides authentication continuity if on-premises infrastructure is unavailable (Correct answer)
Correct answer: PHS provides authentication continuity if on-premises infrastructure is unavailable
PHS stores a hash of the password hash in Azure AD, allowing cloud authentication to continue even when on-premises AD is offline or unreachable.
Question 39: A company's security team discovers that several Azure AD accounts have been compromised through credential stuffing. They need to automatically block sign-ins from these risky accounts. Which solution addresses this with the least manual effort?
- Enable Azure AD smart lockout with a low threshold
- Manually disable each compromised account in Azure AD
- Enable Conditional Access requiring MFA for all users
- Configure Azure AD Identity Protection user risk policy to block high-risk users (Correct answer)
Correct answer: Configure Azure AD Identity Protection user risk policy to block high-risk users
An Identity Protection user risk policy can automatically block or require password change for accounts flagged as high risk, without manual intervention per account.
Question 40: Which report in the Azure AD portal lists all sign-ins that were flagged as risky and the specific detections that triggered the flag?
- Risky sign-ins report (Correct answer)
- Audit logs
- Sign-in logs
- Provisioning logs
Correct answer: Risky sign-ins report
The Risky sign-ins report in Identity Protection consolidates sign-ins with associated risk detections, showing the risk level and detection types that triggered each event.
Question 41: What is the maximum number of objects that can be synchronized to a single Azure AD tenant using Azure AD Connect?
- 300,000
- 100,000
- 500,000 (Correct answer)
- 1,000,000
Correct answer: 500,000
A single Azure AD tenant supports up to 500,000 objects when synchronized using Azure AD Connect from an on-premises directory.
Question 42: When planning an Azure AD Conditional Access policy rollout, what evidence-based tool helps administrators simulate policy impact before going live?
- What If tool in Azure AD Conditional Access (Correct answer)
- Intune device compliance reports
- Microsoft 365 Compliance score dashboard
- Azure AD Audit Logs from previous weeks
Correct answer: What If tool in Azure AD Conditional Access
The What If tool in Azure AD Conditional Access simulates which policies would apply to a specific user, app, and sign-in condition, providing pre-deployment evidence.
Question 43: A healthcare organization wants to classify documents containing patient record numbers automatically. Which Microsoft Purview capability uses pre-trained models to identify this sensitive content type?
- Exact Data Match (EDM) classification
- Trainable classifiers
- Built-in sensitive information types (Correct answer)
- Custom keyword dictionaries
Correct answer: Built-in sensitive information types
Built-in sensitive information types use pattern matching and checksums to detect regulated data like patient IDs, SSNs, and credit card numbers without custom configuration.
Question 44: Which Exchange Online feature allows an administrator to search for and recover emails that were permanently deleted by a user within a defined retention window?
- Litigation Hold
- Recoverable Items folder (Correct answer)
- Journaling
- Archive mailbox
Correct answer: Recoverable Items folder
The Recoverable Items folder retains permanently deleted items for a configurable period, allowing administrators to recover them via eDiscovery or content search.
Question 45: An administrator wants to restrict which OAuth 2.0 applications can access Microsoft 365 data on behalf of users. Which Azure AD feature should they configure?
- Privileged Identity Management
- Conditional Access policies
- App consent policies (Correct answer)
- Identity Protection risk policies
Correct answer: App consent policies
App consent policies in Azure AD control whether users can consent to third-party OAuth applications accessing Microsoft 365 data.
Question 46: An administrator reviews the Microsoft Secure Score dashboard and notices an improvement action to 'Enable Identity Protection sign-in risk policies'. What does implementing this action primarily mitigate?
- Unauthorized access from risky authentication events (Correct answer)
- Data exfiltration via email
- Malware on managed endpoints
- Excessive admin role assignments
Correct answer: Unauthorized access from risky authentication events
Sign-in risk policies in Identity Protection mitigate unauthorized access by enforcing controls like MFA or blocking when suspicious sign-in behavior is detected.
Question 47: An admin needs evidence on the exact retention period for Microsoft's deletion of customer data after a Microsoft 365 subscription expires. Which document is authoritative?
- Microsoft's community support forums
- Microsoft Online Services Terms (OST) or Data Protection Addendum (DPA) (Correct answer)
- Azure AD audit logs after subscription expiry
- The Microsoft 365 admin center billing cancellation page
Correct answer: Microsoft Online Services Terms (OST) or Data Protection Addendum (DPA)
The Microsoft Online Services Terms (OST) and Data Protection Addendum (DPA) contractually specify that Microsoft retains data for 90 days after subscription termination before deletion.
Question 48: A company needs to ensure that emails sent from Microsoft 365 are digitally signed to prove authenticity. Which technology should be deployed?
- DMARC
- SPF
- DKIM (DomainKeys Identified Mail) (Correct answer)
- TLS encryption
Correct answer: DKIM (DomainKeys Identified Mail)
DKIM adds a digital signature to outbound emails, allowing recipients to verify that messages genuinely originated from the sending domain.
Question 49: Which tool in the Microsoft 365 admin center lets an administrator check whether a specific message was delivered to a recipient's mailbox?
- Audit log search
- Mail flow dashboard
- Delivery reports
- Message trace (Correct answer)
Correct answer: Message trace
Message trace in the Exchange admin center allows administrators to trace the path of an email message and confirm its delivery status or identify delivery failures.
Question 50: What role does data analytics play in MS-100 - Microsoft 365 Identity and Services practice?
- It replaces professional judgment
- It supports evidence-based decision making by identifying patterns and trends in relevant data (Correct answer)
- It is only for IT professionals
- It creates unnecessary complexity
Correct answer: It supports evidence-based decision making by identifying patterns and trends in relevant data
This is fundamental to MS-100 - Microsoft 365 Identity and Services practice. It supports evidence-based decision making by identifying patterns and trends in relevant data represents the professional standard for technology in the MS-100 certification framework.
Microsoft 365 Identity and Services (MS-100)
MS-100 validates skills in deploying and managing Microsoft 365 tenants, managing user identity and roles, managing access and authentication, and planning Microsoft 365 workloads and applications. It was retired July 31, 2023 and replaced by MS-102.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds