Microsoft 365 Identity and Services (MS-100) — Questions and Answers
Question 1: A Teams meeting policy is configured with 'Anonymous users can join a meeting' set to Off. What is the result?
- Meeting lobby is disabled
- External federated users cannot join
- Users without a Microsoft account cannot join (Correct answer)
- Only users in the same organization can join
Correct answer: Users without a Microsoft account cannot join
When anonymous join is disabled, users who are not authenticated with any Microsoft account (anonymous participants) are blocked from joining Teams meetings.
Question 2: A company needs to assess their current Microsoft 365 security posture against industry benchmarks. Which tool provides a quantified score with prioritized improvement actions?
- Microsoft Secure Score (Correct answer)
- Azure Advisor
- Service Trust Portal
- Microsoft Compliance Manager
Correct answer: Microsoft Secure Score
Microsoft Secure Score provides a numerical security posture rating and lists prioritized improvement actions to help organizations increase their defenses.
Question 3: A company needs to ensure that emails sent from Microsoft 365 are digitally signed to prove authenticity. Which technology should be deployed?
- DMARC
- SPF
- TLS encryption
- DKIM (DomainKeys Identified Mail) (Correct answer)
Correct answer: DKIM (DomainKeys Identified Mail)
DKIM adds a digital signature to outbound emails, allowing recipients to verify that messages genuinely originated from the sending domain.
Question 4: Which Microsoft 365 plan is required to use Advanced eDiscovery with custodian management and predictive coding?
- Microsoft 365 E5 (Correct answer)
- Microsoft 365 E1
- Microsoft 365 Business Premium
- Microsoft 365 E3
Correct answer: Microsoft 365 E5
Advanced eDiscovery (now Microsoft Purview eDiscovery Premium) with features like custodian hold, predictive coding, and conversation threading requires Microsoft 365 E5.
Question 5: An administrator needs to allow a service account to access Microsoft Graph API without user interaction. Which OAuth 2.0 flow should be used?
- Device code flow
- Client credentials flow (Correct answer)
- Authorization code flow
- On-behalf-of flow
Correct answer: Client credentials flow
The client credentials flow allows a service or daemon application to authenticate using its own credentials (app ID and secret/certificate) without user context.
Question 6: A multinational company must comply with Brazil's LGPD data protection law. Which Microsoft Purview capability helps discover where Brazilian citizen data is stored across Microsoft 365?
- Content Search with sensitive information types for Brazilian data (Correct answer)
- Microsoft Defender for Cloud Apps OAuth app inventory
- Compliance Manager LGPD assessment only
- Azure AD user attribute reports
Correct answer: Content Search with sensitive information types for Brazilian data
Content Search using Brazil-specific sensitive information types (like CPF numbers) identifies where Brazilian personal data resides across Exchange, SharePoint, and Teams.
Question 7: Northwind Traders acquires a subsidiary running its own Azure AD tenant. Employees from the subsidiary need read-only access to SharePoint Online sites in the parent tenant without creating new accounts. What should you configure?
- Cross-tenant synchronization with bidirectional writeback
- Azure AD B2C external identities
- Azure AD B2B collaboration with guest accounts (Correct answer)
- Azure AD Connect cloud sync between the two tenants
Correct answer: Azure AD B2B collaboration with guest accounts
Azure AD B2B collaboration allows external users from another tenant to access resources as guests without creating duplicate internal accounts.
Question 8: Under the EU-U.S. Data Privacy Framework, what must a US organization do before transferring personal data from the EU?
- Apply GDPR sensitivity labels to all transferred data
- Sign Standard Contractual Clauses with each EU data subject
- Obtain explicit consent from each EU data subject individually
- Self-certify with the US Department of Commerce under the framework (Correct answer)
Correct answer: Self-certify with the US Department of Commerce under the framework
US organizations must self-certify their adherence to the EU-U.S. Data Privacy Framework principles with the US Department of Commerce to lawfully receive EU personal data.
Question 9: Which feature in Microsoft Teams allows persistent, topic-based conversations that remain available to all channel members?
- Meeting recordings
- Private chats
- Live events
- Channel posts (Correct answer)
Correct answer: Channel posts
Channel posts in Microsoft Teams are persistent, threaded conversations visible to all members of that channel.
Question 10: A company wants to enforce MFA only when users sign in from outside the corporate network. Which Azure AD feature enables this with the least administrative overhead?
- Azure AD Identity Protection risk-based policies
- Azure AD Privileged Identity Management
- Per-user MFA settings in the Azure portal
- Conditional Access policy with a named location condition (Correct answer)
Correct answer: Conditional Access policy with a named location condition
A Conditional Access policy with a named location condition can require MFA only when users authenticate from outside defined trusted IP ranges.
Question 11: What is reflective practice in MS-100 - Microsoft 365 Identity and Services professional development?
- Only reflecting on successes
- Systematically examining experiences to gain insight and improve future practice (Correct answer)
- Writing personal diaries
- Avoiding past mistakes
Correct answer: Systematically examining experiences to gain insight and improve future practice
This is fundamental to MS-100 - Microsoft 365 Identity and Services practice. Systematically examining experiences to gain insight and improve future practice represents the professional standard for practical in the MS-100 certification framework.
Question 12: What Azure AD feature enables you to create automatic group membership based on user attribute values such as department or job title?
- Group writeback
- Dynamic groups (Correct answer)
- Nested groups
- Access packages
Correct answer: Dynamic groups
Dynamic groups use membership rules based on user attributes like department or job title to automatically add or remove members.
Question 13: A Microsoft 365 tenant admin needs to share planned service maintenance windows with department heads without giving them admin access. What is the best approach?
- Grant Service Support Administrator role
- Share the Service Health URL with external users
- Configure scheduled email digests from the Message Center (Correct answer)
- Assign the Message Center Reader role and share via the Microsoft 365 admin app
Correct answer: Configure scheduled email digests from the Message Center
Message Center email digest can be configured to automatically send summaries of upcoming changes and maintenance to designated recipients without requiring admin portal access.
Question 14: You have a Microsoft 365 tenant with an Environment1 Microsoft Power Platform environment. <br> <br> (default). A Microsoft Dataverse database is present in Environment 1. <br> <br> You create a user named User1 in the tenant. You give User1 a Microsoft Power Apps license. <br> <br> Which of the Environment1 security roles is immediately assigned to User1?
- None of the above
- Environment maker
- System customizer (Correct answer)
- Delegate
Correct answer: System customizer
When a user is created in a Microsoft 365 tenant and assigned a Microsoft Power Apps license, they are automatically assigned the 'System Customizer' security role in the default Microsoft Dataverse environment. This role grants them privileges to customize and create applications within Dataverse, enabling them to build and manage Power Apps solutions.
Question 15: What is the primary value of case study analysis in MS-100 - Microsoft 365 Identity and Services training?
- Replacing hands-on experience
- Learning only from failures
- Memorizing specific outcomes
- Developing critical thinking by applying theory to realistic professional scenarios (Correct answer)
Correct answer: Developing critical thinking by applying theory to realistic professional scenarios
This is fundamental to MS-100 - Microsoft 365 Identity and Services practice. Developing critical thinking by applying theory to realistic professional scenarios represents the professional standard for practical in the MS-100 certification framework.
Question 16: During a QA review of Teams governance, an admin finds that any user can create Teams. Which Microsoft 365 feature restricts Teams creation to authorized users only?
- Microsoft 365 group creation restriction via Microsoft Entra group policy (Correct answer)
- Teams app permission policies
- Teams meeting policies
- Conditional Access for Teams
Correct answer: Microsoft 365 group creation restriction via Microsoft Entra group policy
Microsoft 365 group creation is tied to Teams creation; restricting group creation to a specific security group in Microsoft Entra limits who can create new Teams.
Question 17: Under SOC 2 Type II requirements, an auditor requests evidence that Microsoft 365 admin activity is being logged. Which feature provides this audit trail?
- Microsoft Defender for Identity alerts
- Unified Audit Log in Microsoft Purview (Correct answer)
- Azure AD Sign-in logs only
- Microsoft Secure Score recommendations
Correct answer: Unified Audit Log in Microsoft Purview
The Unified Audit Log captures admin and user activity across Microsoft 365 services and can be exported to satisfy SOC 2 Type II audit evidence requirements.
Question 18: What role does data analytics play in MS-100 - Microsoft 365 Identity and Services practice?
- It is only for IT professionals
- It replaces professional judgment
- It creates unnecessary complexity
- It supports evidence-based decision making by identifying patterns and trends in relevant data (Correct answer)
Correct answer: It supports evidence-based decision making by identifying patterns and trends in relevant data
This is fundamental to MS-100 - Microsoft 365 Identity and Services practice. It supports evidence-based decision making by identifying patterns and trends in relevant data represents the professional standard for technology in the MS-100 certification framework.
Question 19: A department manager wants weekly summaries of their team's Microsoft Teams meeting hours and collaboration patterns. Which tool provides this data?
- Microsoft Teams admin center analytics
- Microsoft 365 Usage Reports admin view
- Microsoft Viva Insights personal and manager insights (Correct answer)
- Azure AD sign-in logs
Correct answer: Microsoft Viva Insights personal and manager insights
Microsoft Viva Insights provides managers with aggregated, privacy-protected data on their team's collaboration patterns including meeting hours and focus time.
Question 20: Which Azure AD Connect staging mode feature is used for?
- Providing a failover server that can be promoted to active
- Running Azure AD Connect on multiple servers simultaneously
- Both A and B (Correct answer)
- Testing synchronization rules without writing changes to Azure AD
Correct answer: Both A and B
Staging mode allows an Azure AD Connect server to import and sync data without exporting to Azure AD, useful for testing rule changes and as a warm standby for failover.
Question 21: How should MS-100 - Microsoft 365 Identity and Services professionals handle conflicts with stakeholders?
- Ignore stakeholder concerns
- Avoid all conflict
- Address issues professionally through active listening, finding common ground, and seeking resolution (Correct answer)
- Escalate immediately to management
Correct answer: Address issues professionally through active listening, finding common ground, and seeking resolution
This is fundamental to MS-100 - Microsoft 365 Identity and Services practice. Address issues professionally through active listening, finding common ground, and seeking resolution represents the professional standard for communication in the MS-100 certification framework.
Question 22: Which Azure AD authentication method generates a time-based one-time password (TOTP) that changes every 30 seconds?
- Microsoft Authenticator app TOTP (Correct answer)
- SMS text message
- Password hash synchronization
- Phone call verification
Correct answer: Microsoft Authenticator app TOTP
The Microsoft Authenticator app (and compatible TOTP apps) generates a 6-digit code that refreshes every 30 seconds as a second authentication factor.
Question 23: What is the importance of data security in MS-100 digital applications?
- Security is unnecessary for professional data
- Only financial data needs protection
- Security slows down work
- Protecting sensitive information from unauthorized access, breaches, and loss is essential (Correct answer)
Correct answer: Protecting sensitive information from unauthorized access, breaches, and loss is essential
This is fundamental to MS-100 - Microsoft 365 Identity and Services practice. Protecting sensitive information from unauthorized access, breaches, and loss is essential represents the professional standard for technology in the MS-100 certification framework.
Question 24: What is the maximum size of an Exchange Online mailbox for a Microsoft 365 E3 licensed user?
- 25 GB
- 100 GB (Correct answer)
- Unlimited with archive
- 50 GB
Correct answer: 100 GB
Microsoft 365 E3 licenses include a 100 GB primary mailbox and an unlimited archive mailbox when auto-expanding archiving is enabled.
Question 25: A tenant administrator wants to prevent users from creating new Microsoft 365 Groups without approval. Which Azure AD setting controls this?
- Conditional Access policy
- Group expiration policy
- Self-service group management settings (Correct answer)
- Group naming policy
Correct answer: Self-service group management settings
The self-service group management settings in Azure AD allow administrators to restrict who can create Microsoft 365 Groups.
Question 26: Which feature in Azure AD Connect allows selective synchronization of specific attributes from on-premises AD to Azure AD without syncing all attributes?
- Delta synchronization
- Object exclusion rules
- Attribute flow customization in sync rules (Correct answer)
- Attribute-based filtering
Correct answer: Attribute flow customization in sync rules
Custom synchronization rules in Azure AD Connect allow administrators to configure which specific attributes flow from on-premises AD to Azure AD and how they are transformed.
Question 27: When researching which Microsoft 365 plan is required for using Azure AD Privileged Identity Management (PIM), what is the authoritative evidence source?
- Azure Active Directory pricing and licensing documentation (Correct answer)
- Microsoft 365 admin center license comparison tool
- The Azure portal PIM blade UI prompts
- Microsoft Q&A community forum answers
Correct answer: Azure Active Directory pricing and licensing documentation
Microsoft's Azure Active Directory pricing and licensing documentation explicitly states that PIM requires Azure AD Premium P2 or Microsoft 365 E5.
Question 28: A global admin reviews the 'Users flagged for risk' report and sees a user with a 'High' risk level. The user's risk was triggered by 'Leaked credentials'. What is the recommended immediate action?
- Disable all Conditional Access policies temporarily
- Remove the user's MFA registration
- Require the user to reset their password and dismiss the risk after verification (Correct answer)
- Delete the user account immediately
Correct answer: Require the user to reset their password and dismiss the risk after verification
For leaked credentials, the best practice is to require an immediate password reset (to invalidate the compromised credential) and then dismiss the risk after confirming the account is secure.
Question 29: An administrator needs to verify that a user's Azure AD password is synchronized correctly from on-premises Active Directory. Which tool should be used?
- Microsoft 365 Connectivity Analyzer
- Azure AD Connect Health (Correct answer)
- Active Directory Users and Computers
- ADFS Event Viewer
Correct answer: Azure AD Connect Health
Azure AD Connect Health monitors the synchronization health of on-premises AD with Azure AD, including password hash synchronization status.
Question 30: Which Microsoft 365 admin center report shows the number of active users per service over the last 7, 30, 90, or 180 days?
- Microsoft 365 active users report (Correct answer)
- Azure AD sign-in logs
- Exchange message trace
- Secure Score report
Correct answer: Microsoft 365 active users report
The Microsoft 365 active users report in the admin center tracks how many users are actively using each service over selectable time periods.
Microsoft 365 Identity and Services (MS-100)
MS-100 validates skills in deploying and managing Microsoft 365 tenants, managing user identity and roles, managing access and authentication, and planning Microsoft 365 workloads and applications. It was retired July 31, 2023 and replaced by MS-102.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds