MS-100 Professional Standards & Competencies 3 — Questions and Answers
Question 1: Which Microsoft 365 admin center section should an admin use to purchase and assign additional licenses to users?
- Settings > Org settings
- Billing > Purchase services (Correct answer)
- Reports > Usage
- Setup > Domains
Correct answer: Billing > Purchase services
The Billing > Purchase services section in the Microsoft 365 admin center is used to buy and manage subscriptions and licenses.
Question 2: An administrator must ensure that service accounts in Microsoft 365 are not used for interactive sign-ins. Which control enforces this?
- Assign them the Guest User role
- Block sign-in on the account in Azure AD (Correct answer)
- Remove their Exchange mailbox
- Disable their MFA registration
Correct answer: Block sign-in on the account in Azure AD
Blocking sign-in on a service account in Azure AD prevents interactive logins while allowing the account to function for automated tasks.
Question 3: What is the recommended Microsoft practice for managing emergency 'break-glass' accounts in Microsoft 365?
- Assign them to the Helpdesk Administrator role only
- Store credentials in a shared team mailbox
- Exclude them from Conditional Access and MFA, monitor via alerts (Correct answer)
- Rotate passwords monthly using SSPR
Correct answer: Exclude them from Conditional Access and MFA, monitor via alerts
Break-glass accounts should be excluded from CA/MFA policies to ensure emergency access, and sign-in activity should be monitored with alerts.
Question 4: Which Microsoft 365 tool provides a centralized view of an organization's security posture and recommends improvement actions?
- Microsoft Compliance Manager
- Microsoft Secure Score (Correct answer)
- Azure Security Center
- Defender for Endpoint
Correct answer: Microsoft Secure Score
Microsoft Secure Score measures an organization's security posture and provides prioritized recommendations to improve it.
Question 5: An admin needs to ensure that all Microsoft 365 admin role assignments are reviewed periodically. Which Azure AD feature supports this?
- Azure AD Identity Protection
- Azure AD Access Reviews (Correct answer)
- Privileged Identity Management alerts
- Conditional Access named locations
Correct answer: Azure AD Access Reviews
Azure AD Access Reviews allow organizations to periodically certify that role assignments are still appropriate.
Question 6: A user reports that they are unable to access Microsoft 365 services from a personal device. An admin suspects a Conditional Access policy is blocking them. Where should the admin investigate?
- Azure AD > Sign-in logs > Conditional Access tab (Correct answer)
- Microsoft 365 admin center > Active users
- Intune > Device compliance
- Microsoft Defender > Incidents
Correct answer: Azure AD > Sign-in logs > Conditional Access tab
The Sign-in logs in Azure AD include a Conditional Access tab that shows which policies applied and whether access was granted or blocked.
Question 7: Which professional competency is most critical when an MS-100 administrator communicates a planned maintenance window to business stakeholders?
- Configuring DNS records accurately
- Clear communication of impact, duration, and rollback plan (Correct answer)
- Enabling audit logging before the change
- Assigning temporary admin roles during the window
Correct answer: Clear communication of impact, duration, and rollback plan
Effective stakeholder communication during planned maintenance requires clearly stating business impact, expected duration, and contingency plans.
Which Microsoft 365 admin center section should an admin use to purchase and assign additional licenses to users?