MS-100 Study Guide 2026

Everything you need to pass the MS-100 exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.

📋 MS-100 Exam Format at a Glance

50
Questions
120 min
Time Limit
70.00%
Passing Score

📚 MS-100 Topics to Study (54)

✍️ Sample MS-100 Questions & Answers

1. A security analyst sees a 'Password spray' risk detection in Identity Protection. What attack pattern does this detection identify?
Multiple accounts attacked with a small number of commonly used passwords to avoid lockout

Password spray attacks try a few common passwords (e.g., 'Password1') across many accounts simultaneously to evade per-account lockout thresholds.

2. Which hybrid join type registers a device with both on-premises AD and Azure AD, enabling Conditional Access policies requiring a domain-joined device?
Hybrid Azure AD joined

Hybrid Azure AD joined devices are joined to both on-premises Active Directory and registered in Azure AD, satisfying Conditional Access policies for compliant or domain-joined devices.

3. Which Exchange Online feature allows an administrator to search for and recover emails that were permanently deleted by a user within a defined retention window?
Recoverable Items folder

The Recoverable Items folder retains permanently deleted items for a configurable period, allowing administrators to recover them via eDiscovery or content search.

4. How do continuing education requirements benefit MS-100 certified professionals?
They ensure professionals stay current with evolving industry practices and knowledge

This is fundamental to MS-100 - Microsoft 365 Identity and Services practice. They ensure professionals stay current with evolving industry practices and knowledge represents the professional standard for professional standards in the MS-100 certification framework.

5. During a Microsoft 365 deployment, an admin notices that some pilot users cannot access the Microsoft 365 admin center even though they are assigned the Global Reader role. What is the likely issue?
The users have not completed MFA registration required by a Conditional Access policy

If a Conditional Access policy requires MFA for admin center access and users haven't registered for MFA, they will be blocked from signing in.

6. Which Microsoft 365 security feature helps identify OAuth applications that have been granted excessive permissions and may pose a risk?
Microsoft Defender for Cloud Apps OAuth app governance policies

Microsoft Defender for Cloud Apps provides OAuth app governance, allowing admins to discover, review, and revoke risky third-party OAuth app permissions granted by users.

🎯 Free MS-100 Practice Tests

📖 MS-100 Guides & Articles

Your MS-100 Study Path
1. Learn with Flashcards → 2. Drill Practice Tests → 3. Take the Full Exam Simulation
Was this helpful?