MS-102 Cheat Sheet 2026

The 30 highest-yield MS-102 facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

50 questions
100 min time limit
70% to pass
  1. Which tool should a Microsoft 365 admin use to analyze how a specific Conditional Access policy would affect users before enabling it? What If tool in Conditional Access
  2. Which attribute is used by default as the source anchor (immutableId) in Azure AD Connect when syncing users? objectGUID
  3. An administrator needs to synchronize only specific OUs from on-premises Active Directory to Azure AD. Which feature in Azure AD Connect should they configure? Domain and OU filtering
  4. An administrator needs to configure Azure AD Connect to filter which OUs are synchronized to Azure AD. Where is this configured? Azure AD Connect wizard > Domain/OU Filtering
  5. Which feature in Microsoft Purview allows organizations to place a legal hold on a user's mailbox to preserve all content indefinitely? Litigation hold
  6. You want to apply different DLP rules based on whether a document's sensitivity label is 'Confidential' or 'Public'. Which DLP condition supports this? Content contains sensitivity label
  7. A company uses Azure AD B2B collaboration. When an external user accepts an invitation and signs in, where is their guest account created? In the inviting organization's Azure AD tenant as a guest user object
  8. In which section of an Intune device compliance policy can an administrator specify minimum and maximum allowed operating system versions for enrolled devices? Device properties
  9. An administrator wants Conditional Access to evaluate every request continuously, not just at initial sign-in. Which feature enables this capability? Continuous Access Evaluation (CAE)
  10. Which Microsoft Defender for Office 365 feature simulates phishing attacks to train end users? Attack Simulator (Attack simulation training)
  11. Which role allows a user to manage Microsoft 365 service requests and monitor service health without granting full Global Administrator privileges? Service Support Administrator
  12. Which tool within the Azure AD Connect package is used to troubleshoot and view the attributes of objects in the connector space and metaverse? Synchronization Service Manager
  13. When migrating from an on-premises file server to SharePoint Online using SPMT, what character in a file name will cause the migration to fail? Hash (#)
  14. A security admin wants to automatically investigate and remediate alerts without manual intervention in Microsoft 365 Defender. Which capability supports this? Automated Investigation and Remediation (AIR)
  15. An admin wants to ensure that high-risk sign-ins require additional verification automatically. Which Azure AD feature should be configured? Identity Protection risk-based Conditional Access policy
  16. An organization wants to enable self-service password reset for all users but requires them to register two authentication methods. Where is this configured? SSPR settings in Azure AD under Password reset
  17. Which onboarding package type should be used when deploying Defender for Endpoint to Windows 10 devices using Microsoft Intune? Mobile Device Management (MDM)
  18. Which Entra ID audit log category would an administrator review to track changes to Conditional Access policies? AuditLogs with category 'Policy'
  19. An administrator needs to restrict users from changing their Microsoft 365 profile photo. Which admin center setting controls this? Azure AD > User settings > Users can manage their own profile photo
  20. An organization needs to ensure that only compliant devices can access Microsoft 365 resources. Which feature enforces device compliance as an access condition? Conditional Access with device compliance requirement
  21. A Conditional Access policy is set to 'Report-Only' mode. What is the impact on end users? Users experience no change in sign-in behavior, but policy outcomes are logged
  22. Which Entra ID feature allows administrators to require users to re-verify their identity after a set number of hours, even if they have a valid session token? Sign-in frequency Conditional Access control
  23. An administrator must ensure that all Microsoft 365 license assignments are removed when a user account is deleted. Which behavior is correct by default? Licenses remain assigned to the deleted user account for 30 days then are reclaimed
  24. A company needs to migrate 10,000 mailboxes from on-premises Exchange to Exchange Online. Which migration method is most appropriate? Hybrid migration with Exchange Hybrid
  25. An organization must retain all Teams chat messages for 5 years to meet regulatory requirements. Which tool in Microsoft Purview should be configured? Retention policy
  26. Which Defender for Endpoint feature provides a risk-based prioritization of vulnerabilities by correlating asset exposure with threat intelligence? Threat and Vulnerability Management (TVM)
  27. A Conditional Access policy targets 'All guest and external users'. Which user type is included by this assignment? B2B collaboration guest users invited to the tenant
  28. Which action in Threat Explorer allows an admin to move a set of malicious emails already delivered to user inboxes into quarantine? Move to Quarantine
  29. Which configuration allows Defender for Office 365 Safe Links to track which users clicked a specific URL in a phishing campaign? Enable 'Track user clicks' in the Safe Links policy
  30. Which PowerShell module is used to manage Microsoft Purview sensitivity labels and DLP policies? ExchangeOnlineManagement (Security & Compliance cmdlets)
Was this helpful?