MS-102 Cheat Sheet 2026
The 30 highest-yield MS-102 facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
50 questions
100 min time limit
70% to pass
- Which tool should a Microsoft 365 admin use to analyze how a specific Conditional Access policy would affect users before enabling it? → What If tool in Conditional Access
- Which attribute is used by default as the source anchor (immutableId) in Azure AD Connect when syncing users? → objectGUID
- An administrator needs to synchronize only specific OUs from on-premises Active Directory to Azure AD. Which feature in Azure AD Connect should they configure? → Domain and OU filtering
- An administrator needs to configure Azure AD Connect to filter which OUs are synchronized to Azure AD. Where is this configured? → Azure AD Connect wizard > Domain/OU Filtering
- Which feature in Microsoft Purview allows organizations to place a legal hold on a user's mailbox to preserve all content indefinitely? → Litigation hold
- You want to apply different DLP rules based on whether a document's sensitivity label is 'Confidential' or 'Public'. Which DLP condition supports this? → Content contains sensitivity label
- A company uses Azure AD B2B collaboration. When an external user accepts an invitation and signs in, where is their guest account created? → In the inviting organization's Azure AD tenant as a guest user object
- In which section of an Intune device compliance policy can an administrator specify minimum and maximum allowed operating system versions for enrolled devices? → Device properties
- An administrator wants Conditional Access to evaluate every request continuously, not just at initial sign-in. Which feature enables this capability? → Continuous Access Evaluation (CAE)
- Which Microsoft Defender for Office 365 feature simulates phishing attacks to train end users? → Attack Simulator (Attack simulation training)
- Which role allows a user to manage Microsoft 365 service requests and monitor service health without granting full Global Administrator privileges? → Service Support Administrator
- Which tool within the Azure AD Connect package is used to troubleshoot and view the attributes of objects in the connector space and metaverse? → Synchronization Service Manager
- When migrating from an on-premises file server to SharePoint Online using SPMT, what character in a file name will cause the migration to fail? → Hash (#)
- A security admin wants to automatically investigate and remediate alerts without manual intervention in Microsoft 365 Defender. Which capability supports this? → Automated Investigation and Remediation (AIR)
- An admin wants to ensure that high-risk sign-ins require additional verification automatically. Which Azure AD feature should be configured? → Identity Protection risk-based Conditional Access policy
- An organization wants to enable self-service password reset for all users but requires them to register two authentication methods. Where is this configured? → SSPR settings in Azure AD under Password reset
- Which onboarding package type should be used when deploying Defender for Endpoint to Windows 10 devices using Microsoft Intune? → Mobile Device Management (MDM)
- Which Entra ID audit log category would an administrator review to track changes to Conditional Access policies? → AuditLogs with category 'Policy'
- An administrator needs to restrict users from changing their Microsoft 365 profile photo. Which admin center setting controls this? → Azure AD > User settings > Users can manage their own profile photo
- An organization needs to ensure that only compliant devices can access Microsoft 365 resources. Which feature enforces device compliance as an access condition? → Conditional Access with device compliance requirement
- A Conditional Access policy is set to 'Report-Only' mode. What is the impact on end users? → Users experience no change in sign-in behavior, but policy outcomes are logged
- Which Entra ID feature allows administrators to require users to re-verify their identity after a set number of hours, even if they have a valid session token? → Sign-in frequency Conditional Access control
- An administrator must ensure that all Microsoft 365 license assignments are removed when a user account is deleted. Which behavior is correct by default? → Licenses remain assigned to the deleted user account for 30 days then are reclaimed
- A company needs to migrate 10,000 mailboxes from on-premises Exchange to Exchange Online. Which migration method is most appropriate? → Hybrid migration with Exchange Hybrid
- An organization must retain all Teams chat messages for 5 years to meet regulatory requirements. Which tool in Microsoft Purview should be configured? → Retention policy
- Which Defender for Endpoint feature provides a risk-based prioritization of vulnerabilities by correlating asset exposure with threat intelligence? → Threat and Vulnerability Management (TVM)
- A Conditional Access policy targets 'All guest and external users'. Which user type is included by this assignment? → B2B collaboration guest users invited to the tenant
- Which action in Threat Explorer allows an admin to move a set of malicious emails already delivered to user inboxes into quarantine? → Move to Quarantine
- Which configuration allows Defender for Office 365 Safe Links to track which users clicked a specific URL in a phishing campaign? → Enable 'Track user clicks' in the Safe Links policy
- Which PowerShell module is used to manage Microsoft Purview sensitivity labels and DLP policies? → ExchangeOnlineManagement (Security & Compliance cmdlets)
Turn these facts into recall:
Was this helpful?