MS-102 Microsoft 365 Administrator Expert Managing Microsoft 365 Tenant 2 — Questions and Answers
Question 1: An administrator needs to prevent users from creating new Microsoft 365 Groups unless they belong to a specific security group. Which Azure AD setting should be configured?
- Group naming policy
- Group expiration policy
- Group creation restriction (Correct answer)
- Dynamic membership rule
Correct answer: Group creation restriction
Group creation restriction in Azure AD settings allows admins to limit Microsoft 365 Group creation to members of a designated security group.
Question 2: A company wants to ensure that all Microsoft 365 Groups are reviewed and either renewed or deleted after 180 days. What feature should be enabled?
- Soft delete policy
- Group expiration policy (Correct answer)
- Access review policy
- Retention policy
Correct answer: Group expiration policy
Group expiration policy in Azure AD automatically prompts group owners to renew groups at set intervals, deleting inactive ones.
Question 3: Which Microsoft 365 admin center role allows a user to manage service health and message center posts but NOT make configuration changes?
- Global Reader
- Service Support Admin
- Helpdesk Admin
- Message Center Reader (Correct answer)
Correct answer: Message Center Reader
The Message Center Reader role grants read-only access to Message Center posts but no ability to change tenant configurations.
Question 4: An admin wants to configure a custom domain for Microsoft 365. After adding the domain in the admin center, what must be done to verify ownership?
- Upload an SSL certificate
- Add a DNS TXT or MX record provided by Microsoft (Correct answer)
- Create a CNAME record pointing to office365.com
- Enable DKIM signing
Correct answer: Add a DNS TXT or MX record provided by Microsoft
Microsoft requires adding a specific TXT or MX record to the domain's DNS zone to verify ownership before the domain can be used.
Question 5: A tenant administrator needs to review all changes made to tenant settings over the last 30 days. Where should they look?
- Microsoft 365 Message Center
- Azure AD Audit Logs (Correct answer)
- Microsoft Secure Score
- Service Health dashboard
Correct answer: Azure AD Audit Logs
Azure AD Audit Logs record all administrative activities including tenant configuration changes with timestamps and actor details.
Question 6: Which setting in the Microsoft 365 admin center controls whether users can install Office applications on personal devices?
- Apps for Microsoft 365 settings
- User-initiated installs under Microsoft 365 Apps (Correct answer)
- Device compliance policy
- Conditional Access policy
Correct answer: User-initiated installs under Microsoft 365 Apps
The 'User-initiated installs' toggle under Microsoft 365 Apps settings in the admin center controls whether users can download and install Office from their account portal.
Question 7: A company acquires another organization and needs to merge their Microsoft 365 tenants. What is the recommended Microsoft approach for tenant-to-tenant migration?
- Use Azure AD Connect to sync both tenants simultaneously
- Perform a cross-tenant migration using Microsoft 365 cross-tenant migration tools (Correct answer)
- Export PST files and reimport to the target tenant
- Create a federated trust between the two tenants
Correct answer: Perform a cross-tenant migration using Microsoft 365 cross-tenant migration tools
Microsoft provides cross-tenant migration tools and guidance for moving mailboxes, Teams data, and SharePoint content between tenants during mergers.
An administrator needs to prevent users from creating new Microsoft 365 Groups unless they belong to a specific security group.
Which Azure AD setting should be configured?