MS-102 Microsoft 365 Administrator Expert Managing Microsoft 365 Tenant 4 — Questions and Answers
Question 1: A Microsoft 365 administrator wants to configure a retention policy that keeps Exchange emails for 7 years but allows users to delete emails sooner. Which retention behavior should be selected?
- Retain only
- Delete only
- Retain and then delete (Correct answer)
- Retain and allow deletion during retention
Correct answer: Retain and then delete
The 'Retain and then delete' setting keeps content for the retention period and deletes it afterward, but users can still delete items before the period ends.
Question 2: Which tool should a Microsoft 365 admin use to analyze how a specific Conditional Access policy would affect users before enabling it?
- Azure AD Sign-in logs
- What If tool in Conditional Access (Correct answer)
- Identity Protection risk detection
- Microsoft Secure Score recommendations
Correct answer: What If tool in Conditional Access
The 'What If' tool in Conditional Access simulates policy outcomes for specific users, apps, and conditions without actually enforcing the policy.
Question 3: An administrator needs to ensure that a contractor's guest account is automatically reviewed and removed if no action is taken within 30 days. Which feature should be used?
- Azure AD group expiration policy
- Azure AD access reviews (Correct answer)
- Privileged Identity Management
- Identity Protection
Correct answer: Azure AD access reviews
Azure AD access reviews can be scheduled to periodically review guest accounts and automatically remove access if reviewers take no action.
Question 4: A new Microsoft 365 tenant is being set up. The admin wants all users to see the company name in their Office apps and email signatures. What should be configured first?
- Exchange Online transport rules
- Organizational profile in Microsoft 365 admin center (Correct answer)
- Microsoft Viva Insights
- Azure AD tenant display name only
Correct answer: Organizational profile in Microsoft 365 admin center
The Organizational profile in the Microsoft 365 admin center stores the company name that appears across Microsoft 365 services and apps.
Question 5: An admin receives a Microsoft 365 Message Center notification about a planned feature change. What action should the admin take to prevent the change from rolling out to users immediately?
- Open a support ticket to block the change
- Use the 'Targeted release' option for a limited group first (Correct answer)
- Disable the feature in the Security & Compliance center
- Set the tenant to 'Standard release' channel
Correct answer: Use the 'Targeted release' option for a limited group first
Configuring Targeted release allows the admin to test changes with a subset of users before broader rollout, providing time to prepare.
Question 6: A Microsoft 365 administrator wants to delegate management of a single application in Azure AD to a specific team without granting them Global Admin rights. What is the best approach?
- Grant the team the Application Administrator role
- Assign the team as owners of the specific application in Azure AD (Correct answer)
- Create a custom admin role scoped to the application
- Add the team to the Security Administrator role
Correct answer: Assign the team as owners of the specific application in Azure AD
Assigning application owners in Azure AD grants the team management rights only over that specific application without broader directory permissions.
Question 7: Which Microsoft 365 admin center section allows an administrator to configure the default app permissions that users grant to third-party applications?
- Security & Compliance center
- Azure AD Enterprise Applications > User consent settings (Correct answer)
- Microsoft 365 Apps admin center
- Microsoft Defender for Cloud Apps
Correct answer: Azure AD Enterprise Applications > User consent settings
User consent settings in Azure AD Enterprise Applications control whether users can grant permissions to third-party apps and what types of permissions are allowed.
A Microsoft 365 administrator wants to configure a retention policy that keeps Exchange emails for 7 years but allows users to delete emails sooner.
Which retention behavior should be selected?