MS-102 Microsoft 365 Tenant & Service Management 4 — Questions and Answers
Question 1: A Microsoft 365 tenant administrator wants to configure a targeted release ring so that specific users receive new Microsoft 365 features before the rest of the organization. Where is this configured?
- Azure AD > Groups > Release rings
- Microsoft 365 admin center > Settings > Org settings > Organization profile > Release preferences (Correct answer)
- Microsoft Endpoint Manager > Update rings
- Microsoft 365 admin center > Settings > Integrated apps > Beta channel
Correct answer: Microsoft 365 admin center > Settings > Org settings > Organization profile > Release preferences
Release preferences, including Targeted release for selected users, are configured under Settings > Org settings > Organization profile in the Microsoft 365 admin center.
Question 2: Which DNS record type is used as the primary method to verify domain ownership when adding a custom domain to a Microsoft 365 tenant?
- MX record pointing to Microsoft servers
- A record pointing to Microsoft IP addresses
- TXT record with a Microsoft-provided verification string (Correct answer)
- CNAME record pointing to autodiscover.outlook.com
Correct answer: TXT record with a Microsoft-provided verification string
Microsoft primarily uses a TXT record with a unique verification string added at the domain registrar to confirm domain ownership before the domain can be used in the tenant.
Question 3: An administrator needs to create a support request for a Microsoft 365 service issue. What is the minimum role required to open a support ticket in the Microsoft 365 admin center?
- Global Reader
- Message Center Reader
- Service Support Administrator (Correct answer)
- Billing Administrator
Correct answer: Service Support Administrator
The Service Support Administrator role (or Global Administrator) is required to create and manage support requests in the Microsoft 365 admin center.
Question 4: What happens to a Microsoft 365 tenant's data if the subscription expires and is not renewed within the grace period?
- Data is immediately deleted upon subscription expiration
- Data is retained indefinitely until the administrator manually deletes it
- The tenant enters a disabled state, then a deprovisioning state, and data is permanently deleted after the deprovisioning period (Correct answer)
- Data is migrated to a free Microsoft 365 tier automatically
Correct answer: The tenant enters a disabled state, then a deprovisioning state, and data is permanently deleted after the deprovisioning period
After subscription expiration, the tenant goes through a grace period (disabled state) followed by a deprovisioning period before data is permanently deleted, with timelines varying by subscription type.
Question 5: A Microsoft 365 administrator wants to allow partner organizations to manage specific aspects of the tenant. Which feature enables this delegation?
- Azure AD B2B collaboration
- Delegated Administration (GDAP or DAP) via Partner Center (Correct answer)
- Azure Lighthouse
- Azure AD External Identities guest access
Correct answer: Delegated Administration (GDAP or DAP) via Partner Center
Delegated Administration Privileges (DAP or Granular DAP/GDAP) through the Microsoft Partner Center allows partner organizations to administer specific tenant functions on behalf of the customer.
Question 6: Which Microsoft 365 admin center section displays the organization's current Microsoft Secure Score and provides actionable improvement recommendations?
- Reports > Usage
- Microsoft 365 Defender > Secure Score (Correct answer)
- Compliance Manager > Score
- Microsoft 365 admin center > Health > Secure Score
Correct answer: Microsoft 365 Defender > Secure Score
Microsoft Secure Score is found in the Microsoft 365 Defender portal, where it shows the current score and provides prioritized security improvement actions.
Question 7: An organization uses Microsoft 365 and wants to enforce that all new Microsoft 365 Groups automatically have an expiration policy applied. Where is this configured?
- Microsoft 365 admin center > Settings > Org settings > Microsoft 365 Groups
- Azure AD > Groups > Expiration (Correct answer)
- Exchange admin center > Recipients > Groups
- SharePoint admin center > Settings > Group expiration
Correct answer: Azure AD > Groups > Expiration
Microsoft 365 Group expiration policies are configured in Azure AD under Groups > Expiration, where you set the lifetime and renewal notification settings.
A Microsoft 365 tenant administrator wants to configure a targeted release ring so that specific users receive new Microsoft 365 features before the rest of the organization.
Where is this configured?