MS-102 Microsoft 365 Tenant & Service Management 5 — Questions and Answers
Question 1: A Microsoft 365 administrator needs to view which admin roles are currently assigned to a specific user. What is the fastest way to check this in the admin center?
- Azure AD > Roles and administrators > Search by user
- Microsoft 365 admin center > Users > Active users > Select user > Roles tab (Correct answer)
- Microsoft 365 admin center > Roles > Role assignments > Filter by user
- Exchange admin center > Permissions > Admin roles > Search user
Correct answer: Microsoft 365 admin center > Users > Active users > Select user > Roles tab
In the Microsoft 365 admin center, selecting a user from Active users and viewing their Roles tab shows all currently assigned admin roles for that specific user.
Question 2: Which Microsoft 365 feature allows an administrator to set policies that automatically classify and label data across Exchange, SharePoint, and OneDrive?
- Azure Information Protection scanner
- Microsoft Purview auto-labeling policies (Correct answer)
- Microsoft Defender for Cloud Apps file policies
- Data Loss Prevention (DLP) auto-classification rules
Correct answer: Microsoft Purview auto-labeling policies
Microsoft Purview auto-labeling policies automatically apply sensitivity labels to content in Exchange, SharePoint, and OneDrive based on sensitive information types or trainable classifiers.
Question 3: An administrator needs to configure the Microsoft 365 tenant to require all guest users to re-authenticate every 30 days even if they use MFA. Which feature enables this?
- Conditional Access — Sign-in frequency policy (Correct answer)
- Azure AD Identity Protection — Guest risk policy
- Microsoft 365 admin center — Guest access expiry setting
- Azure AD B2B — Collaboration restrictions
Correct answer: Conditional Access — Sign-in frequency policy
Conditional Access sign-in frequency policies allow administrators to control how often users, including guests, must reauthenticate, regardless of MFA token persistence.
Question 4: A tenant administrator wants to prevent users from creating new Microsoft 365 tenants using their work email accounts. Which setting controls this?
- Azure AD > User settings > Users can create Azure AD tenants (Correct answer)
- Microsoft 365 admin center > Org settings > Security & privacy > Self-service sign-up
- Azure AD > External Identities > Cross-tenant access settings
- Microsoft 365 admin center > Settings > Org settings > User owned apps
Correct answer: Azure AD > User settings > Users can create Azure AD tenants
The 'Users can create Azure AD tenants' setting in Azure AD User settings controls whether users can create new Azure AD (and thus Microsoft 365) tenants with their organizational credentials.
Question 5: Which Microsoft 365 feature provides a centralized view of all third-party apps that have been granted permissions in the tenant and allows administrators to review and revoke those permissions?
- Microsoft 365 Defender > Cloud Apps > App governance
- Azure AD > Enterprise applications (Correct answer)
- Microsoft 365 admin center > Settings > Integrated apps
- Azure AD > App registrations
Correct answer: Azure AD > Enterprise applications
Azure AD Enterprise applications shows all third-party and first-party apps that have been consented to in the tenant, with options to review permissions and revoke access.
Question 6: An administrator wants to configure the Microsoft 365 tenant so that when users leave the organization, their OneDrive content is automatically transferred to their manager. Which feature enables this?
- Microsoft 365 admin center — User deletion workflow
- SharePoint admin center > Settings > OneDrive retention
- OneDrive access delegation via the Microsoft 365 admin center — Storage settings
- SharePoint admin center > More features > User profiles > Manage user profiles — My Site cleanup job (Correct answer)
Correct answer: SharePoint admin center > More features > User profiles > Manage user profiles — My Site cleanup job
The My Site cleanup job in SharePoint User Profiles (under More features) automatically sends email notifications and can delegate OneDrive access to a former employee's manager.
Question 7: Which Microsoft 365 admin center report shows the adoption and activity data across Microsoft 365 services at the per-user level while respecting privacy settings?
- Reports > Usage > Microsoft 365 > User activity (Correct answer)
- Reports > Usage > Microsoft 365 Apps usage
- Viva Insights > Advanced insights
- Reports > Usage > Active users report
Correct answer: Reports > Usage > Microsoft 365 > User activity
The Microsoft 365 User activity report under Reports > Usage provides per-service adoption and activity details per user, subject to tenant privacy configuration settings.
A Microsoft 365 administrator needs to view which admin roles are currently assigned to a specific user.
What is the fastest way to check this in the admin center?