Free MS-102 Practice Test Questions and Answers (2026)

View Mode
Q: 1

HOTSPOT

Overview

Litware, Inc. is a consulting company that has a main office in Montreal and a branch office in Seattle.

Litware collaborates with a third-party company named A. Datum Corporation.

Environment

On-Premises Environment

The network of Litware contains an Active Directory domain named litware.com. The domain contains three organizational units (OUs) named LitwareAdmins, Montreal Users, and Seattle Users and the users shown in the following table.

The domain contains 2,000 Windows 10 Pro devices and 100 servers that run Windows Server 2019.

Cloud Environment

Litware has a pilot Microsoft 365 subscription that includes Microsoft Office 365 Enterprise E3 licenses and Azure AD Premium P2 licenses.

The subscription contains a verified DNS domain named litware.com.

Azure AD Connect is installed and has the following configurations:

• Password hash synchronization is enabled.

• Synchronization is enabled for the LitwareAdmins OU only.

Users are assigned the roles shown in the following table.

Self-service password reset (SSPR) is enabled.

The Azure AD tenant has Security defaults enabled.

Problem Statements

Litware identifies the following issues:

• Admin1 cannot create conditional access policies.

• Admin4 receives an error when attempting to use SSPR.

• Users access new Office 365 service and feature updates before the updates are reviewed by Admin2.

Requirements

Planned Changes

Litware plans to implement the following changes:

• Implement Microsoft Intune.

• Implement Microsoft Teams.

• Implement Microsoft Defender for Office 365.

• Ensure that users can install Office 365 apps on their device.

• Convert all the Windows 10 Pro devices to Windows 10 Enterprise ES.

• Configure Azure AD Connect to sync the Montreal Users OU and the Seattle Users OU.

Technical Requirements

Litware identifies the following technical requirements:

• Administrators must be able to specify which version of an Office 365 desktop app will be available to users and to roll back to previous versions.

• Only Admin2 must have access to new Office 365 service and feature updates before they are released to the company.

• Litware users must be able to invite A. Datum users to participate in the following activities:

• Join Microsoft Teams channels.

• Join Microsoft Teams chats.

• Access shared files.

• Just in time access to critical administrative roles must be required.

• Microsoft 365 incidents and advisories must be reviewed monthly.

• Office 365 service status notifications must be sent to Admin2.

• The principle of least privilege must be used.

You are evaluating the use of multi-factor authentication (MFA).

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Your Answer
23 comments in the community discussion
6
YES, NO, NO here. Official MS-102 guide and Microsoft docs cover how Security defaults prompt for MFA with a 14-day grace period, but allow multiple MFA methods by default (not just Authenticator) and don't require MFA every single sign-in if trusted device/session is remembered. Saw this pattern in practice test la
6
YES, NO, NO. Had something like this in a mock recently. Security defaults give that 14-day grace period for MFA setup, but users aren’t limited to only Microsoft Authenticator and it’s not forced at every login (it depends on risk). Pretty sure this lines up, correct me if I missed something!
Q: 2

HOTSPOT You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Office 365. You need to automate Attack simulation training for users when a phishing campaign is detected in real-time. Which type of automation should you use. and which condition should you configure for the Attack simulation training? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Microsoft MS-102 question

Your Answer
34 comments in the community discussion
8
Payload automation, credential harvest. Saw this setup show up in recent practice questions.
4
Would payload automation really not be the default for real-time phishing detection triggers in Defender?
Q: 3

HOTSPOT You have three devices enrolled in Microsoft Endpoint Manager as shown in the following table. Microsoft MS-102 question The device compliance policies in Endpoint Manager are configured as shown in the following table. Microsoft MS-102 question The device compliance policies have the assignments shown in the following table. Microsoft MS-102 question For each of the following statements, select Yes if the statement Is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Microsoft MS-102 question

Your Answer
30 comments in the community discussion
7
YES, YES, NO. Device1 and Device2 both fall under policies requiring BitLocker with a 10-day grace (since the shortest period applies). Device3 doesn’t have BitLocker enforced so it stays compliant. Seen similar questions on practice sets.
6
Yeah, saw something just like this on a recent practice exam.YES, YES, NO
Q: 4

HOTSPOT You need to meet the technical requirements and planned changes for Intune. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Microsoft MS-102 question

Your Answer
24 comments in the community discussion
8
Not totally sure here, but I think it's Mobility (MDM and MAM) for Azure AD and Mobile Device Management Authority for Intune. Can anyone confirm if that's right?
6
Mobility (MDM and MAM) in Azure AD, Mobile Device Management Authority in Intune. I don’t think device enrollment restrictions is the right pick here since that’s for limiting which devices can enroll, not enabling tenant-wide Intune management. Seen similar on practice tests, so pretty sure this is right but open i
Q: 5

Case Study

Your organization is deploying Microsoft Intune to manage mobile devices and ensure corporate data security. The company wants to automatically enroll all Windows, iOS, and Android devices used by specific users into Intune as soon as they sign in with their Microsoft 365 credentials.

The IT department has already created Azure AD user groups and device groups to organize users and assets. According to the technical requirements, only selected users from a specific Azure AD group should be targeted for automatic enrollment in Intune. Other users should remain unaffected until the next phase of rollout.

To achieve this, you must configure the correct Intune setting that controls automatic enrollment behavior and then assign it to the appropriate Azure AD group.



HOTSPOT You need to configure automatic enrollment in Intune. The solution must meet the technical requirements. What should you configure, and to which group should you assign the configurations? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Microsoft MS-102 question

Your Answer
30 comments in the community discussion
6
Nah, device group is a trap here. MDM user scope with UserGroup1 is the right way for targeted auto-enrollment.
6
MDM user scope for the config, assigned to UserGroup1. Saw a similar question on recent exam reports and this matches.
Q: 6

HOTSPOT As of March, how long will the computers in each office remain supported by Microsoft? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Microsoft MS-102 question

Your Answer
29 comments in the community discussion
6
Seattle 30 months, New York 18 months (I saw something like this on a practice exam).
6
Pretty sure it's Seattle 30 months, New York 18 months. The trap is thinking both get 30, but NY does March updates.
Q: 7

HOTSPOT You have a Microsoft 365 tenant that contains devices enrolled in Microsoft Intune. The devices are configured as shown in the following table. Microsoft MS-102 question You plan to perform the following device management tasks in Microsoft Endpoint Manager: Deploy a VPN connection by using a VPN device configuration profile. Configure security settings by using an Endpoint Protection device configuration profile. You support the management tasks. What should you identify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Microsoft MS-102 question

Your Answer
34 comments in the community discussion
6
Device1, Device2, and Device3 for VPN config profile. But Endpoint Protection only applies to Device1 (Windows 10). A lot of people pick just Windows and Android for VPN, but iOS is valid too. Seen this tripped up on similar exam questions.
6
I remember a similar scenario from labs: VPN config applies to all three devices, but Endpoint Protection profile is Windows specific so Device1 only. That's what the Intune docs say too, unless I missed something.
Q: 8

HOTSPOT You have an Azure subscription and an on-premises Active Directory domain. The domain contains 50 computers that run Windows 10. You need to centrally monitor System log events from the computers. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Microsoft MS-102 question

Your Answer
28 comments in the community discussion
6
Log Analytics workspace in Azure and install Microsoft Monitoring Agent on each Windows 10 machine is the way to do it.
4
Log Analytics workspace in Azure and install Microsoft Monitoring Agent on each Windows 10 machine.
Q: 9

HOTSPOT You have three devices enrolled in Microsoft Endpoint Manager as shown in the following table. Microsoft MS-102 question The device compliance policies in Endpoint Manager are configured as shown in the following table. Microsoft MS-102 question The device compliance policies have the assignments shown in the following table. Microsoft MS-102 question For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Microsoft MS-102 question

Your Answer
32 comments in the community discussion
6
NO, NO, YES
6
NO, NO, YES
Q: 10

HOTSPOT You have a Microsoft 365 E5 subscription that contains the users shown in the following table. Microsoft MS-102 question You configure the Microsoft Authenticator authentication method policy to enable passwordless authentication as shown in the following exhibit. Both User1 and User2 report that they are NOT prompted for passwordless sign-in in the Microsoft Authenticator app. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Microsoft MS-102 question

Your Answer
19 comments in the community discussion
6
YES, NO, NO (saw similar Q in practice, group targeting controls this).
6
YES, NO, NOUser1 is covered since they're in Group1 and the policy is assigned there. User2 is a common trap-just registering the app isn't enough if their group isn't included in the policy scope. User3 can't use passwordless at all without registering Authenticator. Think YES for User1 only applies once the
Q: 11

HOTSPOT You have a Microsoft 365 E5 subscription that contains the users shown in the following table. Microsoft MS-102 question You have labels in Microsoft 365 as shown in the following table. Microsoft MS-102 question The content in Microsoft 365 is assigned labels as shown in the following table. Microsoft MS-102 question You have labels In Microsoft 365 as shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. Microsoft MS-102 question

Your Answer
6 comments in the community discussion
3
Why wouldn't the second statement be YES? Just because Admin2 has List viewer only, they can't see file content, but list and label info is still visible. Seems like the wording trips people up here.
3
encountered exactly similar question in my exam in recent exam reports. YES, NO, YES for the statements.
Q: 12

HOTSPOT You have a Microsoft 365 E5 subscription linked to an Azure Active Directory (Azure AD) tenant. The tenant contains a group named Group1 and the users shown in the following table: Microsoft MS-102 question The tenant has a conditional access policy that has the following configurations: Name: Policy1 Assignments: - Users and groups: Group1 - Cloud aps or actions: All cloud apps Access controls: Grant, require multi-factor authentication Enable policy: Report-only You set Enabled Security defaults to Yes for the tenant. For each of the following settings select Yes, if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Microsoft MS-102 question

Your Answer
12 comments in the community discussion
4
Makes sense, since both Conditional Access admin and Security admin have full CA policy rights. Only User admin gets blocked from changing CA assignments. So it should be YES, YES, NO here. Open to correction if I missed something.
3
Yep, looks right to me. YES, YES, NO
Q: 13

Overview -


Litware, Inc. is a consulting company that has a main office in Montreal and a branch office in Seattle.


Litware collaborates with a third-party company named A. Datum Corporation.



Environment -



On-Premises Environment -


The network of Litware contains an Active Directory domain named litware.com. The domain contains three organizational units (OUs) named LitwareAdmins, Montreal Users, and Seattle Users and the users shown in the following table.



The domain contains 2,000 Windows 10 Pro devices and 100 servers that run Windows Server 2019.



Cloud Environment -


Litware has a pilot Microsoft 365 subscription that includes Microsoft Office 365 Enterprise E3 licenses and Azure AD Premium P2 licenses.


The subscription contains a verified DNS domain named litware.com.


Azure AD Connect is installed and has the following configurations:


• Password hash synchronization is enabled.

• Synchronization is enabled for the LitwareAdmins OU only.


Users are assigned the roles shown in the following table.



Self-service password reset (SSPR) is enabled.


The Azure AD tenant has Security defaults enabled.



Problem Statements -


Litware identifies the following issues:


• Admin1 cannot create conditional access policies.

• Admin4 receives an error when attempting to use SSPR.

• Users access new Office 365 service and feature updates before the updates are reviewed by Admin2.



Requirements -



Planned Changes -


Litware plans to implement the following changes:


• Implement Microsoft Intune.

• Implement Microsoft Teams.

• Implement Microsoft Defender for Office 365.

• Ensure that users can install Office 365 apps on their device.

• Convert all the Windows 10 Pro devices to Windows 10 Enterprise ES.

• Configure Azure AD Connect to sync the Montreal Users OU and the Seattle Users OU.



Technical Requirements -


Litware identifies the following technical requirements:


• Administrators must be able to specify which version of an Office 365 desktop app will be available to users and to roll back to previous versions.

• Only Admin2 must have access to new Office 365 service and feature updates before they are released to the company.

• Litware users must be able to invite A. Datum users to participate in the following activities:

• Join Microsoft Teams channels.

• Join Microsoft Teams chats.

• Access shared files.

• Just in time access to critical administrative roles must be required.

• Microsoft 365 incidents and advisories must be reviewed monthly.

• Office 365 service status notifications must be sent to Admin2.

• The principle of least privilege must be used.



You need to configure Azure AD Connect to support the planned changes for the Montreal Users and Seattle Users OUs.


What should you do?



Options
9 comments in the community discussion
1
My pick: A, need to use the wizard to update OU syncing, can't do that just with a cmdlet here.
A tbh, since the only way to add more OUs for sync is running the Azure AD Connect wizard with Customize synchronization options. Powershell cmdlets here can't change the OU selection, just trigger or tweak sync cycles. Pretty sure this matches how Microsoft docs say to do it. Open to other views if I've missed somethi
Q: 14
You have a Microsoft 365 tenant that contains a Windows 10 device. The device is onboarded to Microsoft Defender for Endpoint. From Microsoft Defender Security Center, you perform a security investigation. You need to run a PowerShell script on the device to collect forensic information. Which action should you select on the device page?
Options
9 comments in the community discussion
1
Probably A for this one. Live Response is the only option that actually lets you open an interactive shell and run PowerShell scripts on the endpoint. The others either just gather static data or search logs, so I think this is the catch in the options.
1
Its C
Q: 15
You need to ensure that the support technicians can meet the technical requirement for the Montreal office mobile devices. What is the minimum of dedicated support technicians required?
Options
11 comments in the community discussion
2
B , most exam reports and labs show similar math questions, official practice tests cover these rounding scenarios too.
1
B or C? I remember a similar scenario from labs where the calculation required rounding up, so leaning toward B. But not 100 percent sure, depends if they round fractional techs up.
Q: 16
On which server should you use the Defender for identity sensor?
Options
9 comments in the community discussion
2
Its A, official docs say install sensors on DCs. Seen this point come up in the exam guide.
1
A , pretty sure the others try to trip you up. Only DCs get the sensor from what I remember.
Q: 17
You have a Microsoft 365 subscription. You create a retention label named Retention1 as shown in the following exhibit. Microsoft MS-102 question You apply Retention! to all the Microsoft OneDrive content. On January 1, 2020, a user stores a file named File1 in OneDrive. On January 10, 2020, the user modifies File1. On February 1, 2020, the user deletes File1. When will File1 be removed permanently and unrecoverable from OneDrive?
Options
7 comments in the community discussion
Yeah, it's definitely B here. Retention1 is set to start when the item is created, so the timer kicks off Jan 1, 2020 and ends July 1, 2020. Easy to mix up with last modified date but that's not what this label uses.
Looks like C. Had something like this in a mock and I picked last modified date for retention timer. Since the file was changed Jan 10, 2020, 6 months should land on July 10, not July 1. Not totally sure if my logic is off here.
Q: 18
You have a Microsoft 365 subscription that contains the users shown in the following table. Microsoft MS-102 question You need to configure group-based licensing to meet the following requirements: To all users, deploy an Office 365 E3 license without the Power Automate license option. To all users, deploy an Enterprise Mobility + Security E5 license. To the users in the research department only, deploy a Power BI Pro license. To the users in the marketing department only, deploy a Visio Plan 2 license. What is the minimum number of deployment groups required?
Options
8 comments in the community discussion
2
Call it C fits here? Looks like you need one group for everyone (E3 and EMS), then a research group for Power BI, and a marketing group for Visio. Not 100% sure if I'm missing something with the license exclusions. Did anyone get a different answer on similar questions?
1
C, and if you're still unsure, check the official MS-102 docs or a practice test-they break down examples just like this.
Q: 19
Your on-premises network contains an Active Directory domain. You have a Microsoft 365 subscription. You need to sync the domain with the subscription. The solution must meet the following requirements: • On-premises Active Directory password complexity policies must be enforced. • Users must be able to use Microsoft Entra Self-Service Password Reset (SSPR). What should you use?
Options
6 comments in the community discussion
1
C or D? I thought password hash sync (D) would still apply the on-prem complexity, not just pass-through. Not 100% sure.
1
C kinda guessing since I always get mixed up between PTA and password hash sync. Someone confirm if that's right?
Q: 20
You have a Microsoft 365 E5 tenant. You need to ensure that when a document containing a credit card number is added to the tenant, the document is encrypted. Which policy should you use?
Options
9 comments in the community discussion
2
Makes sense to me, C. Auto-labeling policy is built for this kind of sensitive data detection.
1
C/D? But I think C is right since retention policies (A/B) just don't do encryption, and D is more about monitoring risky behaviors, not protecting docs directly. Saw exam tips warning that D is a trap here.
Question 1 of 20

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top

FLASH OFFER

Days
Hours
Minutes
Seconds

avail 10% DISCOUNT on YOUR PURCHASE