Microsoft • MS-102
Validates ability to deploy and manage Microsoft 365 tenants, implement identity and access with Microsoft Entra ID, manage security and threats using Microsoft 365 Defender, and manage compliance using Microsoft Purview.
Questions
965
Duration
120 minutes
Passing Score
700/1000
Difficulty
ExpertLast Updated
Jan 2025
The MS-102 exam certifies Microsoft 365 Administrators who deploy and manage Microsoft 365 tenants across cloud and hybrid environments. It validates mastery across four critical pillars: tenant configuration and management, identity and access management via Microsoft Entra ID, threat protection through Microsoft Defender XDR, and compliance governance through Microsoft Purview. Passing this exam earns the Microsoft 365 Certified: Administrator Expert credential — the highest-level Microsoft 365 administration certification available.
The exam was last updated on November 10, 2025, and reflects current platform capabilities including Microsoft Entra Cloud Sync, Microsoft Defender Vulnerability Management, Defender for Cloud Apps, and Purview data lifecycle management. Candidates are assessed on practical, scenario-based tasks such as configuring Conditional Access policies, implementing directory synchronization using Microsoft Entra Connect Sync, managing attack simulation training, configuring DLP policies across Exchange, SharePoint, OneDrive, and Teams, and monitoring tenant health and adoption metrics through the Microsoft 365 admin center.
This certification targets experienced IT professionals already working as Microsoft 365 administrators who serve as the integrating hub across all Microsoft 365 workloads. Ideal candidates coordinate with architects and workload-specific administrators responsible for infrastructure, identity, security, compliance, endpoints, and applications in enterprise environments.
Typical job titles pursuing this certification include Microsoft 365 Administrator, Cloud Administrator, Identity and Access Administrator, and IT Manager overseeing Microsoft cloud services. Candidates are expected to have hands-on administration experience with at least one Microsoft 365 workload — such as Exchange Online, Teams, SharePoint, or Endpoint Management — and functional familiarity with all workloads. Working knowledge of networking fundamentals, Active Directory Domain Services, DNS, and PowerShell scripting is also expected.
To earn the Microsoft 365 Certified: Administrator Expert credential, candidates must first hold at least one qualifying Microsoft associate-level certification. Accepted prerequisites include: Microsoft 365 Certified: Endpoint Administrator Associate, Microsoft 365 Certified: Messaging Administrator Associate, Microsoft 365 Certified: Teams Administrator Associate, Microsoft Certified: Identity and Access Administrator Associate, or Microsoft Certified: Information Protection and Compliance Administrator Associate. At least one of these must be obtained before the expert certification can be awarded upon passing MS-102.
Beyond formal certification prerequisites, candidates should have practical experience administering Microsoft 365 and Microsoft Entra ID in production or lab environments. Recommended technical knowledge includes hybrid identity synchronization (Microsoft Entra Connect Sync or Cloud Sync), PowerShell-based administration, Microsoft Defender security tools, and Microsoft Purview compliance solutions. Familiarity with DNS configuration, Active Directory, and enterprise networking concepts is strongly advised.
MS-102 is a proctored exam delivered through Pearson VUE, available both online and at authorized testing centers. The exam has a time limit of 120 minutes and requires a passing score of 700 on a scale of 100–1000. Question count typically ranges from 40–60 items, though the exact number varies per exam form. Question types include scenario-based multiple-choice (single and multiple answer), drag-and-drop, build-list/reorder, and active screen (lab simulations may appear).
The exam is available in English, Chinese (Simplified), German, Spanish, French, Japanese, and Portuguese (Brazil). Candidates taking a non-English version may receive 30 additional minutes. The certification is valid for one year and can be renewed annually at no cost by passing a free, unproctored online renewal assessment on Microsoft Learn. Microsoft's standard retake policy applies: 24-hour wait after the first failed attempt, 14-day wait for subsequent attempts, with a maximum of five attempts per exam in any 12-month period.
The Microsoft 365 Certified: Administrator Expert credential directly validates enterprise-level cloud administration skills sought by organizations deeply invested in the Microsoft 365 ecosystem. Common roles held by certified professionals include Microsoft 365 Administrator, Cloud Infrastructure Administrator, Identity and Access Administrator, Security & Compliance Administrator, and IT Manager overseeing Microsoft cloud environments. The certification is also a recognized prerequisite stepping stone toward advanced Microsoft security certifications such as SC-100 (Cybersecurity Architect Expert) and SC-200 (Security Operations Analyst Associate).
According to ZipRecruiter data, Microsoft 365 Certified Enterprise Administrator Experts in the United States earn an average of approximately $100,000 annually, with top earners exceeding $130,000 and contractors billing $50–$120 per hour depending on scope and region. The certification is particularly valued at Microsoft Partner organizations, consulting firms, and large enterprises running hybrid Microsoft 365 and on-premises Active Directory environments. With Microsoft 365 remaining the dominant cloud productivity platform globally, demand for credentialed administrators remains consistently high across North America, Europe, and Asia-Pacific markets.
5 sample questions with correct answers and explanations. Start a practice session to test yourself across all 965 questions.
1. You are a Microsoft 365 Administrator for City Power & Light, with E5 licenses. Users report that when an attachment is detected as malicious, they see a warning icon instead of the file. What Safe Attachments action is configured?
Explanation
Replace action substitutes malicious attachments with a warning icon. Block prevents message delivery, Monitor tracks without changing, and Dynamic Delivery uses placeholders that may become warnings if infected.
2. As the Microsoft 365 Administrator for Contoso, you need to create a group that allows the sales team to collaborate using shared email, conversations, files, and calendar events. Users should not manage membership manually. Which group type should you select?
Explanation
Microsoft 365 groups provide a shared workspace for email, conversations, files, and calendar events, ideal for collaboration. Security groups only manage permissions without collaboration features, distribution groups focus on email distribution only, and mail-enabled security groups combine permissions and email but lack full collaboration tools.
3. You are the Microsoft 365 Administrator for Litware Corp., a company with a Microsoft 365 E3 subscription. You need to create a user account using PowerShell and assign a license. Which module provides the necessary cmdlets?
Explanation
Microsoft Graph PowerShell has cmdlets like New-MgUser for user creation and license assignment. Azure AD is deprecated, Exchange is for mail, Teams for communication.
4. At Northwind Traders, a trading company with Microsoft 365 E3, administrators must use MFA for all sign-ins, including to the admin center. Which method enforces this without per-user configuration? (Select three!)
Multiple correct answersExplanation
Security Defaults, Conditional Access policies, and per-user MFA can enforce MFA for administrators. SSPR allows resets, Smart Lockout protects against attacks, and pass-through authentication validates credentials on-premises.
5. You work as a Microsoft 365 Administrator for Fourth Coffee, using Microsoft Entra ID Protection. During an investigation, you find a risk event that was incorrectly flagged. What action should you take to improve future detections?
Explanation
Marking as false-positive closes the event and improves machine learning algorithms for similar future events. Resolving indicates external remediation, not for incorrect flags. Ignoring closes it without feedback, potentially missing learning opportunities. Reactivating would reopen it, which isn't appropriate for false positives.
One-time access to this exam