Microsoft MS-102 Exam (page: 10)
Microsoft 365 Administrator
Updated on: 25-Dec-2025

Viewing Page 10 of 53

Overview
Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide.
Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States.

Existing Environment
Active Directory Environment
The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts.
All users authenticate to on-premises applications by signing in to their device by using a UPN format of
username@fabrikam.com.
Fabrikam does NOT plan to implement identity federation.

Network Infrastructure
Each office has a high-speed connection to the Internet.
Each office contains two domain controllers. All domain controllers are configured as DNS servers. The public zone for fabrikam.com is managed by an external DNS server.
All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed.
All shared company documents are stored on a Microsoft SharePoint Server farm.
Requirements Planned Changes
Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription.
Fabrikam plans to implement two pilot projects:
Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365.
Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users.
Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses.

Technical Requirements
Fabrikam identifies the following technical requirements:
All users must be able to exchange email messages successfully during Project1 by using their current
email address.
Users must be able to authenticate to cloud services if Active Directory becomes unavailable.
A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal. Microsoft 365 Apps for enterprise applications must be installed from a network share only.
Disruptions to email access must be minimized.
Application Requirements
Fabrikam identifies the following application requirements:
An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal.
The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized.

Security Requirements
Fabrikam identifies the following security requirements:
After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN.
The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically.
After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically.
The principle of least privilege must be used.

HOTSPOT (Drag and Drop is not supported)
You have a Microsoft 365 E5 subscription that contains a user named Admin1. Your company deploys a new branch office named Branch1.
You need to provide Admin1 with the ability to manage Branch1. The solution must meet the following requirements:
Admin1 must only be able to manage users that have Office location set to Branch1.
Admin1 must be able to reset passwords, manage user licenses, and modify user attributes only for the users in Branch1.
What should you use to organize the Branch1 users, and which role should you assign to Admin1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Box 1: An administrative unit Use
Admin1 must only be able to manage users that have Office location set to Branch1.
In Microsoft 365, administrative units can be used to set up administrators for a branch location. They allow for delegated administrative permissions, limiting access to specific resources within a defined scope. This means a branch administrator can manage users, groups, and devices within their specific location without needing global admin access.
Box 2: User Administrator Role
Admin1 must be able to reset passwords, manage user licenses, and modify user attributes only for the users in Branch1.
User admin
Assign the User admin role to users who need to do the following for all users:
Add users and groups
*-> Assign licenses
*-> Manage most users properties
Create and manage user views
*-> Update password expiration policies
• Manage service requests
Monitor service health
The user admin can also do the following actions for users who aren't admins and for users assigned the following roles: Directory reader, Guest inviter, Helpdesk admin, Message center reader, Reports reader:
• Manage usernames
Delete and restore users
*-> Reset passwords
• Force users to sign out
Update (FIDO) device keys
Incorrect:
Password Administrator
A Password Administrator does not manage licenses or modify user attributes. They are primarily responsible for managing password-related aspects of the organization's users. License management and broad user attribute modification are typically handled by Global Administrators or other specific administrative roles.
* Helpdesk admin
Assign the Helpdesk admin role to users who need to do the following:
• Reset passwords
• Force users to sign out
• Manage service requests
• Monitor service health


Reference:

https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/administrative-units https://learn.microsoft.com/en-us/microsoft-365/admin/add-users/about-admin-roles




Overview
Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide.
Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States.

Existing Environment
Active Directory Environment
The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts.
All users authenticate to on-premises applications by signing in to their device by using a UPN format of
username@fabrikam.com.
Fabrikam does NOT plan to implement identity federation.

Network Infrastructure
Each office has a high-speed connection to the Internet.
Each office contains two domain controllers. All domain controllers are configured as DNS servers. The public zone for fabrikam.com is managed by an external DNS server.
All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed.
All shared company documents are stored on a Microsoft SharePoint Server farm.
Requirements Planned Changes
Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription.
Fabrikam plans to implement two pilot projects:
Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365.
Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users.
Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses.

Technical Requirements
Fabrikam identifies the following technical requirements:
All users must be able to exchange email messages successfully during Project1 by using their current
email address.
Users must be able to authenticate to cloud services if Active Directory becomes unavailable.
A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal. Microsoft 365 Apps for enterprise applications must be installed from a network share only.
Disruptions to email access must be minimized.
Application Requirements
Fabrikam identifies the following application requirements:
An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal.
The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized.

Security Requirements
Fabrikam identifies the following security requirements:
After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN.
The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically.
After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically.
The principle of least privilege must be used.

You have Microsoft 365 E5 subscription that contains the identities shown in the following table.


You create a shared mailbox named Shared1.
Which identities can you add to Shared1 as a member?

  1. User1 only
  2. User1 and Group1 only
  3. User1 and Group2 only
  4. User1 and Group3 only
  5. User1, Group2, and Group3 only

Answer(s): D

Explanation:

In Microsoft 365, the following types of identities can be added as members to a shared mailbox: users and mail-enabled security groups. These members can then access the shared mailbox and its contents, subject to the permissions granted to them.
Users:
Individual user accounts within your Microsoft 365 organization can be added as members to a shared mailbox. This allows them to access the shared mailbox's emails, calendars, and other features.
Mail-enabled security groups:
You can also add mail-enabled security groups as members of a shared mailbox. This allows you to manage permissions for a group of users collectively. When you add or remove members from the security group, their access to the shared mailbox is automatically updated.


Reference:

https://learn.microsoft.com/en-us/microsoft-365/admin/email/about-shared-mailboxes




Overview
Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide.
Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States.

Existing Environment
Active Directory Environment
The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts.
All users authenticate to on-premises applications by signing in to their device by using a UPN format of
username@fabrikam.com.
Fabrikam does NOT plan to implement identity federation.

Network Infrastructure
Each office has a high-speed connection to the Internet.
Each office contains two domain controllers. All domain controllers are configured as DNS servers. The public zone for fabrikam.com is managed by an external DNS server.
All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed.
All shared company documents are stored on a Microsoft SharePoint Server farm.
Requirements Planned Changes
Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription.
Fabrikam plans to implement two pilot projects:
Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365.
Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users.
Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses.

Technical Requirements
Fabrikam identifies the following technical requirements:
All users must be able to exchange email messages successfully during Project1 by using their current
email address.
Users must be able to authenticate to cloud services if Active Directory becomes unavailable.
A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal. Microsoft 365 Apps for enterprise applications must be installed from a network share only.
Disruptions to email access must be minimized.
Application Requirements
Fabrikam identifies the following application requirements:
An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal.
The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized.

Security Requirements
Fabrikam identifies the following security requirements:
After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN.
The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically.
After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically.
The principle of least privilege must be used.

HOTSPOT (Drag and Drop is not supported)
You have a Microsoft 365 subscription that uses Microsoft 365 Multi-Geo. The subscription contains two
Microsoft SharePoint Online sites named Site1 and Site2 that are stored in different Multi-Geo regions. You plan to configure a Microsoft 365 Backup policy.
You need to add Site1 and Site2 to the policy and configure the longest retention period available. What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Box 1: Upload a list of the sites in a CSV file. To add the sites
To add SharePoint Online sites from different Multi Geo locations to a Microsoft 365 Backup policy, you need to configure the backup policy to include the specific sites or use a CSV file to upload a list of sites across different geographies. Ensure your tenant is configured for Multi-Geo and that the desired locations are added as satellite geographies.
Box 2: 1 year
Set the retention period to
The maximum retention period for Microsoft 365 backups is one year. This applies to backups of OneDrive accounts and Exchange mailboxes when a user is removed from a backup policy or deleted from Microsoft Entra ID. For SharePoint sites, the backup retention is 52 weeks from the last restore point. Microsoft plans to introduce options for longer or shorter retention periods in the future.


Reference:

https://learn.microsoft.com/en-us/microsoft-365/enterprise/multi-geo-capabilities-in-onedrive-and-sharepoint- online-in-microsoft-365
https://learn.microsoft.com/en-us/microsoft-365/backup/backup-overview




Overview
Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide.
Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States.

Existing Environment
Active Directory Environment
The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts.
All users authenticate to on-premises applications by signing in to their device by using a UPN format of
username@fabrikam.com.
Fabrikam does NOT plan to implement identity federation.

Network Infrastructure
Each office has a high-speed connection to the Internet.
Each office contains two domain controllers. All domain controllers are configured as DNS servers. The public zone for fabrikam.com is managed by an external DNS server.
All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed.
All shared company documents are stored on a Microsoft SharePoint Server farm.
Requirements Planned Changes
Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription.
Fabrikam plans to implement two pilot projects:
Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365.
Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users.
Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses.

Technical Requirements
Fabrikam identifies the following technical requirements:
All users must be able to exchange email messages successfully during Project1 by using their current
email address.
Users must be able to authenticate to cloud services if Active Directory becomes unavailable.
A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal. Microsoft 365 Apps for enterprise applications must be installed from a network share only.
Disruptions to email access must be minimized.
Application Requirements
Fabrikam identifies the following application requirements:
An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal.
The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized.

Security Requirements
Fabrikam identifies the following security requirements:
After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN.
The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically.
After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically.
The principle of least privilege must be used.

You have a Microsoft 365 E5 subscription. You need to create a mail-enabled contact. Which portal should you use?

  1. the Microsoft Defender portal
  2. the SharePoint admin center
  3. the Microsoft Purview portal
  4. the Exchange admin center

Answer(s): D

Explanation:

To create a mail-enabled contact in Microsoft 365, you'll use the Exchange admin center. Navigate to Recipients > Contacts, then click Add a mail contact. Provide the necessary information like first name, last name, and importantly, the External email address. This address is where the contact will receive emails from outside your organization. You can then click Create to finalize the contact.


Reference:

https://learn.microsoft.com/en-us/exchange/recipients-in-exchange-online/manage-mail-contacts




Overview
Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide.
Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States.

Existing Environment
Active Directory Environment
The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts.
All users authenticate to on-premises applications by signing in to their device by using a UPN format of
username@fabrikam.com.
Fabrikam does NOT plan to implement identity federation.

Network Infrastructure
Each office has a high-speed connection to the Internet.
Each office contains two domain controllers. All domain controllers are configured as DNS servers. The public zone for fabrikam.com is managed by an external DNS server.
All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed.
All shared company documents are stored on a Microsoft SharePoint Server farm.
Requirements Planned Changes
Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription.
Fabrikam plans to implement two pilot projects:
Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365.
Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users.
Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses.

Technical Requirements
Fabrikam identifies the following technical requirements:
All users must be able to exchange email messages successfully during Project1 by using their current
email address.
Users must be able to authenticate to cloud services if Active Directory becomes unavailable.
A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal. Microsoft 365 Apps for enterprise applications must be installed from a network share only.
Disruptions to email access must be minimized.
Application Requirements
Fabrikam identifies the following application requirements:
An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal.
The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized.

Security Requirements
Fabrikam identifies the following security requirements:
After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN.
The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically.
After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically.
The principle of least privilege must be used.

You have a Microsoft 365 subscription that contains the users shown in the following table.


You plan to use Microsoft 365 Backup.
Which users can enable Microsoft 365 Backup?

  1. Admin1 only
  2. Admin3 only
  3. Admin1 and Admin3 only
  4. Admin1, Admin2 and Admin3 only
  5. Admin1, Admin2, Admin3, and Admin4

Answer(s): C

Explanation:

You must be a SharePoint Administrator or Global Administrator to be able to access the Microsoft 365 admin center and set up Microsoft 365 Backup.
To enable Microsoft 365 Backup, you need either Global Administrator [Admin1] or SharePoint Administrator [Admin3] permissions within your Microsoft 365 tenant. These roles have the necessary access to configure and manage the backup service for OneDrive, SharePoint, and Exchange.
Global Administrator:
This is the highest level of administrative access in Microsoft 365 and grants the ability to manage all aspects of the service, including backup and restore capabilities.
SharePoint Administrator:
This role has specific permissions to manage SharePoint Online and can enable and manage backups for SharePoint sites and libraries.
Note: While a Global Administrator can enable the initial setup, they may delegate specific backup management tasks to other administrators with the necessary permissions, such as SharePoint Administrators for SharePoint-related backups.


Reference:

https://learn.microsoft.com/en-us/microsoft-365/backup/backup-setup




Overview
Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide.
Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States.

Existing Environment
Active Directory Environment
The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts.
All users authenticate to on-premises applications by signing in to their device by using a UPN format of
username@fabrikam.com.
Fabrikam does NOT plan to implement identity federation.

Network Infrastructure
Each office has a high-speed connection to the Internet.
Each office contains two domain controllers. All domain controllers are configured as DNS servers. The public zone for fabrikam.com is managed by an external DNS server.
All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed.
All shared company documents are stored on a Microsoft SharePoint Server farm.
Requirements Planned Changes
Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription.
Fabrikam plans to implement two pilot projects:
Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365.
Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users.
Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses.

Technical Requirements
Fabrikam identifies the following technical requirements:
All users must be able to exchange email messages successfully during Project1 by using their current
email address.
Users must be able to authenticate to cloud services if Active Directory becomes unavailable.
A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal. Microsoft 365 Apps for enterprise applications must be installed from a network share only.
Disruptions to email access must be minimized.
Application Requirements
Fabrikam identifies the following application requirements:
An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal.
The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized.

Security Requirements
Fabrikam identifies the following security requirements:
After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN.
The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically.
After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically.
The principle of least privilege must be used.

HOTSPOT (Drag and Drop is not supported)
You have a Microsoft 365 subscription that uses the following services: Microsoft Entra
Exchange Online Microsoft Teams SharePoint Online.
You are planning a backup solution that will use Microsoft 365 Backup.
You need to recommend which Microsoft 365 services can be backed up and the longest retention period available.
What should you recommend? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Box 1: Exchange Online and SharePoint Online only Services
Microsoft 365 Backup is designed to ensure your organization’s data is always protected and easily recoverable. With the ability to back up all or select SharePoint sites, OneDrive accounts, and Exchange mailboxes, Microsoft 365 Backup provides comprehensive coverage for your critical data.
Note: Microsoft 365 Backup currently supports backing up Exchange Online mailboxes, SharePoint sites, and OneDrive for Business accounts. It offers granular restore options for Exchange and plans to introduce them for SharePoint and OneDrive in the future, according to Microsoft Adoption. While Teams files are stored on SharePoint and thus backed up, other data within Teams, like chat messages, is not yet covered by the built-in backup service.
Box 2: 1 year Retention period
Retention period is 1 year.


Reference:

https://learn.microsoft.com/en-us/microsoft-365/backup/backup-overview?view=o365-worldwide




Overview
General Overview
Litware, Inc. is a consulting company that has a main office in Montreal and a branch office in Seattle. Litware collaborates with a third-party company named ADatum Corporation.

Environment
On-Premises Environment
The network of Litware contains an Active Directory domain named litware.com. The domain contains three organizational units (OUs) named LitwareAdmins, Montreal Users, and Seattle Users and the users shown in the following table.


The domain contains 2,000 Windows 10 Pro devices and 100 servers that run Windows Server 2019.

Cloud Environment
Litware has a pilot Microsoft 365 subscription that includes Microsoft 365 E3 licenses. The subscription contains a verified DNS domain named litware.com.
Microsoft Entra Connect is installed and has the following configurations:
Password hash synchronization is enabled. Synchronization is enabled for the LitwareAdmins OU only.
Users are assigned the roles shown in the following table.


Self-service password reset (SSPR) is enabled.
The Microsoft Entra tenant has Security defaults enabled.

Problem Statements
Litware identifies the following issues:
Admin1 cannot create conditional access policies. Admin4 receives an error when attempting to use SSPR.
Users access new Microsoft 365 service and feature updates before the updates are reviewed by Admin2.
Requirements Planned Changes
Litware plans to implement the following changes:
Implement Microsoft Intune. Implement Microsoft Teams.
Implement Microsoft Defender for Office 365.
Ensure that users can install Microsoft 365 apps on their device. Convert all the Windows 10 Pro devices to Windows 10 Enterprise E5.
Configure Microsoft Entra Connect Sync to sync the Montreal Users OU and the Seattle Users OU.

Technical Requirements
Litware identifies the following technical requirements:
Administrators must be able to specify which version of a Microsoft 365 desktop app will be available to users and to roll back to previous versions.
Only Admin2 must have access to new Microsoft 365 service and feature updates before they are released to the company.
Litware users must be able to invite ADatum users to participate in the following activities:
- Join Microsoft Teams channels.
- Join Microsoft Teams chats.
- Access shared files.
Just in time access to critical administrative roles must be required. Microsoft 365 incidents and advisories must be reviewed monthly. Microsoft 365 service status notifications must be sent to Admin2 The principle of least privilege must be used.

HOTSPOT (Drag and Drop is not supported)
You need to ensure that Admin4 can use SSPR.
Which tool should you use, and which action should you perform? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Box 1: Enable password writeback
Self-service password reset (SSPR) is enabled.
Admin4 receives an error when attempting to use SSPR.
Enable Microsoft Entra self-service password reset writeback to an on-premises environment Password writeback can be used to synchronize password changes in Microsoft Entra back to your on-
premises AD DS environment. Microsoft Entra Connect provides a secure mechanism to send these password changes back to an existing on-premises directory from Microsoft Entra ID.
Box 2: Microsoft Entra admin center Enable password writeback for SSPR
With password writeback enabled in Microsoft Entra Connect (see Note below), now configure Microsoft Entra SSPR for writeback. SSPR can be configured to writeback through Microsoft Entra Connect Sync agents and Microsoft Entra Connect provisioning agents (cloud sync). When you enable SSPR to use password writeback, users who change or reset their password have that updated password synchronized back to the on-premises AD DS environment as well.
To enable password writeback in SSPR, complete the following steps:
Sign in to the Microsoft Entra admin center as Global Administrator.
Browse to Protection > Password reset, then choose On-premises integration.
Check the option for Write back passwords to your on-premises directory .
(optional) If Microsoft Entra Connect provisioning agents are detected, you can additionally check the option for Write back passwords with Microsoft Entra Connect cloud sync.
6. Check the option for Allow users to unlock accounts without resetting their password to Yes.


Note: Enable password writeback in Microsoft Entra Connect
One of the configuration options in Microsoft Entra Connect is for password writeback. When this option is enabled, password change events cause Microsoft Entra Connect to synchronize the updated credentials back to the on-premises AD DS environment.
To enable SSPR writeback, first enable the writeback option in Microsoft Entra Connect. From your Microsoft Entra Connect server, complete the following steps:
Sign in to your Microsoft Entra Connect server and start the Microsoft Entra Connect configuration wizard.
On the Welcome page, select Configure.
On the Additional tasks page, select Customize synchronization options, and then select Next.
On the Connect to Microsoft Entra ID page, enter a Global Administrator credential for your Azure tenant, and then select Next.
On the Connect directories and Domain/OU filtering pages, select Next.
On the Optional features page, select the box next to Password writeback and select Next.


On the Directory extensions page, select Next.
On the Ready to configure page, select Configure and wait for the process to finish.
9. When you see the configuration finish, select Exit.
Incorrect:
* Microsoft Entra Connect
On August 31, 2022, all 1. x versions of Microsoft Entra Connect was retired because they include SQL Server 2012 components that will no longer be supported.


Reference:

https://learn.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-sspr-writeback https://learn.microsoft.com/en-us/lifecycle/products/azure-active-directory-ad-connect




Overview
General Overview
Litware, Inc. is a consulting company that has a main office in Montreal and a branch office in Seattle. Litware collaborates with a third-party company named ADatum Corporation.

Environment
On-Premises Environment
The network of Litware contains an Active Directory domain named litware.com. The domain contains three organizational units (OUs) named LitwareAdmins, Montreal Users, and Seattle Users and the users shown in the following table.


The domain contains 2,000 Windows 10 Pro devices and 100 servers that run Windows Server 2019.

Cloud Environment
Litware has a pilot Microsoft 365 subscription that includes Microsoft 365 E3 licenses. The subscription contains a verified DNS domain named litware.com.
Microsoft Entra Connect is installed and has the following configurations:
Password hash synchronization is enabled. Synchronization is enabled for the LitwareAdmins OU only.
Users are assigned the roles shown in the following table.


Self-service password reset (SSPR) is enabled.
The Microsoft Entra tenant has Security defaults enabled.

Problem Statements
Litware identifies the following issues:
Admin1 cannot create conditional access policies. Admin4 receives an error when attempting to use SSPR.
Users access new Microsoft 365 service and feature updates before the updates are reviewed by Admin2.
Requirements Planned Changes
Litware plans to implement the following changes:
Implement Microsoft Intune. Implement Microsoft Teams.
Implement Microsoft Defender for Office 365.
Ensure that users can install Microsoft 365 apps on their device. Convert all the Windows 10 Pro devices to Windows 10 Enterprise E5.
Configure Microsoft Entra Connect Sync to sync the Montreal Users OU and the Seattle Users OU.

Technical Requirements
Litware identifies the following technical requirements:
Administrators must be able to specify which version of a Microsoft 365 desktop app will be available to users and to roll back to previous versions.
Only Admin2 must have access to new Microsoft 365 service and feature updates before they are released to the company.
Litware users must be able to invite ADatum users to participate in the following activities:
- Join Microsoft Teams channels.
- Join Microsoft Teams chats.
- Access shared files.
Just in time access to critical administrative roles must be required. Microsoft 365 incidents and advisories must be reviewed monthly. Microsoft 365 service status notifications must be sent to Admin2 The principle of least privilege must be used.

HOTSPOT (Drag and Drop is not supported)
You are evaluating the use of multi-factor authentication (MFA).
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Box 1: Yes
How To: Configure the Microsoft Entra multifactor authentication registration policy
Microsoft Entra ID Protection helps you manage the roll-out of Microsoft Entra multifactor authentication registration by configuring a Conditional Access policy to require MFA registration no matter what modern authentication app you're signing in to.
User experience
Microsoft Entra ID Protection will prompt your users to register the next time they sign in interactively and they'll have 14 days to complete registration. During this 14-day period, they can bypass registration if MFA isn't required as a condition, but at the end of the period they'll be required to register before they can complete the sign-in process.
Box 2: No
All users have 14 days to register using the Microsoft Authenticator app or any app supporting OATH TOTP. After the 14 days have passed, the user can't sign in until registration is completed. A user's 14-day period begins after their first successful interactive sign-in after enabling security defaults.
Box 3: No
After registration is finished, the following administrator roles will be required to do multifactor authentication every time they sign in:
Global Administrator Application Administrator Authentication Administrator
Authentication Policy Administrator Billing Administrator
Cloud Application Administrator Conditional Access Administrator Exchange Administrator Helpdesk Administrator
Identity Governance Administrator Password Administrator
Privileged Authentication Administrator Privileged Role Administrator
Security Administrator SharePoint Administrator User Administrator
Require users to do multifactor authentication when necessary
We tend to think that administrator accounts are the only accounts that need extra layers of authentication. Administrators have broad access to sensitive information and can make changes to subscription-wide settings. But attackers frequently target end users.
After these attackers gain access, they can request access to privileged information for the original account holder. They can even download the entire directory to do a phishing attack on your whole organization.
One common method to improve protection for all users is to require a stronger form of account verification, such as multifactor authentication, for everyone. After users complete registration, they'll be prompted for another authentication whenever necessary. Microsoft decides when a user is prompted for multifactor authentication, based on factors such as location, device, role and task. This functionality protects all registered applications, including SaaS applications.


Reference:

https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure- mfa-policy
https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/security-defaults



Viewing Page 10 of 53



Share your comments for Microsoft MS-102 exam with other users:

Matt 7/31/2025 11:44:40 PM

Great questions.
UNITED STATES