MS-102 is the tenant-level Microsoft 365 administration exam. It tests whether you can connect identity, security, compliance and service administration into one operating model rather than treating each portal as an isolated workload.
Understand the exam domains
| Skill area | Weight | What to be able to do |
|---|---|---|
| Deploy and manage a Microsoft 365 tenant | 25–30% | Domains, organisation settings, service health, adoption, users, groups, licences, roles and administrative units. |
| Implement and manage Microsoft Entra identity and access | 25–30% | Cloud and hybrid identity, authentication, Conditional Access, Identity Protection, access reviews and application access. |
| Manage security and threats with Microsoft Defender XDR | 30–35% | Incidents, alerts, Secure Score, Defender for Office 365, Defender for Endpoint and cross-workload investigation. |
| Manage compliance with Microsoft Purview | 10–15% | Sensitivity labels, DLP, retention, audit, eDiscovery and compliance posture. |
Start with a baseline assessment
- Read every objective in the official guide and mark it as can configure, can explain or needs study.
- Take Microsoft’s free Practice Assessment without looking up answers. Record weak topics, not just the score.
- Create a lab map showing which tasks you can practise in a developer or trial tenant and which need documentation-only study.
- Build a command and portal notebook. For each objective, capture the admin centre, PowerShell module, role required, validation step and rollback consideration.
Four-week study plan
Domains, service health, licensing, group-based licensing, shared mailboxes, Microsoft 365 groups, role groups, PIM and administrative units. Practise creating a least-privilege role assignment and documenting its scope.
Cloud sync and Connect Sync concepts, authentication methods, passwordless options, Conditional Access, Identity Protection, access reviews, enterprise applications and external identities. Build report-only Conditional Access policies and review sign-in results.
Understand incident correlation across Defender products, attack simulation, Safe Links, Safe Attachments, anti-phishing, endpoint onboarding, device groups, indicators, advanced hunting and automated investigation. Work through an incident from alert to remediation.
Practise sensitivity labels, DLP policy design, retention, audit and eDiscovery. Finish with two timed practice assessments and revisit only the objectives that remain weak.
Hands-on labs that provide the most value
- Add and verify a test domain, then trace the DNS dependencies.
- Create users and groups, apply group-based licensing and review licence errors.
- Configure PIM eligibility and test activation with an authentication context.
- Build a report-only Conditional Access policy and interpret sign-in logs.
- Investigate a Defender XDR incident and identify the affected identities, devices and messages.
- Create a sensitivity label and a DLP policy in simulation mode.
- Run an audit search and document what role and licensing were required.
PowerShell areas to know
You do not need to memorise every cmdlet, but you should recognise the appropriate module and understand when PowerShell provides capabilities or scale beyond the portal.
Connect-MgGraph -Scopes "User.ReadWrite.All","Group.ReadWrite.All","Directory.Read.All"
Get-MgSubscribedSku
Get-MgUser -Top 10
Connect-ExchangeOnline
Get-OrganizationConfig
Get-RoleGroup
Connect-IPPSSession
Get-RetentionCompliancePolicy
Exam strategy
- Read the requirement first, then identify the smallest change that satisfies it.
- Watch for scope: tenant, administrative unit, group, user, device or workload.
- Separate licensing questions from configuration questions.
- Prefer report-only, simulation and pilot approaches when the scenario asks for controlled rollout.
- For case studies, record constraints and business requirements before opening the questions.
Final readiness checklist
- I can explain the four exam domains without notes.
- I can choose the correct admin centre and least-privilege role for common tasks.
- I can interpret Entra sign-in, Defender incident and Purview audit evidence.
- I have completed at least two timed practice assessments.
- I checked the official objective change log for my exam date.
Microsoft references
- Official MS-102 study guide
- Exam MS-102 details
- Microsoft 365 Administrator Expert certification
- Course MS-102T00: Microsoft 365 Administrator
- Microsoft Certification Practice Assessments
Review note: Certification objectives, Microsoft cloud features and portal labels change. Check the official Microsoft page for the date of your exam or production deployment.