Instiq

Microsoft 365 AdministratorStudy guide

The associate certification for a Microsoft 365 administrator who manages tenants, Microsoft Entra identity, Microsoft Defender XDR, and Microsoft Purview across all M365 workloads (MS-102).

About Microsoft 365 Administrator (MS-102)

Microsoft 365 Administrator (MS-102) is a Associate-level certification from Microsoft. This page organizes the exam scope into a 5-chapter, 13-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."

Exam domains (approximate weighting)

  • Deploy and manage a Microsoft 365 tenant~27%
  • Implement and manage Microsoft Entra identity and access~27%
  • Manage security and threats by using Microsoft Defender XDR~33%
  • Manage compliance by using Microsoft Purview~13%

Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.

Official exam information: https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/ms-102

1Deploy and manage a Microsoft 365 tenant

  • 1.1Manage the tenant and services

    Understand creating a Microsoft 365 tenant, adding/verifying domains, org settings (Security & privacy / Organization profile), service health monitoring and notifications via Service Health, Network connectivity insights, software updates, Microsoft 365 Backup, and adoption/usage.

  • 1.2Users and groups

    Understand creating users (including external users) and contacts in Microsoft Entra ID, groups (Microsoft 365 Groups / security groups) and shared mailboxes, licensing (including group-based licensing), and bulk management via Microsoft Graph PowerShell.

  • 1.3Roles and role groups

    Understand Microsoft 365 and Microsoft Entra ID roles, workload permissions for Defender XDR/Purview via role groups, delegation with administrative units, and Just-In-Time elevation of Entra roles via Privileged Identity Management (PIM).

2Implement and manage Microsoft Entra identity and access

  • 2.1Identity synchronization

    Understand syncing on-prem AD with Microsoft Entra ID: IdFix for pre-sync error remediation, choosing between Microsoft Entra Connect Sync and Cloud Sync, monitoring with Microsoft Entra Connect Health, and troubleshooting sync.

  • 2.2Authentication

    Understand managing authentication methods, self-service password reset (SSPR), Microsoft Entra Password Protection to block weak/banned passwords, and investigating authentication issues.

  • 2.3Secure access

    Understand risk-based detection with Microsoft Entra Identity Protection, access control via Conditional Access policies, and enforcing multifactor authentication (MFA) using Conditional Access.

3Manage security with Microsoft Defender XDR and Office 365

  • 3.1Investigate and respond with Defender XDR

    Understand posture via Microsoft Security Exposure Management and Secure Score, triaging Defender XDR incidents and alerts, advanced hunting (KQL), and Microsoft Defender Threat Intelligence.

  • 3.2Defender for Office 365

    Understand threat policies (anti-phishing/anti-spam/anti-malware), Safe Attachments and Safe Links, alert policies, investigating email/collab threats with Threat Explorer, attack simulation training, and restricted entities.

4Defender for Endpoint and Cloud Apps

  • 4.1Defender for Endpoint

    Understand onboarding devices to Microsoft Defender for Endpoint, endpoint settings (attack surface reduction ASR, EDR block mode, tamper protection), and Microsoft Defender Vulnerability Management for surfacing and remediating vulnerabilities.

  • 4.2Defender for Cloud Apps

    Understand Microsoft Defender for Cloud Apps: connecting via the Microsoft 365 app connector, policies (activity/file policies that trigger alerts), Cloud App Discovery for shadow IT, and interpreting/responding to the activity log.

5Manage compliance by using Microsoft Purview

  • 5.1Information protection

    Understand defining sensitive data with sensitive information types, classifying/encrypting/marking with sensitivity labels and label policies, and visibility via Content explorer and Activity explorer.

  • 5.2Data lifecycle management

    Understand retention labels (item-level retain/delete), retention label policies (publish/auto-apply labels), and retention policies (location-level bulk retain/delete), plus retention periods and deletion actions.

  • 5.3Data loss prevention (DLP)

    Understand applying DLP policies to Exchange Online/SharePoint Online/OneDrive/Teams to block sharing/sending of sensitive info, Endpoint DLP for device control, and reviewing/responding to DLP alerts/events/reports.