MS-102 Exam Guide: Microsoft 365 Administrator
MS-102 validates whether an experienced administrator can deploy and manage a Microsoft 365 tenant, administer Microsoft Entra identity and access, manage security with Microsoft Defender XDR, and manage compliance with Microsoft Purview. It is intended for administrators who coordinate cloud or hybrid Microsoft 365 environments across workloads, identity, security, endpoints, and compliance. This guide helps you decide whether your current experience is sufficient, which skills deserve the most study time, how to schedule before the retirement date, and how to turn Microsoft’s objectives into a practical preparation plan.
What MS-102 validates
MS-102 tests the integrating work of a Microsoft 365 administrator rather than a single workload specialty. The role connects tenant configuration, identity, security, and compliance decisions, often while coordinating with architects and administrators responsible for infrastructure, applications, endpoints, and individual Microsoft 365 workloads.
Microsoft identifies four measured areas: deploy and manage a Microsoft 365 tenant; implement and manage Microsoft Entra identity and access; manage security and threats by using Microsoft Defender XDR; and manage compliance by using Microsoft Purview. Treat these as connected operating responsibilities, not four unrelated product lists.
The exam is part of the requirements for Microsoft 365 Certified: Administrator Expert. Microsoft’s certification page describes the administrator as the hub that coordinates across Microsoft 365 workloads. That framing matters when you study: a question may test whether you can select an appropriate administrative, identity, security, or compliance control for a stated organizational situation.
Who should take it
Microsoft says the exam is designed for administrators who deploy and manage Microsoft 365 and perform tenant-level implementation and administration in cloud and hybrid environments. Candidates should have functional experience with all Microsoft 365 workloads and Microsoft Entra ID and should have administered at least one of them.
This is not an entry-level orientation to Microsoft 365. A candidate who has only read product documentation may recognize the names of services but still struggle to choose the correct control, understand dependencies, or distinguish an identity problem from a security or compliance problem.
Microsoft also identifies networking, Active Directory Domain Services, DNS, and PowerShell as working-knowledge areas. Use that requirement as a readiness filter. If directory synchronization, name resolution, network connectivity, or scripted administration is unfamiliar, address those gaps before relying on exam-focused review.
How it connects to the expert certification
Passing MS-102 alone does not satisfy every requirement for Microsoft 365 Certified: Administrator Expert. Microsoft requires at least one qualifying associate certification in endpoint administration, Teams administration, identity and access administration, or information security administration.
Check your certification profile and the current Microsoft certification page before scheduling. The required associate credential is a separate decision from MS-102 preparation: it affects whether passing this exam will complete the expert certification requirements or only satisfy the exam component.
Microsoft states that the Microsoft 365 Certified: Administrator Expert certification and its related exam will retire on November 30, 2026, after which the certification can no longer be earned or renewed. If the expert credential is your goal, verify the current requirements and allow enough time to complete all necessary requirements before that date.
Which skills deserve the most study time
The largest official weighting is Microsoft Defender XDR, followed by Microsoft Entra identity and access. Those percentages should influence your study allocation, but they do not make the smaller domains optional: tenant administration and Purview compliance remain explicitly assessed and can expose gaps that broad product familiarity hides.
Microsoft lists Deploy and manage a Microsoft 365 tenant at 10-15%. Study tenant configuration, subscriptions and component services, user accounts and licenses, security groups, administrative roles, tenant health, services, Microsoft 365 Apps for enterprise, and the administrative context of workplace analytics.
Microsoft lists Implement and manage Microsoft Entra identity and access at 25-30%. Prepare to reason about identity synchronization, synchronized identities, password management, multifactor authentication, self-service password management, and access administration. Connect each topic to directory, DNS, networking, and PowerShell foundations rather than studying Entra as an isolated portal.
Microsoft lists Manage security and threats by using Microsoft Defender XDR at 35–40%. This is the largest exam domain. The official preparation material covers common threat vectors, Microsoft security solutions, Secure Score, Identity Protection, Exchange Online Protection, Safe Attachments, Safe Links, security reports, Microsoft 365 Defender, Defender for Cloud Apps, and Defender for Endpoint.
Microsoft lists Manage compliance by using Microsoft Purview at 15-20%. Focus on data governance, archiving and retention, Purview message encryption, data loss prevention, insider risk management, information barriers, data classification, and sensitivity labels. The key study task is understanding how these controls apply to information and users, not memorizing isolated feature names.
Turn the weights into a study allocation
Use the official domain ranges to set priorities, then adjust them with a diagnostic. A practical starting point is to devote the greatest study block to Defender XDR, the next to Entra identity and access, and shorter but deliberate blocks to Purview and tenant management. This is a recommendation, not an additional Microsoft requirement.
Do not average the domains into a single score target. A weak area can remain weak even when strong product knowledge elsewhere makes practice results look acceptable. Record each missed objective by domain and by cause: unfamiliar feature, incorrect prerequisite, confusion between similar controls, or failure to read the scenario constraint.
Revisit the official study guide when planning. Microsoft updates exams to reflect role requirements, and the English-language MS-102 exam was updated on April 28, 2026. Localized versions may be updated later, so check the study guide and the exam details page for the version and language you intend to take.
Build a study plan from the official learning paths
Start with Microsoft Learn’s MS-102 study guide and use the official objectives as your checklist. Then use the Microsoft 365 tenant learning path and MS-102T00 course to fill knowledge and practical gaps. Read for decisions and dependencies, and verify that your notes map back to a measured domain.
The Manage your Microsoft 365 tenant learning path covers administrative roles, tenant health and services, Microsoft 365 Apps for enterprise, and workplace analytics using Microsoft Viva Insights. Its stated prerequisites include proficient DNS understanding, basic functional experience with Microsoft 365 services, general IT practices, and working PowerShell knowledge.
The MS-102T00 course covers tenant management, identity synchronization, security, and compliance. It includes organizational profile and subscription configuration, user accounts and licenses, security groups and administrative roles, Office client connectivity, Microsoft 365 Apps deployment, Azure Active Directory Connect and Connect Cloud Sync, password management, threat protection, Defender services, data governance, retention, encryption, DLP, insider risk, information barriers, classification, and sensitivity labels.
The course is listed as intermediate and offers instructor-led or self-directed preparation. Use instructor-led training if you need a structured explanation of dependencies or a guided sequence. Use self-paced material if you can consistently test each objective against a tenant, lab, documented configuration, or carefully reasoned scenario.
Use a four-pass reading method
On the first pass, map the syllabus to the four exam domains. Do not attempt to memorize every setting. Mark topics you have administered, topics you have observed but not configured, and topics you know only from documentation.
On the second pass, write a decision note for each marked gap. For example: what administrative role is needed, which identity source is authoritative, what service detects or prevents a threat, what data condition activates a compliance control, and what side effect or dependency must be checked?
On the third pass, perform or simulate the workflow. If you have a suitable practice tenant, configure representative identities, roles, security policies, and compliance policies without using live production data. If you cannot perform the task, trace the workflow through Microsoft Learn and record the sequence, prerequisites, and expected administrative outcome.
On the fourth pass, explain the choice without looking at your notes. A useful explanation names the requirement, the selected service or control, the reason alternatives do not fit, and the operational consequence. This method is more reliable than copying portal navigation into a list.
Use a single scenario notebook
Keep one notebook divided into tenant, Entra, Defender XDR, and Purview sections. For every topic, capture five items: the administrative objective, the relevant service, required identity or role context, a dependency such as DNS or synchronization, and a verification or monitoring step.
Add a “why not” column. Similar controls are easier to distinguish when you write why a different service would not meet the requirement. For example, separate identity access decisions from endpoint or threat-detection decisions, and separate data retention from DLP prevention decisions.
This notebook becomes your final review source. It should contain your reasoning and corrections, not copied exam questions. Microsoft’s exam sandbox can help you learn the interface and question formats, but it does not provide access to real exam content.
Study tenant management as an operating foundation
Tenant management is the foundation for the other domains. Prepare to connect organizational settings, subscriptions, services, users, licenses, groups, roles, client connectivity, app deployment, service health, and incident response to the administrative outcome a scenario requests.
Begin by reviewing administrative roles and role groups. The official tenant learning path addresses role management, configuration best practices, delegation, and privilege elevation. Your notes should distinguish broad administrative authority from delegated responsibility and identify why least-privilege administration reduces unnecessary exposure.
Next, study users, licenses, security groups, and component services together. A scenario may describe a user or group requirement and expect you to reason about the administrative object, license or service dependency, and appropriate delegation. Do not treat licensing as a purely commercial topic; it can determine whether a workload or administrative capability is available.
Review tenant health and services as an operational task. The official learning path includes monitoring the organization’s transition to Microsoft 365, developing an incident response plan, and requesting assistance from Microsoft. Practice translating a service-health symptom into an investigation sequence instead of immediately changing configuration.
Microsoft 365 Apps for enterprise is also included in the tenant learning path and course material. Study both user-driven and centralized deployment concepts, then connect them to client connectivity and the administrator’s responsibility for coordinating endpoint-related work with the wider tenant.
Tenant-management mistakes to avoid
A common mistake is treating every problem as a license assignment problem. First identify the requested capability, the affected users or services, the administrative scope, and the condition that prevents the capability from working.
Another mistake is assigning a powerful role simply because it is familiar. Compare the required task with the permission scope and delegation model described in Microsoft Learn. Your answer should minimize unnecessary privilege while still enabling the stated administrative action.
Do not ignore service health and incident response. A configuration change is not automatically the right response to an outage or service incident. Include health information and evidence gathering in your reasoning before changing tenant settings.
Prepare Entra identity and access through dependencies
Study Entra identity and access as a lifecycle: choose or assess synchronization, manage synchronized identities, apply authentication and password controls, and administer access with appropriate roles. The exam expects working administration judgment, so link each decision to the organization’s directory, network, DNS, and operational constraints.
The MS-102T00 course emphasizes Azure Active Directory Connect and Connect Cloud Sync. Compare their planning and implementation considerations in your notes, including how identities are synchronized and subsequently managed. Avoid memorizing product labels without understanding which directory state and administrative responsibility each option creates.
Review multifactor authentication and self-service password management as operational controls. For each, record the user experience, administrative objective, and likely troubleshooting boundary. A strong preparation note explains whether the requirement concerns authentication assurance, password recovery, synchronization, or authorization.
Use PowerShell for repetition and verification where appropriate. The official prerequisites identify PowerShell as a working-knowledge area; you do not need to turn MS-102 into a scripting certification, but you should be comfortable reading an administrative task, identifying the relevant object, and understanding what scripted administration is intended to accomplish.
Include Active Directory Domain Services, DNS, and networking in your Entra review. These are not side topics when hybrid identity or synchronization is involved. Draw a simple dependency diagram showing on-premises directory objects, synchronization, cloud identities, authentication, and the services that consume those identities.
A practical Entra troubleshooting exercise
Create a written scenario in which a synchronized user cannot access a Microsoft 365 workload. Work through the chain in order: does the object exist in the source directory, is synchronization functioning, is the cloud identity present and correct, can the user authenticate, and does the user have the required access?
Then change one condition at a time, such as a synchronization issue, an authentication requirement, or an authorization assignment. Your goal is not to invent a lab result; it is to train the habit of isolating the layer responsible for the symptom.
Finish by naming the evidence you would check and the least disruptive corrective action. This approach prepares you for scenario questions in which several plausible controls appear technically related but only one addresses the stated failure.
Make Defender XDR your deepest review area
Defender XDR carries the largest official weighting, so it should receive your deepest review and the most scenario practice. Organize the material around prevention, detection, investigation, response, and reporting across Microsoft 365 security services rather than memorizing each product independently.
Review Exchange Online Protection, Safe Attachments, and Safe Links as security controls that address different threat paths. Your notes should state what each control is intended to inspect or protect, what kind of threat scenario activates it, and how policy administration affects the user or message flow.
Study Microsoft Secure Score and Identity Protection as management and risk perspectives, then connect them to the broader security posture. Practice distinguishing a recommendation or risk signal from a direct response control. This prevents a common error: selecting a measurement or investigation feature when the scenario asks for prevention or remediation.
The official material also covers Microsoft 365 Defender, Microsoft Defender for Cloud Apps, and Microsoft Defender for Endpoint. Build a matrix with the workload or signal, the threat or activity being addressed, the administrative action, and the evidence used to verify the response.
Finish with security reports and operational monitoring. A security administrator must be able to determine whether a policy or protection change is producing the intended result. Include alert review, report interpretation, and escalation in your study notes rather than stopping at initial configuration.
How to reason through a security scenario
First identify the threat vector and affected resource. Is the scenario about a message, a link, an attachment, an identity risk, a cloud application, an endpoint, or a cross-workload incident? The object and threat path usually narrow the appropriate Defender capability.
Second identify whether the requested outcome is prevent, detect, investigate, respond, or measure. This distinction separates controls such as protection policies from tools used to investigate signals or assess posture.
Third check scope and side effects. Consider which users, devices, applications, or workloads are affected, and whether the proposed action could disrupt legitimate activity. Finally, name the report, alert, or verification step that confirms the change achieved its purpose.
When reviewing practice material, explain why the rejected options fail. Do not accept an answer merely because its product name sounds security-related. The relevant question is whether its capability, scope, and timing match the requirement.
Security preparation pitfalls
Do not reduce Defender XDR to a catalogue of feature definitions. Questions can require coordination across identity, messaging, endpoint, cloud application, and threat intelligence functions, which is why the integrating-administrator perspective matters.
Do not confuse a security recommendation with an enforced policy. A posture score can prioritize improvements, while a protection control changes how a workload handles activity. Keep those outcomes separate in your notebook.
Avoid studying only the newest or most visible features. Microsoft notes that most questions cover generally available features, although commonly used preview features may appear. Use the current study guide and focus first on the listed role skills and generally available capabilities.
Approach Purview as information governance
Purview preparation is strongest when you start with the information risk and desired lifecycle outcome. The official course material covers archiving and retention, message encryption, DLP, insider risk management, information barriers, data classification, and sensitivity labels. Map each control to the information condition it addresses.
Separate retention from DLP in your notes. Retention concerns how long information is kept or governed across its lifecycle; DLP concerns detecting and controlling risky handling or sharing. A scenario can mention sensitive information while requiring either a lifecycle rule or an activity restriction, so the requested outcome matters.
Study data classification and sensitivity labels as the basis for applying protection and governance decisions consistently. Record how classification supports policy scope and how labels relate to the protection of information. Do not assume that naming a sensitive data type automatically answers a question about retention, encryption, insider risk, or information barriers.
Review insider risk management and information barriers as distinct compliance concerns. The first addresses risk associated with user activity and organizational processes; the second addresses communication or collaboration boundaries. Use the scenario’s users, information flow, and organizational constraint to select the appropriate direction.
Include verification and exception handling in your notes. A compliance policy is not complete from an administrator’s perspective until you know what evidence, alert, report, or review process would show whether it is working as intended.
A Purview comparison exercise
Write four short requirements using the same sensitive information but different outcomes: keep it for a defined lifecycle, prevent inappropriate sharing, protect access to the content, or restrict collaboration between groups. For each requirement, select the relevant Purview concept and explain why the other three are not the primary answer.
Then add a business constraint, such as a need to preserve legitimate work or investigate a potential insider-risk event. This forces you to consider scope and operational impact rather than choosing the most restrictive control by default.
Review your answers against the Microsoft Learn course and current study guide. The purpose is to improve classification and reasoning, not to create a bank of supposed exam questions.
Use practice assessments and the exam sandbox correctly
Microsoft provides a free practice assessment for MS-102 and an exam sandbox. Use the assessment to locate weak objectives and the sandbox to learn the interface and available question styles. Neither resource should replace hands-on administration, reading, or scenario-based reasoning.
Take a baseline assessment before intensive review if one is available to you. Categorize every uncertain or incorrect response by official domain and by knowledge gap. Then study the underlying Microsoft Learn material before attempting another assessment.
Use the sandbox to become comfortable with navigation, review behavior, and the general interaction model. Microsoft warns that the sandbox’s secure browser is not enabled, so it is an orientation tool rather than a full test of the secured exam environment.
Microsoft says most certification exams typically contain between 40-60 questions, although the number can vary. Do not build a minute-by-minute plan around an assumed question count. At the start of the exam, review the overview pages carefully because they explain what to expect, including whether labs are available.
Do not use exam dumps, leaked questions, or memorization claims as a preparation method. They do not demonstrate the administration judgment MS-102 measures and can leave you unable to handle changed objectives or unfamiliar scenarios. Build competence from the official objectives, Microsoft Learn, legitimate practice assessment feedback, and your own configuration reasoning.
How to review a missed question
Write the requirement in your own words before looking at the answer explanation. Identify the object, workload, threat or compliance condition, required outcome, and constraint. Then explain why your selected option did not satisfy one of those elements.
Locate the related official objective and update your scenario notebook with a short rule and a counterexample. For instance, note the difference between a control that prevents activity and a report that measures it, or between authentication and authorization.
Retest the concept later in a new scenario. Repeating the same question encourages answer recognition; changing the users, workload, or constraint tests whether you understand the underlying decision.
Schedule MS-102 without avoidable problems
Confirm the retirement and current exam details before you commit to a date. Microsoft states that MS-102 and the Microsoft 365 Certified: Administrator Expert certification will retire on November 30, 2026. The exam page also says to confirm exact pricing with the exam provider before registering.
Use a personal Microsoft account for your certification profile. Microsoft recommends this because exam records associated with an organizational work or school account can be lost and unrecoverable after you leave that organization. Make sure your legal name in the profile exactly matches your government-issued identification.
On the certification or exam details page, select the scheduling option and follow the provider instructions. Microsoft says candidates taking a certification on their own or as part of a training program should select Schedule with Pearson VUE. Students, academic-institution members, and Microsoft Office Specialist candidates may have a Certiport route; confirm the option shown for your situation.
Microsoft allows certification exams to be scheduled no more than 90 days in advance and permits a maximum of two Microsoft Certification exams scheduled at a time through Pearson VUE. Check the live scheduling page for available appointments, provider options, language availability, and any current policy details.
Request accommodations before scheduling if you need extra time, special equipment, or another modification. If your preferred language is unavailable, Microsoft says you can request an additional 30 minutes. The study guide lists MS-102 in English, Chinese (Simplified), German, Spanish, French, Japanese, and Portuguese (Brazil), but verify the currently available language in the Schedule Exam section.
Choose online delivery or a test center
Choose a test center if you prefer a pre-configured environment or do not want to troubleshoot your computer, network, and testing room. Choose online delivery only after checking the technical and room requirements and completing the required system test in the same computer and location you plan to use.
For online delivery, Pearson VUE proctors monitor the session through a webcam and microphone. Microsoft requires identity verification with a current government-issued ID, and the profile name must match the ID. Mobile phone photos must be uploaded for exam launch so the greeter can review them with your headshot and ID.
Use a personal computer if possible; Microsoft notes that work computers may contain software that prevents OnVUE from launching. Check local administrative permissions, security software, network restrictions, and the required system pre-check. A hard-wired connection may help avoid network disruption, but it does not replace the official system test.
Online exams are available in most, but not all, countries or regions. Even when the exam is localized, greeter and proctor support and proctoring software are communicated in English, with possible limited Japanese availability. Choose delivery and language with those practical conditions in mind.
If you do not want facial comparison technology used, Microsoft directs you to schedule at a test center. If you do not wish to be recorded, notify the proctor immediately and reschedule at a test center. Review the current online-exam rules before booking.
Plan for check-in and exam time
Microsoft says online candidates can check in from 30 minutes before up to 15 minutes after the appointment time. The launch and check-in process takes approximately 15 minutes but may take longer depending on the computer configuration, so do not schedule the appointment directly against another obligation.
Microsoft’s duration table lists associate and expert role-based exams without labs at 100 minutes of exam time and 120 minutes of seat time, while associate and expert role-based exams that may contain labs have 120 minutes of exam time and 140 minutes of seat time. The provider supplies the applicable exam time when you register, and the launch overview identifies whether labs are available.
The number of questions and the presence of labs can change. Allocate time for reading scenario constraints, marking uncertain items, and reviewing permitted questions, but avoid spending so long on one item that later questions receive inadequate attention.
Unscheduled breaks are allowed on role-based exams. Microsoft says five minutes are built into the exam time for breaks, the exam clock continues while you are away, and you cannot return to questions viewed before launching a break. Initiate the break through the exam interface and do not access unauthorized materials.
Follow a practical MS-102 study roadmap
A staged roadmap is more useful than a fixed number of study days because candidates begin with different experience. Move from readiness assessment to tenant foundations, identity, security, compliance, and integrated review. Schedule only when you can explain the objectives and diagnose scenarios, not merely recognize service names.
Use the first stage to establish your baseline. Read the current MS-102 study guide, note the update date and retirement warning, take the available practice assessment, and classify gaps by the four official domains. Confirm whether you already hold a qualifying associate certification for the expert credential.
In the second stage, cover tenant management and identity together. Work through the tenant learning path and relevant MS-102T00 material. Review roles, groups, licenses, tenant health, service management, app deployment, synchronization, authentication, password management, DNS, networking, and PowerShell. Produce a dependency map and at least one troubleshooting scenario.
In the third stage, give the longest focused block to Defender XDR. Cover messaging protections, identity risk, Secure Score, security reporting, Defender for Cloud Apps, Defender for Endpoint, and Microsoft 365 Defender. For each topic, practice identifying the threat, desired outcome, scope, response, and verification evidence.
In the fourth stage, study Purview by outcome. Compare retention, archiving, encryption, DLP, classification, sensitivity labels, insider risk management, and information barriers. Write scenarios that use the same data but require different controls so that you learn to distinguish purpose from terminology.
In the final stage, perform integrated review. Mix domains in each session, use the sandbox, revisit missed objectives, and explain cross-workload decisions aloud or in writing. Confirm the exam language, delivery method, profile identity, accommodations, appointment, and retirement implications before registering.
A readiness checklist
You are closer to readiness when you can describe how tenant administration supports identity, how identity affects security, how security signals may inform response, and how compliance controls govern information without confusing their purposes.
Check that you can do the following: map every official objective to a study note; explain the role of DNS, networking, Active Directory Domain Services, and PowerShell in relevant administration; compare synchronization approaches; distinguish prevention, detection, investigation, response, and measurement; and separate retention, DLP, classification, labels, insider risk, and information barriers.
You should also be able to read a scenario for constraints such as administrative scope, affected users, hybrid dependencies, workload boundaries, or business impact. If your answer changes whenever a product name changes, continue studying the underlying capability rather than memorizing the label.
Finally, complete a scheduling check. Verify the current study guide, passing-score information, available language, provider, test-center or online option, account identity, accommodations, and the retirement deadline on Microsoft Learn. These are administrative readiness tasks, not optional extras.
The last review session
Use the last session to consolidate, not to begin a new product area. Review your domain notes, incorrect-answer log, dependency diagrams, and comparison tables. Focus on distinctions that repeatedly caused errors.
Read the exam overview and delivery guidance again, especially if you are taking the exam online. Confirm the computer, room, identification, profile name, and check-in plan. Keep the final review grounded in official materials and your own reasoning rather than unauthorized question collections.
On exam day, read the complete scenario and identify the requested outcome before evaluating answer choices. Mark uncertainty when the interface allows it, manage the clock, and remember the break rule: once a break is launched, previously viewed questions cannot be revisited.
What to do next
Begin with the current Microsoft Learn MS-102 study guide, then compare your experience with the audience profile and working-knowledge expectations. Use the official skill percentages to prioritize, but let diagnostic results determine where your time goes. If you intend to earn Administrator Expert, verify the associate-certification requirement and the November 30, 2026 retirement deadline before setting a schedule.
Next, choose one concrete action from each domain: review tenant roles and health, trace an identity synchronization scenario, build a Defender XDR threat-response matrix, and compare Purview controls by information outcome. Record what you cannot explain and return to the corresponding Microsoft Learn material.
When the technical gaps are controlled, schedule through the appropriate provider using a personal Microsoft account, confirm the live price and language information, request accommodations in advance if needed, and choose online or test-center delivery based on your equipment and testing preferences. MS-102 preparation is complete when you can make and defend cross-workload administration decisions—not when you have simply finished reading a course.
Conclusion
MS-102 is a role-based assessment of coordinated Microsoft 365 administration across tenant operations, Entra identity, Defender XDR, and Purview compliance. Prepare from the current official objectives, spend the greatest effort on the Defender XDR and Entra domains, and use tenant-management and MS-102T00 materials to connect concepts to administrative decisions. Before booking, verify the current exam details, delivery conditions, profile information, qualifying associate certification, and retirement deadline so your study plan leads to the credential you actually intend to earn.