MS-102: Microsoft 365 Administrator Exam Guide
MS-102 validates the tenant-level administration skills used to connect Microsoft 365 workloads across cloud and hybrid environments. It suits administrators who already work with Microsoft 365 and Microsoft Entra ID, rather than candidates looking for a first exposure to either platform. Use this guide to decide whether the exam and its related certification fit your current path, prioritize the measured domains, build practical administration fluency, and schedule before the published retirement deadline.
Decide whether MS-102 is the right next exam
MS-102 is aimed at administrators who deploy and manage Microsoft 365 and perform tenant-level implementation and administration in cloud and hybrid environments. Microsoft describes the role as an integrating hub that coordinates work across Microsoft 365 workloads and works with administrators and architects responsible for identity, security, compliance, endpoints, infrastructure, and applications.
The intended candidate has functional experience with Microsoft 365 workloads and Microsoft Entra ID and has administered at least one of them. Microsoft also identifies networking, Active Directory Domain Services, DNS, and PowerShell as working-knowledge areas. That profile matters: the exam spans decisions and dependencies between services, not a narrow configuration specialty.
A useful readiness check is to ask whether you can explain the administrative consequence of a change before selecting a setting. For example, can you distinguish tenant administration from workload administration, identify when identity synchronization affects account management, and connect a security control with its operational reporting or compliance implications? If those links are unfamiliar, build them before treating practice questions as a primary study method.
MS-102 is required for the Microsoft 365 Certified: Administrator Expert certification, but passing MS-102 alone is not the whole certification requirement. Microsoft’s certification page says candidates also need at least one listed associate certification: Microsoft 365 Certified: Endpoint Administrator Associate, Microsoft 365 Certified: Teams Administrator Associate, Microsoft Certified: Identity and Access Administrator Associate, or Microsoft Certified: Information Security Administrator Associate. Check which associate credential best matches the work you already perform before committing to the expert path.
Account for the retirement date
MS-102 and the Microsoft 365 Certified: Administrator Expert certification retire on November 30, 2026, at 11:59 PM Central Standard Time. Microsoft states that the certification can no longer be earned or renewed after that date.
This makes timing a real decision, not an administrative afterthought. Build enough margin for study, a scheduling change if needed, and completion of the associated certification requirement. Before paying or booking, review the current MS-102 page and the related certification page, because Microsoft directs candidates to the related certification requirements after retirement.
Know what a pass score means
Microsoft lists 700 as the passing score for MS-102. Treat that as the required outcome, not as a target for a single practice result.
A better preparation standard is repeatable reasoning: for each objective, state the business need, identify the relevant Microsoft 365 or Entra administrative capability, and explain the impact on adjacent services. This exposes shallow familiarity earlier than repeated answer recall.
Use the measured skills to allocate study time
The current English-language MS-102 skills list emphasizes security and threat management most heavily, while still requiring broad tenant, identity, and compliance administration. Microsoft updated the English-language exam on April 28, 2026, so base your notes and learning resources on the current study guide rather than an older objective list.
The official domains are ranges, not a promise of a fixed number of questions. Use them to divide study time and to identify gaps, while recognizing that an individual exam can test related scenarios across domains. Microsoft also notes that most questions cover general-availability features, although commonly used Preview features may appear.
Deploy and manage a Microsoft 365 tenant: 10-15%
Deploy and manage a Microsoft 365 tenant accounts for 10-15% of the MS-102 skills measured. The related Microsoft training content includes organizational profile, tenant subscription options, component services, user accounts and licenses, security groups, administrative roles, Office client connectivity, and Microsoft 365 Apps for enterprise deployment.
Do not dismiss this domain because its published range is smaller. Tenant foundations supply the context for identity, security, and compliance decisions. Review administrative roles and delegation closely enough to explain why a role assignment is appropriate, then connect that choice to least-privilege administration rather than simply memorizing role names.
The Microsoft Learn tenant-management path is useful for organizing this work. Its modules address permissions, roles and role groups; tenant health and services; Microsoft 365 Apps for enterprise; and Microsoft Viva Insights. Use each module to make a short operational checklist in your own words.
Implement and manage Microsoft Entra identity and access: 25-30%
Implement and manage Microsoft Entra identity and access accounts for 25-30% of the MS-102 skills measured. Microsoft’s course outline specifically highlights identity synchronization, Azure Active Directory Connect, Connect Cloud Sync, synchronized identities, multifactor authentication, and self-service password management.
Study identity as a lifecycle and design problem. Start with how an identity is sourced, synchronized, governed, authenticated, and recovered. Then compare alternatives by their administrative consequences. A learner who recognizes product terms but cannot describe the path of a synchronized identity will struggle when a question introduces a hybrid constraint.
Keep DNS, Active Directory Domain Services, networking, and PowerShell active in this part of the plan. Microsoft names them as expected working knowledge, and they provide the background needed to reason about hybrid identity rather than treating synchronization as an isolated wizard.
Manage security and threats by using Microsoft Defender XDR: 35–40%
Manage security and threats by using Microsoft Defender XDR accounts for 35–40% of the MS-102 skills measured, making it the largest published domain. Microsoft’s training outline includes threat vectors and data breaches, Microsoft Secure Score, Entra ID Identity Protection, Exchange Online Protection, Safe Attachments, Safe Links, security reporting, Microsoft Defender, Microsoft Defender for Cloud Apps, and Microsoft Defender for Endpoint.
Give this domain the largest share of hands-on review. Build a map from threat signal to administrative investigation and response capability, then add the reports that help evaluate security health. The purpose is not to memorize a product list; it is to understand how protections, signals, and administrative actions fit together.
A common mistake is studying email protections, endpoint capabilities, cloud-app controls, and identity risk as separate flashcard categories. Instead, take a scenario such as suspicious user activity and identify what evidence and control boundaries may involve identity, messaging, endpoint, and cloud application services. That approach better reflects the cross-workload administrator role Microsoft describes.
Manage compliance by using Microsoft Purview: 15–20%
Manage compliance by using Microsoft Purview accounts for 15–20% of the MS-102 skills measured. Microsoft’s course material identifies data governance, archiving and retention, message encryption, data loss prevention, insider risk management, information barriers, data classification, and sensitivity labels as part of the compliance learning sequence.
Prepare by separating classification, protection, retention, and monitoring in your notes, then connecting them in a policy outcome. For example, be able to explain the difference between identifying sensitive content, applying a protection decision, preserving information for a defined purpose, and reviewing risk-related signals. Avoid assuming that similarly named controls have interchangeable purposes.
Compliance questions often reward careful reading of scope and intent. Before choosing an answer in practice, write down the requested result: prevent an action, apply protection, preserve data, restrict interaction, or surface a risk. This simple step reduces the tendency to choose a familiar Purview feature that does not solve the stated requirement.
Build a study plan around administration workflows
A strong MS-102 plan moves from tenant foundations to identity, then security, then compliance, before returning to cross-domain scenarios. This sequence gives later topics a working tenant and identity context, and it prevents compliance or Defender features from becoming disconnected lists.
Microsoft offers both self-paced and instructor-led preparation. Its MS-102T00-A course is described as intermediate, covers tenant management, identity synchronization, and security and compliance, and is listed with a course duration of 5 days. Treat that duration as the course listing, not as a prediction of the time any individual candidate will need to become exam-ready.
Phase 1: establish the tenant and role model
Begin with tenant configuration, users, licenses, groups, administrative roles, service health, and Microsoft 365 Apps deployment concepts. Make a one-page tenant map that shows which decisions belong to tenant administration and which require coordination with another workload owner.
Practice explaining role delegation in terms of scope and operational responsibility. Then review tenant health and services as an operational activity: identify what must be monitored, who needs to act, and what information should be retained for escalation. The official learning path includes these topics and provides a practical starting structure.
Phase 2: make hybrid identity understandable
Next, study Entra identity and access with a special focus on synchronization planning, synchronized identity management, authentication, and password management. Microsoft’s course specifically addresses Azure Active Directory Connect and Connect Cloud Sync.
Use comparison notes rather than isolated definitions. For every synchronization option or identity-management task, record the intended condition, prerequisite knowledge, administrative outcome, and likely operational concern. Review the notes until you can justify a choice without relying on the wording of a study question.
Phase 3: concentrate on Defender XDR scenarios
Then devote the largest block of your plan to security and threat management, matching the 35–40% Microsoft Defender XDR domain. Work through the services in the official course outline and build a response-oriented study sheet for each one.
For each security topic, answer four questions: what risk is being addressed, which service produces or consumes the relevant information, what control can be administered, and what report or signal helps verify the result? This method turns product knowledge into usable scenario reasoning.
Phase 4: turn Purview topics into policy outcomes
Follow security with Microsoft Purview. Study data governance, retention and archiving, encryption, data loss prevention, insider risk, information barriers, classification, and sensitivity labels as connected controls rather than independent features.
Create a decision table with a business outcome in the first column and the control category in the second. Leave product names out of the first draft. Only after you can identify the correct category should you attach the relevant Microsoft capability. This is a practical safeguard against selecting a familiar tool for the wrong compliance requirement.
Phase 5: test integration and repair weak areas
Finish each study cycle with mixed scenarios that require tenant, identity, security, and compliance reasoning together. MS-102’s audience is expected to coordinate across Microsoft 365 workloads, so your final review should not be divided into four sealed domains.
Use Microsoft’s free Practice Assessment if it is available from the exam page, and use the official exam sandbox to become familiar with the exam interface. After every incorrect or uncertain response, return to the objective and official learning material, identify the missing decision rule, and update a concise error log. Do not use recalled or unauthorized exam content as study material.
Avoid preparation habits that create false confidence
The biggest MS-102 study risk is mistaking recognition for administration competence. The exam covers a connected administrator role, so a long list of feature names is less useful than the ability to select a control that satisfies the requirement while respecting tenant, identity, security, and compliance boundaries.
Use short recall checks, but make each one require a reason. Replace “What is this feature?” with “What administrative outcome does it support, what dependency matters, and what nearby feature would be inappropriate?” That produces notes that remain useful when Microsoft updates an objective or service experience.
Do not study from an obsolete blueprint
Microsoft says its exams are updated periodically to reflect role requirements and that the English version is updated first. The MS-102 English-language exam was updated on April 28, 2026, and localized versions may be updated approximately eight weeks later, though Microsoft says that timing is not guaranteed.
Check the official study guide shortly before you schedule and again before final review. If you are testing in a localized language, compare the available language information on the exam details page and plan from the current applicable objectives rather than assuming a translated resource is synchronized with older notes.
Do not let practice results replace skill review
Practice assessments are preparation feedback, not a substitute for examining the official objectives. Microsoft describes Practice Assessments on Learn as free resources for some exams and notes that they can be available in multiple languages.
Use a practice result to decide what to revisit. A wrong answer may indicate a missing concept, a failure to identify the requested outcome, or a rushed reading error. Classify it before restudying; otherwise, candidates often repeat broad content they already know and leave the actual weakness unchanged.
Do not ignore the credential path
Candidates pursuing the Administrator Expert certification should verify the associate-certification prerequisite alongside MS-102 preparation. Microsoft’s current certification page lists four qualifying associate certifications, and the certification and related exam retire on November 30, 2026.
Keep a simple completion record: qualifying associate certification status, MS-102 study status, planned appointment, and retirement-date margin. This is a practical planning tool, not an official requirement, but it helps prevent a passed exam from failing to support the credential goal because another required element was overlooked.
Plan registration and delivery without assumptions
Schedule from the official MS-102 exam details page after confirming the current exam language, provider options, price for your location, and appointment availability. Microsoft says price is based on the country or region in which the exam is proctored and advises candidates to confirm exact pricing with the provider before registration.
Microsoft strongly recommends using a personal Microsoft account for exam registration because records tied to an organizational work or school account can be lost and unrecoverable after leaving that organization. Confirm that the legal name in your certification profile matches the government-issued ID you will present.
Choose online testing or a test center
In most cases, Microsoft says candidates can choose online delivery or a local test center, but an online option may not be available from a given provider. For online delivery, Pearson VUE proctors monitor through a webcam and microphone.
Choose a test center if a controlled, preconfigured environment better suits your circumstances or if you do not want facial comparison technology used. Choose online delivery only after you can meet the technical and environmental requirements reliably; convenience is not a substitute for a successful system test.
Complete the online readiness checks
For an online MS-102 appointment, complete the required system test on the same computer and from the same location you intend to use on exam day. Microsoft recommends a personal computer where possible because work computers may include software that prevents the OnVUE software from launching.
Ensure the account used on the computer has local administrative permissions. Microsoft also warns that proxy servers, packet inspection or filtering, and strict network security configurations can disrupt online proctored exams; a hard-wired internet connection is suggested where possible. Keep your mobile number, including country code, current in your Microsoft Certification profile in case Pearson VUE needs to contact you.
Know the check-in expectations
Microsoft says online candidates can check in from 30 minutes before through 15 minutes after the appointment time. The launch and check-in process takes approximately 15 minutes and can take longer depending on the computer configuration.
Bring a current government-issued ID. Microsoft states that mobile phone photos must be uploaded to launch the online exam and are reviewed with the headshot and ID; if no phone is available, a webcam can be used. The greeter reviews identity and the room scan before placing the candidate in the proctor queue.
Understand time and breaks
Microsoft does not publish a fixed MS-102 question count in the supplied material. Across Microsoft Certification exams, the typical range is 40-60 questions, but Microsoft says the actual number can vary as the exam changes.
For associate and expert role-based exams without labs, Microsoft lists 100 minutes of exam duration and 120 minutes of seat duration. For associate and expert role-based exams that may contain labs, Microsoft lists 120 minutes of exam duration and 140 minutes of seat duration. Microsoft does not provide a list of exams with labs because labs can be removed, so confirm the information shown when you register and review the overview pages when the exam launches.
Unscheduled breaks are permitted on certification exams other than MOS exams. Microsoft says Five (5) minutes are built into exam time for break time, although the exam clock continues while you are away. Once a break begins, you cannot return to questions viewed before it, including questions marked for review or left unanswered. Plan to resolve or consciously abandon the current set before starting a break.
Use the exam interface deliberately
Microsoft provides an exam sandbox to familiarize candidates with the interface and navigation. The sandbox is for interface practice; Microsoft notes that the secure browser used in a real exam is not enabled there.
When Microsoft Learn access is provided during an exam, the Learn button appears in the left navigation pane. Microsoft says candidates can open multiple Learn tabs and navigate to different portions of the site, except Q&A, practice assessments, and their personal profile. This is a reference capability, not a reason to postpone foundational learning until the appointment.
Practice navigation before the appointment
Use the sandbox to locate navigation controls, review behavior, question formats, and the timer without the pressure of a scored attempt. Microsoft’s exam-experience material shows examples including case studies, drag and drop, hot area, multiple choice, labs, mark review, review screen, and navigation and timer.
During practice, decide on a personal triage rule. For instance, identify questions that need immediate resolution, questions where one official concept lookup could settle a narrow uncertainty, and questions that should be marked for later. The rule is a practical recommendation, but rehearsing it can reduce avoidable time loss.
Treat Learn as targeted reference material
Microsoft Learn access can help with precise documentation checks when it is available, but it should be used sparingly and purposefully. Microsoft notes that candidates can search the current Learn page with Ctrl+F on Windows or Command+F on a Mac.
Before the exam, practice turning a scenario into a specific documentation query: service name, administrative action, and required outcome. Broad searches consume time and may return too much material. Learn the core relationships in advance so any permitted reference use is limited to confirmation rather than discovery.
Set a realistic final-week checklist
The final week should be for validation, not for adding every possible Microsoft 365 topic. Confirm that you can reason through each official domain, schedule only when the technical and logistical requirements are settled, and protect time for reviewing mistakes rather than accumulating more notes.
Start by revisiting the current official MS-102 study guide and exam page. Then use your error log to select focused review sessions. If a gap remains in a high-weighted area, especially the Microsoft Defender XDR domain, make a deliberate choice to postpone scheduling rather than hoping broad familiarity will cover it.
Technical and scheduling checklist
Verify your personal Microsoft account, legal name, government-issued ID, preferred language availability, delivery choice, and current provider pricing. If testing online, repeat the system test using the intended computer and location, review the room and network requirements, and ensure you can complete check-in without last-minute account changes.
Microsoft permits certification exams to be scheduled no more than 90 days in advance and allows a maximum of two Microsoft Certification exams scheduled at a time through Pearson VUE. From the Learn profile, Microsoft says you can manage a scheduled appointment, including rescheduling, cancellation, or beginning a scheduled online exam.
Knowledge checklist
For tenant administration, review roles, licensing, groups, service health, client connectivity, and deployment concepts. For identity, review synchronization planning, synchronized identities, authentication, password management, and the supporting DNS, networking, Active Directory Domain Services, and PowerShell knowledge Microsoft expects.
For security, connect protection capabilities with threats, signals, reports, and response choices across the services named in the official course outline. For compliance, distinguish classification, sensitivity labels, encryption, retention, archiving, data loss prevention, information barriers, and insider risk management by the outcome each supports.
Conclusion
MS-102 is most useful for an administrator who already operates in Microsoft 365 and needs to demonstrate cross-workload tenant, identity, security, and compliance judgment. Prioritize the current official objectives, give Microsoft Defender XDR the largest study allocation, and use hands-on workflow reasoning to connect the domains. Confirm the certification prerequisite path and schedule with enough margin to complete MS-102 before its November 30, 2026 retirement date.