Microsoft MS-102 Microsoft 365 Administrator 1-10

表示モード
画像位置
文字位置
理解度の自動記録
STATUS FILTER

Choose confidence levels to display

Loading...
Q1MS-102
Show answer
Correct answer: C. Windows 11 and Windows 10 only

Co-management is a mechanism that manages a single Windows client simultaneously with both Microsoft Configuration Manager and Microsoft Intune.
This feature supports Windows 10 and later clients, and Windows 8.1 and macOS are not eligible for co-management.
Therefore, only Windows 11 and Windows 10 devices can be co-managed after deployment.
It is important to accurately distinguish that the supported OSes for co-management are limited to Windows 10 and later.
Note that Azure Active Directory in the question has now been renamed to Microsoft Entra ID.
Co-management for Windows devices – Configuration Manager

Q2MS-102
Name Type
User1 User
Group1 Microsoft 365 group
Group2 Mail-enabled security group
Group3 Distribution group
Show answer
Correct answer: C. User1 and Group2 only

For delegation to a shared mailbox, you can assign users and mail-enabled security groups.
On the other hand, Microsoft 365 groups and distribution groups cannot be specified as members of a shared mailbox.
Therefore, only User1 and Group2 can be added.
It is important to be able to distinguish that only users and mail-enabled security groups can be used as delegation targets.
Manage permissions for recipients in Exchange Online | Microsoft Learn

Q3MS-102
Show answer
Correct answer: B. XLSX

In Compliance Manager, an Excel-format file is generated when you export an existing template.
Microsoft Learn also explains that downloading the current or an updated template produces an Excel file.
Therefore, among the options, XLSX is the correct answer.
It is important to correctly distinguish that the export format is not CSV, JSON, or XML.
Build and manage assessments in Microsoft Purview Compliance Manager | Microsoft Learn

Q4MS-102
Show answer
Correct answer: D. Microsoft 365 admin center

A mail-enabled contact is treated as an Exchange Online recipient, and the actual creation is done in the Exchange admin center.
However, because the Exchange admin center is not among the options, the most appropriate entry point to navigate there is the Microsoft 365 admin center.
You cannot create it in the Microsoft Entra admin center, Purview, or the SharePoint admin center.
It is important to grasp that managing mail recipients is within the Exchange administration domain.
Manage mail contacts in Exchange Online

Q5MS-102
The location where DLP1 cannot be applied

The documents to which DLP1 applies

Show answer
Correct answer: Exchange email / Documents that have either a credit card number or a 1-year label applied

Because DLP1’s matching condition is set to “any of these,” a document qualifies if either a credit card number is detected with a match accuracy of 85-100, or the document has a 1-year retention label applied.
However, retention labels can be used as a condition only for SharePoint and OneDrive, and cannot be used for Exchange email.
Therefore, the location where DLP1 cannot be applied is Exchange email, and the applicable documents are those that have either a credit card number or a 1-year label.
Data loss prevention policy reference | Microsoft Learn

Q6MS-102
Category Name Content Scope
Administrative unit AU1 Group1, User2
Administrative unit AU2 Group2, User3, User4
Group Group1 User1
Group Group2 User2, User4
User User1 No role N/A
User User2 Password Administrator AU1
User User3 License Administrator Organization
User User4 No role N/A
Statement Yes No
User2 can reset User1’s password
User2 can reset User4’s password
User3 can assign a license to User1
Show answer
Correct answer: Statement 1 “No” / Statement 2 “No” / Statement 3 “Yes”

In the current official specification, when a group is added to an administrative unit, the group itself becomes managed, but the users who are members of the group are not automatically included in the management scope.
Therefore, User2, who is a Password Administrator scoped to AU1, cannot reset the password of User1 (via Group1) or User4 (who belongs to a different administrative unit).
On the other hand, User3, who is a License Administrator scoped to the organization, can assign a license to User1.
Therefore, the determinations are No, No, and Yes.
Add users, groups, or devices to an administrative unit

Q7MS-102
Name Platform
Device1 Windows 10
Device2 Android
Device3 iOS
VPN device configuration profile

Endpoint Protection device configuration profile

Show answer
Correct answer: Device1, Device2, Device3 / Device1 only

The VPN device configuration profile supports multiple platforms such as Windows, Android, and iOS, so the targets are all of Device1, Device2, and Device3.
On the other hand, because the Endpoint Protection device configuration profile primarily targets Windows and macOS, only Device1 (Windows 10) applies in this table.
It is important to accurately distinguish that the supported platforms differ by profile type.
Device features and settings in Microsoft Intune – Microsoft Intune | Microsoft Learn

Q8MS-102
Activity to search

Field to filter by

Show answer
Correct answer: Show results for all activities / Detail

Because creating a role is a management operation not limited to a specific workload, it is appropriate to first set the search target to “Show results for all activities.”
Furthermore, because you need to narrow down by the created role name Role1, you filter by the “Detail” field rather than by user name or IP address.
This allows you to check the operation target name within the audit record and identify the administrator who created Role1.
It is important to distinguish what to search for in the audit log and which column to filter by.
Search the audit log

Q9MS-102
Show answer
Correct answer: A. Yes

This solution achieves the goal.
Microsoft Learn explicitly lists Windows Server 2019 as capable of configuring Windows Update for Business client policies.
By upgrading Server1 to Windows Server 2019 and using the GPMC, you can manage the Windows Update for Business Group Policy settings for Windows 10.
The question addresses that what matters is whether the management endpoint’s OS is supported, not the functional level.
Configure Windows Update client policies | Microsoft Learn

Q10MS-102
Name Platform
Device1 Windows 11
Device2 Android
Device3 Linux
Name Template
Policy1 Microsoft Defender Antivirus
Policy2 Device control
Policy1

Policy2

Show answer
Correct answer: Device1 only / Device1 or Device2 only

Policy1’s template, Microsoft Defender Antivirus, is configured for Windows in Intune.
Therefore, only Device1 (Windows 11) can be applied in this question.
On the other hand, Policy2’s Device control supports multiple platforms, and in this question, Device1 or Device2 is the applicable target.
It is important to distinguish that the applicable platforms differ for each endpoint security policy.
Endpoint security in Microsoft Intune – Microsoft Intune | Microsoft Learn