AzureMS-102

MS-102 Microsoft 365 Administrator: Tenant Management, Security, and Compliance

MS-102 is the Microsoft 365 Administrator Expert certification — the most comprehensive Microsoft 365 credential. It validates your ability to manage the full Microsoft 365 tenant: user and licence management, security and compliance configuration, Teams and Exchange administration, and Copilot deployment. It is the successor to MS-100 and MS-101 combined, redesigned for the AI-era Microsoft 365 environment. This is the exam for senior M365 administrators responsible for a complete Microsoft 365 deployment.

11 min
3 sections · 10 exam key points

Microsoft 365 Tenant Administration

Tenant administration for MS-102 covers the full breadth of M365 admin. Microsoft 365 Admin Center: central hub for all M365 admin tasks — user creation, licence assignment, service health, billing. Role-based administration: multiple admin roles with varying scopes — Global Admin (unrestricted), Exchange Admin (Exchange Online only), Teams Admin (Teams policies), Security Admin (Defender and compliance settings). Principle of least privilege: assign the most restrictive role that meets the admin's needs. Microsoft 365 Copilot administration: Copilot requires M365 E3/E5 base licence plus Copilot add-on, enable per user or group, review Copilot usage reports (Microsoft 365 Admin Center > Reports > Adoption score), configure data boundary settings. eDiscovery and Purview: Content Search (find emails and Teams messages — keyword query syntax, date ranges, mailbox filters), Core eDiscovery (preserve, collect, review, export content for legal requests), Purview eDiscovery Premium (custodian management, advanced ML-based review, export in EDRM XML format). Information barriers: restrict communication between groups (e.g., investment banking and retail banking cannot communicate via Teams — compliance requirement).

Exchange Online Administration

Exchange Online is the M365 email platform. Mailbox types: User mailbox (individual users), Shared mailbox (accessible by multiple users, no licence required for read/send — requires licence for mobile access), Room mailbox (meeting room calendars — bookable resource), Equipment mailbox (projectors, vehicles — bookable). Mail flow: connectors (inbound from on-premises, outbound to on-premises or third-party) — hybrid configuration wizard automates connector creation for Exchange hybrid. Mail flow rules (transport rules): evaluate messages in transit and apply actions (add disclaimers, redirect messages, block sensitive data). Anti-spam and anti-phishing: Exchange Online Protection (EOP) — included with all M365 plans, Defender for Office 365 Plan 1/2 adds Safe Links and Safe Attachments. DKIM (DomainKeys Identified Mail): cryptographic signature in email headers — prove email actually sent from your domain. DMARC (Domain-based Message Authentication): policy for how receivers should handle email that fails SPF or DKIM checks (quarantine or reject). SPF record: lists authorised sending IPs for your domain. Implement all three (SPF + DKIM + DMARC) for full email authentication.

Teams, SharePoint, and Compliance Administration

Teams administration for MS-102. Teams policies: meeting policies (allow/deny cloud recording, screen sharing, external participants), messaging policies (allow editing/deleting messages, read receipts), calling policies (PSTN calling permissions if Teams Phone licensed). Teams Phone (Direct Routing vs Calling Plans): Calling Plan purchases phone numbers from Microsoft, Direct Routing connects on-premises telephony to Teams via a Session Border Controller (SBC). Sensitivity labels: Microsoft Purview Information Protection labels classify and protect content — applied to emails, Office documents, Teams channels, SharePoint sites. Label actions: encryption (rights management — control who can open, edit, print), content marking (headers, footers, watermarks), auto-labelling (based on sensitive information types or trainable classifiers). SharePoint administration: site collections (Teams-connected sites, communication sites, classic sites), storage limits per site, external sharing settings (Anyone link, authenticated guests, block external sharing). Retention policies and retention labels: keep content for a defined period (legal hold, regulatory retention), delete content after a period, or both. Adaptive scopes: dynamically target policies to users or sites based on attributes (department, country, site classification).

Key exam facts — MS-102

  • MS-102 is the successor to MS-100 + MS-101 combined — covers full M365 expert scope
  • Global Admin has unrestricted access — assign least-privilege roles (Exchange Admin, Teams Admin)
  • Shared mailbox: no licence required for web access; licence required for mobile/desktop client access
  • DKIM signs outbound email; DMARC enforces action on SPF/DKIM failures; SPF authorises sending IPs
  • Defender for Office 365 Plan 1: adds Safe Links and Safe Attachments on top of base EOP
  • Sensitivity labels: encrypt, mark, and auto-label content across M365 services
  • Teams Direct Routing: connect on-premises telephony via SBC — bring your own PSTN
  • Retention labels: keep, delete, or keep-then-delete content — per item; retention policies = per location
  • eDiscovery Core: preserve and export; eDiscovery Premium: adds custodian management and ML review
  • Information barriers: prevent Teams communication between specified compliance-separated groups

Common exam traps

Global Administrator is the standard admin account for day-to-day tasks

Global Admin accounts should be kept for emergency access and tightly controlled (separate admin accounts, MFA, PIM just-in-time activation). Day-to-day admin tasks should use the most restrictive role that permits the task — this limits blast radius if an admin account is compromised.

Retention policies and litigation hold do the same thing

Litigation hold preserves a single mailbox or site indefinitely for legal proceedings. Retention policies apply organisation-wide rules to keep or delete content after defined periods — for regulatory compliance. Both can coexist, and the most restrictive policy wins (content kept longest when multiple policies conflict).

Practice this topic

Test yourself on MS-102 M365 Administrator

JT Exams routes you to questions in your exact weak areas — automatically, after every session.

No credit card · Cancel anytime

Related certification topics