Technology24 min read

FREE MS-102 Exam Guide 2026: Pass Microsoft 365 Administrator (Entra, Defender XDR, Purview)

Free 2026 MS-102 study guide: Microsoft 365 Administrator exam format, $165 fee, 700/1000 passing score, Entra ID + Defender XDR + Purview skills, MS-100/MS-101 replacement, and 8-12 week study plan.

Ran Chen, EA, CFP®April 23, 2026

Key Facts

  • Exam MS-102: Microsoft 365 Administrator launched on March 28, 2023 and earns the Microsoft 365 Certified: Administrator Expert credential.
  • MS-102 replaced the MS-100 and MS-101 pair, both of which retired on September 30, 2023.
  • The MS-102 exam fee is $165 USD in the United States, with pricing set by Microsoft and administered through Pearson VUE test centers and OnVUE.
  • MS-102 uses a scaled passing score of 700 out of 1000, not a fixed percentage, so 700 does not necessarily equal 70% of items correct.
  • The exam contains approximately 40-60 items delivered in 100 minutes via Pearson VUE test centers or OnVUE online proctoring.
  • As of the April 28, 2026 outline revision, MS-102 weights are: tenant management 25-30%, Entra identity 25-30%, Defender XDR security 30-35%, and Purview compliance 10-15%.
  • Microsoft 365 Administrator Expert certifications are valid for 1 year and renewed free via a Microsoft Learn assessment.
  • MS-102 retake policy requires 24 hours after a first failure and 14 days for attempts 2 through 5, capped at 5 attempts per 12 months.
  • US Microsoft 365 Administrator salaries in 2026 typically range $85,000-$130,000 per Glassdoor, ZipRecruiter, Salary.com, and Robert Half.
  • Passing MS-102 alone does not earn the Administrator Expert title; candidates must also hold MD-102, MS-700, SC-300, or SC-401 per the current Microsoft Learn prerequisite list.

📺 Watch the Video

MS-102 Exam Guide 2026: The Only Walkthrough Built Around the Current Skills Measured Outline

If you are a Microsoft 365 administrator in 2026, the single certification that defines your career tier is Exam MS-102: Microsoft 365 Administrator. It is the sole exam standing between you and the Microsoft 365 Certified: Administrator Expert credential - a role-based cert that regulated industries, MSP partners, and enterprise tenants explicitly call out in job descriptions.

Most guides on the internet still reference MS-100 and MS-101, the two-exam predecessor pair Microsoft retired in 2023. If a study plan mentions "sit MS-100 first," it is out of date. This guide is written exclusively for the 2026 exam window: current skills-measured weights, the Entra ID + Defender XDR + Purview stack, the $165 USD Pearson VUE fee, the 700/1000 passing score, and the free Microsoft Learn renewal.

MS-102 At-a-Glance (2026)

ItemDetail (2026)
Full NameExam MS-102: Microsoft 365 Administrator
Credential EarnedMicrosoft 365 Certified: Administrator Expert
DeliveryPearson VUE (test center or online-proctored OnVUE)
Questions~40-60 items (multiple choice, multi-select, drag-and-drop, case studies, lab/performance-based)
Time Limit100 minutes of exam time (~120 minutes total seat time with NDA, instructions, tutorial)
Passing Score700 out of 1000 (scaled)
Exam Fee$165 USD (varies by country; India ~$55, UK £113)
Prerequisites to sit the examNone - MS-102 has no formal exam prerequisite
Prerequisites to earn the credentialPassing MS-102 alone is not enough. You must also hold at least one associate-level cert: MD-102 (Endpoint Administrator), MS-700 (Teams Administrator), SC-300 (Identity & Access Administrator), or SC-401 (Information Security Administrator)
LanguagesEnglish, Chinese (Simplified), German, Spanish, French, Japanese, Portuguese (Brazil) - 7 languages; non-English versions update ~8 weeks after English
Certification Validity1 year; renew FREE on Microsoft Learn (6-month window opens before expiration)
Retake Policy24-hour wait after 1st fail; 14-day wait for attempts 2-5; max 5 attempts per 12 months
LaunchedMarch 28, 2023 (replacing MS-100 + MS-101, both retired September 30, 2023)
RelatedAZ-104 (Azure Administrator), SC-300 (Identity & Access Administrator), SC-401 (Information Security Administrator - replaced SC-400 May 31, 2025), MS-700 (Teams Administrator), MD-102 (Endpoint Administrator)

Source: Microsoft Learn exam page (learn.microsoft.com/credentials/certifications/exams/ms-102), Microsoft MS-102 Study Guide, and Pearson VUE scheduling portal.


Start Your FREE MS-102 Prep Today

Start FREE MS-102 practice questions for the Microsoft 365 Administrator examPractice questions with detailed explanations

Why MS-102 (and Why It Replaced MS-100 + MS-101)

Before March 28, 2023, to earn the Microsoft 365 Certified: Enterprise Administrator Expert title you had to pass two exams:

  • MS-100: Microsoft 365 Identity and Services - tenant planning, identity synchronization, federation, and workloads.
  • MS-101: Microsoft 365 Mobility and Security - device management, threat protection, information governance, and compliance.

Both exams retired on September 30, 2023. Microsoft consolidated the content into a single exam - MS-102 - and renamed the credential simply Microsoft 365 Certified: Administrator Expert (dropping "Enterprise"). The new exam is narrower in scope than MS-100 + MS-101 combined, but tests each domain deeper and with heavier emphasis on Entra ID, Microsoft Defender XDR, and Microsoft Purview - the three pillars Microsoft has invested most aggressively in since 2023.

If you hold old MS-100 or MS-101 credentials, you can no longer renew them. The only path to the current Administrator Expert title is MS-102.

Who Should Sit MS-102

The Microsoft skills outline targets professionals who:

  • Administer Microsoft 365 tenants end-to-end: tenant setup, domains, licensing, role-based access.
  • Manage identity via Microsoft Entra ID (formerly Azure AD), Entra Connect Sync / Cloud Sync, and hybrid identity.
  • Operate security controls across Microsoft Defender XDR (Defender for Office 365, Defender for Endpoint, Defender for Identity, Defender for Cloud Apps).
  • Manage compliance via Microsoft Purview (DLP, Information Protection, eDiscovery, Insider Risk, Communication Compliance).
  • Support cross-workload governance across Exchange Online, SharePoint Online, OneDrive, Teams, and Intune.
Candidate ProfileWhy MS-102 Fits
Existing M365 admins with MS-100/MS-101Only current path to Administrator Expert; old credentials cannot be renewed
Help desk / IT pros moving into admin rolesValidates cross-workload admin competency at the Expert tier
Azure admins (AZ-104) expanding into M365Natural lateral move; ~30% of content overlaps with Entra fundamentals
MSPs and Microsoft partnersMS-102 frequently required for partner competency designations
Security-adjacent adminsExposure to Defender XDR and Purview sets up SC-200, SC-300, SC-401 paths

If your role is purely identity-focused, sit SC-300 (Identity & Access Administrator Associate) instead. If your role is purely security operations, sit SC-200 (Security Operations Analyst). MS-102 is the right choice when you own the tenant broadly, not just one workload.

The Credential Prerequisite Almost Every Guide Gets Wrong

Here is the detail that trips up more candidates than any exam-day tactic: passing MS-102 does not, by itself, earn you the Microsoft 365 Certified: Administrator Expert badge. Per the current Microsoft Learn certification page, you must also hold at least one of these four associate-level certifications:

  • MD-102: Microsoft 365 Certified: Endpoint Administrator Associate
  • MS-700: Microsoft 365 Certified: Teams Administrator Associate
  • SC-300: Microsoft Certified: Identity and Access Administrator Associate
  • SC-401: Microsoft Certified: Information Security Administrator Associate

This four-certification prerequisite list was expanded in mid-2026 to add SC-401 alongside the original three. If you already hold MD-102, MS-700, or SC-300 from an earlier role-based path, you are covered - MS-102 is your last step. If you hold none of them, budget for a second exam (most candidates pair MS-102 with SC-300, since the Entra ID content overlaps heavily). Most third-party MS-102 guides only describe prerequisites for sitting the exam (there are none) and never mention this credential-level requirement - verify your own status on your Microsoft Learn transcript before assuming one exam finishes the job.


Build MS-102 Mastery with FREE Practice Questions

Access FREE MS-102 practice questionsPractice questions with detailed explanations

MS-102 Skills Measured (2026 Domain Weights)

The official Microsoft Learn skills outline for MS-102 was most recently revised April 28, 2026, reflecting the rebrands (Azure AD -> Microsoft Entra ID, Microsoft 365 Defender -> Microsoft Defender XDR) and new GA features (Microsoft Security Exposure Management, Microsoft 365 Backup, Copilot-related DLP coverage). The April 2026 revision shifted weight noticeably: Entra identity moved up from 15-20% to 25-30%, and Purview compliance moved down from 15-20% to 10-15%. If a guide you are reading still shows Entra at 15-20% or Purview at 15-20%, it is describing the pre-April-2026 outline and is out of date. Always verify against the current PDF at aka.ms/MS102-StudyGuide before test day.

DomainCurrent Weight (as of Apr 28, 2026)What It Covers
1. Deploy and manage a Microsoft 365 tenant25-30%Tenant setup, domains, organizational settings, users/groups/licenses, roles, health and adoption reporting, Microsoft 365 Backup
2. Implement and manage Microsoft Entra identity and access25-30%Entra ID Connect Sync / Cloud Sync, hybrid identity, authentication methods, Conditional Access, identity protection
3. Manage security and threats by using Microsoft Defender XDR30-35%Defender for Office 365, Defender for Endpoint, Defender for Cloud Apps, Security Exposure Management, incident response
4. Manage compliance by using Microsoft Purview10-15%DLP, Information Protection (sensitivity labels), retention labels/policies, Content/Activity explorer

Source: Microsoft Learn MS-102 study guide, skills measured as of April 28, 2026.

Domain 3 (Defender XDR) is the heaviest single domain, but Domains 1 and 2 are now tied for a close second at 25-30% each - the old assumption that Entra ID is a 'light' section is no longer accurate. Do not under-study it.

Domain 1: Deploy and Manage a Microsoft 365 Tenant (25-30%)

This is the "core admin" domain - tenant hygiene, users, groups, licensing, and cross-workload oversight.

Plan and configure the tenant

  • Initial tenant setup, tenant name, and primary domain.
  • Add and verify custom domains (TXT / MX records), plan domain-based email routing.
  • Configure organizational settings: release preferences (targeted release), password policies, self-service settings.
  • Configure usage analytics (Microsoft 365 usage reports, Viva Insights organizational analytics).
  • Configure and review Network connectivity insights and monitor/configure software updates via the Microsoft 365 admin center.
  • Configure and manage Microsoft 365 Backup - a newer GA capability now named explicitly in the 2026 outline for backing up Exchange, SharePoint, and OneDrive data.

Manage users, licenses, and mail-enabled objects

  • Create, modify, bulk-import, and delete user accounts (admin center, PowerShell, Graph).
  • Assign licenses directly vs via group-based licensing; understand license conflicts and dependencies.
  • Manage guest users (B2B collaboration) and contact objects.
  • Manage mailboxes, shared mailboxes, distribution groups, Microsoft 365 groups, and mail-enabled security groups.

Manage roles and role groups

  • Use Microsoft 365 admin roles (Global Admin, Exchange Admin, Teams Admin, SharePoint Admin, User Admin, Security Admin, Compliance Admin, etc.).
  • Apply Privileged Identity Management (PIM) just-in-time elevation for Entra ID roles.
  • Manage delegation using administrative units (scope admin permissions to a subset of users/groups).
  • Manage permissions for Defender XDR and Purview via roles/role groups; limit Global Admin count to the recommended 2-4 break-glass accounts.

Monitor tenant health and service

  • Service health dashboard, Message center advisories, Microsoft 365 health status API.
  • Adoption Score trends and Viva Insights organizational reports (some signals now surfaced through Viva Insights).
  • Tenant-wide reports (active users, email activity, OneDrive storage, Teams usage).

Domain 2: Implement and Manage Microsoft Entra Identity and Access (25-30%)

Entra ID is the backbone of every other domain, and the April 28, 2026 outline raised this domain's weight from 15-20% to 25-30% - it now carries as much weight as tenant administration. Do not treat it as the "short" section anymore.

Implement and manage identity synchronization

  • Prepare for synchronization, including the IdFix tool for pre-sync AD cleanup.
  • Entra Connect Sync (traditional AD Connect Sync, on-prem server) - full tenant sync, filtering, password hash sync, pass-through authentication.
  • Entra Cloud Sync (lightweight agent, cloud-managed) - multi-forest, preview features, and when to pick Cloud Sync vs Connect Sync.
  • Monitor with Microsoft Entra Connect Health; troubleshoot both Connect Sync and Cloud Sync.

Implement and manage authentication

  • Authentication methods policy (migration from legacy MFA/SSPR policies).
  • Methods: Microsoft Authenticator (push + number matching), FIDO2 security keys, Windows Hello for Business, passkeys, SMS, voice, OATH tokens, Temporary Access Pass (TAP).
  • Self-service password reset (SSPR) and Microsoft Entra Password Protection (banned password lists, on-prem enforcement).
  • Investigate and resolve authentication issues.

Implement and manage secure access

  • Plan and implement Microsoft Entra Identity Protection: user risk + sign-in risk policies; risky users / risky sign-ins remediation.
  • Plan and implement Conditional Access policies: users/groups, cloud apps, conditions (sign-in risk, user risk, device platform, location, client apps), controls (grant/block, require MFA, compliant device, terms of use).
  • Implement MFA by using Conditional Access policies (the modern, recommended enforcement path).
  • Report-only mode vs enabled; What-If tool; sign-in logs.

Domain 3: Manage Security and Threats by Using Microsoft Defender XDR (30-35%)

The largest single domain. Microsoft unified "Microsoft 365 Defender" into Microsoft Defender XDR with a single portal at security.microsoft.com. As of the April 28, 2026 outline, the four named functional groups are: security reports/alerts, Defender for Office 365, Defender for Endpoint, and Defender for Cloud Apps.

Review and respond to security reports and alerts

  • Microsoft Security Exposure Management (newer GA surface) and Microsoft Secure Score - identify and prioritize exposure/attack-path risk.
  • Incidents and alerts generated by Defender XDR, including advanced hunting (KQL across email, identity, endpoint, cloud).
  • Issues surfaced in Defender XDR reports and by Microsoft Defender Threat Intelligence.

Microsoft Defender for Office 365

  • Threat policies and rules: Safe Attachments, Safe Links, anti-phishing, anti-spam, anti-malware.
  • Alert policies, preset security policies (Standard, Strict) vs custom.
  • Attack simulation training campaigns; managing restricted entities / blocked users.
  • Threat Explorer, real-time detections, and incident investigation.

Microsoft Defender for Endpoint

  • Onboarding devices (Intune, Group Policy, local script, Configuration Manager).
  • Endpoint settings configuration, Attack Surface Reduction (ASR) rules, tamper protection.
  • Reviewing and responding to vulnerabilities in the Microsoft Defender Vulnerability Management dashboard.

Microsoft Defender for Cloud Apps (formerly Cloud App Security / MCAS)

  • App connector configuration for Microsoft 365; policies and alert triggers.
  • Activity log interpretation; Cloud App Discovery configuration and response.

Note on Defender for Identity: unlike earlier MS-102 revisions, the current (April 2026) skills outline does not list Microsoft Defender for Identity as its own named functional group. Its detections still surface inside the unified Defender XDR incident queue, so understand the concept, but do not over-invest study time in standalone MDI sensor deployment mechanics - it is no longer a dedicated bullet in Microsoft's own outline.

Domain 4: Manage Compliance by Using Microsoft Purview (10-15%)

Purview absorbed the old Microsoft 365 Compliance Center. This domain got narrower in the April 28, 2026 revision - it dropped from 15-20% to 10-15%, and Microsoft's outline now names only two functional groups: information protection/data lifecycle management, and DLP. eDiscovery, Insider Risk Management, Communication Compliance, and records management are no longer named as their own skill bullets (Microsoft's outline note says 'related topics may be covered,' so know the concepts, but do not over-weight your study time toward them the way older guides suggest).

Information protection and data lifecycle management

  • Sensitive information types (SITs) using keywords, keyword lists, or regular expressions.
  • Retention labels, retention label policies, and retention policies.
  • Sensitivity labels and sensitivity label policies (create, publish, auto-apply).
  • Monitor label usage via Content explorer, Activity explorer, and label reports.

Data Loss Prevention (DLP)

  • Policies across Exchange Online, SharePoint Online, OneDrive, Teams, Power BI, and Microsoft 365 Copilot (both explicitly named in the current outline - a notable 2026 addition reflecting Copilot data-exfiltration risk).
  • Endpoint DLP configuration (Windows/macOS devices onboarded to Defender for Endpoint).
  • Reviewing and responding to DLP alerts, events, and reports.

Background Purview topics (not named bullets in the current outline, but still fair game under "related topics may be covered")

  • Retention and records management: retention policies vs retention labels, adaptive vs static scopes, records management (declare, lock, review disposition).
  • eDiscovery: eDiscovery (Standard) vs eDiscovery (Premium) case workflow (custodians, holds, collections, reviews, export); Content Search vs eDiscovery case search.
  • Insider Risk Management and Communication Compliance: policy templates (data theft by departing users, data leaks, offensive language), alerts, cases, investigation workflow.

Spend your limited Domain 4 study time on the two named bullets (info protection/data lifecycle + DLP) first; treat the three background topics above as a lower-priority pass once the named material is solid.


Cost and Registration (2026)

ItemCostNotes
Exam fee (US)$165Varies by country
Microsoft 365 Developer Program tenant$0Free sandbox with sample users/data (conditions apply)
Microsoft Learn training$0Free official learning path + sandbox labs
OpenExamPrep practice$0Free scenario bank with AI explanations
MeasureUp practice tests~$129Closest to the real item style (optional)
Instructor-led bootcamp (Andy Malone, John Christopher, Pluralsight)$200-$2,000Optional
Renewal$0Free Microsoft Learn assessment yearly
Typical all-in first-time cost$165-$500Lower end if self-study only

Register via the MS-102 page on Microsoft Learn - the Schedule Exam button hands off to Pearson VUE. Pick test center or online-proctored (OnVUE). Confirm your Microsoft Learn profile name matches your government-issued ID exactly; mismatches cause same-day cancellations.

Renewal: FREE on Microsoft Learn After 1 Year

Like every Microsoft role-based certification, MS-102 is valid for one year from the date you pass. Renewal is FREE via Microsoft Learn - a browser-based, unproctored assessment opens in your Microsoft Learn profile 6 months before expiration. It is typically 25-35 questions focused on what has changed in Microsoft 365 since your initial pass (new Entra features, Defender XDR updates, Purview releases). You can retake the renewal unlimited times.

If a certification lapses, it cannot be renewed. You would need to re-sit the full MS-102 at $165. Set a calendar reminder 9 months after your pass date.

8-12 Week MS-102 Study Plan

Most candidates come from AZ-104, MS-100/MS-101 alumni work, or hands-on M365 admin roles. This plan assumes ~8-10 hours per week.

WeekFocusDeliverable
Week 1Tenant fundamentals, domains, licensingProvision a free M365 Developer tenant; verify a custom domain
Week 2Users, groups, roles, PIMBulk-import 25 users via CSV + PowerShell; configure PIM for Global Admin
Week 3Entra ID basics, Connect Sync vs Cloud SyncInstall Entra Cloud Sync in a lab; sync on-prem OU
Week 4Authentication methods, passwordless, Identity Protection, Conditional Access (heaviest Domain 2 week - weight rose to 25-30% in Apr 2026)Build 3 Conditional Access policies: require MFA, block legacy auth, require compliant device
Week 5Defender for Office 365 + Defender for EndpointEnable preset Strict policies; onboard a test device to Defender
Week 6Security Exposure Management/Secure Score + Defender for Cloud Apps (MDI no longer a named skill bullet - light-touch only)Review Secure Score recommendations; connect a SaaS app to Defender for Cloud Apps
Week 7Defender XDR unified: incidents, hunting, Secure ScoreRun 5 KQL advanced-hunting queries across email + endpoint
Week 8Purview DLP (incl. Power BI/Copilot) + sensitivity labels + retention labelsPublish a sensitivity label with encryption; build a DLP policy across Exchange/SharePoint/Teams
Week 9Purview background topics (eDiscovery, Insider Risk) - lower priority pass onlyCreate a retention policy; open a mock eDiscovery Premium case for familiarity
Week 10Review weak domains, take first timed mockTarget >70% on full-length mock
Week 11Remediation + hands-on gap labsClose weakest 2 sub-domains with Microsoft Learn modules
Week 12Two timed full-length mocks; rest day beforeScore >75% consistently before booking

If you are an experienced M365 admin, compress to 6-8 weeks by skipping Weeks 1-2.

Recommended MS-102 Resources (FREE-First)

ResourceTypeWhy It Helps
OpenExamPrep MS-102 Practice (FREE)Free, unlimitedScenario items mapped to the 2026 skills outline with AI explanations
Microsoft Learn MS-102 learning pathFreeOfficial modules across all four domains; includes sandbox labs
Microsoft 365 Developer Program tenantFree90-day renewable sandbox tenant with sample users, Teams, SharePoint content
Microsoft MS-102 Study Guide (PDF)FreeAuthoritative skills-measured list; print it and check off weekly
Andy Malone MVP (YouTube)FreeThe gold standard for MS-102 walkthroughs; full exam cram + domain deep dives
John Christopher / JC Pierre (YouTube / Udemy)Free + paidFull MS-102 course with demos, popular on Udemy
Pluralsight MS-102 pathPaidStructured video course from multiple Microsoft MVPs
MeasureUp MS-102 Practice TestsPaid ($129)Closest to the real item style and difficulty
Microsoft Tech Community (M365 admin, Defender, Purview)Free forumReal-world troubleshooting and product-team AMAs
Merill Fernando's "Entra.News" newsletterFreeWeekly Entra ID updates

Hands-On Microsoft 365 Trial Tenant Strategy

MS-102 is not a memorize-the-facts exam. Case studies embed 2-4 pages of tenant context and multiple linked questions, and drag-and-drop + performance-based items reward real admin muscle memory. Without a live tenant you will run out of the 100 minutes.

Use the Microsoft 365 Developer Program (free, renewable) to provision a trial tenant with:

  • 25 sample users with realistic Exchange/SharePoint/Teams content
  • E5 license-equivalent capabilities (Defender XDR, Purview, Entra ID P2) for dev/test
  • A refreshable sandbox you can reset between study sessions

If your employer has a Microsoft 365 E5 tenant, ask for a sandbox sub-tenant or a non-production OU. For Entra Connect Sync labs, spin up a small Hyper-V or Azure VM with AD DS.

Build at least these six scenarios end-to-end:

  1. Custom domain verification + pilot user cutover from on-prem Exchange.
  2. Entra Cloud Sync from an on-prem AD lab into a trial tenant.
  3. Conditional Access: MFA for all users, block legacy auth, require compliant device for sensitive apps.
  4. Defender for Endpoint onboarding via Intune, plus ASR rules + tamper protection.
  5. DLP policy across Exchange/SharePoint/OneDrive/Teams with sensitive info types + policy tips.
  6. eDiscovery Premium case: add custodian, place hold, run collection, review, export.

If you have built all six, you will recognize every scenario on the exam.

Test-Day Strategy: The Case-Study Format

MS-102 uses case studies, standalone items, and performance-based labs the same way other Microsoft Expert-tier exams do. The case-study format is where most first-time failures happen.

Before you sit:

  • Confirm your Microsoft Learn profile name matches your government ID exactly.
  • If online-proctored, run the Pearson VUE OnVUE system check 24 hours in advance.
  • Clear your desk; the proctor will ask for a 360-degree room scan.

During the exam:

  • Case studies appear as standalone timed sections (typically 2-3 cases). Once you submit a section you cannot return to it - but within a section you can flag, move back and forth, and review.
  • Read the question first, then skim the case study for the specific detail. Do not read all 4 pages twice.
  • Budget ~4-5 minutes per case-study item and ~1.5-2 minutes per standalone item.
  • On any ambiguous item, pick the option that is most aligned with Microsoft's current recommended best practice (Conditional Access over legacy MFA, Entra Cloud Sync over Connect Sync for new small deployments, Defender XDR unified portal over standalone Defender for Office).
  • Flag anything under 90% confidence; Microsoft gives you the full section time to revisit flagged items.

After the exam:

  • Immediate pass/fail with scaled score (0-1000, pass = 700).
  • A skills-measured breakdown is emailed within 1-3 business days.
  • If you fail, wait 24 hours for retake #1, 14 days for retakes 2-5.

Common Pitfalls That Sink First-Time Scores

  1. Confusing Conditional Access with Identity Protection. Conditional Access grants or blocks access based on signals; Identity Protection detects risky users / risky sign-ins. Conditional Access consumes the risk signals Identity Protection generates. The exam uses subtle wording to separate them - pay attention to whether the question is about detection (Identity Protection) or enforcement (Conditional Access).
  2. Not knowing the Defender XDR vs Purview boundary. Defender XDR is threats (malware, phishing, identity attacks, endpoint compromise). Purview is compliance (DLP, labels, retention, eDiscovery, insider risk). Example: a DLP policy alerting on PII exfiltration is Purview, not Defender. An anti-phishing policy quarantining a message is Defender, not Purview. Never confuse the two portals.
  3. Studying MS-100 / MS-101 content. Federation with AD FS, Skype for Business hybrid, legacy Intune UI - all out of scope. If a resource still teaches those, it is out of date.
  4. Under-studying Entra Cloud Sync vs Connect Sync trade-offs. Every revision of the outline has pushed Cloud Sync harder. Know the feature parity gaps (device writeback, password writeback, complex filtering) and when each is the right answer.
  5. Skipping PowerShell / Graph completely. The exam is not a scripting test, but drag-and-drop items can include cmdlet ordering (Connect-MgGraph, Get-MgUser, New-MgGroup). Know the Microsoft Graph PowerShell module basics.
  6. Ignoring Preset security policies in Defender for Office. "Standard" and "Strict" presets are the recommended modern answer over hand-rolled custom policies in most scenarios - Microsoft rewards the preset option.
  7. Forgetting that DLP endpoint extension requires onboarding. Endpoint DLP only works on devices onboarded to Defender for Endpoint. This trips up case-study questions about DLP coverage on unmanaged devices.
  8. No timed full-length practice. 100 minutes with case studies + performance-based labs + standalone items is tight. Two timed mocks minimum before test day.

Career Value and Salary (Microsoft 365 Administrator, 2026)

Microsoft 365 admin roles remain one of the most durable cloud-ops career tracks. Every enterprise that runs Exchange Online, SharePoint, Teams, or Intune needs people who can administer the tenant, enforce security, and manage compliance. MS-102 is explicitly referenced in many MSP and regulated-industry job descriptions.

Source (2026)Microsoft 365 Administrator Pay
Glassdoor (US, "Microsoft 365 Administrator")Median total comp ~$102,000/yr; range $85K-$130K
ZipRecruiter (M365 Admin, US)Average $96,000/yr; range $72K-$125K
Salary.com (Microsoft 365 Administrator II)Median $108,000/yr; range $90K-$128K
Robert Half Tech Salary Guide 2026Systems admin + M365 range $90K-$135K with cert premium
LinkedIn Talent Insights20,000+ US roles tagged "Microsoft 365 administrator"; 15-25% YoY growth

M365 Admin Career Ladder

RoleTypical 2026 US PayNext Step
Help desk / Tier 1 support$45K-$65KEarn MS-900 then MS-102
M365 Administrator (mid)$85K-$120KMS-102 + SC-300 or MS-700
Senior M365 / Collaboration Engineer$115K-$145KMS-102 + SC-300 + SC-401 + team lead scope
M365 / Modern Workplace Architect$140K-$190KMS-102 + AZ-104 + SC-100 + architectural ownership
Identity / Security Architect$160K-$220K+MS-102 + SC-100 + SC-300 + enterprise scope

The MS-102 + SC-300 pair is the single highest-ROI certification combination for M365 admins in 2026, unlocking both the Administrator Expert title and the Identity & Access Administrator Associate title.

Deep Dives on Three Topics Competitor Guides Skim

1. Entra Connect Sync vs Entra Cloud Sync

This is the most testable Domain 2 topic. Both tools sync on-prem Active Directory into Entra ID, but they differ meaningfully.

FactorEntra Connect SyncEntra Cloud Sync
Agent footprintFull server install with SQL Server Express or SQL ServerLightweight agent, any domain-joined Windows Server 2016+
ConfigurationLocal wizard, server-side rulesCloud-managed in the Entra admin portal
Multi-forestSingle agent; complex rules neededMultiple agents per forest natively supported
Device writebackSupportedNot supported (as of early 2026)
Password writebackSupportedSupported
Group writebackSupported (to AD DS as security groups)Limited
Complex attribute flowsFull rules engineBasic attribute mapping; no custom sync rules
When to pickLarge tenants, complex AD, hybrid Exchange with device writebackNew small/mid deployments, multi-forest M&A, AD with minimal customization

The exam frequently asks "which is the minimal solution to sync a new forest after an acquisition" - the answer is usually Cloud Sync.

2. Conditional Access Nuance (What Trips Candidates Up)

  • Report-only mode is not the same as disabled. Report-only still evaluates the policy and logs the result, but never enforces - essential for pre-production testing.
  • Grant controls use AND/OR: "Require MFA AND Require compliant device" is much stricter than "Require MFA OR Require compliant device."
  • What-If tool is your friend for troubleshooting - use it to simulate specific user + app + condition combos.
  • Excluded users (break-glass accounts) should always include at least two emergency Global Admin accounts with long passphrases stored in a vault.
  • Workload identity Conditional Access (for service principals) is a newer premium feature; the exam tests when it applies.
  • Legacy authentication (IMAP, POP, SMTP AUTH, older Office clients) must be blocked via a dedicated Conditional Access policy; Microsoft's Security Defaults block it by default for tenants that have them enabled.

3. Purview DLP + Information Protection Interaction

  • Sensitivity labels classify and optionally encrypt content.
  • DLP policies enforce actions (block, warn, audit) based on conditions including "content contains sensitive info type X" or "content has sensitivity label Y."
  • The labeled-content approach scales better than sensitive-info-type matching alone because labels survive file format changes.
  • Auto-labeling (service-side) applies labels at rest in SharePoint/OneDrive/Exchange without user action - a Purview E5 feature.
  • Endpoint DLP requires devices onboarded to Defender for Endpoint and covers Windows 10/11 and macOS; Linux support is limited.
  • DLP now explicitly covers Power BI and Microsoft 365 Copilot in the current outline - a 2026 addition reflecting the risk of sensitive data surfacing through Copilot-generated summaries and Power BI reports. Older guides that list only Exchange/SharePoint/OneDrive/Teams miss this.

Case-study items often present a scenario where sensitive data leaks from a managed device to an unmanaged USB drive - the right answer combines endpoint DLP (to block the action) with a sensitivity label (to classify the content in the first place).

How MS-102 Fits into the Broader Microsoft Certification Path

ExamRoleWhen to Sit
MS-900 Microsoft 365 FundamentalsEntryOptional warmup if you are new to M365
MS-102 Microsoft 365 AdministratorAdmin ExpertThis exam
SC-300 Identity & Access AdministratorIdentityNatural next step after MS-102; also satisfies the Administrator Expert associate-cert requirement
SC-401 Information Security AdministratorCompliance/SecurityDeeper Purview info-protection focus; replaced SC-400 (retired May 31, 2025); also satisfies the Expert associate-cert requirement
MD-102 Endpoint AdministratorEndpointAlso satisfies the Expert associate-cert requirement
SC-200 Security Operations AnalystSecurity opsDeeper Defender XDR + Sentinel focus
MS-700 Teams AdministratorTeamsIf Teams is your primary workload; also satisfies the Expert associate-cert requirement
AZ-104 Azure AdministratorAzure opsComplementary Azure admin scope
SC-100 Cybersecurity ArchitectArchitectSenior/architect-tier capstone

Remember: MS-102 plus one of SC-300 / SC-401 / MD-102 / MS-700 is what actually earns the Administrator Expert badge (see "The Credential Prerequisite Almost Every Guide Gets Wrong" above). MS-102 + SC-300 + SC-401 is the "Modern Work + Security" trio many enterprises expect.


Keep Training with FREE MS-102 Practice

Practice MS-102 scenario questionsPractice questions with detailed explanations

Frequently Missed 2026 Details (Competitor Guides Get These Wrong)

  • MS-100 and MS-101 are gone. If a guide recommends taking them first "for background," it is out of date - they retired September 30, 2023.
  • Azure AD is now Microsoft Entra ID. Old terminology (AAD Connect, AAD Conditional Access) still appears in community posts but the exam uses current Entra naming.
  • Microsoft 365 Defender is now Microsoft Defender XDR with a unified portal at security.microsoft.com.
  • Preset security policies (Standard, Strict) in Defender for Office are the recommended modern answer over custom policies in most scenarios.
  • Entra Cloud Sync is preferred over Connect Sync for new, smaller, or multi-forest deployments when device writeback is not required.
  • Passwordless + phishing-resistant MFA (FIDO2, Windows Hello for Business, passkeys, certificate-based authentication) is the direction every new Microsoft identity question pushes toward.
  • Endpoint DLP requires Defender for Endpoint onboarding - DLP alone does not cover the device channel.
  • Renewal is free and unproctored - and opens 6 months before expiration, not after.
  • The April 28, 2026 outline revision moved weight, not just terminology: Entra identity rose from 15-20% to 25-30%; Purview compliance fell from 15-20% to 10-15%. A guide still quoting the old split is describing a retired outline.
  • SC-400 retired May 31, 2025 and was replaced by SC-401 (Information Security Administrator Associate) - guides still recommending SC-400 as a next step are stale.
  • Earning the Administrator Expert credential requires more than passing MS-102 - you also need at least one of MD-102, MS-700, SC-300, or SC-401. Guides that describe MS-102 as a single stand-alone exam for the Expert badge are incomplete.
  • The exam's own languages list is 7, not 9 - English, Chinese (Simplified), German, Spanish, French, Japanese, and Portuguese (Brazil). Korean and Italian are not currently offered for MS-102.

Official Sources Used

  • Microsoft Learn - Exam MS-102: Microsoft 365 Administrator (skills outline effective April 28, 2026)
  • Microsoft Learn - MS-102 Study Guide (aka.ms/MS102-StudyGuide)
  • Microsoft 365 Certified: Administrator Expert credential page (prerequisite certifications, updated 2026-06-02)
  • Microsoft Certified: Information Security Administrator Associate / Exam SC-401 credential page
  • Microsoft Learn exam retake policy (learn.microsoft.com/credentials/support/retake-policy)
  • Microsoft Entra ID / Entra Connect Sync / Entra Cloud Sync documentation
  • Microsoft Defender XDR documentation (security.microsoft.com)
  • Microsoft Purview documentation (purview.microsoft.com)
  • Pearson VUE Microsoft exam scheduling portal (fee and retake policy)
  • Microsoft Learn credential renewal policy (6-month renewal window, free online assessment)
  • Glassdoor / ZipRecruiter / Salary.com / Robert Half - 2026 salary references
  • LinkedIn Talent Insights - M365 admin job demand signals

Certification details, fees, and skills measured may be revised by Microsoft. Always confirm current requirements directly on learn.microsoft.com before scheduling.

Test Your Knowledge
Question 1 of 7

You need to sync a newly acquired second Active Directory forest into your existing Microsoft 365 tenant. The acquisition must be synced within a week, the source AD has minimal customization, and device writeback is not required. Which Entra identity sync tool is the best fit?

A
Entra Connect Sync (full server install)
B
Entra Cloud Sync (lightweight agent)
C
Federation with AD FS
D
Password hash sync only, via PowerShell
Learn More with AI

10 free AI interactions per day

MS-102Microsoft 365 AdministratorMicrosoft 365 CertifiedMicrosoft Entra IDEntra Connect SyncEntra Cloud SyncMicrosoft Defender XDRMicrosoft PurviewConditional AccessDLPeDiscoveryMS-100 MS-101 replacementMicrosoft certification 2026free exam prep

Free Study Resources

Related Articles

Stay Updated

Get free exam tips and study guides delivered to your inbox.

Free exam tips & study guides. Unsubscribe anytime.