MS-102 Exam Guide: Microsoft 365 Administrator Preparation and Scheduling
MS-102 validates the ability to administer Microsoft 365 at tenant level across identity, security, compliance, and connected workloads. It is aimed at administrators working in cloud or hybrid environments who already have practical Microsoft 365 experience and have administered Microsoft Entra ID or another Microsoft 365 workload. This guide helps you decide whether your current experience is sufficient, which skills to study first, how to use Microsoft’s learning resources, and what to check before booking an exam that is scheduled to retire on November 30, 2026.
What MS-102 validates
MS-102 tests whether you can connect the major Microsoft 365 administration responsibilities rather than operate one isolated service. The assessed work spans tenant management, Microsoft Entra identity and access, Microsoft Defender XDR security and threat management, and Microsoft Purview compliance. The exam is part of the Microsoft 365 Certified: Administrator Expert certification.
Microsoft describes the role as an integrating hub for Microsoft 365 workloads. That means preparation should not stop at memorizing portal locations. You need to understand how an administrative choice affects users, licensing, authentication, security controls, device or client access, data handling, and operational monitoring.
The exam is designed for administrators who deploy and manage Microsoft 365 and perform tenant-level implementation and administration in cloud and hybrid environments. It also expects coordination with specialists responsible for infrastructure, identity, security, compliance, endpoints, applications, and individual workloads.
Check your experience before choosing a study plan
Start with the experience requirement, not with a question bank. Microsoft expects functional experience with Microsoft 365 workloads and Microsoft Entra ID, plus administration of at least one of them. Candidates should also have working knowledge of networking, Active Directory Domain Services, DNS, and PowerShell.
A candidate who has only read Microsoft 365 documentation may need a skills-building phase before exam-focused revision. In contrast, an administrator who has handled tenant configuration, identity synchronization, security policies, or compliance investigations can usually begin by mapping practical experience to the official objectives.
Use this quick readiness test: can you explain how a tenant is configured and monitored; how identities are synchronized or protected; how Defender controls and investigations fit together; and how Purview policies classify, retain, or protect data? If any answer is limited to product names, schedule hands-on learning before relying on assessment practice.
The Microsoft 365 Administrator course is marked intermediate and is designed for people aspiring to the role who have completed at least one role-based administrator certification path. Its stated prerequisites include proficient DNS knowledge, basic Microsoft 365 service experience, general IT practices, and working PowerShell knowledge.
Understand the four measured domains
Use the official domain percentages to allocate study time, but do not treat them as a prediction of exact question counts. The largest allocation is Manage security and threats by using Microsoft Defender XDR at 35–40%, followed by Implement and manage Microsoft Entra identity and access at 25–30%, Manage compliance by using Microsoft Purview at 15–20%, and Deploy and manage a Microsoft 365 tenant at 10–15%.
The percentages describe the current skills-measured structure. Microsoft updates exams to reflect role requirements, and the study guide provides the version of the objectives that applies according to when you take the exam. Recheck the study guide before final revision, particularly if your exam date is near an update.
A sensible study allocation follows both the weights and your experience. Give the greatest structured practice to Defender XDR, then Entra identity and access. Do not ignore tenant management because it has the smallest percentage: it supplies the administrative context in which the other controls are configured and operated.
Deploy and manage a Microsoft 365 tenant
This domain covers the administrative foundation: tenant configuration, service settings, users, licenses, groups, roles, tenant health, and Microsoft 365 Apps for enterprise. Microsoft’s tenant-management learning path also includes tenant health and services, role and role-group management, app deployment, and Viva Insights.
Study this area by tracing a complete administrative change. For example, identify the required role, configure the relevant tenant or service setting, assign the correct license or group membership, deploy the client or service, and confirm health or usage information. The point is to understand dependencies rather than memorize a sequence of clicks.
Pay particular attention to least-privilege administration and delegated responsibilities. The learning path specifically addresses role management, role groups, best practices for administrative roles, delegation, and privilege elevation. Make notes that distinguish a role’s authority from a workload’s configuration setting.
The course syllabus also places Office client connectivity and user-driven Microsoft 365 Apps for enterprise installations within tenant administration. Review how these activities relate to tenant configuration and user readiness instead of studying app deployment as an unrelated endpoint topic.
Implement and manage Microsoft Entra identity and access
This domain requires more than knowing that Entra ID provides cloud identity. Prepare to reason about identity synchronization, synchronized identities, password management, multifactor authentication, self-service password management, roles, and access decisions across Microsoft 365.
The MS-102 course describes Azure Active Directory Connect and Connect Cloud Sync as central synchronization topics. When studying, compare where each approach fits, what identities or attributes are involved, and how an administrator would monitor or troubleshoot the resulting identity state. Keep current Microsoft terminology in your notes while recognizing that older learning material may use the Azure Active Directory name.
Build an identity decision table with columns for the administrative goal, affected identity, control or service, dependency, and verification method. Populate it with scenarios such as synchronizing identities, managing passwords, applying multifactor authentication, and delegating administration. This exposes gaps more effectively than rereading definitions.
Do not isolate identity from networking and DNS. The official candidate profile names networking, Active Directory Domain Services, and DNS as working-knowledge areas. Review those foundations when they explain why synchronization, authentication, or hybrid administration succeeds or fails.
Manage security and threats with Microsoft Defender XDR
Defender XDR is the heaviest weighted MS-102 domain at 35–40%, so it deserves the deepest study cycle. The official material connects threat vectors and data breaches with Microsoft 365 security solutions, Secure Score, Identity Protection, Exchange Online Protection, Safe Attachments, Safe Links, reports, and Defender products.
Organize revision around a threat-to-control chain. Start with the threat or signal, identify the applicable protection or detection service, determine the administrative configuration, and finish with the report or investigation that confirms the result. This approach helps you distinguish preventive controls from detection, investigation, and response capabilities.
The course syllabus specifically names Microsoft 365 Defender, Microsoft Defender for Cloud Apps, and Microsoft Defender for Endpoint in its threat-intelligence coverage. Create a comparison sheet describing each product’s role, the signals it handles, the type of administrative action it supports, and the other Microsoft 365 controls that may be involved.
Include Exchange Online Protection, Safe Attachments, and Safe Links in the same security model. A common preparation mistake is to study Defender portals as one large feature list while overlooking how mail-flow protection and threat intelligence address different stages of an attack.
Use Microsoft’s free practice assessment as a diagnostic, not as a substitute for product learning. For each missed or guessed item, record the underlying task, affected workload, and reason the other options were less suitable. Do not attempt to reconstruct or memorize live exam content.
Manage compliance with Microsoft Purview
The Purview domain accounts for 15–20% of the exam and focuses on managing compliance rather than simply naming compliance features. Prepare for data governance, archiving and retention, message encryption, data loss prevention, insider risk management, information barriers, data classification, and sensitivity labels.
The MS-102 course presents these subjects as connected decisions. Data classification and sensitivity labels can inform protection and governance; retention and archiving address lifecycle requirements; DLP helps manage inappropriate sharing or handling; insider risk and information barriers address specialized organizational risks.
Build a policy matrix for each compliance capability. Record the business problem, data or user scope, policy action, exclusions or exceptions, alert or review path, and evidence used to validate the result. This is a practical recommendation, not an official exam requirement, but it mirrors the administrative reasoning needed for scenario questions.
Avoid treating every Purview policy as interchangeable. During revision, state what each policy is intended to control and what it does not control. Then connect the policy to identity, workload, or security context where relevant. That distinction is more useful than a collection of isolated feature definitions.
Use Microsoft Learn without studying passively
Microsoft provides both self-paced and instructor-led preparation routes. The official MS-102 study guide should be your control document: use it to confirm the current objectives, updates, languages, scoring information, practice assessment availability, and links to related resources. Build your notes from objectives and tasks, not from a generic checklist.
The Manage your Microsoft 365 tenant learning path contains four modules covering permissions and role groups, tenant health and services, Microsoft 365 Apps for enterprise, and Viva Insights. It is particularly useful for the tenant-management domain and for candidates who need a structured starting point.
The MS-102T00-A course covers tenant management, identity synchronization, and security and compliance. Its syllabus includes tenant configuration, accounts and licenses, groups, administrative roles, Office client connectivity, app installations, directory synchronization, password management, threat protection, security reporting, data governance, retention, encryption, DLP, insider risk, information barriers, and sensitivity labels.
Read a module, perform the corresponding task in an authorized practice tenant or lab, and write a short explanation of the design choice. If you cannot access a lab, use Microsoft Learn demonstrations and documentation to produce a process map, but mark unverified hands-on assumptions for later review. The official sources support the learning content; the sequencing is a practical recommendation.
A practical MS-102 study roadmap
A staged roadmap works better than switching between four domains every day. First establish the current blueprint and your experience gaps, then build tenant and identity foundations, study security and compliance through scenarios, and finish with timed assessment review and registration checks.
Stage one: baseline and scope. Download or open the current study guide and copy its objective headings into a tracker. Mark each task as can perform, can explain, recognize only, or unknown. Take the official practice assessment if it is available to you. Treat the result as a diagnostic signal; investigate every uncertain answer rather than focusing only on the final score.
Stage two: tenant foundation. Work through tenant configuration, administrative roles, licenses, groups, service health, Microsoft 365 Apps for enterprise, and Viva Insights. For each topic, answer three questions: what is being administered, which identity or role is involved, and how would you verify the outcome?
Stage three: identity and access. Study synchronization options, synchronized identity management, password management, multifactor authentication, self-service password management, and administrative delegation. Add DNS, Active Directory Domain Services, networking, and PowerShell review wherever your understanding depends on hybrid or scripted administration.
Stage four: security. Reserve the longest study block for Defender XDR because Manage security and threats by using Microsoft Defender XDR is the 35–40% domain. Move from threat vectors to controls, then to alerts, reports, investigation, and response. Compare the named Defender services and connect them to mail protection and identity risk.
Stage five: compliance. Build the Purview policy matrix and work through retention, archiving, encryption, DLP, insider risk, information barriers, classification, and sensitivity labels. Practice explaining why a control fits a scenario and what evidence would show that it is working.
Stage six: integration review. Use cross-domain scenarios. Ask how a user, license, role, synchronized identity, security signal, or compliance policy affects another workload. This is where an administrator’s integrating-hub responsibility becomes concrete.
Stage seven: final readiness. Revisit the official study guide for changes, take another practice assessment if available, and review only documented gaps. Avoid replacing this work with exam dumps or leaked-question claims. Such material is not a reliable way to establish competence and does not guarantee a passing result.
How to turn weak areas into useful notes
A useful MS-102 note explains a decision, not just a definition. For every weak objective, write the administrative goal, prerequisite, configuration choice, expected effect, monitoring or validation method, and one reason an alternative would be unsuitable.
For tenant and identity topics, use flow diagrams. Show where a user or group originates, how licensing and roles are applied, how synchronization or authentication is involved, and where an administrator confirms status. Diagrams reveal missing dependencies quickly.
For Defender and Purview, use scenario cards. The front should describe a business or security problem; the back should identify the relevant service, policy or control, scope, expected signal, and follow-up action. Keep the cards based on Microsoft Learn documentation and your own authorized practice, not recalled exam questions.
For PowerShell, focus on administrative intent and safe execution. Know what task a command or module supports, what permissions it requires, what objects it changes, and how you would validate the result. Do not spend revision time collecting commands without understanding their effect.
Avoid these preparation mistakes
The most damaging mistake is treating MS-102 as a product-name exam. The objectives describe administrative tasks across workloads, so prepare to choose an appropriate control under stated constraints, not merely identify a service from a definition.
A second mistake is giving every domain equal time despite the blueprint. Security and threats by using Microsoft Defender XDR represents 35–40%, while tenant management represents 10–15%; these labels must remain attached to the percentages because the figures have meaning only as domain allocations. Your personal gaps may justify a different order, but not an unexamined one.
A third mistake is studying only portal navigation. Microsoft services change interfaces, and navigation memory does not explain permissions, dependencies, policy scope, synchronization behavior, or validation. Use each interface exercise to answer what the setting accomplishes and how you would confirm it.
A fourth mistake is ignoring updates. Microsoft says the English-language exam was updated on April 28, 2026, and localized versions may follow approximately eight weeks later. Check the study guide and exam page for the version relevant to your appointment rather than assuming an older course reflects every current objective.
Finally, do not schedule before checking your certification path. MS-102 is the required exam for Microsoft 365 Certified: Administrator Expert, and the certification page lists associate certifications in endpoint administration, Teams administration, identity and access administration, or information security administration as prerequisites. Confirm the current requirement on the certification page before relying on an older checklist.
Know the scoring and exam experience limits
Microsoft lists a passing score of 700 for MS-102. The number of questions can change, so use the appointment information and the exam overview rather than relying on a fixed question count. Microsoft’s exam-experience resource also provides an exam sandbox to familiarize you with the interface and question types.
Role-based exams may include labs, but Microsoft does not provide a permanent list of exams with labs because labs can be removed. When you launch the exam, review the overview pages carefully for information about the current experience, including whether labs are available.
Microsoft Learn may be available during the exam through the Learn button in the left navigation pane on eligible role-based exams. Learn access has limitations: candidates cannot use it to access the Q&A section, practice assessments, or personal profile, and the exam sandbox is intended to explain navigation rather than reproduce the secure browser used in a live exam.
Breaks require deliberate time management. Microsoft says five minutes are built into the exam time for break use, while the exam clock continues during a break. Once a break is launched, you cannot return to questions viewed before it, including unanswered or marked questions. Initiate a break through the exam interface and do not access unauthorized materials.
These rules create a practical decision: if you need a break, take it at a clean boundary and accept that earlier questions are closed. Before test day, use the sandbox to become comfortable with marking, reviewing, navigation, and any available problem-solution or case-study flow.
Choose online delivery or a test center
Choose the delivery method based on your equipment, room, network, and preference for controlled conditions. Microsoft generally offers online or local test-center options through its exam provider, but availability depends on the provider and region. If no online option appears during scheduling, it is not available from that provider.
For an online exam, Pearson VUE proctors monitor through webcam and microphone. You must complete the required system test on the same computer and in the same location intended for testing. Microsoft recommends using a personal computer where possible because work-device software can prevent OnVUE from launching.
Before scheduling online, check local administrative permissions, security software, network restrictions, camera and microphone operation, and the testing area requirements. A hard-wired connection may be preferable where practical, particularly if proxy servers, packet inspection, or strict filtering could disrupt the session. These are preparation checks, not guarantees of technical compatibility.
Identity and profile details matter. Microsoft requires a current government-issued ID, and the name on the certification profile must match the legal ID. Online check-in includes identity and room review steps, and mobile phone photos must be uploaded for the launch process. If facial comparison technology is not acceptable to you, Microsoft directs candidates to schedule at a test center.
Online exams are available in most, but not all, countries or regions. Support and proctoring communication may be in English even when the exam itself is localized, with limited Japanese availability noted by Microsoft. Review the current language and regional information before booking.
Schedule without creating a record problem
Use a personal Microsoft account when registering. Microsoft warns that exam records associated with an organizational work or school account can be lost and unrecoverable after leaving that organization. Also ensure your legal name and profile information are correct before you move into provider scheduling.
From the MS-102 or certification page, choose the schedule option and follow the provider instructions. Pearson VUE is the route Microsoft identifies for people taking a certification independently or through a training program; Certiport is presented for students, academic institutions, or Microsoft Office Specialist exams.
Microsoft allows certification exams to be scheduled no more than 90 days ahead and permits a maximum of two Microsoft Certification exams to be scheduled at a time through Pearson VUE. Those policies affect how far ahead you can plan a retake or a second certification appointment.
Request accommodations before scheduling if you need extra time, special equipment, or another modification. Microsoft also advises checking provider pricing because price depends on the country or region where the exam is proctored. Do not rely on a third-party listing for the current fee.
The current MS-102 exam page and certification page state that the exam and related Administrator Expert certification retire on November 30, 2026. Microsoft says the certification can no longer be earned or renewed after that date, and the exam page advises completing the exam before retirement so it is applied toward the certification. Confirm the current retirement notice when you schedule, especially if your preparation plan is long.
Languages, updates, and renewal planning
The exam page lists English, Chinese (Simplified), German, Spanish, French, Japanese, and Portuguese (Brazil) for MS-102. The study guide says available languages should be checked in the Schedule Exam section, because localized availability and update timing can change.
Microsoft updates the English version first and says localized versions are generally updated approximately eight weeks after the English update, although the schedule is not guaranteed. If the exam is unavailable in your preferred language, the study guide says you can request an additional 30 minutes to complete it.
Plan the language decision before intensive revision. If you will test in a language different from your daily administrative work, maintain a glossary of Microsoft service names, policy terms, role names, and action verbs in the exam language. This is a practical recommendation; the official language and accommodation rules remain the authority.
Microsoft says associate, expert, and specialty certifications expire annually and can be renewed through a free online assessment on Microsoft Learn. That renewal information matters only if you earn the certification before the stated retirement deadline, so check the current certification page for the applicable path and status.
Your final week and next actions
In the final week, stop expanding your resource list. Confirm the current study-guide objectives, review your error log, rehearse cross-domain decisions, and complete the provider’s technical or appointment checks. Your goal is dependable reasoning across the blueprint, not exposure to every possible Microsoft 365 feature.
Complete these actions in order: verify whether you meet the Administrator Expert prerequisite; open the current MS-102 study guide; map your confidence across the four labeled domains; prioritize Defender XDR and Entra gaps; use the tenant-management path or MS-102T00 course where foundations are weak; take the official practice assessment if available; and record the exam version, language, provider, and retirement implications for your appointment.
On the day before an online appointment, repeat the system check from the intended location, confirm the profile name against your government ID, prepare the required phone-photo process, and remove unauthorized materials from the testing area. For a test center, confirm the appointment details and identification requirements instead of assuming online procedures apply.
If your diagnostic work shows that you cannot explain the administrative decisions behind your answers, postpone rather than substitute exam dumps or memorization. If the objectives are understood, your environment is ready, and your weak areas have been addressed with official material and practical exercises, proceed to scheduling through the Microsoft Learn profile.
Conclusion
MS-102 is best approached as an integration exam for experienced Microsoft 365 administrators. Anchor preparation to the current skills-measured domains, give the largest study block to Defender XDR, strengthen Entra and hybrid fundamentals, and use Purview and tenant-management scenarios to connect policy with administration. Before booking, verify prerequisites, language, provider availability, accommodations, account ownership, and the November 30, 2026 retirement notice on Microsoft Learn. Then schedule only when your practice shows that you can explain and validate the administrative choice behind an answer.