Skip to content

ms-102Expert

Microsoft 365 Administrator

Microsoft 365 Certified: Administrator Expert

MS-102 spans the whole tenant: setup and roles, hybrid identity and Entra ID, the Defender stack, and Purview. It is the exam this site is closest to, so the path is long — the how-to guides are there because the exam is scenario-based and expects you to know which portal blade does what.

For: Tenant administrators who own identity, security, and compliance day to day. Replaced the MS-100 + MS-101 pair.

36 guides in 4sections. The sections are this site's grouping, written to follow the shape of the published skills outline; weightings and the current outline live on the exam page above and change between exam versions.

01Deploy and manage the tenant

  1. 1Setting up Microsoft 365 from scratchThe setup order for a brand-new Microsoft 365 tenant — tenant, domain, identity, security baseline, then data and clients. Sequence matters more than speed.
  2. 2Microsoft 365 domains and DNS setupThe DNS records every Microsoft 365 tenant needs — and what each one does.
  3. 3Microsoft 365 admin centerThe Microsoft 365 admin center: what actually lives there, the specialist portals it hands off to, and the role design that should gate all of it.
  4. 4Microsoft 365 administrator rolesThe Entra ID admin roles that gate Microsoft 365 administration — and how to assign them with least privilege.
  5. 5Microsoft 365 admin role designHow to design admin role assignments for least-privilege Microsoft 365 administration at scale.
  6. 6Microsoft 365 service health and Message CenterHow to track Microsoft 365 service incidents and upcoming changes — and how to keep your organisation informed.
  7. 7Microsoft 365 monitoring and alertsHow to monitor a Microsoft 365 tenant — service health, audit logs, security alerts, and third-party tooling.
  8. 8Microsoft 365 tenant audit checklistA practical checklist for auditing a Microsoft 365 tenant's configuration, security posture, and compliance.
  9. 9Microsoft 365 reporting via PowerShellPowerShell patterns for extracting reporting data from Microsoft 365 — licensing, usage, security posture, mailbox stats.

02Identity and access with Entra ID

  1. 10Hybrid identity strategy for Microsoft 365How to plan the hybrid-identity journey from on-premises AD to Entra ID-only — staged, with the right choices at each stage.
  2. 11Entra Connect vs Entra Cloud SyncThe two ways to sync on-prem Active Directory to Entra ID — what each does, the scenarios that still force the old tool, and which to use today.
  3. 12Microsoft Entra Connect HealthConnect Health monitors the hybrid-identity infrastructure — Entra Connect, AD FS, and AD DS.
  4. 13Entra ID groups and group-based licensingGroup types in Entra ID, dynamic groups, and using groups to assign licences automatically.
  5. 14How to assign licenses with group-based licensing in Entra IDHow-toHow to assign Microsoft 365 licences with group-based licensing in Entra ID: build the groups, set usage location, migrate direct assignments, fix errors.
  6. 15Entra ID Administrative UnitsAdministrative Units scope admin roles to subsets of the directory — for delegated administration without tenant-wide privileges.
  7. 16Entra ID Conditional Access designDesigning a Conditional Access baseline: the policies, the principles, the order to write them in, and the habits that keep the estate healthy.
  8. 17How to require MFA for all users with Conditional AccessHow-toHow to require MFA for all users in Entra ID with Conditional Access: the exclusions that matter, report-only rollout, registration campaign, enforcement.
  9. 18Entra ID passwordless authenticationThe realistic options for going passwordless in Microsoft 365 — Authenticator, FIDO2, Windows Hello, and passkeys.
  10. 19Entra ID self-service password resetSSPR lets users reset their own passwords without calling the help desk. Here's the configuration and rollout.
  11. 20Entra ID Privileged Identity ManagementPIM turns standing admin access into just-in-time, approval-gated activation. The model, what it covers, role settings that work, and a rollout that sticks.
  12. 21Entra ID B2B guest accessHow Entra ID B2B brings external users into your tenant as guests — invitations, controls, and lifecycle.

03Security and threats with Defender

  1. 22Which Microsoft Defender is whichWhich Microsoft Defender is which: Endpoint, Office 365, Identity, Cloud Apps, Business, XDR, Cloud, Antivirus — what each does and which licence gets it.
  2. 23Microsoft Defender for Office 365 explainedWhat Defender for Office 365 adds on top of EOP — Safe Links, Safe Attachments, AIR, attack simulation — plus Plan 1 vs Plan 2 and the settings worth tuning.
  3. 24Exchange Online anti-spam and anti-phishingThe layered defences Exchange Online uses against spam, malware, and phishing — and how to tune them.
  4. 25Defender for Office 365 quarantine workflowHow users and admins work with quarantine — release, request, report, and the policy decisions behind it.
  5. 26Attack Simulation Training in Defender for Office 365How to run controlled phishing simulations and embedded training to harden users against real attacks.
  6. 27Microsoft Defender for Endpoint explainedDefender for Endpoint is Microsoft's EDR/XDR platform for laptops, servers, and mobile. Here's what it does.
  7. 28Defender XDR and attack-surface managementHow Microsoft Defender XDR unifies Defender for Office, Endpoint, Identity, and Cloud Apps into a single SOC workflow.
  8. 29Microsoft 365 security baselinesThe minimum security configuration every Microsoft 365 tenant should have — and how to get there.

04Compliance with Purview

  1. 30What is Microsoft Purview?What Microsoft Purview is: labels, DLP, retention, eDiscovery, insider risk, and the data-governance catalogue — how the two halves differ and where to start.
  2. 31Microsoft Purview sensitivity labels — a deep diveHow Purview sensitivity labels classify and protect content, how to design a taxonomy that survives contact with users, and the rollout order that works.
  3. 32Microsoft Purview Data Loss Prevention — a deep diveDLP policies detect and prevent sensitive data from leaving Microsoft 365. Here's the architecture and how to roll them out.
  4. 33Purview retention policies explainedHow Microsoft Purview retention policies keep and delete content across Microsoft 365 — the model and the gotchas.
  5. 34Microsoft Purview audit retentionHow long Microsoft 365 retains audit logs by default, what Audit (Premium) adds, and how to think about retention.
  6. 35How to search the audit log in Microsoft PurviewHow-toHow to search the Microsoft 365 unified audit log in Purview: check it's on, search by activity, user, and date, export, and Search-UnifiedAuditLog at scale.
  7. 36Microsoft Purview Compliance ManagerCompliance Manager scores your tenant against compliance frameworks and tracks improvements over time.

Independent site, not affiliated with Microsoft. Found a gap in this path? Send it through the contact form.