ms-102Expert
Microsoft 365 Administrator
Microsoft 365 Certified: Administrator Expert
MS-102 spans the whole tenant: setup and roles, hybrid identity and Entra ID, the Defender stack, and Purview. It is the exam this site is closest to, so the path is long — the how-to guides are there because the exam is scenario-based and expects you to know which portal blade does what.
For: Tenant administrators who own identity, security, and compliance day to day. Replaced the MS-100 + MS-101 pair.
36 guides in 4sections. The sections are this site's grouping, written to follow the shape of the published skills outline; weightings and the current outline live on the exam page above and change between exam versions.
01Deploy and manage the tenant
- 1Setting up Microsoft 365 from scratchThe setup order for a brand-new Microsoft 365 tenant — tenant, domain, identity, security baseline, then data and clients. Sequence matters more than speed.
- 2Microsoft 365 domains and DNS setupThe DNS records every Microsoft 365 tenant needs — and what each one does.
- 3Microsoft 365 admin centerThe Microsoft 365 admin center: what actually lives there, the specialist portals it hands off to, and the role design that should gate all of it.
- 4Microsoft 365 administrator rolesThe Entra ID admin roles that gate Microsoft 365 administration — and how to assign them with least privilege.
- 5Microsoft 365 admin role designHow to design admin role assignments for least-privilege Microsoft 365 administration at scale.
- 6Microsoft 365 service health and Message CenterHow to track Microsoft 365 service incidents and upcoming changes — and how to keep your organisation informed.
- 7Microsoft 365 monitoring and alertsHow to monitor a Microsoft 365 tenant — service health, audit logs, security alerts, and third-party tooling.
- 8Microsoft 365 tenant audit checklistA practical checklist for auditing a Microsoft 365 tenant's configuration, security posture, and compliance.
- 9Microsoft 365 reporting via PowerShellPowerShell patterns for extracting reporting data from Microsoft 365 — licensing, usage, security posture, mailbox stats.
02Identity and access with Entra ID
- 10Hybrid identity strategy for Microsoft 365How to plan the hybrid-identity journey from on-premises AD to Entra ID-only — staged, with the right choices at each stage.
- 11Entra Connect vs Entra Cloud SyncThe two ways to sync on-prem Active Directory to Entra ID — what each does, the scenarios that still force the old tool, and which to use today.
- 12Microsoft Entra Connect HealthConnect Health monitors the hybrid-identity infrastructure — Entra Connect, AD FS, and AD DS.
- 13Entra ID groups and group-based licensingGroup types in Entra ID, dynamic groups, and using groups to assign licences automatically.
- 14How to assign licenses with group-based licensing in Entra IDHow-toHow to assign Microsoft 365 licences with group-based licensing in Entra ID: build the groups, set usage location, migrate direct assignments, fix errors.
- 15Entra ID Administrative UnitsAdministrative Units scope admin roles to subsets of the directory — for delegated administration without tenant-wide privileges.
- 16Entra ID Conditional Access designDesigning a Conditional Access baseline: the policies, the principles, the order to write them in, and the habits that keep the estate healthy.
- 17How to require MFA for all users with Conditional AccessHow-toHow to require MFA for all users in Entra ID with Conditional Access: the exclusions that matter, report-only rollout, registration campaign, enforcement.
- 18Entra ID passwordless authenticationThe realistic options for going passwordless in Microsoft 365 — Authenticator, FIDO2, Windows Hello, and passkeys.
- 19Entra ID self-service password resetSSPR lets users reset their own passwords without calling the help desk. Here's the configuration and rollout.
- 20Entra ID Privileged Identity ManagementPIM turns standing admin access into just-in-time, approval-gated activation. The model, what it covers, role settings that work, and a rollout that sticks.
- 21Entra ID B2B guest accessHow Entra ID B2B brings external users into your tenant as guests — invitations, controls, and lifecycle.
03Security and threats with Defender
- 22Which Microsoft Defender is whichWhich Microsoft Defender is which: Endpoint, Office 365, Identity, Cloud Apps, Business, XDR, Cloud, Antivirus — what each does and which licence gets it.
- 23Microsoft Defender for Office 365 explainedWhat Defender for Office 365 adds on top of EOP — Safe Links, Safe Attachments, AIR, attack simulation — plus Plan 1 vs Plan 2 and the settings worth tuning.
- 24Exchange Online anti-spam and anti-phishingThe layered defences Exchange Online uses against spam, malware, and phishing — and how to tune them.
- 25Defender for Office 365 quarantine workflowHow users and admins work with quarantine — release, request, report, and the policy decisions behind it.
- 26Attack Simulation Training in Defender for Office 365How to run controlled phishing simulations and embedded training to harden users against real attacks.
- 27Microsoft Defender for Endpoint explainedDefender for Endpoint is Microsoft's EDR/XDR platform for laptops, servers, and mobile. Here's what it does.
- 28Defender XDR and attack-surface managementHow Microsoft Defender XDR unifies Defender for Office, Endpoint, Identity, and Cloud Apps into a single SOC workflow.
- 29Microsoft 365 security baselinesThe minimum security configuration every Microsoft 365 tenant should have — and how to get there.
04Compliance with Purview
- 30What is Microsoft Purview?What Microsoft Purview is: labels, DLP, retention, eDiscovery, insider risk, and the data-governance catalogue — how the two halves differ and where to start.
- 31Microsoft Purview sensitivity labels — a deep diveHow Purview sensitivity labels classify and protect content, how to design a taxonomy that survives contact with users, and the rollout order that works.
- 32Microsoft Purview Data Loss Prevention — a deep diveDLP policies detect and prevent sensitive data from leaving Microsoft 365. Here's the architecture and how to roll them out.
- 33Purview retention policies explainedHow Microsoft Purview retention policies keep and delete content across Microsoft 365 — the model and the gotchas.
- 34Microsoft Purview audit retentionHow long Microsoft 365 retains audit logs by default, what Audit (Premium) adds, and how to think about retention.
- 35How to search the audit log in Microsoft PurviewHow-toHow to search the Microsoft 365 unified audit log in Purview: check it's on, search by activity, user, and date, export, and Search-UnifiedAuditLog at scale.
- 36Microsoft Purview Compliance ManagerCompliance Manager scores your tenant against compliance frameworks and tracks improvements over time.
Independent site, not affiliated with Microsoft. Found a gap in this path? Send it through the contact form.