Microsoft MS-102 Microsoft Entra Users External Users And Microsoft 365 Contacts Practice Test
MS-102 skills 1.2 | 28 original questions
This MS-102 practice set focuses on microsoft entra users external users and microsoft 365 contacts through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.
Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.
Question 1
A quarterly control review at Proseware Logistics identifies a gap that must be corrected before the next audit. An internal assessment finds the control technically functional but unable to provision an internal workforce identity that belongs to the tenant. The service desk has 17 related tickets from 20 business units, so the team wants a targeted fix. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which administrative choice should be recommended?
Correct answer: A
Why: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
Option review:
A: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
B: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q001: Create a member user in Microsoft Entra ID – Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate.
Question 2
A quarterly control review at Woodgrove Bank identifies a gap that must be corrected before the next audit. The change advisory board wants the smallest supported control that can provide a partner access to tenant resources without creating a normal internal workforce identity. The affected scope contains 34 users across 10 administrative groups. The administrator must avoid granting unrelated tenant-wide privilege. Which action should the administrator take?
Correct answer: B
Why: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
Option review:
A: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
C: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q002: Invite the partner as an external guest user – Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context.
Question 3
A quarterly control review at Wide World Importers identifies a gap that must be corrected before the next audit. A controlled pilot must demonstrate how to provision an internal workforce identity that belongs to the tenant. The change must be repeatable and supportable after the project team leaves. The control owner requires a review after 51 days and evidence from 23 representative cases. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: C
Why: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
Option review:
A: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
D: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q003: Create a member user in Microsoft Entra ID – Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate.
Question 4
During a tenant review at Consolidated Messenger, the tenant administrator identifies one unresolved requirement. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to provide a partner access to tenant resources without creating a normal internal workforce identity. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The affected scope contains 68 users across 13 administrative groups. Which action should the administrator take?
Correct answer: D
Why: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
Option review:
A: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Network connectivity insights correlate Microsoft 365 connectivity measurements with locations and recommendations, helping isolate network design issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
E: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q004: Invite the partner as an external guest user – Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context.
Question 5
The tenant administrator at Margie Travel is designing the next phase of the Microsoft 365 rollout. A production change is approved only if it can provision an internal workforce identity that belongs to the tenant. The design should minimize manual per-user administration where a scoped central control exists. The control owner requires a review after 85 days and evidence from 3 representative cases. Which control should the team use?
Correct answer: E
Why: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
Option review:
A: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
Learning point: MS102-T04-Q005: Create a member user in Microsoft Entra ID – Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate.
Question 6
The operations team at Fabrikam Health needs to resolve an issue without granting broader permissions than necessary. The current workaround is too manual. The replacement should provide a partner access to tenant resources without creating a normal internal workforce identity. The service desk has 11 related tickets from 16 business units, so the team wants a targeted fix. The administrator must avoid granting unrelated tenant-wide privilege. Which control should the team use?
Correct answer: A
Why: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
Option review:
A: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
B: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q006: Invite the partner as an external guest user – Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context.
Question 7
Margie Travel is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The current workaround is too manual. The replacement should provision an internal workforce identity that belongs to the tenant. The service desk has 28 related tickets from 6 business units, so the team wants a targeted fix. The solution should use a native Microsoft control that matches the stated requirement. What should the administrator configure first?
Correct answer: B
Why: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
Option review:
A: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
C: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q007: Create a member user in Microsoft Entra ID – Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate.
Question 8
Wingtip Services is preparing a change requested by the hybrid identity engineer. The project board will approve the next step only if it can provide a partner access to tenant resources without creating a normal internal workforce identity. The service desk has 45 related tickets from 19 business units, so the team wants a targeted fix. The organization wants a reversible rollout with measurable verification before broad enforcement. What is the most appropriate next step?
Correct answer: C
Why: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
Option review:
A: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
D: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q008: Invite the partner as an external guest user – Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context.
Question 9
A quarterly control review at City Power & Light identifies a gap that must be corrected before the next audit. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to provision an internal workforce identity that belongs to the tenant. The control owner requires a review after 62 days and evidence from 9 representative cases. The response must address the cause described in the scenario rather than simply suppressing the symptom. What should the administrator configure first?
Correct answer: D
Why: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
Option review:
A: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
E: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q009: Create a member user in Microsoft Entra ID – Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate.
Question 10
During a tenant review at Fabrikam Health, the identity administrator identifies one unresolved requirement. The next migration wave is blocked until the team can provide a partner access to tenant resources without creating a normal internal workforce identity. The administrator must avoid granting unrelated tenant-wide privilege. The affected scope contains 79 users across 22 administrative groups. Which option best satisfies the requirement?
Correct answer: E
Why: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
Option review:
A: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
Learning point: MS102-T04-Q010: Invite the partner as an external guest user – Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context.
Question 11
The security administrator at Northwind Traders is designing the next phase of the Microsoft 365 rollout. A production change is approved only if it can provision an internal workforce identity that belongs to the tenant. The response must address the cause described in the scenario rather than simply suppressing the symptom. The control owner requires a review after 5 days and evidence from 12 representative cases. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: A
Why: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
Option review:
A: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
B: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q011: Create a member user in Microsoft Entra ID – Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate.
Question 12
During a tenant review at Fabrikam Health, the governance lead identifies one unresolved requirement. Administrators have confirmed the present design does not provide a partner access to tenant resources without creating a normal internal workforce identity. The initial rollout covers 2 locations and approximately 220 managed identities or devices. The response must address the cause described in the scenario rather than simply suppressing the symptom. What should the administrator configure first?
Correct answer: B
Why: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
Option review:
A: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
C: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q012: Invite the partner as an external guest user – Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context.
Question 13
Litware Financial is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The change advisory board wants the smallest supported control that can provision an internal workforce identity that belongs to the tenant. The control owner requires a review after 39 days and evidence from 15 representative cases. The design should minimize manual per-user administration where a scoped central control exists. Which control should the team use?
Correct answer: C
Why: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
Option review:
A: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. It directly addresses the stated requirement.
D: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q013: Create a member user in Microsoft Entra ID – Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate.
Question 14
Wingtip Services has completed a pilot and must now choose the production administration approach. The change advisory board wants the smallest supported control that can provide a partner access to tenant resources without creating a normal internal workforce identity. The control owner requires a review after 56 days and evidence from 5 representative cases. The design should minimize manual per-user administration where a scoped central control exists. Which action should the administrator take?
Correct answer: D
Why: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
Option review:
A: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. It directly addresses the stated requirement.
E: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q014: Invite the partner as an external guest user – Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context.
Question 15
An incident review at Consolidated Messenger produces a single administrative requirement for the compliance administrator. The implementation review is focused on one outcome: make an external recipient available in the organization address book without creating a sign-in account. The team will validate the change with 18 pilot groups before expanding it to 73 users. The team does not want to redesign unrelated workloads. Which action should the administrator take?
Correct answer: E
Why: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
Option review:
A: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Network connectivity insights correlate Microsoft 365 connectivity measurements with locations and recommendations, helping isolate network design issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
Learning point: MS102-T04-Q015: Create an organizational contact in the Microsoft 365 admin center – A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity.
Question 16
Graphic Design Institute has completed a pilot and must now choose the production administration approach. The next migration wave is blocked until the team can update address-book information for an external recipient who never signs in. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The affected scope contains 90 users across 8 administrative groups. Which option best satisfies the requirement?
Correct answer: A
Why: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
Option review:
A: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
B: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q016: Edit the Microsoft 365 contact instead of creating a licensed user – Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead.
Question 17
An incident review at Graphic Design Institute produces a single administrative requirement for the compliance administrator. The support team has reproduced the issue and narrowed it to this requirement: make an external recipient available in the organization address book without creating a sign-in account. The initial rollout covers 21 locations and approximately 160 managed identities or devices. The architecture board will reject a choice that solves a different problem from the one stated. Which option best satisfies the requirement?
Correct answer: B
Why: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
Option review:
A: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
C: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q017: Create an organizational contact in the Microsoft 365 admin center – A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity.
Question 18
An incident review at Alpine Ski House produces a single administrative requirement for the hybrid identity engineer. An internal assessment finds the control technically functional but unable to update address-book information for an external recipient who never signs in. The control owner requires a review after 33 days and evidence from 11 representative cases. The response must address the cause described in the scenario rather than simply suppressing the symptom. What is the most appropriate next step?
Correct answer: C
Why: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
Option review:
A: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
D: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q018: Edit the Microsoft 365 contact instead of creating a licensed user – Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead.
Question 19
Margie Travel is preparing a change requested by the identity administrator. The implementation review is focused on one outcome: make an external recipient available in the organization address book without creating a sign-in account. The initial rollout covers 24 locations and approximately 500 managed identities or devices. The team does not want to redesign unrelated workloads. Which control should the team use?
Correct answer: D
Why: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
Option review:
A: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
E: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q019: Create an organizational contact in the Microsoft 365 admin center – A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity.
Question 20
The identity administrator at Woodgrove Bank is designing the next phase of the Microsoft 365 rollout. The existing configuration works for normal operations but fails the new requirement to update address-book information for an external recipient who never signs in. The design should minimize manual per-user administration where a scoped central control exists. The team will validate the change with 14 pilot groups before expanding it to 67 users. Which action should the administrator take?
Correct answer: E
Why: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
Option review:
A: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
Learning point: MS102-T04-Q020: Edit the Microsoft 365 contact instead of creating a licensed user – Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead.
Question 21
The operations team at Wingtip Services needs to resolve an issue without granting broader permissions than necessary. Security and operations teams agree on the target state: make an external recipient available in the organization address book without creating a sign-in account. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The service desk has 84 related tickets from 4 business units, so the team wants a targeted fix. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: A
Why: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
Option review:
A: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
B: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q021: Create an organizational contact in the Microsoft 365 admin center – A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity.
Question 22
Wingtip Services is standardizing administration after several teams used inconsistent procedures. The existing configuration works for normal operations but fails the new requirement to update address-book information for an external recipient who never signs in. The organization wants a reversible rollout with measurable verification before broad enforcement. The service desk has 10 related tickets from 17 business units, so the team wants a targeted fix. Which action should the administrator take?
Correct answer: B
Why: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
Option review:
A: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
C: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q022: Edit the Microsoft 365 contact instead of creating a licensed user – Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead.
Question 23
The operations team at Trey Research needs to resolve an issue without granting broader permissions than necessary. The administrator is comparing native Microsoft controls after documenting a requirement to make an external recipient available in the organization address book without creating a sign-in account. The control owner requires a review after 27 days and evidence from 7 representative cases. The organization wants a reversible rollout with measurable verification before broad enforcement. Which action should the administrator take?
Correct answer: C
Why: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
Option review:
A: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
D: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q023: Create an organizational contact in the Microsoft 365 admin center – A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity.
Question 24
Wide World Importers is preparing a change requested by the messaging administrator. Administrators have confirmed the present design does not update address-book information for an external recipient who never signs in. The service desk has 44 related tickets from 20 business units, so the team wants a targeted fix. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. What should the administrator configure first?
Correct answer: D
Why: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
Option review:
A: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
E: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q024: Edit the Microsoft 365 contact instead of creating a licensed user – Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead.
Question 25
An incident review at Contoso Retail produces a single administrative requirement for the identity administrator. The change advisory board wants the smallest supported control that can make an external recipient available in the organization address book without creating a sign-in account. The control owner requires a review after 61 days and evidence from 10 representative cases. The design should minimize manual per-user administration where a scoped central control exists. Which administrative choice should be recommended?
Correct answer: E
Why: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
Option review:
A: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
Learning point: MS102-T04-Q025: Create an organizational contact in the Microsoft 365 admin center – A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity.
Question 26
During a tenant review at Alpine Ski House, the security operations analyst identifies one unresolved requirement. The implementation review is focused on one outcome: update address-book information for an external recipient who never signs in. The affected scope contains 78 users across 23 administrative groups. The team does not want to redesign unrelated workloads. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: A
Why: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
Option review:
A: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
B: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Network connectivity insights correlate Microsoft 365 connectivity measurements with locations and recommendations, helping isolate network design issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q026: Edit the Microsoft 365 contact instead of creating a licensed user – Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead.
Question 27
City Power & Light is preparing a change requested by the governance lead. Before the tenant expands to another business unit, the administrator must make an external recipient available in the organization address book without creating a sign-in account. The service desk has 95 related tickets from 13 business units, so the team wants a targeted fix. The solution should use a native Microsoft control that matches the stated requirement. What should the administrator configure first?
Correct answer: B
Why: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
Option review:
A: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. It directly addresses the stated requirement.
C: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q027: Create an organizational contact in the Microsoft 365 admin center – A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity.
Question 28
The tenant administrator at A. Datum Manufacturing is designing the next phase of the Microsoft 365 rollout. An internal assessment finds the control technically functional but unable to update address-book information for an external recipient who never signs in. The control owner requires a review after 21 days and evidence from 3 representative cases. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which administrative choice should be recommended?
Correct answer: C
Why: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
Option review:
A: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. It directly addresses the stated requirement.
D: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T04-Q028: Edit the Microsoft 365 contact instead of creating a licensed user – Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead.
Popular posts
Recent Posts
