Microsoft MS-102 Microsoft 365 Roles Role Groups Administrative Units And PIM Practice Test

 

MS-102 skills 1.3 | 27 original questions

This MS-102 practice set focuses on microsoft 365 roles role groups administrative units and pim through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

Graphic Design Institute is standardizing administration after several teams used inconsistent procedures. The support team has reproduced the issue and narrowed it to this requirement: grant only the tenant permissions required for an administrator job function. The service desk has 93 related tickets from 15 business units, so the team wants a targeted fix. The administrator must avoid granting unrelated tenant-wide privilege. What should the administrator configure first?

  1. Use Microsoft 365 usage reports
  2. Create a member user in Microsoft Entra ID
  3. Review license assignment errors for the affected users or groups
  4. Assign the least-privileged built-in Microsoft Entra role
  5. Scope the delegated administrator to the administrative unit instead of the tenant

Correct answer: D

Why: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. It directly addresses the stated requirement.

Option review:

A: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. It directly addresses the stated requirement.

E: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q001: Assign the least-privileged built-in Microsoft Entra role – Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse.

Question 2

An incident review at Graphic Design Institute produces a single administrative requirement for the Microsoft 365 administrator. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to delegate administration of a Microsoft 365 workload without granting Global Administrator. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The initial rollout covers 5 locations and approximately 190 managed identities or devices. Which action should the administrator take?

  1. Use Microsoft Purview role groups for Purview responsibilities
  2. Add the custom domain and verify ownership with DNS
  3. Prefer local internet egress for Microsoft 365 traffic where appropriate
  4. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  5. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary

Correct answer: E

Why: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. It directly addresses the stated requirement.

Option review:

A: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. It directly addresses the stated requirement.

Learning point: MS102-T06-Q002: Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary – Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege.

Question 3

The operations team at Humongous Insurance needs to resolve an issue without granting broader permissions than necessary. The next migration wave is blocked until the team can grant only the tenant permissions required for an administrator job function. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The initial rollout covers 18 locations and approximately 360 managed identities or devices. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Assign the least-privileged built-in Microsoft Entra role
  2. Create a Microsoft 365 Backup protection policy
  3. Create an organizational contact in the Microsoft 365 admin center
  4. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set
  5. Require approval or MFA for PIM role activation

Correct answer: A

Why: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. It directly addresses the stated requirement.

Option review:

A: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. It directly addresses the stated requirement.

B: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q003: Assign the least-privileged built-in Microsoft Entra role – Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse.

Question 4

The messaging administrator at Wingtip Services is designing the next phase of the Microsoft 365 rollout. Audit evidence shows that the current process cannot reliably delegate administration of a Microsoft 365 workload without granting Global Administrator. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The affected scope contains 53 users across 8 administrative groups. What is the most appropriate next step?

  1. Scope the delegated administrator to the administrative unit instead of the tenant
  2. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary
  3. Configure the Organization profile in the Microsoft 365 admin center
  4. Review software update status in the Microsoft 365 admin center
  5. Select the restore point that predates the damaging event

Correct answer: B

Why: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. It directly addresses the stated requirement.

Option review:

A: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. It directly addresses the stated requirement.

C: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q004: Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary – Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege.

Question 5

Margie Travel is migrating a business process to Microsoft 365 and wants the narrowest supported solution. Audit evidence shows that the current process cannot reliably grant only the tenant permissions required for an administrator job function. The organization wants a reversible rollout with measurable verification before broad enforcement. The service desk has 70 related tickets from 21 business units, so the team wants a targeted fix. Which approach most directly addresses the requirement?

  1. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  2. Create a Microsoft 365 Group for shared collaboration resources
  3. Assign the least-privileged built-in Microsoft Entra role
  4. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  5. Use a tenant administrator account for initial setup

Correct answer: C

Why: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. It directly addresses the stated requirement.

D: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q005: Assign the least-privileged built-in Microsoft Entra role – Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse.

Question 6

The hybrid identity engineer at Blue Yonder Airlines is designing the next phase of the Microsoft 365 rollout. The service owner wants a supportable design that will delegate administration of a Microsoft 365 workload without granting Global Administrator. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The service desk has 87 related tickets from 11 business units, so the team wants a targeted fix. What should the administrator configure first?

  1. Require approval or MFA for PIM role activation
  2. Open Health > Service health in the Microsoft 365 admin center
  3. Use Adoption Score for organization-level adoption insights
  4. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary
  5. Invite the partner as an external guest user

Correct answer: D

Why: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. It directly addresses the stated requirement.

Option review:

A: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. It directly addresses the stated requirement.

E: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q006: Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary – Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege.

Question 7

During a tenant review at Woodgrove Bank, the security administrator identifies one unresolved requirement. The organization is replacing a manual process. The replacement must grant only the tenant permissions required for an administrator job function while remaining centrally manageable. The initial rollout covers 24 locations and approximately 130 managed identities or devices. The team must preserve a clear audit trail for the administrative decision. Which option best satisfies the requirement?

  1. Select the restore point that predates the damaging event
  2. Use group-based licensing
  3. Create an administrative unit and assign a scoped role over it
  4. Make the verified custom domain the default domain
  5. Assign the least-privileged built-in Microsoft Entra role

Correct answer: E

Why: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. It directly addresses the stated requirement.

Option review:

A: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. It directly addresses the stated requirement.

Learning point: MS102-T06-Q007: Assign the least-privileged built-in Microsoft Entra role – Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse.

Question 8

City Power & Light is preparing a change requested by the messaging administrator. The project board will approve the next step only if it can grant scoped Defender XDR permissions without assigning unrelated tenant-wide administration. The control owner requires a review after 30 days and evidence from 14 representative cases. The change must be repeatable and supportable after the project team leaves. What is the most appropriate next step?

  1. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  2. Use a tenant administrator account for initial setup
  3. Review Network connectivity insights for the affected office
  4. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  5. Edit the Microsoft 365 contact instead of creating a licensed user

Correct answer: A

Why: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. It directly addresses the stated requirement.

Option review:

A: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. It directly addresses the stated requirement.

B: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Network connectivity insights correlate Microsoft 365 connectivity measurements with locations and recommendations, helping isolate network design issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q008: Use Microsoft Defender Unified RBAC or the appropriate Defender role – Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately.

Question 9

Wingtip Services is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. Audit evidence shows that the current process cannot reliably delegate compliance tasks by adding administrators to the role group that contains the required Purview roles. The organization wants a reversible rollout with measurable verification before broad enforcement. The affected scope contains 47 users across 4 administrative groups. Which control should the team use?

  1. Invite the partner as an external guest user
  2. Use Microsoft Purview role groups for Purview responsibilities
  3. Use Microsoft Graph PowerShell for scripted bulk user changes
  4. Make the privileged role eligible in Microsoft Entra PIM
  5. Review Security & privacy organization settings

Correct answer: B

Why: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. It directly addresses the stated requirement.

Option review:

A: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. It directly addresses the stated requirement.

C: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q009: Use Microsoft Purview role groups for Purview responsibilities – Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties.

Question 10

The operations team at VanArsdel Media needs to resolve an issue without granting broader permissions than necessary. An internal assessment finds the control technically functional but unable to grant scoped Defender XDR permissions without assigning unrelated tenant-wide administration. The initial rollout covers 17 locations and approximately 640 managed identities or devices. The organization wants a reversible rollout with measurable verification before broad enforcement. Which option best satisfies the requirement?

  1. Make the verified custom domain the default domain
  2. Use Microsoft 365 admin center update management to configure the update approach
  3. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  4. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  5. Create and manage a shared mailbox

Correct answer: C

Why: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. It directly addresses the stated requirement.

Option review:

A: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. It directly addresses the stated requirement.

D: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q010: Use Microsoft Defender Unified RBAC or the appropriate Defender role – Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately.

Question 11

Contoso Retail is standardizing administration after several teams used inconsistent procedures. A production change is approved only if it can delegate compliance tasks by adding administrators to the role group that contains the required Purview roles. The change must be repeatable and supportable after the project team leaves. The service desk has 81 related tickets from 7 business units, so the team wants a targeted fix. What should the administrator configure first?

  1. Edit the Microsoft 365 contact instead of creating a licensed user
  2. Assign the least-privileged built-in Microsoft Entra role
  3. Create a new Microsoft 365 tenant
  4. Use Microsoft Purview role groups for Purview responsibilities
  5. Configure Service health notifications

Correct answer: D

Why: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. It directly addresses the stated requirement.

Option review:

A: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. It directly addresses the stated requirement.

E: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q011: Use Microsoft Purview role groups for Purview responsibilities – Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties.

Question 12

Alpine Ski House is standardizing administration after several teams used inconsistent procedures. The next migration wave is blocked until the team can grant scoped Defender XDR permissions without assigning unrelated tenant-wide administration. The solution should use a native Microsoft control that matches the stated requirement. The team will validate the change with 20 pilot groups before expanding it to 7 users. Which option best satisfies the requirement?

  1. Review Security & privacy organization settings
  2. Use Microsoft 365 usage reports
  3. Create a member user in Microsoft Entra ID
  4. Review license assignment errors for the affected users or groups
  5. Use Microsoft Defender Unified RBAC or the appropriate Defender role

Correct answer: E

Why: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. It directly addresses the stated requirement.

Option review:

A: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. It directly addresses the stated requirement.

Learning point: MS102-T06-Q012: Use Microsoft Defender Unified RBAC or the appropriate Defender role – Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately.

Question 13

The identity administrator at Woodgrove Bank is designing the next phase of the Microsoft 365 rollout. The change advisory board wants the smallest supported control that can delegate compliance tasks by adding administrators to the role group that contains the required Purview roles. The team will validate the change with 10 pilot groups before expanding it to 24 users. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which option best satisfies the requirement?

  1. Use Microsoft Purview role groups for Purview responsibilities
  2. Create and manage a shared mailbox
  3. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  4. Add the custom domain and verify ownership with DNS
  5. Prefer local internet egress for Microsoft 365 traffic where appropriate

Correct answer: A

Why: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. It directly addresses the stated requirement.

Option review:

A: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. It directly addresses the stated requirement.

B: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q013: Use Microsoft Purview role groups for Purview responsibilities – Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties.

Question 14

Proseware Logistics is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The implementation review is focused on one outcome: grant scoped Defender XDR permissions without assigning unrelated tenant-wide administration. The affected scope contains 41 users across 23 administrative groups. The team does not want to redesign unrelated workloads. Which option best satisfies the requirement?

  1. Configure Service health notifications
  2. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  3. Create a Microsoft 365 Backup protection policy
  4. Create an organizational contact in the Microsoft 365 admin center
  5. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set

Correct answer: B

Why: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. It directly addresses the stated requirement.

Option review:

A: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. It directly addresses the stated requirement.

C: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q014: Use Microsoft Defender Unified RBAC or the appropriate Defender role – Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately.

Question 15

The operations team at Wingtip Services needs to resolve an issue without granting broader permissions than necessary. The next migration wave is blocked until the team can delegate administration for a defined subset of users or groups. The team must preserve a clear audit trail for the administrative decision. The control owner requires a review after 58 days and evidence from 13 representative cases. Which control should the team use?

  1. Review license assignment errors for the affected users or groups
  2. Scope the delegated administrator to the administrative unit instead of the tenant
  3. Create an administrative unit and assign a scoped role over it
  4. Configure the Organization profile in the Microsoft 365 admin center
  5. Review software update status in the Microsoft 365 admin center

Correct answer: C

Why: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. It directly addresses the stated requirement.

Option review:

A: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. It directly addresses the stated requirement.

D: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q015: Create an administrative unit and assign a scoped role over it – Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant.

Question 16

Coho Winery is preparing a change requested by the governance lead. The current workaround is too manual. The replacement should limit regional or departmental administration to only the objects in that delegated scope. The team will validate the change with 3 pilot groups before expanding it to 75 users. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which option best satisfies the requirement?

  1. Prefer local internet egress for Microsoft 365 traffic where appropriate
  2. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  3. Create a Microsoft 365 Group for shared collaboration resources
  4. Scope the delegated administrator to the administrative unit instead of the tenant
  5. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary

Correct answer: D

Why: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. It directly addresses the stated requirement.

E: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q016: Scope the delegated administrator to the administrative unit instead of the tenant – A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects.

Question 17

Humongous Insurance is standardizing administration after several teams used inconsistent procedures. Security and operations teams agree on the target state: delegate administration for a defined subset of users or groups. The organization wants a reversible rollout with measurable verification before broad enforcement. The initial rollout covers 16 locations and approximately 920 managed identities or devices. Which approach most directly addresses the requirement?

  1. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set
  2. Require approval or MFA for PIM role activation
  3. Open Health > Service health in the Microsoft 365 admin center
  4. Use Adoption Score for organization-level adoption insights
  5. Create an administrative unit and assign a scoped role over it

Correct answer: E

Why: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. It directly addresses the stated requirement.

Option review:

A: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. It directly addresses the stated requirement.

Learning point: MS102-T06-Q017: Create an administrative unit and assign a scoped role over it – Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant.

Question 18

A quarterly control review at Consolidated Messenger identifies a gap that must be corrected before the next audit. The project board will approve the next step only if it can limit regional or departmental administration to only the objects in that delegated scope. The initial rollout covers 6 locations and approximately 180 managed identities or devices. The change must be repeatable and supportable after the project team leaves. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Scope the delegated administrator to the administrative unit instead of the tenant
  2. Review software update status in the Microsoft 365 admin center
  3. Select the restore point that predates the damaging event
  4. Use group-based licensing
  5. Use Microsoft Purview role groups for Purview responsibilities

Correct answer: A

Why: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. It directly addresses the stated requirement.

Option review:

A: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. It directly addresses the stated requirement.

B: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q018: Scope the delegated administrator to the administrative unit instead of the tenant – A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects.

Question 19

Coho Winery is standardizing administration after several teams used inconsistent procedures. The change advisory board wants the smallest supported control that can delegate administration for a defined subset of users or groups. The affected scope contains 35 users across 19 administrative groups. The team must preserve a clear audit trail for the administrative decision. Which action should the administrator take?

  1. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary
  2. Create an administrative unit and assign a scoped role over it
  3. Use a tenant administrator account for initial setup
  4. Review Network connectivity insights for the affected office
  5. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account

Correct answer: B

Why: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. It directly addresses the stated requirement.

Option review:

A: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. It directly addresses the stated requirement.

C: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Network connectivity insights correlate Microsoft 365 connectivity measurements with locations and recommendations, helping isolate network design issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q019: Create an administrative unit and assign a scoped role over it – Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant.

Question 20

Litware Financial is preparing a change requested by the hybrid identity engineer. The administrator is comparing native Microsoft controls after documenting a requirement to limit regional or departmental administration to only the objects in that delegated scope. The team will validate the change with 9 pilot groups before expanding it to 52 users. The administrator must avoid granting unrelated tenant-wide privilege. What is the most appropriate next step?

  1. Use Adoption Score for organization-level adoption insights
  2. Invite the partner as an external guest user
  3. Scope the delegated administrator to the administrative unit instead of the tenant
  4. Use Microsoft Graph PowerShell for scripted bulk user changes
  5. Make the privileged role eligible in Microsoft Entra PIM

Correct answer: C

Why: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. It directly addresses the stated requirement.

Option review:

A: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. It directly addresses the stated requirement.

D: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q020: Scope the delegated administrator to the administrative unit instead of the tenant – A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects.

Question 21

An incident review at A. Datum Manufacturing produces a single administrative requirement for the messaging administrator. The organization is replacing a manual process. The replacement must delegate administration for a defined subset of users or groups while remaining centrally manageable. The team will validate the change with 22 pilot groups before expanding it to 69 users. The solution should use a native Microsoft control that matches the stated requirement. What should the administrator configure first?

  1. Use Microsoft Purview role groups for Purview responsibilities
  2. Make the verified custom domain the default domain
  3. Use Microsoft 365 admin center update management to configure the update approach
  4. Create an administrative unit and assign a scoped role over it
  5. Verify the workload is protected before relying on Microsoft 365 Backup recovery

Correct answer: D

Why: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. It directly addresses the stated requirement.

Option review:

A: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. It directly addresses the stated requirement.

E: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q021: Create an administrative unit and assign a scoped role over it – Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant.

Question 22

Coho Winery is preparing a change requested by the messaging administrator. Audit evidence shows that the current process cannot reliably avoid permanent standing privilege while allowing approved activation when needed. The administrator must avoid granting unrelated tenant-wide privilege. The affected scope contains 86 users across 12 administrative groups. Which administrative choice should be recommended?

  1. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  2. Edit the Microsoft 365 contact instead of creating a licensed user
  3. Assign the least-privileged built-in Microsoft Entra role
  4. Create a new Microsoft 365 tenant
  5. Make the privileged role eligible in Microsoft Entra PIM

Correct answer: E

Why: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. It directly addresses the stated requirement.

Learning point: MS102-T06-Q022: Make the privileged role eligible in Microsoft Entra PIM – PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active.

Question 23

The governance lead at Proseware Logistics is designing the next phase of the Microsoft 365 rollout. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to add control to privileged role activation before the role becomes active. The control owner requires a review after 12 days and evidence from 2 representative cases. The design should minimize manual per-user administration where a scoped central control exists. Which option best satisfies the requirement?

  1. Require approval or MFA for PIM role activation
  2. Scope the delegated administrator to the administrative unit instead of the tenant
  3. Review Security & privacy organization settings
  4. Use Microsoft 365 usage reports
  5. Create a member user in Microsoft Entra ID

Correct answer: A

Why: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. It directly addresses the stated requirement.

Option review:

A: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. It directly addresses the stated requirement.

B: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q023: Require approval or MFA for PIM role activation – PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations.

Question 24

During a tenant review at VanArsdel Media, the compliance administrator identifies one unresolved requirement. A production change is approved only if it can avoid permanent standing privilege while allowing approved activation when needed. The change must be repeatable and supportable after the project team leaves. The initial rollout covers 15 locations and approximately 290 managed identities or devices. Which control should the team use?

  1. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  2. Make the privileged role eligible in Microsoft Entra PIM
  3. Create and manage a shared mailbox
  4. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  5. Add the custom domain and verify ownership with DNS

Correct answer: B

Why: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. It directly addresses the stated requirement.

Option review:

A: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. It directly addresses the stated requirement.

C: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q024: Make the privileged role eligible in Microsoft Entra PIM – PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active.

Question 25

The security administrator at Datum Dynamics is designing the next phase of the Microsoft 365 rollout. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to add control to privileged role activation before the role becomes active. The team will validate the change with 5 pilot groups before expanding it to 46 users. The organization wants a reversible rollout with measurable verification before broad enforcement. Which approach most directly addresses the requirement?

  1. Create a new Microsoft 365 tenant
  2. Configure Service health notifications
  3. Require approval or MFA for PIM role activation
  4. Create a Microsoft 365 Backup protection policy
  5. Create an organizational contact in the Microsoft 365 admin center

Correct answer: C

Why: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. It directly addresses the stated requirement.

Option review:

A: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. It directly addresses the stated requirement.

D: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q025: Require approval or MFA for PIM role activation – PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations.

Question 26

The Microsoft 365 administrator at Margie Travel is designing the next phase of the Microsoft 365 rollout. A controlled pilot must demonstrate how to avoid permanent standing privilege while allowing approved activation when needed. The administrator must avoid granting unrelated tenant-wide privilege. The affected scope contains 63 users across 18 administrative groups. What is the most appropriate next step?

  1. Create a member user in Microsoft Entra ID
  2. Review license assignment errors for the affected users or groups
  3. Create an administrative unit and assign a scoped role over it
  4. Make the privileged role eligible in Microsoft Entra PIM
  5. Configure the Organization profile in the Microsoft 365 admin center

Correct answer: D

Why: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. It directly addresses the stated requirement.

Option review:

A: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. It directly addresses the stated requirement.

E: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T06-Q026: Make the privileged role eligible in Microsoft Entra PIM – PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active.

Question 27

A quarterly control review at Contoso Retail identifies a gap that must be corrected before the next audit. The service owner wants a supportable design that will add control to privileged role activation before the role becomes active. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The service desk has 80 related tickets from 8 business units, so the team wants a targeted fix. What is the most appropriate next step?

  1. Add the custom domain and verify ownership with DNS
  2. Prefer local internet egress for Microsoft 365 traffic where appropriate
  3. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  4. Create a Microsoft 365 Group for shared collaboration resources
  5. Require approval or MFA for PIM role activation

Correct answer: E

Why: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. It directly addresses the stated requirement.

Learning point: MS102-T06-Q027: Require approval or MFA for PIM role activation – PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations.

Popular posts

img