Microsoft MS-102 Microsoft 365 Groups Shared Mailboxes Licensing And Bulk User Management Practice Test

 

MS-102 skills 1.2 | 30 original questions

This MS-102 practice set focuses on microsoft 365 groups shared mailboxes licensing and bulk user management through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

The operations team at Wingtip Services needs to resolve an issue without granting broader permissions than necessary. Before the tenant expands to another business unit, the administrator must provide a team with group membership plus shared collaboration services such as a group mailbox and associated workspace capabilities. The affected scope contains 38 users across 16 administrative groups. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which option best satisfies the requirement?

  1. Use Adoption Score for organization-level adoption insights
  2. Invite the partner as an external guest user
  3. Create an administrative unit and assign a scoped role over it
  4. Create a Microsoft 365 Group for shared collaboration resources
  5. Use Microsoft Graph PowerShell for scripted bulk user changes

Correct answer: D

Why: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. It directly addresses the stated requirement.

Option review:

A: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. It directly addresses the stated requirement.

E: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q001: Create a Microsoft 365 Group for shared collaboration resources – Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources.

Question 2

Humongous Insurance is standardizing administration after several teams used inconsistent procedures. The change advisory board wants the smallest supported control that can allow multiple users to send and receive from a common business mailbox. The control owner requires a review after 55 days and evidence from 6 representative cases. Existing workload settings should remain unchanged unless the requirement specifically depends on them. What is the most appropriate next step?

  1. Use group-based licensing
  2. Make the verified custom domain the default domain
  3. Use Microsoft 365 admin center update management to configure the update approach
  4. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  5. Create and manage a shared mailbox

Correct answer: E

Why: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. It directly addresses the stated requirement.

Option review:

A: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. It directly addresses the stated requirement.

Learning point: MS102-T05-Q002: Create and manage a shared mailbox – A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox.

Question 3

A quarterly control review at Woodgrove Bank identifies a gap that must be corrected before the next audit. The change advisory board wants the smallest supported control that can provide a team with group membership plus shared collaboration services such as a group mailbox and associated workspace capabilities. The control owner requires a review after 72 days and evidence from 19 representative cases. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which option best satisfies the requirement?

  1. Create a Microsoft 365 Group for shared collaboration resources
  2. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  3. Edit the Microsoft 365 contact instead of creating a licensed user
  4. Make the privileged role eligible in Microsoft Entra PIM
  5. Create a new Microsoft 365 tenant

Correct answer: A

Why: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. It directly addresses the stated requirement.

B: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q003: Create a Microsoft 365 Group for shared collaboration resources – Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources.

Question 4

During a tenant review at Southridge Video, the messaging administrator identifies one unresolved requirement. The current workaround is too manual. The replacement should allow multiple users to send and receive from a common business mailbox. The service desk has 89 related tickets from 9 business units, so the team wants a targeted fix. The organization wants a reversible rollout with measurable verification before broad enforcement. Which administrative choice should be recommended?

  1. Use Microsoft Graph PowerShell for scripted bulk user changes
  2. Create and manage a shared mailbox
  3. Review Security & privacy organization settings
  4. Use Microsoft 365 usage reports
  5. Create a member user in Microsoft Entra ID

Correct answer: B

Why: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. It directly addresses the stated requirement.

Option review:

A: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. It directly addresses the stated requirement.

C: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q004: Create and manage a shared mailbox – A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox.

Question 5

The service desk lead at Wingtip Services is designing the next phase of the Microsoft 365 rollout. Before the tenant expands to another business unit, the administrator must provide a team with group membership plus shared collaboration services such as a group mailbox and associated workspace capabilities. The affected scope contains 15 users across 22 administrative groups. The organization wants a reversible rollout with measurable verification before broad enforcement. Which control should the team use?

  1. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  2. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary
  3. Create a Microsoft 365 Group for shared collaboration resources
  4. Create and manage a shared mailbox
  5. Add the custom domain and verify ownership with DNS

Correct answer: C

Why: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. It directly addresses the stated requirement.

Option review:

A: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. It directly addresses the stated requirement.

D: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q005: Create a Microsoft 365 Group for shared collaboration resources – Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources.

Question 6

An incident review at Humongous Insurance produces a single administrative requirement for the compliance administrator. Audit evidence shows that the current process cannot reliably allow multiple users to send and receive from a common business mailbox. The team must preserve a clear audit trail for the administrative decision. The initial rollout covers 12 locations and approximately 320 managed identities or devices. Which control should the team use?

  1. Create a new Microsoft 365 tenant
  2. Configure Service health notifications
  3. Create a Microsoft 365 Backup protection policy
  4. Create and manage a shared mailbox
  5. Create an organizational contact in the Microsoft 365 admin center

Correct answer: D

Why: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. It directly addresses the stated requirement.

Option review:

A: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. It directly addresses the stated requirement.

E: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q006: Create and manage a shared mailbox – A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox.

Question 7

Northwind Traders is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The change advisory board wants the smallest supported control that can provide a team with group membership plus shared collaboration services such as a group mailbox and associated workspace capabilities. The control owner requires a review after 49 days and evidence from 2 representative cases. The team must preserve a clear audit trail for the administrative decision. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Create a member user in Microsoft Entra ID
  2. Use Microsoft Purview role groups for Purview responsibilities
  3. Review license assignment errors for the affected users or groups
  4. Configure the Organization profile in the Microsoft 365 admin center
  5. Create a Microsoft 365 Group for shared collaboration resources

Correct answer: E

Why: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. It directly addresses the stated requirement.

Option review:

A: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. It directly addresses the stated requirement.

Learning point: MS102-T05-Q007: Create a Microsoft 365 Group for shared collaboration resources – Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources.

Question 8

A quarterly control review at Blue Yonder Airlines identifies a gap that must be corrected before the next audit. Administrators have confirmed the present design does not allow multiple users to send and receive from a common business mailbox. The affected scope contains 66 users across 15 administrative groups. The organization wants a reversible rollout with measurable verification before broad enforcement. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Create and manage a shared mailbox
  2. Add the custom domain and verify ownership with DNS
  3. Prefer local internet egress for Microsoft 365 traffic where appropriate
  4. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  5. Assign the least-privileged built-in Microsoft Entra role

Correct answer: A

Why: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. It directly addresses the stated requirement.

Option review:

A: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. It directly addresses the stated requirement.

B: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q008: Create and manage a shared mailbox – A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox.

Question 9

Blue Yonder Airlines is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The implementation review is focused on one outcome: provide a team with group membership plus shared collaboration services such as a group mailbox and associated workspace capabilities. The control owner requires a review after 83 days and evidence from 5 representative cases. The team does not want to redesign unrelated workloads. What should the administrator configure first?

  1. Create an organizational contact in the Microsoft 365 admin center
  2. Create a Microsoft 365 Group for shared collaboration resources
  3. Scope the delegated administrator to the administrative unit instead of the tenant
  4. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set
  5. Open Health > Service health in the Microsoft 365 admin center

Correct answer: B

Why: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. It directly addresses the stated requirement.

Option review:

A: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. It directly addresses the stated requirement.

C: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q009: Create a Microsoft 365 Group for shared collaboration resources – Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources.

Question 10

During a tenant review at City Power & Light, the identity administrator identifies one unresolved requirement. The administrator is comparing native Microsoft controls after documenting a requirement to allow multiple users to send and receive from a common business mailbox. The team will validate the change with 18 pilot groups before expanding it to 9 users. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Configure the Organization profile in the Microsoft 365 admin center
  2. Review software update status in the Microsoft 365 admin center
  3. Create and manage a shared mailbox
  4. Select the restore point that predates the damaging event
  5. Use Microsoft Defender Unified RBAC or the appropriate Defender role

Correct answer: C

Why: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. It directly addresses the stated requirement.

Option review:

A: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. It directly addresses the stated requirement.

D: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q010: Create and manage a shared mailbox – A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox.

Question 11

Graphic Design Institute is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The support team has reproduced the issue and narrowed it to this requirement: automatically assign or remove licenses based on Microsoft Entra group membership. The affected scope contains 26 users across 8 administrative groups. The change must be repeatable and supportable after the project team leaves. What should the administrator configure first?

  1. Assign the least-privileged built-in Microsoft Entra role
  2. Require approval or MFA for PIM role activation
  3. Use a tenant administrator account for initial setup
  4. Use group-based licensing
  5. Review Network connectivity insights for the affected office

Correct answer: D

Why: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. It directly addresses the stated requirement.

Option review:

A: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. It directly addresses the stated requirement.

E: Network connectivity insights correlate Microsoft 365 connectivity measurements with locations and recommendations, helping isolate network design issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q011: Use group-based licensing – Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work.

Question 12

A quarterly control review at A. Datum Manufacturing identifies a gap that must be corrected before the next audit. The current workaround is too manual. The replacement should find why a user did not receive the expected service plan from a group-based license assignment. The control owner requires a review after 43 days and evidence from 21 representative cases. The architecture board will reject a choice that solves a different problem from the one stated. Which option best satisfies the requirement?

  1. Open Health > Service health in the Microsoft 365 admin center
  2. Use Adoption Score for organization-level adoption insights
  3. Invite the partner as an external guest user
  4. Create an administrative unit and assign a scoped role over it
  5. Review license assignment errors for the affected users or groups

Correct answer: E

Why: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. It directly addresses the stated requirement.

Option review:

A: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. It directly addresses the stated requirement.

Learning point: MS102-T05-Q012: Review license assignment errors for the affected users or groups – License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses.

Question 13

Proseware Logistics has completed a pilot and must now choose the production administration approach. Before the tenant expands to another business unit, the administrator must automatically assign or remove licenses based on Microsoft Entra group membership. The service desk has 60 related tickets from 11 business units, so the team wants a targeted fix. The design should minimize manual per-user administration where a scoped central control exists. What should the administrator configure first?

  1. Use group-based licensing
  2. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  3. Create and manage a shared mailbox
  4. Make the verified custom domain the default domain
  5. Use Microsoft 365 admin center update management to configure the update approach

Correct answer: A

Why: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. It directly addresses the stated requirement.

Option review:

A: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. It directly addresses the stated requirement.

B: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q013: Use group-based licensing – Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work.

Question 14

An incident review at Fourth Coffee produces a single administrative requirement for the identity administrator. A post-incident action item requires the tenant to find why a user did not receive the expected service plan from a group-based license assignment. The initial rollout covers 24 locations and approximately 770 managed identities or devices. The design should minimize manual per-user administration where a scoped central control exists. Which option best satisfies the requirement?

  1. Review Network connectivity insights for the affected office
  2. Review license assignment errors for the affected users or groups
  3. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  4. Edit the Microsoft 365 contact instead of creating a licensed user
  5. Make the privileged role eligible in Microsoft Entra PIM

Correct answer: B

Why: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. It directly addresses the stated requirement.

Option review:

A: Network connectivity insights correlate Microsoft 365 connectivity measurements with locations and recommendations, helping isolate network design issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. It directly addresses the stated requirement.

C: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q014: Review license assignment errors for the affected users or groups – License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses.

Question 15

Southridge Video is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The project board will approve the next step only if it can automatically assign or remove licenses based on Microsoft Entra group membership. The affected scope contains 94 users across 14 administrative groups. The architecture board will reject a choice that solves a different problem from the one stated. Which action should the administrator take?

  1. Create an administrative unit and assign a scoped role over it
  2. Use Microsoft Graph PowerShell for scripted bulk user changes
  3. Use group-based licensing
  4. Review Security & privacy organization settings
  5. Use Microsoft 365 usage reports

Correct answer: C

Why: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. It directly addresses the stated requirement.

Option review:

A: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. It directly addresses the stated requirement.

D: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q015: Use group-based licensing – Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work.

Question 16

An incident review at Graphic Design Institute produces a single administrative requirement for the security operations analyst. The support team has reproduced the issue and narrowed it to this requirement: find why a user did not receive the expected service plan from a group-based license assignment. The control owner requires a review after 20 days and evidence from 4 representative cases. The administrator must avoid granting unrelated tenant-wide privilege. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use Microsoft 365 admin center update management to configure the update approach
  2. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  3. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary
  4. Review license assignment errors for the affected users or groups
  5. Create a Microsoft 365 Group for shared collaboration resources

Correct answer: D

Why: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. It directly addresses the stated requirement.

Option review:

A: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. It directly addresses the stated requirement.

E: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q016: Review license assignment errors for the affected users or groups – License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses.

Question 17

Margie Travel is preparing a change requested by the compliance administrator. Security and operations teams agree on the target state: automatically assign or remove licenses based on Microsoft Entra group membership. The administrator must avoid granting unrelated tenant-wide privilege. The initial rollout covers 17 locations and approximately 370 managed identities or devices. Which control should the team use?

  1. Make the privileged role eligible in Microsoft Entra PIM
  2. Create a new Microsoft 365 tenant
  3. Configure Service health notifications
  4. Create a Microsoft 365 Backup protection policy
  5. Use group-based licensing

Correct answer: E

Why: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. It directly addresses the stated requirement.

Option review:

A: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. It directly addresses the stated requirement.

Learning point: MS102-T05-Q017: Use group-based licensing – Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work.

Question 18

City Power & Light has completed a pilot and must now choose the production administration approach. The organization is replacing a manual process. The replacement must find why a user did not receive the expected service plan from a group-based license assignment while remaining centrally manageable. The service desk has 54 related tickets from 7 business units, so the team wants a targeted fix. The administrator must avoid granting unrelated tenant-wide privilege. Which option best satisfies the requirement?

  1. Review license assignment errors for the affected users or groups
  2. Use Microsoft 365 usage reports
  3. Create a member user in Microsoft Entra ID
  4. Use Microsoft Purview role groups for Purview responsibilities
  5. Use group-based licensing

Correct answer: A

Why: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. It directly addresses the stated requirement.

Option review:

A: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. It directly addresses the stated requirement.

B: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q018: Review license assignment errors for the affected users or groups – License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses.

Question 19

Margie Travel is preparing a change requested by the messaging administrator. The administrator is comparing native Microsoft controls after documenting a requirement to automatically assign or remove licenses based on Microsoft Entra group membership. The control owner requires a review after 71 days and evidence from 20 representative cases. The solution should use a native Microsoft control that matches the stated requirement. Which approach most directly addresses the requirement?

  1. Create a Microsoft 365 Group for shared collaboration resources
  2. Use group-based licensing
  3. Add the custom domain and verify ownership with DNS
  4. Prefer local internet egress for Microsoft 365 traffic where appropriate
  5. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate

Correct answer: B

Why: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. It directly addresses the stated requirement.

C: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q019: Use group-based licensing – Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work.

Question 20

Blue Yonder Airlines is migrating a business process to Microsoft 365 and wants the narrowest supported solution. A post-incident action item requires the tenant to find why a user did not receive the expected service plan from a group-based license assignment. The affected scope contains 88 users across 10 administrative groups. The team must preserve a clear audit trail for the administrative decision. What is the most appropriate next step?

  1. Create a Microsoft 365 Backup protection policy
  2. Create an organizational contact in the Microsoft 365 admin center
  3. Review license assignment errors for the affected users or groups
  4. Scope the delegated administrator to the administrative unit instead of the tenant
  5. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set

Correct answer: C

Why: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. It directly addresses the stated requirement.

D: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q020: Review license assignment errors for the affected users or groups – License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses.

Question 21

Humongous Insurance is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The next migration wave is blocked until the team can apply repeatable user changes across many identities through supported Microsoft Graph administration cmdlets. The design should minimize manual per-user administration where a scoped central control exists. The service desk has 14 related tickets from 23 business units, so the team wants a targeted fix. Which approach most directly addresses the requirement?

  1. Use group-based licensing
  2. Configure the Organization profile in the Microsoft 365 admin center
  3. Review software update status in the Microsoft 365 admin center
  4. Use Microsoft Graph PowerShell for scripted bulk user changes
  5. Select the restore point that predates the damaging event

Correct answer: D

Why: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. It directly addresses the stated requirement.

Option review:

A: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. It directly addresses the stated requirement.

E: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q021: Use Microsoft Graph PowerShell for scripted bulk user changes – Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations.

Question 22

Blue Yonder Airlines is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The current workaround is too manual. The replacement should perform a repeatable bulk identity operation while keeping the scope explicit and reviewable. The team will validate the change with 13 pilot groups before expanding it to 31 users. The solution should use a native Microsoft control that matches the stated requirement. Which approach most directly addresses the requirement?

  1. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  2. Assign the least-privileged built-in Microsoft Entra role
  3. Require approval or MFA for PIM role activation
  4. Use a tenant administrator account for initial setup
  5. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set

Correct answer: E

Why: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. It directly addresses the stated requirement.

Learning point: MS102-T05-Q022: Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set – PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently.

Question 23

Proseware Logistics has completed a pilot and must now choose the production administration approach. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to apply repeatable user changes across many identities through supported Microsoft Graph administration cmdlets. The design should minimize manual per-user administration where a scoped central control exists. The control owner requires a review after 48 days and evidence from 3 representative cases. Which approach most directly addresses the requirement?

  1. Use Microsoft Graph PowerShell for scripted bulk user changes
  2. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set
  3. Open Health > Service health in the Microsoft 365 admin center
  4. Use Adoption Score for organization-level adoption insights
  5. Invite the partner as an external guest user

Correct answer: A

Why: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. It directly addresses the stated requirement.

Option review:

A: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. It directly addresses the stated requirement.

B: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q023: Use Microsoft Graph PowerShell for scripted bulk user changes – Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations.

Question 24

Southridge Video is migrating a business process to Microsoft 365 and wants the narrowest supported solution. Security and operations teams agree on the target state: perform a repeatable bulk identity operation while keeping the scope explicit and reviewable. The organization wants a reversible rollout with measurable verification before broad enforcement. The initial rollout covers 16 locations and approximately 650 managed identities or devices. Which approach most directly addresses the requirement?

  1. Select the restore point that predates the damaging event
  2. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set
  3. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  4. Create and manage a shared mailbox
  5. Make the verified custom domain the default domain

Correct answer: B

Why: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. It directly addresses the stated requirement.

Option review:

A: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. It directly addresses the stated requirement.

C: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q024: Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set – PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently.

Question 25

Fabrikam Health has completed a pilot and must now choose the production administration approach. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to apply repeatable user changes across many identities through supported Microsoft Graph administration cmdlets. The response must address the cause described in the scenario rather than simply suppressing the symptom. The initial rollout covers 6 locations and approximately 820 managed identities or devices. What is the most appropriate next step?

  1. Use a tenant administrator account for initial setup
  2. Review Network connectivity insights for the affected office
  3. Use Microsoft Graph PowerShell for scripted bulk user changes
  4. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  5. Edit the Microsoft 365 contact instead of creating a licensed user

Correct answer: C

Why: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. It directly addresses the stated requirement.

Option review:

A: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Network connectivity insights correlate Microsoft 365 connectivity measurements with locations and recommendations, helping isolate network design issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. It directly addresses the stated requirement.

D: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q025: Use Microsoft Graph PowerShell for scripted bulk user changes – Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations.

Question 26

Graphic Design Institute is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to perform a repeatable bulk identity operation while keeping the scope explicit and reviewable. The affected scope contains 8 users across 19 administrative groups. The administrator must avoid granting unrelated tenant-wide privilege. What is the most appropriate next step?

  1. Invite the partner as an external guest user
  2. Create an administrative unit and assign a scoped role over it
  3. Review license assignment errors for the affected users or groups
  4. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set
  5. Review Security & privacy organization settings

Correct answer: D

Why: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. It directly addresses the stated requirement.

Option review:

A: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. It directly addresses the stated requirement.

E: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q026: Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set – PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently.

Question 27

Lucerne Publishing has completed a pilot and must now choose the production administration approach. The existing configuration works for normal operations but fails the new requirement to apply repeatable user changes across many identities through supported Microsoft Graph administration cmdlets. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The control owner requires a review after 25 days and evidence from 9 representative cases. What should the administrator configure first?

  1. Make the verified custom domain the default domain
  2. Use Microsoft 365 admin center update management to configure the update approach
  3. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  4. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary
  5. Use Microsoft Graph PowerShell for scripted bulk user changes

Correct answer: E

Why: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. It directly addresses the stated requirement.

Option review:

A: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. It directly addresses the stated requirement.

Learning point: MS102-T05-Q027: Use Microsoft Graph PowerShell for scripted bulk user changes – Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations.

Question 28

The service desk lead at Adventure Works is designing the next phase of the Microsoft 365 rollout. The service owner wants a supportable design that will perform a repeatable bulk identity operation while keeping the scope explicit and reviewable. The administrator must avoid granting unrelated tenant-wide privilege. The initial rollout covers 22 locations and approximately 420 managed identities or devices. Which option best satisfies the requirement?

  1. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set
  2. Edit the Microsoft 365 contact instead of creating a licensed user
  3. Make the privileged role eligible in Microsoft Entra PIM
  4. Create a new Microsoft 365 tenant
  5. Configure Service health notifications

Correct answer: A

Why: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. It directly addresses the stated requirement.

Option review:

A: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. It directly addresses the stated requirement.

B: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q028: Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set – PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently.

Question 29

VanArsdel Media has completed a pilot and must now choose the production administration approach. The organization is replacing a manual process. The replacement must apply repeatable user changes across many identities through supported Microsoft Graph administration cmdlets while remaining centrally manageable. The service desk has 59 related tickets from 12 business units, so the team wants a targeted fix. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which control should the team use?

  1. Review Security & privacy organization settings
  2. Use Microsoft Graph PowerShell for scripted bulk user changes
  3. Use Microsoft 365 usage reports
  4. Create a member user in Microsoft Entra ID
  5. Use Microsoft Purview role groups for Purview responsibilities

Correct answer: B

Why: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. It directly addresses the stated requirement.

Option review:

A: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. It directly addresses the stated requirement.

C: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q029: Use Microsoft Graph PowerShell for scripted bulk user changes – Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations.

Question 30

A quarterly control review at Adventure Works identifies a gap that must be corrected before the next audit. The next migration wave is blocked until the team can perform a repeatable bulk identity operation while keeping the scope explicit and reviewable. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The affected scope contains 76 users across 2 administrative groups. Which approach most directly addresses the requirement?

  1. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary
  2. Create a Microsoft 365 Group for shared collaboration resources
  3. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set
  4. Add the custom domain and verify ownership with DNS
  5. Prefer local internet egress for Microsoft 365 traffic where appropriate

Correct answer: C

Why: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. It directly addresses the stated requirement.

Option review:

A: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. It directly addresses the stated requirement.

D: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T05-Q030: Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set – PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently.

Popular posts

img