Microsoft MS-102 Tenant Creation Domains And Organization Settings Practice Test

 

MS-102 skills 1.1 | 28 original questions

This MS-102 practice set focuses on tenant creation domains and organization settings through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

Alpine Ski House is preparing a change requested by the hybrid identity engineer. A post-incident action item requires the tenant to establish an isolated Microsoft 365 organization with its own directory boundary. The service desk has 22 related tickets from 15 business units, so the team wants a targeted fix. The change must be repeatable and supportable after the project team leaves. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Create a new Microsoft 365 tenant
  2. Use Microsoft Graph PowerShell for scripted bulk user changes
  3. Scope the delegated administrator to the administrative unit instead of the tenant
  4. Review Security & privacy organization settings
  5. Use Microsoft 365 usage reports

Correct answer: A

Why: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. It directly addresses the stated requirement.

Option review:

A: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. It directly addresses the stated requirement.

B: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q001: Create a new Microsoft 365 tenant – A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment.

Question 2

A quarterly control review at Trey Research identifies a gap that must be corrected before the next audit. Before the tenant expands to another business unit, the administrator must perform tenant-level setup with an account that can configure organization-wide settings. The team will validate the change with 5 pilot groups before expanding it to 39 users. The change must be repeatable and supportable after the project team leaves. Which action should the administrator take?

  1. Use Microsoft 365 admin center update management to configure the update approach
  2. Use a tenant administrator account for initial setup
  3. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  4. Create and manage a shared mailbox
  5. Use Microsoft Defender Unified RBAC or the appropriate Defender role

Correct answer: B

Why: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. It directly addresses the stated requirement.

Option review:

A: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. It directly addresses the stated requirement.

C: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q002: Use a tenant administrator account for initial setup – Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user.

Question 3

A quarterly control review at Contoso Retail identifies a gap that must be corrected before the next audit. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to establish an isolated Microsoft 365 organization with its own directory boundary. The change must be repeatable and supportable after the project team leaves. The control owner requires a review after 56 days and evidence from 18 representative cases. Which control should the team use?

  1. Assign the least-privileged built-in Microsoft Entra role
  2. Require approval or MFA for PIM role activation
  3. Create a new Microsoft 365 tenant
  4. Configure Service health notifications
  5. Create a Microsoft 365 Backup protection policy

Correct answer: C

Why: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. It directly addresses the stated requirement.

Option review:

A: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. It directly addresses the stated requirement.

D: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q003: Create a new Microsoft 365 tenant – A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment.

Question 4

City Power & Light is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The organization is replacing a manual process. The replacement must perform tenant-level setup with an account that can configure organization-wide settings while remaining centrally manageable. The team will validate the change with 8 pilot groups before expanding it to 73 users. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which option best satisfies the requirement?

  1. Use Microsoft 365 usage reports
  2. Create a member user in Microsoft Entra ID
  3. Review license assignment errors for the affected users or groups
  4. Use a tenant administrator account for initial setup
  5. Create an administrative unit and assign a scoped role over it

Correct answer: D

Why: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. It directly addresses the stated requirement.

Option review:

A: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. It directly addresses the stated requirement.

E: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q004: Use a tenant administrator account for initial setup – Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user.

Question 5

  1. Datum Manufacturing is preparing a change requested by the compliance administrator. The organization is replacing a manual process. The replacement must establish an isolated Microsoft 365 organization with its own directory boundary while remaining centrally manageable. The affected scope contains 90 users across 21 administrative groups. The solution should use a native Microsoft control that matches the stated requirement. What is the most appropriate next step?
  2. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  3. Add the custom domain and verify ownership with DNS
  4. Prefer local internet egress for Microsoft 365 traffic where appropriate
  5. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  6. Create a new Microsoft 365 tenant

Correct answer: E

Why: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. It directly addresses the stated requirement.

Option review:

A: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. It directly addresses the stated requirement.

Learning point: MS102-T01-Q005: Create a new Microsoft 365 tenant – A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment.

Question 6

A quarterly control review at VanArsdel Media identifies a gap that must be corrected before the next audit. Administrators have confirmed the present design does not perform tenant-level setup with an account that can configure organization-wide settings. The service desk has 16 related tickets from 11 business units, so the team wants a targeted fix. The organization wants a reversible rollout with measurable verification before broad enforcement. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use a tenant administrator account for initial setup
  2. Create a Microsoft 365 Backup protection policy
  3. Create an organizational contact in the Microsoft 365 admin center
  4. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set
  5. Make the privileged role eligible in Microsoft Entra PIM

Correct answer: A

Why: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. It directly addresses the stated requirement.

Option review:

A: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. It directly addresses the stated requirement.

B: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q006: Use a tenant administrator account for initial setup – Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user.

Question 7

The operations team at Litware Financial needs to resolve an issue without granting broader permissions than necessary. Before the tenant expands to another business unit, the administrator must establish an isolated Microsoft 365 organization with its own directory boundary. The initial rollout covers 24 locations and approximately 330 managed identities or devices. The organization wants a reversible rollout with measurable verification before broad enforcement. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Create an administrative unit and assign a scoped role over it
  2. Create a new Microsoft 365 tenant
  3. Configure the Organization profile in the Microsoft 365 admin center
  4. Review software update status in the Microsoft 365 admin center
  5. Select the restore point that predates the damaging event

Correct answer: B

Why: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. It directly addresses the stated requirement.

Option review:

A: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. It directly addresses the stated requirement.

C: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q007: Create a new Microsoft 365 tenant – A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment.

Question 8

The operations team at VanArsdel Media needs to resolve an issue without granting broader permissions than necessary. The project board will approve the next step only if it can perform tenant-level setup with an account that can configure organization-wide settings. The control owner requires a review after 50 days and evidence from 14 representative cases. The team must preserve a clear audit trail for the administrative decision. What is the most appropriate next step?

  1. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  2. Create a Microsoft 365 Group for shared collaboration resources
  3. Use a tenant administrator account for initial setup
  4. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary
  5. Create a new Microsoft 365 tenant

Correct answer: C

Why: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. It directly addresses the stated requirement.

D: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q008: Use a tenant administrator account for initial setup – Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user.

Question 9

Graphic Design Institute is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The project board will approve the next step only if it can establish an isolated Microsoft 365 organization with its own directory boundary. The team will validate the change with 4 pilot groups before expanding it to 67 users. The design should minimize manual per-user administration where a scoped central control exists. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Make the privileged role eligible in Microsoft Entra PIM
  2. Open Health > Service health in the Microsoft 365 admin center
  3. Use Adoption Score for organization-level adoption insights
  4. Create a new Microsoft 365 tenant
  5. Invite the partner as an external guest user

Correct answer: D

Why: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. It directly addresses the stated requirement.

Option review:

A: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. It directly addresses the stated requirement.

E: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q009: Create a new Microsoft 365 tenant – A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment.

Question 10

Woodgrove Bank is standardizing administration after several teams used inconsistent procedures. The current workaround is too manual. The replacement should perform tenant-level setup with an account that can configure organization-wide settings. The team will validate the change with 17 pilot groups before expanding it to 84 users. The change must be repeatable and supportable after the project team leaves. Which administrative choice should be recommended?

  1. Select the restore point that predates the damaging event
  2. Use group-based licensing
  3. Use Microsoft Purview role groups for Purview responsibilities
  4. Make the verified custom domain the default domain
  5. Use a tenant administrator account for initial setup

Correct answer: E

Why: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. It directly addresses the stated requirement.

Option review:

A: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. It directly addresses the stated requirement.

Learning point: MS102-T01-Q010: Use a tenant administrator account for initial setup – Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user.

Question 11

An incident review at Fabrikam Health produces a single administrative requirement for the identity administrator. The service owner wants a supportable design that will use the company public domain for Microsoft 365 identities after proving control of it. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The service desk has 10 related tickets from 7 business units, so the team wants a targeted fix. Which approach most directly addresses the requirement?

  1. Add the custom domain and verify ownership with DNS
  2. Create a new Microsoft 365 tenant
  3. Review Network connectivity insights for the affected office
  4. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  5. Edit the Microsoft 365 contact instead of creating a licensed user

Correct answer: A

Why: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. It directly addresses the stated requirement.

B: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Network connectivity insights correlate Microsoft 365 connectivity measurements with locations and recommendations, helping isolate network design issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q011: Add the custom domain and verify ownership with DNS – Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully.

Question 12

Adventure Works is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to have newly created identities use the organization domain by default after verification. The team will validate the change with 20 pilot groups before expanding it to 27 users. The organization wants a reversible rollout with measurable verification before broad enforcement. Which control should the team use?

  1. Invite the partner as an external guest user
  2. Make the verified custom domain the default domain
  3. Use Microsoft Graph PowerShell for scripted bulk user changes
  4. Scope the delegated administrator to the administrative unit instead of the tenant
  5. Review Security & privacy organization settings

Correct answer: B

Why: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. It directly addresses the stated requirement.

Option review:

A: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. It directly addresses the stated requirement.

C: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q012: Make the verified custom domain the default domain – After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default.

Question 13

Woodgrove Bank is preparing a change requested by the hybrid identity engineer. Audit evidence shows that the current process cannot reliably use the company public domain for Microsoft 365 identities after proving control of it. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The service desk has 44 related tickets from 10 business units, so the team wants a targeted fix. What is the most appropriate next step?

  1. Make the verified custom domain the default domain
  2. Use Microsoft 365 admin center update management to configure the update approach
  3. Add the custom domain and verify ownership with DNS
  4. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  5. Create and manage a shared mailbox

Correct answer: C

Why: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. It directly addresses the stated requirement.

Option review:

A: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. It directly addresses the stated requirement.

D: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q013: Add the custom domain and verify ownership with DNS – Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully.

Question 14

During a tenant review at Fabrikam Health, the Microsoft 365 administrator identifies one unresolved requirement. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to have newly created identities use the organization domain by default after verification. The affected scope contains 61 users across 23 administrative groups. The solution should use a native Microsoft control that matches the stated requirement. Which administrative choice should be recommended?

  1. Edit the Microsoft 365 contact instead of creating a licensed user
  2. Assign the least-privileged built-in Microsoft Entra role
  3. Require approval or MFA for PIM role activation
  4. Make the verified custom domain the default domain
  5. Configure Service health notifications

Correct answer: D

Why: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. It directly addresses the stated requirement.

Option review:

A: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. It directly addresses the stated requirement.

E: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q014: Make the verified custom domain the default domain – After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default.

Question 15

An incident review at Margie Travel produces a single administrative requirement for the identity administrator. Before the tenant expands to another business unit, the administrator must use the company public domain for Microsoft 365 identities after proving control of it. The control owner requires a review after 78 days and evidence from 13 representative cases. The team must preserve a clear audit trail for the administrative decision. What should the administrator configure first?

  1. Review Security & privacy organization settings
  2. Use Microsoft 365 usage reports
  3. Create a member user in Microsoft Entra ID
  4. Review license assignment errors for the affected users or groups
  5. Add the custom domain and verify ownership with DNS

Correct answer: E

Why: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. It directly addresses the stated requirement.

Option review:

A: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. It directly addresses the stated requirement.

Learning point: MS102-T01-Q015: Add the custom domain and verify ownership with DNS – Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully.

Question 16

Tailspin Toys is standardizing administration after several teams used inconsistent procedures. The current workaround is too manual. The replacement should have newly created identities use the organization domain by default after verification. The control owner requires a review after 95 days and evidence from 3 representative cases. The change must be repeatable and supportable after the project team leaves. Which administrative choice should be recommended?

  1. Make the verified custom domain the default domain
  2. Create and manage a shared mailbox
  3. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  4. Use a tenant administrator account for initial setup
  5. Prefer local internet egress for Microsoft 365 traffic where appropriate

Correct answer: A

Why: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. It directly addresses the stated requirement.

Option review:

A: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. It directly addresses the stated requirement.

B: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q016: Make the verified custom domain the default domain – After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default.

Question 17

Fourth Coffee has completed a pilot and must now choose the production administration approach. Administrators have confirmed the present design does not use the company public domain for Microsoft 365 identities after proving control of it. The affected scope contains 21 users across 16 administrative groups. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which control should the team use?

  1. Configure Service health notifications
  2. Add the custom domain and verify ownership with DNS
  3. Create a Microsoft 365 Backup protection policy
  4. Create an organizational contact in the Microsoft 365 admin center
  5. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set

Correct answer: B

Why: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. It directly addresses the stated requirement.

Option review:

A: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. It directly addresses the stated requirement.

C: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q017: Add the custom domain and verify ownership with DNS – Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully.

Question 18

Datum Dynamics is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The implementation review is focused on one outcome: have newly created identities use the organization domain by default after verification. The affected scope contains 38 users across 6 administrative groups. The team does not want to redesign unrelated workloads. What is the most appropriate next step?

  1. Review license assignment errors for the affected users or groups
  2. Create an administrative unit and assign a scoped role over it
  3. Make the verified custom domain the default domain
  4. Configure the Organization profile in the Microsoft 365 admin center
  5. Review software update status in the Microsoft 365 admin center

Correct answer: C

Why: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. It directly addresses the stated requirement.

Option review:

A: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. It directly addresses the stated requirement.

D: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q018: Make the verified custom domain the default domain – After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default.

Question 19

Fabrikam Health is migrating a business process to Microsoft 365 and wants the narrowest supported solution. A production change is approved only if it can use the company public domain for Microsoft 365 identities after proving control of it. The solution should use a native Microsoft control that matches the stated requirement. The initial rollout covers 19 locations and approximately 550 managed identities or devices. Which administrative choice should be recommended?

  1. Prefer local internet egress for Microsoft 365 traffic where appropriate
  2. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  3. Create a Microsoft 365 Group for shared collaboration resources
  4. Add the custom domain and verify ownership with DNS
  5. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary

Correct answer: D

Why: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. It directly addresses the stated requirement.

E: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q019: Add the custom domain and verify ownership with DNS – Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully.

Question 20

Fabrikam Health has completed a pilot and must now choose the production administration approach. A controlled pilot must demonstrate how to update tenant-wide organization identity and profile information. The change must be repeatable and supportable after the project team leaves. The service desk has 72 related tickets from 9 business units, so the team wants a targeted fix. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set
  2. Make the privileged role eligible in Microsoft Entra PIM
  3. Open Health > Service health in the Microsoft 365 admin center
  4. Use Adoption Score for organization-level adoption insights
  5. Configure the Organization profile in the Microsoft 365 admin center

Correct answer: E

Why: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. It directly addresses the stated requirement.

Option review:

A: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. It directly addresses the stated requirement.

Learning point: MS102-T01-Q020: Configure the Organization profile in the Microsoft 365 admin center – Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties.

Question 21

Consolidated Messenger is standardizing administration after several teams used inconsistent procedures. The existing configuration works for normal operations but fails the new requirement to control tenant-level privacy or security settings exposed through Microsoft 365 organization settings. The administrator must avoid granting unrelated tenant-wide privilege. The control owner requires a review after 89 days and evidence from 22 representative cases. Which option best satisfies the requirement?

  1. Review Security & privacy organization settings
  2. Review software update status in the Microsoft 365 admin center
  3. Select the restore point that predates the damaging event
  4. Use group-based licensing
  5. Use Microsoft Purview role groups for Purview responsibilities

Correct answer: A

Why: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. It directly addresses the stated requirement.

Option review:

A: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. It directly addresses the stated requirement.

B: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q021: Review Security & privacy organization settings – Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences.

Question 22

During a tenant review at City Power & Light, the security operations analyst identifies one unresolved requirement. The service owner wants a supportable design that will update tenant-wide organization identity and profile information. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The control owner requires a review after 15 days and evidence from 12 representative cases. Which administrative choice should be recommended?

  1. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary
  2. Configure the Organization profile in the Microsoft 365 admin center
  3. Create a new Microsoft 365 tenant
  4. Review Network connectivity insights for the affected office
  5. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account

Correct answer: B

Why: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. It directly addresses the stated requirement.

Option review:

A: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. It directly addresses the stated requirement.

C: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Network connectivity insights correlate Microsoft 365 connectivity measurements with locations and recommendations, helping isolate network design issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q022: Configure the Organization profile in the Microsoft 365 admin center – Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties.

Question 23

An incident review at Blue Yonder Airlines produces a single administrative requirement for the messaging administrator. An internal assessment finds the control technically functional but unable to control tenant-level privacy or security settings exposed through Microsoft 365 organization settings. The affected scope contains 32 users across 2 administrative groups. The team must preserve a clear audit trail for the administrative decision. Which approach most directly addresses the requirement?

  1. Use Adoption Score for organization-level adoption insights
  2. Invite the partner as an external guest user
  3. Review Security & privacy organization settings
  4. Use Microsoft Graph PowerShell for scripted bulk user changes
  5. Scope the delegated administrator to the administrative unit instead of the tenant

Correct answer: C

Why: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. It directly addresses the stated requirement.

Option review:

A: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. It directly addresses the stated requirement.

D: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q023: Review Security & privacy organization settings – Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences.

Question 24

Lucerne Publishing has completed a pilot and must now choose the production administration approach. Before the tenant expands to another business unit, the administrator must update tenant-wide organization identity and profile information. The team will validate the change with 15 pilot groups before expanding it to 49 users. The administrator must avoid granting unrelated tenant-wide privilege. What should the administrator configure first?

  1. Use Microsoft Purview role groups for Purview responsibilities
  2. Add the custom domain and verify ownership with DNS
  3. Use Microsoft 365 admin center update management to configure the update approach
  4. Configure the Organization profile in the Microsoft 365 admin center
  5. Verify the workload is protected before relying on Microsoft 365 Backup recovery

Correct answer: D

Why: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. It directly addresses the stated requirement.

Option review:

A: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. It directly addresses the stated requirement.

E: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q024: Configure the Organization profile in the Microsoft 365 admin center – Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties.

Question 25

Wide World Importers is preparing a change requested by the compliance administrator. The service owner wants a supportable design that will control tenant-level privacy or security settings exposed through Microsoft 365 organization settings. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The service desk has 66 related tickets from 5 business units, so the team wants a targeted fix. Which option best satisfies the requirement?

  1. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  2. Edit the Microsoft 365 contact instead of creating a licensed user
  3. Assign the least-privileged built-in Microsoft Entra role
  4. Require approval or MFA for PIM role activation
  5. Review Security & privacy organization settings

Correct answer: E

Why: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. It directly addresses the stated requirement.

Learning point: MS102-T01-Q025: Review Security & privacy organization settings – Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences.

Question 26

The messaging administrator at Contoso Retail is designing the next phase of the Microsoft 365 rollout. An internal assessment finds the control technically functional but unable to update tenant-wide organization identity and profile information. The affected scope contains 83 users across 18 administrative groups. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which approach most directly addresses the requirement?

  1. Configure the Organization profile in the Microsoft 365 admin center
  2. Scope the delegated administrator to the administrative unit instead of the tenant
  3. Review Security & privacy organization settings
  4. Use Microsoft 365 usage reports
  5. Create a member user in Microsoft Entra ID

Correct answer: A

Why: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. It directly addresses the stated requirement.

Option review:

A: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. It directly addresses the stated requirement.

B: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q026: Configure the Organization profile in the Microsoft 365 admin center – Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties.

Question 27

Adventure Works is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The project board will approve the next step only if it can control tenant-level privacy or security settings exposed through Microsoft 365 organization settings. The control owner requires a review after 9 days and evidence from 8 representative cases. The architecture board will reject a choice that solves a different problem from the one stated. What is the most appropriate next step?

  1. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  2. Review Security & privacy organization settings
  3. Create and manage a shared mailbox
  4. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  5. Use a tenant administrator account for initial setup

Correct answer: B

Why: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. It directly addresses the stated requirement.

Option review:

A: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. It directly addresses the stated requirement.

C: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q027: Review Security & privacy organization settings – Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences.

Question 28

The operations team at Graphic Design Institute needs to resolve an issue without granting broader permissions than necessary. The implementation review is focused on one outcome: update tenant-wide organization identity and profile information. The initial rollout covers 21 locations and approximately 260 managed identities or devices. The team does not want to redesign unrelated workloads. What should the administrator configure first?

  1. Require approval or MFA for PIM role activation
  2. Configure Service health notifications
  3. Configure the Organization profile in the Microsoft 365 admin center
  4. Create a Microsoft 365 Backup protection policy
  5. Create an organizational contact in the Microsoft 365 admin center

Correct answer: C

Why: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. It directly addresses the stated requirement.

Option review:

A: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. It directly addresses the stated requirement.

D: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T01-Q028: Configure the Organization profile in the Microsoft 365 admin center – Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties.

Popular posts

img