Step2Study
IT & TechnologyMS-102100% Free

Microsoft 365 Certified: Administrator Expert

Practice bank
217 Qs
Real exam
50 Qs
Time limit
120 min
Passing
300 out of 1000

Exam blueprint

Deploy and manage a Microsoft 365 tenant
25%
Implement and manage Microsoft Entra ID
25%
Implement and manage Microsoft Defender XDR
25%
Implement and manage Microsoft Purview compliance
25%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 216 min · pass 70% · 217 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Microsoft 365 Certified: Administrator Expert practice test questions

Sample questions from the 217-question bank, with answers and explanations.

All questions
  1. 1. A Microsoft 365 administrator is setting up a new Microsoft 365 tenant. The organization requires that all new user accounts created for employees automatically include their department name in the user principal name (UPN) and email address, following the format 'firstname.lastname@department.contoso.com'. Additionally, these users should also be members of an Azure AD security group corresponding to their department. Which combination of features should the administrator leverage to automate this user provisioning and management?

    Deploy and manage a Microsoft 365 tenant

    • A. Azure AD Dynamic Groups and a custom PowerShell script for UPN/email generation.
    • B. Azure AD Connect for UPN sync and manual group assignment.
    • C. Microsoft 365 Group naming policy and manual UPN/email configuration.
    • D. Azure AD User Provisioning (HR to Azure AD) and Azure AD Dynamic Groups.
    Show answer

    D. Azure AD User Provisioning (HR to Azure AD) and Azure AD Dynamic Groups.

    Azure AD User Provisioning (specifically HR-driven provisioning) can automate the creation of user accounts from an HR system, including generating UPNs and email addresses based on attributes. Azure AD Dynamic Groups can then automatically add these users to department-specific security groups based on their department attribute, fulfilling all requirements for automation.

  2. 2. A company is planning to deploy Microsoft 365 and wants to ensure that all user data, including email, documents, and chat messages, remains within a specific geographic region (e.g., Europe) to comply with data residency regulations. Which Microsoft 365 feature is designed to address this requirement for data at rest?

    Deploy and manage a Microsoft 365 tenant

    • A. Microsoft 365 Multi-Geo Capabilities
    • B. Microsoft 365 Customer Lockbox
    • C. Azure Information Protection (AIP)
    • D. Microsoft Defender for Cloud Apps
    Show answer

    A. Microsoft 365 Multi-Geo Capabilities

    Microsoft 365 Multi-Geo Capabilities allow an organization to provision and store data at rest in specified geographic locations (data regions) for Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams, thereby addressing data residency requirements.

  3. 3. A company is implementing Microsoft Entra Identity Protection to enhance security. They want to automatically block sign-ins from IP addresses that are detected as malicious. Additionally, for users signing in from 'risky' locations (e.g., unusual travel), they want to enforce multi-factor authentication (MFA). Which type of policy in Microsoft Entra Identity Protection should be configured to achieve these outcomes?

    Implement and manage Microsoft Entra ID

    • A. Sign-in risk policy
    • B. MFA registration policy
    • C. User risk policy
    • D. Conditional Access policy
    Show answer

    A. Sign-in risk policy

    A Microsoft Entra Identity Protection Sign-in risk policy evaluates the risk associated with a sign-in attempt in real-time. It can be configured to block access for high-risk sign-ins (e.g., from malicious IPs) and require MFA for medium-risk sign-ins (e.g., from unusual locations).

  4. 4. A Microsoft 365 administrator is setting up a new tenant for a company that frequently collaborates with external partners. The company wants to allow external users to access specific SharePoint Online sites and Microsoft Teams channels, but they need to ensure that these external users are only granted access for a limited time and must re-request access after expiration. Which Azure AD feature should the administrator configure to manage this requirement?

    Deploy and manage a Microsoft 365 tenant

    • A. Azure AD Dynamic Groups
    • B. Azure AD Entitlement Management
    • C. Azure AD Privileged Identity Management (PIM)
    • D. Azure AD External Identities (B2B collaboration)
    Show answer

    B. Azure AD Entitlement Management

    Azure AD Entitlement Management allows organizations to manage identity and access lifecycle at scale, including creating access packages that bundle resources and include settings for access expiration and recurring access reviews for external users. This directly addresses the requirement for time-limited access and re-requesting access.

  5. 5. A company is planning to implement Microsoft Entra ID for identity management. They have an existing on-premises Active Directory Domain Services (AD DS) environment. The security team insists that user passwords must *never* leave the on-premises network and that users should authenticate directly against the on-premises AD DS. Which Microsoft Entra Connect authentication method should you recommend?

    Implement and manage Microsoft Entra ID

    • A. Cloud Kerberos Trust
    • B. Pass-through Authentication (PTA)
    • C. Federation with AD FS
    • D. Password Hash Synchronization (PHS)
    Show answer

    B. Pass-through Authentication (PTA)

    Pass-through Authentication (PTA) is the correct choice because it allows users to authenticate against their on-premises Active Directory directly, ensuring that passwords never leave the on-premises network. This fulfills the security team's requirement.

  6. 6. A company is implementing Microsoft Entra Connect. They have a single on-premises Active Directory forest with 10,000 user accounts. However, due to compliance regulations, only users located in the 'Sales' and 'Marketing' departments should be synchronized to Microsoft Entra ID. All other users, including service accounts and administrative accounts, must remain on-premises and not be replicated to the cloud. You need to configure Microsoft Entra Connect to meet this requirement. Which filtering method should you use?

    Implement and manage Microsoft Entra ID

    • A. Organizational Unit (OU) filtering
    • B. Domain-based filtering
    • C. Attribute-based filtering
    • D. Group-based filtering
    Show answer

    C. Attribute-based filtering

    To synchronize only users from specific departments ('Sales' and 'Marketing') while excluding all others, attribute-based filtering is the most precise method. You can filter based on an attribute like 'department' to include only the desired users.

  7. 7. A company is migrating its on-premises user accounts to Microsoft 365. The security team mandates that all user identities must be managed centrally from the on-premises Active Directory and that users should experience a single sign-on experience when accessing Microsoft 365 services. Which synchronization method should be implemented to meet these requirements?

    Deploy and manage a Microsoft 365 tenant

    • A. Pass-through Authentication (PTA)
    • B. Cloud-only identities
    • C. Federation with Active Directory Federation Services (AD FS)
    • D. Password Hash Synchronization (PHS)
    Show answer

    C. Federation with Active Directory Federation Services (AD FS)

    Federation with AD FS allows for centralized identity management on-premises and provides a true single sign-on experience where authentication requests are redirected to the on-premises AD FS server. This meets the security team's mandate for central management and single sign-on.

  8. 8. A Microsoft 365 administrator is configuring a new tenant and needs to set up a group that automatically includes all users from the 'Sales' department whose 'City' attribute is set to 'New York'. The group should update its membership dynamically as user attributes change. Which type of group should the administrator create in Azure AD to meet these requirements?

    Deploy and manage a Microsoft 365 tenant

    • A. Dynamic user group
    • B. Microsoft 365 group
    • C. Mail-enabled security group
    • D. Static security group
    Show answer

    A. Dynamic user group

    A dynamic user group in Azure AD allows membership to be automatically managed based on user attributes defined by a rule. This directly fulfills the requirement for a group that includes users based on their 'Department' and 'City' attributes and dynamically updates membership.

  9. 9. A company is implementing Microsoft Entra ID governance. They want to ensure that all new users are automatically assigned to appropriate groups and have the necessary licenses based on their department. This assignment should be dynamic and update automatically if a user's department changes. Which Microsoft Entra ID governance feature should you use?

    Implement and manage Microsoft Entra ID

    • A. Access reviews
    • B. Terms of use
    • C. Entitlement management
    • D. Privileged Identity Management (PIM)
    Show answer

    C. Entitlement management

    Entitlement management allows you to manage identity and access lifecycle at scale by creating access packages. These packages can automatically assign users to groups and apply licenses based on rules, including dynamic updates when user attributes (like department) change.

  10. 10. A Microsoft 365 administrator needs to integrate security alerts and raw event data from Microsoft Defender XDR with an external Security Information and Event Management (SIEM) system for centralized logging and long-term retention. The integration must provide a continuous, real-time stream of all available security data. Which Defender XDR feature should the administrator configure for this purpose?

    Implement and manage Microsoft Defender XDR

    • A. Streaming API for raw data
    • B. API for custom detections
    • C. Microsoft Graph Security API
    • D. Alerts API
    Show answer

    A. Streaming API for raw data

    The Streaming API in Microsoft Defender XDR (formerly Defender for Endpoint) is specifically designed to stream raw event data and alerts to external systems like SIEMs or Azure Storage. It provides a continuous, real-time feed of all available security data, which is essential for centralized logging and long-term retention requirements.

  11. 11. A consultant is assisting a small business with implementing Microsoft Entra Connect. The business has a single on-premises Active Directory domain, 'contoso.local', with approximately 300 user objects. They prefer a solution that requires minimal infrastructure, is resilient, and can be deployed quickly without significant changes to their network. They are also concerned about high availability of the synchronization service. Which Microsoft Entra Connect deployment option would best fit these requirements?

    Implement and manage Microsoft Entra ID

    • A. Microsoft Entra Connect with Federation (AD FS)
    • B. Microsoft Entra Connect with Password Hash Synchronization (PHS)
    • C. Microsoft Entra Connect with Pass-through Authentication (PTA)
    • D. Microsoft Entra Connect Cloud Sync
    Show answer

    D. Microsoft Entra Connect Cloud Sync

    Microsoft Entra Connect Cloud Sync is ideal for small businesses with single domains, offering minimal infrastructure requirements (lightweight agents), high resilience (agents are self-updating and Microsoft manages the service), and quick deployment. It inherently supports high availability through multiple agents.

  12. 12. A company is planning to implement Microsoft Entra Connect Cloud Sync to synchronize users from a single on-premises Active Directory Domain Services (AD DS) domain. They have identified several Organizational Units (OUs) within this domain that contain legacy user accounts and service accounts that should *not* be synchronized to Microsoft Entra ID. You need to ensure that only specific OUs are synchronized. How should you configure Cloud Sync to achieve this?

    Implement and manage Microsoft Entra ID

    • A. Modify the synchronization rules in Synchronization Service Manager.
    • B. Define the desired OUs directly in the Cloud Sync configuration within the Microsoft Entra admin center.
    • C. Disable the synchronization for the entire domain via PowerShell.
    • D. Configure attribute-based filtering for each user in the OUs.
    Show answer

    B. Define the desired OUs directly in the Cloud Sync configuration within the Microsoft Entra admin center.

    Microsoft Entra Connect Cloud Sync allows you to define the specific Organizational Units (OUs) to be synchronized directly within its configuration in the Microsoft Entra admin center. This is the intended and most efficient way to achieve OU filtering for Cloud Sync.

  13. 13. A Microsoft 365 administrator needs to ensure that all user accounts created in the tenant have a default usage location set to 'United States' to comply with licensing requirements for specific services. Where in the Microsoft 365 admin center can this default setting be configured?

    Deploy and manage a Microsoft 365 tenant

    • A. Users > Active users > Bulk operations
    • B. Azure Active Directory admin center > Users > User settings
    • C. Billing > Licenses > License settings
    • D. Settings > Org settings > Organization profile
    Show answer

    D. Settings > Org settings > Organization profile

    The default usage location for new users is a tenant-wide organizational setting. This can be configured under 'Settings > Org settings > Organization profile' in the Microsoft 365 admin center, specifically within the 'Data location' or 'Organization information' section, depending on the exact interface version.

  14. 14. A company is implementing Microsoft Entra Connect in a new hybrid environment. The security team has mandated that, for disaster recovery purposes, user authentication must remain functional even if the on-premises Active Directory Domain Services (AD DS) becomes temporarily unavailable. Which authentication method should you choose for Microsoft Entra Connect to meet this requirement?

    Implement and manage Microsoft Entra ID

    • A. Pass-through Authentication (PTA)
    • B. Cloud Kerberos Trust
    • C. Password Hash Synchronization (PHS)
    • D. Federation with AD FS
    Show answer

    C. Password Hash Synchronization (PHS)

    Password Hash Synchronization (PHS) is the only authentication method that allows users to authenticate directly against Microsoft Entra ID even if on-premises AD DS is unavailable. This is because a hash of their password is synchronized and stored in Microsoft Entra ID.

  15. 15. A company is using Microsoft 365 and has several departments, each with its own set of SharePoint sites and Microsoft Teams. The IT department wants to create a new administrator role that can manage SharePoint site collections and Teams settings ONLY for the Sales department, without affecting other departments. Which type of administrative unit should be created to delegate this specific scope of administration?

    Deploy and manage a Microsoft 365 tenant

    • A. Administrative unit
    • B. Microsoft 365 group
    • C. Security group
    • D. Distribution group
    Show answer

    A. Administrative unit

    Administrative units (AUs) in Azure AD allow administrators to define a more granular scope of administrative control over users, groups, and devices. By creating an AU for the Sales department and adding relevant users, groups, and devices to it, an administrator can be delegated permissions to manage only those resources within that AU, achieving the required departmental scope.

  16. 16. A Microsoft 365 administrator is configuring a new tenant and needs to ensure that all user accounts created in the tenant are assigned a default usage location. This is critical for compliance with regional service availability and feature enablement. Which setting in Azure AD should the administrator configure to achieve this?

    Deploy and manage a Microsoft 365 tenant

    • A. Set the default preferred data location for the tenant.
    • B. Configure an Azure AD Conditional Access policy.
    • C. Set the default usage location in Azure AD User settings.
    • D. Implement a custom role-based access control (RBAC) role.
    Show answer

    C. Set the default usage location in Azure AD User settings.

    The default usage location for new users can be configured in Azure AD user settings. This ensures that every new user account is automatically assigned a usage location, which is a mandatory property for services like Exchange Online and for determining feature availability based on regional regulations.

  17. 17. A Microsoft 365 administrator needs to assign a custom domain, 'contoso.com', to their tenant. After adding the domain in the Microsoft 365 admin center, the system prompts the administrator to add a specific DNS record to verify ownership. Which type of DNS record is typically used for domain ownership verification during the initial setup of a custom domain in Microsoft 365?

    Deploy and manage a Microsoft 365 tenant

    • A. A record
    • B. TXT record
    • C. SRV record
    • D. MX record
    Show answer

    B. TXT record

    Microsoft 365 uses a TXT record for domain ownership verification. This record, which contains a unique string provided by Microsoft, needs to be added to the domain's DNS zone to prove that you own the domain before it can be fully configured in Microsoft 365.

  18. 18. An organization is setting up Microsoft Entra Connect to synchronize identities from its on-premises Active Directory to Microsoft Entra ID. They have several Organizational Units (OUs) that contain service accounts and disabled user accounts which should NOT be synchronized to Microsoft Entra ID to reduce clutter and improve security. Which feature of Microsoft Entra Connect should be configured to exclude these specific OUs?

    Implement and manage Microsoft Entra ID

    • A. Domain filtering
    • B. Attribute filtering
    • C. Group-based filtering
    • D. Organizational Unit (OU) filtering
    Show answer

    D. Organizational Unit (OU) filtering

    Organizational Unit (OU) filtering in Microsoft Entra Connect allows administrators to specify which OUs from the on-premises Active Directory should be synchronized to Microsoft Entra ID, effectively excluding unwanted OUs.

  19. 19. A company is performing a phased rollout of Microsoft Entra Connect. They have installed the Microsoft Entra Connect software on a secondary server in their data center but do not want it to actively synchronize any changes to Microsoft Entra ID yet. They need to thoroughly test the synchronization rules and verify the impact of the configuration before enabling full synchronization. Which operational mode should the secondary Microsoft Entra Connect server be configured in?

    Implement and manage Microsoft Entra ID

    • A. Passthrough mode
    • B. Failover mode
    • C. Disabled mode
    • D. Staging mode
    Show answer

    D. Staging mode

    Staging mode in Microsoft Entra Connect allows an instance to perform the full synchronization process (import, synchronize) but prevents it from exporting any changes to Microsoft Entra ID. This enables testing of configuration, troubleshooting, and preparing for a cutover without affecting the production environment.

  20. 20. A Microsoft 365 administrator is performing an advanced hunting query in Microsoft Defender XDR to investigate a potential data exfiltration incident. The analyst needs to identify all files that were accessed by a specific user account (UserA) on a particular device (DeviceX) within the last 24 hours and were subsequently uploaded to a cloud storage application. The query must correlate file access events with cloud application upload activities. Which KQL operator should the analyst use to combine these two distinct data sets effectively?

    Implement and manage Microsoft Defender XDR

    • A. join
    • B. summarize
    • C. parse
    • D. union
    Show answer

    A. join

    The 'join' operator in KQL is used to combine rows from two or more tables based on a common column. In this scenario, the analyst needs to correlate 'file access events' (likely from DeviceFileEvents) with 'cloud application upload activities' (likely from CloudAppEvents), which contain distinct but related information (e.g., file hash, device ID, user ID). The join operator is essential for linking these two datasets to identify the full sequence of events.

  21. 21. A company has recently acquired another organization. Both companies use Microsoft Entra ID. You need to enable seamless collaboration and resource sharing between users from both organizations without creating duplicate user accounts or synchronizing user data. Which Microsoft Entra ID feature should you implement?

    Implement and manage Microsoft Entra ID

    • A. Microsoft Entra Connect Sync
    • B. Microsoft Entra B2C collaboration
    • C. Microsoft Entra B2B collaboration
    • D. Microsoft Entra Connect Cloud Sync
    Show answer

    C. Microsoft Entra B2B collaboration

    Microsoft Entra B2B collaboration allows external users (guest users) from another Entra ID tenant to access resources in your tenant without creating duplicate accounts or synchronizing their full identity data.

  22. 22. A Microsoft 365 administrator is configuring email routing for a new custom domain, 'example.com', which will be used for all user mailboxes in Exchange Online. After adding and verifying the domain, the administrator needs to ensure that all incoming emails for 'example.com' are correctly delivered to the Exchange Online mailboxes. Which type of DNS record must be configured for email to flow correctly to Exchange Online?

    Deploy and manage a Microsoft 365 tenant

    • A. A record
    • B. MX record
    • C. CNAME record
    • D. SRV record
    Show answer

    B. MX record

    The MX (Mail Exchanger) record is a critical DNS record type that specifies the mail servers responsible for accepting email messages on behalf of a domain name. For Exchange Online, the MX record must point to the Microsoft 365 mail servers to ensure proper email delivery.

  23. 23. A Microsoft 365 tenant administrator is reviewing the tenant's service health. They notice several advisories indicating degraded performance for Exchange Online in their region. Where is the most authoritative and up-to-date information regarding the status of Microsoft 365 services, including any ongoing incidents or planned maintenance, typically found?

    Deploy and manage a Microsoft 365 tenant

    • A. Microsoft Support website public page
    • B. Azure portal > Service Health
    • C. Microsoft Tech Community forums
    • D. Microsoft 365 admin center > Health > Service health
    Show answer

    D. Microsoft 365 admin center > Health > Service health

    The Microsoft 365 admin center's Service health dashboard provides the most accurate and real-time information about the status of Microsoft 365 services specific to your tenant, including incidents, advisories, and planned maintenance.

  24. 24. A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint for a new set of Windows 11 client devices. The organization has a strict security posture that requires limiting the execution of unsigned scripts and potentially malicious macros in Office applications. The administrator wants to implement a proactive defense mechanism that blocks these types of activities without relying solely on signature-based detection. Which Defender for Endpoint capability should be used to achieve this goal?

    Implement and manage Microsoft Defender XDR

    • A. Next-generation protection
    • B. Attack Surface Reduction (ASR) rules
    • C. Endpoint detection and response (EDR)
    • D. Automated investigation and remediation
    Show answer

    B. Attack Surface Reduction (ASR) rules

    Attack Surface Reduction (ASR) rules are designed to prevent actions and apps commonly used by malware to exploit devices and data. Specifically, ASR rules can block unsigned scripts, disable malicious macros, and prevent other risky behaviors, providing a proactive defense mechanism against exploits and fileless attacks.

  25. 25. A Microsoft 365 administrator is notified that users in a specific department are experiencing slow loading times and intermittent disconnections when accessing Microsoft Teams and SharePoint Online. Other departments are not reporting similar issues. The administrator suspects a network performance problem. Which dashboard or tool should the administrator use to investigate this issue?

    Deploy and manage a Microsoft 365 tenant

    • A. Microsoft 365 Service Health dashboard
    • B. Microsoft Purview compliance portal
    • C. Azure AD sign-in logs
    • D. Microsoft 365 Network Connectivity Performance dashboard
    Show answer

    D. Microsoft 365 Network Connectivity Performance dashboard

    The Microsoft 365 Network Connectivity Performance dashboard provides insights into network performance from user locations to Microsoft 365 services, helping identify and troubleshoot issues like slow loading times and disconnections.

Microsoft 365 Certified: Administrator Expert flashcards

Tap a card to flip it. 145 flashcards in the full deck.

  • Azure AD HR-Driven User Provisioning & Dynamic Groups

    Flip card

    A combined solution where Azure AD automates user account creation and attribute population from an HR system, and Dynamic Groups automatically manage group memberships based on user attributes.

    • Automates user lifecycle from hire to retire.
    • Generates UPNs and email addresses using attribute-based expressions.
    • Dynamic Groups ensure users are automatically added/removed from relevant groups.
    Study this card →
  • Microsoft 365 Multi-Geo

    Flip card

    A Microsoft 365 feature that enables organizations to store user data at rest in specified geographic locations (geos) to meet data residency requirements.

    • Requires an Enterprise Agreement and specific license types (e.g., E3, E5).
    • Applies to Exchange Online, SharePoint Online, OneDrive, and Teams.
    • Administrators can assign users to a preferred data location (PDL).
    Study this card →
  • Microsoft Entra Identity Protection Sign-in Risk Policy

    Flip card

    A Microsoft Entra Identity Protection Sign-in risk policy automatically detects and responds to real-time sign-in risks. It can enforce actions such as blocking access or requiring multi-factor authentication (MFA) based on the risk level associated with a user's sign-in attempt.

    • Evaluates risk of individual sign-in attempts.
    • Actions include block access or require MFA.
    • Works with Microsoft Entra Conditional Access.
    Study this card →
  • Azure AD Entitlement Management

    Flip card

    An identity governance feature in Azure AD that enables organizations to manage identity and access lifecycle at scale by automating access requests, approvals, access reviews, and expiration.

    • Automates access to groups, applications, and SharePoint sites.
    • Supports both internal and external users (B2B collaboration).
    • Allows defining access packages with expiration dates and periodic access reviews.
    Study this card →
  • Pass-through Authentication (PTA)

    Flip card

    A Microsoft Entra Connect authentication method where user sign-in requests are redirected to an agent running on an on-premises server, which validates the password directly against Active Directory.

    • Passwords never leave the on-premises network.
    • Requires one or more lightweight agents on-premises.
    • Provides a seamless sign-in experience for users.
    Study this card →
  • Microsoft Entra Connect Attribute Filtering

    Flip card

    A filtering method in Microsoft Entra Connect that allows administrators to define which objects synchronize to Microsoft Entra ID based on the values of their attributes.

    • Provides granular control over synchronization.
    • Can be used to include or exclude objects based on specific attribute values.
    • Configured using the Synchronization Rules Editor.
    Study this card →
  • Federated Identity

    Flip card

    A system where a user's identity and authentication are managed by one system (identity provider) but trusted by another system (service provider) to grant access.

    • Enables single sign-on across multiple services.
    • Requires an identity provider (e.g., AD FS) to handle authentication.
    • Provides centralized control over authentication policies.
    Study this card →
  • Azure AD Dynamic Groups

    Flip card

    Azure AD groups (security or Microsoft 365) whose membership is automatically updated based on predefined rules that query user or device attributes.

    • Requires an Azure AD Premium P1 or P2 license.
    • Supports dynamic membership for users or devices.
    • Simplifies group management for large and frequently changing organizations.
    Study this card →
  • Microsoft Entra Entitlement Management

    Flip card

    An identity governance feature that enables organizations to manage identity and access lifecycle at scale, automating access requests, approvals, provisioning, and de-provisioning.

    • Uses 'access packages' to bundle resources (groups, applications, SharePoint sites).
    • Supports automatic assignment and removal of access based on user attributes.
    • Streamlines onboarding, offboarding, and internal transfers.
    Study this card →
  • Defender XDR Streaming API

    Flip card

    The Microsoft Defender XDR Streaming API enables continuous, real-time export of raw event data and alerts to Azure Storage, Azure Event Hubs, or a SIEM, facilitating centralized logging, long-term retention, and custom analytics.

    • Exports raw event data and security alerts.
    • Provides a continuous, real-time stream.
    • Integrates with SIEMs, Azure Storage, Event Hubs.
    Study this card →
  • Microsoft Entra Connect Cloud Sync

    Flip card

    Microsoft Entra Connect Cloud Sync is a lightweight Microsoft Entra Connect agent-based service that synchronizes users, groups, and contacts from on-premises Active Directory to Microsoft Entra ID. It's designed for hybrid identity scenarios with simpler requirements, minimal infrastructure, and high resilience.

    • Lightweight agents, cloud-managed.
    • Good for multi-forest, disconnected forests, or small environments.
    • Supports high availability with multiple agents.
    Study this card →
  • Cloud Sync Domain and OU Filtering

    Flip card

    In Microsoft Entra Connect Cloud Sync, filtering allows administrators to explicitly define which domains and Organizational Units (OUs) from on-premises Active Directory are synchronized to Microsoft Entra ID.

    • Configured directly in the Microsoft Entra admin center.
    • Supports both domain-level and OU-level filtering.
    • Essential for controlling the scope of synchronized objects.
    Study this card →
  • Usage Location

    Flip card

    A mandatory user property in Microsoft 365 that determines the country/region where the user is located, impacting licensing and service availability.

    • Required for assigning most Microsoft 365 licenses.
    • Affects data residency and compliance for some services.
    • Can be set per user or as a default for the organization.
    Study this card →
  • Password Hash Synchronization (PHS)

    Flip card

    A Microsoft Entra Connect authentication method where a cryptographic hash of a user's password hash is synchronized from on-premises Active Directory to Microsoft Entra ID.

    • Provides a cloud-only authentication experience.
    • Allows users to sign in even if on-premises AD DS is unavailable.
    • Simplest to deploy and manage among hybrid authentication methods.
    Study this card →
  • Azure AD Administrative Units

    Flip card

    An Azure AD Premium feature that allows the creation of logical containers to group users, groups, or devices, enabling granular delegation of administrative roles to specific scopes.

    • Requires Azure AD Premium P1 or P2 license.
    • Used to delegate administrative permissions to a subset of the organization.
    • Supports delegation for roles like User Administrator, Group Administrator, Helpdesk Administrator.
    Study this card →
  • Azure AD Default Usage Location

    Flip card

    A configuration in Azure AD that sets a default country/region for new user accounts, which is essential for license assignment, service availability, and compliance with regional regulations.

    • Mandatory property for assigning licenses to users.
    • Impacts service availability and feature enablement.
    • Can be set globally for the tenant in Azure AD user settings.
    Study this card →
  • DNS TXT Record for Domain Verification

    Flip card

    A type of DNS record containing text information, used by services like Microsoft 365 to verify ownership of a domain by requiring the domain owner to publish a specific string.

    • Contains a unique string provided by Microsoft 365.
    • Must be added to the domain's public DNS zone.
    • Temporary for verification, though often left in place.
    Study this card →
  • Microsoft Entra Connect OU Filtering

    Flip card

    Microsoft Entra Connect Organizational Unit (OU) filtering allows administrators to select specific OUs within their on-premises Active Directory that should be synchronized to Microsoft Entra ID. This is used to control which objects are provisioned to the cloud.

    • Prevents unwanted objects from syncing.
    • Configured during or after Microsoft Entra Connect installation.
    • Reduces cloud clutter and improves security.
    Study this card →
  • Microsoft Entra Connect Staging Mode

    Flip card

    Microsoft Entra Connect Staging mode allows a second Microsoft Entra Connect server to be installed and configured in parallel with an active server. It performs full synchronization cycles (import and synchronize) but does not export any changes to Microsoft Entra ID, making it ideal for testing, disaster recovery, and configuration validation.

    • Performs full sync but no export.
    • Used for testing, DR, and configuration validation.
    • Can be easily promoted to active server.
    Study this card →
  • KQL 'join' operator

    Flip card

    The Kusto Query Language (KQL) 'join' operator merges rows from two tables by matching values from specified columns in each table, allowing for correlation of distinct but related events across different data sources.

    • Combines rows from two or more tables.
    • Requires a common column (or columns) between tables.
    • Essential for correlating events across different data types (e.g., device events and cloud app events).
    Study this card →
  • Microsoft Entra B2B Collaboration

    Flip card

    A feature in Microsoft Entra ID that enables external users to access your organization's applications and resources without creating a new local account.

    • Users authenticate with their home directory credentials.
    • Guest user accounts are created in your tenant, linked to their original identity.
    • Facilitates secure collaboration with partners, customers, and vendors.
    Study this card →
  • DNS MX Record for Email Routing

    Flip card

    A DNS record that specifies the mail servers responsible for receiving email messages on behalf of a domain name, essential for directing email to the correct mailboxes in Exchange Online.

    • Mandatory for incoming email delivery.
    • Must point to the Microsoft 365 mail servers (e.g., example-com.mail.protection.outlook.com).
    • Can have a priority value to specify preferred mail servers.
    Study this card →
  • Microsoft 365 Service Health

    Flip card

    A dedicated dashboard within the Microsoft 365 admin center that provides real-time information on the status and health of Microsoft 365 services relevant to a specific tenant.

    • Shows active incidents, advisories, and planned maintenance.
    • Provides tenant-specific impact details.
    • Accessible only to administrators with appropriate roles.
    Study this card →
  • Defender for Endpoint Attack Surface Reduction (ASR) Rules

    Flip card

    Attack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint target common attack vectors and prevent behaviors often used by malware, such as blocking unsigned scripts, disabling malicious macros, and preventing execution of suspicious processes.

    • Prevents common malware behaviors and exploits.
    • Blocks unsigned scripts and malicious macros.
    • Reduces the attack surface of devices.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.