---
title: "MS-102 Study Guide — Microsoft 365 Administrator"
description: "An interactive study guide built on 7 memory techniques to help you pass the Microsoft 365 Administrator (MS-102) exam — note: this exam retires in October 2026 as Microsoft restructures the M365 Administrator Expert path, so confirm the current requirements on Microsoft Learn before you book."
url: "https://lucidlabs.com.au/insights/ms-102"
---

# Master the MS-102

An interactive study guide built on 7 memory techniques to help you pass the Microsoft 365 Administrator (MS-102) exam — note: this exam retires in October 2026 as Microsoft restructures the M365 Administrator Expert path, so confirm the current requirements on Microsoft Learn before you book.

Deploy & Manage Tenant 10-15%Entra Identity & Access 25-30%Defender XDR Security 35-40%Purview Compliance 15-20%

What it covers

Microsoft 365 tenant setup (org profile, domains, subscriptions, licensing, admin roles); Microsoft Entra ID hybrid identity (Entra Connect, Connect Cloud Sync, authentication methods, Conditional Access, PIM); the Microsoft Defender XDR suite (Defender for Office 365, Defender for Endpoint, Defender for Cloud Apps, Secure Score, unified incidents); and Microsoft Purview compliance (retention, sensitivity labels, DLP, insider risk, eDiscovery).

Ideal for

Microsoft 365 administrators, IT generalists, and helpdesk-to-admin career movers responsible for tenant-level implementation and administration of a Microsoft 365 environment.

Aspire to this if

You're the person who gets called when a mailbox won’t sync, a phishing email slips through, or legal needs an eDiscovery hold — and you want the breadth to own the whole M365 tenant, not just one workload.

Section 1 / Spatial Memory

## The Map

Tap any component to see what you need to know for the exam.

**🏢 Tenant & Org Profile**

Domains · Subscriptions · Multi-Geo

**👤 Roles & RBAC**

Admin Roles · GDAP · Admin Units

**🔗 Hybrid Identity**

Entra Connect · Cloud Sync

**🔑 Authentication Methods**

PHS · PTA · Federation · SSPR

**🛡️ Access Governance**

Conditional Access · PIM

**📧 Defender for Office 365**

Safe Links · Safe Attachments

**💻 Defender for Endpoint**

EDR · ASR · Onboarding

**☁️ Defender for Cloud Apps**

Cloud Discovery · OAuth

**🎯 Secure Score & Incidents**

XDR · Hunting · Disruption

**🗂️ Data Governance & Retention**

Policies · Labels · Records

**🚫 DLP & Sensitivity Labels**

Classify · Protect · Prevent

**🕵️ Insider Risk & eDiscovery**

Investigate · Hold · Audit

Section 2 / Narrative Memory

## The Story

Follow the narrative to build a mental model of how everything connects.

🏢

### Standing Up the Tenant

Every M365 deployment starts with the tenant: an org profile, a default onmicrosoft.com domain, and whatever custom domains the business actually sends mail from. Before a single user is created, you’re verifying DNS records, deciding where data lives geographically, and assigning the subscriptions that unlock everything else.

**Exam Intel**Org profile lives in admin centre > Settings > Org settings. Custom domains verified via DNS TXT/MX record. Multi-Geo stores specific users’ data in a chosen region. Group-based licensing assigns SKUs via Entra ID security groups.

👤

### Who Gets the Keys

Handing every admin Global Administrator is the fastest way to fail an audit. MS-102 tests whether you know the narrower roles — User Administrator, Exchange Administrator — and the scoping tools that keep access tight: administrative units for internal delegation, GDAP for external partners.

**Exam Intel**Least privilege: pick the most specific built-in role. Administrative units scope a role to a subset of users/groups/devices. GDAP gives partners scoped, time-bound access instead of standing admin rights.

🔗

### Bridging On-Prem and Cloud

Most real organisations aren’t cloud-only — they have an on-premises Active Directory that needs to sync. Entra Connect is the full-featured, server-based sync engine. Entra Connect Cloud Sync is its lighter, cloud-managed sibling: no dedicated server, and it natively handles multiple AD forests.

**Exam Intel**Entra Connect = full sync engine, complex rules, single forest focus. Cloud Sync = lightweight agents, multi-forest native, simpler topology. Staged rollout pilots cloud auth for a test group before full cutover.

🔑

### Three Ways In

Once directories are linked, you choose how users actually authenticate. Password Hash Sync keeps things resilient — the cloud can validate sign-ins even if on-prem goes down. Pass-through Authentication keeps password hashes on-premises entirely. Federation hands the job to AD FS for legacy or highly regulated scenarios.

**Exam Intel**PHS = hash of hash synced to cloud, resilient to on-prem outage. PTA = validates against on-prem AD live, no hash leaves the network. Federation = AD FS, most complex. SSPR + MFA close the loop on self-service and verification.

🛡️

### Access on Your Terms

Authentication answers "who are you?" — access governance answers "should you get in, right now, from there, on that device?" Conditional Access evaluates signals in real time. PIM makes sure even trusted admins only hold powerful roles for as long as the task takes.

**Exam Intel**Conditional Access = if-this-then-that policies on user/location/device/risk. Identity Protection feeds risk signals into risk-based CA. PIM = just-in-time role activation with approval. Access reviews recertify who still needs access.

📧

### The Inbox Is the Front Line

Email remains the single biggest attack surface, which is why Defender for Office 365 gets a dedicated toolkit. Safe Links checks a URL again the moment someone clicks it — not just when the email arrives. Safe Attachments detonates files in a sandbox before they ever reach an inbox.

**Exam Intel**Safe Links = time-of-click URL rewriting. Safe Attachments = sandbox detonation before delivery (Plan 1/2). Anti-phishing = impersonation + spoof intelligence + mailbox intelligence. Attack simulation training measures user resilience.

💻

### Defending the Device

Phishing that gets through is only step one of an attack — the payload still has to run somewhere. Defender for Endpoint watches every onboarded device with behavioural sensors, blocks common malware techniques with attack surface reduction rules, and can automatically investigate and close out routine alerts.

**Exam Intel**Onboarding via Intune, GPO, or script. EDR = behavioural sensors + device timeline. ASR rules block known malware techniques (e.g. Office spawning child processes). AIR auto-resolves common alerts without an analyst.

☁️

### The Apps Nobody Approved

Employees connect dozens of SaaS tools to their Microsoft 365 identity that IT never signed off on. Defender for Cloud Apps discovers that shadow IT from traffic logs, reviews the OAuth permissions those apps were granted, and can throttle risky sessions in real time via Conditional Access App Control.

**Exam Intel**Cloud Discovery = shadow IT from traffic logs. OAuth app governance = review/revoke third-party app permissions. Conditional Access App Control = real-time session control (block download, read-only). Anomaly detection flags impossible travel.

🎯

### One Queue, Not Five

The whole point of "XDR" is that Office 365, Endpoint, Identity, and Cloud Apps alerts don’t stay siloed — they correlate into a single incident so an analyst sees the full attack chain. Automatic attack disruption can even isolate a compromised account mid-attack, and Secure Score keeps the org honest about its baseline posture.

**Exam Intel**Unified incident queue correlates alerts across all Defender XDR workloads. Automatic attack disruption contains active attacks in real time. Secure Score = prioritised posture recommendations. Advanced hunting = raw telemetry via KQL.

🗂️

### Nothing Lives Forever (On Purpose)

Compliance starts with deciding how long data should stick around. A retention policy blankets a whole mailbox or site with one rule. A retention label goes further — different items in the same mailbox can carry entirely different retention rules, and records management adds a formal disposition review before deletion.

**Exam Intel**Retention policy = location-level, no user action. Retention label = item-level, can be auto-applied via trainable classifiers. Records management = disposition review + regulatory records. Data Lifecycle Management = adaptive, attribute-based scopes.

🚫

### Classify, Then Prevent

Sensitivity labels and DLP policies solve two different problems that people constantly conflate. A sensitivity label classifies and protects a piece of content — encrypting it, watermarking it. A DLP policy watches actions — sharing, copying, printing — and blocks or warns when sensitive content moves somewhere it shouldn’t.

**Exam Intel**Sensitivity label = classify + protect the content itself (encryption, watermark). DLP = detect + govern actions on sensitive info types across Exchange/SharePoint/OneDrive/Teams/endpoints. Adaptive protection ties DLP strictness to a user’s insider risk score.

🕵️

### When You Need to Look Closer

Sometimes prevention isn’t enough and you need to investigate. Insider Risk Management flags a departing employee downloading unusual volumes of data. Information barriers stop two teams from talking who legally shouldn’t. eDiscovery preserves and searches content the moment legal says "hold everything."

**Exam Intel**Insider Risk Management = signals-based triage of risky user activity. Information barriers = block communication between defined groups. eDiscovery Standard/Premium = search, hold, review for legal cases. Audit Standard/Premium = investigation trail of user/admin activity.

Section 3 / Acronym Memory

## Mnemonic Wall

Memorable acronyms and phrases to anchor key exam concepts in your memory.

🔗

PTF

**P**assword hash sync, Pass-**t**hrough auth, **F**ederation

The three sign-in methods configured through Microsoft Entra Connect for hybrid identity. PHS is the resilient default; PTA keeps hashes on-prem; Federation delegates to AD FS.

🛡️

CAPRI

**C**onditional Access, **A**ccess reviews, **P**IM, **R**isk policies, **I**dentity Protection

The five pillars of Entra access governance. Conditional Access gates entry, PIM gates privilege duration, access reviews recertify, risk policies and Identity Protection catch compromised accounts.

📧

SAFE

**S**afe Links, **A**nti-phishing, **F**ishing simulation training, **E**xplorer

The Defender for Office 365 toolkit: Safe Links rewrites URLs, anti-phishing catches impersonation, attack simulation training builds resilience, Threat Explorer investigates campaigns.

💻

MEGA

**M**achine onboarding, **E**DR, **G**overnance (OAuth), **A**SR

Defender for Endpoint and Defender for Cloud Apps together: onboard devices, detect with EDR, govern risky OAuth apps, and block malware techniques with attack surface reduction.

🎯

ACES

**A**ttack disruption, **C**orrelated incidents, **E**xposure (Secure Score), **S**uspicious activity hunting

The unified Defender XDR response layer: automatic attack disruption contains threats, incidents correlate alerts across workloads, Secure Score tracks exposure, advanced hunting finds what automation missed.

🕵️

IRIS

**I**nsider risk, **R**eview sets (eDiscovery), **I**nformation barriers, **S**urveillance (comms compliance)

The Purview investigation toolkit for when prevention isn’t enough — detecting risky insiders, holding content for legal, walling off conflicted teams, and monitoring communications for violations.

Section 4 / Contrast Memory

## Versus Arena

Side-by-side comparisons to sharpen your understanding of similar concepts.

vs

Entra ConnectvsConnect Cloud Sync

Click to compare

#### Microsoft Entra Connect vs Entra Connect Cloud Sync

| Aspect | Entra Connect | Connect Cloud Sync |
| --- | --- | --- |
| Architecture | Full sync engine, on-prem server | Lightweight cloud-managed sync |
| Agents | Single sync server (+ optional staging server) | Multiple lightweight provisioning agents |
| Multi-forest | Supported, more complex configuration | Native multi-forest support out of the box |
| Password writeback | Supported | Supported |
| Filtering | OU filtering + full sync rules editor | Group-based scoping (simpler) |
| Best for | Complex sync rules, Exchange hybrid, device writeback | Simple topology, fast setup, multiple forests |

Click to flip back

vs

Defender for Office 365vsEndpoint

Click to compare

#### Defender for Office 365 vs Defender for Endpoint

| Aspect | Defender for Office 365 | Endpoint |
| --- | --- | --- |
| Protects | Email and collaboration (Exchange, Teams, SharePoint) | Devices (Windows, macOS, Linux, mobile) |
| Core features | Safe Links, Safe Attachments, anti-phishing | EDR, attack surface reduction, vulnerability management |
| Investigation tool | Threat Explorer | Device timeline / advanced hunting |
| Simulation | Attack simulation training (phishing) | Not applicable |
| Licence tiers | Plan 1 (prevention) / Plan 2 (investigation) | Plan 1 (protection) / Plan 2 (EDR) |
| Onboarding | Applies automatically to mailboxes | Requires device onboarding (Intune/GPO/script) |

Click to flip back

vs

Defender for EndpointvsCloud Apps

Click to compare

#### Defender for Endpoint vs Defender for Cloud Apps

| Aspect | Defender for Endpoint | Cloud Apps |
| --- | --- | --- |
| Protects | Endpoint devices | SaaS applications and cloud usage |
| Core features | EDR, ASR rules, vulnerability management | Cloud Discovery, OAuth app governance, session control |
| Visibility into | Malware, exploits, device compromise | Shadow IT, risky OAuth apps, anomalous cloud activity |
| Control mechanism | Sensors + automated remediation | Conditional Access App Control (reverse proxy) |
| Data source | Device telemetry | Traffic logs + SaaS API connectors |
| Best for | Stopping malware/exploits on a device | Governing SaaS app risk and shadow IT |

Click to flip back

vs

Retention PoliciesvsRetention Labels

Click to compare

#### Retention Policies vs Retention Labels

| Aspect | Retention Policies | Retention Labels |
| --- | --- | --- |
| Applied at | Location level (mailbox, site, whole org) | Item level (individual email/document) |
| Assignment | Admin-configured, no user action | Manual, auto-apply, or trainable classifier |
| Granularity | Same rule across the entire location | Different items can carry different labels |
| Disposition review | Not supported | Supported (records management) |
| Conflict handling | Shortest-delete or longest-retain wins across policies | Explicit label can override a broader policy |
| Managed in | Microsoft Purview compliance portal | Microsoft Purview compliance portal |

Click to flip back

vs

DLP PoliciesvsSensitivity Labels

Click to compare

#### DLP Policies vs Sensitivity Labels

| Aspect | DLP Policies | Sensitivity Labels |
| --- | --- | --- |
| Purpose | Prevent leakage of sensitive data | Classify and protect content |
| Trigger | Detects sensitive info types in content/actions | Applied manually or automatically to a file/email |
| Enforcement | Blocks, warns, or audits an action (share, copy, print) | Encrypts, watermarks, restricts permissions |
| Scope | Exchange, SharePoint, OneDrive, Teams, endpoints | Office apps, SharePoint, OneDrive, Teams |
| Relationship | Can use a label as a DLP condition | Labels can trigger DLP policy evaluation |
| Managed in | Microsoft Purview compliance portal | Microsoft Purview compliance portal |

Click to flip back

Section 5 / Grouping Memory

## Cheat Sheet

Organised reference grouped by exam domain — everything you need on one page.

### Deploy & Manage Tenant

10-15%

#### Tenant Setup

-   Org profile: name, address, technical contact, preferred data location
-   Default \*.onmicrosoft.com domain plus verified custom domains
-   Multi-Geo stores specific users’ data in a chosen region
-   Service health and message centre track incidents and upcoming changes

#### Domains & DNS

-   Add custom domain, verify ownership via DNS TXT (or MX) record
-   Configure MX/CNAME/TXT records for mail routing and autodiscover
-   Set a domain as the default/primary domain for new users

#### Licensing

-   Subscriptions managed per SKU in the admin centre
-   Group-based licensing assigns licences via Entra ID security groups
-   Licence conflicts (e.g. duplicate service plans) are flagged automatically

#### Admin Roles

-   Global, User, Exchange, SharePoint, and Teams Administrator roles
-   GDAP grants partners scoped, time-bound delegated access
-   Administrative units scope role assignments to a subset of objects

### Entra Identity & Access

25-30%

#### Hybrid Identity

-   Entra Connect: full sync engine, complex rules, single forest focus
-   Entra Connect Cloud Sync: lightweight agents, native multi-forest support
-   Staged rollout pilots cloud auth for a test group before cutover

#### Authentication Methods

-   Password Hash Sync: resilient, cloud validates even if on-prem is down
-   Pass-through Authentication: no password hash leaves the network
-   Federation (AD FS): delegated auth for legacy/regulated scenarios
-   SSPR: self-service reset, requires combined registration with MFA

#### Conditional Access

-   Signal-based policies: user, device, location, sign-in risk
-   Block legacy authentication protocols
-   Require MFA or a compliant/hybrid-joined device

#### Privileged Access

-   PIM: just-in-time, time-bound role activation with approval
-   Access reviews recertify group, app, and role assignments
-   Entitlement management automates access packages
-   Identity Protection risk policies feed risk-based Conditional Access

### Defender XDR Security

35-40%

#### Defender for Office 365

-   Safe Links: time-of-click URL rewriting and checking
-   Safe Attachments: sandbox detonation before delivery
-   Anti-phishing: impersonation protection, spoof intelligence
-   Threat Explorer for hunting email campaigns
-   Attack simulation training measures user resilience

#### Defender for Endpoint

-   Onboarding via Intune, Group Policy, or local script
-   EDR: behavioural sensors + device alert timeline
-   Attack surface reduction (ASR) rules block malware techniques
-   Threat and vulnerability management: exposure score, missing patches
-   Automated investigation and remediation (AIR) auto-resolves alerts

#### Defender for Cloud Apps

-   Cloud Discovery surfaces shadow IT from traffic logs
-   OAuth app governance reviews/revokes risky app permissions
-   Conditional Access App Control: real-time session control
-   Anomaly detection: impossible travel, mass download

#### Unified XDR

-   Microsoft Secure Score: prioritised posture recommendations
-   Correlated incident queue spans all Defender workloads
-   Automatic attack disruption contains active attacks
-   Advanced hunting (KQL) queries raw telemetry
-   Threat analytics maps threat intel to tenant exposure

### Purview Compliance

15-20%

#### Data Governance

-   Retention policies: location-level, no user action required
-   Retention labels: item-level, auto-apply via trainable classifiers
-   Records management adds disposition review for regulatory records
-   Data Lifecycle Management: adaptive, attribute-based policy scopes

#### Information Protection

-   Sensitivity labels classify and protect: encrypt, watermark, header/footer
-   Label priority ordering resolves multiple matching conditions
-   Auto-labelling uses sensitive info types and trainable classifiers

#### Data Loss Prevention

-   DLP policies span Exchange, SharePoint, OneDrive, Teams, endpoints
-   Endpoint DLP blocks copy-to-USB, printing, unsafe uploads
-   Adaptive protection ties DLP strictness to insider risk level

#### Investigation & Risk

-   Insider Risk Management triages risky user activity from signals
-   Information barriers restrict communication between defined groups
-   eDiscovery (Standard/Premium): search, hold, review for legal cases
-   Communication compliance monitors messages for policy violations
-   Audit (Standard/Premium) logs user and admin activity

Section 6 / Method of Loci

## The Memory Palace

Walk through themed rooms — each object anchors a concept in spatial memory.

### The Tenant Foundation

Deploy & Manage Tenant — Where the environment is built

🏢

Org Profile

Name, address, technical contact, preferred data location, Multi-Geo

🌐

Custom Domains

Added and verified via DNS TXT/MX record before routing mail

📄

Licensing

Per-SKU subscriptions, group-based licensing via Entra ID groups

👤

Admin Roles & GDAP

Least-privilege built-in roles, administrative units, partner GDAP

### The Identity Bridge

Entra Identity & Access — Where users prove who they are

🔄

Entra Connect

Full sync engine, complex rules, single forest, staging server

☁️

Connect Cloud Sync

Lightweight agents, native multi-forest, no dedicated server

🔑

Auth Methods

Password Hash Sync, Pass-through Authentication, Federation

🛡️

Conditional Access

Signal-based policies: user, device, location, risk

⏱️

PIM

Just-in-time, time-bound privileged role activation

### The Defender War Room

Defender XDR Security — Where threats are hunted and stopped

📧

Defender for Office 365

Safe Links, Safe Attachments, anti-phishing, Threat Explorer

💻

Defender for Endpoint

EDR, attack surface reduction, automated investigation

☁️

Defender for Cloud Apps

Cloud Discovery, OAuth app governance, session control

🎯

Secure Score

Prioritised, scored recommendations to improve posture

🔗

Unified Incident Queue

Correlated alerts across all Defender XDR workloads

### The Compliance Archive

Purview Compliance — Where data is governed and investigated

🗂️

Retention Policies & Labels

Location-level policies vs item-level labels; records management

🔒

Sensitivity Labels & DLP

Classify and protect content; detect and prevent risky actions

🕵️

Insider Risk Management

Signal-based triage of risky user activity

🔍

eDiscovery

Search, hold, and review content for legal cases

📋

Comms Compliance & Barriers

Monitor messages for violations; restrict cross-team communication

Section 7 / Pattern Recognition

## Pattern Spotter

Decision trees and trigger-answer pairs — see the pattern, know the answer.

Which Hybrid Identity / Auth Method?

Which Hybrid Identity / Auth Method?  
  ├── Need complex sync rules, device writeback, single forest → Microsoft Entra Connect  ├── Need multi-forest support with a simple, lightweight setup → Entra Connect Cloud Sync  ├── Cloud must validate sign-in even if on-prem is down → Password Hash Sync  ├── Password hashes must never leave the network → Pass-through Authentication  ├── Need an on-prem federation server / legacy claims → AD FS Federation  └── Users need self-service reset without the helpdesk → Self-Service Password Reset (SSPR)

Which Defender XDR Component?

Which Defender XDR Component?  
  ├── Phishing email or malicious attachment → Defender for Office 365  ├── Malware or exploit running on a device → Defender for Endpoint  ├── Shadow IT or a risky OAuth app → Defender for Cloud Apps  ├── Need one correlated view of a multi-stage attack → Unified Defender XDR incident  ├── Want to measure and improve overall posture → Microsoft Secure Score  └── Need to proactively query raw telemetry → Advanced hunting (KQL)

Which Purview Compliance Tool?

Which Purview Compliance Tool?  
  ├── Apply retention to an entire mailbox or site → Retention Policy  ├── Apply different retention rules to individual items → Retention Label  ├── Classify and encrypt a specific document → Sensitivity Label  ├── Stop sensitive data being shared inappropriately → DLP Policy  ├── Investigate a departing employee’s exfiltration risk → Insider Risk Management  └── Preserve content for a legal case → eDiscovery

Which Admin Action for Tenant Setup?

Which Admin Action for Tenant Setup?  
  ├── Assign licences to a large, dynamic group of users → Group-based licensing (Entra ID)  ├── Grant a partner scoped, time-bound support access → Granular Delegated Admin Privileges (GDAP)  ├── Limit a helpdesk admin to one region’s users → Administrative unit  ├── Verify ownership of a new company domain → Add a DNS TXT record  └── Store a subsidiary’s data in a specific region → Multi-Geo capabilities

## Decision Cards

“time-of-click URL check”→Safe Links (Defender for Office 365)

“attack surface reduction rules”→Defender for Endpoint

“Cloud Discovery” or “shadow IT”→Defender for Cloud Apps

“unified incident queue” or “correlated alerts”→Microsoft Defender XDR

“automatic attack disruption”→Defender XDR real-time containment of an active attack

“hash of a hash”→Password Hash Sync

“no password hash ever leaves the network”→Pass-through Authentication

“just-in-time role activation”→Privileged Identity Management (PIM)

“item-level retention that travels with the file”→Retention Label

“risk-adjusted DLP strictness”→Adaptive Protection

Ready to certify?

## Train with practitioners, not presenters

Lucid Labs delivers Microsoft certification training led by Microsoft Certified Trainers (MCTs) and grounded in real-world project experience. We adapt every session to your team's environment, data stack, and business objectives — because the best exam prep comes from engineers who build these solutions every day.

🎯

Tailored Content

Training built around your tenant’s hybrid identity setup, licensing model, and Defender/Purview configuration — not generic slides.

🛠️

Hands-On Labs

Configure Conditional Access, onboard devices to Defender for Endpoint, and build retention/DLP policies in a real tenant with expert guidance.

📈

Exam + Capability

Build the practical skills to run tenant, identity, security, and compliance administration day-to-day — not just pass an exam.

[Talk to us about Microsoft 365 Administrator training](https://lucidlabs.com.au/?service=training-consulting&message=I%27m%20interested%20in%20Microsoft%20365%20tenant%20administration%20training%20for%20my%20team.#contact)

Custom training for teams & individuals — remote or on-site across Australia

![Keith Oak](https://lucidlabs.com.au/team/koak-400.jpg)

Keith Oak

Chief Technology Officer — Lucid Labs

Microsoft Solutions Partner architect specialising in Fabric, Azure Data & AI, and GitHub Enterprise. 18+ years delivering data platforms for Australian businesses — building the systems these exams test every day.

[LinkedIn ↗](https://www.linkedin.com/in/keithoak/)[lucidlabs.com.au ↗](https://lucidlabs.com.au/)Published 29-03-2026
