MS-100Free trialFree trial

By microsoft
Aug, 2025

Verified

25Q per page

Question 1

After your company migrates their on-premises email solution to Microsoft Exchange Online, you are tasked with assessing which licenses to acquire.
You are informed that licenses acquired for the company's IT and Managers groups should allow for the following:
✑ The IT group needs to have access to the Microsoft Azure Active Directory (Azure AD) Privileged Identity Management.
✑ Both the IT and Managers groups should have access to Microsoft Azure Active Directory (Azure AD) conditional access.
You need to make sure that the licensing costs are kept to a minimum.
Which two of the following options should you recommend? (Choose two.)

  • A: You should acquire Microsoft 365 E3 licenses for the Managers group members.
  • B: You should acquire Microsoft 365 E5 licenses for the Managers group members.
  • C: You should acquire Microsoft 365 E3 licenses for the IT group members.
  • D: You should acquire Microsoft 365 E5 licenses for the IT group members.

Question 2

You have previously accessed the Security & Compliance admin center to upload a number of archive PST files to Microsoft 365.
When you try to run an import job for the PST files 45 days later, you find that they have been removed from Microsoft 365.
Which of the following is the number of days that Microsoft 365 retains PST file before deleting them automatically?

  • A: 1 day.
  • B: 30 days.
  • C: 15 days.
  • D: 45 days.

Question 3

You need to consider the underlined segment to establish whether it is accurate.
You have been tasked with deploying a Windows 10 Enterprise image to a large number of Windows 8.1 devices. These devices are joined to an Active Directory domain.
You use the in-place upgrade Windows 10 deployment method for the task.
Select No adjustment required if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.
What should you recommend?

  • A: No adjustment required.
  • B: Windows Autopilot
  • C: Windows Update
  • D: Azure AD Connect

Question 4

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company currently has an on-premises Active Directory forest.
You have been tasked with assessing the application of Microsoft 365 and the utilization of an authentication strategy.
You have been informed that the authentication strategy should permit sign in via smart card-based certificates, and also permitting the use of SSO to connect to on-premises and Microsoft 365 services.
Solution: You recommend the use of pass-through authentication and seamless SSO with password hash synchronization as the authentication strategy.
Does the solution meet the goal?

  • A: Yes
  • B: No

Question 5

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company currently has an on-premises Active Directory forest.
You have been tasked with assessing the application of Microsoft 365 and the utilization of an authentication strategy.
You have been informed that the authentication strategy should permit sign in via smart card-based certificates, and also permitting the use of SSO to connect to on-premises and Microsoft 365 services.
Solution: You recommend the use of password hash synchronization and seamless SSO as the authentication strategy.
Does the solution meet the goal?

  • A: Yes
  • B: No

Question 6

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company currently has an on-premises Active Directory forest.
You have been tasked with assessing the application of Microsoft 365 and the utilization of an authentication strategy.
You have been informed that the authentication strategy should permit sign in via smart card-based certificates, and also permitting the use of SSO to connect to on-premises and Microsoft 365 services.
Solution: You recommend the use of federation with Active Directory Federation Services (AD FS) as the authentication strategy.
Does the solution meet the goal?

  • A: Yes
  • B: No

Question 7

Your company's Microsoft Azure Active Directory (Azure AD) tenant includes four users. Three of the users are each configured with the Password administrator,
Security administrator, and the User administrator roles respectively. The fourth user has no role configured.
Which of the following are the users that are able to reset the password of the fourth user?

  • A: The users with the Password administrator and the User administrator roles.
  • B: The users with the Security administrator and the User administrator roles.
  • C: The users with the Password administrator and the Security administrator roles.
  • D: The user with the Password administrator role only.

Question 8

Your network contains an Active Directory domain that spans a number of cities and a multitude of users.
After acquiring Microsoft 365, you intend to deploy quite a few Microsoft 365 services.
You want to make sure that pass-through authentication and seamless SSO can be used in your environment. You also decide that Azure AD Connect won't be configured to be in staging mode.
With regards to redundancy limits, which of the following is the maximum amount of servers that can run Azure AD Connect?

  • A: 1
  • B: 3
  • C: 5
  • D: 7

Question 9

Your network contains an Active Directory domain that spans a number of cities and a multitude of users.
After acquiring Microsoft 365, you intend to deploy quite a few Microsoft 365 services.
You want to make sure that pass-through authentication and seamless SSO can be used in your environment. You also decide that Azure AD Connect won't be configured to be in staging mode.
With regards to redundancy limits, which of the following is the most amount of servers that can run standalone Authentication Agents?

  • A: 7
  • B: 9
  • C: 11
  • D: 13

Question 10

Your company's Microsoft Azure Active Directory (Azure AD) tenant includes four users that are configured with the Privileged role administrator, the User administrator, the Security administrator, and the Billing administrator roles respectively.
A security group has been included in the tenant for the purpose of managing administrative accounts.
Which of the four roles can be used to create a guest user account?

  • A: The Privileged role administrator role.
  • B: The User administrator role.
  • C: The Security administrator role.
  • D: The Billing administrator role.

Question 11

Your company's Microsoft Azure Active Directory (Azure AD) tenant includes four users that are configured with the Privileged role administrator, the User administrator, the Security administrator, and the Billing administrator roles respectively.
A security group has been included in the tenant for the purpose of managing administrative accounts.
Which of the four roles can be used to add a user with the Security administrator role to the security group?

  • A: The Privileged role administrator role.
  • B: The User administrator role.
  • C: The Security administrator role.
  • D: The Billing administrator role.

Question 12

Your company's Microsoft 365 tenant includes Microsoft Exchange Online.
You have been tasked with enabling calendar sharing with a partner organization, who also has a Microsoft 365 tenant.
You have to make sure that users in the partner organization has access to the calendar of every user instantly.
Which of the following actions should you take?

  • A: Configure a conditional access policy via Exchange admin center.
  • B: Configure a new organization relationship via Exchange admin center.
  • C: Configure the sharing settings via Exchange admin center.
  • D: Run the Set-SPOSite cmdlet.

Question 13

Your company has an Active Directory domain as well as a Microsoft Azure Active Directory (Azure AD) tenant.
After configuring directory synchronization for all users in the organization, you configure a number of new user accounts to be created automatically.
You want to run a command to make sure that the new user accounts synchronize to Azure AD in the shortest time required.
Which of the following is the command that you should use?

  • A: New-ADSyncRule
  • B: Set-ADSyncSchedulerConnectorOverride
  • C: Start-ADSyncSyncCycle
  • D: Set-ADSyncSchema

Question 14

Your company's Microsoft Azure Active Directory (Azure AD) tenant includes four users. Two of the users are configured with the Global administrator, Password administrator roles respectively. A third user has both the Security administrator and the Guest inviter roles configured. The fourth user has no roles configured.
Which of the following is the user that has the necessary permissions to alter the password protection policy? (Choose all that apply.)

  • A: The user with the Global administrator role.
  • B: The user with the Password administrator role.
  • C: The user with the Security administrator and Guest inviter roles.
  • D: The user with no roles.

Question 15

Your company's Microsoft Azure Active Directory (Azure AD) tenant includes four users. Two of the users are configured with the Global administrator, Password administrator roles respectively. A third user has both the Security administrator and the Guest inviter roles configured. The fourth user has no roles configured.
Which of the following is the user that has the necessary permissions to create guest users? (Choose all that apply.)

  • A: The user with the Global administrator role.
  • B: The user with the Password administrator role.
  • C: The user with the Security administrator and Guest inviter roles.
  • D: The user with no roles.

Question 16

You have been tasked with enable Microsoft Azure Information Protection for your company's Microsoft 365 subscription.
You are informed that only the members of a group, named Group1, are able to protect content. To achieve your goal, you plan to run a PowerShell cmdlet.
Which of the following is the cmdlet you should run?

  • A: The Add-AadrmRoleBaseAdministrator cmdlet.
  • B: The Set-AadrmDoNotTrackUserGroup cmdlet.
  • C: The Clear-AadrmSuperUserGroup cmdlet.
  • D: The Set-AadrmOnboardingControlPolicy cmdlet.

Question 17

Your company has acquired Microsoft 365 for their Active Directory domain, which includes five domain controllers.
Prior to implementing a number of Microsoft 365 services, you are tasked with making use of an authentication solution that allows users to access Microsoft 365 by using their on-premises credentials. The solution should also only make use of the current server infrastructure. Furthermore, must allow for all user passwords to only be stored on-premises, and be highly available.
Solution: You configure the use of password hash synchronization only.
Does the solution meet the goal?

  • A: Yes
  • B: No

Question 18

Your company has acquired Microsoft 365 for their Active Directory domain, which includes five domain controllers.
Prior to implementing a number of Microsoft 365 services, you are tasked with making use of an authentication solution that allows users to access Microsoft 365 by using their on-premises credentials. The solution should also only make use of the current server infrastructure. Furthermore, must allow for all user passwords to only be stored on-premises, and be highly available.
Solution: You configure the use of pass-through authentication only.
Does the solution meet the goal?

  • A: Yes
  • B: No

Question 19

Your company has acquired Microsoft 365 for their Active Directory domain, which includes five domain controllers.
Prior to implementing a number of Microsoft 365 services, you are tasked with making use of an authentication solution that allows users to access Microsoft 365 by using their on-premises credentials. The solution should also only make use of the current server infrastructure. Furthermore, must allow for all user passwords to only be stored on-premises, and be highly available.
Solution: You configure the use of pass-through authentication and seamless SSO.
Does the solution meet the goal?

  • A: Yes
  • B: No

Question 20

Your company has a Microsoft Azure Active Directory (Azure AD) tenant with multi-factor authentication enabled.
You have also configured the Allow users to submit fraud alerts, and the Block user when fraud is reported settings to ON.
A tenant user has submitted a fraud alert for his account.
Which of the following is the length of time that the user's account will automatically be blocked for?

  • A: 24 hours
  • B: 90 days
  • C: 1 month
  • D: 1 week

Question 21

Your company has a Microsoft Azure Active Directory (Azure AD) tenant with multi-factor authentication enabled.
You have also configured the Allow users to submit fraud alerts, and the Block user when fraud is reported settings to ON.
A tenant user has submitted a fraud alert for his account. After receiving an alert call, the user needs to enter a special code followed by #.
Which of the following is default special code?

  • A: 0
  • B: 9
  • C: 0000
  • D: 1234

Question 22

Your company has a Microsoft Office 365 subscription with a number of Microsoft SharePoint Online sites.
Currently, users are able to invite external users to access files on the SharePoint sites. You are tasked with making sure that users are only able to authenticated guest users to the SharePoint sites.
Which of the following actions should you take?

  • A: You should create a threat management policy via the Security & Compliance admin center.
  • B: You should run the Set-SPOSite cmdlet.
  • C: You should run the Add-SPOUser cmdlet.
  • D: You should modify the sharing settings via the SharePoint admin center.

Question 23

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
After acquiring a Microsoft 365 Enterprise subscription, you are tasked with migrating your company's Microsoft Exchange Server 2016 mailboxes and groups to
Exchange Online.
You have started a new migration batch. You, subsequently, receive complaints from on-premises Exchange Server users about slow performance.
Your analysis shows that the issue has resulted from the migration. You want to make sure that the effect the mailbox migration has on users is decreased.
Solution: You create a label policy.
Does the solution meet the goal?

  • A: Yes
  • B: No

Question 24

Your company has a Microsoft 365 subscription.
You have been tasked with configuring external collaboration settings for your company's Microsoft Azure Active Directory (Azure AD) tenant.
You want to make sure that authorized users are able to create guest users in the tenant.
Which of the following actions should you take?
Which setting should you modify?

  • A: You should make sure that the Guests can invite setting is set to NO.
  • B: You should make sure that the Guest users permissions are limited setting is set to Yes.
  • C: You should make sure that the Members can invite setting is set to NO.
  • D: You should make sure that the Admins and users in the guest inviter role can invite setting is set to Yes.

Question 25

After acquiring a Microsoft 365 subscription, you configure the use of Microsoft Azure Multi-Factor Authentication (MFA) for all users in the Azure Active Directory
(Azure AD) tenant.
You want to produce a report that includes all the users who finished the Azure MFA registration process. You want to make use of an Azure Cloud Shell cmdlet.
Which of the following is the cmdlet you should use?

  • A: Get-AzureADUser
  • B: Get-MsolUser
  • C: New-AzureADMSInvitation
  • D: Set-MsolUserPrincipalName
Page 1 of 18 • Questions 1-25 of 426

Free preview mode

Enjoy the free questions and consider upgrading to gain full access!