Microsoft MS-100
Microsoft MS-100
Microsoft MS-100
3. B. No
1 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Note: The question is included in a number of ques-
tions that depicts the identical set-up. However, every
question has a distinctive result. Establish if the so-
lution satisfies the requirements.After acquiring a Mi-
crosoft 365 Enterprise subscription, you are tasked
with migrating your company's Microsoft Exchange
Server 2016 mailboxes and groups toExchange On-
line.You have started a new migration batch. You,
subsequently, receive complaints from on-premises
Exchange Server users about slow performance.Your
analysis shows that the issue has resulted from the
migration. You want to make sure that the effect the
mailbox migration has on users is decreased.Solu-
tion: You create a label policy.Does the solution meet
the goal?
A. Yes
B. No
2 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
from receiving phishing email messages, create a
new mail flow rule.Select `No adjustment required` if
the underlined segment is accurate. If the underlined
segment is inaccurate, select the accurate option.
A. No adjustment required
B. Label policy.
C. Threat management policy.
D. Spam filter policy.
8. You have been tasked with detecting all users in your A. You should ac-
company's Microsoft 365 subscription who has a Mi- cess the Azure
crosoft Office 365 license as a result of belonging to portal, and navi-
a group.You need to make sure that the group used to gate to the Licens-
assign the license is included in your results.Which es blade.
of the following actions should you take?
3 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
A. You should access the Azure portal, and navigate
to the Licenses blade.
B. You should access the Microsoft 365 admin center,
and navigate to the Products blade.
C. You should access the Azure portal, and navigate
to the Monitor blade.
D. You should access the Microsoft 365 admin center,
and navigate to the Users blade.
4 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
lution satisfies the requirements.Your company cur-
rently has an on-premises Active Directory forest.You
have been tasked with assessing the application of
Microsoft 365 and the utilization of an authentica-
tion strategy.You have been informed that the au-
thentication strategy should permit sign in via smart
card-based certificates, and also permitting the use
of SSO to connect to on-premises and Microsoft
365 services.Solution: You recommend the use of
pass-through authentication and seamless SSO with
password hash synchronization as the authentica-
tion strategy.Does the solution meet the goal? Yes or
no?
5 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
tion strategy.You have been informed that the au-
thentication strategy should permit sign in via smart
card-based certificates, and also permitting the use
of SSO to connect to on-premises and Microsoft 365
services.Solution: You recommend the use of feder-
ation with Active Directory Federation Services (AD
FS) as the authentication strategy.Does the solution
meet the goal?
A. Yes
B. No
14. Your company's Microsoft Azure Active Directory A. The users with
(Azure AD) tenant includes four users. Three of the the Password ad-
users are each configured with the Password admin- ministrator and the
istrator,Security administrator, and the User adminis- User administrator
trator roles respectively. The fourth user has no role roles.
configured.Which of the following are the users that
are able to reset the password of the fourth user?
A. The users with the Password administrator and the
User administrator roles.
B. The users with the Security administrator and the
User administrator roles.
C. The users with the Password administrator and the
Security administrator roles.
D. The user with the Password administrator role only.
Hide Solution Discussion 5
6 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
C. 5
D. 7
17. Your company's Microsoft Azure Active Directory B. The User ad-
(Azure AD) tenant includes four users that are con- ministrator role.
figured with the Privileged role administrator, the
User administrator, the Security administrator, and
the Billing administrator roles respectively.A security
group has been included in the tenant for the pur-
pose of managing administrative accounts.Which of
the four roles can be used to create a guest user
account?
A. The Privileged role administrator role.
B. The User administrator role.
C. The Security administrator role.
D. The Billing administrator role.
Hide Solution
18. Your company's Microsoft Azure Active Directory B. The User ad-
(Azure AD) tenant includes four users that are con- ministrator role.
figured with the Privileged role administrator, the
User administrator, the Security administrator, and
the Billing administrator roles respectively.A security
7 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
group has been included in the tenant for the purpose
of managing administrative accounts.Which of the
four roles can be used to add a user with the Security
administrator role to the security group?
A. The Privileged role administrator role.
B. The User administrator role.
C. The Security administrator role.
D. The Billing administrator role.
20. Your company's Microsoft Azure Active Directory A. The user with
(Azure AD) tenant includes four users. Two of the the Global admin-
users are configured with the Global administrator, istrator role.
Password administrator roles respectively. A third C. The user
user has both the Security administrator and the with the Secu-
Guest inviter roles configured. The fourth user has no rity administrator
roles configured.Which of the following is the user and Guest inviter
that has the necessary permissions to alter the pass- roles.
word protection policy? (Choose all that apply.)
A. The user with the Global administrator role.
B. The user with the Password administrator role.
C. The user with the Security administrator and Guest
inviter roles.
D. The user with no roles.
21.
8 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Your company's Microsoft Azure Active Directory A. The user with
(Azure AD) tenant includes four users. Two of the the Global admin-
users are configured with the Global administrator, istrator role.
Password administrator roles respectively. A third C. The user
user has both the Security administrator and the with the Secu-
Guest inviter roles configured. The fourth user has no rity administrator
roles configured.Which of the following is the user and Guest inviter
that has the necessary permissions to create guest roles.
users? (Choose all that apply.)
A. The user with the Global administrator role.
B. The user with the Password administrator role.
C. The user with the Security administrator and Guest
inviter roles.
D. The user with no roles.
22. You have been tasked with enable Microsoft Azure D. The
Information Protection for your company's Microsoft Set-AadrmOn-
365 subscription.You are informed that only the mem- boardingCon-
bers of a group, named Group1, are able to protect trolPolicy cmdlet.
content. To achieve your goal, you plan to run a Pow- Hide Solution Dis-
erShell cmdlet.Which of the following is the cmdlet cussion 1
you should run?
A. The Add-AadrmRoleBaseAdministrator cmdlet.
B. The Set-AadrmDoNotTrackUserGroup cmdlet.
C. The Clear-AadrmSuperUserGroup cmdlet.
D. The Set-AadrmOnboardingControlPolicy cmdlet.
Hide Solution Discussion 1
9 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
only.Does the solution meet the goal?
A. Yes
B. No
24. Your company has acquired Microsoft 365 for their A. Yes
Active Directory domain, which includes five domain
controllers.Prior to implementing a number of Mi-
crosoft 365 services, you are tasked with making
use of an authentication solution that allows users
to access Microsoft 365 by using their on-premis-
es credentials. The solution should also only make
use of the current server infrastructure. Furthermore,
must allow for all user passwords to only be stored
on-premises, and be highly available.Solution: You
configure the use of pass-through authentication
only.Does the solution meet the goal?
A. Yes
B. No
10 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
a fraud alert for his account.Which of the following is
the length of time that the user's account will auto-
matically be blocked for?
A. 24 hours
B. 90 days
C. 1 month
D. 1 week
28. Your company has a Microsoft Office 365 subscrip- D. You should
tion with a number of Microsoft SharePoint Online modify the shar-
sites.Currently, users are able to invite external users ing settings via the
to access files on the SharePoint sites. You are tasked SharePoint admin
with making sure that users are only able to authen- center.
ticated guest users to the SharePoint sites.Which of
the following actions should you take?
A. You should create a threat management policy via
the Security & Compliance admin center.
B. You should run the Set-SPOSite cmdlet.
C. You should run the Add-SPOUser cmdlet.
D. You should modify the sharing settings via the
SharePoint admin center.
11 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
sure that authorized users are able to create guest role can invite set-
users in the tenant.Which of the following actions ting is set to Yes.
should you take?Which setting should you modify?
A. You should make sure that the Guests can invite
setting is set to NO.
B. You should make sure that the Guest users permis-
sions are limited setting is set to Yes.
C. You should make sure that the Members can invite
setting is set to NO.
D. You should make sure that the Admins and users
in the guest inviter role can invite setting is set to Yes.
31. You need to consider the underlined segment to es- B. user sign-ins
tablish whether it is accurate.You have recently con-
figured a conditional access policy to force mobile
device users to use multi-factor authentication when
accessing Microsoft SharePoint.To check who used
multi-factor authentication to authenticate, you view
the Usage reports from Azure Active Directory admin
center.Select `No adjustment required` if the under-
lined segment is accurate. If the underlined segment
is inaccurate, select the accurate option.
A. No adjustment required
B. user sign-ins
C. event logs
12 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
D. audit logs
Hide Solution
13 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
B. password protection
C. DLP
D. label
15 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
C. App Connector flow
D. a custom key
41. You have been tasked with migrating your company's C. 150
on-premises Microsoft Exchange Server 2013 orga-
nization to Microsoft 365.You plan to make use of
the cutover migration method.Which of the following
is the maximum recommended number of mailboxes
that you should migrate?
A. 2000
B. 1000
C. 150
D. 75
42. You have recently created a Microsoft 365 Enterprise B. An XML down-
subscription and assigned all users licenses for all load file.
products.You want to configure all Microsoft Office
365 ProPlus installations to be done via a network
share. You also want to make sure that users are
prevented from using the Internet to install Office 365
ProPlus.Which of the following is the type of file that
you should create?NOTE: Each correct selection is
worth one point.
A. An HTML download file.
B. An XML download file.
C. An HTTP download file.
D. An EXE download file.
43. You have recently created a Microsoft 365 subscrip- C. Six monthly
tion.You have prepared an XML file for the upcoming
Microsoft Office 365 ProPlus deployment.The Chan-
nel attribute for the OfficeClientEdition attribute is set
to Broad, while the Channel attribute for the Updates
element is set to Targeted.Which of the following the
following is the frequency with which the installation
of Office 365 ProPlus feature updates will occur?
A. Weekly.
B. Monthly
16 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
C. Six monthly
D. Annually
44. You have recently created a Microsoft 365 subscrip- B. March and Sep-
tion.You have prepared an XML file for the upcoming tember
Microsoft Office 365 ProPlus deployment.The Chan-
nel attribute for the OfficeClientEdition attribute is set
to Broad, while the Channel attribute for the Updates
element is set to Targeted.Which of the following the
following are the months of the year that security
updates will be installed?
A. January and July.
B. March and September
C. June and December
D. April and October
45. Your company's network contains two Active Directo- D. A new service
ry forests, with two domains configured per forest. All connection point
workstations are domain-joined and have Windows (SCP).
10 installed.You have created a Microsoft Azure Ac-
tive Directory (Azure AD) tenant in preparation for
configuring Hybrid Azure AD join for the worksta-
tions.You want to make sure that the tenant can be
discovered by the workstations.Which of the follow-
ing should you create in each forest?
A. A migration endpoint.
B. A new conditional access policy.
C. A new trust relationship.
D. A new service connection point (SCP).
46. After your company acquires a Microsoft 365 sub- B. IMAP migration
scription, they instruct you to move all email data
from their corporate Gmail to Microsoft Exchange
Online.The migration will be done via the Exchange
admin center.Which of the following is the migration
method you should use?
A. Exchange Hybrid
B. IMAP migration
17 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
C. Cutover
D. Express migration
47. After your company acquires a Microsoft 365 sub- B. Only email data
scription, they instruct you to move all email data will be migrated.
from their corporate Gmail to Microsoft Exchange
Online.The migration will be done via the Exchange
admin center.Which of the following is TRUE with
regards to the data included in the migration?
A. All data will be migrated.
B. Only email data will be migrated.
C. Email and task data will be migrated.
D. Email and contact data will be migrated.
18 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
review screen.Your company has a Microsoft Office
365 tenant.You suspect that several Office 365 fea-
tures were recently updated.You need to view a list
of the features that were recently updated in the ten-
ant.Solution: You use Dashboard in Security & Com-
pliance.Does this meet the goal?
A. Yes
B. No
19 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
in the Microsoft 365 admin center.Does this meet the
goal?
A. Yes
B. No
52. You recently migrated your on-premises email solu- D. 200 Microsoft
tion to Microsoft Exchange Online and are evaluating 365 E3 and 50 Mi-
which licenses to purchase.You want the members crosoft 365 E5
of two groups named IT and Managers to be able to
use the features shown in the following table.The IT
group contains 50 users. The Managers group con-
tains 200 users.You need to recommend which li-
censes must be purchased for the planned solution.
The solution must minimize licensing costs.Which
licenses should you recommend?
A. 250 Microsoft 365 E3 only
B. 50 Microsoft 365 E3 and 200 Microsoft 365 E5
C. 250 Microsoft 365 E5 only
D. 200 Microsoft 365 E3 and 50 Microsoft 365 E5
53. You have a Microsoft 365 tenant that contains Mi- B. From the
crosoft Exchange Online.You plan to enable calen- Exchange admin
dar sharing with a partner organization named ada- center, create a
tum.com. The partner organization also has a Mi- new organization
crosoft 365 tenant.You need to ensure that the cal- relationship.
endar of every user is available to the users in ada-
tum.com immediately.What should you do?
A. From the Exchange admin center, create a sharing
policy.
B. From the Exchange admin center, create a new
organization relationship.
C. From the Microsoft 365 admin center, modify the
Organization profile settings.
D. From the Microsoft 365 admin center, configure
external site sharing.
Reveal Solution Discussion 12
20 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Enterprise subscription.You plan to migrate mailbox- C. Modify the mi-
es and groups to Exchange Online.You start a new gration endpoint
migration batch.Users report slow performance when settings.
they use the on-premises Exchange Server organiza-
tion.You discover that the migration is causing the
slow performance.You need to reduce the impact of
the mailbox migration on the end-users.What should
you do?
A. Create a mail flow rule.
B. Configure back pressure.
C. Modify the migration endpoint settings.
D. Create a throttling policy.
55. You have a Microsoft 365 subscription.You need to C. From the Secu-
prevent phishing email messages from being deliv- rity & Compliance
ered to your organization.What should you do? admin center, cre-
A. From the Exchange admin center, create an ate a new threat
anti-malware policy. management poli-
B. From the Security & Compliance admin center, cy.
create a DLP policy.
C. From the Security & Compliance admin center,
create a new threat management policy.
D. From the Exchange admin center, create a spam
filter policy.
56. our company has a Microsoft 365 subscription. All C. From the Mi-
identities are managed in the cloud.The company crosoft 365 ad-
purchases a new domain name.You need to ensure min center, select
that all new mailboxes use the new domain as their Setup, and then
primary email address.What are two possible ways configure the do-
to achieve the goal? Each correct answer presents mains.
a complete solution.NOTE: Each correct selection is E. From the Azure
worth one point. Active Directory
A. Run the Update-EmailAddressPolicy Windows admin center, con-
PowerShell command figure the custom
B. From the Exchange admin center, select mail flow, domain names.
and then configure the email address policies.
C. From the Microsoft 365 admin center, select Setup,
and then configure the domains.
21 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
D. Run the Set-EmailAddressPolicy Windows Power-
Shell command.
E. From the Azure Active Directory admin center, con-
figure the custom domain names.
59. Your company has a Microsoft 365 subscription.You B. PST files are
upload several archive PST files to Microsoft 365 deleted automat-
by using the Security & Compliance admin center.A ically from Mi-
month later, you attempt to run an import job for the crosoft 365 after
PST files.You discover that the PST files were deleted 30 days.
from Microsoft 365.What is the most likely cause of
the files being deleted? More than one answer choice
may achieve the goal. Select the BEST answer.
A. The PST files were corrupted and deleted by Mi-
crosoft 365 security features.
22 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
B. PST files are deleted automatically from Microsoft
365 after 30 days.
C. The size of the PST files exceeded a storage quota
and caused the files to be deleted.
D. Another administrator deleted the PST files.
60. Your company has a main office and 20 branch offices D. In the branch
in North America and Europe. Each branch connects offices, configure
to the main office by using a WAN link. All the of- name resolution
fices connect to the Internet and resolve external host so that all queries
names by using the main office connections.You plan for external host
to deploy Microsoft 365 and to implement a direct names are redi-
Internet connection in each office.You need to rec- rected to public
ommend a change to the infrastructure to provide DNS servers di-
the quickest possible access to Microsoft 365 ser- rectly.
vices.What is the best recommendation to achieve
the goal? More than one answer choice may achieve
the goal. Select the BEST answer.
A. For all the client computers in the branch offices,
modify the MTU setting by using a Group Policy ob-
ject (GPO).
B. In each branch office, deploy a proxy server that
has user authentication enabled.
C. In each branch office, deploy a firewall that has
packet inspection enabled.
D. In the branch offices, configure name resolution so
that all queries for external host names are redirected
to public DNS servers directly.
61. Your network contains an Active Directory forest C. From Active Di-
named adatum.local. The forest contains 500 users rectory Users and
and uses adatum.com as a UPN suffix.You deploy Computers, modi-
a Microsoft 365 tenant.You implement directory syn- fy the UPN suffix
chronization and sync only 50 support users.You dis- of the five user ac-
cover that five of the synchronized users have user- counts.
names that use a UPN suffix of onmicrosoft.com.You
need to ensure that all synchronized identities retain
the UPN set in their on-premises user account.What
should you do?
23 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
A. From the Microsoft 365 admin center, add ada-
tum.com as a custom domain name.
B. From Windows PowerShell, run the Set-ADDomain
Ò€"AllowedDNSSuffixes adatum.com command.
C. From Active Directory Users and Computers, mod-
ify the UPN suffix of the five user accounts.
D. From the Microsoft 365 admin center, add ada-
tum.local as a custom domain name.
62. Your company has on-premises servers and a Mi- A. From Windows
crosoft Azure Active Directory (Azure AD) tenant.Sev- PowerShell, run
eral months ago, the Azure AD Connect Health agent the
was installed on all the servers.You review the health Register-AzureAD-
status of all the servers regularly.Recently, you at- ConnectHealth-
tempted to view the health status of a server named SyncAgent
Server1 and discovered that the server is NOT list- cmdlet.
ed on the Azure Active Directory ConnectServers E. From Serv-
list.You suspect that another administrator removed er1, reinstall the
Server1 from the list.You need to ensure that you can Azure AD Connect
view the health status of Server1.What are two pos- Health agent.
sible ways to achieve the goal? Each correct answer
presents a complete solution.NOTE: Each correct se-
lection is worth one point.
A. From Windows PowerShell, run the Regis-
ter-AzureADConnectHealthSyncAgent cmdlet.
B. From Azure Cloud shell, run the Connect-AzureAD
cmdlet.
C. From Server1, change the Azure AD Connect
Health services Startup type to Automatic (Delayed
Start).
D. From Server1, change the Azure AD Connect
Health services Startup type to Automatic.
E. From Server1, reinstall the Azure AD Connect
Health agent.
63. You have a Microsoft 365 subscription.You suspect A. From the Mi-
that several Microsoft Office 365 applications or ser- crosoft 365 ad-
vices were recently updated.You need to identify min center, review
which applications or services were recently up- the Message cen-
24 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
dated.What are two possible ways to achieve the ter blade.
goal? Each correct answer presents a complete solu- B. From the Office
tion.NOTE: Each correct selection is worth one point. 365 Admin mobile
A. From the Microsoft 365 admin center, review the app, review the
Message center blade. messages.
B. From the Office 365 Admin mobile app, review the
messages.
C. From the Microsoft 365 admin center, review the
Products blade.
D. From the Microsoft 365 admin center, review the
Service health blade.
25 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
crosoft Azure Active Directory (Azure AD).You man-
age Windows 10 devices by using Microsoft System
Center Configuration Manager (Current Branch).You
configure a pilot for co-management.You add a new
device named Device1 to the domain. You install the
Configuration Manager client on Device1.You need to
ensure that you can manage Device1 by using Mi-
crosoft Intune and Configuration Manager.Solution:
You add Device1 to an Active Directory group.Does
this meet the goal?
A. Yes
B. No
26 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
series contains a unique solution that might meet the
stated goals. Some question sets might have more
than one correct solution, while others might not
have a correct solution.After you answer a question
in this section, you will NOT be able to return to it.
As a result, these questions will not appear in the
review screen.Your network contains an Active Direc-
tory domain named contoso.com that is synced to Mi-
crosoft Azure Active Directory (Azure AD).You man-
age Windows 10 devices by using Microsoft System
Center Configuration Manager (Current Branch).You
configure a pilot for co-management.You add a new
device named Device1 to the domain. You install the
Configuration Manager client on Device1.You need to
ensure that you can manage Device1 by using Mi-
crosoft Intune and Configuration Manager.Solution:
You create a device configuration profile from the
Intune admin center.Does this meet the goal?
A. Yes
B. No
73. Your company uses on-premises Windows Server A. From the Share-
File Classification Infrastructure 9FCI). Some doc- Point admin cen-
uments on the on-premises file servers are clas- ter, create a man-
sifies asConfidential.You migrate the files from the aged property.
on-premises file servers to Microsoft SharePoint On-
line.You need to ensure that you can implement data
loss prevention (DLP) policies for the uploaded files
based on the Confidential classification.What should
you do first?
A. From the SharePoint admin center, create a man-
aged property.
B. From the SharePoint admin center, configure hy-
brid search.
C. From the Security & Compliance Center Power-
Shell, run the New-DlpComplianceRule cmdlet.
D. From the Security & Compliance Center Power-
Shell, run the New-DataClassification cmdlet.
29 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
80. You have a Microsoft 365 tenant.You have a A. From Microsoft
line-of-business application named App1 that users Cloud App Se-
access by using the My Apps portal.After some re- curity, modify the
cent security breaches, you implement a conditional impossible travel
access policy for App1 that uses Conditional Access alert policy.
App Control.You need to be alerted by email if im-
possible travel is detected for a user of App1. The
solution must ensure that alerts are generated for
App1 only.What should you do?
A. From Microsoft Cloud App Security, modify the
impossible travel alert policy.
B. From Microsoft Cloud App Security, create a Cloud
Discovery anomaly detection policy.
C. From the Azure Active Directory admin center,
modify the conditional access policy.
D. From Microsoft Cloud App Security, create an app
discovery policy.
30 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Advanced Threat Protection (ATP) for 10 test devices.
During the onboarding process, you configure Win-
dows Defender ATP-related data to be stored in the
United States.You plan to onboard all the devices to
Windows Defender ATP data in Europe.What should
you do first?
A. Create a workspace
B. Offboard the test devices
C. Delete the workspace
D. Onboard a new device
87. Your network contains an Active Directory domain A. Wipe and load
named contoso.com. The domain contains 1000 Win- refresh
dows 8.1 devices.You plan to deploy a custom Win-
dows 10 Enterprise image to the Windows 8.1 de-
vices.You need to recommend a Windows 10 deploy-
ment method.What should you recommend?
A. Wipe and load refresh
B. Windows Autopilot
31 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
C. a provisioning package
D. an in-place upgrade
92. Your company has two offices. The offices are lo- B. From the Mi-
cated in Seattle and New York.The company uses crosoft 365 admin
a third-party email system.You implement Microsoft center, add the
365.You move all the users in the Seattle office to adatum.com do-
Exchange Online. You configure Microsoft 365 to suc- main. From the
cessfully receive all the email messages sent to the Exchange admin
Seattle office users.All the users in the New York of- center, configure
fice continue to use the third-party email system.The adatum.com as an
users use the email domains shown in the following internal relay do-
table.You need to ensure that all the email messages main.
sent to the New York office users are delivered suc-
cessfully. The solution must ensure that all the email
messages for the users in both offices are routed
through Microsoft 365.You create the required DNS
records and Send connectors.What should you do
next from Microsoft 365?
A. From the Microsoft 365 admin center, set the de-
fault domain. From the Exchange admin center, cre-
ate a transport rule for all the email messages sent to
adatum.com.
B. From the Microsoft 365 admin center, add the ada-
tum.com domain. From the Exchange admin center,
configure adatum.com as an internal relay domain.
C. From the Microsoft 365 admin center, add the ada-
tum.com domain. From the Exchange admin center,
configure adatum.com as an authoritative domain.
D. From the Microsoft 365 admin center, set the de-
fault domain. From the Exchange admin center, con-
figure adatum.com as a remote domain.
94.
33 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
SIMULATION -Please wait while the virtual machine You need to add
loads. Once loaded, you may proceed to the lab sec- the contoso.com
tion. This may take a few minutes, and the wait time domain to
will not be deducted from your overall test time.When Microsoft 365
the Next button is available, click it to access the then set the
lab section. In this section, you will perform a set of domain as the
tasks in a live environment. While most functionality default.1. In the
will be available to you as it would be in a live en- Admin Center,
vironment, some functionality (e.g., copy and paste, click Setup then
ability to navigate to external websites) will not be click Domains.2.
possible by design.Scoring is based on the outcome Click the Ò€˜ Add
of performing the tasks stated in the lab. In other DomainÒ€™
words, it doesn't matter how you accomplish the task, button.3. Type in
if you successfully perform it, you will earn credit the domain name
for that task.Labs are not timed separately, and this (contoso.com)
exam may have more than one lab that you must and click the
complete. You can use as much time as you would Ò€˜ Use this
like to complete each lab. But, you should manage domainÒ€™
your time appropriately to ensure that you are able button.4. The
to complete the lab(s) and all other sections of the question states
exam in the time provided.Please note that once that another
you submit your work by clicking the Next button administrator will
within a lab, you will NOT be able to return to the perform the
lab.You may now click next to proceed to the lab.Lab required
information -Use the following login credentials as information to
needed:To enter your username, place your cursor in your DNS zone.
the Sign in box and click on the username below.To Therefore, you
enter your password, place your cursor in the Enter just need to click
password box and click on the password below.Mi- the Ò€˜ VerifyÒ€™
crosoft 365 Username:admin@LODSe426243.onmi- button to verify
crosoft.comMicrosoft 365 Password: 3&YWyjse-6-dIf domain
the Microsoft 365 portal does not load successfully ownership.5. Click
in the browser, press CTRL-K to reload the portal Finish.6. In the
in a new browser tab.The following information is domains list,
for technical support purposes only:Lab Instance: select the
10887751 -You plan to create 1,000 users in your Mi- contoso.com
crosoft 365 subscription.You need to ensure that all domain.7. Select
the users can use the @contoso.com suffix in their Ò€˜ Set as
username.Another administrator will perform the re-
34 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
quired information to your DNS zone to complete the defaultÒ€™.
Refer-
operation. ences:https://docs.mic
95. SIMULATION -Please wait while the virtual machine You need to edit
loads. Once loaded, you may proceed to the lab sec- the Data Loss Pre-
tion. This may take a few minutes, and the wait time vention Policy to
will not be deducted from your overall test time.When disable the email
the Next button is available, click it to access the notifications.1. Go
lab section. In this section, you will perform a set of to https://protec-
tasks in a live environment. While most functionality tion.office.com or
will be available to you as it would be in a live en- navigate to the Se-
vironment, some functionality (e.g., copy and paste, curity & Compli-
ability to navigate to external websites) will not be ance admin cen-
possible by design.Scoring is based on the outcome ter.2. In the left
of performing the tasks stated in the lab. In other navigation pane,
words, it doesn't matter how you accomplish the task, expand Data Loss
if you successfully perform it, you will earn credit Protection and se-
for that task.Labs are not timed separately, and this lect Policy.3. Se-
exam may have more than one lab that you must lect the Data Loss
complete. You can use as much time as you would Prevention poli-
like to complete each lab. But, you should manage cy and click the
your time appropriately to ensure that you are able to Edit Policy but-
complete the lab(s) and all other sections of the exam ton.4. Click Policy
in the time provided.Please note that once you submit Settings in the left
your work by clicking the Next button within a lab, you navigation pane of
will NOT be able to return to the lab.You may now click the policy.5. Se-
next to proceed to the lab.Lab information -Use the lect the policy
following login credentials as needed:To enter your rule and click the
username, place your cursor in the Sign in box and Edit Rule button.6.
click on the username below.To enter your password, Scroll down to
place your cursor in the Enter password box and click the Ò€˜ User noti-
on the password below.Microsoft 365 Username:ad- ficationsÒ€™sec-
min@LODSe1211885.onmicrosoft.comMicrosoft 365 tion.7. Toggle the
Password: oL9z0=?Nq@oxIf the Microsoft 365 por- slider labelled Ò€-
tal does not load successfully in the browser, press Use Notifications
CTRL-K to reload the portal in a new browser tab.The to inform users-
following information is for technical support purpos- Ò€¦.Ò€to Off.8. Click
es only: Save to save the
changes to the
35 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
policy rule.9. Click
Save to save the
changes to the
policy.
96. You have a Microsoft 365 subscription.You add a do- A. From the
main named contoso.com.When you attempt to verify domain registrar,
the domain, you are prompted to send a verification modify the contact
email to admin@contoso.com.You need to change information of the
the email address used to verify the domain.What domain
should you do?
A. From the domain registrar, modify the contact in-
formation of the domain
B. Add a TXT record to the DNS zone of the domain
C. Modify the NS records for the domain
D. From the Microsoft 365 admin center, change the
global administrator of the Microsoft 365 subscrip-
tion
97. Your company uses email, calendar, contact, and task B. email
services in Microsoft Outlook.com.You purchase a
Microsoft 365 subscription and plan to migrate all
users from Outlook.com to Microsoft 365.You need to
identify which user data can be migrated to Microsoft
365.Which type of data should you identify?
A. task
B. email
C. calendar
D. contacts
98. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When modify the default
the Next button is available, click it to access the remote domain.
lab section. In this section, you will perform a set of When you add
tasks in a live environment. While most functionality a remote domain,
will be available to you as it would be in a live en- you specify the do-
vironment, some functionality (e.g., copy and paste, main name and
36 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
ability to navigate to external websites) will not be the settings ap-
possible by design.Scoring is based on the outcome ply to that domain.
of performing the tasks stated in the lab. In other The default re-
words, it doesn't matter how you accomplish the task, mote domain ap-
if you successfully perform it, you will earn credit plies to all other
for that task.Labs are not timed separately, and this domains. There-
exam may have more than one lab that you must fore, we need to
complete. You can use as much time as you would disable Out of Of-
like to complete each lab. But, you should manage fice replies for ex-
your time appropriately to ensure that you are able ternal users in the
to complete the lab(s) and all other sections of the settings of the de-
exam in the time provided.Please note that once you fault remote do-
submit your work by clicking the Next button within a main.1. Go to the
lab, you will NOT be able to return to the lab.You may Exchange Admin
now click next to proceed to the lab.Lab information Center.2. Click
-Use the following login credentials as needed:To Mail Flow in
enter your username, place your cursor in the Sign the left naviga-
in box and click on the username below.To enter your tion pane.3. Click
password, place your cursor in the Enter password on Remote Do-
box and click on the password below.Microsoft 365 mains.4. Select
Username: admin@LODSe878763.onmicrosoft.com- the default re-
Microsoft 365 Password: m3t^We$Z7&xyIf the Mi- mote domain and
crosoft 365 portal does not load successfully in the click the Edit icon
browser, press CTRL-K to reload the portal in a new (pencil icon).5. In
browser tab.The following information is for technical the Ò€Õut of Of-
support purposes only: fice automatic re-
ply typesÒ€™sec-
tion, select Ò€˜-
NoneÒ€™.6. Click
Save to save to
changes to the de-
fault remote do-
main.
99. https://gya- B. No
zo.com/f718b02b5745dce69da1c080c10d71af
100. https://gya- B. No
zo.com/74c87aaec20f496d1ff0ae2042e5cd6d
37 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
101. https://gya- A. Yes
zo.com/d5751d7d9be31cd20b0b377a77313e59
103. https://gya- B. No
zo.com/a0bad0a941a9d0f6b1f4e8def25dc570
39 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
365 tenant.You suspect that several Office 365 fea-
tures were recently updated.You need to view a list
of the features that were recently updated in the ten-
ant.Solution: You use the Service health option in the
Microsoft 365 admin center.Does this meet the goal?
A. Yes
B. No
114. You have a Microsoft 365 subscription. You have a B. the eDiscov-
user named User1.You need to ensure that User1 can ery Manager role
place a hold on all mailbox content.What permission from the Security
should you assign to User1? & Compliance ad-
A. the User management administrator role from the min center
40 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Microsoft 365 admin center
B. the eDiscovery Manager role from the Security &
Compliance admin center
C. the Information Protection administrator role from
the Azure Active Directory admin center
D. the Compliance Management role from the Ex-
change admin center
117. You have a Microsoft 365 subscription that contains C. Compliance Ad-
a Microsoft Azure Active Directory (Azure AD) tenant ministrator
named contoso.com.In the tenant, you create a user
named User1.You need to ensure that User1 can pub-
lish retention labels from the Security & Compliance
admin center. The solution must use the principle of
least privilege.To which role group should you add
User1?
A. Security Administrator
B. Records Management
C. Compliance Administrator
D. eDiscovery Manager
121. A user receives the following message when attempt- C. Microsoft Azure
ing to sign in to https://myapps.microsoft.com:"Your Active Directory
sign-in was blocked. We've detected something un- (Azure AD) condi-
usual about this sign-in. For example, you might be tional access poli-
signing in from a new location, device, or app. Before cies
you can continue, we need to verify your identity.
Please contact your admin."Which configuration pre-
vents the users from signing in?
A. Security & Compliance supervision policies
B. Security & Compliance data loss prevention (DLP)
policies
C. Microsoft Azure Active Directory (Azure AD) con-
ditional access policies
D. Microsoft Azure Active Directory (Azure AD) Iden-
tity Protection policies
43 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
126. Note: This question is part of a series of questions B. No
that present the same scenario. Each question in the
series contains a unique solution that might meet the
stated goals. Some question sets might have more
than one correct solution, while others might not
have a correct solution.After you answer a question
in this section, you will NOT be able to return to it. As
a result, these questions will not appear in the review
screen.Your network contains an Active Directory do-
main.You deploy a Microsoft Azure Active Directory
(Azure AD) tenant.Another administrator configures
the domain to synchronize to Azure AD.You discover
that 10 user accounts in an organizational unit (OU)
are NOT synchronized to Azure AD. All the other
user accounts synchronized successfully.You review
Azure AD Connect Health and discover that all the
user account synchronizations completed success-
fully.You need to ensure that the 10 user accounts are
synchronized to Azure AD.Solution: From Azure AD
Connect, you modify the Azure AD credentials.Does
this meet the goal?
A. Yes
B. No
45 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
132. Note: This question is part of a series of questions B. No
that present the same scenario. Each question in the
series contains a unique solution that might meet the
stated goals. Some question sets might have more
than one correct solution, while others might not
have a correct solution.After you answer a question
in this section, you will NOT be able to return to it. As
a result, these questions will not appear in the review
screen.Your company has 3,000 users. All the users
are assigned Microsoft 365 E3 licenses.Some users
are assigned licenses for all Microsoft 365 services.
Other users are assigned licenses for only certain Mi-
crosoft 365 services.You need to determine whether
a user named User1 is licensed for Exchange On-
line only.Solution: You run the Get-MsolAccountSku
cmdlet.Does this meet the goal?
A. Yes
B. No
134.
46 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
https://gya- https://gya-
zo.com/1d24b03887d03061a4625b42fb17f248 zo.com/16ca947b4182
137. You have a Microsoft 365 subscription that contains A. Security reader
a Microsoft Azure Active Directory (Azure AD) ten-
ant named contoso.com. The tenant includes a user
namedUser1.You enable Azure AD Identity Protec-
tion.You need to ensure that User1 can review the
list in Azure AD Identity Protection of users flagged
for risk. The solution must use the principle of least
privilege.To which role should you add User1?
A. Security reader
B. User administrator
C. Owner
D. Global administrator
47 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
D. six Azure AD Connect sync servers and three
Azure AD Connect sync servers in staging mode
48 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
A. Yes
B. No
146. Your network contains an Active Directory forest B. From Active Di-
named contoso.local.You have a Microsoft 365 sub- rectory Domains
scription.You plan to implement a directory synchro- and Trusts, add
nization solution that will use password hash syn- contoso.com as a
chronization.From the Microsoft 365 admin center, UPN suffix.
you verify the contoso.com domain name.You need
to prepare the environment for the planned directory
49 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
synchronization solution.What should you do first?
A. From the public DNS zone of contoso.com, add a
new mail exchanger (MX) record.
B. From Active Directory Domains and Trusts, add
contoso.com as a UPN suffix.
C. From the Microsoft 365 admin center, verify the
contoso.local domain name.
D. From Active Directory Users and Computers, mod-
ify the UPN suffix for all users.
148. Your network contains an Active Directory do- E. From the fire-
main and a Microsoft Azure Active Directory (Azure wall, modify the
AD) tenant.The network uses a firewall that con- list of allowed out-
tains a list of allowed outbound domains.You be- bound domains.
gin to implement directory synchronization.You dis-
cover that the firewall configuration contains only
the following domain names in the list of allowed
domains: *.microsoft.com*.office.comDirectory syn-
chronization fails.You need to ensure that directory
synchronization completes successfully.What is the
best approach to achieve the goal? More than one
answer choice may achieve the goal. Select the BEST
answer.
A. From the firewall, allow the IP address range of the
Azure data center for outbound communication.
B. From Azure AD Connect, modify the Customize
synchronization options task.
C. Deploy an Azure AD Connect sync server in stag-
ing mode.
D. From the firewall, create a list of allowed inbound
domains.
E. From the firewall, modify the list of allowed out-
bound domains.
50 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Microsoft 365 and the deployment of an authentica- Federation Ser-
tion strategy.You need to recommend an authentica- vices (AD FS)
tion strategy that meets the following requirements:
Allows users to sign in by using smart card-based
certificates Allows users to connect to on-premises
and Microsoft 365 services by using SSOWhich au-
thentication strategy should you recommend?
A. password hash synchronization and seamless
SSO
B. federation with Active Directory Federation Ser-
vices (AD FS)
C. pass-through authentication and seamless SSO
154. https://gya- A. 1
zo.com/f51cf9b52d1647d42a9b2e8be6d9de6d
158. Your company has 10,000 users who access all ap- D. Run idfix.exe,
plications from an on-premises data center.You plan and then click Edit.
to create a Microsoft 365 subscription and to migrate
data to the cloud.You plan to implement directory
synchronization.User accounts and group accounts
must sync to Microsoft Azure Active Directory (Azure
AD) successfully.You discover that several user ac-
counts fail to sync to Azure AD.You need to resolve
the issue as quickly as possible.What should you do?
A. From Active Directory Administrative Center,
search for all the users, and then modify the proper-
ties of the user accounts.
B. Run idfix.exe, and then click Complete.
C. From Windows PowerShell, run the Start-AdSync-
Cycle Ò€" PolicyType Delta command.
D. Run idfix.exe, and then click Edit.
159. Your network contains an Active Directory forest. The D. From Windows
forest contains two domains named contoso.com PowerShell, run
and adatum.com.Your company recently purchased the
a Microsoft 365 subscription.You deploy a federated Update-MSOLFed-
identity solution to the environment.You use the fol- eratedDomain
lowing command to configure contoso.com for fed- Ò€"
DomainName
eration.Convert-MsolDomaintoFederated `"Domain- contoso.com
Name contoso.comIn the Microsoft 365 tenant, an ad- Ò€"
SupportMultiple-
ministrator adds and verifies the adatum.com domain Domain
name.You need to configure the adatum.com Active command.
52 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Directory domain for federated authentication.Which E. From the fed-
two actions should you perform before you run the eration server, re-
Azure AD Connect wizard? Each correct answer pre- move the Mi-
sents part of the solution.NOTE: Each correct selec- crosoft Office 365
tion is worth one point. relying party trust.
A. From Windows PowerShell, run the Convert-Msol-
DomaintoFederated Ò€" DomainName contoso.com Ò€"-
SupportMultipleDomain command.
B. From Windows PowerShell, run the New-MsolFed-
eratedDomain Ò€" SupportMultipleDomain -Domain-
Name contoso.com command.
C. From Windows PowerShell, run the New-MsolFed-
eratedDomain -DomainName adatum.com command.
D. From Windows PowerShell, run the Up-
date-MSOLFederatedDomain Ò€" DomainName con-
toso.com Ò€" SupportMultipleDomain command.
E. From the federation server, remove the Microsoft
Office 365 relying party trust.
160. You have a Microsoft 365 subscription that contains D. Security admin-
a Microsoft Azure Active Directory (Azure AD) ten- istrator
ant named contoso.com. The tenant includes a user
namedUser1.You enable Azure AD Identity Protec-
tion.You need to ensure that User1 can review the
list in Azure AD Identity Protection of users flagged
for risk. The solution must use the principle of least
privilege.To which role should you add User1?
A. Compliance administrator
B. Global administrator
C. Owner
D. Security administrator
161. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When assign Christie
the Next button is available, click it to access the the Ò€˜
Service
lab section. In this section, you will perform a set of Support
tasks in a live environment. While most functionality AdminÒ€™role.1.
53 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
will be available to you as it would be in a live en- In the Microsoft
vironment, some functionality (e.g., copy and paste, 365 Admin
ability to navigate to external websites) will not be Center, click
possible by design.Scoring is based on the outcome Ò€˜ RolesÒ€™.2.
of performing the tasks stated in the lab. In other Scroll down to the
words, it doesn't matter how you accomplish the task, Service Support
if you successfully perform it, you will earn credit Admin role and
for that task.Labs are not timed separately, and this click on the role
exam may have more than one lab that you must name.3. Click the
complete. You can use as much time as you would Ò€˜ Assigned
like to complete each lab. But, you should manage AdminsÒ€™link.4.
your time appropriately to ensure that you are able Click the
to complete the lab(s) and all other sections of the Ò€˜ AddÒ€™
exam in the time provided.Please note that once button.5. Start
you submit your work by clicking the Next button typing the name
within a lab, you will NOT be able to return to the Christie then
lab.You may now click next to proceed to the lab.Lab select her
information -Use the following login credentials as account when it
needed:To enter your username, place your cursor in appears.6. Click
the Sign in box and click on the username below.To Save.Refer-
enter your password, place your cursor in the Enter ences:https://docs.mic
password box and click on the password below.Mi-
crosoft 365 Username:admin@LODSe426243.onmi-
crosoft.comMicrosoft 365 Password: 3&YWyjse-6-dIf
the Microsoft 365 portal does not load successfully
in the browser, press CTRL-K to reload the portal
in a new browser tab.The following information is
for technical support purposes only:Lab Instance:
10887751 -You need to modify Christie Cline to meet
the following requirements: Christie Cline must be
able to view the service dashboard and the Microsoft
Office 365 Message center. Christie Cline must be
able to create Microsoft support requests.The solu-
tion must use the principle of least privilege.
162. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When create a Dynamic
54 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
the Next button is available, click it to access the group. User
lab section. In this section, you will perform a set of accounts with the
tasks in a live environment. While most functionality city attribute set to
will be available to you as it would be in a live en- Ò€˜
SeattleÒ€™will
vironment, some functionality (e.g., copy and paste, automatically be
ability to navigate to external websites) will not be added to the
possible by design.Scoring is based on the outcome group.1. Go to the
of performing the tasks stated in the lab. In other Azure Active
words, it doesn't matter how you accomplish the task, Directory admin
if you successfully perform it, you will earn credit center.2. Select
for that task.Labs are not timed separately, and this Azure Active
exam may have more than one lab that you must Directory then
complete. You can use as much time as you would select Groups.3.
like to complete each lab. But, you should manage Click on the New
your time appropriately to ensure that you are able Group link.4. Give
to complete the lab(s) and all other sections of the the group a name
exam in the time provided.Please note that once such as Seattle
you submit your work by clicking the Next button Users.5. Select
within a lab, you will NOT be able to return to the Users as the
lab.You may now click next to proceed to the lab.Lab membership
information -Use the following login credentials as type.6. Select
needed:To enter your username, place your cursor in Ò€˜ Add dynamic
the Sign in box and click on the username below.To queryÒ€™.7.
enter your password, place your cursor in the Enter Select Ò€˜ CityÒ€™
password box and click on the password below.Mi- in the Property
crosoft 365 Username:admin@LODSe426243.onmi- drop-down box.8.
crosoft.comMicrosoft 365 Password: 3&YWyjse-6-dIf Select
the Microsoft 365 portal does not load successfully Ò€˜ EqualsÒ€™in
in the browser, press CTRL-K to reload the portal the Operator
in a new browser tab.The following information is drop-down box.9.
for technical support purposes only:Lab Instance: Enter Seattle as
10887751 -Your organization has an office in Seat- the Value. You
tle.You plan to create 100 users who will work in the should see the
Seattle office. The city attribute for all the users will following text in
be Seattle.You need to create a group named Group1 the Expression
that will automatically contain all the Seattle office box: user.city -eq
users. "Seattle"10. Click
Save to create the
55 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
group.Refer-
ences:https://docs.mic
163. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When create a user ac-
the Next button is available, click it to access the count and assign
lab section. In this section, you will perform a set of a license to the
tasks in a live environment. While most functionality account. You then-
will be available to you as it would be in a live en- To create the user
vironment, some functionality (e.g., copy and paste, account and mail-
ability to navigate to external websites) will not be box:1. In the Mi-
possible by design.Scoring is based on the outcome crosoft 365 ad-
of performing the tasks stated in the lab. In other min center, go
words, it doesn't matter how you accomplish the task, to User manage-
if you successfully perform it, you will earn credit ment, and select
for that task.Labs are not timed separately, and this Add user.2. En-
exam may have more than one lab that you must ter the name Ben
complete. You can use as much time as you would Smith in the First
like to complete each lab. But, you should manage Name and Last
your time appropriately to ensure that you are able Name fields.3. En-
to complete the lab(s) and all other sections of the ter Ben.Smith in
exam in the time provided.Please note that once the username field
you submit your work by clicking the Next button and click Next.4.
within a lab, you will NOT be able to return to the Assign a Microsoft
lab.You may now click next to proceed to the lab.Lab 365 license to the
information -Use the following login credentials as account.5. Click
needed:To enter your username, place your cursor in Next.6. Click Next
the Sign in box and click on the username below.To again.7. Click Ò€˜-
enter your password, place your cursor in the Enter Finish addingÒ€™.
password box and click on the password below.Mi-
crosoft 365 Username:admin@LODSe426243.onmi-
crosoft.comMicrosoft 365 Password: 3&YWyjse-6-dIf
the Microsoft 365 portal does not load successfully
in the browser, press CTRL-K to reload the portal
in a new browser tab.The following information is
for technical support purposes only:Lab Instance:
10887751 -A user named Johanna Lorenz recently
56 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
left the company. A new employee named Ben Smith
will handle the tasks of Johanna Lorenz.You need to
create a user named Ben Smith. Ben Smith must be
able to sign in to http://myapps.microsoft.com and
open Microsoft Word Online.
164. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need
will not be deducted from your overall test time.When to sign-in status
the Next button is available, click it to access the for the account
lab section. In this section, you will perform a set of to Ò€˜BlockedÒ€™.
tasks in a live environment. While most functionality Blocking doesn't
will be available to you as it would be in a live en- stop the ac-
vironment, some functionality (e.g., copy and paste, count from re-
ability to navigate to external websites) will not be ceiving email and
possible by design.Scoring is based on the outcome it doesn't delete
of performing the tasks stated in the lab. In other any data.1. On
words, it doesn't matter how you accomplish the task, the home page
if you successfully perform it, you will earn credit of the Microsoft
for that task.Labs are not timed separately, and this 365 admin cen-
exam may have more than one lab that you must ter, type the user-
complete. You can use as much time as you would Ò€™ s name into
like to complete each lab. But, you should manage the Search box.2.
your time appropriately to ensure that you are able Select the Nestor
to complete the lab(s) and all other sections of the Wilke account in
exam in the time provided.Please note that once the search re-
you submit your work by clicking the Next button sults.3. In the
within a lab, you will NOT be able to return to the Ò€˜
Sign-in status-
lab.You may now click next to proceed to the lab.Lab Ò€™section of
information -Use the following login credentials as the account prop-
needed:To enter your username, place your cursor in erties, click the
the Sign in box and click on the username below.To Edit link.4. Select
enter your password, place your cursor in the Enter Ò€˜ Block the user
password box and click on the password below.Mi- from signing inÒ€™
crosoft 365 Username:admin@LODSe426243.onmi- and click the Save
crosoft.comMicrosoft 365 Password: 3&YWyjse-6-dIf button.
the Microsoft 365 portal does not load successfully
in the browser, press CTRL-K to reload the portal
57 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
in a new browser tab.The following information is
for technical support purposes only:Lab Instance:
10887751 -You hire a new Microsoft 365 administrator
named Nestor Wilke. Nestor Wilke will begin working
for your organization in several days.You need to
ensure that Nestor Wilke is prevented from using his
account until he begins working.
165. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When create the group
the Next button is available, click it to access the and assign a
lab section. In this section, you will perform a set of license to the
tasks in a live environment. While most functionality group. Anyone
will be available to you as it would be in a live en- who is added to
vironment, some functionality (e.g., copy and paste, the group will
ability to navigate to external websites) will not be automatically be
possible by design.Scoring is based on the outcome assigned the
of performing the tasks stated in the lab. In other license that is
words, it doesn't matter how you accomplish the task, assigned to the
if you successfully perform it, you will earn credit group.1. Go to the
for that task.Labs are not timed separately, and this Azure Active
exam may have more than one lab that you must Directory admin
complete. You can use as much time as you would center.2. Select
like to complete each lab. But, you should manage the Azure Active
your time appropriately to ensure that you are able Directory link then
to complete the lab(s) and all other sections of the select Groups.3.
exam in the time provided.Please note that once Click the New
you submit your work by clicking the Next button Group link.4.
within a lab, you will NOT be able to return to the Select
lab.You may now click next to proceed to the lab.Lab Ò€˜ SecurityÒ€™as
information -Use the following login credentials as the group type
needed:To enter your username, place your cursor in and enter
the Sign in box and click on the username below.To Ò€G̃roup2Ò€™for
enter your password, place your cursor in the Enter the group name.5.
password box and click on the password below.Mi- Click the Create
crosoft 365 Username:admin@LODSe426243.onmi- button to create
crosoft.comMicrosoft 365 Password: 3&YWyjse-6-dIf the group.6. Back
58 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
the Microsoft 365 portal does not load successfully in the Groups list,
in the browser, press CTRL-K to reload the portal select Group2 to
in a new browser tab.The following information is open the
for technical support purposes only:Lab Instance: properties page
10887751 -You need to create a group named Group2. for the group.7.
Users who are added to Group2 must be licensed Select
automatically for Microsoft Offline 365. Ò€˜LicensesÒ€™.8.
Select the Ò€˜+
AssignmentsÒ€™
link.9. Tick the box
to select the
license.10. Click
the Save button to
save the
changes.Refer-
ences:https://docs.mic
166. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When assign the
the Next button is available, click it to access the Ò€˜
Billing
lab section. In this section, you will perform a set of AdministratorÒ€™
tasks in a live environment. While most functionality role to Grady
will be available to you as it would be in a live en- Archie.1. Go to
vironment, some functionality (e.g., copy and paste, the Azure Active
ability to navigate to external websites) will not be Directory admin
possible by design.Scoring is based on the outcome center.2. Select
of performing the tasks stated in the lab. In other Users.3. Select
words, it doesn't matter how you accomplish the task, the Grady Archie
if you successfully perform it, you will earn credit account to open
for that task.Labs are not timed separately, and this the account
exam may have more than one lab that you must properties
complete. You can use as much time as you would page.4. Select
like to complete each lab. But, you should manage Ò€˜ Assigned
your time appropriately to ensure that you are able rolesÒ€™.5. Click
to complete the lab(s) and all other sections of the the Ò€˜ Add
exam in the time provided.Please note that once AssignmentsÒ€™
you submit your work by clicking the Next button button.6. Select
59 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
within a lab, you will NOT be able to return to the Billing
lab.You may now click next to proceed to the lab.Lab Administrator
information -Use the following login credentials as then click the Add
needed:To enter your username, place your cursor in button.Refer-
the Sign in box and click on the username below.To ence:https://docs.micro
enter your password, place your cursor in the Enter
password box and click on the password below.Mi-
crosoft 365 Username:admin@LODSe426243.onmi-
crosoft.comMicrosoft 365 Password: 3&YWyjse-6-dIf
the Microsoft 365 portal does not load successfully
in the browser, press CTRL-K to reload the portal
in a new browser tab.The following information is
for technical support purposes only:Lab Instance:
10887751 -You have a user named Grady Archie.
The solution must meet the following requirements:
Grady Archie must be able to add payment methods
to your Microsoft Office 365 tenant. The solution must
minimize the number of licenses assigned to users.
The solution must use the principle of least privilege.
167. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need
will not be deducted from your overall test time.When create a dynamic
the Next button is available, click it to access the group based on
lab section. In this section, you will perform a set of the city attribute.
tasks in a live environment. While most functionality You then need to
will be available to you as it would be in a live en- assign a license
vironment, some functionality (e.g., copy and paste, to the group. User
ability to navigate to external websites) will not be accounts with the
possible by design.Scoring is based on the outcome city attribute set to
of performing the tasks stated in the lab. In other Ò€˜
NewYork will
words, it doesn't matter how you accomplish the task, automatically be
if you successfully perform it, you will earn credit added to the
for that task.Labs are not timed separately, and this group. Anyone
exam may have more than one lab that you must who is added to
complete. You can use as much time as you would the group will
like to complete each lab. But, you should manage automatically be
your time appropriately to ensure that you are able assigned the
60 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
to complete the lab(s) and all other sections of the license that is
exam in the time provided.Please note that once assigned to the
you submit your work by clicking the Next button group.1. Go to the
within a lab, you will NOT be able to return to the Azure Active
lab.You may now click next to proceed to the lab.Lab Directory admin
information -Use the following login credentials as center.2. Select
needed:To enter your username, place your cursor in Azure Active
the Sign in box and click on the username below.To Directory then
enter your password, place your cursor in the Enter select Groups.3.
password box and click on the password below.Mi- Click on the New
crosoft 365 Username:admin@M365x981607.onmi- Group link.4. Give
crosoft.comMicrosoft 365 Password: *yfLo7Ir2&y-If the group a name
the Microsoft 365 portal does not load successfully such as New York
in the browser, press CTRL-K to reload the portal Users.5. Select
in a new browser tab.The following information is Users as the
for technical support purposes only:Lab Instance: membership
10811525 -Your organization plans to open an office type.6. Select
in New York, and then to add 100 users to the of- Ò€˜Add dynamic
fice. The city attribute for all new users will be New queryÒ€™.7.
York.You need to ensure that all the new users in the Select Ò€˜ CityÒ€™
New York office are licensed for Microsoft Office 365 in the Property
automatically. drop-down box.8.
Select
Ò€˜EqualsÒ€™in
the Operator
drop-down box.9.
Enter Ò€˜ New
YorkÒ€™as the
Value. You should
see the following
text in the
Expression box:
user.city -eq "New
York"10. Click
Save to create the
group.11. In the
Groups list, select
the new group to
open the
61 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
properties page
for the group.12.
Select
Ò€˜Licenses-
Ò€™.13. Select the
Ò€˜+
AssignmentsÒ€™
link.14. Tick the
box to select the
license.15. Click
the Save button to
save the
changes.Refer-
ences:https://docs.mic
168. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When assign the
the Next button is available, click it to access the Ò€˜
Password
lab section. In this section, you will perform a set of AdministratorÒ€™
tasks in a live environment. While most functionality role to Alex
will be available to you as it would be in a live en- Wilber. A user
vironment, some functionality (e.g., copy and paste, assigned the
ability to navigate to external websites) will not be Password
possible by design.Scoring is based on the outcome Administrator role
of performing the tasks stated in the lab. In other can reset
words, it doesn't matter how you accomplish the task, passwords for
if you successfully perform it, you will earn credit non-administra-
for that task.Labs are not timed separately, and this tors and
exam may have more than one lab that you must Password
complete. You can use as much time as you would administrators.1.
like to complete each lab. But, you should manage Go to the Azure
your time appropriately to ensure that you are able Active Directory
to complete the lab(s) and all other sections of the admin center.2.
exam in the time provided.Please note that once Select Users.3.
you submit your work by clicking the Next button Select the Alex
within a lab, you will NOT be able to return to the Wilber account to
lab.You may now click next to proceed to the lab.Lab open the account
62 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
information -Use the following login credentials as properties
needed:To enter your username, place your cursor in page.4. Select
the Sign in box and click on the username below.To Ò€˜
Assigned
enter your password, place your cursor in the Enter rolesÒ€™.5. Click
password box and click on the password below.Mi- the Ò€˜
Add
crosoft 365 Username:admin@M365x981607.onmi- AssignmentsÒ€™
crosoft.comMicrosoft 365 Password: *yfLo7Ir2&y-If button.6. Select
the Microsoft 365 portal does not load successfully Password
in the browser, press CTRL-K to reload the portal Administrator
in a new browser tab.The following information is then click the Add
for technical support purposes only:Lab Instance: button.Refer-
10811525 -Alex Wilber must be able to reset the pass- ences:https://docs.mic
word of each user in your organization. The solution
must prevent Alex Wilber from modifying the pass-
word of global administrators.
169. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.Debra will
will not be deducted from your overall test time.When need the Mail-
the Next button is available, click it to access the box Import Ex-
lab section. In this section, you will perform a set of port and Mail Re-
tasks in a live environment. While most functionality cipients roles to
will be available to you as it would be in a live en- be able to import
vironment, some functionality (e.g., copy and paste, PST files. These
ability to navigate to external websites) will not be roles cannot be
possible by design.Scoring is based on the outcome assigned directly
of performing the tasks stated in the lab. In other to a user account.
words, it doesn't matter how you accomplish the task, The way to as-
if you successfully perform it, you will earn credit sign just those two
for that task.Labs are not timed separately, and this roles to a user is to
exam may have more than one lab that you must create a new role
complete. You can use as much time as you would group, assign the
like to complete each lab. But, you should manage roles to the role
your time appropriately to ensure that you are able group and add the
to complete the lab(s) and all other sections of the user as a mem-
exam in the time provided.Please note that once ber.1. Go to the
you submit your work by clicking the Next button Exchange admin
within a lab, you will NOT be able to return to the center.2. Select
63 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
lab.You may now click next to proceed to the lab.Lab Permissions.3. In
information -Use the following login credentials as the Admin roles
needed:To enter your username, place your cursor in section, click the
the Sign in box and click on the username below.To plus (+) sign to
enter your password, place your cursor in the Enter create a new
password box and click on the password below.Mi- role.4. Give the
crosoft 365 Username:admin@M365x981607.onmi- role group a name
crosoft.comMicrosoft 365 Password: *yfLo7Ir2&y-If such as PST Im-
the Microsoft 365 portal does not load success- port.5. In the roles
fully in the browser, press CTRL-K to reload the section, click the
portal in a new browser tab.The following informa- plus (+) sign.6.
tion is for technical support purposes only:Lab In- Select the Mail-
stance: 10811525 -You plan to migrate data from an box Import Ex-
on-premises email system to your Microsoft 365 ten- port and Mail Re-
ant.You need to ensure that Debra Berger can import cipients roles and
a PST file. click Add to add
the roles.7. In the
Members section,
click the plus (+)
sign.8. Select De-
bra Berger then
click Add then Ok
to add Debra as
a member of the
new role group.9.
Click the Save but-
ton to save the
new role group.
64 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
than one correct solution, while others might not
have a correct solution.After you answer a question
in this section, you will NOT be able to return to it.
As a result, these questions will not appear in the
review screen.Your network contains an on-premis-
es Active Directory forest named contoso.com. The
forest contains the following domains: Contoso.com
East.contoso.comAn Azure AD Connect server is de-
ployed to contoso.com. Azure AD Connect syncs
to an Azure Active Directory (Azure AD) tenant.You
deploy a new domain named west.contoso.com to
the forest.You need to ensure that west.contoso.com
syncs to the Azure AD tenant.Solution: You create
an Azure DNS zone for west.contoso.com. On the
on-premises DNS servers, you create a conditional
forwarder for west.contoso.com.Does this meet the
goal?
A. Yes
B. No
174. You have a Microsoft 365 subscription that contains A. From the Azure
an Azure Active Directory (Azure AD) tenant named Active Directory
contoso.com.Corporate policy states that user pass- admin center, con-
words must not include the word Contoso.What figure the Pass-
should you do to implement the corporate policy? word protection
A. From the Azure Active Directory admin center, settings.
configure the Password protection settings.
B. From the Microsoft 365 admin center, configure the
Password policy settings.
C. From Azure AD Identity Protection, configure a
sign-in risk policy.
D. From the Azure Active Directory admin center, cre-
ate a conditional access policy.
65 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
176. https://gya- Correct Answer:
zo.com/b99b881425d6bb1865e0dd6d1ea23356 See explanation
below.You need
to configure the
Password Expira-
tion Policy.1. Sign
in to the Microsoft
365 Admin Cen-
ter.2. In the left
navigation pane,
expand the Set-
tings section then
select the Settings
option.3. Click on
Security and Pri-
vacy.4. Select the
Password Expira-
tion Policy.5. En-
sure that the
checkbox labelled
Ò€Set user pass-
words to expire af-
ter a number of
daysÒ€is ticked.6.
Enter 180 in
the Ò€Days before
passwords expire-
Ò€field.7. Click the
Ò€˜Save changes-
Ò€™button.
66 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
and add Adele
Vance to the
group. To ensure
that you can grant
permissions to the
Managers group,
the group needs
to be a Security
Group.1. Sign in to
the Microsoft 365
Admin Center.2. In
the left naviga-
tion pane, expand
the Groups sec-
tion then select
Groups.3. Click
the Ò€˜ Add a group-
Ò€™link.4. For the
group type, se-
lect Security and
click Next.5. En-
ter Ò€M̃anagers-
Ò€™in the Name
field and click
Next.6. Click the
Ò€˜Create Group-
Ò€™button to cre-
ate the Managers
group.7. In the
list of groups, se-
lect the Managers
group.8. Click the
Members link.9.
Click the Ò€˜ View
all and man-
age members link-
Ò€™.10. Click the
Ò€˜Add Members-
Ò€™button.11. Se-
67 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
lect Adele Vance
and click the Save
button.12. Click
the Close button
to close the group
page.
68 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Ò€Days before a
user is notified
about expirationÒ€
field.8. Click the
Ò€˜Save changes-
Ò€™button.
69 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
tains the following domains: Contoso.com East.con-
toso.comAn Azure AD Connect server is deployed to
contoso.com. Azure AD Connect syncs to an Azure
Active Directory (Azure AD) tenant.You deploy a new
domain named west.contoso.com to the forest.You
need to ensure that west.contoso.com syncs to the
Azure AD tenant.Solution: You install a new Azure
AD Connect server in west.contoso.com and set AD
Connect to staging mode.Does this meet the goal?
A. Yes
B. No
188. Your network contains a single Active Directory do- A. Deploy two
main and two Microsoft Azure Active Directory (Azure servers that run
AD) tenants.You plan to implement directory syn- Azure AD Con-
chronization for both Azure AD tenants. Each tenant nect, and then fil-
will contain some of the Active Directory users.You ter the users for
need to recommend a solution for the planned direc- each tenant by us-
70 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
tory synchronization.What should you include in the ing organization-
recommendation? al unit (OU)-based
A. Deploy two servers that run Azure AD Connect, filtering.
and then filter the users for each tenant by using
organizational unit (OU)-based filtering.
B. Deploy one server that runs Azure AD Connect,
and then specify two sync groups.
C. Deploy one server that runs Azure AD Connect,
and then filter the users for each tenant by using
organizational unit (OU)-based filtering.
D. Deploy one server that runs Azure AD Connect,
and then filter the users for each tenant by using
domain-based filtering.
191. You have a Microsoft 365 E5 subscription that is A. From the Azure
linked to an Azure Active Directory (Azure AD) tenant Active Directo-
named contoso.com.You purchase 100 Microsoft 365 ry admin center,
Business Voice add-on licenses.You need to ensure modify the set-
that the members of a group named Voice are as- tings of the Voice
signed a Microsoft 365 Business Voice add-on license group.
automatically.What should you do?
A. From the Azure Active Directory admin center,
modify the settings of the Voice group.
B. From the Microsoft 365 admin center, modify the
settings of the Voice group.
C. From the Licenses page of the Microsoft 365 admin
center, assign the licenses.
192. Your company has a Microsoft Azure Active Directory A. Security admin-
(Azure AD) tenant named contoso.onmicrosoft.com istrator
that contains a user named User1.You suspect that E. Reports reader
an imposter is signing in to Azure AD by using the F. Security reader
credentials of User1.You need to ensure that an ad-
ministrator named Admin1 can view all the sign in
71 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
details of User1 from the past 24 hours.To which three
roles should you add Admin1? Each correct answer
presents a complete solution.NOTE: Each correct se-
lection is worth one point.
A. Security administrator
B. Password administrator
C. User administrator
D. Compliance administrator
E. Reports reader
F. Security reader
193. You have Microsoft 365 tenant that contains a Mi- A. Environment
crosoft Power Platform environment named Environ- maker
ment1 (default). Environment1 contains a Microsoft-
Dataverse database.In the tenant, you create a user
named User1. You assign a Microsoft Power Apps li-
cense to User1.Which security role for Environment1
is assigned automatically to User1?
A. Environment maker
B. System customizer
C. Delegate
D. Environment admin
198. Your company recently purchased a Microsoft 365 C. From the Azure
subscription.You enable Microsoft Azure Multi-Factor Active Directory
Authentication (MFA) for all 500 users in the Azure admin center, use
72 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Active Directory (Azure AD) tenant.You need to gen- the Usage & in-
erate a report that lists all the users who completed sights blade.
the Azure MFA registration process.What is the best
approach to achieve the goal? More than one answer
choice may achieve the goal. Select the BEST answer.
A. From Azure Cloud Shell, run the Get-AzureADUser
cmdlet.
B. From Azure Cloud Shell, run the Get-MsolUser
cmdlet.
C. From the Azure Active Directory admin center, use
the Usage & insights blade.
D. From the Azure Active Directory admin center, use
the Risky sign-ins blade.
199. You have a Microsoft 365 Enterprise subscription.You B. From the Azure
have a conditional access policy to force multi-fac- Active Directory
tor authentication when accessing Microsoft Share- admin center, view
Point from a mobile device.You need to view which the user sign-ins.
users authenticated by using multi-factor authentica-
tion.What should you do?
A. From the Microsoft 365 admin center, view the
Security & Compliance reports.
B. From the Azure Active Directory admin center, view
the user sign-ins.
C. From the Microsoft 365 admin center, view the
Usage reports.
D. From the Azure Active Directory admin center, view
the audit logs.
73 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
201. Your network contains an on-premises Active Direc- B. From the Azure
tory domain named contoso.local. The domain con- portal, add a cus-
tains five domain controllers.Your company purchas- tom domain name.
es Microsoft 365 and creates a Microsoft Azure Ac- C. From Active Di-
tive Directory (Azure AD) tenant named contoso.on- rectory Domains
microsoft.com.You plan to install Azure AD connect and Trusts, add a
on a member server and implement pass-through UPN suffix.
authentication.You need to prepare the environment D. Modify the User
for the planned implementation of pass-through au- logon name for
thentication.Which three actions should you per- each user ac-
form? Each correct answer presents part of the solu- count.
tion.NOTE: Each correct selection is worth one point.
A. Modify the email address attribute for each user
account.
B. From the Azure portal, add a custom domain name.
C. From Active Directory Domains and Trusts, add a
UPN suffix.
D. Modify the User logon name for each user account.
E. From the Azure portal, configure an authentication
method.
F. From a domain controller, install an Authentication
Agent.
76 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
207. You have a Microsoft 365 subscription.Your company A. From all the AD
deploys an Active Directory Federation Services (AD FS servers, run
FS) solution.You need to configure the environment auditpol.exe.
to audit AD FS user authentication.Which two actions E. On an AD
should you perform? Each correct answer presents FS server, install
part of the solution.NOTE: Each correct selection is Azure AD Connect
worth one point. Health for AD FS.
A. From all the AD FS servers, run auditpol.exe.
B. From all the domain controllers, run the Set-Ad-
minAuditLogConfig cmdlet and specify the Ò€"-
LogLevel parameter.
C. On a domain controller, install Azure AD Connect
Health for AD DS.
D. From the Azure AD Connect server, run the Regis-
ter-AzureADConnectHealthSyncAgent cmdlet.
E. On an AD FS server, install Azure AD Connect
Health for AD FS.
77 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
A. Yes
B. No
210. You have a Microsoft 365 subscription that uses an C. From the Azure
Azure Active Directory (Azure AD) tenant named con- Active Directory
toso.com.A temporary employee at your company admin center, cre-
uses an email address of user1@outlook.com.You ate a new guest
need to ensure that the temporary employee can sign user.
in to contoso.com by using the user1@outlook.com
account.What should you do?
A. From the Azure Active Directory admin center,
create a new user.
B. From the Microsoft 365 admin center, create a new
contact.
C. From the Azure Active Directory admin center,
create a new guest user.
78 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
D. From the Microsoft 365 admin center, create a new
user.
211. Your company has an Azure Active Directory (Azure D. From the Azure
AD) tenant named contoso.com that contains 10,000 Active Directory
users.The company has a Microsoft 365 subscrip- admin center, con-
tion.You enable Azure Multi-Factor Authentication figure the diag-
(MFA) for all the users in contoso.com.You run the nostics settings to
following query.search "SigninLogs" | where Result- send logs to an
Description == "User did not pass the MFA chal- Azure Log Analyt-
lenge."The query returns blank results.You need ics workspace.
to ensure that the query returns the expected re-
sults.What should you do?
A. From the Azure Active Directory admin center,
configure the diagnostics settings to archive logs to
an Azure Storage account.
B. From the Security & Compliance admin center, turn
on auditing.
C. From the Security & Compliance admin center,
enable Office 365 Analytics.
D. From the Azure Active Directory admin center,
configure the diagnostics settings to send logs to an
Azure Log Analytics workspace.
212. Your company has a Microsoft 365 subscription B. Enable the re-
that has multi-factor authentication configured for all member multi-fac-
users.Users that connect to Microsoft 365 services tor authentication
report that they are prompted for multi-factor authen- setting, and then
tication multiple times a day.You need to reduce the verify each device
number of times the users are prompted for multi-fac- as a trusted de-
tor authentication on their company-owned devices. vice.
Your solution must ensure that users are still prompt-
ed for MFA.What should you do?
A. Enable the multi-factor authentication trusted IPs
setting, and then verify each device as a trusted de-
vice.
B. Enable the remember multi-factor authentication
setting, and then verify each device as a trusted de-
vice.
79 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
C. Enable the multi-factor authentication trusted IPs
setting, and then join all client computers to Microsoft
Azure Active Directory (Azure AD).
D. Enable the remember multi-factor authentication
setting, and then join all client computers to Microsoft
Azure Active Directory (Azure AD).
213. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When add gmail.com as
the Next button is available, click it to access the a denied domain
lab section. In this section, you will perform a set of in the Ò€˜External
tasks in a live environment. While most functionality collaboration
will be available to you as it would be in a live en- settingsÒ€™.1. Go
vironment, some functionality (e.g., copy and paste, to the Azure
ability to navigate to external websites) will not be Active Directory
possible by design.Scoring is based on the outcome admin center.2.
of performing the tasks stated in the lab. In other Select Users then
words, it doesn't matter how you accomplish the task, select Ò€˜ User
if you successfully perform it, you will earn credit settingsÒ€™.3.
for that task.Labs are not timed separately, and this Under External
exam may have more than one lab that you must Users, select the
complete. You can use as much time as you would Ò€M̃anage
like to complete each lab. But, you should manage external
your time appropriately to ensure that you are able collaboration
to complete the lab(s) and all other sections of the settingsÒ€™.4.
exam in the time provided.Please note that once Under
you submit your work by clicking the Next button Ò€˜
Collaboration
within a lab, you will NOT be able to return to the restrictionsÒ€™,
lab.You may now click next to proceed to the lab.Lab select the Ò€˜ Deny
information -Use the following login credentials as invitations to the
needed:To enter your username, place your cursor in specified
the Sign in box and click on the username below.To domainsÒ€™
enter your password, place your cursor in the Enter option.5. Under,
password box and click on the password below.Mi- Target Domains,
crosoft 365 Username:admin@LODSe426243.onmi- type in the domain
crosoft.comMicrosoft 365 Password: 3&YWyjse-6-dIf name
the Microsoft 365 portal does not load successfully Ò€˜ gmail.comÒ€™6.
80 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
in the browser, press CTRL-K to reload the portal Click the Save
in a new browser tab.The following information is button at the top
for technical support purposes only:Lab Instance: of the screen to
10887751 -You plan to allow the users in your orga- save your
nization to invite external users as guest users to changes.Refer-
your Microsoft 365 tenant.You need to prevent the ences:https://docs.mic
organization's users from inviting guests who have
an email address that uses a suffix of @gmail.com.
214. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When assign the Glob-
the Next button is available, click it to access the al Admin role to
lab section. In this section, you will perform a set of Irvin Sayers. You
tasks in a live environment. While most functionality then need to con-
will be available to you as it would be in a live en- figure the account
vironment, some functionality (e.g., copy and paste, to require Mul-
ability to navigate to external websites) will not be ti-Factor Authen-
possible by design.Scoring is based on the outcome tication (MFA).1.
of performing the tasks stated in the lab. In other In the Microsoft
words, it doesn't matter how you accomplish the task, 365 admin cen-
if you successfully perform it, you will earn credit ter, select Users
for that task.Labs are not timed separately, and this then select Active
exam may have more than one lab that you must Users.2. Select
complete. You can use as much time as you would the Irvin Sayers
like to complete each lab. But, you should manage account to open
your time appropriately to ensure that you are able the account prop-
to complete the lab(s) and all other sections of the erties blade.3. In
exam in the time provided.Please note that once the Roles sec-
you submit your work by clicking the Next button tion, click on the
within a lab, you will NOT be able to return to the Ò€M̃anage roles-
lab.You may now click next to proceed to the lab.Lab Ò€™link.4. Se-
information -Use the following login credentials as lect the Ò€˜ Ad-
needed:To enter your username, place your cursor in min center ac-
the Sign in box and click on the username below.To cessÒ€™option.5.
enter your password, place your cursor in the Enter Select Global Ad-
password box and click on the password below.Mi- ministrator then
crosoft 365 Username:admin@LODSe426243.onmi- click the Ò€˜ Save
81 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
crosoft.comMicrosoft 365 Password: 3&YWyjse-6-dIf changesÒ€™but-
the Microsoft 365 portal does not load successfully ton.The next step
in the browser, press CTRL-K to reload the portal is to enable the
in a new browser tab.The following information is account for Mul-
for technical support purposes only:Lab Instance: ti-Factor Authenti-
10887751 -You hire a new global administrator named cation (MFA).1. If
Irvin Sayers to manage your Microsoft 365 tenant.You the Irvin Sayers
need to modify Irvin Sayers to meet the following account is select-
requirements: Uses at least two methods of user ed in the user ac-
authentication Has the highest Microsoft Office 365 counts list, des-
administrative privileges elect it (click on
the tick icon next
to the account
name). Selecting
a user account
changes the menu
options at the top
of the page; de-
selecting the ac-
counts changes
the menu op-
tions back.2. Click
on the Ò€M̃ulti-fac-
tor authentication-
Ò€™link at the
top of the page.3.
In the Ò€M̃ulti-fac-
tor authentication-
Ò€™page, select
the Irvin Sayers
account.4. Click
the Ò€˜EnableÒ€™
link on the right
side of the page.5.
In the pop-up win-
dow, click the Ò€˜-
enable multi-factor
authÒ€™button.
82 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
215. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When register App1 in
the Next button is available, click it to access the Azure Active
lab section. In this section, you will perform a set of Directory.1. Go to
tasks in a live environment. While most functionality the Azure Active
will be available to you as it would be in a live en- Directory admin
vironment, some functionality (e.g., copy and paste, center.2. Select
ability to navigate to external websites) will not be Azure Active
possible by design.Scoring is based on the outcome Directory.3.
of performing the tasks stated in the lab. In other Select Ò€˜ App
words, it doesn't matter how you accomplish the task, registrations-
if you successfully perform it, you will earn credit Ò€™.4. Click the
for that task.Labs are not timed separately, and this Ò€˜ New
exam may have more than one lab that you must registrationÒ€™
complete. You can use as much time as you would link.5. Enter the
like to complete each lab. But, you should manage name App1.6.
your time appropriately to ensure that you are able Click the Register
to complete the lab(s) and all other sections of the button.7. To add
exam in the time provided.Please note that once the URL to App1,
you submit your work by clicking the Next button select App1 in the
within a lab, you will NOT be able to return to the list of registered
lab.You may now click next to proceed to the lab.Lab apps.8. In the
information -Use the following login credentials as properties page of
needed:To enter your username, place your cursor in App1, select
the Sign in box and click on the username below.To Branding.9. Enter
enter your password, place your cursor in the Enter the URL
password box and click on the password below.Mi- https://app1.con-
crosoft 365 Username:admin@LODSe426243.onmi- toso.com in the
crosoft.comMicrosoft 365 Password: 3&YWyjse-6-dIf Ò€˜ Home page
the Microsoft 365 portal does not load successfully URLÒ€™box.10.
in the browser, press CTRL-K to reload the portal Click Save to save
in a new browser tab.The following information is the
for technical support purposes only:Lab Instance: changes.Refer-
10887751 -Your company has a web application ences:https://docs.mic
named App1.The company plans to publish App1 by
using a URL of https://app1.contoso.com.You need to
register App1 to your Microsoft Office 365 tenant.
83 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
216. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When create a guest
the Next button is available, click it to access the account for the
lab section. In this section, you will perform a set of external user.1.
tasks in a live environment. While most functionality Go to the Azure
will be available to you as it would be in a live en- Active Directory
vironment, some functionality (e.g., copy and paste, admin center.2.
ability to navigate to external websites) will not be Select Users.3.
possible by design.Scoring is based on the outcome Click the Ò€˜ New
of performing the tasks stated in the lab. In other guest userÒ€™
words, it doesn't matter how you accomplish the task, link.4. Select the
if you successfully perform it, you will earn credit Ò€˜Invite userÒ€™
for that task.Labs are not timed separately, and this option.5. Give the
exam may have more than one lab that you must account a name
complete. You can use as much time as you would and enter
like to complete each lab. But, you should manage fabrika-
your time appropriately to ensure that you are able muser@fab-
to complete the lab(s) and all other sections of the rikam.com in the
exam in the time provided.Please note that once email address
you submit your work by clicking the Next button field.6. Click the
within a lab, you will NOT be able to return to the Ò€˜InviteÒ€™
lab.You may now click next to proceed to the lab.Lab button.Refer-
information -Use the following login credentials as ences:https://docs.mic
needed:To enter your username, place your cursor in
the Sign in box and click on the username below.To
enter your password, place your cursor in the Enter
password box and click on the password below.Mi-
crosoft 365 Username:admin@LODSe426243.onmi-
crosoft.comMicrosoft 365 Password: 3&YWyjse-6-dIf
the Microsoft 365 portal does not load successfully
in the browser, press CTRL-K to reload the portal
in a new browser tab.The following information is
for technical support purposes only:Lab Instance:
10887751 -You plan to provide an external user
named fabrikamuser@fabrikam.com with access to
several resources in your Microsoft 365 tenant.You
84 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
need to ensure that the external user can be added to
Office 365 groups.
217. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When modify the default
the Next button is available, click it to access the mobile device
lab section. In this section, you will perform a set of mailbox policy.1.
tasks in a live environment. While most functionality Go to the
will be available to you as it would be in a live en- Exchange Admin
vironment, some functionality (e.g., copy and paste, Center.2. Select
ability to navigate to external websites) will not be Ò€m̃obileÒ€™then
possible by design.Scoring is based on the outcome select Ò€m̃obile
of performing the tasks stated in the lab. In other device mailbox
words, it doesn't matter how you accomplish the task, policiesÒ€™.3.
if you successfully perform it, you will earn credit Click the Ò€˜
Create
for that task.Labs are not timed separately, and this a policyÒ€™
exam may have more than one lab that you must button.4. Select
complete. You can use as much time as you would the Default policy
like to complete each lab. But, you should manage and click the edit
your time appropriately to ensure that you are able icon (pencil
to complete the lab(s) and all other sections of the icon).5. Select the
exam in the time provided.Please note that once Ò€˜
SecurityÒ€™link
you submit your work by clicking the Next button to open the
within a lab, you will NOT be able to return to the security
lab.You may now click next to proceed to the lab.Lab settings.6. Tick
information -Use the following login credentials as the Ò€˜ Require a
needed:To enter your username, place your cursor in passwordÒ€™
the Sign in box and click on the username below.To checkbox.7. Tick
enter your password, place your cursor in the Enter the Ò€˜ Require
password box and click on the password below.Mi- encryption on
crosoft 365 Username:admin@LODSe426243.onmi- deviceÒ€™
crosoft.comMicrosoft 365 Password: 3&YWyjse-6-dIf checkbox.8. Click
the Microsoft 365 portal does not load successfully the Save button to
in the browser, press CTRL-K to reload the portal save the
in a new browser tab.The following information is changes.Refer-
for technical support purposes only:Lab Instance: ences:https://docs.mic
10887751 -You need to ensure that all mobile devices
85 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
that connect to Microsoft Exchange Online meet the
following requirements: A password must be used
to access the devices. Data on the devices must be
encrypted.
218. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When add contoso.com
the Next button is available, click it to access the as an allowed
lab section. In this section, you will perform a set of domain in the
tasks in a live environment. While most functionality Ò€˜ External
will be available to you as it would be in a live en- collaboration
vironment, some functionality (e.g., copy and paste, settingsÒ€™.1. Go
ability to navigate to external websites) will not be to the Azure
possible by design.Scoring is based on the outcome Active Directory
of performing the tasks stated in the lab. In other admin center.2.
words, it doesn't matter how you accomplish the task, Select Users then
if you successfully perform it, you will earn credit select Ò€˜
User
for that task.Labs are not timed separately, and this settingsÒ€™.3.
exam may have more than one lab that you must Under External
complete. You can use as much time as you would Users, select the
like to complete each lab. But, you should manage Ò€M̃anage
your time appropriately to ensure that you are able external
to complete the lab(s) and all other sections of the collaboration
exam in the time provided.Please note that once settingsÒ€™.4.
you submit your work by clicking the Next button Under
within a lab, you will NOT be able to return to the Ò€˜
Collaboration
lab.You may now click next to proceed to the lab.Lab restrictionsÒ€™,
information -Use the following login credentials as select the Ò€˜ Allow
needed:To enter your username, place your cursor in invitations only to
the Sign in box and click on the username below.To the specified
enter your password, place your cursor in the Enter domains (most
password box and click on the password below.Mi- restrictive)Ò€™
crosoft 365 Username:admin@M365x981607.onmi- option.5. Under,
crosoft.comMicrosoft 365 Password: *yfLo7Ir2&y-If Target Domains,
the Microsoft 365 portal does not load successfully type in the domain
in the browser, press CTRL-K to reload the portal name
in a new browser tab.The following information is Ò€˜
contoso.com-
86 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
for technical support purposes only:Lab Instance: Ò€™6. Click the
10811525 -You plan to invite several guest users to Save button at the
access the resources in your organization.You need top of the screen
to ensure that only guests who have an email address to save your
that uses the @contoso.com suffix can connect to changes.Refer-
the resources in your Microsoft 365 tenant. ences:https://docs.mic
219. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need
will not be deducted from your overall test time.When to configure the
the Next button is available, click it to access the App Registrations
lab section. In this section, you will perform a set of setting in Azure
tasks in a live environment. While most functionality Active Directory.1.
will be available to you as it would be in a live en- Go to the Azure
vironment, some functionality (e.g., copy and paste, Active Directory
ability to navigate to external websites) will not be admin center.2.
possible by design.Scoring is based on the outcome Select Azure Ac-
of performing the tasks stated in the lab. In other tive Directory.3.
words, it doesn't matter how you accomplish the task, Select Ò€˜ User set-
if you successfully perform it, you will earn credit tingsÒ€™4. In the
for that task.Labs are not timed separately, and this Ò€˜ App registra-
exam may have more than one lab that you must tionsÒ€™section,
complete. You can use as much time as you would toggle the Ò€˜ Users
like to complete each lab. But, you should manage can register ap-
your time appropriately to ensure that you are able plicationsÒ€™set-
to complete the lab(s) and all other sections of the ting to No.5. Click
exam in the time provided.Please note that once Save to save the
you submit your work by clicking the Next button changes.
within a lab, you will NOT be able to return to the
lab.You may now click next to proceed to the lab.Lab
information -Use the following login credentials as
needed:To enter your username, place your cursor in
the Sign in box and click on the username below.To
enter your password, place your cursor in the Enter
password box and click on the password below.Mi-
crosoft 365 Username:admin@M365x981607.onmi-
crosoft.comMicrosoft 365 Password: *yfLo7Ir2&y-If
the Microsoft 365 portal does not load successfully
87 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
in the browser, press CTRL-K to reload the portal
in a new browser tab.The following information is
for technical support purposes only:Lab Instance:
10811525 -You need to prevent non-administrators in
your organization from registering applications.
220. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When create a guest
the Next button is available, click it to access the account for
lab section. In this section, you will perform a set of user1.1. Go to the
tasks in a live environment. While most functionality Azure Active
will be available to you as it would be in a live en- Directory admin
vironment, some functionality (e.g., copy and paste, center.2. Select
ability to navigate to external websites) will not be Users.3. Click the
possible by design.Scoring is based on the outcome Ò€˜ New guest
of performing the tasks stated in the lab. In other userÒ€™link.4.
words, it doesn't matter how you accomplish the task, Select the Ò€˜ Invite
if you successfully perform it, you will earn credit userÒ€™option.5.
for that task.Labs are not timed separately, and this Give the account
exam may have more than one lab that you must a name (User1)
complete. You can use as much time as you would and enter
like to complete each lab. But, you should manage user1@fab-
your time appropriately to ensure that you are able rikam.com in the
to complete the lab(s) and all other sections of the email address
exam in the time provided.Please note that once field.6. Click the
you submit your work by clicking the Next button Ò€˜InviteÒ€™
within a lab, you will NOT be able to return to the button.Refer-
lab.You may now click next to proceed to the lab.Lab ences:https://docs.mic
information -Use the following login credentials as
needed:To enter your username, place your cursor in
the Sign in box and click on the username below.To
enter your password, place your cursor in the Enter
password box and click on the password below.Mi-
crosoft 365 Username:admin@M365x981607.onmi-
crosoft.comMicrosoft 365 Password: *yfLo7Ir2&y-If
the Microsoft 365 portal does not load successfully
in the browser, press CTRL-K to reload the portal
88 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
in a new browser tab.The following information is
for technical support purposes only:Lab Instance:
10811525 -Your organization recently partnered with
another organization named Fabrikam, Inc.You plan
to provide a Microsoft 365 license to an external user
named user1@fabrikam.com, and then to share doc-
uments with the user.You need to invite user1@fab-
rikam.com to access your organization.
221. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When configure the
the Next button is available, click it to access the device settings in
lab section. In this section, you will perform a set of Azure Active
tasks in a live environment. While most functionality Directory.1. Go to
will be available to you as it would be in a live en- the Azure Active
vironment, some functionality (e.g., copy and paste, Directory admin
ability to navigate to external websites) will not be center.2. Select
possible by design.Scoring is based on the outcome Azure Active
of performing the tasks stated in the lab. In other Directory.3.
words, it doesn't matter how you accomplish the task, Select Devices.4.
if you successfully perform it, you will earn credit Select Device
for that task.Labs are not timed separately, and this Settings.5. Toggle
exam may have more than one lab that you must the Ò€˜
Require
complete. You can use as much time as you would Multi-Factor Auth
like to complete each lab. But, you should manage to join devicesÒ€™
your time appropriately to ensure that you are able setting to Yes.6.
to complete the lab(s) and all other sections of the Click Save to save
exam in the time provided.Please note that once the
you submit your work by clicking the Next button changes.Refer-
within a lab, you will NOT be able to return to the ences:https://docs.mic
lab.You may now click next to proceed to the lab.Lab
information -Use the following login credentials as
needed:To enter your username, place your cursor in
the Sign in box and click on the username below.To
enter your password, place your cursor in the Enter
password box and click on the password below.Mi-
crosoft 365 Username:admin@M365x981607.onmi-
89 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
crosoft.comMicrosoft 365 Password: *yfLo7Ir2&y-If
the Microsoft 365 portal does not load successfully
in the browser, press CTRL-K to reload the portal
in a new browser tab.The following information is
for technical support purposes only:Lab Instance:
10811525 -You plan to provide several users in your
organization with the ability to join their Windows
10 device to Microsoft Azure Active Directory (Azure
AD).You need to ensure that all the users who join a
device use multi-factor authentication.
Reveal Solution Discussion 3
222. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When configure the Ex-
the Next button is available, click it to access the ternal Communi-
lab section. In this section, you will perform a set of cations settings in
tasks in a live environment. While most functionality the Skype for
will be available to you as it would be in a live en- Business admin
vironment, some functionality (e.g., copy and paste, center.1. You need
ability to navigate to external websites) will not be to go to the Skype
possible by design.Scoring is based on the outcome for Business ad-
of performing the tasks stated in the lab. In other min center. If you
words, it doesn't matter how you accomplish the task, see a Skype for
if you successfully perform it, you will earn credit Business admin
for that task.Labs are not timed separately, and this center in the ad-
exam may have more than one lab that you must min center list in
complete. You can use as much time as you would the Microsoft por-
like to complete each lab. But, you should manage tal, open it and
your time appropriately to ensure that you are able skip to step 4.2.
to complete the lab(s) and all other sections of the If you donÒ€™ t see
exam in the time provided.Please note that once a Skype for Busi-
you submit your work by clicking the Next button ness admin cen-
within a lab, you will NOT be able to return to the ter in the admin
lab.You may now click next to proceed to the lab.Lab center list in the
information -Use the following login credentials as Microsoft portal,
needed:To enter your username, place your cursor in open the Teams
the Sign in box and click on the username below.To admin center.3. In
90 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
enter your password, place your cursor in the Enter the Teams admin
password box and click on the password below.Mi- center, choose
crosoft 365 Username:admin@M365x981607.onmi- Skype > Lega-
crosoft.comMicrosoft 365 Password: *yfLo7Ir2&y-If cy Portal.4. In the
the Microsoft 365 portal does not load successfully Skype for Busi-
in the browser, press CTRL-K to reload the portal ness admin cen-
in a new browser tab.The following information is ter, select Orga-
for technical support purposes only:Lab Instance: nization.5. Select
10811525 -You need to prevent the users in your orga- External commu-
nization from establishing voice calls from Microsoft nications.6. Untick
Skype for Business to external Skype users. the Ò€˜Let peo-
ple use Skype
for Business to
communicate with
Skype users out-
side your organi-
zationÒ€™check-
box.7. Click Save
to save the
changes.
225. Your company has three main offices and one branch A. Microsoft Azure
office. The branch office is used for research.The Active Directory
company plans to implement a Microsoft 365 tenant (Azure AD) condi-
and to deploy multi-factor authentication.You need to tional access.
recommend a Microsoft 365 solution to ensure that
multi-factor authentication is enforced only for users
in the branch office.What should you include in the
recommendation?
A. Microsoft Azure Active Directory (Azure AD) con-
ditional access.
B. Microsoft Azure Active Directory (Azure AD) pass-
word protection.
92 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
C. A Microsoft Endpoint Manager device compliance
policy.
D. A Microsoft Endpoint Manager device configura-
tion profile.
93 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
ment. The solution must meet the following require-
ments: Users must be able to authenticate during
business hours only. Authentication requests must
be processed successfully if a single server fails.
When the password for an on-premises user account
expires, the new password must be enforced the next
time the user signs in. Users who connect to Office
365 services from domain-joined devices that are
connected to the internal network must be signed in
automatically.Solution: You design an authentication
strategy that uses federation authentication by using
Active Directory Federation Services (AD FS). The
solution contains two AD FS servers and two Web
Application Proxies.Does this meet the goal?
A. Yes
B. No
94 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
230. Your network contains an on-premises Active Di- A. From a do-
rectory domain.You have a Microsoft 365 subscrip- main controller, in-
tion.You implement a directory synchronization solu- stall the Azure AD
tion that uses pass-through authentication.You con- Password Protec-
figure Microsoft Azure Active Directory (Azure AD) tion Proxy.
smart lockout as shown in the following exhibit.You D. From Pass-
discover that Active Directory users can use the word protection for
passwords in the custom banned passwords list.You Windows Server
need to ensure that banned passwords are effective Active Directory,
for all users.Which three actions should you per- modify the Mode
form? Each correct answer presents part of the solu- setting.
tion.NOTE: Each correct selection is worth one point. E. From all the do-
A. From a domain controller, install the Azure AD main controllers,
Password Protection Proxy. install the Azure
B. From a domain controller, install the Microsoft AAD AD Password Pro-
Application Proxy connector. tection DC Agent.
C. From Custom banned passwords, modify the En-
force custom list setting.
D. From Password protection for Windows Server Ac-
tive Directory, modify the Mode setting.
E. From all the domain controllers, install the Azure
AD Password Protection DC Agent.
F. From Active Directory, modify the Default Domain
Policy.
Reveal Solution Discussion 12
237. Your company has a Microsoft 365 subscription and C. From the Azure
a Microsoft Azure Active Directory (Azure AD) tenant portal, add a
named contoso.onmicrosoft.com.An external vendor new guest user,
has a Microsoft account that has a username of and then spec-
user1@outlook.com.You plan to provide user1@out- ify user1@out-
look.com with access to several resources in the sub- look.com as the
scription.You need to add the external user account email address.
98 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
to contoso.onmicrosoft.com. The solution must en-
sure that the external vendor can authenticate by
using user1@outlook.com.What should you do?
A. From Azure Cloud Shell, run the New-AzureADUser
cmdlet and specify Ò€"UserPrincipalName user1@out-
look.com.
B. From the Microsoft 365 admin center, add a con-
tact, and then specify user1@outlook.com as the
email address.
C. From the Azure portal, add a new guest user, and
then specify user1@outlook.com as the email ad-
dress.
D. From the Azure portal, add a custom domain
name, and then create a new Azure AD user and use
user1@outlook.com as the username.
238. You have a Microsoft 365 subscription that contains D. From the Share-
several Microsoft SharePoint Online sites.You dis- Point admin cen-
cover that users from your company can invite exter- ter, configure the
nal users to access files on the SharePoint sites.You sharing settings.
need to ensure that the company users can invite only Reveal Solution
authenticated guest users to the sites.What should Discussion 7
you do?
A. From the Microsoft 365 admin center, configure a
partner relationship.
B. From SharePoint Online Management Shell, run
the Set-SPOSite cmdlet.
C. From the Azure Active Directory admin center,
configure a conditional access policy.
D. From the SharePoint admin center, configure the
sharing settings.
Reveal Solution Discussion 7
239. Your network contains an on-premises Active Direc- D. Modify the In-
tory domain. The domain contains 2,000 computers tranet zone set-
that run Windows 10.You purchase a Microsoft 365 tings by using
subscription.You implement password hash synchro- Group Policy
nization and Azure Active Directory (Azure AD) Seam-
less Single Sign-On (Seamless SSO).You need to en-
99 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
sure that users can use Seamless SSO from the Win-
dows 10 computers.What should you do?
A. Create a conditional access policy in Azure AD.
B. Deploy an Azure AD Connect staging server.
C. Join the computers to Azure AD.
D. Modify the Intranet zone settings by using Group
Policy
246. https://gyazo.com/6ad727b1a84cd3caf7b2fd- B. No
fde6b58142
100 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
247. https://gya- B. No
zo.com/95f9ec2c95086e466a4eb0296e508432
248. https://gya- B. No
zo.com/221ef94752c1cafd71bcd00ee26ae57d
251. You have a Microsoft 365 E5 subscription.You need C. From the Azure
to ensure that users are prompted for multi-factor Active Directory
authentication (MFA) when they attempt to access admin center, cre-
Microsoft SharePoint Online resources. Users must ate a conditional
NOT be prompted for MFA when they attempt to ac- access policy.
cess other Microsoft 365 services.What should you
do?
A. From the Microsoft Endpoint Manager admin cen-
ter, create an app protection policy.
B. From the multi-factor authentication page, config-
ure the users settings.
C. From the Azure Active Directory admin center,
create a conditional access policy.
D. From the Cloud App Security admin center, create
an app access policy.
102 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
need to prevent users from accessing your Microsoft
SharePoint Online sites unless the users are con-
nected to your on-premises network.Solution: From
the Device Management admin center, you a trusted
location and compliance policy.Does this meet the
goal?
A. Yes
B. No
103 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
From the Azure Active Directory admin center, you
create a trusted location and a conditional access
policy.Does this meet the goal?
A. Yes
B. No
261. You have a Microsoft 365 subscription.You register D. From the Azure
two applications named App1 and App2 to Azure Active Directory
Active Directory (Azure AD).You need to ensure admin center, cre-
that users who connect to App1 require multi-fac- ate a conditional
tor authentication (MFA). MFA is required only for access policy.
App1.What should you do?
A. From the Microsoft 365 admin center, configure the
Modern authentication settings.
B. From Multi-Factor Authentication, configure the
service settings.
C. From the Enterprise applications blade of the
Azure Active Directory admin center, configure the
Users settings.
D. From the Azure Active Directory admin center, cre-
ate a conditional access policy.
265. You create a Microsoft 365 Enterprise subscrip- A. From your com-
tion.You assign licenses for all products to all puter, run set-
users.You need to prepare the environment to ensure up.exe /down-
that all Microsoft 365 Apps for enterprise installations load download-
occur from a network share. The solution must pre- config.xml.
vent the users from installing Microsoft 365 Apps for B. Create an XML
enterprise from the Internet.You download the Office download file.
Deployment Tool (ODT).Which three actions should E. From the Mi-
you perform? Each correct answer presents part of crosoft 365 ad-
the solution.NOTE: Each correct selection is worth min center, con-
one point. figure the Soft-
A. From your computer, run setup.exe /download ware download
downloadconfig.xml. settings.
B. Create an XML download file.
C. From the Microsoft 365 admin center, deactivate
the Office 365 licenses for all the users.
D. From each client computer, run setup.exe /config-
ure installconfig.xml.
E. From the Microsoft 365 admin center, configure the
Software download settings.
267. Your on-premises network contains five file servers. D. Run the Share-
The file servers host shares that contain user Point Migration
data.You plan to migrate the user data to a Microsoft Tool.
365 subscription.You need to recommend a solution
105 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
to import the user data into Microsoft OneDrive.What
should you include in the recommendation?
A. Configure the settings of the OneDrive client on
your Windows 10 device.
B. Configure the Sync settings in the OneDrive admin
center.
C. Run the SharePoint Hybrid Configuration Wizard.
D. Run the SharePoint Migration Tool.
268. Your network contains two Active Directory forests. D. a new service
Each forest contains two domains.You plan to con- connection point
figure Hybrid Azure AD join for the computers.You (SCP) for each for-
create a Microsoft Azure Active Directory (Azure AD) est
tenant.You need to ensure that the computers can
discover the Azure AD tenant.What should you cre-
ate?
A. a new computer account for each computer
B. a new service connection point (SCP) for each
domain
C. a new trust relationship for each forest
D. a new service connection point (SCP) for each
forest
106 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
correct answer presents a complete solution.NOTE:
Each correct selection is worth one point.
A. Users must have a single SharePoint profile for
both on-premises and on the cloud.
B. OneDrive sites must redirect users to online con-
tent.
C. Users must be able to follow both on-premises and
cloud-based sites.
D. When users search for a document by us-
ing keywords, the results must include online and
on-premises results.
Reveal Solution Discussion 8
273. B. No
107 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Note: This question is part of a series of questions
that present the same scenario. Each question in the
series contains a unique solution that might meet the
stated goals. Some question sets might have more
than one correct solution, while others might not
have a correct solution.After you answer a question
in this section, you will NOT be able to return to it.
As a result, these questions will not appear in the
review screen.Your company has a main office and
three branch offices. All the branch offices connect to
the main office by using a WAN link. The main office
has a high-speedInternet connection. All the branch
offices connect to the Internet by using the main
office connection.Users use Microsoft Outlook 2016
to connect to a Microsoft Exchange Server mailbox
hosted in the main office.The users report that when
the WAN link in their office becomes unavailable, they
cannot access their mailbox.You create a Microsoft
365 subscription, and then migrate all the user data
to Microsoft 365.You need to ensure that all the users
can continue to use Outlook to receive email mes-
sages if a WAN link fails.Solution: You enable Cached
Exchange Mode for all the Outlook profiles.Does this
meet the goal?
A. Yes
B. No
109 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
create the chan-
nel.
278. Your company has a Microsoft Azure Active Directo- D. Instruct all the
ry (Azure AD) directory tenant named contoso.onmi- users to log off
crosoft.com.All users have client computers that run of their computer,
Windows 10 Pro and are joined to Azure AD.The com- and then to log in
pany purchases a Microsoft 365 E3 subscription.You again.
need to upgrade all the computers to Windows 10
111 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Enterprise. The solution must minimize administra-
tive effort.You assign licenses from the Microsoft 365
admin center.What should you do next?
A. Add a custom domain name to the subscription.
B. Deploy Windows 10 Enterprise by using Windows
Autopilot.
C. Create a provisioning package, and then deploy the
package to all the computers.
D. Instruct all the users to log off of their computer,
and then to log in again.
280. You have Windows 10 devices that are managed by B. an app configu-
using Microsoft Endpoint Manager. All the devices ration policy
have Microsoft Office 365 apps installed.You need to
configure the proofing tool settings for the Office 365
apps.From the Microsoft Endpoint Manager admin
center, what should you create?
A. a device compliance policy
B. an app configuration policy
C. an app
D. a device configuration profile
112 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
access to App1 is revoked for users who no longer
require viewing the processed financial data.What
should you configure?
A. an owner
B. an app protection policy
C. an access review
D. a conditional access policy
116 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
for external access to the application. The solution B. From the Azure
must support multi-factor authentication.Which two Active Directory
actions should you recommend? Each correct an- admin center, en-
swer presents part of the solution.NOTE: Each cor- able an Applica-
rect selection is worth one point. tion Proxy.
A. From an on-premises server, install a connector,
and then publish the app.
B. From the Azure Active Directory admin center,
enable an Application Proxy.
C. From the Azure Active Directory admin center,
create a conditional access policy.
D. From an on-premises server, install an Authentica-
tion Agent.
E. Republish the web application by using
https://app.contoso.com.
300. You have a Microsoft 365 subscription.From the Se- A. an export key
curity & Compliance admin center, you create a con-
tent search of all the mailboxes that contain the word
ProjectX.You need to export the results of the content
search.What do you need to download the report?
A. an export key
B. a password
C. a user certificate
D. a certification authority (CA) certificate
302. You have a Microsoft 365 subscription that contains C. Modify the Re-
a user named User1.You need to ensure that User1 lease preferences
receives Microsoft 365 feature and service updates settings.
before the updates are released to all users.What
should you do in the Microsoft 365 admin center?
A. Modify the privileged access management set-
tings.
B. Modify Office software download settings.
C. Modify the Release preferences settings.
D. Submit a new service request.
303. You have a Microsoft 365 subscription.All users have C. From the Secu-
their email stored in Microsoft Exchange OnlineIn the rity & Compliance
mailbox of a user named User, you need to preserve a admin center, cre-
copy of all the email messages that contain the word ate a label and la-
ProjectX.What should you do first? bel policy.
A. From the Exchange admin center, start a mail flow
message trace.
B. From the Security & Compliance admin center,
start a message trace.
C. From the Security & Compliance admin center,
create a label and label policy.
D. From the Exchange admin center, create a mail flow
rule.
304.
118 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
https://gyazo.com/686c728a7bc04166504e1d9caf- https://gya-
ff3c28 zo.com/f0341bc09bba
309. SIMULATION -Please wait while the virtual machine Correct Answer:
loads. Once loaded, you may proceed to the lab sec- See explanation
tion. This may take a few minutes, and the wait time below.You need to
will not be deducted from your overall test time.When configure the
the Next button is available, click it to access the OneDrive
lab section. In this section, you will perform a set of retention period
tasks in a live environment. While most functionality for deleted
will be available to you as it would be in a live en- users.1. Go to the
vironment, some functionality (e.g., copy and paste, OneDrive admin
ability to navigate to external websites) will not be center.2. Select
possible by design.Scoring is based on the outcome Storage.3. Set the
of performing the tasks stated in the lab. In other Ò€
Days to retain
words, it doesn't matter how you accomplish the task, files in OneDrive
if you successfully perform it, you will earn credit after a user
for that task.Labs are not timed separately, and this account is
exam may have more than one lab that you must marked for
complete. You can use as much time as you would deletionÒ€option
like to complete each lab. But, you should manage to 60.4. Click
your time appropriately to ensure that you are able Save to save the
119 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
to complete the lab(s) and all other sections of the changes.Refer-
exam in the time provided.Please note that once ences:https://docs.mic
you submit your work by clicking the Next button
within a lab, you will NOT be able to return to the
lab.You may now click next to proceed to the lab.Lab
information -Use the following login credentials as
needed:To enter your username, place your cursor in
the Sign in box and click on the username below.To
enter your password, place your cursor in the Enter
password box and click on the password below.Mi-
crosoft 365 Username:admin@M365x981607.onmi-
crosoft.comMicrosoft 365 Password: *yfLo7Ir2&y-If
the Microsoft 365 portal does not load successfully
in the browser, press CTRL-K to reload the portal
in a new browser tab.The following information is
for technical support purposes only:Lab Instance:
10811525 -Your organization recently implemented a
new data retention policy. The policy requires that all
files stored in an employee's Microsoft OneDrive fold-
ers be retained for 60 days after the employee is ter-
minated from the organization.The human resources
(HR) department of the organization deletes the user
accounts of all terminated employees.You need to
ensure that the organization meets the requirements
of the data retention policy.
120 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
C. Organization details
D. Default behavior
313. You have a Microsoft 365 tenant that contains a Mi- C. From Power
crosoft Power Platform environment.You need to en- Platform settings,
sure that only specific users can create new envi- modify the Gover-
ronments.What should you do in the Power Platform nance settings for
admin center? the environment.
A. From Data policies, create a new data policy.
B. From Data integration, create a new connection
set.
C. From Power Platform settings, modify the Gover-
nance settings for the environment.
D. From Environments, modify the behaviour settings
for the default environment.
https://gya-
zo.com/fe924cd3bd28bda22793fe968c12dfd8
https://gya-
zo.com/6c54cc15dafb89ddbc8f15acb82d4f0b
https://gya-
zo.com/0f008224e953af916189b95ddf44b76c
322. B. No
133 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Introductory InfoCase study -This is a case study.
Case studies are not timed separately. You can use
as much exam time as you would like to complete
each case. However, there may be additional case
studies and sections on this exam. You must manage
your time to ensure that you are able to complete
all questions included on this exam in the time pro-
vided.To answer the questions included in a case
study, you will need to reference information that is
provided in the case study. Case studies might con-
tain exhibits and other resources that provide more
information about the scenario that is described in
the case study. Each question is independent of the
other questions in this case study.At the end of this
case study, a review screen will appear. This screen
allows you to review your answers and to make
changes before you move to the next section of the
exam. After you begin a new section, you cannot
return to this section.To start the case study -To
display the first question in this case study, click
the Next button. Use the buttons in the left pane to
explore the content of the case study before you
answer the questions. Clicking these buttons dis-
plays information such as business requirements,
existing environment, and problem statements. When
you are ready to answer a question, click the Ques-
tion button to return to the question.Overview -Con-
toso, Ltd. is a consulting company that has a main
office in Montreal and two branch offices in Seat-
tle and New York.The offices have the users and
devices shown in the following table. https://gya-
zo.com/65dc716aaa8003b636cd39bbb04317f3
148 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
lection is worth one point.Hot Area: https://gya-
zo.com/d94e290a7eb36f2991f117b40bcd39f0
331.
150 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Introductory InfoThis is a case study. Case studies D. From the
are not timed separately. You can use as much exam Azure portal, cre-
time as you would like to complete each case. How- ate guest ac-
ever, there may be additional case studies and sec- counts.
tions on this exam. You must manage your time to
ensure that you are able to complete all questions
included on this exam in the time provided.To answer
the questions included in a case study, you will need
to reference information that is provided in the case
study. Case studies might contain exhibits and other
resources that provide more information about the
scenario that is described in the case study. Each
question is independent of the other questions in this
case study.At the end of this case study, a review
screen will appear. This screen allows you to review
your answers and to make changes before you move
to the next section of the exam. After you begin a new
section, you cannot return to this section.To start the
case study -To display the first question in this case
study, click the Next button. Use the buttons in the left
pane to explore the content of the case study before
you answer the questions. Clicking these buttons
displays information such as business requirements,
existing environment, and problem statements. When
you are ready to answer a question, click the Ques-
tion button to return to the question.Overview -Con-
toso, Ltd. is a consulting company that has a main
office in Montreal and two branch offices in Seat-
tle and New York.The offices have the users and
devices shown in the following table. https://gya-
zo.com/e30bd698c76b5b3b293811a2a7ac4edb
334. Introductory InfoThis is a case study. Case studies A. From the Azure
are not timed separately. You can use as much exam Active Directory
time as you would like to complete each case. How- admin center, con-
ever, there may be additional case studies and sec- figure the applica-
tions on this exam. You must manage your time to tion URL settings.
ensure that you are able to complete all questions B. From the Azure
included on this exam in the time provided.To answer Active Directory
the questions included in a case study, you will need admin center, add
to reference information that is provided in the case an enterprise ap-
study. Case studies might contain exhibits and other plication.
resources that provide more information about the C. On an
scenario that is described in the case study. Each on-premises serv-
question is independent of the other questions in this er, download and
case study.At the end of this case study, a review install the Mi-
screen will appear. This screen allows you to review crosoft AAD Appli-
your answers and to make changes before you move cation Proxy con-
to the next section of the exam. After you begin a new nector.
section, you cannot return to this section.To start the
case study -To display the first question in this case
study, click the Next button. Use the buttons in the left
pane to explore the content of the case study before
you answer the questions. Clicking these buttons
displays information such as business requirements,
existing environment, and problem statements. When
157 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
you are ready to answer a question, click the Ques-
tion button to return to the question.Overview -Fab-
rikam, Inc. is an electronics company that produces
consumer products. Fabrikam has 10,000 employees
worldwide.Fabrikam has a main office in London and
branch offices in major cities in Europe, Asia, and the
United States.Existing Environment -Active Directory
Environment -The network contains an Active Direc-
tory forest named fabrikam.com. The forest contains
all the identities used for user and computer authenti-
cation.Each department is represented by a top-level
organizational unit (OU) that contains several child
OUs for user accounts and computer accounts.All
users authenticate to on-premises applications by
signing in to their device by using a UPN format of
username@fabrikam.com.Fabrikam does NOT plan
to implement identity federation.Network Infrastruc-
ture -Each office has a high-speed connection to the
Internet.Each office contains two domain controllers.
All domain controllers are configured as a DNS serv-
er.The public zone for fabrikam.com is managed
by an external DNS server.All users connect to an
on-premises Microsoft Exchange Server 2016 organi-
zation. The users access their email by using Outlook
Anywhere, Outlook on the web, or the Microsoft Out-
look app for iOS. All the Exchange servers have the
latest cumulative updates installed.All shared com-
pany documents are stored on a Microsoft Share-
Point Server farm.Requirements -Planned Changes
-Fabrikam plans to implement a Microsoft 365 En-
terprise subscription and move all email and shared
documents to the subscription.Fabrikam plans to im-
plement two pilot projects:Project1: During Project1,
the mailboxes of 100 users in the sales department
will be moved to Microsoft 365.Project2: After the
successful completion of Project1, Microsoft Teams
& Skype for Business will be enabled in Microsoft
365 for the sales department users.Fabrikam plans to
create a group named UserLicenses that will manage
158 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
the allocation of all Microsoft 365 bulk licenses.Tech-
nical Requirements -Fabrikam identifies the follow-
ing technical requirements:All users must be able to
exchange email messages successfully during Pro-
ject1 by using their current email address.Users must
be able to authenticate to cloud services if Active
Directory becomes unavailable.A user named User1
must be able to view all DLP reports from the Mi-
crosoft 365 admin center.Microsoft 365 Apps for en-
terprise applications must be installed from a net-
work share only.Disruptions to email access must
be minimized.Application Requirements -Fabrikam
identifies the following application requirements:An
on-premises web application named App1 must allow
users to complete their expense reports online. App1
must be available to users from the My Apps por-
tal.The installation of feature updates for Microsoft
365 Apps for enterprise must be minimized.Security
Requirements -Fabrikam identifies the following se-
curity requirements:After the planned migration to
Microsoft 365, all users must continue to authenticate
to their mailbox and to SharePoint sites by using
their UPN.The memberships of UserLicenses must
be validated monthly. Unused user accounts must
be removed from the group automatically.After the
planned migration to Microsoft 365, all users must
be signed in to on-premises and cloud-based ap-
plications automatically.The principle of least privi-
lege must be used.QuestionYou need to meet the ap-
plication requirement for App1.Which three actions
should you perform? Each correct answer presents
part of the solution.NOTE: Each correct selection is
worth one point.
A. From the Azure Active Directory admin center,
configure the application URL settings.
B. From the Azure Active Directory admin center, add
an enterprise application.
C. On an on-premises server, download and install
the Microsoft AAD Application Proxy connector.
159 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
D. On an on-premises server, install the Hybrid Con-
figuration wizard.
E. From the Microsoft 365 admin center, configure the
Software download settings.
163 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
Requirements -Planned Changes -Litware identifies
the following issues:Admin1 cannot create con-
ditional access policies.Admin4 receives an er-
ror when attempting to use SSPR.Users access
new Office 365 service and feature updates be-
fore the updates are reviewed by Admin2.Technical
Requirements -Litware plans to implement the fol-
lowing changes:Implement Microsoft Intune.Imple-
ment Microsoft Teams.Implement Microsoft Defend-
er for Office 365.Ensure that users can install Of-
fice 365 apps on their device.Convert all the Win-
dows 10 Pro devices to Windows 10 Enterprise
E5.Configure Azure AD Connect to sync the Mon-
treal Users OU and the Seattle Users OU.Ques-
tionHOTSPOT -You are evaluating the use of mul-
ti-factor authentication (MFA).For each of the fol-
lowing statements, select Yes if the statement is
true. Otherwise, select No.NOTE: Each correct se-
lection is worth one point.Hot Area: https://gya-
zo.com/b33c61ae4ccdf71ee623f6792c49142f
168 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
D. From the Exchange admin center, start the migra-
tion and select Cutover migration.
339. Introductory InfoCase study -This is a case study. A. From the Mi-
Case studies are not timed separately. You can use crosoft 365 admin
as much exam time as you would like to complete center, start a data
each case. However, there may be additional case migration and click
studies and sections on this exam. You must manage Exchange as the
your time to ensure that you are able to complete all data service.
questions included on this exam in the time provid-
ed.To answer the questions included in a case study,
you will need to reference information that is pro-
vided in the case study. Case studies might contain
exhibits and other resources that provide more in-
formation about the scenario that is described in the
case study. Each question is independent of the other
questions in this case study.At the end of this case
study, a review screen will appear. This screen allows
you to review your answers and to make changes
before you move to the next section of the exam.
After you begin a new section, you cannot return
to this section.To start the case study -To display
the first question in this case study, click the Next
button. Use the buttons in the left pane to explore
the content of the case study before you answer the
questions. Clicking these buttons displays informa-
tion such as business requirements, existing environ-
ment, and problem statements. When you are ready
to answer a question, click the Question button to
return to the question.Overview -Fabrikam, Inc. is an
electronics company that produces consumer prod-
ucts. Fabrikam has 10,000 employees worldwide.Fab-
rikam has a main office in London and branch of-
fices in major cities in Europe, Asia, and the United
States.Existing Environment -Active Directory Envi-
ronment -The network contains an Active Directory
forest named fabrikam.com. The forest contains all
the identities used for user and computer authenti-
cation.Each department is represented by a top-level
169 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
organizational unit (OU) that contains several child
OUs for user accounts and computer accounts.All
users authenticate to on-premises applications by
signing in to their device by using a UPN format of
username@fabrikam.com.Fabrikam does NOT plan
to implement identity federation.Network Infrastruc-
ture -Each office has a high-speed connection to the
Internet.Each office contains two domain controllers.
All domain controllers are configured as a DNS serv-
er.The public zone for fabrikam.com is managed
by an external DNS server.All users connect to an
on-premises Microsoft Exchange Server 2016 organi-
zation. The users access their email by using Outlook
Anywhere, Outlook on the web, or the Microsoft Out-
look app for iOS. All the Exchange servers have the
latest cumulative updates installed.All shared com-
pany documents are stored on a Microsoft Share-
Point Server farm.Requirements -Planned Changes
-Fabrikam plans to implement a Microsoft 365 En-
terprise subscription and move all email and shared
documents to the subscription.Fabrikam plans to im-
plement two pilot projects:Project1: During Project1,
the mailboxes of 100 users in the sales department
will be moved to Microsoft 365.Project2: After the
successful completion of Project1, Microsoft Teams
& Skype for Business will be enabled in Microsoft
365 for the sales department users.Fabrikam plans to
create a group named UserLicenses that will manage
the allocation of all Microsoft 365 bulk licenses.Tech-
nical Requirements -Fabrikam identifies the follow-
ing technical requirements:All users must be able to
exchange email messages successfully during Pro-
ject1 by using their current email address.Users must
be able to authenticate to cloud services if Active
Directory becomes unavailable.A user named User1
must be able to view all DLP reports from the Mi-
crosoft 365 admin center.Microsoft 365 Apps for en-
terprise applications must be installed from a net-
work share only.Disruptions to email access must
170 / 171
M365 Enterprise Admin Expert: MS- 100 Identity and Services
Study online at https://quizlet.com/_b37gf9
be minimized.Application Requirements -Fabrikam
identifies the following application requirements:An
on-premises web application named App1 must allow
users to complete their expense reports online. App1
must be available to users from the My Apps por-
tal.The installation of feature updates for Microsoft
365 Apps for enterprise must be minimized.Security
Requirements -Fabrikam identifies the following se-
curity requirements:After the planned migration to
Microsoft 365, all users must continue to authenticate
to their mailbox and to SharePoint sites by using
their UPN.The memberships of UserLicenses must
be validated monthly. Unused user accounts must
be removed from the group automatically.After the
planned migration to Microsoft 365, all users must
be signed in to on-premises and cloud-based ap-
plications automatically.The principle of least privi-
lege must be used.QuestionWhich migration solution
should you recommend for Project1?
A. From the Microsoft 365 admin center, start a data
migration and click Exchange as the data service.
B. From the Exchange admin center, start a migration
and select Cutover migration.
C. From the Exchange admin center, start a migration
and select Staged migration.
D. From the Microsoft 365 admin center, start a data
migration and click Upload PST as the data service.
171 / 171