Microsoft MS-102: Study Plan: What to Practice
MS-102 is a broad Microsoft 365 administrator exam, and in late 2026 it also has a deadline. Microsoft has announced that the exam will retire on November 30, 2026 at 11:59 PM Central Standard Time. Candidates planning to use MS-102 toward Microsoft 365 Certified: Administrator Expert need to complete the exam before the retirement date and should verify current certification requirements before booking.
The current MS-102 exam covers four major responsibilities: Microsoft 365 tenant administration, Microsoft Entra identity and access, security and threat management with Microsoft Defender XDR, and compliance with Microsoft Purview. The role is intentionally cross-workload: the Microsoft 365 administrator acts as an integrating hub rather than a specialist in only Exchange, Teams, or endpoints.
A practical study plan should therefore use a test tenant where possible and focus on workflows that cross products. Create users, assign roles, configure identity, review service health, investigate security alerts, create data-protection controls, and verify how those decisions affect the tenant.
Start with domains, tenant settings, service health, organization profile, licenses, subscriptions, users, groups, roles, and administrative units. Learn how the Microsoft 365 admin center relates to specialized portals and Microsoft Entra.
The Microsoft 365 Administrator Expert certification expects cross-service administration. Build a map of where identity, security, compliance, endpoint, Teams, Exchange, and SharePoint responsibilities meet.
Practice creating a user lifecycle from onboarding to role or group assignment to offboarding. This makes licensing, groups, access, and administrative responsibility concrete.
Add Microsoft 365 Backup and service-health monitoring to the tenant lab. Even though backup and service availability are not identity topics, they belong to tenant administration because the administrator must know what Microsoft is responsible for, what the organization still needs to protect, and how to distinguish a Microsoft service incident from a local configuration problem.
MS-102 expects candidates to manage Microsoft Entra identities, hybrid identity, authentication, secure access, and synchronization. Build scenarios for cloud-only users, synchronized users, external users, administrators, and self-service password or authentication recovery.
The SC-300 exam is the deeper identity credential, but MS-102 administrators still need to understand Conditional Access, multifactor authentication, authentication methods, password protection, identity synchronization, and privileged roles well enough to operate a tenant safely.
For every identity control, ask what happens during failure. If synchronization stops, which users are affected? If Conditional Access blocks a user, what evidence explains the decision? If an administrator loses access, which recovery path is permitted?
Compare Microsoft Entra Connect Sync with Cloud Sync at a role-awareness level and understand password-hash synchronization, pass-through authentication, federation considerations, and hybrid identity lifecycle. You do not need to turn MS-102 into a directory-engineering exam, but you should be able to recognize which synchronization model is in use and where to look when a cloud identity no longer reflects the expected on-premises state.
Security and threat management is a major part of the role. Learn how Microsoft Defender XDR brings together alerts, incidents, threat intelligence, automated investigation, endpoint protection, email and collaboration security, and advanced hunting.
Create or use simulated incidents and practice moving from alert to incident to affected entity to remediation. The Microsoft Sentinel observability topic is useful context for SIEM, but MS-102 candidates should keep Defender XDR and Microsoft 365 tenant security as the center of the study plan.
Do not memorize alert names. Focus on how an administrator decides whether the incident is credible, which workload is affected, whether automated actions are safe, and when the issue must be escalated to a security operations team.
Microsoft Defender for Endpoint, device risk, attack-surface-reduction controls, endpoint onboarding, and the relationship between device state and identity access appear in the Microsoft 365 security model.
The MD-102 Endpoint Administrator exam goes much deeper into Intune deployment and device management. For MS-102, understand the tenant-level integration points and how endpoint security contributes to Defender XDR and Conditional Access decisions.
A useful scenario is a compromised device used by a legitimate user. Trace the endpoint signal, incident, identity risk, access decision, and remediation workflow across products.
Compliance questions become easier when you follow data from creation to sharing, retention, discovery, and deletion. Microsoft Purview capabilities can include information protection, data loss prevention, records management, retention, eDiscovery, insider risk, communication compliance, and audit depending on licensing and scope.
Create a simple sensitive-information scenario. A finance document is created, shared to a team, emailed externally, retained for a required period, and later needed for an investigation. Which controls classify, restrict, retain, discover, and audit the information?
Add DLP policy tuning to the exercise. A rule that blocks every match may disrupt legitimate work, while a policy that only reports may not reduce enough risk. Practice choosing user notifications, overrides, incident reporting, scope, and testing mode based on the business requirement. Purview questions are easier when the control is connected to real data behavior rather than a list of portal features.
The exam expects administrators to manage compliance capabilities, not just recognize product names. Practice creating a policy, generating a matching event, and reviewing the resulting evidence where your lab permits.
Administrators need to distinguish a Microsoft service incident from a local configuration problem. Review Service Health, message center communications, usage and adoption reporting, network connectivity insights, and other tenant-level monitoring.
When a user reports that a Microsoft 365 workload is unavailable, check whether the problem is isolated to one user, one group, one client, one network location, or the wider service. That simple scope question prevents wasted troubleshooting.
The wider Microsoft certifications divide endpoint, identity, Teams, security, compliance, and cloud roles, but MS-102 administrators are often the people who coordinate across those boundaries.
The role expects working knowledge of PowerShell. Use it to retrieve users, groups, roles, licenses, or service configuration in a lab. Compare what is easy in the admin center with what becomes faster or more repeatable through scripting.
Do not attempt to memorize every cmdlet. Learn how to discover command help, authenticate to the relevant service, inspect objects, filter results, and make controlled changes. The professional skill is using automation safely when the tenant is too large for manual administration.
Record any script that changes state and test it against a small group first. Tenant-wide automation can amplify mistakes quickly.
MS-102 does not make you the deepest specialist in every Microsoft 365 workload, but the administrator role needs enough breadth to understand where workloads depend on identity, licensing, security, and compliance.
The MS-700 Teams Administrator exam is a deeper collaboration specialization. In MS-102 preparation, use Teams, Exchange, SharePoint, and Microsoft 365 Apps as examples of how tenant settings and security policies affect real services.
When a workload-specific problem exceeds your depth, know what evidence to collect and which specialist role should own the next step. Coordination is part of administration at enterprise scale.
Because MS-102 retires on November 30, 2026, candidates testing in the final weeks should avoid building an open-ended study plan. Book only when you are realistically ready, but work backward from the last available exam date and leave room for retake policy if needed.
Microsoft has already updated the English-language exam in April 2026, so use the current live study guide rather than older course outlines. The existing MS-102 can support preparation, but Microsoft’s current retirement notice and study guide should control timing and scope.
Also verify the current Administrator Expert prerequisite options before the exam. Microsoft certification requirements can change independently of your personal study material.
Create one fictional organization. Add verified domains, users, groups, licenses, administrators, hybrid identity assumptions, Conditional Access, Defender XDR, endpoint protection, and Purview data controls. Then introduce an incident and a compliance request.
Trace who is affected, which portal provides evidence, which role can make the change, what should be automated, what should be documented, and how the organization verifies recovery. This combines the four exam areas into the same operating model.
Repeat the scenario after changing one assumption: an external user is involved, a device becomes risky, a retention requirement changes, or Microsoft reports a service degradation. The administrator should be able to explain whether the response belongs in identity, Defender XDR, Purview, workload administration, or Microsoft support. That boundary recognition is one of the clearest signs that cross-tenant administration is becoming coherent.
MS-102 is broad because Microsoft 365 administration is broad. A candidate is ready when they can move between tenant, identity, security, compliance, and workloads without losing the ownership boundary or the evidence needed to explain what happened.
Because the retirement window is short, finish with a dated readiness check rather than an endless list of weak topics. Mark every objective as explain, configure, verify, or troubleshoot; schedule the exam only when the gaps are realistic to close before the final testing date. If timing becomes too tight, verify Microsoft’s current certification route instead of rushing through an expiring exam without enough hands-on practice.