Free Microsoft MS-100 Exam Actual Questions

The questions for MS-100 were last updated On Mar 4, 2025

At ValidExamDumps, we consistently monitor updates to the Microsoft MS-100 exam questions by Microsoft. Whenever our team identifies changes in the exam questions,exam objectives, exam focus areas or in exam requirements, We immediately update our exam questions for both PDF and online practice exams. This commitment ensures our customers always have access to the most current and accurate questions. By preparing with these actual questions, our customers can successfully pass the Microsoft 365 Identity and Services exam on their first attempt without needing additional materials or study guides.

Other certification materials providers often include outdated or removed questions by Microsoft in their Microsoft MS-100 exam. These outdated questions lead to customers failing their Microsoft 365 Identity and Services exam. In contrast, we ensure our questions bank includes only precise and up-to-date questions, guaranteeing their presence in your actual exam. Our main priority is your success in the Microsoft MS-100 exam, not profiting from selling obsolete exam questions in PDF or Online Practice Test.

 

Question No. 1

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a hybrid deployment of Microsoft 365 that contains the objects shown in the following table.

Azure AD Connect has the following settings:

Password Hash Sync: Enabled

Password writeback: Enabled

Group writeback: Enabled

You need to add User2 to Group 2.

Solution: You use the Azure Active Directory admin center.

Does this meet the goal?

Show Answer Hide Answer
Correct Answer: A

Question No. 2

You have a Microsoft 365 subscription that contains a Microsoft Azure Directory (Azure AD) tenant Contoso.com. The tenant includes a user named user1.

You enable Azure AD Identity protection.

You need to ensure that User1 can review the list in Azure AD identity protection of users flagged for risk. The solution must use the principle of least privilege.

To which role should you add User1?

Show Answer Hide Answer
Correct Answer: A

Question No. 3

Your company has an on-premises Microsoft Exchange Server 2013 organization.

The company has 100 users.

The company purchases Microsoft 365 and plans to move its entire.- infrastructure to the cloud.

The company does NOT plan to sync the on-premises Active Directory domain to Microsoft Azure Active Directory (Azure AD).

You need to recommend which type of migration to use to move all email messages, contacts, and calendar items to Exchange Online.

What should you recommend?

Show Answer Hide Answer
Correct Answer: A

https://docs.microsoft.com/en-us/exchange/mailbox-migration/cutover-migration-to-office-365

A cutover migration and an IMAP migration do not require the company to sync the on-premises Active Directory domain to Microsoft Azure Active Directory (Azure AD). Only a cutover migration meets the requirements in this question.

With a cutover migration, user accounts will need to be created in Azure Active Directory for each user. The mailboxes are all migrated in one go and MX records configured to redirect email to Microsoft 365.

Question No. 4

You need to Add the custom domain name* to Office 36S K> support the planned changes as quickly as possible.

What should you create to verify the domain names successfully?

Show Answer Hide Answer
Correct Answer: D

Contoso plans to provide email addresses for all the users in the following domains:

East.adatum.com

Contoso.adatum.com

Humongousinsurance.com

To verify three domain names, you need to add three TXT records.


https://docs.microsoft.com/en-us/office365/admin/setup/add-domain?view=o365-worldwide

Question No. 5

Your Network contains an on-premises Active Directory domain named contoso.local. The domain contains five domain controllers.

Your company purchases Microsoft 365 and creates a Microsoft Anne Active Directory (Azure AD) tenant named.contoso.onmicrosoft.com.

You plan to implement pass- through authentication.

You need to prepare the environment for the planned implementation of pass-through authentication.

Which three actions should you perform? Each correct answer presents pan of the solution.

NOTE: Each correct selection is worth one point.

Show Answer Hide Answer
Correct Answer: B, C, F

To implement pass-through authentication, you need to install and configure Azure AD Connect.

The on-premise Active Directory domain is named contoso.local. Before you can configure Azure AD Connect, you need to purchase a routable domain, for example, contoso.com.

You then need to add the domain contoso.com to Microsoft as a custom domain name.

The user accounts in the Active Directory domain need to be configured to use the domain name contoso.com as a UPN suffix. You need to add contoso.com to the Active Directory first by using Active Directory Domains and Trusts to add contoso.com add a UPN suffix. You can then configure each account to use the new UPN suffix.

An Authentication Agent is required on a domain controller to perform the authentication when pass-through authentication is used. When the custom domain and user accounts are configured, you can install and configure Azure AD Connect. An Authentication Agent is installed when you select the pass-through authentication option in the Azure AD Connect configuration or you can install the Authentication Agent manually.


https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-quick-start