MS-102 Microsoft 365 Administrator:
The Complete Learning Path
A structured, exam-and-real-world-aligned roadmap through tenant administration, identity, hybrid sync, security operations, and Microsoft Purview compliance โ organized so you learn it in the right order, not a random order.
MS-102 Microsoft 365 Administrator: Learn It the Way You’ll Actually Use It
MS-102 Microsoft 365 Administrator is where Microsoft 365 stops being theory and starts being operational responsibility. If SC-900 taught you why Zero Trust, identity, and compliance matter, MS-102 asks a harder question: can you actually deploy, secure, and run a tenant?
This page brings together the complete MS-102 learning path โ from setting up your first tenant, through identity and hybrid sync, into security operations with Microsoft Defender XDR, and finally into Microsoft Purview compliance โ organized in the order a real administrator (and the exam) expects you to learn it.
If you already hold SC-900 or are moving straight into Microsoft 365 administration, this is the correct place to start. You can also explore our full Microsoft Certification learning paths, or grab additional materials from our Free Resources page.
๐น MS-102 Foundations & the SC-900 โ MS-102 Mindset Shift
6 guidesStart here if you’re coming from SC-900 or are new to Microsoft 365 administration. These set up how to think about the role before you touch a single setting.
Why “Never Trust, Always Verify” gets messy the moment you’re responsible for a live tenant.
A practical, real-world framing of what the administrator role actually covers.
Moving from feature knowledge to owning the joiner-mover-leaver lifecycle.
Identity stops being a concept and becomes something you configure and defend.
Why strong tools still fail without the right administrative decisions behind them.
The shift from “protecting the cloud” to knowing exactly where each workload stores data.
๐น Tenant Setup & Admin Centers
7 guidesEvery configuration you’ll ever make starts at the tenant level. This is where you build your lab and learn the control surfaces.
Build the tenant you’ll use for every lab in this path.
What a tenant actually is, and why every setting starts here.
A guided first look at the primary admin workspace.
Why Microsoft splits administration across multiple specialized centers.
Why so many “bugs” are actually licensing problems in disguise.
Getting your organization’s domain correctly configured before anything else works.
The deep tenant-wide settings menu most admins never fully explore.
๐น Users, Groups, Roles & Licensing
9 guidesThe objects and permissions administrators manage daily โ accounts, groups, delegated roles, and licenses.
Where every identity, license, and access decision starts.
Creating, securing, licensing, monitoring, and offboarding users properly.
How groups control access, collaboration, and licensing โ not just membership.
Attribute-based email groups that stay accurate as people move teams.
Avoiding the two failure modes: too many Global Admins, or admins who can’t do their job.
Step-by-step, least-privilege role configuration done correctly.
Delegating admin permissions to a subset of users instead of the whole tenant.
What plan names actually unlock, and how licensing drives operational control.
Assigning licenses automatically through group membership instead of one-by-one.
๐น Privileged Identity & Access Governance
2 guidesControlling and reviewing admin-level access before it becomes an attack surface.
Just-in-time admin access instead of standing Global Admin privileges.
Catching privilege creep before it becomes a breach.
๐น Identity Foundations (Microsoft Entra ID)
8 guidesIdentity is the control plane of every Microsoft 365 tenant. This module covers authentication, MFA, and Conditional Access in depth.
The identity foundation every login, policy, and permission flows through.
How users verify identity, and why it underpins MFA and passwordless.
Enforcing phishing-resistant authentication instead of weak fallback methods.
Authenticator, passkeys, and Temporary Access Pass explained.
Self-service password reset and writeback configuration, step by step.
The single most important control against credential-based attacks.
The policy engine that decides when, where, and how access is granted.
Defending identity against password sprays and token replay in real time.
๐น Hybrid Identity & Directory Sync
8 guidesBridging on-premises Active Directory with Microsoft Entra ID โ one of the heaviest lab-based domains in the exam.
Building the on-prem AD lab environment everything else depends on.
Fixing bad directory data before it breaks your sync deployment.
Installing and configuring the classic Entra Connect sync engine.
Controlling exactly which objects sync to the cloud.
Choosing the right authentication model for your organization.
Security, infrastructure, and administrative trade-offs of each method.
The lightweight, cloud-centric alternative to classic Entra Connect.
Monitoring, alerts, and fixing sync problems before users notice.
๐น Security Foundations & Secure Score
3 guidesThe shift from configuration to proactive defense โ Domain 3 of the exam begins here.
Moving from tenant enablement into proactive protection.
A hands-on lab fixing 20 at-risk recommendations end to end.
Measuring and improving tenant-wide security posture over time.
๐น Microsoft Defender XDR & Security Operations
7 guidesDetection, investigation, and automated response โ the security operations layer of MS-102.
Architecture and admin responsibilities for the security operations center.
Understanding what’s actively targeting organizations right now.
Analyzing severity, entities, and evidence during an investigation.
Correlating alerts into incidents and driving them to resolution.
Automated Investigation & Response โ cutting through alert fatigue.
Identity threat detection across hybrid Active Directory environments.
Discovering and controlling Shadow IT and unsanctioned cloud apps.
๐น Email & Collaboration Security
5 guidesEmail remains the number one attack vector โ this module covers the full Defender for Office 365 stack.
How Exchange Online Protection filters spam and malicious mail.
Spoof intelligence and impersonation protection against targeted deception.
Time-of-click URL protection against phishing and shortened links.
Sandbox detonation that catches zero-day threats signature scanning misses.
Full email authentication setup to stop domain spoofing.
๐น Microsoft Purview: Compliance & Governance
11 guidesThe largest module in this path โ classification, protection, retention, investigation, and data loss prevention across Microsoft 365.
How Purview centrally manages compliance and governance across M365.
Delegating compliance responsibility with least-privilege RBAC.
Classifying and protecting sensitive data across every workload.
User-applied classification, encryption, and access control.
Detecting and labeling sensitive content without relying on users.
Managing the data lifecycle across Microsoft 365 workloads.
Item-level retention control beyond broad policy scopes.
Protecting and disposing of official business records compliantly.
Tracking and investigating user and admin activity tenant-wide.
Case-based search across Exchange, SharePoint, Teams, and OneDrive.
Stopping sensitive data from leaving the organization by accident.
๐น Operations, Continuity & Adoption
5 guidesKeeping a tenant healthy, resilient, and actually used well after go-live.
Moving from reactive troubleshooting to proactive tenant management.
Testing and troubleshooting the network experience users actually feel.
Closing the gap between “it’s in the cloud” and “it’s actually recoverable.”
Update rings and release strategy so changes don’t blindside your helpdesk.
Measuring whether users are actually benefiting from what you deployed.
๐๏ธ Suggested MS-102 Study Plan
4 phasesUnderstand the system first, configure it later. Work through this in the same order as the modules above — Purview will make far less sense if Identity isn’t solid yet.
Build your trial tenant and get comfortable in the admin centers before touching identity or security settings.
Users, groups, licensing, PIM, Entra ID, and hybrid identity — the heaviest lab-based domain in the exam.
Secure Score, Defender XDR, and email security — move from enablement into proactive defense.
Compliance, retention, DLP, and eDiscovery, then tenant health and release management to close the loop.
๐ฏ MS-102 Exam Tips
Practical notes from working through this content, not generic test-taking advice.
- Expect scenario questions that test which admin center a setting lives in — not just what the setting does.
- Purview and Hybrid Identity are the densest domains here. If you’re short on time, prioritize these two over Email Security.
- Know the difference between retention policies and retention labels — this distinction shows up repeatedly.
- PIM and Conditional Access questions often test the reasoning behind a control, not just the click-path to enable it.
- Build the lab yourself. Reading about Entra Connect is not the same as watching a sync cycle actually run.
๐งช Hands-On Labs in This Path
6 labsThese guides are lab-based, not just conceptual — build them yourself rather than just reading them.
The tenant every other lab in this path depends on.
Build the on-prem AD lab environment for hybrid identity.
Installing and configuring the classic hybrid sync engine.
Fixing bad directory data before it breaks your sync deployment.
A hands-on lab fixing 20 at-risk Secure Score recommendations end to end.
Identity threat detection across hybrid Active Directory environments.
โ MS-102 FAQ
Do I need SC-900 before MS-102?
Not strictly, but it helps. SC-900 teaches the concepts; MS-102 asks you to actually operate them. Coming in cold is possible, just steeper.
How long does this learning path take?
Most learners following the phased study plan above take 3–5 weeks, depending on how much hands-on lab time you put in.
Which module should I not skip?
Identity Foundations. Almost everything downstream — security, compliance, hybrid sync — assumes you already understand Entra ID.
Do I need an on-premises server for the hybrid identity labs?
A free trial VM or local virtual machine works fine — you don’t need physical hardware. The Trial Account and AD & Domain Controller guides above walk through the setup.
What should I study after MS-102?
Explore the rest of our Microsoft Certification learning paths to see what’s next in your track.
๐ Free Resources for MS-102
Grab our free MS-102 study materials — cheat sheets, planners, and additional reference guides.
Visit the Free Resources Pageโก๏ธ Continue Your Certification Journey
You’ve now seen the complete MS-102 learning path. Explore every Microsoft certification path we cover, or head back to SC-900 if you need to reinforce the fundamentals first.
Explore All Certification PathsOfficial Microsoft Reference
For the most up-to-date MS-102 exam objectives and skills outline, Microsoft maintains them directly on Microsoft Learn.
View MS-102 on Microsoft Learn