MS-102 is the single exam behind the Microsoft 365 Certified: Administrator Expert certification, and it covers far more than Exchange: tenant management, Microsoft Entra identity, Defender XDR and Purview. In this post I'll lay out a six-stage study plan built on the official Microsoft Learn paths, with the Exchange Online depth that makes the tenant and protection objectives click, and the scheduling fact you must plan around: the exam retires at the end of November 2026.
Watch out: Microsoft Learn states that Exam MS-102 and the Microsoft 365 Certified: Administrator Expert certification retire on November 30, 2026 (11:59 PM Central Time); after that the certification can't be earned or renewed. Microsoft's listed successor is Exam AB-650, Administering Microsoft 365 and AI Services (in beta at the time of writing, with no prerequisite certification). If you can't realistically sit MS-102 before the deadline, use this plan as your foundation and switch to the AB-650 study guide.
Who this path is for#
This path suits the generalist Microsoft 365 administrator who sits between workloads, and the Exchange-focused admin who wants to prove they can also run identity, security and compliance. Microsoft's audience profile expects functional experience with the Microsoft 365 workloads and Microsoft Entra ID, plus working knowledge of networking, Active Directory Domain Services, DNS and PowerShell.
Prerequisites matter. The certification page says the Expert credential requires at least one of: Microsoft 365 Certified: Endpoint Administrator Associate (MD-102), Microsoft 365 Certified: Teams Administrator Associate (MS-700), Microsoft Certified: Identity and Access Administrator Associate (SC-300) or Microsoft Certified: Information Security Administrator Associate (SC-401). Given the retirement date, have one of them on your transcript before you book MS-102.
The exam at a glance#
MS-102 earns the Microsoft 365 Certified: Administrator Expert certification. The skills measured and their weights below are as published in Microsoft's study guide (skills measured as of April 28, 2026). Microsoft revises study guides periodically and keeps a change log at the bottom of the page, so re-check it the week you book.
| Domain | Weight | Where Exchange Online shows up |
|---|---|---|
| Deploy and manage a Microsoft 365 tenant | 25–30% | Domains and DNS, contacts, groups and shared mailboxes, roles, bulk PowerShell |
| Implement and manage Microsoft Entra identity and access | 25–30% | Directory sync that feeds your recipients; authentication and Conditional Access for mail clients |
| Manage security and threats by using Microsoft Defender XDR | 30–35% | Defender for Office 365 threat and alert policies, email investigations, restricted entities |
| Manage compliance by using Microsoft Purview | 10–15% | Retention, sensitivity labels, DLP for Exchange Online |
The study guide also states that a score of 700 or greater is required to pass, and it links a free Practice Assessment and the exam sandbox. Use both.
Stage-by-stage plan#
The plan assumes about twelve weeks of evenings and weekends; every stage pairs a Learn path with hands-on work in a test tenant.
Stage 1 – Tenant foundations (weeks 1–2)#
Study the learning paths MS-102 Configure your Microsoft 365 tenant and MS-102 Manage your Microsoft 365 tenant. Practise adding a custom domain and its DNS records, organization settings, Service health notifications, Network connectivity insights and Microsoft 365 Backup. Create users, contacts, Microsoft 365 Groups and shared mailboxes, use group-based licensing, and run one bulk operation with the Microsoft Graph PowerShell SDK. Finish with role groups in the Defender and Purview portals, administrative units and a Privileged Identity Management activation.
Stage 2 – Identity and access (weeks 3–4)#
Study MS-102 Implement identity synchronization and Manage identity and access in Microsoft 365. Know when to pick Microsoft Entra Connect Sync versus Cloud Sync, what IdFix cleans up and how Connect Health surfaces sync problems, then work through authentication methods, self-service password reset, Password Protection, Identity Protection and Conditional Access policies that require MFA. The objectives explicitly include troubleshooting synchronization and authentication, so break things on purpose in your lab and fix them.
Stage 3 – Exchange Online depth (weeks 5–6)#
Exchange isn't a separate domain on MS-102, but many objectives assume you can run mail confidently. Use the modules Examine email protection in Microsoft 365 and Manage Exchange Online by using Windows PowerShell, then go deeper in four areas:
- Mail flow: accepted domains (Authoritative versus Internal relay), connectors, mail flow rules with priorities and exceptions, and reading a message trace end to end.
- Recipients: mailbox types, shared mailbox permissions, distribution groups versus Microsoft 365 Groups, mail users and contacts, and how directory synchronization affects each.
- Protection: Exchange Online Protection anti-spam, anti-malware and anti-phishing policies, preset security policies, quarantine, and Defender for Office 365 Safe Links and Safe Attachments.
- Compliance basics: litigation hold, retention policies on mailboxes, archive mailboxes, and how DLP policies for Exchange Online are built and reported.
Do all of it twice: once in the Exchange admin center, once in Exchange Online PowerShell V3.
Stage 4 – Security with Microsoft Defender XDR (weeks 7–9)#
This is the heaviest domain. Study MS-102 Manage your security services in Microsoft Defender XDR and lean on the Defender documentation for Secure Score and Exposure Management, incidents, alerts and advanced hunting, Defender for Office 365 threat and alert policies, attack simulation training, restricted entities, Defender for Endpoint onboarding and Vulnerability Management, and Defender for Cloud Apps (app connector, policies, activity log, Cloud App Discovery).
Stage 5 – Compliance with Microsoft Purview (weeks 10–11)#
Study MS-102 Explore data governance in Microsoft 365, MS-102 Implement compliance in Microsoft 365 and MS-102 Manage compliance in Microsoft 365. Build a custom sensitive information type, retention labels and policies, sensitivity labels and their policies, and DLP policies across Exchange Online, SharePoint, OneDrive, Teams and Endpoint DLP. Review results in Content explorer, Activity explorer and the DLP alerts and reports.
Stage 6 – Consolidate and book (week 12)#
Take the Practice Assessment, re-read the study guide's change log, revisit your weakest domain, and book a date with a buffer before the retirement deadline in case you need a retake.
Hands-on practice#
Use a test tenant you control, never production:
- Add a custom domain with MX, SPF, DKIM and Autodiscover records, and prove mail flow both ways with a message trace.
- Create a shared mailbox, grant Full Access and Send As to a security group, and verify in Outlook on the web.
- Build a mail flow rule in test mode with an incident report, confirm the match in message trace, then enforce it.
- Create a Conditional Access policy requiring MFA for Exchange Online in report-only mode, then read the sign-in log.
- Apply the Standard preset security policy, release a quarantined message, and review the threat protection reports.
- Create a retention policy, a sensitivity label that encrypts, and a DLP policy for credit card numbers in Exchange and Teams; trigger the DLP rule and walk through the alert.
- Run a mailbox report with
Get-EXOMailboxandGet-EXOMailboxStatisticsand export it to CSV.
Exam-day tips#
- Run through the exam sandbox beforehand so the question formats and case studies hold no surprises.
- Read for the hidden constraint: least privilege, least administrative effort or no impact to existing users usually decides between two plausible answers.
- Portal names matter: Microsoft Entra admin center, Microsoft Defender portal, Microsoft Purview portal, Exchange admin center. Know which task lives where.
- If the exam isn't offered in your preferred language, the study guide says you can request an extra 30 minutes.
After the exam#
Microsoft's role-based certifications normally expire annually and renew for free through an online assessment on Microsoft Learn. Because this certification retires on November 30, 2026, it can't be renewed after that date, so check the expiry in your Learn profile. For next steps, the natural successor is AB-650 (Microsoft 365 and AI Services Administrator Associate); otherwise pick up whichever of SC-300, SC-401, MD-102 or MS-700 you don't already hold. The earlier messaging administrator certification is no longer on the prerequisite list, so Exchange depth now comes from doing the work and documenting it.