Later this month MS-102 will receive a very minor update, following an update late last year that made some big changes, including a new section on Microsoft Defender for Cloud Apps, which I’ll focus on a bit more below. There were also been changes to the weightings of two sections of the exam, so let’s start off with that.

New weightings

Percentages in green are increases, percentages in red are decreases

  • Deploy and manage a Microsoft 365 tenant (15–20%)
  • Implement and manage Microsoft Entra identity and access (25–30%)
  • Manage security and threats by using Microsoft Defender XDR (35–40%)
  • Manage compliance by using Microsoft Purview (15–20%)

Old weightings

  • Deploy and manage a Microsoft 365 tenant (25–30%)
  • Implement and manage Microsoft Entra identity and access (25–30%)
  • Manage security and threats by using Microsoft Defender XDR (25–30%)
  • Manage compliance by using Microsoft Purview (15–20%)

As mentioned above, the major change was the inclusion of a new section for Microsoft Defender for Cloud Apps. Some of these overlap with what you might see in a few of the SC-x00 exams, as well as what you may have seen previously in MS-500 before it was retired. An important point to note here is that if you haven’t worked with Defender for Cloud Apps previously, you may be overwhelmed by the features it has, so it’s important to focus on what the exam covers, rather than spreading yourself too thin with other capabilities that it provides. Here is the list for this exam.

  • Implement, and manage Microsoft Defender for Cloud Apps
    • Configure the app connector for Microsoft 365
    • Configure Microsoft Defender for Cloud Apps policies
    • Review and respond to Microsoft Defender for Cloud Apps alerts
    • Interpret activity log
    • Configure Cloud App Discovery
    • Review and respond to issues identified in Cloud App Discovery

In terms of other new additions, or items that have been mentioned explicitly versus alluded to, here is a summary

  • Network connectivity insights
  • Microsoft 365 backup (make sure you have a basic understanding of core Azure terminology)
  • Shared mailboxes
  • Entra custom roles
  • MFA via Conditional Access policies
  • Purview label usage monitoring

With all this preamble out of the way, let’s get into the latest resource guide.

Deploy and manage a Microsoft 365 tenant (15–20%)

Implement and manage a Microsoft 365 tenant

Manage users and groups

Manage roles and role groups

Implement and manage Microsoft Entra identity and access (25–30%)

Implement and manage identity synchronization with Microsoft Entra tenant

Implement and manage authentication

Implement and manage secure access

Manage security and threats by using Microsoft Defender XDR (35–40%)

Review and respond to security reports and alerts generated by Microsoft Defender XDR

Implement and manage email and collaboration protection by using Microsoft Defender for Office 365

Implement and manage endpoint protection by using Microsoft Defender for Endpoint

Implement, and manage Microsoft Defender for Cloud Apps

Manage compliance by using Microsoft Purview (15–20%)

Implement Microsoft Purview information protection and data lifecycle management

Implement Microsoft Purview data loss prevention (DLP)