Courseiva

Microsoft 365 Certified: Teams Administrator Associate (MS-700) — Questions 151–211

211 questions total · 3pages · All types, answers revealed

Page 2

Page 3 of 3

151
MCQhard

You are a Teams administrator for Fabrikam. The security team requires that all files shared in Teams chats and channels are scanned for malware before users can download them. You need to ensure this scanning occurs without affecting user ability to upload files. What should you do?

A.Set up a third-party antivirus integration in Teams admin center > Teams apps > Manage apps.
B.Enable Conditional Access policy requiring compliant devices for Teams access.
C.Enable Safe Attachments in Microsoft Defender for Office 365 and apply a policy to SharePoint Online and OneDrive for Business.
D.Configure a Data Loss Prevention (DLP) policy in Microsoft Purview to block files containing malware.
AnswerC

Safe Attachments in Defender for Office 365 can scan files in SharePoint Online, OneDrive, and Teams. Configuring a policy for these workloads ensures files are scanned before download, meeting the security requirement without blocking uploads. This is the correct integrated solution.

Why this answer

Safe Attachments in Microsoft Defender for Office 365 is the correct solution because it provides malware scanning for files in SharePoint Online, OneDrive, and Microsoft Teams. By applying a Safe Attachments policy to these workloads, files are scanned asynchronously, and malicious files are blocked from download, ensuring security without hindering uploads.

Exam trap

The trap here is assuming DLP or Conditional Access can scan for malware; they address data leakage and access control, not antivirus scanning.

152
MCQmedium

You need to determine which third-party applications are most frequently used by employees within Microsoft Teams. Which report should you analyze?

A.Teams User Activity report
B.Call Analytics
C.Microsoft 365 Audit Logs
D.Teams Device report
E.Teams App Usage report
AnswerE

The Teams App Usage report specifically lists the applications in use across the tenant. It provides the name of the app, the publisher, and the number of active users, allowing administrators to see exactly which third-party tools are most popular among their staff.

Why this answer

The Teams App Usage report in the Microsoft Teams admin center provides detailed information about which third-party apps are used, including the number of active users and usage per app. This report is specifically designed to track app adoption and usage frequency across the organization. Therefore, it is the correct report to determine the most frequently used third-party applications.

Exam trap

MS-700 often tests the confusion between the Teams User Activity report (which covers overall activity) and the Teams App Usage report (which specifically tracks app usage), causing candidates to pick the former for app-specific questions.

How to eliminate wrong answers

Option A is wrong because the Teams User Activity report shows overall user activity (messages, calls, meetings) but does not break down usage by third-party app. Option B is wrong because Call Analytics focuses on call quality and troubleshooting for individual users, not app usage. Option C is wrong because Microsoft 365 Audit Logs record events like app installation or permission changes, but they do not provide aggregated usage frequency of third-party apps.

Option D is wrong because the Teams Device report shows device usage (Windows, Mac, mobile) and does not detail third-party app usage.

153
Multi-Selecthard

You are a Teams administrator for a company that uses Direct Routing with a single Session Border Controller (SBC). The SBC fails, causing all PSTN calls to fail. You need to implement a highly available and survivable solution for Direct Routing. (Choose two.)

Select 2 answers
A.Configure multiple SBCs in the voice route and assign them to the same PSTN usage.
B.Assign a Calling Plan license to all users.
C.Configure a Survivable Branch Appliance (SBA) for each site.
D.Implement a Session Border Controller (SBC) that supports media bypass.
E.Enable cloud voicemail for all users.
AnswersA, C

Adding multiple SBCs to the same voice route provides redundancy. If one SBC fails, Teams can attempt to route the call through another SBC listed in the route. This ensures high availability for outbound and inbound calls, as the voice route will try the next SBC in the list. This is a core method for achieving Direct Routing resiliency.

Why this answer

High availability and survivability for Direct Routing require redundant SBCs and local survivability options. Configuring multiple SBCs in a voice route ensures that if one fails, calls can route through another. Deploying Survivable Branch Appliances at branch sites provides local PSTN connectivity and call continuity if the connection to Microsoft 365 is lost.

Together, these provide both redundancy and survivability.

Exam trap

The trap here is confusing media bypass with high availability; media bypass improves media flow but does not provide redundancy if the SBC itself fails.

154
MCQmedium

You need to monitor the health of the Microsoft Teams service and receive alerts for incidents that affect your organization. You want to use the Microsoft 365 admin center. Which feature should you configure?

A.Microsoft 365 network connectivity dashboard
B.Usage reports
C.Service health dashboard
D.Message center
AnswerC

The Service health dashboard in the Microsoft 365 admin center provides real-time status of Microsoft services, including Teams. It shows active incidents, planned maintenance, and advisories. You can configure notifications to alert you of issues. This is the correct tool for monitoring service health and receiving alerts.

Why this answer

The Service health dashboard in the Microsoft 365 admin center is the central location for monitoring the health of Microsoft services, including Teams. It provides current status, incident details, and the ability to set up notifications. Administrators use it to stay informed about outages and advisories that may impact their organization.

Exam trap

The trap here is confusing the Message center, which is for feature updates, with the Service health dashboard, which is for incident monitoring.

155
MCQmedium

You are the Teams administrator for Contoso. A user reports that during a Teams meeting, the audio from a specific participant was intermittently cutting out. You open Call Analytics for that user's session. Which metric should you examine first to determine whether the issue was caused by network jitter on the user's side?

A.Audio codec
B.Jitter
C.Packet loss
D.Round-trip time
AnswerB

Jitter measures the variation in packet arrival times. High jitter on the user's side indicates network instability that can cause audio to cut out. Call Analytics displays jitter for both the user's endpoint and the participant's, so you can pinpoint whether the problem originated locally. This metric directly addresses the intermittent audio symptom described.

Why this answer

Jitter is the metric that quantifies variation in packet arrival times, which directly causes intermittent audio cutouts. In Call Analytics, you can compare jitter values for the user and the participant to isolate the problematic side. The other metrics—packet loss, round-trip time, and codec—are related but do not specifically measure the consistency of packet delivery that jitter captures.

Exam trap

The trap here is confusing jitter with packet loss, but jitter measures timing variability while packet loss measures missing packets.

156
MCQmedium

Your organization has noticed a recurring pattern of poor audio quality during weekly executive town hall meetings. You need to identify if these issues are related to specific network segments or common hardware devices used by participants over the last three months. Which tool should you use to analyze this long-term trend?

A.Call Analytics
B.Teams Usage Reports
C.Call Quality Dashboard (CQD)
D.Network Planner
AnswerC

CQD provides a comprehensive view of quality for the entire organization by aggregating data from all calls and meetings. It allows administrators to filter by subnets, buildings, and endpoints over a 90-day period. This makes it the correct choice for identifying systemic patterns and historical trends across different network segments.

Why this answer

Call Quality Dashboard (CQD) is the correct tool because it aggregates telemetry from Teams calls over extended periods (up to 90 days by default, extendable) and allows slicing by network segment, subnet, building, and device type. This makes it ideal for identifying long-term trends tied to specific network segments or hardware across three months of town hall meetings.

Exam trap

The trap is confusing Call Analytics (per-call, short-term, user-focused troubleshooting) with Call Quality Dashboard (aggregate, long-term, segment/device-focused trend analysis) — the exam tests whether you can match the tool to the scope and duration of the investigation.

How to eliminate wrong answers

Option A is wrong because Call Analytics provides per-user, per-call diagnostic detail for a single call or user over a short window (typically 30 days) and is designed for real-time troubleshooting, not long-term aggregate trend analysis across segments. Option B is wrong because Teams Usage Reports show adoption and activity metrics (active users, messages, meetings) but do not contain audio quality telemetry like jitter, packet loss, or device-level call quality. Option D is wrong because Network Planner is a pre-deployment capacity and topology planning tool — it models bandwidth and network requirements before rollout, not post-deployment quality analysis.

157
MCQmedium

A user reports that during a Microsoft Teams meeting, they can hear other participants but no one can hear them. The user is using a USB headset. You need to determine the most likely cause using available Teams diagnostic tools. Which tool should you use first?

A.The Teams admin center's Meeting policies report
B.Teams device settings and the Make a test call feature
C.Network Planner in the Microsoft Teams admin center
D.Call Analytics in the Microsoft Teams admin center
AnswerB

The Make a test call feature in Teams device settings records a short message and plays it back, allowing the user to verify if their microphone is working and if they are muted. This is the fastest way to isolate a local audio input problem. It directly tests the microphone and speaker, which is the most likely cause of one-way audio when using a USB headset.

Why this answer

The Make a test call feature in Teams device settings is the correct first step because it directly tests the user's microphone and speakers, allowing them to hear their own recorded voice. This quickly identifies if the microphone is muted, not selected, or faulty. Call Analytics and Network Planner are for deeper network and quality analysis, not for immediate device troubleshooting.

Exam trap

The trap here is assuming that a one-way audio issue is always a network or service problem when it is often a simple local device or mute setting.

158
Multi-Selecthard

You want to implement Conditional Access policies to secure Microsoft Teams access. Which THREE components are essential when defining a Conditional Access policy in Azure AD for Teams? (Each correct answer presents part of the solution.)

Select 3 answers
A.Assignments (Users and Groups)
B.Cloud apps (Microsoft Teams)
C.Grant controls (e.g., Require MFA)
D.Teams Messaging policy settings
E.A Skype for Business Voice route
AnswersA, B, C

The 'Assignments' section of a Conditional Access policy defines who the policy applies to. Without specifying users or groups, the policy cannot be enforced, as it needs to know which identities are subject to the security requirements and conditions you are establishing for Teams access.

Why this answer

Option A (Assignments - Users and Groups) is correct because every Conditional Access policy must specify the target users or groups to whom the policy applies, which is the 'Assignments' section's user scope in Azure AD. Option B (Cloud apps - Microsoft Teams) is correct because a Conditional Access policy must designate the target cloud application, and selecting Microsoft Teams as the cloud app scopes the policy specifically to Teams access. Option C (Grant controls - e.g., Require MFA) is correct because grant controls define what must be satisfied to gain access, such as requiring multi-factor authentication, compliant device, or hybrid Azure AD joined device, which enforces the actual access condition.

Option D (Teams Messaging policy settings) is incorrect because messaging policies are configured in the Microsoft Teams admin center to control chat and channel features, not in Azure AD Conditional Access. Option E (A Skype for Business Voice route) is incorrect because voice routes are telephony configuration components in Skype for Business Online/Teams Phone, unrelated to Conditional Access policy definition.

Exam trap

MS-700 often tests the misconception that Teams admin center settings (messaging policies, voice routes) are part of Conditional Access, when in fact Conditional Access is exclusively an Azure AD identity construct built from Assignments, Cloud apps, and Access controls.

159
Multi-Selecthard

You are a Teams administrator for a company that uses Microsoft Teams Phone with Direct Routing. You need to configure a new user for Enterprise Voice and ensure they can make outbound PSTN calls. The user must be able to dial 911, and all outbound calls must be routed through a specific SBC named SBC-Main. You have already created the SBC, voice route, PSTN usage, and voice policy. Which two actions must you perform to enable the user for outbound PSTN calling? (Choose two.)

Select 2 answers
A.Create a dial plan and assign it to the user.
B.Assign a Calling Plan license to the user.
C.Assign the voice policy to the user.
D.Configure the SBC to allow all outbound calls.
E.Enable the user for Enterprise Voice.
AnswersC, E

Assigning the voice policy to the user is essential because the voice policy links the user to the PSTN usages and voice routes that define how outbound calls are routed. Without this assignment, the user cannot make PSTN calls. The voice policy also controls other calling features. This step is required to enable outbound calling through the configured SBC.

Why this answer

To enable a user for outbound PSTN calling in Direct Routing, you must enable the user for Enterprise Voice and assign the voice policy that contains the appropriate PSTN usages and voice routes. Dial plans are helpful but not mandatory for basic outbound calling if numbers are normalized. Calling Plan licenses are not used with Direct Routing.

SBC configuration is part of the voice route setup, which is already completed. Thus, the two required actions are enabling Enterprise Voice and assigning the voice policy.

Exam trap

The trap here is assuming that a dial plan or Calling Plan license is required for Direct Routing; in fact, the essential user-level steps are enabling Enterprise Voice and assigning the voice policy.

160
MCQhard

You are a Teams administrator. A user reports that they cannot access the Teams admin center to view usage reports. You need to grant them the minimum permissions required to view Teams usage reports without giving them the ability to modify Teams settings. Which role should you assign?

A.Global Reader
B.Reports Reader
C.Teams Communications Support Specialist
D.Teams Administrator
AnswerB

The Reports Reader role provides read-only access to usage reports across Microsoft 365 services, including Teams. It allows viewing reports without the ability to change any settings. This role is specifically designed for users who need to analyze data but not administer the service, making it the least privileged role for this scenario.

Why this answer

The Reports Reader role is purpose-built to grant read-only access to usage reports, including Teams reports, without any administrative capabilities. It ensures the user can view the necessary data while preventing any modifications to Teams settings. Other roles either grant excessive permissions or lack the required reporting access.

Exam trap

The trap here is assuming that Global Reader or Teams Administrator is needed, but Reports Reader is the least privileged role for viewing usage reports.

161
MCQmedium

You are a Teams administrator for a company that uses Direct Routing. A user reports that when they dial a 10-digit phone number from the Teams client, the call fails immediately with 'Call failed'. You verify that the user has a valid Phone System license and an assigned phone number. You need to ensure that calls to external PSTN numbers are routed correctly. What should you configure?

A.Configure a calling policy with 'Allow calling' enabled.
B.Assign an audio conferencing license to the user.
C.Add the user to a call queue.
D.Create a voice routing policy and assign it to the user.
AnswerD

A voice routing policy (dial plan) defines normalization rules and PSTN usage records that map dialed numbers to the correct routes to the Session Border Controller (SBC). Without an assigned voice routing policy, Teams cannot determine how to route the call, causing immediate failure. Assigning the policy ensures the dialed number is normalized and matched to a PSTN usage, which is then associated with a route.

Why this answer

For Direct Routing, outbound PSTN calls require a voice routing policy that contains normalization rules and PSTN usage records linked to a voice route. Without this policy assigned, Teams cannot translate the dialed number or determine which SBC to send the call to, resulting in immediate failure. The other options do not provide the necessary routing logic.

Exam trap

The trap here is assuming that a Phone System license alone enables outbound PSTN calling, when a voice routing policy is also required to normalize and route the dialed number.

162
MCQhard

Your organization has a team named 'Field Ops' with 4,000 members. You need to give a small group of dispatchers the ability to post announcements in the General channel while preventing the remaining 3,990 members from starting new conversations. The dispatchers must still be able to reply to existing threads. What should you do?

A.Create a new standard channel named 'Dispatch' and add only the dispatchers as members.
B.Enable channel moderation on the General channel, add the dispatchers as moderators, and set member permissions to not start new posts.
C.Create a messaging policy that disables chat for the 3,990 members and assign it to the team.
D.Assign the dispatchers the Teams Communications Administrator role and configure a meeting policy for the team.
AnswerB

Channel moderation on General lets you grant moderator rights to the dispatchers so they can post announcements, while the member permission 'Allow members to start new posts' can be turned off to stop the 3,990 members from beginning conversations. Replies to existing threads remain possible because reply permission is a separate toggle, so the dispatchers keep working as required.

Why this answer

Channel moderation is designed exactly for this kind of gated posting. Enabling it on General and making the dispatchers moderators lets them publish announcements, while clearing the member ability to start new posts blocks the other 3,990 members from opening conversations. Because replying is controlled independently, members can still participate in existing threads.

Exam trap

The trap here is assuming moderation is all-or-nothing, when starting new posts and replying to existing posts are controlled by separate permissions.

163
MCQeasy

You need to ensure that the 'Tasks by Planner and To Do' app is automatically pinned to the navigation bar for all members of the Sales department in Microsoft Teams. Which policy should you modify or create?

A.App permission policy
B.App setup policy
C.Teams messaging policy
D.Teams update policy
AnswerB

An app setup policy allows administrators to pin apps to the Teams sidebar and determine the installation behavior for users. By creating a custom policy for the Sales department, you can ensure the 'Tasks' app is consistently visible, which streamlines the user experience and ensures that critical business tools are always within reach for the target audience.

Why this answer

To automatically pin an app like 'Tasks by Planner and To Do' to the navigation bar for all members of a department, you need to modify or create an App Setup Policy. This policy defines which apps are pinned and whether users can change them. You can assign the policy to the Sales department group, ensuring the app is pinned for all members.

Exam trap

MS-700 often tests the difference between app setup and app permission policies, tricking candidates into choosing permission policies when the requirement is about pinning apps.

How to eliminate wrong answers

Option A is wrong because App permission policies control whether apps are allowed or blocked, not which apps are pinned. Option C is wrong because Teams messaging policies manage chat and channel features, not app pinning. Option D is wrong because Teams update policies control the Teams client update behavior, not app setup.

164
MCQmedium

A user reports that they are unable to dial out to external PSTN numbers from their Teams client. Which policy must you verify to ensure they have the correct permissions?

A.Teams Meeting policy
B.Teams Calling policy
C.Teams App setup policy
D.Teams Messaging policy
AnswerB

The Calling policy is the specific configuration set that governs whether a user can make or receive calls, including PSTN calls. By modifying this policy, administrators can grant or revoke dial-out permissions, making it the primary place to check when PSTN calling functionality is failing.

Why this answer

The Teams Calling policy controls whether a user can make and receive PSTN calls, including public switched telephone network (PSTN) dial-out permissions. It defines settings such as Make private calls, Call forwarding, and voicemail, and it is the policy that must be assigned to grant external dialing rights. Without the correct calling policy, the user's Teams client will not present the dial pad or will block outbound PSTN calls.

Exam trap

MS-700 often tests the confusion between Teams Calling policy and Teams Meeting policy, since both are assigned per user and both affect voice-related features; candidates must remember that only the Calling policy governs PSTN dial-out permissions.

How to eliminate wrong answers

Option A is wrong because Teams Meeting policy governs meeting features like recording, screen sharing, and lobby settings, not PSTN dialing. Option C is wrong because Teams App setup policy controls which apps are pinned or installed for users, not calling permissions. Option D is wrong because Teams Messaging policy controls chat and messaging features such as edit/delete messages and GIFs, not external calling.

165
MCQhard

You are the Teams administrator for Contoso. A team named 'Field Ops' was created from a Microsoft 365 group and includes a channel named 'Dispatch'. The Dispatch channel must be visible only to the 12 dispatchers in the team, and only those dispatchers should be able to post messages in it. You need to configure the channel so that membership is limited to the dispatchers while all other team members cannot see or join it. What should you do?

A.Change the Dispatch channel's membership type to Private, then add the 12 dispatchers as members of the channel.
B.Use a channel moderation policy to limit who can post, and rely on the team's existing membership to control visibility.
C.Create a new security group containing the dispatchers, then assign the group to the Dispatch channel.
D.Change the Dispatch channel's membership type to Shared and add the dispatchers as shared channel members.
AnswerA

Changing the channel's membership type to Private makes the channel available only to the users explicitly added as channel members, even though they remain members of the parent team. Adding the dispatchers as channel members satisfies both visibility and posting restrictions because non-members cannot see or post in a private channel. This is the supported way to scope a channel to a subset of team members in Microsoft Teams.

Why this answer

A private channel is the only channel membership type that limits both visibility and participation to an explicitly defined set of members within the parent team. By converting Dispatch to a private channel and adding the dispatchers as channel members, non-dispatchers in Field Ops cannot see or post in the channel, while the dispatchers retain access. Shared channels and moderation policies address different collaboration or posting needs and do not provide the required exclusion.

Exam trap

The trap here is assuming that channel moderation or a security group assignment can hide a channel from other team members, when only changing the channel membership type to Private actually restricts visibility and membership.

166
MCQhard

Refer to the exhibit. An administrator runs the Get-CsTeamsMeetingPolicy cmdlet and reviews the output. Users in the organization report that they cannot generate transcripts during confidential meetings. Based on the output, what must the administrator change to enable meeting transcription?

A.Set AllowCloudRecording to false.
B.Set AutoRecording to true.
C.Set AllowTranscription to true.
D.Change LiveCaptionsEnabledType to Enabled.
AnswerC

Changing the AllowTranscription parameter to true enables the underlying capability for users governed by this policy to start transcriptions during meetings. This adjustment directly addresses the reported issue by unlocking the required menu option within the Teams client interface.

Why this answer

Meeting transcription in Microsoft Teams is controlled by the AllowTranscription parameter in the Teams meeting policy. If users cannot generate transcripts, the administrator must set AllowTranscription to true in the assigned policy. Cloud recording and auto-recording are separate settings that do not govern transcription.

Exam trap

MS-700 often tests the confusion between recording, transcription, and live captions, so candidates pick AllowCloudRecording or LiveCaptionsEnabledType instead of the specific AllowTranscription parameter.

How to eliminate wrong answers

Option A is wrong because setting AllowCloudRecording to false would disable recording entirely, which is the opposite of enabling transcription and would not fix the issue. Option B is wrong because AutoRecording controls whether meetings are recorded automatically, not whether transcripts can be generated. Option D is wrong because LiveCaptionsEnabledType governs live captions, a different feature from post-meeting transcription, so changing it does not enable transcript generation.

167
Multi-Selectmedium

You need to restrict a specific group of users from using any third-party apps in Teams, while still allowing them to use all Microsoft-provided apps. Which TWO steps are required to implement this using App Permission Policies?

Select 2 answers
A.Create a custom App Permission Policy and set 'Third-party apps' to 'Block all apps'.
B.Assign the custom App Permission Policy to the specific users.
C.Disable the 'Allow third-party apps' toggle in the Org-wide app settings.
D.Delete all third-party apps from the 'Manage apps' list.
E.Modify the Global (Org-wide default) App Permission Policy.
AnswersA, B

This is the core configuration step. Within the policy, you can independently set the permissions for Microsoft apps, third-party apps, and custom apps. Choosing to block all third-party apps ensures that only the apps developed by Microsoft will be visible and usable for those users.

Why this answer

Option A is correct because a custom App Permission Policy is the mechanism that lets you set the 'Third-party apps' control to 'Block all apps' while leaving Microsoft-provided apps allowed, which is exactly the granular restriction required for this group. Option B is correct because creating a policy alone does nothing until it is assigned to the specific users (or a group) who must be restricted, so the policy must be assigned to those users. Option C is not correct because disabling third-party apps in Org-wide app settings affects the entire tenant, not just the specific group.

Option D is not correct because deleting apps from 'Manage apps' removes them tenant-wide and does not implement a per-user permission restriction. Option E is not correct because modifying the Global (Org-wide default) policy would change behavior for all users rather than only the targeted group.

Exam trap

MS-700 often tests the difference between org-wide app settings and per-user App Permission Policies — the trap is choosing the org-wide toggle or Global policy when the requirement is to restrict only a specific group.

168
MCQmedium

You are the Teams administrator for a company that uses Microsoft Teams. The IT manager reports that some users on the Sales team are seeing the message 'Your organization does not allow you to create teams' when they try to create a new team. You need to identify which policy setting is preventing these users from creating teams. What should you check?

A.The Teams app permission policy assigned to the users.
B.The Microsoft 365 group creation settings in the Microsoft 365 admin center.
C.The meeting policy assigned to the users.
D.The messaging policy assigned to the users.
AnswerB

The ability to create teams is tied to the ability to create Microsoft 365 groups. If group creation is restricted to certain users or disabled, users without permission will see this error when attempting to create a team. Checking the Microsoft 365 group creation settings in the Microsoft 365 admin center will reveal if the Sales team users are allowed to create groups.

Why this answer

The ability to create teams depends on the permission to create Microsoft 365 groups. When group creation is restricted, users without rights receive an error when trying to create a team. The correct setting to verify is the Microsoft 365 group creation configuration in the Microsoft 365 admin center.

Exam trap

The trap here is assuming that Teams-specific policies control team creation, when actually Microsoft 365 group creation settings govern it.

169
MCQhard

You are a Teams administrator for a multinational company. The company uses Direct Routing for PSTN connectivity. A user reports that when they receive an incoming PSTN call, the call rings on their Teams client but when they answer, the call drops immediately. You have verified that the user's voice configuration is correct and that the Session Border Controller (SBC) is reachable. You need to troubleshoot the issue. Which tool should you use to capture and analyze the SIP traffic for this call?

A.Teams client debug logs
B.Session Border Controller (SBC) logs and SIP tracing
C.Microsoft 365 network connectivity test tool
D.Microsoft Teams admin center Call Analytics
AnswerB

SBC logs and SIP tracing capture the SIP signaling between the SBC and Teams. Since the call rings but drops upon answer, the issue likely lies in SIP signaling (e.g., media negotiation, codec mismatch, or SDP issues). Analyzing SBC logs and SIP traces will reveal the exact SIP messages and error codes causing the drop.

Why this answer

For Direct Routing call drops, SIP signaling issues are common. Capturing and analyzing SIP traffic on the SBC provides the detailed SIP messages exchanged with Teams, revealing errors like 488 Not Acceptable Here or 603 Decline. SBC logs and SIP tracing are essential for this level of troubleshooting, whereas other tools offer only high-level or client-side data.

Exam trap

The trap here is assuming that Call Analytics or client logs provide sufficient SIP detail, when in fact SBC-level tracing is required to see the full SIP dialog.

170
MCQmedium

You are a Teams administrator for a company that has a team named 'Engineering' with several channels. The company policy requires that all messages in the 'General' channel of the 'Engineering' team be reviewed by a moderator before being posted. You need to configure this requirement. What should you do?

A.Enable channel moderation for the 'General' channel and add the required moderators.
B.Configure a data loss prevention (DLP) policy that blocks messages containing certain keywords in the 'General' channel.
C.Create a messaging policy in the Teams admin center that requires approval for all messages in the 'Engineering' team.
D.Assign the 'Moderator' role to all members of the 'Engineering' team for the 'General' channel.
AnswerA

Channel moderation allows you to control who can post messages in a channel. By enabling moderation on the 'General' channel and assigning moderators, you ensure that only moderators can post, or that messages require approval before posting. This meets the requirement for review before posting.

Why this answer

To require that messages in a channel be reviewed before posting, you must enable channel moderation for that channel. This feature allows you to designate moderators who can approve or reject messages. It is configured in the channel settings within the Teams client, not through messaging policies or DLP.

Exam trap

The trap here is thinking that messaging policies or DLP can enforce message approval, when only channel moderation provides that capability.

171
Multi-Selectmedium

You need to ensure that only members of the Human Resources department can create new Teams. Which TWO actions must you perform to implement this governance requirement?

Select 2 answers
A.Create an Azure AD security group containing the HR department members.
B.Disable Microsoft 365 Group creation for all users except the HR security group.
C.Assign the Teams Communications Administrator role to all HR department members.
D.Modify the Teams Messaging Policy to disable the 'Create channels' option.
E.Enable the 'Scoped directory search' in the Teams admin center.
AnswersA, B

A security group is necessary to identify the specific subset of users who will be granted the exception to the creation block. Microsoft 365 uses this group within a PowerShell script to map the 'EnableGroupCreation' attribute, allowing only these specific members to bypass the tenant-wide restriction.

Why this answer

Option A is correct because restricting Microsoft 365 Group (and therefore Team) creation is done by allowing a specific Azure AD security group to retain the group-creation right, so you must first create an Azure AD security group that contains the HR department members. Option B is correct because the actual governance control is implemented by disabling Microsoft 365 Group creation for all users while permitting it only for that HR security group, which is configured via the Azure AD directory settings (for example, the EnableGroupCreation / GroupCreationAllowedGroupId settings in the Microsoft 365 Groups / Azure AD blade or the corresponding Microsoft Graph/Exchange Online policy). Together these two actions ensure that only HR members can create new Teams.

Option C is not relevant because the Teams Communications Administrator role governs calling and meeting capabilities, not the ability to create Teams. Option D is incorrect because the Teams Messaging Policy's 'Create channels' option controls channel creation inside existing teams, not team creation. Option E is incorrect because Scoped directory search only limits which users appear in searches, not who can create Teams.

Exam trap

MS-700 often tests the misconception that Teams creation is controlled via Teams admin center policies, when in fact it is governed by Azure AD group creation settings and requires a security group to scope permissions.

172
MCQmedium

A Teams administrator at Contoso needs to ensure that when a user dials an emergency number from a Teams client in the United States, the call is routed to the appropriate Public Safety Answering Point (PSAP) and includes the user's validated street address. The organization uses Microsoft Calling Plans. What should the administrator configure first?

A.Add and validate an emergency location for the user, then assign it.
B.Create an emergency calling policy and assign it to the user.
C.Enable the user for Enterprise Voice and assign a phone number.
D.Configure a network topology and associate the subnet with a location.
AnswerA

For Calling Plans, the administrator must add and validate an emergency location (civil address) in the Teams admin center and assign it to the user. This address is transmitted to the PSAP during an emergency call. Without a validated location, the call may not route to the correct PSAP or may fail. This is the foundational step for emergency calling.

Why this answer

For Microsoft Calling Plans, emergency calling requires each user to have a validated emergency location assigned. This location is used to route the call to the correct PSAP and to provide the dispatcher with the caller's address. While network topology can be used for dynamic location in Direct Routing, Calling Plans rely on the static assignment of a validated civic address.

Exam trap

The trap here is assuming that enabling Enterprise Voice and assigning a phone number automatically configures emergency calling, when in fact a validated emergency location must be explicitly added and assigned.

173
Multi-Selectmedium

Which TWO actions must you take to allow external users from a specific domain to participate in Teams chats?

Select 2 answers
A.Add the domain to the Allow list in External Access.
B.Enable Guest Access for the organization.
C.Configure the External Access setting to 'Allow only specific external domains'.
D.Assign a Guest Access policy to the external users.
E.Create a shared channel for the external domain.
AnswersA, C

Adding a domain to the allow-list is a mandatory step for restricted external access configurations. Without this entry, Microsoft 365 blocks incoming and outgoing communication requests from that specific domain, effectively preventing any Teams chat interaction between users of the two organizations involved in the collaboration.

Why this answer

Option A is correct because adding the specific domain to the Allow list in External Access (Teams admin center > Users > External access) explicitly permits users with that domain to communicate with your users in Teams chats. Option C is correct because the External Access setting must be configured to 'Allow only specific external domains' so that the Allow list is actually enforced; without this mode, the domain list is not applied. Together, A and C satisfy the requirement of allowing only one specific external domain to participate in chats.

Option B is incorrect because Guest Access governs guests who are invited into the tenant via Azure AD B2B, not federated external users chatting from their own tenant. Option D is incorrect because Guest Access policies apply to guest accounts in your tenant, not to external users in another domain. Option E is incorrect because shared channels are for cross-organization collaboration within channels and do not govern external chat participation for a specific domain.

Exam trap

The trap is confusing external access (federation) with guest access. Candidates often think enabling guest access is needed for external chats, but guest access is for inviting external users into teams, not for one-to-one chats. Also, shared channels are sometimes mistaken as a solution for external chat, but they are for collaboration within a team.

174
MCQmedium

You are a Teams administrator for a company that uses Microsoft 365. The company has a team named 'Sales' with 50 members. The sales manager wants to add a new tab to the 'Sales' team's general channel that displays a Power BI report. The report is in a Power BI workspace that is not currently connected to Teams. You need to add the tab with the least administrative effort. What should you do?

A.In the Power BI service, go to the workspace, select 'Embed', and generate a secure embed code. Then, in Teams, add a Website tab and paste the code.
B.In Teams, go to the general channel, select '+', choose 'Website', and paste the URL of the Power BI report.
C.In the Power BI service, open the report, select 'Export', and choose 'Embed in Teams'.
D.In Teams, go to the general channel, select '+', choose Power BI, and select the report from the workspace.
AnswerD

This is correct because adding a Power BI tab directly from Teams allows you to select a report from any workspace you have access to. It requires no additional configuration and is the simplest method. The tab will display the report and update automatically.

Why this answer

The simplest way to add a Power BI report to a Teams channel is to use the built-in Power BI tab. This method allows you to browse and select reports from any workspace you have access to, and it automatically handles authentication and rendering. It requires no additional configuration or code.

Exam trap

The trap here is overcomplicating the process by using embed codes or website tabs, when the native Power BI tab is the straightforward solution.

175
MCQmedium

A company wants to provide users with the ability to use Dropbox and Google Drive as file storage options within Teams channels. Where should an administrator enable these third-party storage providers?

A.Teams Messaging Policies
B.Org-wide settings > Teams settings
C.Teams App Setup Policies
D.SharePoint Admin Center Settings
AnswerB

Within the Teams admin center, the 'Teams settings' section under 'Org-wide settings' (or 'Files' in the newer interface) contains the toggle switches for third-party storage providers. Enabling Dropbox and Google Drive here makes these services available for all users to add as tabs or storage locations.

Why this answer

Third-party storage providers like Dropbox and Google Drive are enabled at the tenant level in the Teams admin center under Org-wide settings > Teams settings. This section includes the 'Files' settings where you can turn on or off cloud storage options such as Dropbox, Google Drive, Box, and ShareFile. Once enabled, users can add these as storage locations when working with files in Teams channels.

Exam trap

MS-700 often tests the location of file storage settings, tricking candidates into choosing SharePoint Admin Center or Messaging Policies when the correct place is Org-wide Teams settings.

How to eliminate wrong answers

Option A is wrong because Teams Messaging Policies control chat and channel messaging features (e.g., edit/delete messages, giphy), not file storage providers. Option C is wrong because App Setup Policies govern which apps are pinned and available, not the underlying file storage integrations. Option D is wrong because SharePoint Admin Center settings manage SharePoint sites and storage, but the toggle for third-party storage providers in Teams is specifically in the Teams admin center.

176
Multi-Selectmedium

You are implementing a Microsoft 365 Group naming policy to ensure all new Teams follow a standard naming convention. Which THREE requirements or components are necessary to configure this using the Azure Active Directory (Azure AD) admin center? (Each correct answer presents part of the solution.)

Select 3 answers
A.Azure AD Premium P1 or P2 licenses
B.A list of blocked words
C.A defined prefix/suffix naming convention
D.A Teams Messaging policy
E.A Skype for Business Server hybrid connection
AnswersA, B, C

Configuring and enforcing a Microsoft 365 Group naming policy requires that at least one user in the organization has an Azure AD Premium P1 or P2 license. This license level unlocks advanced governance features necessary for managing group lifecycles and naming standards across the entire Microsoft 365 tenant.

Why this answer

The Microsoft 365 Groups naming policy is configured in Azure AD and requires Azure AD Premium P1 or P2 licenses (A), since the feature is a premium Azure AD capability; without P1/P2 the naming policy settings are unavailable. A list of blocked words (B) is one of the two configurable components of the policy, used to prevent specific terms from appearing in group names. A defined prefix/suffix naming convention (C) is the other required component, letting you enforce a standard prefix and/or suffix (optionally with user attributes like [Department]) on new group and Teams names.

A Teams Messaging policy (D) governs chat and messaging features in Teams and has nothing to do with group naming, and a Skype for Business Server hybrid connection (E) is unrelated to Azure AD group naming policy configuration.

Exam trap

MS-700 often tests the misconception that naming policies are configured in the Teams admin center or that they require a Teams-specific policy, when in fact they are Azure AD directory settings requiring Premium P1/P2 licensing.

177
MCQmedium

You are a Teams administrator for a company that uses Microsoft Teams. Several users report that during meetings, their shared content appears blurry and they experience delays when presenting. You need to determine if the issue is related to network bandwidth. Which report should you use?

A.Microsoft 365 network connectivity test tool
B.Call Quality Dashboard (CQD)
C.Teams usage report in the Teams admin center
D.Teams client diagnostic logs
AnswerB

The Call Quality Dashboard (CQD) aggregates media quality data, including bandwidth usage, packet loss, jitter, and latency. It can show if there are network bandwidth issues affecting screen sharing and video. By analyzing CQD reports, you can identify if poor quality is due to insufficient bandwidth, making it the correct tool for this scenario.

Why this answer

The Call Quality Dashboard is designed to provide aggregated media quality data, including network bandwidth metrics, for meetings and calls. It allows administrators to filter by various dimensions and identify patterns, such as poor screen sharing quality due to insufficient bandwidth. Other tools like usage reports or client logs do not offer the necessary network performance insights for this scenario.

Exam trap

The trap here is selecting a usage report or connectivity test instead of the Call Quality Dashboard, which is specifically built for analyzing media quality and network bandwidth trends.

178
Multi-Selectmedium

Which TWO of the following settings can be configured via a Messaging policy in Microsoft Teams? (Choose two.)

Select 2 answers
A.Allow users to delete sent messages
B.Allow users to create private channels
C.Allow Giphy in conversations
D.Restrict access to third-party apps
E.Configure meeting lobby settings
AnswersA, C

The ability to delete sent messages is a configurable setting within the messaging policy. This is often restricted in highly regulated industries to ensure that all communication is preserved for eDiscovery purposes, demonstrating the importance of granular control over user communication habits within the environment.

Why this answer

A Messaging policy in Microsoft Teams controls chat and channel messaging features, and it includes the 'Allow users to delete sent messages' setting (Option A), which lets an admin enable or disable the ability for users to delete messages they have sent. It also includes the 'Allow Giphy in conversations' setting (Option C), which controls whether Giphy content (and its content rating) is permitted in chats and channels. Option B (creating private channels) is governed by Teams policies and channel creation settings, not Messaging policies.

Option D (restricting third-party apps) is controlled via app permission policies and app setup policies. Option E (meeting lobby settings) is configured through meeting policies, not Messaging policies.

Exam trap

MS-700 often tests the boundaries of each policy type. Candidates may think messaging policies control private channels or app access, but those are governed by Teams policies and App Permission Policies respectively.

179
Multi-Selectmedium

Which TWO of the following are valid ways to create a new team in Microsoft Teams? (Choose two.)

Select 2 answers
A.Using the Teams client 'Join or create a team' button
B.Using the Teams admin center
C.Using the Microsoft Purview compliance center
D.Using the Azure AD Conditional Access portal
E.Using the Microsoft 365 Security Center
AnswersA, B

This is the standard end-user method for creating a team. It is the most common way for users to self-provision teams, and it respects any tenant-level restrictions or naming policies that may be configured by the organization's administrators to maintain order within the environment.

Why this answer

Option A is correct because the Teams client provides a 'Join or create a team' button that lets users create a new team directly from the app, either from scratch or from an existing Microsoft 365 group or template. Option B is correct because the Teams admin center allows administrators to create and manage teams, including assigning owners and members, through the Teams management interface. Option C is incorrect because the Microsoft Purview compliance center is used for compliance, data governance, and eDiscovery tasks, not for creating teams.

Option D is incorrect because the Azure AD Conditional Access portal is used to configure access policies and sign-in conditions, not to create Teams teams. Option E is incorrect because the Microsoft 365 Security Center is focused on security posture, threat protection, and incident management, not team creation.

Exam trap

The trap is that Microsoft 365 has many admin portals, and candidates assume any 'admin center' can create teams — only the Teams client and Teams admin center (plus PowerShell/Graph) are valid creation surfaces.

180
MCQhard

You are a Teams administrator for a large organization that uses Microsoft Teams meetings. The company policy requires that all meeting recordings be stored for 90 days and then automatically deleted. You need to implement this policy with minimal administrative effort. What should you do?

A.Use a PowerShell script to delete recordings older than 90 days from SharePoint and OneDrive.
B.Configure a meeting policy in the Teams admin center to set recordings to expire after 90 days.
C.Create a retention policy in the Microsoft 365 compliance center for Teams recordings with a 90-day retention period.
D.Set the Teams meeting recording storage to Stream and configure a Stream retention policy for 90 days.
AnswerC

A retention policy in the Microsoft 365 compliance center can be applied to Teams meeting recordings stored in SharePoint and OneDrive. Setting a 90-day retention period with deletion after that period ensures recordings are automatically removed. This is the centralized, minimal-effort solution that meets the requirement without manual intervention.

Why this answer

The correct approach is to use a retention policy in the Microsoft 365 compliance center. Retention policies can target Teams meeting recordings, which are stored in SharePoint and OneDrive, and automatically delete them after 90 days. This is a built-in, centralized feature that requires minimal administrative effort and ensures compliance.

Meeting policies and custom scripts do not provide the same automated, policy-based deletion.

Exam trap

The trap here is assuming that meeting policies in the Teams admin center control recording retention, when actually retention is managed in the compliance center.

181
MCQmedium

Your organization uses Microsoft Teams for all internal and external meetings. The legal department requires that all meetings organized by legal team members include a disclaimer that participants must acknowledge before joining. You need to configure this without affecting other departments. What should you do?

A.Create a meeting policy with a custom disclaimer and assign it to the legal team members.
B.Configure a meeting template with the disclaimer and require the legal team to use it for all meetings.
C.Set up a sensitivity label with the disclaimer text and assign it to the legal team.
D.Use Teams admin center to enable a global disclaimer for all meetings and instruct other departments to ignore it.
AnswerA

Meeting policies in Teams support a custom disclaimer setting that displays a disclaimer to participants before they join a meeting. By creating a new meeting policy with the required disclaimer text and assigning it to the legal team members, you ensure that only meetings organized by those users show the disclaimer. This meets the requirement without impacting other departments.

Why this answer

The correct approach is to use a Teams meeting policy with a custom disclaimer. This policy setting allows administrators to provide disclaimer text that appears to participants before they join a meeting. By assigning this policy only to legal team members, the disclaimer will only appear for meetings they organize, leaving other departments unaffected.

Exam trap

The trap here is assuming that meeting templates or sensitivity labels can enforce a disclaimer, when in fact only meeting policies include a dedicated custom disclaimer setting.

182
MCQmedium

You want to prevent users from sharing GIFs in Teams chats. Which policy should you modify to accomplish this?

A.Teams policy
B.Messaging policy
C.Meeting policy
D.App permission policy
AnswerB

Messaging policies contain the settings for chat-based interactions, including the use of Giphy, memes, and stickers. By updating the messaging policy assigned to your users, you can toggle these settings off, effectively preventing the use of GIFs in any chat or channel conversation.

Why this answer

The Messaging policy in Microsoft Teams controls user-level chat and channel messaging features, including the ability to send and receive GIFs. Specifically, the 'Use Giphys in conversations' setting within the Messaging policy determines whether users can insert animated images (GIFs) into their messages. By setting this to 'Off', you prevent users from sharing GIFs in chats.

Other policies like Teams policy, Meeting policy, or App permission policy do not govern this specific chat feature.

Exam trap

MS-700 often tests the distinction between different policy types in Teams, and candidates frequently confuse Messaging policies with Teams policies or Meeting policies, leading them to select the wrong policy for controlling chat features like GIFs.

How to eliminate wrong answers

Option A is wrong because Teams policies control team-level settings such as guest access, @mentions, and channel creation, not the ability to share GIFs in chats. Option C is wrong because Meeting policies govern features within meetings, such as recording, screen sharing, and chat during meetings, not general chat messaging. Option D is wrong because App permission policies control which third-party or custom apps are available to users, not the built-in GIF sharing capability in chats.

183
MCQeasy

Which report would you use to identify which users in your organization are using the Teams desktop client versus the web client?

A.Teams User Activity report
B.Teams Device Usage report
C.Teams Meeting report
D.Teams App Usage report
AnswerB

This report specifically tracks the platform used to access Teams, categorizing activity by desktop, web, or mobile. It is the correct report to determine which users are accessing the service via the browser versus the dedicated desktop application for support or compliance reasons.

Why this answer

The Teams Device Usage report in the Microsoft 365 admin center breaks down usage by device type — Windows, Mac, iOS, Android, web, and others — so you can see which users are on the desktop client versus the web client. It provides per-user and aggregate views of device distribution, which is exactly what the question asks for. The User Activity report shows activity counts but not device breakdown.

Exam trap

MS-700 often tests the confusion between the User Activity report (what users do) and the Device Usage report (what they do it on) — candidates pick User Activity because it sounds more comprehensive, but it lacks device-type granularity.

How to eliminate wrong answers

Option A is wrong because the Teams User Activity report shows counts of messages sent, calls made, and meetings attended per user, but does not break down usage by device type (desktop vs. web). Option C is wrong because the Teams Meeting report focuses on meeting counts, durations, and participant numbers, not client type. Option D is wrong because the Teams App Usage report shows which third-party or first-party apps (tabs, bots, connectors) are used, not which client platform users connect from.

184
MCQmedium

Your organization requires that all new Teams created by users must automatically include a specific set of tabs and a standard channel structure. Which feature should you configure to achieve this requirement?

A.Microsoft 365 group naming policies
B.Team templates
C.Organization-wide teams
D.Sensitivity labels
AnswerB

Team templates provide a predefined structure of channels and apps that are automatically provisioned when a user creates a new team. This ensures that every team starts with the required configuration, minimizing administrative overhead and guaranteeing that essential collaboration tools are immediately available to the members.

Why this answer

Team templates in Microsoft Teams let administrators define a reusable structure — channels, tabs, apps, and settings — that is applied automatically whenever a user creates a new team from that template. By publishing a custom team template and setting it as the default (or restricting team creation to templates), the organization ensures every new team inherits the standard channel structure and tabs.

Exam trap

MS-700 often tests the confusion between governance features — candidates pick naming policies or sensitivity labels because they sound like 'standards enforcement,' but only team templates actually provision channels and tabs at creation time.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 group naming policies only enforce naming conventions and blocked words for groups/teams — they do not control channel structure or tabs. Option C is wrong because organization-wide teams are a single large team that includes everyone in the tenant (up to 10,000 members); they are not a mechanism for templating new user-created teams. Option D is wrong because sensitivity labels classify and protect content (e.g., encryption, external sharing restrictions) but do not provision channels or tabs when a team is created.

185
MCQmedium

Your company is planning a transition from Skype for Business Online to Microsoft Teams. You need to ensure that users can only use Microsoft Teams for chat and meetings, but they must still be able to join Skype for Business meetings hosted by external partners. Which coexistence mode should you assign to these users?

A.Islands mode
B.Skype for Business only mode
C.Teams Only mode
D.Skype for Business with Teams Collaboration mode
AnswerC

Teams Only mode ensures all chat and meetings are handled by Microsoft Teams, satisfying the requirement. Even in this mode, users can still use the Skype for Business client to join meetings hosted by external users who have not yet migrated, providing the necessary interoperability while centralizing internal communications.

Why this answer

Teams Only mode ensures users use Microsoft Teams for all chat and meetings, while still allowing them to join Skype for Business meetings hosted by external partners. This mode completes the upgrade to Teams while preserving interoperability for external Skype meetings.

Exam trap

MS-700 often tests the misconception that Teams Only mode blocks joining Skype for Business meetings — in fact, Teams Only users can still join external Skype meetings, which is exactly what this scenario requires.

How to eliminate wrong answers

Option A is wrong because Islands mode allows users to use both Teams and Skype for Business concurrently, which does not meet the requirement to use only Teams. Option B is wrong because Skype for Business only mode keeps users on Skype for Business, contradicting the requirement to use Teams. Option D is wrong because Skype for Business with Teams Collaboration mode allows Teams for chat and channels but keeps meetings in Skype for Business, which does not satisfy 'only Teams for chat and meetings.'

186
MCQeasy

You are setting up a Microsoft Teams Room in a conference room. What type of account is required to properly configure the Teams Room device and allow it to be invited to meetings?

A.A standard User account with an E5 license
B.A Guest account from an external tenant
C.A Resource account with a Teams Room license
D.A Service Principal in Azure Active Directory
AnswerC

Resource accounts are specialized accounts for meeting rooms and shared devices. When combined with a Teams Room Basic or Pro license, they enable the device to join meetings, share content, and be discovered in the global address list as a bookable location for internal users.

Why this answer

Microsoft Teams Rooms require a dedicated resource account (room mailbox) that is assigned a Teams Rooms license (such as Teams Rooms Pro or the legacy Standard). The resource account is what gets invited to meetings and what the room device signs in as, allowing it to auto-accept and join scheduled meetings. A standard user account, guest account, or service principal cannot fulfill the calendar/meeting processing role that a resource account provides.

Exam trap

MS-700 often tests the confusion between a resource account (room mailbox) and a regular user account — candidates assume any licensed account works, but Teams Rooms specifically require a resource account with a Teams Rooms license for calendar and meeting processing.

How to eliminate wrong answers

Option A is wrong because a standard user account with an E5 license is a personal identity — Teams Rooms need a resource (room) mailbox so the device can process meeting invites and manage the room calendar, and E5 does not include the Teams Rooms license. Option B is wrong because a guest account from an external tenant cannot own a room mailbox or be licensed for Teams Rooms in the host tenant. Option D is wrong because a Service Principal is an application identity in Azure AD used for app-only authentication; it has no mailbox and cannot be invited to meetings or manage a room calendar.

187
MCQmedium

A user reports poor audio quality during Teams calls. You need to identify the specific network metrics causing the issue for a specific session. Which tool should you use?

A.Microsoft 365 Admin Center Usage Reports
B.Teams Call Analytics
C.Microsoft Purview Audit Logs
D.Call Quality Dashboard (CQD)
AnswerB

Call Analytics provides detailed per-user and per-session telemetry, including network performance, device information, and client versions. This tool is specifically designed to troubleshoot individual call issues by exposing technical metadata that helps pinpoint whether the failure occurred on the local network or the internet backbone.

Why this answer

Teams Call Analytics provides per-user, per-session diagnostic data including network metrics (jitter, packet loss, latency, round-trip time) for specific calls. It is designed for troubleshooting individual call quality issues and shows the exact metrics affecting a session. This makes it the correct tool for identifying why a specific user experienced poor audio.

Exam trap

MS-700 often tests the confusion between Call Analytics (per-user, per-session troubleshooting) and Call Quality Dashboard (org-wide aggregate trending), causing candidates to pick CQD for individual session diagnosis.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Admin Center Usage Reports show adoption and activity trends, not per-session network metrics. Option C is wrong because Microsoft Purview Audit Logs track administrative and user activities for compliance, not call quality telemetry. Option D is wrong because Call Quality Dashboard (CQD) aggregates quality data across the organization for trend analysis, not for drilling into a single user's specific session — Call Analytics is the per-session tool.

188
MCQeasy

A user reports they cannot sign in to the Microsoft Teams desktop client. You suspect a conditional access policy might be blocking the login. Which tool should you use first to verify if the sign-in attempt was blocked by a policy?

A.Teams Admin Center usage reports
B.Microsoft 365 Connectivity Test Tool
C.Call Quality Dashboard (CQD)
D.Microsoft Entra ID sign-in logs
AnswerD

The sign-in logs in Microsoft Entra ID provide a comprehensive record of all login attempts. They specify the status of each attempt and detail which conditional access policies were triggered, allowing administrators to pinpoint exactly why a user's access to Teams was denied.

Why this answer

Microsoft Entra ID sign-in logs record every authentication attempt, including the conditional access policies evaluated and whether access was granted, blocked, or required MFA. They show the specific policy that applied and the result, making them the definitive tool to verify if a conditional access policy blocked a Teams sign-in. This is the first place to check for policy-related sign-in failures.

Exam trap

MS-700 often tests the confusion between sign-in logs (authentication and conditional access events) and audit logs (administrative and user activity), causing candidates to pick the wrong log for diagnosing policy blocks.

How to eliminate wrong answers

Option A is wrong because Teams Admin Center usage reports show activity and adoption metrics, not authentication or policy evaluation details. Option B is wrong because the Microsoft 365 Connectivity Test Tool diagnoses network connectivity and performance issues, not conditional access policy blocks. Option C is wrong because Call Quality Dashboard reports on media quality metrics, not sign-in or authentication events.

189
MCQmedium

You are the Teams administrator for a company that uses Microsoft 365. The company wants to allow users to add third-party cloud storage services, such as Dropbox and Google Drive, to Teams chats and channels. However, the security team requires that only approved services be allowed. You need to configure Teams to permit only specific cloud storage providers. What should you do?

A.Configure a conditional access policy in Azure AD that blocks access to unapproved cloud storage services.
B.In the Teams admin center, go to Teams settings > Files and modify the Cloud storage options to enable only the approved providers.
C.Use the Set-CsTeamsClientConfiguration cmdlet to set the -AllowDropBox and -AllowGoogleDrive parameters to $false.
D.In the Teams admin center, go to Teams apps > Permission policies and create a custom policy that allows only the approved cloud storage apps.
AnswerB

The Cloud storage options in Teams settings allow administrators to enable or disable specific third-party storage providers for the entire organization. By enabling only the approved providers, you restrict users to those services. This directly meets the requirement to permit only specific cloud storage providers. This is the correct location to configure this setting.

Why this answer

The correct action is to modify the Cloud storage options in Teams settings. This allows you to enable only the approved third-party storage providers organization-wide. Other options either target the wrong settings (app permission policies, conditional access) or use cmdlets that do not control cloud storage providers.

This configuration ensures that users can only add approved services to Teams.

Exam trap

The trap here is confusing app permission policies with cloud storage settings; permission policies control app availability, not the storage providers that can be integrated into Teams.

190
MCQmedium

A user is experiencing issues with app performance in Teams. You want to view the current app permission policy assigned to this specific user. Which tool is most appropriate?

A.Microsoft 365 Security Center
B.Teams admin center
C.Azure Active Directory admin center
D.Microsoft Purview eDiscovery
AnswerB

The Teams admin center allows administrators to navigate to the 'Users' tab, select a specific user, and view their assigned policies, including app permission policies. This direct approach is the standard procedure for auditing and troubleshooting policy-related issues for individual users within a Microsoft 365 tenant.

Why this answer

The Teams admin center is the primary tool for managing and viewing app permission policies assigned to users. Administrators can navigate to Teams apps > Permission policies, select a policy, and view its assigned users, or use the 'Manage users' option to see which policy applies to a specific user. This provides a direct way to audit app permissions for troubleshooting.

Exam trap

MS-700 often tests the appropriate admin portal for specific tasks, tricking candidates into choosing Azure AD or Security Center when the Teams admin center is the correct tool for app permission policies.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Security Center focuses on security and compliance across services, not on Teams app permission policies. Option C is wrong because Azure AD admin center manages user identities and groups, not Teams-specific app policies. Option D is wrong because Microsoft Purview eDiscovery is for legal and compliance search, not for viewing app permission assignments.

191
MCQhard

You are a Teams administrator for a large organization that uses Microsoft Teams Rooms on Windows. A meeting room device is not appearing in the Teams Admin Center under Teams devices, and users cannot join meetings from that room. You have verified that the device is powered on and connected to the network. You need to diagnose the issue. What should you check first?

A.Verify that the device is signed in with a resource account that has a Teams Rooms license.
B.Check the network firewall rules to ensure that the device can reach the Teams service endpoints.
C.Verify that the device's firmware is up to date and that it is running a supported version of the Teams Rooms app.
D.Restart the Teams Rooms device and check if it appears after the restart.
AnswerA

Teams Rooms devices must be signed in with a resource account that has a Microsoft Teams Rooms license assigned. Without a valid license, the device cannot register with Teams and will not appear in the Teams Admin Center. This is a common misconfiguration. Checking the account and license is the first step to ensure the device can authenticate and be managed.

Why this answer

Teams Rooms devices require a resource account with a Teams Rooms license to authenticate and register with the Teams service. Without a valid license, the device will not appear in the Teams Admin Center and cannot join meetings. Therefore, verifying the resource account and its license is the critical first step.

Other checks like network or firmware are secondary.

Exam trap

The trap here is assuming that network connectivity or device restart will resolve the issue, when the most common cause is a missing or misconfigured resource account license.

192
MCQmedium

The Human Resources department reports that inappropriate animated GIFs are appearing in their team chats. You need to restrict the Giphy content to only 'Strict' ratings for the HR team without affecting other departments. What should you do?

A.Modify the Global messaging policy to use the Strict Giphy rating.
B.Create a custom messaging policy and assign it to the HR users.
C.Adjust the Giphy settings in the Microsoft 365 Tenant Wide settings.
D.Change the HR team's privacy setting to Private.
AnswerB

Custom messaging policies are the correct administrative tool for applying specific chat settings to a subset of users. By setting the Giphy content rating to 'Strict' within this custom policy and then assigning it to HR staff, you meet the requirement of localized control without impacting the rest of the organization's messaging capabilities.

Why this answer

To restrict Giphy content to 'Strict' for only the HR team without affecting other departments, you create a custom messaging policy in the Teams admin center, set the Giphy content rating to Strict, and assign the policy to HR users. Messaging policies control per-user chat and channel settings including Giphy ratings, and custom policies allow granular scoping.

Exam trap

MS-700 often tests the difference between Global (org-wide) policies and custom policies, tricking candidates into modifying the Global policy when the requirement is to scope a setting to a single department.

How to eliminate wrong answers

Option A is wrong because modifying the Global (Org-wide default) messaging policy would apply the Strict Giphy rating to every user in the tenant, affecting all departments, not just HR. Option C is wrong because there is no separate 'Giphy settings' tenant-wide toggle outside of messaging policies — Giphy control lives inside messaging policies. Option D is wrong because team privacy settings (Private vs.

Public) control membership visibility, not content filtering or Giphy ratings.

193
MCQeasy

A user complains that during a Teams meeting, they could hear others but others could not hear them. You want to quickly verify if the user's microphone is functioning correctly within Teams. Which tool should you use?

A.Teams device settings
B.Call Analytics
C.Microsoft 365 network connectivity test
D.Network Planner
AnswerA

The Teams device settings include a 'Make a test call' feature that allows users to record a message and play it back, verifying microphone and speaker functionality. This is a quick, user-driven test to confirm if the microphone is working. It directly addresses the need to check the microphone in real time.

Why this answer

The 'Make a test call' feature in Teams device settings is designed to let users verify their microphone and speakers by recording and playing back a message. It is the fastest way to confirm if the microphone is capturing audio. Other tools focus on network or call quality metrics but do not provide a direct microphone test.

Exam trap

The trap here is thinking Call Analytics can test a microphone in real time, but it only reports on past sessions.

194
MCQmedium

A user complains that their screen sharing quality is blurry during calls. Which metric in Call Analytics is most relevant to investigate this?

A.Audio Jitter
B.Round Trip Time (RTT)
C.Video/Sharing Bitrate
D.Signaling latency
AnswerC

The bitrate indicates how much data is being transmitted per second for the screen sharing stream. If the bitrate is low, the Teams client will dynamically reduce the resolution, resulting in the blurry images that the user observes during their presentation.

Why this answer

Video and screen sharing quality in Teams is directly governed by the video/sharing bitrate reported in Call Analytics. A low bitrate indicates the encoder is sending fewer bits per second, which manifests as blurry or pixelated video. Investigating this metric tells you whether the issue is bandwidth, network congestion, or a device/encoder limitation.

Exam trap

MS-700 often tests the distinction between audio-quality metrics (jitter, packet loss, RTT) and video-quality metrics (bitrate, frame rate), and candidates incorrectly pick RTT or jitter when the complaint is specifically about blurry video.

How to eliminate wrong answers

Option A is wrong because audio jitter affects voice quality (choppy or robotic audio), not screen sharing sharpness — jitter is variation in packet arrival time for audio streams. Option B is wrong because Round Trip Time measures network latency between endpoints, which affects responsiveness and delay but does not directly cause blurry video; high RTT causes lag, not low resolution. Option D is wrong because signaling latency relates to call setup and control messages (SIP signaling), not the media stream quality during an active call.

195
Multi-Selectmedium

Which TWO of the following are common indicators in the Call Analytics 'Advanced' view that a call was impacted by a poor local network connection?

Select 2 answers
A.High round-trip time (RTT)
B.CPU utilization over 90%
C.High packet loss
D.Low participant count
E.Unsupported client version
AnswersA, C

A high RTT indicates significant network latency. When this value exceeds thresholds, it suggests the local network is struggling to handle the traffic or the ISP route is heavily congested, which directly leads to audio delays and choppy video during a Teams session.

Why this answer

High round-trip time (RTT) (Option A) is a correct indicator because elevated RTT in the Call Analytics Advanced view reflects latency on the local network path, meaning packets are taking too long to traverse the connection and degrading real-time media quality. High packet loss (Option C) is also correct because lost packets on the local network directly cause audio/video gaps, jitter, and retransmissions that Call Analytics flags as network-related call quality problems. The other options do not belong: CPU utilization over 90% (B) points to endpoint resource exhaustion rather than a network connection issue, low participant count (D) is simply a call size metric and not a quality indicator, and an unsupported client version (E) is a compatibility/software issue unrelated to local network conditions.

Exam trap

MS-700 often tests the distinction between network-layer indicators (RTT, packet loss, jitter) and endpoint or service indicators (CPU, client version) — candidates pick CPU utilization because it 'sounds like' a performance problem, but the question specifically asks about local network connection issues.

196
MCQhard

You are the Teams administrator for a large organization. Users in the finance department report that they cannot start new chats with external partners who use Teams. Internal chats work fine. You need to troubleshoot the issue. Which policy should you check first?

A.Messaging policy
B.Teams app permission policy
C.Meeting policy
D.External access policy
AnswerD

External access policies control whether users can communicate with people outside the organization who are using Teams. If external access is disabled for the finance users, they cannot start chats with external partners. Checking this policy first is logical because the issue is specific to external chats while internal chats work, pointing to a policy that governs external communication.

Why this answer

The external access policy is the correct place to check because it specifically governs whether users can communicate with external Teams users. If the policy is set to block external access, users will be unable to start chats with partners outside the organization. The other policies control different aspects of Teams functionality and would not affect external chat initiation.

Exam trap

The trap here is mixing up external access with guest access or other policies, assuming any external communication setting controls chat.

197
MCQmedium

Your organization requires that all Teams meeting chats be deleted after 90 days. Which tool should you use to implement this retention requirement?

A.Teams admin center Messaging policy.
B.Microsoft Purview compliance portal Retention policy.
C.Teams admin center Org-wide settings.
D.Exchange admin center Mailbox retention tags.
AnswerB

Retention policies in the Purview portal are designed to enforce data lifecycle management. By applying a policy to Teams chats, you can automatically purge messages after a 90-day window, ensuring that the organization adheres to its data governance and privacy policies consistently across the entire tenant.

Why this answer

Retention requirements for Teams meeting chats are enforced through Microsoft Purview retention policies, which can target Teams chat and channel messages and delete them after a specified period (e.g., 90 days). Purview retention policies apply at the workload level and are the correct tool for compliance-driven deletion of Teams messages.

Exam trap

MS-700 often tests the confusion between Teams admin center messaging policies (feature control) and Purview retention policies (compliance deletion), causing candidates to pick a Teams admin center option for a retention requirement.

How to eliminate wrong answers

Option A is wrong because Teams admin center Messaging policies control user-level chat and messaging features (e.g., edit/delete permissions, GIFs), not retention or deletion schedules. Option C is wrong because Org-wide settings in Teams admin center govern tenant-wide feature toggles (e.g., apps, meetings), not message retention. Option D is wrong because Exchange mailbox retention tags apply to Exchange email items, not Teams meeting chats, which are stored in Exchange Online but managed via Purview retention policies for Teams.

198
MCQmedium

A user reports that they cannot see the 'Meet Now' option in their Microsoft Teams client. You need to determine the cause. Which policy setting should you check?

A.The app permission policy assigned to the user, specifically the 'Allow external apps' setting.
B.The meeting policy assigned to the user, specifically the 'Allow Meet Now' setting.
C.The messaging policy assigned to the user, specifically the 'Allow chat' setting.
D.The live events policy assigned to the user, specifically the 'Allow scheduling' setting.
AnswerB

The 'Allow Meet Now' setting in the Teams meeting policy controls whether users can start ad-hoc meetings. If this setting is disabled, the 'Meet Now' option will not appear. This is the most direct policy to check when a user reports missing 'Meet Now' functionality, as it specifically governs that feature.

Why this answer

The 'Meet Now' option is controlled by the 'Allow Meet Now' setting in the Teams meeting policy. If this setting is disabled, users will not see the option to start an instant meeting. Checking the meeting policy is the correct troubleshooting step.

Other policies, such as messaging or app permission policies, do not govern this feature.

Exam trap

The trap here is confusing meeting policies with messaging or app policies, when only the meeting policy contains the 'Allow Meet Now' setting.

199
MCQhard

You are investigating a report that a specific Microsoft Teams meeting had poor audio quality. The meeting occurred 20 hours ago. You need to analyze the call quality metrics for that meeting. Which tool should you use?

A.Call Quality Dashboard (CQD)
B.Microsoft 365 Service Health Dashboard
C.Call Analytics in the Microsoft Teams admin center
D.Teams user activity report
AnswerC

Call Analytics provides detailed per-user and per-meeting call quality data for the last 30 days. Since the meeting occurred 20 hours ago, it falls within the retention window, and you can filter by meeting or user to analyze metrics like packet loss, jitter, and latency. This is the appropriate tool for troubleshooting a specific meeting's audio quality.

Why this answer

Call Analytics in the Microsoft Teams admin center is specifically designed to troubleshoot call and meeting quality for individual users and meetings within the last 30 days. It provides detailed metrics such as packet loss, jitter, and latency. Since the meeting occurred 20 hours ago, it is within the retention period, making Call Analytics the correct tool for this analysis.

Exam trap

The trap here is confusing Call Analytics with Call Quality Dashboard; CQD is for aggregate trends, while Call Analytics provides per-meeting diagnostics.

200
MCQmedium

A manager asks you to provide a quality report for a specific internal meeting that took place 15 days ago. When you check the user's call history in the Teams Admin Center, you cannot find the detailed telemetry for that meeting. What is the most likely reason?

A.Detailed telemetry is only retained for 7 days in Call Analytics.
B.The meeting was not recorded, so no telemetry was captured.
C.Internal-only meetings do not generate Call Analytics data.
D.The user has a 'Teams Exploratory' license.
AnswerA

Microsoft Teams Call Analytics retains granular, advanced telemetry (such as per-minute CPU and network stats) for exactly 7 days. After this period, you can still see that a call occurred, but you cannot access the deep technical details required for thorough quality analysis.

Why this answer

Call Analytics in the Teams admin center retains detailed telemetry for meetings and calls for only 7 days. After that period, the detailed data is no longer available, which explains why the manager cannot find telemetry for a meeting that occurred 15 days ago. This is a built-in retention limit, not related to recording or licensing.

Exam trap

MS-700 often tests the 7-day retention limit of Call Analytics detailed telemetry, and candidates may incorrectly attribute missing data to recording or licensing issues.

How to eliminate wrong answers

Option B is wrong because telemetry is captured for all calls and meetings regardless of whether they are recorded; recording is a separate feature. Option C is wrong because internal-only meetings do generate Call Analytics data; there is no distinction between internal and external meetings for telemetry collection. Option D is wrong because Teams Exploratory licenses still generate Call Analytics data; the limitation is retention time, not licensing.

201
Multi-Selectmedium

You need to monitor the overall health of the Microsoft Teams service and receive notifications about known incidents. Which TWO tools should you use? (Each correct answer presents a complete solution).

Select 2 answers
A.Teams Client Diagnostic Logs
B.Teams Advisor
C.Service health in the Microsoft 365 Admin Center
D.Teams App Store
E.Microsoft 365 Admin mobile app
AnswersC, E

The Service Health page is the official source for status updates on all Microsoft 365 services. It lists active incidents, advisories, and resolved issues, providing detailed information on the scope of the impact and the current progress of the engineering teams toward a fix.

Why this answer

Option C (Service health in the Microsoft 365 Admin Center) is correct because the Service health dashboard provides real-time status of Microsoft Teams and other Microsoft 365 services, showing active incidents, advisories, and planned maintenance, and it allows administrators to configure notifications for service issues. Option E (Microsoft 365 Admin mobile app) is correct because it delivers the same Service health information and push notifications about known incidents and service degradation directly to a mobile device, enabling monitoring on the go. Together these tools give a complete solution for tracking overall Teams service health and receiving incident alerts.

Option A (Teams Client Diagnostic Logs) is incorrect because those logs only capture client-side troubleshooting data for a single user's device, not service-wide health or incident notifications. Option B (Teams Advisor) is incorrect because it is a deployment and adoption guidance tool, not a live service health monitor. Option D (Teams App Store) is incorrect because it is only a catalog for discovering and installing apps, with no health-monitoring capability.

Exam trap

MS-700 often tests the distinction between service-level health monitoring (Admin Center Service health, Admin mobile app) and client-level diagnostics (Teams Client Diagnostic Logs) or planning tools (Teams Advisor), so candidates who pick troubleshooting tools instead of monitoring tools lose the mark.

202
MCQhard

You are a Teams administrator for a large organization. You need to investigate why a specific user's Teams meetings frequently have poor video quality. You have already used Call Analytics and identified that the issue is related to the network. You now want to see a detailed breakdown of the media streams, including the codecs used and the network traversal details, for a particular meeting session. Which tool should you use?

A.Call Quality Dashboard (CQD)
B.Teams admin center > Users > Manage users > Call history
C.Call Analytics session details
D.Microsoft 365 network connectivity test tool
AnswerC

Call Analytics session details provide a granular view of a specific call or meeting, including media stream information such as codecs used, network traversal (relay vs. direct), packet loss, jitter, and latency for each stream. This is exactly what is needed to investigate poor video quality for a particular meeting and understand the technical reasons behind it.

Why this answer

Call Analytics session details offer the deepest level of diagnostic information for a single call or meeting, including per-stream media metrics and codec details. While CQD is excellent for aggregate analysis, it cannot show session-level specifics. Call history and network connectivity tests lack the technical depth required to analyze media streams and network traversal for a specific meeting.

Exam trap

The trap here is assuming that CQD provides session-level details because it is a quality dashboard, when in fact it only offers aggregated data.

203
MCQmedium

A user reports that they cannot find the 'Shift' app in the Teams app store. You verify that the app is enabled at the org-level. Which policy should you check to ensure the user has permission to use the app?

A.Teams App Setup Policy
B.Teams App Permission Policy
C.Teams Messaging Policy
D.Teams Meeting Policy
AnswerB

Permission policies allow you to 'Allow' or 'Block' specific apps for users. If the 'Shift' app (a Microsoft app) is not included in the allowed list of the permission policy assigned to the user, it will be hidden from their view in the app store, regardless of other settings.

Why this answer

Teams App Permission Policies control which apps individual users or groups are allowed to use, overriding the org-level app enablement. Even if an app is enabled tenant-wide, a user assigned to a restrictive permission policy will not see it in the Teams app store. Therefore, the Teams App Permission Policy is the correct policy to check.

Exam trap

MS-700 often tests the confusion between App Setup Policies (which control pinning and installation) and App Permission Policies (which control access). Candidates frequently pick App Setup Policy thinking it governs availability, but it only affects the user's app bar and pre-installed apps.

How to eliminate wrong answers

Option A is wrong because Teams App Setup Policy controls how apps are pinned and installed for users, not whether they are permitted to use them. Option C is wrong because Teams Messaging Policy governs chat and channel messaging features (e.g., edit/delete messages, Giphy), not app availability. Option D is wrong because Teams Meeting Policy controls meeting features such as recording, transcription, and lobby settings, not app access.

204
MCQhard

A company requires all Teams meetings to be recorded for compliance purposes. The administrator must ensure that users cannot delete their own meeting recordings. Where is this permission managed?

A.Teams Meeting Policy in the Teams Admin Center.
B.Microsoft Purview Retention Policies and Labels.
C.Teams Messaging Policy in the Teams Admin Center.
D.The 'Recording' tab in the Teams client settings.
AnswerB

Retention policies in Microsoft Purview can be applied to OneDrive and SharePoint sites to prevent the deletion of files for a specific period. By applying a 'Retain' policy to meeting recordings, you ensure that even if a user tries to delete the file, it remains discoverable for compliance and legal purposes.

Why this answer

Microsoft Purview Retention Policies and Labels are the correct place to manage this because they govern the lifecycle of the meeting recording file itself once it is stored in SharePoint/OneDrive. A retention policy or label can be configured to retain recordings for a set period and prevent users from deleting or editing them, which directly satisfies the compliance requirement. Teams meeting policies only control whether recording is allowed, not what happens to the file afterward.

Exam trap

MS-700 often tests the boundary between Teams meeting policies (which control recording capability) and Purview retention (which controls the recording file's lifecycle), causing candidates to pick the Teams Admin Center option.

How to eliminate wrong answers

Option A is wrong because Teams Meeting Policies in the Teams Admin Center control recording availability, transcription, and who can record — they do not enforce immutability or prevent deletion of the resulting file. Option C is wrong because Teams Messaging Policies govern chat, channel, and messaging features such as edit/delete of chat messages, not meeting recording files stored in SharePoint/OneDrive. Option D is wrong because the Recording tab in the Teams client is a user-facing setting for auto-recording preferences and has no administrative control over retention or deletion rights.

205
Multi-Selectmedium

You are managing external collaboration for your tenant. You want to allow your users to search for and chat with users in another specific organization (domain: contoso.com) but block communication with all other external domains. Which TWO settings must you configure? Each correct answer presents part of the solution.

Select 2 answers
A.In External access, set the domain access to 'Allow only specific external domains'.
B.In External access, add 'contoso.com' to the list of allowed domains.
C.In Guest access, set 'Allow guest access in Teams' to Off.
D.In External access, set the domain access to 'Block all external domains'.
E.In the Microsoft 365 admin center, disable 'External sharing' for SharePoint.
AnswersA, B

Setting the domain access to 'Allow only specific external domains' changes the default behavior of the tenant from 'Open' to 'Restricted'. This ensures that the system will automatically block communication with any domain that is not explicitly added to the allowed list, providing a high level of security.

Why this answer

Option A is correct because in Teams External access you must first change the domain access setting from the default to 'Allow only specific external domains' to switch from allowing all federated domains to a restricted allow-list model. Option B is correct because after selecting that mode you must explicitly add contoso.com to the allowed domains list, which enables Teams federation (chat, calls, presence) with users in that specific organization while blocking all others. Options C and E are incorrect because guest access and SharePoint external sharing govern guest accounts and file sharing, not federated chat/search with external Teams users.

Option D is incorrect because 'Block all external domains' would prevent communication with contoso.com as well, contradicting the requirement.

Exam trap

MS-700 often tests the confusion between External Access and Guest Access; candidates may incorrectly select Guest Access settings when the requirement is about chat and search with external users, not team membership.

206
MCQmedium

You are the Teams administrator for Contoso. An executive reports that a Teams meeting recording from a critical board meeting is not appearing in the meeting chat and cannot be found in SharePoint or OneDrive. The meeting was scheduled by the executive and had 12 participants. The recording was started by a participant who is a member of the organization. Where should you first check to locate the recording file?

A.The Microsoft Stream portal under My content
B.The SharePoint site of the team channel where the meeting was posted
C.The OneDrive for Business of the participant who started the recording
D.The OneDrive for Business of the meeting organizer
AnswerC

For non-channel meetings, the recording is saved to the OneDrive of the person who initiated the recording. Since a participant started the recording, the file will be in that participant's OneDrive under the Recordings folder. This is the correct first location to check to find the missing recording.

Why this answer

Teams meeting recordings are stored based on the meeting type and who starts the recording. For regular (non-channel) meetings, the recording is saved to the OneDrive for Business of the person who clicked Record. The organizer's OneDrive or a team's SharePoint site are incorrect unless the meeting was a channel meeting or the organizer started the recording.

Microsoft Stream is not the default storage location for new recordings.

Exam trap

The trap here is assuming recordings always go to the meeting organizer's OneDrive, but they actually go to the OneDrive of the person who initiates the recording.

207
MCQmedium

You are a Teams administrator. You need to receive proactive notifications about service incidents and advisories that affect Microsoft Teams, and you want to integrate these notifications into your existing ticketing system via a webhook. Which tool should you use?

A.Microsoft Teams admin center
B.Microsoft Graph API for Service Communications
C.Microsoft 365 Service Health Dashboard
D.Microsoft 365 admin center Message Center
AnswerB

The Microsoft Graph API for Service Communications allows you to programmatically retrieve service health and incident data. You can use it to build a custom integration that sends notifications to a ticketing system via webhook. This API provides the necessary endpoints to subscribe to and fetch service communications, enabling proactive alerts.

Why this answer

The Microsoft Graph API for Service Communications enables programmatic access to service health data, including incidents and advisories. By leveraging this API, you can create a custom solution that pushes notifications to a ticketing system via webhook, ensuring proactive alerts. Other tools provide the information but lack the direct integration capability required.

Exam trap

The trap here is assuming the Service Health Dashboard can send webhooks, but it only provides a UI and email alerts; programmatic integration requires the Graph API.

208
MCQhard

You are a Teams administrator for a global organization. You need to ensure that all users in the sales department can only use the Teams client on Windows devices that are compliant with your organization's conditional access policies. What should you configure?

A.In the Teams admin center, modify the global app permission policy to block Teams on unmanaged devices.
B.Create a Teams app setup policy that blocks the mobile client for sales users.
C.Configure a conditional access policy in Azure AD that requires compliant devices for the Teams cloud app and assign it to the sales department.
D.Use Intune to deploy a device compliance policy that blocks the Teams app on non-compliant devices.
AnswerC

Conditional access policies in Azure AD can enforce device compliance for specific cloud apps, including Teams. By targeting the Teams cloud app and the sales group, and requiring a compliant device, you ensure that only compliant Windows devices can access Teams. This directly satisfies the requirement.

Why this answer

Conditional access is the correct tool to enforce device compliance for cloud apps like Teams. By creating a policy that requires compliant devices and targeting the sales department, you ensure that only compliant Windows devices can access Teams. This integrates with Intune compliance policies to evaluate device state.

Exam trap

The trap here is confusing Intune compliance policies with conditional access; compliance policies alone do not block access without a conditional access policy.

209
MCQmedium

Refer to the exhibit. A user is unable to add external guests to a meeting despite the policy shown. What is the most likely reason?

A.The policy is corrupted.
B.Organization-wide Guest Access is disabled.
C.The user is not licensed for guest access.
D.The AllowPrivateCalling parameter is blocking the guests.
AnswerB

Guest access must be enabled at the organization level before any user-level policy can permit it. Even with a policy allowing guest interactions, if the tenant-wide setting is disabled, the system will block all attempts to invite external guests to meetings to maintain security.

Why this answer

In Microsoft Teams, guest access is governed at two levels: the organization-wide Guest Access configuration in Teams admin center (or Entra ID external collaboration settings) and per-user or per-policy meeting settings. If organization-wide guest access is disabled, no user can add external guests to meetings regardless of what the meeting policy allows — the policy shown may permit it, but the tenant-level switch overrides it. This is the most likely reason the user cannot add guests.

Exam trap

The trap is focusing on the per-user meeting policy shown in the exhibit and ignoring the tenant-wide Guest Access switch — the exam expects you to know that the org-level setting overrides policy-level permissions.

How to eliminate wrong answers

Option A is wrong because policies in Teams admin center are not 'corrupted' in a way that silently blocks a single capability — policy corruption would typically produce errors or affect all settings, not a clean block of guest addition. Option C is wrong because guest access is not a per-user license entitlement in the way described; guest access is a tenant-level and policy-level setting, and users with standard Teams licenses can add guests if the tenant allows it. Option D is wrong because AllowPrivateCalling is a calling policy parameter unrelated to meeting guest admission — it controls private calling, not external participant invitations.

210
MCQmedium

A company has a Microsoft 365 tenant with Microsoft Teams. The security team requires that all meeting recordings are stored for 90 days and then automatically deleted. You need to configure the appropriate policy. Which setting should you modify?

A.SharePoint Online storage quota for the site
B.Microsoft 365 retention policy for Teams recordings
C.Teams meeting policy - Recording expiration
D.Teams meeting policy - Allow cloud recording
AnswerB

A Microsoft 365 retention policy applied to Teams recordings (stored in SharePoint or OneDrive) can automatically delete recordings after 90 days. This is the correct method because it ensures compliance across all recordings regardless of meeting policy settings. Retention policies are managed in the Microsoft 365 compliance center and take precedence for data lifecycle management.

Why this answer

The requirement is to store meeting recordings for 90 days and then delete them automatically. This is a data lifecycle task that must be handled by a Microsoft 365 retention policy targeting Teams recordings. Meeting policies control recording capabilities, not retention duration.

SharePoint quotas are unrelated to time-based deletion. Therefore, configuring a retention policy is the correct action.

Exam trap

The trap here is assuming that a Teams meeting policy setting controls how long recordings are kept, when actually retention is managed by Microsoft 365 compliance policies.

211
MCQeasy

A Teams administrator needs to ensure that a newly hired support agent can create teams, but the agent must not be able to change organizational-wide settings in the Teams admin center. The agent already has a Microsoft 365 E3 license. What should the administrator do?

A.Enable the agent to create Microsoft 365 groups by using the Microsoft 365 groups creation setting and assign no Teams admin role.
B.Assign the Teams Communications Administrator role to the agent.
C.Assign the Teams Administrator role to the agent in the Microsoft 365 admin center.
D.Assign the Global Administrator role to the agent temporarily and remove it after team creation.
AnswerA

Team creation is governed by the ability to create Microsoft 365 groups, which can be controlled at the tenant level. By allowing this user to create groups and not assigning a Teams admin role, the agent can create teams while remaining unable to modify organizational-wide Teams settings. This satisfies least privilege and directly addresses the requirement.

Why this answer

Team creation depends on the right to create Microsoft 365 groups, which can be granted independently of any Teams administrative role. Leaving the user without a Teams admin role ensures they cannot alter tenant-wide settings. The Teams Administrator, Teams Communications Administrator, and Global Administrator roles all grant broader or unrelated permissions that exceed the requirement.

Exam trap

The trap here is assuming that creating teams requires a Teams administrative role, when in fact it is controlled by Microsoft 365 group creation permissions.

Page 2

Page 3 of 3

All pages