Your organization wants to prevent users from sharing sensitive internal files with external guests in Teams. Which feature should you implement?
Sensitivity labels allow you to define rules for how data should be handled. By applying these to teams or files, you can enforce policies that restrict external sharing, ensuring that sensitive content remains protected even if a user tries to share it externally with a guest user.
Why this answer
Microsoft Purview Sensitivity Labels allow organizations to classify and protect content (including files shared in Teams) with encryption, content marking, and sharing restrictions. When applied to files, labels can enforce encryption that prevents external guests from opening or forwarding sensitive content, directly addressing the requirement to stop external sharing of internal files.
Exam trap
The trap is confusing communication controls (External Access, Messaging policies) with data protection controls; candidates must recognize that only sensitivity labels apply persistent encryption and classification to files themselves.
How to eliminate wrong answers
Option A is wrong because Teams Messaging policies control features like chat, channel, and editing capabilities for users — they do not classify or protect file content from external sharing. Option C is wrong because App Setup policies govern which apps are installed and pinned in Teams, unrelated to data protection. Option D is wrong because External Access configuration controls whether users can communicate with external domains (federation), not whether specific sensitive files can be shared with guests.