Courseiva

CCNA Configure Manage Teams Environment Questions

67 questions · Configure Manage Teams Environment topic · All types, answers revealed

1
MCQmedium

Your organization wants to prevent users from sharing sensitive internal files with external guests in Teams. Which feature should you implement?

A.Teams Messaging policy.
B.Microsoft Purview Sensitivity Labels.
C.Teams App setup policies.
D.External Access configuration.
AnswerB

Sensitivity labels allow you to define rules for how data should be handled. By applying these to teams or files, you can enforce policies that restrict external sharing, ensuring that sensitive content remains protected even if a user tries to share it externally with a guest user.

Why this answer

Microsoft Purview Sensitivity Labels allow organizations to classify and protect content (including files shared in Teams) with encryption, content marking, and sharing restrictions. When applied to files, labels can enforce encryption that prevents external guests from opening or forwarding sensitive content, directly addressing the requirement to stop external sharing of internal files.

Exam trap

The trap is confusing communication controls (External Access, Messaging policies) with data protection controls; candidates must recognize that only sensitivity labels apply persistent encryption and classification to files themselves.

How to eliminate wrong answers

Option A is wrong because Teams Messaging policies control features like chat, channel, and editing capabilities for users — they do not classify or protect file content from external sharing. Option C is wrong because App Setup policies govern which apps are installed and pinned in Teams, unrelated to data protection. Option D is wrong because External Access configuration controls whether users can communicate with external domains (federation), not whether specific sensitive files can be shared with guests.

2
Multi-Selecthard

You are a Teams administrator for a large enterprise. The company wants to implement a new Teams meeting policy to control meeting features. You need to configure the policy to allow only organizers to bypass the lobby, and to prevent attendees from using reactions. Which two settings should you configure in the Teams meeting policy? (Choose two.)

Select 2 answers
A.Set 'Who can bypass the lobby' to 'Organizers only'.
B.Set 'Allow meeting chat' to 'Disabled'.
C.Set 'Allow reactions' to 'Off'.
D.Set 'Allow IP video' to 'Off'.
E.Set 'Allow participants to use the lobby' to 'Enabled'.
AnswersA, C

This setting controls which participants can bypass the lobby. Setting it to 'Organizers only' ensures that only meeting organizers can bypass the lobby, while attendees must wait in the lobby. This directly meets the requirement to allow only organizers to bypass the lobby. It is configured in the Teams meeting policy under 'Participants & guests'.

Why this answer

To allow only organizers to bypass the lobby, you must set 'Who can bypass the lobby' to 'Organizers only'. To prevent attendees from using reactions, you must set 'Allow reactions' to 'Off'. These two settings are part of the Teams meeting policy and directly address the requirements.

Other options either affect unrelated features or are not valid settings.

Exam trap

The trap here is confusing meeting chat settings with reaction settings, or thinking that lobby bypass is controlled by a participant lobby setting rather than 'Who can bypass the lobby'.

3
MCQhard

You are trying to implement a policy that forces all Teams members to use a specific set of pinned apps. Which policy configuration is required?

A.Modify the Messaging policy
B.Modify the App Permission policy
C.Modify the App Setup policy
D.Modify the Teams global org-wide settings
AnswerC

The App Setup policy is specifically designed to manage the look and feel of the Teams client, including the ability to pin specific apps to the sidebar. By creating a custom setup policy, you can dictate exactly which apps appear for the users assigned to that policy.

Why this answer

The App Setup policy in Teams allows administrators to pin apps to the app bar for users, ensuring they have quick access to specific apps. By modifying the App Setup policy, you can define a set of pinned apps that will be applied to all users assigned that policy. This is the correct policy type for controlling pinned apps.

Exam trap

MS-700 often tests the difference between App Setup and App Permission policies; candidates might confuse pinning apps with allowing apps.

How to eliminate wrong answers

Option A is wrong because the Messaging policy controls chat and messaging features, not pinned apps. Option B is wrong because the App Permission policy controls which apps are allowed or blocked, not which are pinned. Option D is wrong because global org-wide settings do not include options for pinning apps; that is managed through App Setup policies.

4
Multi-Selecthard

Your organization is preparing for a Teams rollout and needs to use Teams Advisor to streamline the process. Which THREE deployment workloads can Teams Advisor help you plan? Each correct answer presents a complete solution.

Select 3 answers
A.Chat, teams, channels, and apps
B.Meetings and conferencing
C.Cloud voice (Phone System)
D.SharePoint Online migration
E.Exchange Online mailbox migration
AnswersA, B, C

This workload focuses on the core collaboration features of Teams. Teams Advisor provides a step-by-step guide for setting up the basic infrastructure, including team structures, channel management, and the initial integration of applications, which are essential for getting the organization started with modern teamwork and communication.

Why this answer

Teams Advisor in the Microsoft Teams admin center is designed to guide an organization through a Teams rollout by breaking it into specific deployment workloads, and the three it supports are chat/teams/channels/apps, meetings and conferencing, and cloud voice (Phone System). Option A (Chat, teams, channels, and apps) is correct because this is the core collaboration workload that Teams Advisor plans, covering the fundamental messaging, team, channel, and app experiences. Option B (Meetings and conferencing) is correct because Teams Advisor includes a dedicated workload for planning meeting and conferencing capabilities, including audio/video and content sharing.

Option C (Cloud voice (Phone System)) is correct because Teams Advisor provides a specific workload for planning Phone System/cloud voice deployment, including calling plans, direct routing, and PSTN connectivity. Options D and E are not part of Teams Advisor: SharePoint Online migration and Exchange Online mailbox migration are separate migration workloads handled by tools such as the SharePoint Migration Tool and Exchange migration wizards, not by Teams Advisor's deployment planning workloads.

Exam trap

MS-700 often tests the scope of Teams Advisor; candidates may incorrectly include SharePoint or Exchange migrations, which are not part of Teams Advisor's planning workloads.

5
MCQeasy

A user reports that they cannot see the 'Calls' app in the Microsoft Teams client. The user is a member of a team that has calling enabled, and they have a valid Phone System license. You need to ensure the user can access the Calls app. What should you check first?

A.Verify that the user has the correct Teams upgrade policy assigned.
B.Ensure that the user is assigned a Teams calling policy that allows private calling.
C.Verify that the user has the correct Microsoft 365 license assigned and that the Teams service is enabled.
D.Check if the user has been assigned a Teams meeting policy with AllowCloudRecording enabled.
AnswerB

The Teams calling policy includes settings such as AllowPrivateCalling, which controls whether users can make private calls. If this setting is disabled, the Calls app may be hidden. Ensuring the user is assigned a calling policy with AllowPrivateCalling enabled is the correct first step to make the Calls app visible.

Why this answer

The visibility of the Calls app in Teams is controlled by the Teams calling policy, specifically the AllowPrivateCalling setting. If this setting is disabled, users cannot see the Calls app. Therefore, checking and ensuring the user is assigned a calling policy with AllowPrivateCalling enabled is the correct first step.

Other policies like meeting or upgrade policies do not affect the Calls app.

Exam trap

The trap here is confusing calling policies with meeting or upgrade policies, which do not control the Calls app visibility.

6
MCQmedium

You are reviewing call quality data in the Call Quality Dashboard (CQD). You notice that many calls are flagged as 'Poor', but you cannot identify which physical office buildings are affected. What must you do to view call quality data organized by physical location?

A.Enable Location-Based Routing
B.Upload a tenant data file containing building information
C.Configure a Network Topology in the Teams admin center
D.Assign a Teams Communications Support Engineer role
AnswerB

The Call Quality Dashboard requires a building mapping file to associate network subnets with physical site names. Without this file, CQD only shows raw IP addresses, making it impossible for administrators to determine which physical locations are experiencing quality issues based on the aggregated telemetry data provided in the reports.

Why this answer

The Call Quality Dashboard (CQD) organizes data by building, subnet, and network only after you upload a tenant data file that maps subnets to building names and other metadata. Without this file, CQD can only show generic dimensions like 'Unknown' or IP-based groupings, so you cannot attribute poor calls to a specific physical office. Uploading the building data file (a TSV with Network, Building, Ownership, etc.) enables the 'Building' dimension in CQD reports.

Exam trap

MS-700 often tests the misconception that configuring Network Topology or enabling LBR automatically populates CQD building data — the actual requirement is the tenant data file upload.

How to eliminate wrong answers

Option A is wrong because Location-Based Routing (LBR) controls how PSTN calls are routed based on the user's location for regulatory/emergency purposes; it does not populate CQD building metadata. Option C is wrong because Network Topology in the Teams admin center defines trusted subnets, sites, and regions for media bypass and dynamic emergency calling — it feeds some network info but does not replace the CQD tenant data file for building-level reporting. Option D is wrong because the Teams Communications Support Engineer role is a RBAC role granting read access to CQD and call analytics; it does not create the building mapping data.

7
MCQeasy

An administrator needs to quickly assess the network readiness of a new branch office to determine if the current bandwidth can support 50 simultaneous Teams video calls. Which tool within the Teams admin center should be used for this purpose?

A.Call Quality Dashboard (CQD)
B.Network Planner
C.Teams Advisor
D.Call Analytics
AnswerB

Network Planner is specifically designed to help administrators estimate the bandwidth requirements for their organization's sites. By inputting the number of users and their expected personas, it calculates the network impact of Teams traffic, including video, audio, and screen sharing, providing a clear readiness report.

Why this answer

Network Planner is the Teams admin center tool designed specifically to model network capacity requirements before deployment, including estimating bandwidth for a given number of simultaneous video calls, meetings, and PSTN usage at a site. It lets an admin input the number of users and usage profiles per location and outputs the required bandwidth, making it the correct tool for assessing whether a new branch office can support 50 concurrent video calls.

Exam trap

MS-700 often tests the confusion between Network Planner (pre-deployment capacity modeling) and CQD (post-deployment quality analysis) — candidates pick CQD because it 'analyzes calls' but it cannot model a site with no existing call data.

How to eliminate wrong answers

Option A is wrong because Call Quality Dashboard (CQD) analyzes historical call quality data from already-deployed users — it cannot model future capacity for a new site that has no call data yet. Option C is wrong because Teams Advisor provides deployment guidance and best-practice checklists, not bandwidth calculations for concurrent video sessions. Option D is wrong because Call Analytics provides per-user diagnostic data for individual calls (poor quality, failed connections), not aggregate network capacity planning.

8
MCQmedium

You need to implement a solution that allows users to report inappropriate messages in Teams. The messages should be reviewed by the organization's compliance team. What should you configure?

A.Teams Feedback Policy
B.Microsoft Purview Communication Compliance
C.Teams Alert Policies
D.Azure Sentinel with Teams Connector
AnswerB

Communication Compliance is the correct tool for this requirement. By enabling the 'Report message' feature in Teams messaging policies and setting up a policy in Purview, flagged messages are routed to a dedicated dashboard where compliance officers can investigate and take action.

Why this answer

Microsoft Purview Communication Compliance is correct because it provides the ability to detect, capture, and review inappropriate or policy-violating messages across Teams, Exchange, and other channels, with a built-in review workflow for compliance teams. Users can report messages directly in Teams, and those reports flow into Communication Compliance for triage and remediation. This is the purpose-built solution for message review by compliance officers.

Exam trap

MS-700 often tests the distinction between message moderation (Communication Compliance) and administrative alerting (Alert Policies) — candidates pick Alert Policies because both sound like 'monitoring,' but only Communication Compliance provides a review workflow.

How to eliminate wrong answers

Option A is wrong because Teams Feedback Policy controls whether users can send product feedback or surveys to Microsoft about Teams itself — it has nothing to do with reporting inappropriate user messages. Option C is wrong because Teams Alert Policies generate notifications for administrative events (e.g., policy changes, security alerts) but do not capture or route user-reported messages for compliance review. Option D is wrong because Azure Sentinel is a SIEM/SOAR platform for security incident detection and response, not a message moderation or compliance review tool.

9
MCQmedium

Your company has many inactive teams that are no longer needed. You want to implement a solution that automatically asks team owners if they still need their team after 180 days of inactivity. If they do not respond, the team should be deleted. What should you configure?

A.Teams Retention policy
B.Microsoft 365 Group Expiration policy
C.Archive the teams manually in the Teams admin center
D.Sensitivity labels with expiration settings
AnswerB

The Group Expiration policy is the correct tool for this scenario as it automatically sends renewal notifications to owners of inactive teams. It integrates with Azure AD to monitor activity and provides a mechanism for owners to extend the life of their teams or allow them to be automatically deleted.

Why this answer

Microsoft 365 Group Expiration policy is the correct solution because it automatically prompts group owners to renew their group after a defined inactivity period (e.g., 180 days) and deletes the group if they do not respond. Since every team is backed by a Microsoft 365 group, this policy applies to Teams. It is configured in the Microsoft 365 admin center or via Azure AD/Entra ID.

Exam trap

MS-700 often tests the confusion between retention policies (compliance) and expiration policies (lifecycle), so candidates pick retention because it sounds like it controls how long a team exists.

How to eliminate wrong answers

Option A is wrong because Teams Retention policy governs how long messages and files are kept for compliance, not group lifecycle or deletion. Option C is wrong because manually archiving teams does not automate the renewal prompt or deletion and does not scale. Option D is wrong because sensitivity labels with expiration settings apply to content classification and retention, not to group/team lifecycle management.

10
MCQeasy

You are a Teams administrator. You need to ensure that all members of a team can only use the General channel and cannot create new channels. What should you do?

A.Create a Teams policy that restricts channel creation and assign it to the team members.
B.Modify the team's settings to disable channel creation for members.
C.Configure the team as an org-wide team.
D.Assign a messaging policy that disables channel creation.
AnswerB

In Teams, team owners can control whether members are allowed to create channels. By default, members can create channels. In the team's settings, under 'Member permissions', you can uncheck 'Allow members to create and update channels'. This restricts members to only use existing channels, such as the General channel, and prevents them from creating new ones.

Why this answer

The correct way to prevent team members from creating new channels is to modify the team's settings and disable the option for members to create and update channels. This is done in the team's settings under 'Member permissions'. Messaging policies, Teams policies, and org-wide team configuration do not provide this control for standard channels.

Exam trap

The trap here is confusing Teams policies with team-level settings; channel creation permissions are set per team, not via policies.

11
MCQmedium

You are a Teams administrator for a company that uses Microsoft 365 E5. The security team requires that all new teams created by users have a sensitivity label applied before members can be added. You need to enforce a policy so that when a user creates a new team, they must select a sensitivity label from a predefined list. The label must also apply to the associated SharePoint site and Microsoft 365 group. What should you configure?

A.Create a Data Loss Prevention (DLP) policy in Microsoft Purview that blocks team creation without a sensitivity label.
B.Use a Teams app permission policy to require a label before creating a team.
C.Configure a sensitivity label policy in Microsoft Purview and publish it to the users, then enable the setting to require users to apply a label to teams.
D.Create a team template in the Teams admin center with a predefined sensitivity label.
AnswerC

Sensitivity labels in Microsoft Purview, when published to users and configured with the 'Require users to apply a label to their groups or sites' setting, enforce label selection during team creation. The label automatically applies to the Microsoft 365 group and connected SharePoint site. This directly satisfies the requirement to enforce a label and apply it to associated resources.

Why this answer

Sensitivity labels from Microsoft Purview are the correct mechanism to enforce label application during team creation. By publishing a label policy and enabling the requirement for groups and sites, users must choose a label, and that label is automatically applied to the Microsoft 365 group and SharePoint site. Other options do not enforce label selection or apply labels to associated resources.

Exam trap

The trap here is assuming that team templates or DLP policies can enforce sensitivity labels, when only a published sensitivity label policy with the group/site requirement does so.

12
MCQmedium

Your organization has a Microsoft 365 E5 tenant with Teams Phone. The security team requires that all external calls to the PSTN from Teams clients must be recorded automatically for compliance. You need to configure the environment to meet this requirement. What should you do?

A.Enable 'Automatic recording' in the Teams meeting policy for all users.
B.Assign a compliance recording policy to the affected users and integrate a certified recording solution.
C.Configure a call park policy and assign it to all users who make external calls.
D.Create a calling policy and set 'Record external calls automatically' to On.
AnswerB

Compliance recording in Teams requires a certified recording partner solution and a compliance recording policy assigned to users. The policy tells Teams to route calls to the recording service, which then records and stores the calls. This is the correct method to automatically record PSTN calls for compliance.

Why this answer

To automatically record external PSTN calls for compliance, you must use a certified compliance recording solution integrated with Teams and assign a compliance recording policy to the users. Calling policies, meeting policies, and call park policies do not provide automatic recording of PSTN calls. The compliance recording policy ensures that calls are routed to the recording service, which handles the recording and storage.

Exam trap

The trap here is confusing meeting recording policies with compliance recording policies for PSTN calls.

13
MCQmedium

A user complains that they cannot add a new member from a partner organization to a specific team. What is the first thing you should check in the Teams admin center?

A.The user's individual Messaging policy
B.The Org-wide Guest Access setting
C.The Meeting policy assigned to the user
D.The Teams app permission policy
AnswerB

The Org-wide Guest Access setting is the master switch for external collaboration. If this is disabled, no guests can be added to any team. You must verify this setting first, as it acts as a global blocker that overrides all other team-level or user-level configuration settings.

Why this answer

Guest access in Microsoft Teams is governed first by the tenant-level Org-wide Guest Access setting in the Teams admin center. If guest access is disabled or restricted at the organization level, no team owner can add external members regardless of other policies. This is the correct first check because it is the broadest gate controlling all guest invitations.

Exam trap

MS-700 often tests the distinction between tenant-level guest access and per-user policies — candidates incorrectly reach for messaging or meeting policies when the blocker is the org-wide guest setting.

How to eliminate wrong answers

Option A is wrong because the Messaging policy controls chat features like edit/delete and chat permissions, not the ability to add external members. Option C is wrong because Meeting policies govern meeting behavior such as recording and screen sharing, unrelated to guest membership. Option D is wrong because app permission policies control which apps are available to users, not external collaboration.

14
MCQeasy

A department manager requests that a specific third-party project management app be automatically pinned to the sidebar of the Teams client for all members of their team. Which policy should the Teams administrator modify?

A.App Permission policy
B.Messaging policy
C.Meeting policy
D.App Setup policy
AnswerD

App Setup policies give administrators the power to pin apps to the navigation bar and install them on behalf of users. By creating a custom setup policy and assigning it to the department members, the administrator can ensure the project management app is prominently displayed for everyone in that group.

Why this answer

Teams App Setup policies control which apps are installed for users and which apps are pinned to the app bar (sidebar) in the Teams client. Modifying the App Setup policy allows the administrator to pin the third-party project management app for all members of the team.

Exam trap

The trap is confusing App Permission policies (which control access to apps) with App Setup policies (which control installation and pinning); candidates must remember that pinning is exclusively a setup policy function.

How to eliminate wrong answers

Option A is wrong because App Permission policies control whether users can interact with specific apps (allow/block) based on Microsoft's app permission model, not pinning behavior. Option B is wrong because Messaging policies govern chat and channel messaging features like edit/delete and read receipts. Option C is wrong because Meeting policies control meeting-related features such as recording, transcription, and lobby settings.

15
MCQmedium

An administrator is preparing for a company-wide rollout of Microsoft Teams and wants a structured checklist of tasks and a way to track progress. Which tool within the Teams admin center provides this functionality?

A.Teams Usage reports
B.Advisor for Teams
C.Network Planner
D.Teams Policy packages
AnswerB

Advisor for Teams analyzes your Microsoft 365 environment and creates a tailored deployment plan. It provides specific recommendations for workloads like Chat, Teams, and Meetings, and sets up a dedicated team for the deployment project to help administrators stay organized throughout the rollout process.

Why this answer

Advisor for Teams is the guided deployment tool inside the Teams admin center that provides a structured checklist, task assignments, and progress tracking for a Teams rollout. It walks administrators through planning, pilot, and organization-wide deployment phases, with best-practice guidance and the ability to assign tasks to team members. This directly matches the requirement for a checklist plus progress tracking.

Exam trap

The trap is confusing planning/coordination tools (Advisor for Teams, Network Planner) with reporting tools (Usage reports) — the exam expects you to match 'checklist and progress tracking' specifically to Advisor for Teams.

How to eliminate wrong answers

Option A is wrong because Teams Usage reports are analytics dashboards showing adoption metrics (active users, messages, meetings) — they report on what happened, not on rollout tasks. Option C is wrong because Network Planner is a separate tool for estimating bandwidth and network requirements before deployment; it does not provide a task checklist. Option D is wrong because Teams Policy packages are bundles of pre-defined policies (messaging, meeting, calling) applied to user groups — they govern behavior, not deployment workflow.

16
MCQmedium

You need to ensure that all Teams IP phones in your organization have a specific background image and a common screen timeout value. What should you create and apply in the Teams admin center?

A.A Device Configuration Profile
B.An App Setup Policy
C.A Teams Meeting Policy
D.A Calling Policy
AnswerA

Device Configuration Profiles are specifically designed for managing the settings of Teams-certified IP phones and other Android-based Teams devices. They allow you to centrally manage brightness, language, network settings, and UI customizations like background images, ensuring that all devices adhere to corporate standards and branding.

Why this answer

A Device Configuration Profile in the Teams admin center is specifically designed to manage settings on Teams-certified devices, including IP phones, Teams Rooms, and displays. It allows administrators to enforce custom background images and screen timeout values across all devices in a group. These profiles are assigned to device accounts or groups, ensuring consistent configuration without manual intervention.

This is the only option that directly targets device-level settings for Teams phones.

Exam trap

MS-700 often tests the confusion between user policies (App Setup, Meeting, Calling) and device policies (Device Configuration Profiles), causing candidates to incorrectly select a user policy for device-level settings.

How to eliminate wrong answers

Option B is wrong because an App Setup Policy controls the pinning and installation of apps within Teams clients, not device-level settings like background images or screen timeouts. Option C is wrong because a Teams Meeting Policy governs meeting features such as recording, transcription, and participant capabilities, not physical device configurations. Option D is wrong because a Calling Policy manages calling features like voicemail, call forwarding, and simultaneous ringing, not device hardware settings.

17
MCQeasy

You need to ensure that only users in the marketing department can create teams in Microsoft Teams. All other users should be able to use Teams but not create new teams. What should you do?

A.In the Teams admin center, create a team creation policy and assign it to the marketing department.
B.Modify the global Teams meeting policy to restrict team creation.
C.Create an app permission policy that blocks the Teams app for non-marketing users.
D.In Azure AD, configure group settings to allow only a specific security group to create Microsoft 365 groups, and add marketing users to that group.
AnswerD

Team creation is tied to Microsoft 365 group creation. By restricting group creation to a specific security group, you control who can create teams. Adding marketing users to that group allows them to create teams while others cannot. This is the correct method.

Why this answer

Team creation is governed by Microsoft 365 group creation settings in Azure AD. By allowing only a designated security group to create groups, you restrict team creation to those members. The other options either target unrelated policies or reference non-existent features.

Exam trap

The trap here is thinking that Teams admin center has a direct team creation policy, when actually it is controlled via Azure AD group settings.

18
MCQhard

A company is implementing Location-Based Routing (LBR) to comply with local telecommunications regulations. Which Microsoft Teams component is primarily responsible for enforcing LBR restrictions when a user attempts to make a PSTN call?

A.The Teams Phone Mobile provider
B.The Network Site associated with the user's IP address
C.The Azure Virtual Desktop agent
D.The SBC (Session Border Controller) hardware
AnswerB

LBR uses the network site configuration, which maps IP subnets to physical locations. When a user makes a call, Teams checks their current IP against the defined network sites. If the site is configured for LBR, the service enforces the routing rules associated with that specific geographical location.

Why this answer

Location-Based Routing (LBR) in Microsoft Teams enforces restrictions based on the user's physical location, which is determined by the Network Site associated with the user's IP address. When a user attempts a PSTN call, Teams checks the network site to determine if the call is allowed based on the LBR policy. The SBC enforces the routing but the decision is based on the network site configuration.

Exam trap

MS-700 often tests the misconception that the SBC enforces LBR, when in fact the network site determines the routing policy, and the SBC only executes the routing decision.

How to eliminate wrong answers

Option A is wrong because Teams Phone Mobile is a service that allows mobile phone numbers to be used with Teams, but it does not enforce LBR restrictions. Option C is wrong because Azure Virtual Desktop is a virtualization service and has no role in LBR enforcement. Option D is wrong because while the SBC is involved in routing calls, it does not make the LBR decision; it simply follows the routing instructions provided by Teams based on the network site.

19
Multi-Selectmedium

You need to restrict a specific group of users in the Marketing department from creating private channels within their teams. Which TWO configurations must be performed to achieve this? Each correct answer presents part of the solution.

Select 2 answers
A.Create a new Teams channels policy and disable the 'Create private channels' setting.
B.Modify the Global (Org-wide default) Teams channels policy.
C.Assign the custom Teams channels policy to the Marketing department users.
D.Disable private channel creation in the Microsoft 365 admin center under Groups settings.
E.Enable the 'Prevent channel creation' setting in the Teams guest access settings.
AnswersA, C

Teams channel policies allow administrators to define specific permissions for users, such as whether they can create private or shared channels. By creating a custom policy with private channel creation disabled, you create the administrative framework necessary to restrict these specific actions for any user to whom the policy is assigned.

Why this answer

Option A is correct because private channel creation is controlled by a Teams channels policy, and the 'Create private channels' setting within that policy must be turned off to block users from creating private channels. Option C is correct because a policy only takes effect once it is assigned to the targeted users; assigning the custom channels policy to the Marketing department users applies the restriction to exactly that group. Option B is incorrect because modifying the Global (Org-wide default) policy would affect all users in the tenant, not just the Marketing department.

Option D is incorrect because the Microsoft 365 admin center Groups settings do not contain a control for private channel creation in Teams. Option E is incorrect because guest access settings govern external guest capabilities, not private channel creation by internal Marketing users, and no such 'Prevent channel creation' setting exists there.

Exam trap

MS-700 often tests the misconception that editing the Global policy is the way to restrict a subset of users — candidates forget that Global affects everyone and that a custom policy must be created and assigned to the specific group.

20
MCQeasy

Which administrative role should you assign to a user who only needs to manage Teams meeting policies and messaging policies?

A.Global Administrator.
B.Teams Administrator.
C.SharePoint Administrator.
D.Teams Communications Support Specialist.
AnswerB

The Teams Administrator role is specifically designed to grant access to the Teams admin center and PowerShell cmdlets for managing teams, channels, and all policy types. This role perfectly matches the required tasks without over-provisioning permissions, keeping the management environment secure and compliant.

Why this answer

The Teams Administrator role is purpose-built to manage Teams and its policies, including meeting, messaging, calling, and app policies, without granting broader tenant-wide control. It provides exactly the least-privilege access needed for managing Teams meeting and messaging policies, making it the correct assignment for this user.

Exam trap

MS-700 often tests least-privilege role selection, and candidates who default to Global Administrator for 'full control' fall into the trap of over-privileging instead of choosing the scoped Teams Administrator role.

How to eliminate wrong answers

Option A is wrong because Global Administrator grants full control over all Microsoft 365 services and settings, far exceeding the least-privilege requirement and creating unnecessary security risk. Option C is wrong because SharePoint Administrator manages SharePoint sites and settings, not Teams meeting or messaging policies. Option D is wrong because Teams Communications Support Specialist is a read-only-ish role focused on troubleshooting call quality and user call issues, not on managing meeting and messaging policies.

21
MCQmedium

You need to ensure that certain users receive new Microsoft Teams features before the rest of the organization to perform compatibility testing. Which policy should you modify to enable these users to access the Public Preview of Teams?

A.Teams App Setup Policy
B.Teams Update Policy
C.Teams Meeting Policy
D.Teams App Permission Policy
AnswerB

Teams update policies allow administrators to manage how users receive updates to the Teams client. By setting the 'Allow public preview' option to 'Enabled' or 'Follow Office Preview' within this policy, administrators can grant specific users access to new features before they are generally available to the public.

Why this answer

The Teams Update Policy controls whether users receive preview features via the Teams Public Preview program. By assigning a Teams Update Policy with 'Show preview features' enabled to specific users, you allow those users to access new features before the rest of the organization, enabling compatibility testing.

Exam trap

MS-700 often tests the distinction between Teams Update Policy (preview features) and App Setup/Permission Policies (app management) — candidates pick App Setup Policy because 'features' sounds app-related, but preview access is controlled solely by the Update Policy.

How to eliminate wrong answers

Option A is wrong because Teams App Setup Policy controls app pinning and auto-installation, not access to preview features. Option C is wrong because Teams Meeting Policy governs meeting-related settings (recording, transcription, lobby), not the Teams client update channel. Option D is wrong because Teams App Permission Policy controls which apps users can access, not whether they receive preview builds of Teams.

22
MCQmedium

You are the Teams administrator for a company that uses Microsoft 365. The security team wants to ensure that only devices that are compliant with Intune compliance policies can access Microsoft Teams. All users are licensed for Microsoft 365 E5 and have Intune enrolled devices. You need to configure a conditional access policy that applies specifically to the Microsoft Teams cloud app and requires compliant devices. Which of the following should you do?

A.In the Microsoft 365 admin center, create a new sensitivity label with encryption settings and apply it to all Teams sites, then require the label for access.
B.In the Microsoft Teams admin center, create a new meeting policy and set 'Require compliant devices' to On, then assign the policy to all users.
C.In the Microsoft Intune admin center, create a device compliance policy and assign it to all devices, then create a configuration profile that blocks Teams on noncompliant devices.
D.In the Microsoft Entra admin center, create a new conditional access policy, assign it to all users, select the Microsoft Teams cloud app, and under Access controls, require the device to be marked as compliant.
AnswerD

This is the correct approach because conditional access policies in Microsoft Entra ID can target the Microsoft Teams cloud app specifically. By requiring the device to be marked as compliant, only devices that meet Intune compliance policies will be granted access. This enforces the security team's requirement without affecting other applications. The policy must be scoped to the Teams cloud app to avoid unintended impact on other services.

Why this answer

The security team requires that only compliant devices access Microsoft Teams. Conditional access in Microsoft Entra ID is the correct tool to enforce device compliance for specific cloud apps. By targeting the Microsoft Teams cloud app and requiring compliant devices, you ensure that only Intune-compliant devices can access Teams, while other apps remain unaffected.

Meeting policies, Intune configuration profiles, and sensitivity labels do not provide this level of access control.

Exam trap

The trap here is assuming that Teams admin center policies or Intune configuration profiles can enforce device compliance for app access, when conditional access is the only mechanism that evaluates device compliance at sign-in.

23
Multi-Selectmedium

You are setting up an Auto Attendant for your company's main reception line. Which TWO prerequisites must be met before you can finalize the Auto Attendant configuration? Each correct answer presents part of the solution.

Select 2 answers
A.Create a Resource Account and assign it a Microsoft 365 Phone System - Virtual User license.
B.Assign a Microsoft 365 E5 license to the Resource Account.
C.Assign a service number or a direct routing number to the Resource Account.
D.Create a team specifically for the Auto Attendant to store call logs.
E.Enable 'Allow guest access' in the Teams admin center.
AnswersA, C

Every Auto Attendant must be associated with a Resource Account, which serves as its identity in the system. To function without using a standard paid license, Microsoft provides a 'Virtual User' license specifically for these accounts, allowing them to handle calls and be assigned phone numbers.

Why this answer

Option A is correct because an Auto Attendant in Microsoft Teams is anchored to a Resource Account, and that Resource Account must be licensed with a Microsoft 365 Phone System - Virtual User license (or a Phone System license) so the Auto Attendant can be provisioned and function. Option C is correct because the Resource Account must be assigned either a Microsoft service number (for Microsoft Calling Plans/Operator Connect) or a Direct Routing number, which serves as the phone number callers dial to reach the Auto Attendant. Option B is not required because an E5 license is not the correct licensing mechanism for a Resource Account used by an Auto Attendant; the Virtual User license is the appropriate SKU.

Option D is incorrect because call logs are not stored in a dedicated team; Auto Attendant call handling and reporting are managed through Teams admin center and Call Analytics, not a team. Option E is incorrect because guest access settings are unrelated to Auto Attendant prerequisites and do not affect its configuration or operation.

Exam trap

MS-700 often tests the misconception that a full E5 or E3 license is needed for resource accounts, when in fact the free Virtual User license is the correct and required choice.

24
MCQhard

A company wants to implement a policy where only the 'Helpdesk' group can use the 'Walkie Talkie' app in Teams. You have created an App Setup Policy that includes the app. How should you assign this policy to ensure it only affects the members of the Helpdesk group with the least administrative effort?

A.Use the 'Assign policy to users' option and manually select every member of the group.
B.Use the 'Group policy assignment' tab in the Teams admin center to assign the policy to the Helpdesk group.
C.Edit the Global (Org-wide default) App Setup Policy to include the Walkie Talkie app.
D.Run a PowerShell script that loops through all users and grants the policy if they are in the group.
AnswerB

Group policy assignment is the most efficient method because it links the policy directly to a Microsoft 365 group or security group. Teams automatically handles the assignment and removal of the policy based on group membership, significantly reducing the administrative workload and ensuring that policy application is always up to date.

Why this answer

Group policy assignment in the Teams admin center allows you to assign a policy directly to a security group or Microsoft 365 group, automatically applying it to all current and future members. This satisfies the requirement to affect only Helpdesk members with minimal administrative effort, as you don't need to manually manage individual users. The policy is enforced for all group members, and any changes to group membership are reflected automatically.

Exam trap

MS-700 often tests the difference between group policy assignment and manual assignment, and candidates may overlook that group policy assignment is the only method that automatically applies to future group members with minimal effort.

How to eliminate wrong answers

Option A is wrong because manually selecting every member is time-consuming and error-prone, and does not automatically include future members. Option C is wrong because editing the Global policy applies the policy to all users in the organization, not just the Helpdesk group. Option D is wrong because running a PowerShell script requires ongoing maintenance and does not provide a native, automated way to keep policy assignments in sync with group membership.

25
MCQmedium

Your organization has a Microsoft 365 E5 subscription. The security team wants to ensure that only members of a specific security group can create new teams, while all other users can still use Teams for chat and meetings. What should you do?

A.In the Microsoft 365 admin center, modify the Groups settings to allow only a specific security group to create Microsoft 365 groups, and ensure the security group is listed.
B.Use the Microsoft Teams admin center to assign the 'Teams Creator' role to the security group.
C.In the Microsoft Teams admin center, create a Teams policy that disables team creation for all users, then assign the policy to the security group.
D.In Azure AD, create a conditional access policy that blocks the Teams web app for all users except the security group.
AnswerA

Team creation relies on Microsoft 365 Groups. By default, all users can create groups. To restrict this, you use the Groups settings in the Microsoft 365 admin center or Azure AD to allow only a designated security group to create groups. This effectively limits team creation to members of that group while others can still use Teams for chat and meetings.

Why this answer

Team creation is controlled through Microsoft 365 Groups settings, not through Teams policies or roles. By default, all users can create groups and thus teams. To restrict creation to a specific security group, you configure the group creation settings in the Microsoft 365 admin center or Azure AD to allow only that group.

This allows other users to continue using Teams for chat and meetings without creating new teams.

Exam trap

The trap here is assuming that Teams policies or roles can control team creation, when actually it is governed by Microsoft 365 Groups settings.

26
MCQeasy

You need to identify which users in your organization have been inactive in Microsoft Teams for the last 30 days. Which tool should you use?

A.Azure AD sign-in logs.
B.Microsoft 365 admin center Reports.
C.Teams admin center Guest access settings.
D.Security & Compliance Center Content Search.
AnswerB

The Microsoft 365 Reports dashboard is designed specifically to track service usage. It provides a dedicated Teams user activity report that displays the last activity date for every user, making it the correct tool to identify inactive users for license reclamation or audit purposes.

Why this answer

The Microsoft 365 admin center Reports section includes usage reports for Microsoft Teams, such as the Teams user activity report, which shows last activity dates and can identify users inactive for a specified period (e.g., 30 days). This is the built-in, supported way to identify inactive Teams users without custom scripting. It provides per-user activity data including last activity date, messages sent, and meetings attended.

Exam trap

MS-700 often tests the difference between activity reports (usage/inactivity) and configuration or sign-in data — candidates may pick Azure AD sign-in logs, but those reflect authentication, not Teams usage.

How to eliminate wrong answers

Option A is wrong because Azure AD sign-in logs show authentication events across services, not Teams-specific activity — a user could sign in to email but never use Teams, so sign-in logs cannot identify Teams inactivity. Option C is wrong because Teams admin center Guest access settings control external collaboration configuration, not user activity reporting. Option D is wrong because Security & Compliance Center Content Search is for eDiscovery and searching content (emails, documents, chats), not for reporting user activity or inactivity.

27
MCQmedium

When configuring your corporate firewall for Microsoft Teams media traffic, which UDP port range should be opened to allow for optimized audio, video, and screen sharing?

A.UDP 3478 through 3481
B.UDP 1024 through 5000
C.UDP 80 and 443
D.UDP 50000 through 50059
AnswerA

This is the primary range of UDP ports used by the Microsoft Teams client for media traffic (audio, video, and sharing). Ensuring these ports are open to the Teams service IP addresses is a fundamental requirement for achieving high-quality, real-time communication without the performance penalties of TCP-based transport.

Why this answer

Microsoft Teams media traffic (audio, video, screen sharing) uses UDP ports 3478 through 3481 for optimized real-time communication. These ports support STUN/TURN and media relay functions required for Teams' real-time transport.

Exam trap

The trap is confusing Teams media ports (UDP 3478–3481) with Skype for Business media ports (UDP 50000–50059) or with generic web ports (TCP 443).

How to eliminate wrong answers

Option B is wrong because UDP 1024–5000 is an overly broad range that does not correspond to Teams' documented media ports. Option C is wrong because UDP 80 and 443 are not used for Teams media — TCP 443 is used for signaling and fallback, but not for optimized UDP media. Option D is wrong because UDP 50000–50059 is the port range used by Skype for Business Online media, not Microsoft Teams.

28
MCQmedium

Your organization plans to deploy Microsoft Teams to 5,000 users across three different office locations. You need to estimate the network bandwidth requirements for each site based on expected usage patterns like video conferencing and screen sharing. Which tool in the Microsoft Teams admin center should you use?

A.Call Quality Dashboard (CQD)
B.Network Planner
C.Teams Advisor
D.Network Testing Tool
AnswerB

Network Planner allows administrators to create a representation of their organization's network and calculate the bandwidth needed for Teams services. It uses personas to estimate data usage for different types of users, providing a detailed outlook on how Teams traffic will impact the existing network infrastructure at each site.

Why this answer

The Network Planner in the Microsoft Teams admin center is the dedicated tool for modeling an organization's network topology, sites, and expected usage (video, screen sharing, PSTN) to produce per-site bandwidth estimates. It lets you define personas, network subnets, and meeting/conferencing ratios, then calculates the required bandwidth for each location. This is exactly the pre-deployment sizing task described.

Exam trap

MS-700 often tests the confusion between pre-deployment planning tools (Network Planner) and post-deployment diagnostics tools (CQD), so candidates who see 'bandwidth' and jump to CQD pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because Call Quality Dashboard (CQD) is a post-deployment monitoring and troubleshooting tool that analyzes call quality data (jitter, packet loss, MOS) — it does not estimate future bandwidth. Option C is wrong because Teams Advisor provides guided deployment checklists and recommendations, not quantitative per-site bandwidth calculations. Option D is wrong because the Network Testing Tool (Microsoft 365 network connectivity test) validates connectivity and performance from a client location, but does not model bandwidth requirements across multiple sites.

29
MCQmedium

You are managing a fleet of Microsoft Teams Rooms (MTR) on Windows. You want to use the 'Remote Login' and 'Advanced Proactive Management' features. Which license must be assigned to these devices?

A.Microsoft Teams Shared Devices license
B.Microsoft Teams Rooms Basic license
C.Microsoft Teams Rooms Pro license
D.Microsoft 365 E5 license
AnswerC

The Teams Rooms Pro license is the required tier for accessing advanced management features. It includes the Pro management portal, which offers proactive alerts, remote remediation, and detailed analytics that help administrators maintain high availability for their meeting room environments and resolve issues before they impact users.

Why this answer

The Microsoft Teams Rooms Pro license is required for advanced management features such as Remote Login and Advanced Proactive Management. These features allow IT admins to remotely access and manage Teams Rooms devices, monitor health, and perform proactive troubleshooting. The Pro license also includes other advanced capabilities like conditional access and detailed device analytics.

Exam trap

MS-700 often tests the feature differences between Teams Rooms Basic and Pro licenses, so candidates may assume that any Teams device license includes advanced management, or confuse it with user licenses like E5.

How to eliminate wrong answers

Option A is wrong because the Microsoft Teams Shared Devices license is for shared devices like Teams phones and displays, but it does not include the advanced management features required for MTRs. Option B is wrong because the Teams Rooms Basic license provides only essential meeting functionality and limited management, without Remote Login or Advanced Proactive Management. Option D is wrong because a Microsoft 365 E5 license is a user license, not a device license for Teams Rooms, and it does not grant the specific device management features needed.

30
MCQeasy

You need to prevent users from using Giphy in their private chats and team channels. Which policy should you modify to achieve this?

A.Teams App Setup Policy
B.Teams Meeting Policy
C.Teams Messaging Policy
D.Teams Update Policy
AnswerC

Messaging policies allow administrators to enable or disable features like Giphys, memes, and stickers. By editing the policy and turning off the Giphy toggle, or setting a content rating, you can immediately restrict users' ability to search for and send animated GIFs within the platform.

Why this answer

Giphy integration in Teams is controlled by the Teams Messaging Policy, which includes settings such as 'Allow Giphy,' 'Giphy content rating,' and 'Allow memes and stickers.' To block Giphy in private chats and team channels, an administrator modifies the messaging policy assigned to users and sets Allow Giphy to Off. This is the only policy that governs in-conversation content features.

Exam trap

The trap is confusing app-level controls (App Setup Policy, App Permission Policy) with content-level controls — Giphy is a messaging content feature, not an installable app, so only the Messaging Policy applies.

How to eliminate wrong answers

Option A is wrong because the Teams App Setup Policy controls which apps are pinned or allowed to install for users, not in-chat content features like Giphy. Option B is wrong because the Teams Meeting Policy governs meeting-specific capabilities such as recording, transcription, and lobby settings, not chat content. Option D is wrong because the Teams Update Policy controls which Teams client versions users can run and update behavior, not messaging content.

31
MCQmedium

A user reports that they cannot see the 'Calendar' icon in the Teams sidebar. You check their configuration and find they are assigned a custom App Setup Policy. What is the most likely cause of this issue?

A.The user does not have an Exchange Online mailbox licensed and configured.
B.The 'Calendar' app has been removed from the Pinned apps list in their App Setup Policy.
C.The user is currently in 'Island' coexistence mode.
D.The 'Allow third-party apps' setting is disabled in the Org-wide app settings.
AnswerB

App Setup Policies define which apps appear in the sidebar. If the 'Calendar' app is not included in the 'Pinned apps' section of the policy assigned to the user, the icon will not appear, regardless of whether the user has the appropriate licenses for the service.

Why this answer

In Microsoft Teams, the Calendar icon in the left sidebar is not a native Teams feature — it is a pinned app that surfaces the user's Exchange Online calendar. When a custom App Setup Policy is assigned, the Pinned apps list in that policy defines exactly which apps appear in the sidebar. If 'Calendar' is not included in the pinned apps list of the assigned policy, the icon will not appear, regardless of licensing or coexistence mode.

Exam trap

MS-700 often tests the distinction between app availability (licensing, permissions, coexistence) and app pinning (App Setup Policy), causing candidates to blame licensing when the real cause is a missing pinned app entry.

How to eliminate wrong answers

Option A is wrong because a missing Exchange Online mailbox would cause the Calendar app to fail to load data, but the icon itself would still be pinned and visible (or show an error); the question states the icon is absent, which points to policy pinning. Option C is wrong because Island coexistence mode affects how Teams and Skype for Business interoperate for chat and meetings, not whether the Calendar icon is pinned in the sidebar. Option D is wrong because 'Allow third-party apps' governs third-party app installation and availability, not the pinning of first-party apps like Calendar.

32
Multi-Selectmedium

Your organization is planning to deploy Microsoft Teams rooms across multiple conference locations. You need to ensure that the devices are properly managed and secured according to enterprise standards. Which TWO actions should you perform as part of the initial configuration? (Choose two.)

Select 2 answers
A.Assign a Microsoft Teams Rooms Pro license to each resource account associated with the conference room devices.
B.Configure a standard user policy that automatically syncs the personal OneDrive storage of the IT administrator to the room console.
C.Ensure that Modern Authentication is enabled across the tenant and enforced for all room resource accounts.
D.Enable anonymous inbound PSTN calling directly on the Microsoft Teams Rooms console hardware interface settings.
E.Create a dedicated Exchange resource mailbox for each room and link it directly to the corresponding Teams Rooms account.
AnswersA, C

A Microsoft Teams Rooms Pro licence must be assigned to each room resource account before the device can sign in and receive the management, security and meeting features enterprise standards require. Without it, the console cannot authenticate, so no further configuration applies.

Why this answer

Option A is correct because Microsoft Teams Rooms devices require a Microsoft Teams Rooms Pro (or equivalent Rooms) license assigned to the room's resource account to enable the Teams Rooms experience, management, and security features. Option C is correct because Modern Authentication (OAuth 2.0/ADAL/MSAL-based) must be enabled tenant-wide and enforced for room resource accounts so the devices can authenticate securely to Microsoft 365 without legacy basic authentication. The unmarked options do not belong: B is wrong because syncing an IT administrator's personal OneDrive to a room console is neither a supported nor secure management practice; D is wrong because enabling anonymous inbound PSTN calling on the console is not a standard security configuration and is not how calling is provisioned; and E is wrong because while each room needs a resource account, the mailbox is created as part of the resource account provisioning in Exchange Online rather than being a separate dedicated mailbox linked to the Teams Rooms account.

Exam trap

The trap is selecting plausible-sounding but non-standard actions (manual mailbox creation, OneDrive sync, anonymous PSTN) instead of the two documented prerequisites: Pro licensing and Modern Authentication.

33
Multi-Selecthard

You are configuring communication settings for a company that needs to collaborate with a partner organization. You need to allow users to chat with the partner's users without adding them as guests in your Azure Active Directory. Which TWO actions must you perform? (Each correct answer presents part of the solution.)

Select 2 answers
A.Enable Guest access in the Teams admin center
B.Create a new Teams App Setup policy
C.Add the partner domain to the allowed list in External Access
D.Configure a Messaging policy to allow Giphy
E.Ensure the partner organization has External Access enabled
AnswersC, E

Adding the specific domain to the allowed list within the External Access settings ensures that communication is permitted with that organization. This configuration allows Teams users to search for and initiate chats with users in the partner domain using their email addresses without requiring guest account creation.

Why this answer

External federation in Teams is controlled by the External Access (formerly external access/federation) settings, so option C is correct: adding the partner's domain to the allowed list in External Access permits your users to chat with users in that domain without creating guest accounts in your Azure AD. Option E is also correct because federation is bidirectional — the partner tenant must likewise have External Access enabled and allow your domain, otherwise their users cannot communicate with yours. Options A and B are wrong because guest access and app setup policies govern guest membership and app availability, not federated chat, and the scenario explicitly avoids adding guests.

Option D is wrong because a messaging policy controlling Giphy only affects message content features and has nothing to do with cross-tenant chat.

Exam trap

MS-700 often tests the confusion between External Access (federation, no guest account) and Guest access (B2B collaboration, requires a guest object in Azure AD), causing candidates to pick 'Enable Guest access' when the scenario explicitly forbids guest accounts.

34
MCQhard

You are a Teams administrator for Contoso. The company has a policy that all Teams meeting recordings must be stored for 7 years. You need to configure the environment to meet this requirement. What should you do?

A.Set the Teams meeting policy to automatically record meetings and save to OneDrive.
B.Create a data loss prevention (DLP) policy in the Teams admin center to retain recordings for 7 years.
C.Configure a retention policy in Microsoft 365 compliance center for Teams meeting recordings.
D.Enable the Teams setting to store recordings in Microsoft Stream with a 7-year retention.
AnswerC

Microsoft 365 retention policies can be applied to Teams meeting recordings stored in SharePoint and OneDrive. You can create a retention policy that keeps recordings for 7 years. This is the correct method to enforce long-term retention for compliance.

Why this answer

To retain Teams meeting recordings for a specific period, you must use a retention policy in the Microsoft 365 compliance center. These policies can target Teams recordings stored in SharePoint and OneDrive, ensuring they are kept for 7 years. Other options do not provide retention enforcement.

Exam trap

The trap here is assuming that Teams meeting policies or Stream settings can enforce retention, but retention is exclusively managed via compliance retention policies.

35
MCQeasy

You are the Teams administrator for a large enterprise. The company has a policy that all Teams channels must be moderated to prevent inappropriate content. You need to configure a team so that only team owners can post messages in a specific channel, while members can reply to existing posts. What should you do?

A.Create a new team with only owners and move the channel to that team.
B.Modify the team's member permissions to restrict members from creating new posts.
C.Assign a custom messaging policy to members that disables posting in that channel.
D.Set the channel moderation setting to 'Only owners can post messages' for the channel.
AnswerD

Channel moderation allows you to restrict who can post new messages. Setting it to 'Only owners can post messages' means that only team owners can start new posts, while members can still reply to existing posts. This exactly meets the requirement of preventing members from posting new messages but allowing them to reply. This is the correct configuration for moderating a specific channel.

Why this answer

The correct action is to enable channel moderation and set it to 'Only owners can post messages'. This setting allows only team owners to create new posts while members can still reply to existing posts, exactly matching the requirement. Other options either affect the entire team, are not supported, or use policies that cannot be scoped to a single channel.

Exam trap

The trap here is thinking that team-level member permissions or messaging policies can control posting in a specific channel; only channel moderation provides that granularity.

36
MCQmedium

Your company is transitioning from Skype for Business Online to Microsoft Teams. You need to ensure that all incoming chats and calls for all users are received only in Microsoft Teams, while still allowing users to join Skype for Business meetings. Which coexistence mode should you assign?

A.Islands mode
B.Skype for Business only
C.Teams Only
D.Skype for Business with Teams Collaboration
AnswerC

In Teams Only mode, all chats and calls are routed to Microsoft Teams. However, users can still use the Skype for Business client to join meetings hosted by other users who have not yet moved to Teams, providing the necessary interoperability during the migration phase of the project.

Why this answer

Teams Only mode ensures that all incoming chats and calls are received in Microsoft Teams, while users can still join Skype for Business meetings. This is the standard coexistence mode for organizations completing their migration to Teams. It disables Skype for Business for chat/calling but preserves meeting join capability.

Exam trap

MS-700 often tests the subtle differences between coexistence modes, especially that Teams Only still allows joining Skype for Business meetings, tricking candidates into thinking it blocks all SfB functionality.

How to eliminate wrong answers

Option A is wrong because Islands mode allows users to use both Teams and Skype for Business for chat and calls, so incoming chats/calls may still arrive in Skype for Business. Option B is wrong because Skype for Business only mode keeps all chats and calls in Skype for Business, the opposite of the requirement. Option D is wrong because Skype for Business with Teams Collaboration allows Teams for channels and collaboration but keeps chat/calls in Skype for Business, not Teams.

37
MCQmedium

You are the Teams administrator for a company that uses Microsoft 365 E5. The security team requires that all internal users can only communicate with other internal users and cannot initiate chats or calls with anyone outside the organization. You need to configure the appropriate policy to enforce this restriction. What should you do?

A.Configure a Teams meeting policy to disable anonymous join and dial-in users.
B.Create and assign a Teams external access policy that blocks all external domains, and also disable communication with consumer and unmanaged Teams users.
C.Create and assign a Teams external access policy that blocks all external domains.
D.Modify the global Teams messaging policy to disable external chat and file sharing.
AnswerB

An external access policy is the correct tool to control federation with other organizations. To fully block all external communication, you must also disable the ability to communicate with consumer (personal) Teams users and unmanaged Teams users. This combination ensures that internal users cannot chat or call anyone outside the organization, meeting the security requirement.

Why this answer

The correct approach is to use a Teams external access policy to block all external domains, and additionally disable communication with consumer and unmanaged Teams users. This prevents all forms of external communication, including chats and calls, aligning with the security team's requirement. Other policies, such as meeting or messaging policies, do not address external chat and calling restrictions comprehensively.

Exam trap

The trap here is assuming that blocking external domains in an external access policy is sufficient to block all external communication, when in fact consumer and unmanaged user communication must also be disabled.

38
MCQmedium

You want to ensure that only approved third-party apps are available for users to install in Teams. Which setting should you modify?

A.Teams settings for organization-wide features
B.The App Permission Policy
C.The Teams policy assigned to the user
D.The sensitivity label configuration
AnswerB

App Permission Policies allow you to specify which apps are allowed or blocked for different groups of users. This is the primary mechanism for controlling the app experience, allowing admins to enforce a curated selection of tools while ensuring that unverified apps remain inaccessible to the users.

Why this answer

The App Permission Policy in Teams controls whether users can install third-party apps and which apps are allowed or blocked. By configuring the policy to allow only specific approved apps (or by blocking all and permitting a curated list), administrators ensure that only approved third-party apps are available. This policy is the correct control for governing app installation at the user or group level.

Exam trap

The trap is selecting the org-wide Teams settings option because it sounds broad, but app installation control is specifically delegated to App Permission Policies, which can be scoped per user or group.

How to eliminate wrong answers

Option A is wrong because org-wide Teams settings control tenant-level features like guest access and file sharing, not per-user app installation permissions. Option C is wrong because 'the Teams policy assigned to the user' is too vague — the specific policy that governs app installation is the App Permission Policy, not a generic Teams policy such as messaging or meeting policy. Option D is wrong because sensitivity labels classify and protect content; they have no role in controlling app installation.

39
MCQmedium

You are a Teams administrator for a company that uses Microsoft 365. The security team requires that all new teams created by users have a naming convention that includes the department code and a sequential number (e.g., 'HR-001'). You need to enforce this convention automatically. What should you do?

A.Use a PowerShell script that runs on a schedule to rename non-compliant teams.
B.Enable sensitivity labels for teams and require a label during creation.
C.Configure a Teams naming policy in the Teams admin center and assign it to all users.
D.Create an Azure AD administrative unit for each department and assign users to it.
AnswerC

Teams naming policies allow administrators to enforce a prefix, suffix, and allowed characters for team names. By assigning the policy to users, any new team they create must comply with the specified format, such as including a department code and sequential number. This directly satisfies the requirement.

Why this answer

A Teams naming policy is the built-in feature that enforces a consistent naming structure for new teams. It supports prefixes, suffixes, and custom blocked words, and can be assigned to specific users or all users. This ensures that every new team created by those users adheres to the required format without manual intervention.

Exam trap

The trap here is confusing naming policies with sensitivity labels or administrative units, which serve different governance purposes.

40
MCQeasy

A department head wants to allow external project members to send documents directly to a specific Teams channel via email. Which setting must be enabled in the Teams admin center to support this?

A.Allow users to send emails to a channel email address.
B.Enable 'External access' for all domains.
C.Turn on 'Guest access' at the Org-wide level.
D.Enable 'Direct Routing' in the Voice settings.
AnswerA

This global setting enables the generation of email addresses for channels. Without this toggle being turned on, the option to 'Get email address' will not appear for channel owners, preventing anyone from sending content to the channel via the standard SMTP protocol for document ingestion.

Why this answer

To let external project members email documents directly into a specific Teams channel, the tenant must enable the channel email address feature, which is controlled by the 'Allow users to send emails to a channel email address' setting in the Teams admin center. Once enabled, each channel gets an email address that external senders can use.

Exam trap

MS-700 often tests the confusion between external access, guest access, and channel email — candidates pick guest access or external access thinking they enable email, but only the channel email setting does.

How to eliminate wrong answers

Option B is wrong because External access controls federation with other Teams tenants for chat/calling, not inbound email to channels. Option C is wrong because Guest access governs external users joining teams as guests, not emailing into a channel. Option D is wrong because Direct Routing is a PSTN/voice feature unrelated to channel email.

41
MCQeasy

You are a Teams administrator for a multinational corporation. The company has recently deployed Microsoft Teams and wants to ensure that all users can make and receive calls using Teams. You need to assign phone numbers to users. Which PowerShell cmdlet should you use to assign a phone number to a user?

A.Set-CsUser
B.Grant-CsOnlineVoiceRoutingPolicy
C.Set-CsOnlineVoiceUser
D.Set-CsPhoneNumberAssignment
AnswerD

Set-CsPhoneNumberAssignment is the correct cmdlet to assign, update, or remove a phone number for a user in Microsoft Teams. It is part of the MicrosoftTeams PowerShell module and is used to manage phone number assignments for Direct Routing, Calling Plans, and Operator Connect. This cmdlet directly fulfills the requirement to assign a phone number to a user.

Why this answer

The Set-CsPhoneNumberAssignment cmdlet is specifically designed to assign, update, or remove phone numbers for users in Microsoft Teams. It supports various phone number types and is the current recommended method for phone number management. Other cmdlets either serve different purposes or are not valid for this task.

Using the correct cmdlet ensures successful phone number assignment.

Exam trap

The trap here is assuming that legacy Skype for Business cmdlets like Set-CsUser are still used for Teams phone number assignment, when the newer Set-CsPhoneNumberAssignment is required.

42
MCQeasy

You want to ensure that the 'Tasks by Planner and To Do' app is automatically pinned to the navigation bar for all users in your company. Which policy should you modify?

A.App Permission Policy
B.App Setup Policy
C.Teams Meeting Policy
D.Teams Messaging Policy
AnswerB

App setup policies allow you to specify which apps are pinned to the Teams app bar (on the side for desktop, at the bottom for mobile). By editing the Global policy or a custom one, you can ensure the Tasks app is prominently displayed for all targeted users automatically.

Why this answer

The App Setup Policy in Teams controls which apps are pinned to the app bar and which apps are installed by default for users. To automatically pin 'Tasks by Planner and To Do' to the navigation bar for all users, you modify the App Setup Policy and add the app as a pinned app. This policy is applied via policy assignment to users or groups.

Exam trap

MS-700 often tests the distinction between App Setup Policy (pinning/installing apps) and App Permission Policy (allowing/blocking apps) — candidates confuse 'which apps are available' with 'which apps are pinned by default'.

How to eliminate wrong answers

Option A is wrong because App Permission Policies control which third-party or custom apps users can access (allow/block lists), not what is pinned or pre-installed. Option C is wrong because Teams Meeting Policies govern meeting features like recording, transcription, and lobby settings — they have no bearing on app pinning. Option D is wrong because Teams Messaging Policies control chat and messaging features (e.g., edit/delete messages, GIFs), not app installation or pinning.

43
MCQmedium

A network administrator needs to open the correct firewall ports to ensure that Microsoft Teams media traffic (audio/video) can flow properly. Which port range and protocol are primarily used for Teams media traffic?

A.TCP ports 80 and 443
B.UDP ports 3478-3481
C.TCP ports 50000-50059
D.UDP port 53
AnswerB

UDP ports 3478, 3479, 3480, and 3481 are the specific ports used by the Teams client for media traffic. Opening these ports ensures that audio, video, and screen sharing data can be transmitted efficiently with minimal delay, which is critical for the performance of real-time communication.

Why this answer

Microsoft Teams media traffic (audio, video, screen sharing) primarily uses UDP ports 3478 through 3481, which support the STUN/TURN protocols used for NAT traversal and media relay. Opening this range is essential for reliable real-time media flow.

Exam trap

MS-700 often tests the confusion between signaling ports (443) and media ports (UDP 3478-3481), or between primary UDP media and TCP fallback, causing candidates to pick 443 as the 'media' answer.

How to eliminate wrong answers

Option A is wrong because TCP 80/443 carry signaling, authentication, and web-based fallback traffic — not the primary real-time media stream. Option C is wrong because TCP 50000-50059 is used for Teams media fallback when UDP is blocked, not the primary path. Option D is wrong because UDP 53 is DNS, not media transport.

44
MCQhard

Refer to the exhibit. You attempt to enable Planner for a specific department, but users report it is still unavailable. Based on the JSON configuration, what must you do?

A.Assign a new App Setup policy to the users
B.Change the tenant-wide app status to Allowed
C.Update the Teams policy assigned to the department
D.Add the users to the 'App Creators' group
AnswerB

The exhibit shows the status is blocked at a tenant-wide scope. To make the app available, you must first update the tenant-level configuration to allow the application. Only after the tenant-wide block is removed can individual App Permission Policies be effectively used to manage access for specific users.

Why this answer

In Microsoft Teams, app permission policies and app setup policies control availability, but the tenant-wide app status must be set to 'Allowed' for an app to be available to any user. If the app is blocked at the tenant level, no policy can override it. Therefore, changing the tenant-wide app status to Allowed is required.

Exam trap

MS-700 often tests the hierarchy of app controls; candidates might think a user-level policy can override a tenant-wide block, but tenant settings always take precedence.

How to eliminate wrong answers

Option A is wrong because assigning a new App Setup policy only affects how apps are pinned or installed, but if the app is blocked tenant-wide, it remains unavailable. Option C is wrong because Teams policies do not control app availability; app permission policies do, and they cannot override a tenant-wide block. Option D is wrong because adding users to the 'App Creators' group allows them to build custom apps, not to use a blocked app.

45
MCQhard

Refer to the exhibit. An administrator runs the PowerShell command shown to manage a user's meeting experience. What is the result of executing this command?

A.A new meeting policy named user1@contoso.com is created
B.The RestrictMeetingPolicy is applied to all users in the tenant
C.The RestrictMeetingPolicy is assigned to a specific user
D.The user is prevented from joining any meetings
AnswerC

The command correctly identifies a user by their UPN and assigns the named policy to them. This is the standard method for per-user policy assignment in Teams via PowerShell, providing granular control over features like recording, screen sharing, and lobby settings for that specific individual.

Why this answer

The PowerShell command shown (likely Grant-CsTeamsMeetingPolicy -Identity user1@contoso.com -PolicyName RestrictMeetingPolicy) assigns the existing RestrictMeetingPolicy to the specific user user1@contoso.com. This is a per-user policy assignment, not the creation of a new policy or a tenant-wide application.

Exam trap

MS-700 often tests the difference between New-CsTeamsMeetingPolicy (creates a policy) and Grant-CsTeamsMeetingPolicy (assigns a policy), so candidates who see a policy name in the command assume a new policy is being created.

How to eliminate wrong answers

Option A is wrong because the command uses Grant-CsTeamsMeetingPolicy, which assigns an existing policy — it does not create a new policy (that would require New-CsTeamsMeetingPolicy). Option B is wrong because the command targets a single user identity, not all users in the tenant (a tenant-wide assignment would use a different approach, such as a policy package or batch assignment). Option D is wrong because assigning a meeting policy does not prevent the user from joining meetings — it only restricts specific meeting features defined in the policy.

46
MCQmedium

You are the Teams administrator for a company with 5,000 users. The security team reports that employees can add external consultants as members of existing teams, which exposes internal SharePoint content. You must allow external consultants to be added only as guests with limited access, and block any attempt to add them as regular members. Which configuration should you implement?

A.Modify the global meeting policy to disable anonymous users from joining meetings.
B.In the Microsoft 365 admin center, configure guest sharing settings and restrict who can invite guests, then verify guest access is enabled in Teams.
C.Create a sensitivity label that blocks external sharing and publish it to all teams.
D.In the Microsoft Teams admin center, set the external access policy to Block all external domains.
AnswerB

Guest access controls whether people outside the tenant can be added to teams as guests with scoped access to channels, files, and chats. By enabling guest access and limiting who can invite guests, consultants can only be added as guests rather than as members, which matches the security requirement. This is the supported way to control external membership in teams.

Why this answer

Guest access is the Teams and Microsoft 365 capability that lets people outside the organization participate in teams with limited permissions. Enabling guest access while restricting who can invite guests ensures external consultants are added only as guests, not as full members. External access, sensitivity labels, and meeting policies address different concerns and cannot enforce the required membership restriction.

Exam trap

The trap here is confusing external access (federation for chat and meetings with other tenants) with guest access (adding outside people into your own teams).

47
Multi-Selecthard

You are configuring sensitivity labels for use with Microsoft Teams. Which THREE settings can be controlled specifically through the application of a sensitivity label to a Team?

Select 3 answers
A.Privacy (Public or Private) of the team
B.External user access (Guest access)
C.Access from unmanaged devices
D.The ability to record meetings within the team
E.The maximum number of members allowed in the team
AnswersA, B, C

Sensitivity labels can dictate the privacy level of a team. For example, a label named 'Highly Confidential' can be configured to force a team to be 'Private', preventing users from accidentally creating a public team that would expose sensitive information to the entire organization.

Why this answer

Sensitivity labels applied to a Team can enforce container-level settings, and option A is correct because a label can set the team's Privacy to Public or Private, controlling whether the team is discoverable and joinable by anyone in the organization or restricted to invited members. Option B is correct because labels can control external user access, i.e., whether guest access is allowed for the team, blocking or permitting external collaboration. Option C is correct because labels can govern access from unmanaged devices, using Conditional Access integration to allow, block, or limit (web-only) access for users on devices not managed by the organization.

Option D is not controlled by sensitivity labels; meeting recording is governed by Teams meeting policies and the recording feature settings, not by the label applied to the team. Option E is also not controlled by sensitivity labels; the maximum number of members is a tenant/team limit rather than a label-enforced container setting.

Exam trap

MS-700 often tests the misconception that sensitivity labels control all Teams settings — candidates may pick meeting recording or member limits, but labels only control Privacy, guest access, and unmanaged device access for Teams.

48
MCQmedium

An organization is currently in Islands mode during a migration from Skype for Business Server to Microsoft Teams. Users report that they receive chats in both clients, causing confusion. Which coexistence mode should the administrator implement to ensure all incoming chats and calls are received exclusively in Microsoft Teams?

A.Skype for Business only
B.Teams Only
C.Skype for Business with Teams collaboration
D.Skype for Business with Teams collaboration and meetings
AnswerB

Teams Only mode routes all incoming calls and chats to the Teams client regardless of where the sender originates the communication. It is the target state for all migrations, ensuring that users utilize the full feature set of Teams while decommissioning legacy Skype for Business functionality for that specific user.

Why this answer

Teams Only mode is the coexistence mode that routes all incoming chats, calls, and meetings to Microsoft Teams exclusively, removing the dual-client confusion of Islands mode. When a user is in Teams Only, Skype for Business clients are effectively disabled for communication, and all new conversations land in Teams. This is the required end-state for organizations completing a Skype for Business to Teams migration.

Exam trap

MS-700 often tests the distinction between the four coexistence modes, and candidates confuse 'Teams collaboration' (channels/files only) with full Teams chat and calling, leading them to pick option C or D.

How to eliminate wrong answers

Option A is wrong because Skype for Business only mode routes all chats and calls to Skype for Business, which is the opposite of the requirement. Option C is wrong because Skype for Business with Teams collaboration keeps chat and calling in Skype for Business while only enabling Teams for channels and file collaboration — users would still receive chats in Skype for Business. Option D is wrong because Skype for Business with Teams collaboration and meetings adds Teams meetings but still leaves chat and calling in Skype for Business, so incoming chats would not be exclusively in Teams.

49
Multi-Selectmedium

You need to configure External Access (federation) for your Teams environment. You want to allow your users to communicate with users from 'contoso.com' and 'fabrikam.com', but block communication with all other external domains. Which TWO actions should you perform in the Teams admin center?

Select 2 answers
A.Add 'contoso.com' and 'fabrikam.com' to the allowed domains list.
B.Set the 'External access' option to 'Allow only specific external domains'.
C.Enable 'Guests can access Microsoft Teams' in Guest access settings.
D.Set the 'External access' option to 'Block all external domains'.
E.Create a new Teams App Permission policy for the domains.
AnswersA, B

Adding specific domains to the allowed list is the first step in creating a restricted federation policy. This tells the Teams service exactly which external entities are trusted for communication, forming the basis of your security boundary while still enabling the necessary collaboration with your two primary business partners.

Why this answer

Option B is correct because in the Teams admin center under Users > External access, you must set the External access toggle to 'Allow only specific external domains' — this changes the federation mode from the default 'Allow all external domains' to a restricted allow-list model, which is the prerequisite for blocking all other domains. Option A is correct because after selecting that mode you must add 'contoso.com' and 'fabrikam.com' to the allowed domains list; only domains on this list will be able to federate with your users, and any domain not listed (e.g., tailspintoys.com) is automatically blocked. Option C is incorrect because 'Guests can access Microsoft Teams' is a Guest access setting that controls whether guests (B2B collaboration users) can use Teams, not external federation with other Teams tenants.

Option D is incorrect because 'Block all external domains' would prevent communication with contoso.com and fabrikam.com as well, contradicting the requirement. Option E is incorrect because Teams App Permission policies govern which third-party or custom apps users can install, and have nothing to do with external federation or domain allow-lists.

Exam trap

MS-700 often tests the confusion between External access (federation) and Guest access, causing candidates to pick guest-related settings when the scenario is really about cross-tenant chat and calling.

50
MCQeasy

You are a Teams administrator for a large organization. The IT manager asks you to ensure that all users can use the same set of emojis, GIFs, and memes in Teams chats. Which policy should you configure?

A.Teams policy
B.Messaging policy
C.App permission policy
D.Meeting policy
AnswerB

Messaging policies in Teams control chat and channel features, including whether users can use emojis, GIFs, memes, and stickers. By configuring a messaging policy, you can enable or disable these features for users. To ensure all users have the same set, you would apply a consistent messaging policy to all users or groups.

Why this answer

Messaging policies in Microsoft Teams determine the chat and channel features available to users, including emojis, GIFs, memes, and stickers. By configuring and assigning a messaging policy, you can ensure a consistent set of these features for all users. Other policy types focus on meetings, apps, or team-level settings.

Exam trap

The trap here is mixing up messaging policies with meeting or app policies, which control different aspects of Teams.

51
Multi-Selectmedium

You are configuring the 'Email integration' settings for Teams. Which TWO actions can users perform when this feature is enabled and properly configured?

Select 2 answers
A.Users can retrieve the email address for any channel to which they belong.
B.Users can send an email to a channel and have it appear as a new conversation.
C.Users can use Teams to send outbound emails to external SMTP addresses.
D.Users can automatically sync their entire Outlook Inbox to a Teams tab.
E.Users can change the channel's email address to a custom vanity address.
AnswersA, B

When email integration is enabled, users can click the ellipsis next to a channel name to 'Get email address'. This address can then be shared with others or used in automated workflows to send messages and attachments directly into the channel's conversation thread.

Why this answer

Option A is correct because when Email integration is enabled, each channel exposes a unique channel email address (found via the channel's 'Get email address' option), and any member of that channel can retrieve it. Option B is correct because sending an email to that channel address posts the message as a new conversation in the channel, including attachments. Option C is wrong because Teams Email integration is inbound-only; Teams does not act as an SMTP client to send outbound email to external addresses.

Option D is wrong because there is no feature that syncs an entire Outlook Inbox into a Teams tab; only individual emails can be shared or moved to Teams. Option E is wrong because the channel email address is system-generated and cannot be changed to a custom vanity address.

Exam trap

MS-700 often tests the two-way nature of email integration, tricking candidates into thinking Teams can send outbound emails or that channel addresses can be customized, when in fact it is inbound-only and addresses are fixed.

52
MCQhard

You are the Teams administrator for a pharmaceutical company. The compliance department requires that all Teams meeting recordings are stored in a specific Azure region for data residency. You need to ensure that recordings are stored in the correct region. What should you do?

A.Use the Teams admin center to change the default storage region for all recordings.
B.Configure a retention policy in Microsoft 365 compliance center to enforce data residency for Teams recordings.
C.Configure the Teams meeting policy to set the recording storage location to the desired Azure region.
D.Ensure that the user's OneDrive and the team's SharePoint site are provisioned in the desired Azure region.
AnswerD

Teams meeting recordings are stored in the OneDrive of the user who initiates the recording (for non-channel meetings) or in the SharePoint site of the channel (for channel meetings). The storage location is determined by the region where the OneDrive or SharePoint site is provisioned. To meet data residency requirements, you must ensure that these services are provisioned in the desired Azure region, which is typically set based on the user's or tenant's location.

Why this answer

Meeting recordings are stored in SharePoint or OneDrive, depending on the meeting type. Their storage location is determined by the region where those services are provisioned. To enforce data residency, you must ensure that the user's OneDrive and the team's SharePoint site are in the desired Azure region.

Other options reference non-existent settings or misunderstand how data residency is controlled.

Exam trap

The trap here is assuming that Teams has a direct setting to control recording storage location, when it actually inherits the location from SharePoint and OneDrive.

53
Multi-Selecthard

You want to implement Conditional Access policies to secure Microsoft Teams access. Which THREE components are essential when defining a Conditional Access policy in Azure AD for Teams? (Each correct answer presents part of the solution.)

Select 3 answers
A.Assignments (Users and Groups)
B.Cloud apps (Microsoft Teams)
C.Grant controls (e.g., Require MFA)
D.Teams Messaging policy settings
E.A Skype for Business Voice route
AnswersA, B, C

The 'Assignments' section of a Conditional Access policy defines who the policy applies to. Without specifying users or groups, the policy cannot be enforced, as it needs to know which identities are subject to the security requirements and conditions you are establishing for Teams access.

Why this answer

Option A (Assignments - Users and Groups) is correct because every Conditional Access policy must specify the target users or groups to whom the policy applies, which is the 'Assignments' section's user scope in Azure AD. Option B (Cloud apps - Microsoft Teams) is correct because a Conditional Access policy must designate the target cloud application, and selecting Microsoft Teams as the cloud app scopes the policy specifically to Teams access. Option C (Grant controls - e.g., Require MFA) is correct because grant controls define what must be satisfied to gain access, such as requiring multi-factor authentication, compliant device, or hybrid Azure AD joined device, which enforces the actual access condition.

Option D (Teams Messaging policy settings) is incorrect because messaging policies are configured in the Microsoft Teams admin center to control chat and channel features, not in Azure AD Conditional Access. Option E (A Skype for Business Voice route) is incorrect because voice routes are telephony configuration components in Skype for Business Online/Teams Phone, unrelated to Conditional Access policy definition.

Exam trap

MS-700 often tests the misconception that Teams admin center settings (messaging policies, voice routes) are part of Conditional Access, when in fact Conditional Access is exclusively an Azure AD identity construct built from Assignments, Cloud apps, and Access controls.

54
Multi-Selectmedium

You need to restrict a specific group of users from using any third-party apps in Teams, while still allowing them to use all Microsoft-provided apps. Which TWO steps are required to implement this using App Permission Policies?

Select 2 answers
A.Create a custom App Permission Policy and set 'Third-party apps' to 'Block all apps'.
B.Assign the custom App Permission Policy to the specific users.
C.Disable the 'Allow third-party apps' toggle in the Org-wide app settings.
D.Delete all third-party apps from the 'Manage apps' list.
E.Modify the Global (Org-wide default) App Permission Policy.
AnswersA, B

This is the core configuration step. Within the policy, you can independently set the permissions for Microsoft apps, third-party apps, and custom apps. Choosing to block all third-party apps ensures that only the apps developed by Microsoft will be visible and usable for those users.

Why this answer

Option A is correct because a custom App Permission Policy is the mechanism that lets you set the 'Third-party apps' control to 'Block all apps' while leaving Microsoft-provided apps allowed, which is exactly the granular restriction required for this group. Option B is correct because creating a policy alone does nothing until it is assigned to the specific users (or a group) who must be restricted, so the policy must be assigned to those users. Option C is not correct because disabling third-party apps in Org-wide app settings affects the entire tenant, not just the specific group.

Option D is not correct because deleting apps from 'Manage apps' removes them tenant-wide and does not implement a per-user permission restriction. Option E is not correct because modifying the Global (Org-wide default) policy would change behavior for all users rather than only the targeted group.

Exam trap

MS-700 often tests the difference between org-wide app settings and per-user App Permission Policies — the trap is choosing the org-wide toggle or Global policy when the requirement is to restrict only a specific group.

55
Multi-Selectmedium

You need to ensure that only members of the Human Resources department can create new Teams. Which TWO actions must you perform to implement this governance requirement?

Select 2 answers
A.Create an Azure AD security group containing the HR department members.
B.Disable Microsoft 365 Group creation for all users except the HR security group.
C.Assign the Teams Communications Administrator role to all HR department members.
D.Modify the Teams Messaging Policy to disable the 'Create channels' option.
E.Enable the 'Scoped directory search' in the Teams admin center.
AnswersA, B

A security group is necessary to identify the specific subset of users who will be granted the exception to the creation block. Microsoft 365 uses this group within a PowerShell script to map the 'EnableGroupCreation' attribute, allowing only these specific members to bypass the tenant-wide restriction.

Why this answer

Option A is correct because restricting Microsoft 365 Group (and therefore Team) creation is done by allowing a specific Azure AD security group to retain the group-creation right, so you must first create an Azure AD security group that contains the HR department members. Option B is correct because the actual governance control is implemented by disabling Microsoft 365 Group creation for all users while permitting it only for that HR security group, which is configured via the Azure AD directory settings (for example, the EnableGroupCreation / GroupCreationAllowedGroupId settings in the Microsoft 365 Groups / Azure AD blade or the corresponding Microsoft Graph/Exchange Online policy). Together these two actions ensure that only HR members can create new Teams.

Option C is not relevant because the Teams Communications Administrator role governs calling and meeting capabilities, not the ability to create Teams. Option D is incorrect because the Teams Messaging Policy's 'Create channels' option controls channel creation inside existing teams, not team creation. Option E is incorrect because Scoped directory search only limits which users appear in searches, not who can create Teams.

Exam trap

MS-700 often tests the misconception that Teams creation is controlled via Teams admin center policies, when in fact it is governed by Azure AD group creation settings and requires a security group to scope permissions.

56
MCQmedium

A company wants to provide users with the ability to use Dropbox and Google Drive as file storage options within Teams channels. Where should an administrator enable these third-party storage providers?

A.Teams Messaging Policies
B.Org-wide settings > Teams settings
C.Teams App Setup Policies
D.SharePoint Admin Center Settings
AnswerB

Within the Teams admin center, the 'Teams settings' section under 'Org-wide settings' (or 'Files' in the newer interface) contains the toggle switches for third-party storage providers. Enabling Dropbox and Google Drive here makes these services available for all users to add as tabs or storage locations.

Why this answer

Third-party storage providers like Dropbox and Google Drive are enabled at the tenant level in the Teams admin center under Org-wide settings > Teams settings. This section includes the 'Files' settings where you can turn on or off cloud storage options such as Dropbox, Google Drive, Box, and ShareFile. Once enabled, users can add these as storage locations when working with files in Teams channels.

Exam trap

MS-700 often tests the location of file storage settings, tricking candidates into choosing SharePoint Admin Center or Messaging Policies when the correct place is Org-wide Teams settings.

How to eliminate wrong answers

Option A is wrong because Teams Messaging Policies control chat and channel messaging features (e.g., edit/delete messages, giphy), not file storage providers. Option C is wrong because App Setup Policies govern which apps are pinned and available, not the underlying file storage integrations. Option D is wrong because SharePoint Admin Center settings manage SharePoint sites and storage, but the toggle for third-party storage providers in Teams is specifically in the Teams admin center.

57
Multi-Selectmedium

You are implementing a Microsoft 365 Group naming policy to ensure all new Teams follow a standard naming convention. Which THREE requirements or components are necessary to configure this using the Azure Active Directory (Azure AD) admin center? (Each correct answer presents part of the solution.)

Select 3 answers
A.Azure AD Premium P1 or P2 licenses
B.A list of blocked words
C.A defined prefix/suffix naming convention
D.A Teams Messaging policy
E.A Skype for Business Server hybrid connection
AnswersA, B, C

Configuring and enforcing a Microsoft 365 Group naming policy requires that at least one user in the organization has an Azure AD Premium P1 or P2 license. This license level unlocks advanced governance features necessary for managing group lifecycles and naming standards across the entire Microsoft 365 tenant.

Why this answer

The Microsoft 365 Groups naming policy is configured in Azure AD and requires Azure AD Premium P1 or P2 licenses (A), since the feature is a premium Azure AD capability; without P1/P2 the naming policy settings are unavailable. A list of blocked words (B) is one of the two configurable components of the policy, used to prevent specific terms from appearing in group names. A defined prefix/suffix naming convention (C) is the other required component, letting you enforce a standard prefix and/or suffix (optionally with user attributes like [Department]) on new group and Teams names.

A Teams Messaging policy (D) governs chat and messaging features in Teams and has nothing to do with group naming, and a Skype for Business Server hybrid connection (E) is unrelated to Azure AD group naming policy configuration.

Exam trap

MS-700 often tests the misconception that naming policies are configured in the Teams admin center or that they require a Teams-specific policy, when in fact they are Azure AD directory settings requiring Premium P1/P2 licensing.

58
MCQmedium

You want to prevent users from sharing GIFs in Teams chats. Which policy should you modify to accomplish this?

A.Teams policy
B.Messaging policy
C.Meeting policy
D.App permission policy
AnswerB

Messaging policies contain the settings for chat-based interactions, including the use of Giphy, memes, and stickers. By updating the messaging policy assigned to your users, you can toggle these settings off, effectively preventing the use of GIFs in any chat or channel conversation.

Why this answer

The Messaging policy in Microsoft Teams controls user-level chat and channel messaging features, including the ability to send and receive GIFs. Specifically, the 'Use Giphys in conversations' setting within the Messaging policy determines whether users can insert animated images (GIFs) into their messages. By setting this to 'Off', you prevent users from sharing GIFs in chats.

Other policies like Teams policy, Meeting policy, or App permission policy do not govern this specific chat feature.

Exam trap

MS-700 often tests the distinction between different policy types in Teams, and candidates frequently confuse Messaging policies with Teams policies or Meeting policies, leading them to select the wrong policy for controlling chat features like GIFs.

How to eliminate wrong answers

Option A is wrong because Teams policies control team-level settings such as guest access, @mentions, and channel creation, not the ability to share GIFs in chats. Option C is wrong because Meeting policies govern features within meetings, such as recording, screen sharing, and chat during meetings, not general chat messaging. Option D is wrong because App permission policies control which third-party or custom apps are available to users, not the built-in GIF sharing capability in chats.

59
MCQmedium

Your company is planning a transition from Skype for Business Online to Microsoft Teams. You need to ensure that users can only use Microsoft Teams for chat and meetings, but they must still be able to join Skype for Business meetings hosted by external partners. Which coexistence mode should you assign to these users?

A.Islands mode
B.Skype for Business only mode
C.Teams Only mode
D.Skype for Business with Teams Collaboration mode
AnswerC

Teams Only mode ensures all chat and meetings are handled by Microsoft Teams, satisfying the requirement. Even in this mode, users can still use the Skype for Business client to join meetings hosted by external users who have not yet migrated, providing the necessary interoperability while centralizing internal communications.

Why this answer

Teams Only mode ensures users use Microsoft Teams for all chat and meetings, while still allowing them to join Skype for Business meetings hosted by external partners. This mode completes the upgrade to Teams while preserving interoperability for external Skype meetings.

Exam trap

MS-700 often tests the misconception that Teams Only mode blocks joining Skype for Business meetings — in fact, Teams Only users can still join external Skype meetings, which is exactly what this scenario requires.

How to eliminate wrong answers

Option A is wrong because Islands mode allows users to use both Teams and Skype for Business concurrently, which does not meet the requirement to use only Teams. Option B is wrong because Skype for Business only mode keeps users on Skype for Business, contradicting the requirement to use Teams. Option D is wrong because Skype for Business with Teams Collaboration mode allows Teams for chat and channels but keeps meetings in Skype for Business, which does not satisfy 'only Teams for chat and meetings.'

60
MCQeasy

You are setting up a Microsoft Teams Room in a conference room. What type of account is required to properly configure the Teams Room device and allow it to be invited to meetings?

A.A standard User account with an E5 license
B.A Guest account from an external tenant
C.A Resource account with a Teams Room license
D.A Service Principal in Azure Active Directory
AnswerC

Resource accounts are specialized accounts for meeting rooms and shared devices. When combined with a Teams Room Basic or Pro license, they enable the device to join meetings, share content, and be discovered in the global address list as a bookable location for internal users.

Why this answer

Microsoft Teams Rooms require a dedicated resource account (room mailbox) that is assigned a Teams Rooms license (such as Teams Rooms Pro or the legacy Standard). The resource account is what gets invited to meetings and what the room device signs in as, allowing it to auto-accept and join scheduled meetings. A standard user account, guest account, or service principal cannot fulfill the calendar/meeting processing role that a resource account provides.

Exam trap

MS-700 often tests the confusion between a resource account (room mailbox) and a regular user account — candidates assume any licensed account works, but Teams Rooms specifically require a resource account with a Teams Rooms license for calendar and meeting processing.

How to eliminate wrong answers

Option A is wrong because a standard user account with an E5 license is a personal identity — Teams Rooms need a resource (room) mailbox so the device can process meeting invites and manage the room calendar, and E5 does not include the Teams Rooms license. Option B is wrong because a guest account from an external tenant cannot own a room mailbox or be licensed for Teams Rooms in the host tenant. Option D is wrong because a Service Principal is an application identity in Azure AD used for app-only authentication; it has no mailbox and cannot be invited to meetings or manage a room calendar.

61
MCQmedium

You are the Teams administrator for a company that uses Microsoft 365. The company wants to allow users to add third-party cloud storage services, such as Dropbox and Google Drive, to Teams chats and channels. However, the security team requires that only approved services be allowed. You need to configure Teams to permit only specific cloud storage providers. What should you do?

A.Configure a conditional access policy in Azure AD that blocks access to unapproved cloud storage services.
B.In the Teams admin center, go to Teams settings > Files and modify the Cloud storage options to enable only the approved providers.
C.Use the Set-CsTeamsClientConfiguration cmdlet to set the -AllowDropBox and -AllowGoogleDrive parameters to $false.
D.In the Teams admin center, go to Teams apps > Permission policies and create a custom policy that allows only the approved cloud storage apps.
AnswerB

The Cloud storage options in Teams settings allow administrators to enable or disable specific third-party storage providers for the entire organization. By enabling only the approved providers, you restrict users to those services. This directly meets the requirement to permit only specific cloud storage providers. This is the correct location to configure this setting.

Why this answer

The correct action is to modify the Cloud storage options in Teams settings. This allows you to enable only the approved third-party storage providers organization-wide. Other options either target the wrong settings (app permission policies, conditional access) or use cmdlets that do not control cloud storage providers.

This configuration ensures that users can only add approved services to Teams.

Exam trap

The trap here is confusing app permission policies with cloud storage settings; permission policies control app availability, not the storage providers that can be integrated into Teams.

62
MCQmedium

Your organization requires that all Teams meeting chats be deleted after 90 days. Which tool should you use to implement this retention requirement?

A.Teams admin center Messaging policy.
B.Microsoft Purview compliance portal Retention policy.
C.Teams admin center Org-wide settings.
D.Exchange admin center Mailbox retention tags.
AnswerB

Retention policies in the Purview portal are designed to enforce data lifecycle management. By applying a policy to Teams chats, you can automatically purge messages after a 90-day window, ensuring that the organization adheres to its data governance and privacy policies consistently across the entire tenant.

Why this answer

Retention requirements for Teams meeting chats are enforced through Microsoft Purview retention policies, which can target Teams chat and channel messages and delete them after a specified period (e.g., 90 days). Purview retention policies apply at the workload level and are the correct tool for compliance-driven deletion of Teams messages.

Exam trap

MS-700 often tests the confusion between Teams admin center messaging policies (feature control) and Purview retention policies (compliance deletion), causing candidates to pick a Teams admin center option for a retention requirement.

How to eliminate wrong answers

Option A is wrong because Teams admin center Messaging policies control user-level chat and messaging features (e.g., edit/delete permissions, GIFs), not retention or deletion schedules. Option C is wrong because Org-wide settings in Teams admin center govern tenant-wide feature toggles (e.g., apps, meetings), not message retention. Option D is wrong because Exchange mailbox retention tags apply to Exchange email items, not Teams meeting chats, which are stored in Exchange Online but managed via Purview retention policies for Teams.

63
MCQmedium

A user reports that they cannot find the 'Shift' app in the Teams app store. You verify that the app is enabled at the org-level. Which policy should you check to ensure the user has permission to use the app?

A.Teams App Setup Policy
B.Teams App Permission Policy
C.Teams Messaging Policy
D.Teams Meeting Policy
AnswerB

Permission policies allow you to 'Allow' or 'Block' specific apps for users. If the 'Shift' app (a Microsoft app) is not included in the allowed list of the permission policy assigned to the user, it will be hidden from their view in the app store, regardless of other settings.

Why this answer

Teams App Permission Policies control which apps individual users or groups are allowed to use, overriding the org-level app enablement. Even if an app is enabled tenant-wide, a user assigned to a restrictive permission policy will not see it in the Teams app store. Therefore, the Teams App Permission Policy is the correct policy to check.

Exam trap

MS-700 often tests the confusion between App Setup Policies (which control pinning and installation) and App Permission Policies (which control access). Candidates frequently pick App Setup Policy thinking it governs availability, but it only affects the user's app bar and pre-installed apps.

How to eliminate wrong answers

Option A is wrong because Teams App Setup Policy controls how apps are pinned and installed for users, not whether they are permitted to use them. Option C is wrong because Teams Messaging Policy governs chat and channel messaging features (e.g., edit/delete messages, Giphy), not app availability. Option D is wrong because Teams Meeting Policy controls meeting features such as recording, transcription, and lobby settings, not app access.

64
Multi-Selectmedium

You are managing external collaboration for your tenant. You want to allow your users to search for and chat with users in another specific organization (domain: contoso.com) but block communication with all other external domains. Which TWO settings must you configure? Each correct answer presents part of the solution.

Select 2 answers
A.In External access, set the domain access to 'Allow only specific external domains'.
B.In External access, add 'contoso.com' to the list of allowed domains.
C.In Guest access, set 'Allow guest access in Teams' to Off.
D.In External access, set the domain access to 'Block all external domains'.
E.In the Microsoft 365 admin center, disable 'External sharing' for SharePoint.
AnswersA, B

Setting the domain access to 'Allow only specific external domains' changes the default behavior of the tenant from 'Open' to 'Restricted'. This ensures that the system will automatically block communication with any domain that is not explicitly added to the allowed list, providing a high level of security.

Why this answer

Option A is correct because in Teams External access you must first change the domain access setting from the default to 'Allow only specific external domains' to switch from allowing all federated domains to a restricted allow-list model. Option B is correct because after selecting that mode you must explicitly add contoso.com to the allowed domains list, which enables Teams federation (chat, calls, presence) with users in that specific organization while blocking all others. Options C and E are incorrect because guest access and SharePoint external sharing govern guest accounts and file sharing, not federated chat/search with external Teams users.

Option D is incorrect because 'Block all external domains' would prevent communication with contoso.com as well, contradicting the requirement.

Exam trap

MS-700 often tests the confusion between External Access and Guest Access; candidates may incorrectly select Guest Access settings when the requirement is about chat and search with external users, not team membership.

65
MCQhard

You are a Teams administrator for a global organization. You need to ensure that all users in the sales department can only use the Teams client on Windows devices that are compliant with your organization's conditional access policies. What should you configure?

A.In the Teams admin center, modify the global app permission policy to block Teams on unmanaged devices.
B.Create a Teams app setup policy that blocks the mobile client for sales users.
C.Configure a conditional access policy in Azure AD that requires compliant devices for the Teams cloud app and assign it to the sales department.
D.Use Intune to deploy a device compliance policy that blocks the Teams app on non-compliant devices.
AnswerC

Conditional access policies in Azure AD can enforce device compliance for specific cloud apps, including Teams. By targeting the Teams cloud app and the sales group, and requiring a compliant device, you ensure that only compliant Windows devices can access Teams. This directly satisfies the requirement.

Why this answer

Conditional access is the correct tool to enforce device compliance for cloud apps like Teams. By creating a policy that requires compliant devices and targeting the sales department, you ensure that only compliant Windows devices can access Teams. This integrates with Intune compliance policies to evaluate device state.

Exam trap

The trap here is confusing Intune compliance policies with conditional access; compliance policies alone do not block access without a conditional access policy.

66
MCQmedium

A company has a Microsoft 365 tenant with Microsoft Teams. The security team requires that all meeting recordings are stored for 90 days and then automatically deleted. You need to configure the appropriate policy. Which setting should you modify?

A.SharePoint Online storage quota for the site
B.Microsoft 365 retention policy for Teams recordings
C.Teams meeting policy - Recording expiration
D.Teams meeting policy - Allow cloud recording
AnswerB

A Microsoft 365 retention policy applied to Teams recordings (stored in SharePoint or OneDrive) can automatically delete recordings after 90 days. This is the correct method because it ensures compliance across all recordings regardless of meeting policy settings. Retention policies are managed in the Microsoft 365 compliance center and take precedence for data lifecycle management.

Why this answer

The requirement is to store meeting recordings for 90 days and then delete them automatically. This is a data lifecycle task that must be handled by a Microsoft 365 retention policy targeting Teams recordings. Meeting policies control recording capabilities, not retention duration.

SharePoint quotas are unrelated to time-based deletion. Therefore, configuring a retention policy is the correct action.

Exam trap

The trap here is assuming that a Teams meeting policy setting controls how long recordings are kept, when actually retention is managed by Microsoft 365 compliance policies.

67
MCQeasy

A Teams administrator needs to ensure that a newly hired support agent can create teams, but the agent must not be able to change organizational-wide settings in the Teams admin center. The agent already has a Microsoft 365 E3 license. What should the administrator do?

A.Enable the agent to create Microsoft 365 groups by using the Microsoft 365 groups creation setting and assign no Teams admin role.
B.Assign the Teams Communications Administrator role to the agent.
C.Assign the Teams Administrator role to the agent in the Microsoft 365 admin center.
D.Assign the Global Administrator role to the agent temporarily and remove it after team creation.
AnswerA

Team creation is governed by the ability to create Microsoft 365 groups, which can be controlled at the tenant level. By allowing this user to create groups and not assigning a Teams admin role, the agent can create teams while remaining unable to modify organizational-wide Teams settings. This satisfies least privilege and directly addresses the requirement.

Why this answer

Team creation depends on the right to create Microsoft 365 groups, which can be granted independently of any Teams administrative role. Leaving the user without a Teams admin role ensures they cannot alter tenant-wide settings. The Teams Administrator, Teams Communications Administrator, and Global Administrator roles all grant broader or unrelated permissions that exceed the requirement.

Exam trap

The trap here is assuming that creating teams requires a Teams administrative role, when in fact it is controlled by Microsoft 365 group creation permissions.

Ready to test yourself?

Try a timed practice session using only Configure Manage Teams Environment questions.