Courseiva

MS-700 Configure and Manage a Teams Environment Practice Question

You need to configure External Access (federation) for your Teams environment. You want to allow your users to communicate with users from 'contoso.com' and 'fabrikam.com', but block communication with all other external domains. Which TWO actions should you perform in the Teams admin center?

⚠ Common exam trap

MS-700 often tests the confusion between External access (federation) and Guest access, causing candidates to pick guest-related settings when the scenario is really about cross-tenant chat and calling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add 'contoso.com' and 'fabrikam.com' to the allowed domains list.

Option B is correct because in the Teams admin center under Users > External access, you must set the External access toggle to 'Allow only specific external domains' — this changes the federation mode from the default 'Allow all external domains' to a restricted allow-list model, which is the prerequisite for blocking all other domains. Option A is correct because after selecting that mode you must add 'contoso.com' and 'fabrikam.com' to the allowed domains list; only domains on this list will be able to federate with your users, and any domain not listed (e.g., tailspintoys.com) is automatically blocked. Option C is incorrect because 'Guests can access Microsoft Teams' is a Guest access setting that controls whether guests (B2B collaboration users) can use Teams, not external federation with other Teams tenants. Option D is incorrect because 'Block all external domains' would prevent communication with contoso.com and fabrikam.com as well, contradicting the requirement. Option E is incorrect because Teams App Permission policies govern which third-party or custom apps users can install, and have nothing to do with external federation or domain allow-lists.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add 'contoso.com' and 'fabrikam.com' to the allowed domains list.

    Why this is correct

    Adding specific domains to the allowed list is the first step in creating a restricted federation policy. This tells the Teams service exactly which external entities are trusted for communication, forming the basis of your security boundary while still enabling the necessary collaboration with your two primary business partners.

  • ✓

    Set the 'External access' option to 'Allow only specific external domains'.

    Why this is correct

    Selecting this specific mode changes the global federation logic from an open model to a restricted model. Once this is set, any domain that is not explicitly added to your allowed list will be blocked by default, ensuring that users cannot chat with unauthorized individuals from other organizations.

  • ✗

    Enable 'Guests can access Microsoft Teams' in Guest access settings.

    Why it's wrong here

    Guest access is a separate feature from External Access (federation). Guest access allows users to be added to teams as members, while external access allows for chat and calls with users in their own tenants. Enabling guest access does not configure the domain-level chat restrictions required here.

  • ✗

    Set the 'External access' option to 'Block all external domains'.

    Why it's wrong here

    Blocking all external domains would prevent communication with even the trusted partners at Contoso and Fabrikam. This setting overrides any allowed list and completely isolates the tenant from external chat and calls, making it impossible to meet the requirement of allowing communication with the two specific partners.

  • ✗

    Create a new Teams App Permission policy for the domains.

    Why it's wrong here

    App permission policies control which applications are available to users within the Teams client. They have no relationship with network-level federation or the ability to communicate with users in external Microsoft 365 tenants, and therefore cannot be used to manage domain-level allow-lists for chat and calling.

About these practice questions

One of 211 original MS-700 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-700 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-700 exam.