mediumMultiple Choice
MS-102 A company has a Microsoft 365 E5 subscription Practice Question
A company has a Microsoft 365 E5 subscription. The security team requires that all guest users must have terms of use acceptance before accessing resources. Which Microsoft Entra ID feature should be configured?
⚠ Common exam trap
Candidates often confuse the 'Terms of Use' feature with 'Conditional Access policies' because Conditional Access is the enforcement mechanism, but the question specifically asks which feature should be configured to have the terms of use document itself, not the policy that enforces it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Terms of Use
Microsoft Entra ID Terms of Use (ToU) is the correct feature because it allows administrators to present a document to guest users that they must accept before accessing resources. This directly meets the security team's requirement for mandatory terms of use acceptance. Conditional Access policies can enforce ToU acceptance, but the ToU document itself is created and managed under the Microsoft Entra ID Terms of Use blade.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID Terms of Use
Why this is correct
Microsoft Entra ID Terms of Use (now part of Microsoft Entra ID) is the correct feature because it lets an organization create a customizable legal document and require specific users or groups to accept it before accessing a resource. You author the ToU in the Entra admin center under Protection > Conditional Access > Terms of use, and the service tracks each user's acceptance, including the version accepted and the timestamp. Acceptance can then be enforced via a Conditional Access policy, but the ToU itself is a separate configuration object that independently fulfills the requirement to have terms users must accept.
- ✗
Conditional Access policy
Why it's wrong here
A Conditional Access policy is a rule that controls access based on conditions like user, device, or location, and it can include 'Grant' controls such as requiring MFA or requiring a Terms of Use. However, the policy cannot be used to create or maintain the ToU content; the ToU must first be created in the Microsoft Entra ID Terms of Use feature and then selected as a grant control. Without a pre-existing ToU, you cannot enforce acceptance, and simply having a Conditional Access policy does not satisfy the requirement to present a terms-of-use agreement.
- ✗
Microsoft Entra ID Protection
Why it's wrong here
Microsoft Entra ID Protection is a risk-engineering service that detects suspicious signals such as anonymous IP addresses, impossible travel, and leaked credentials, and it can automatically trigger remediation like prompting for additional authentication or password change. It has no authoring or presentation workflow for Terms of Use; its capabilities are centered on identifying and responding to identity risk rather than managing consent or legal agreements. Therefore, while Identity Protection may occasionally integrate with Conditional Access, it never creates or requires acceptance of a ToU.
- ✗
Self-service password reset
Why it's wrong here
Self-service password reset (SSPR) is a feature that allows users to reset or unlock their own passwords using pre-defined authentication methods like SMS, email, or security questions. It is designed solely for credential recovery and does not include any mechanism to display or capture acceptance of a Terms of Use document. Requiring ToU acceptance is unrelated to password lifecycle management, so SSPR would not help the company achieve this requirement.
Go deeper
Related to this question
Learn chapter
Intune and Conditional Access Integration
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.