Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

A company wants to prevent their Microsoft 365 tenant from allowing external users to be invited by default. Only specific administrators should be able to invite guests. Which setting should be changed?

⚠ Common exam trap

A common mix-up: candidates confuse 'blocking external users' via Conditional Access (Option B) with controlling the invitation process, but Conditional Access only applies after the user is already in the directory, not to the invitation permission itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

External Identities – External collaboration settings

The correct setting is under External Identities – External collaboration settings, specifically the 'Guest invite settings' option. By default, this is set to 'Anyone in the organization can invite guest users including guests and non-admins'. Changing it to 'Only users assigned to specific admin roles can invite guest users' restricts guest invitations to designated administrators, meeting the requirement to prevent default external user invitations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    External Identities – External collaboration settings

    Why this is correct

    In Entra ID (Azure AD), navigate to External Identities > External collaboration settings and change the Guest invite settings to 'Only users assigned to specific admin roles can invite guests' (or 'No one can invite guests'). This is the administrative toggle that directly restricts who can issue B2B invitations, so it is the correct control to prevent the tenant from broadcasting external-user invitation privileges.

  • ✗

    Conditional Access policy to block external users

    Why it's wrong here

    A Conditional Access policy blocks sign-in sessions by evaluating conditions such as user, device, location, and risk after an identity attempts to authenticate. It can deny external users access to resources at sign-in time, but it has no influence over the B2B invitation process because invitation delivery is an administrative operation in Entra ID, not a sign-in event that Conditional Access can intercept or block.

  • ✗

    Tenant restrictions

    Why it's wrong here

    Tenant restrictions use a proxy-injected 'Restrict-Access-To-Tenants' header to prevent users in your organization from authenticating to unauthorized external tenant IDs, establishing an outbound security boundary. They do not govern the inbound B2B invitation workflow or who in your tenant has permission to send guest invitations, so they cannot stop external-user invites from being issued.

  • ✗

    B2B direct connect

    Why it's wrong here

    B2B direct connect creates a mutual, transparent trust relationship between your tenant and another tenant for collaborative scenarios like Teams Connect shared channels, and it does not require guest user accounts. It is an enabling feature for cross-tenant collaboration rather than a governance setting, and it neither grants nor blocks the ability to invite external users as B2B guests.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.