Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Exhibit

Refer to the exhibit.

```powershell
Get-MgPolicyCrossTenantAccessPolicy

Id           : /policies/crossTenantAccessPolicy
DisplayName   : Default policy
DefaultPolicy : Microsoft.Graph.PowerShell.Models.MicrosoftGraphCrossTenantAccessPolicyDefault

(DefaultPolicy properties)
B2BCollaborationInbound : @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BCollaborationOutbound: @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BDirectConnectInbound : @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BDirectConnectOutbound: @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
OfficeSyncInbound        : @{AllowedTenants=}
OfficeSyncOutbound       : @{AllowedTenants=}
IsServiceDefault         : True

Get-MgPolicyCrossTenantAccessPolicyPartner -CrossTenantAccessPolicyId "/policies/crossTenantAccessPolicy"

Id                   : /policies/crossTenantAccessPolicy/partners/contoso.com
TenantId             : contoso.com
B2BCollaborationInbound : @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BCollaborationOutbound: @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BDirectConnectInbound : @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BDirectConnectOutbound: @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
OfficeSyncInbound        : @{AllowedTenants=}
OfficeSyncOutbound       : @{AllowedTenants=}
IsServiceDefault         : False
AutomaticUserConsentSettings: @{InboundAllowed=; OutboundAllowed=}
```

Refer to the exhibit. The Contoso tenant has a cross-tenant access policy configured for Fabrikam. Users from Fabrikam are unable to access resources in Contoso via B2B collaboration. What is the most likely reason?

⚠ Common exam trap

Many exam-takers confuse inbound vs. outbound settings or assume the default policy applies to explicitly configured tenants, when in fact a specific tenant policy overrides the default for that tenant.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The B2BCollaborationInbound setting for Fabrikam does not allow any identities or applications

The B2BCollaborationInbound setting for Fabrikam controls which external users and applications are allowed to access Contoso resources via B2B collaboration. If this setting does not allow any identities or applications, all inbound B2B collaboration attempts from Fabrikam will be blocked, even if the default cross-tenant access policy is permissive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The B2BCollaborationOutbound setting is blocking access

    Why it's wrong here

    The B2BCollaborationOutbound setting controls how Contoso users, the users in the originating tenant, are shared with Fabrikam - specifically, whether Contoso users can be invited to Fabrikam's tenant or access applications hosted there. It says nothing about Fabrikam identities trying to get into Contoso resources. Because the reported problem is an external user from Fabrikam being unable to access Contoso, an outbound policy cannot be the root cause; that failure can only be governed by Contoso's inbound cross-tenant access settings.

  • ✗

    The default cross-tenant access policy is set to block all

    Why it's wrong here

    The default cross-tenant access policy applies only when no tenant-specific policy has been configured for that partner organization. In the exhibit, Fabrikam has its own organizational-specific cross-tenant access settings, and those settings take precedence over the default policy for that tenant. Even if the default policy were shown as blocking - which it is not - the partner-specific inbound B2B collaboration configuration would override it. Therefore, an empty or non-blocking default cannot explain why Fabrikam B2B users are failing to gain access to Contoso.

  • ✓

    The B2BCollaborationInbound setting for Fabrikam does not allow any identities or applications

    Why this is correct

    The B2BCollaborationInbound section for Fabrikam is the exact place where Contoso must explicitly allow Fabrikam users, groups, and applications to participate in B2B collaboration. When this inbound section contains no entries at all, Microsoft Entra ID treats it as an implicit deny: no Fabrikam identities are authorized to be invited as B2B guests, and no Contoso applications are available for them to access. Because the exhibit shows an empty inbound B2B collaboration policy for Fabrikam, it actively blocks the invitation and sign-in flow for those external users, which directly causes the reported access failure.

  • ✗

    The B2BDirectConnectInbound setting is empty

    Why it's wrong here

    B2B direct connect is a different collaboration capability used for Teams shared channels, allowing users from Fabrikam to participate in shared channels in Contoso's tenant without becoming B2B guest directory objects. An empty B2BDirectConnectInbound setting would therefore affect Teams shared-channel access, not the standard B2B collaboration invitation flow that lets external users sign in as guests and access Contoso apps. Since the issue described is about B2B collaboration guest access, the empty direct-connect setting is irrelevant to the failure, even if it appears alongside the collaboration settings in the cross-tenant access policy.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.