Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A company uses Microsoft 365 (a SaaS offering). A security incident occurs where an employee's account is compromised because the employee reused their corporate password on a personal website. According to the shared responsibility model, who is primarily responsible for this security failure?

⚠ Common exam trap

Watch out — candidates often assume SaaS means Microsoft handles all security, but the shared responsibility model clearly places identity and credential management on the customer, especially for user-caused password reuse incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The customer (the company using Microsoft 365)

In the Microsoft 365 shared responsibility model, the customer is responsible for securing user identities, including password hygiene and multi-factor authentication (MFA). Since the employee reused their corporate password on a personal website, this is a customer-side identity management failure, not a platform vulnerability. Microsoft secures the SaaS infrastructure, but customer-managed credentials fall under the customer's responsibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The customer (the company using Microsoft 365)

    Why this is correct

    The customer is accountable for the identity plane in the Microsoft 365 shared responsibility model. Entra ID (Azure AD) tenant configuration, user accounts, passwords, and access policies like MFA and Conditional Access are all customer-managed controls. Because the incident stemmed from weak password practices and password reuse, the failure resides in the customer's cloud-hosted data and identity responsibilities, not in Microsoft's infrastructure or code.

  • Microsoft, because they provide the SaaS platform

    Why it's wrong here

    While Microsoft operates and secures the underlying SaaS infrastructure, application binaries, and platform endpoints, it does not control how each tenant's users choose or manage their passwords. Microsoft 365 offers security baselines, password protection, and MFA, but these are disabled or configurable by the customer; Microsoft cannot prevent a user from reusing a password on an external site. Thus, attributing the breach to Microsoft because it provides the platform conflates 'security of the cloud' with 'security in the cloud,' and the specific cause falls outside Microsoft's layer of control.

  • Both Microsoft and the customer share equal responsibility

    Why it's wrong here

    The shared responsibility model does not assign equal responsibility for every security control; it assigns each control to the party best positioned to act. Microsoft owns applicable responsibilities such as patching Exchange Online and mitigating platform-level DDoS, while the customer owns identity management, including password complexity and credential reuse monitoring. Since the compromise originated from inadequately managed credentials, the customer bears full responsibility for that particular control, so saying both share equally overstates Microsoft's role and misstates the model's allocation.

  • It depends on the contract terms with Microsoft

    Why it's wrong here

    The shared responsibility model for Microsoft 365 is defined in Microsoft's Online Services Terms and Standard Contractual Clauses, but the fundamental allocation is not a term negotiated per customer; identity security is always customer-owned. Contract documents state that Microsoft provides the service and customer retains control of data and identities, including accessing, securing, and managing them. Even if a contract increases Microsoft's support commitments, it cannot reassign the inherent customer duty to govern user passwords, so the correct assignment does not depend on contract terms.

About these practice questions

This MS-900 question is part of Courseiva's 217-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.