Describe security, compliance, privacy, and trust in Microsoft 365 →hardMultiple ChoiceObjective-mapped
MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A company uses Microsoft 365 (a SaaS offering). A security incident occurs where an employee's account is compromised because the employee reused their corporate password on a personal website. According to the shared responsibility model, who is primarily responsible for this security failure?
⚠ Common exam trap
Watch out — candidates often assume SaaS means Microsoft handles all security, but the shared responsibility model clearly places identity and credential management on the customer, especially for user-caused password reuse incidents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer (the company using Microsoft 365)
In the Microsoft 365 shared responsibility model, the customer is responsible for securing user identities, including password hygiene and multi-factor authentication (MFA). Since the employee reused their corporate password on a personal website, this is a customer-side identity management failure, not a platform vulnerability. Microsoft secures the SaaS infrastructure, but customer-managed credentials fall under the customer's responsibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The customer (the company using Microsoft 365)
Why this is correct
The customer is accountable for the identity plane in the Microsoft 365 shared responsibility model. Entra ID (Azure AD) tenant configuration, user accounts, passwords, and access policies like MFA and Conditional Access are all customer-managed controls. Because the incident stemmed from weak password practices and password reuse, the failure resides in the customer's cloud-hosted data and identity responsibilities, not in Microsoft's infrastructure or code.
- ✗
Microsoft, because they provide the SaaS platform
Why it's wrong here
While Microsoft operates and secures the underlying SaaS infrastructure, application binaries, and platform endpoints, it does not control how each tenant's users choose or manage their passwords. Microsoft 365 offers security baselines, password protection, and MFA, but these are disabled or configurable by the customer; Microsoft cannot prevent a user from reusing a password on an external site. Thus, attributing the breach to Microsoft because it provides the platform conflates 'security of the cloud' with 'security in the cloud,' and the specific cause falls outside Microsoft's layer of control.
- ✗
Both Microsoft and the customer share equal responsibility
Why it's wrong here
The shared responsibility model does not assign equal responsibility for every security control; it assigns each control to the party best positioned to act. Microsoft owns applicable responsibilities such as patching Exchange Online and mitigating platform-level DDoS, while the customer owns identity management, including password complexity and credential reuse monitoring. Since the compromise originated from inadequately managed credentials, the customer bears full responsibility for that particular control, so saying both share equally overstates Microsoft's role and misstates the model's allocation.
- ✗
It depends on the contract terms with Microsoft
Why it's wrong here
The shared responsibility model for Microsoft 365 is defined in Microsoft's Online Services Terms and Standard Contractual Clauses, but the fundamental allocation is not a term negotiated per customer; identity security is always customer-owned. Contract documents state that Microsoft provides the service and customer retains control of data and identities, including accessing, securing, and managing them. Even if a contract increases Microsoft's support commitments, it cannot reassign the inherent customer duty to govern user passwords, so the correct assignment does not depend on contract terms.
Go deeper
Related to this question
Learn chapter
Benefits of Microsoft Cloud
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
This MS-900 question is part of Courseiva's 217-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.