MS-900 Describe Microsoft 365 apps and services Practice Question
A company uses Microsoft 365 Business Premium. A user reports that when they try to access a file in SharePoint Online, they receive an error that the file is blocked by policy. The IT admin needs to identify which policy is blocking the file. Which tool should the admin use?
⚠ Common exam trap
Watch out — candidates often confuse Microsoft Defender for Cloud Apps session policies (which control user actions in real-time) with SharePoint's native DLP enforcement, but the 'blocked by policy' error is a direct result of a DLP policy applied at the SharePoint level, not a session-level control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Data Loss Prevention policies
Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to detect and block the sharing or access of sensitive information, such as credit card numbers or personally identifiable information, in Microsoft 365 services like SharePoint Online. When a file is blocked with a 'blocked by policy' error, it is typically because a DLP rule has matched the file's content and applied an action to restrict access. The admin can use the Microsoft Purview compliance portal to review DLP policy matches and identify the exact rule that triggered the block.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune compliance policies
Why it's wrong here
Microsoft Intune compliance policies evaluate the device's health and security posture, such as OS version, patch level, and threat detection, to determine if it meets conditional access requirements. They operate at the device level, not the document level, and do not inspect file content or metadata within SharePoint. Consequently, they cannot block access to or sharing of a specific sensitive file, making them incorrect for this requirement.
- ✗
Microsoft Entra ID Conditional Access policies
Why it's wrong here
Microsoft Entra ID Conditional Access policies enforce access controls at the authentication and session level, for example requiring multi-factor authentication or blocking sign-ins from certain geographies. They consider user, device, location, and application context, but they do not analyze the actual content of files stored in SharePoint. Therefore, a user who satisfies the sign-in conditions could still access or share a sensitive file, so these policies cannot provide file-level blocking based on data sensitivity.
- ✗
Microsoft Defender for Cloud Apps session policies
Why it's wrong here
Microsoft Defender for Cloud Apps session policies leverage conditional access app control to monitor and control user activities within a cloud app in real time, such as preventing downloads or blocking upload of files. However, they are session-oriented and primarily restrict user actions like copying or printing, rather than blocking a specific file from being shared or accessed in SharePoint. They do not inspect the file content to identify sensitive data, so they cannot stop a user from sharing a file that contains confidential information.
- ✓
Microsoft Purview Data Loss Prevention policies
Why this is correct
Microsoft Purview Data Loss Prevention (DLP) policies are designed to detect and protect sensitive data across Microsoft 365 workloads, including SharePoint. A DLP policy can analyze files for sensitive content types, such as personally identifiable information, and then trigger actions like blocking external sharing or restricting access to specific users. Because it operates directly on the file's content and can execute file-level restrictions, it is the correct solution for blocking files in SharePoint based on their data sensitivity.
Go deeper
Related to this question
Learn chapter
Anti-Phishing Policies in Microsoft 365
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.