Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

A company uses Microsoft 365 Business Premium. A user reports that when they try to access a file in SharePoint Online, they receive an error that the file is blocked by policy. The IT admin needs to identify which policy is blocking the file. Which tool should the admin use?

⚠ Common exam trap

Watch out — candidates often confuse Microsoft Defender for Cloud Apps session policies (which control user actions in real-time) with SharePoint's native DLP enforcement, but the 'blocked by policy' error is a direct result of a DLP policy applied at the SharePoint level, not a session-level control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Data Loss Prevention policies

Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to detect and block the sharing or access of sensitive information, such as credit card numbers or personally identifiable information, in Microsoft 365 services like SharePoint Online. When a file is blocked with a 'blocked by policy' error, it is typically because a DLP rule has matched the file's content and applied an action to restrict access. The admin can use the Microsoft Purview compliance portal to review DLP policy matches and identify the exact rule that triggered the block.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Intune compliance policies

    Why it's wrong here

    Microsoft Intune compliance policies evaluate the device's health and security posture, such as OS version, patch level, and threat detection, to determine if it meets conditional access requirements. They operate at the device level, not the document level, and do not inspect file content or metadata within SharePoint. Consequently, they cannot block access to or sharing of a specific sensitive file, making them incorrect for this requirement.

  • ✗

    Microsoft Entra ID Conditional Access policies

    Why it's wrong here

    Microsoft Entra ID Conditional Access policies enforce access controls at the authentication and session level, for example requiring multi-factor authentication or blocking sign-ins from certain geographies. They consider user, device, location, and application context, but they do not analyze the actual content of files stored in SharePoint. Therefore, a user who satisfies the sign-in conditions could still access or share a sensitive file, so these policies cannot provide file-level blocking based on data sensitivity.

  • ✗

    Microsoft Defender for Cloud Apps session policies

    Why it's wrong here

    Microsoft Defender for Cloud Apps session policies leverage conditional access app control to monitor and control user activities within a cloud app in real time, such as preventing downloads or blocking upload of files. However, they are session-oriented and primarily restrict user actions like copying or printing, rather than blocking a specific file from being shared or accessed in SharePoint. They do not inspect the file content to identify sensitive data, so they cannot stop a user from sharing a file that contains confidential information.

  • ✓

    Microsoft Purview Data Loss Prevention policies

    Why this is correct

    Microsoft Purview Data Loss Prevention (DLP) policies are designed to detect and protect sensitive data across Microsoft 365 workloads, including SharePoint. A DLP policy can analyze files for sensitive content types, such as personally identifiable information, and then trigger actions like blocking external sharing or restricting access to specific users. Because it operates directly on the file's content and can execute file-level restrictions, it is the correct solution for blocking files in SharePoint based on their data sensitivity.

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.