MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A company wants to prevent employees from forwarding sensitive emails outside the organization. Which Microsoft Purview feature should they use?
⚠ Common exam trap
MS-900 often tests the confusion between data protection features (Purview Message Encryption, DLP) and access/identity controls (Conditional Access, Intune MAM) — candidates pick Conditional Access thinking it restricts email forwarding, but it only gates access to resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Message Encryption
Microsoft Purview Message Encryption (part of Purview Information Protection) lets organizations encrypt and apply usage restrictions to email, including preventing forwarding, printing, or copying of sensitive messages. It uses Azure Rights Management to enforce protection that travels with the message, so even if a recipient tries to forward it outside the organization, the protection persists. This directly addresses the requirement to prevent forwarding sensitive emails outside the organization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune Mobile Application Management
Why it's wrong here
Intune MAM controls app-level access and data-sharing on managed devices; it does not inspect email content or block forwarding to external recipients. It is tempting because it restricts corporate data movement, and it would be correct for containing data within managed mobile apps.
- ✗
Microsoft Entra ID Conditional Access
Why it's wrong here
Conditional Access governs sign-in and session access to cloud resources, not email forwarding after delivery, so it cannot block a recipient from forwarding a message. It is tempting because it enforces access policy, and would be correct for restricting who may authenticate to a service or requiring compliant devices.
- ✗
Microsoft Defender for Office 365 Anti-Phishing
Why it's wrong here
Anti-Phishing detects and blocks inbound spoofing, impersonation and malicious links; it does not inspect outbound mail for forwarding of sensitive content. It is tempting because Defender for Office 365 does filter email, and would be correct for stopping phishing messages reaching user inboxes.
- ✓
Microsoft Purview Message Encryption
Why this is correct
Message Encryption wraps outbound email in protection that travels with the message, so recipients outside the organisation cannot forward, copy, or print the sensitive content. This directly satisfies the requirement to prevent external forwarding, unlike sensitivity labels, which rely on client-side enforcement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.