MS-900 Describe Microsoft 365 apps and services Practice Question
A global consulting firm uses Microsoft 365 E5. Consultants frequently travel and need to access email, files, and Teams on personal iOS and Android devices without enrolling the devices in mobile device management. The security team requires that corporate data remain protected and that they can selectively wipe corporate data if a device is lost. Which Microsoft 365 feature should the firm implement?
⚠ Common exam trap
The trap here is assuming that device compliance or Conditional Access App Control can protect data on unenrolled devices, when only app protection policies provide app-level containerization and selective wipe without enrollment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Intune app protection policies (MAM)
Intune app protection policies (mobile application management) secure corporate data within apps on personal devices without enrollment. They prevent data leakage between managed and unmanaged apps and allow selective wipe of corporate data. Device compliance policies, Information Barriers, and Conditional Access App Control do not provide the same app-level containerization and selective wipe for unenrolled devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune device compliance policies
Why it's wrong here
Intune device compliance policies evaluate settings on enrolled devices and can mark them compliant or non-compliant, but they depend on device enrollment. The firm's requirement is to protect data on personal devices without enrollment. Compliance policies alone would not provide the app-level protection and selective wipe needed in this unenrolled scenario.
- ✗
Microsoft Purview Information Barriers
Why it's wrong here
Information Barriers restrict communication and collaboration between groups of users, such as preventing certain departments from communicating. It does not protect corporate data on personal mobile devices or enable selective wipe. While useful for compliance, it does not address the requirement to secure email, files, and Teams on unenrolled iOS and Android devices.
- ✓
Microsoft Intune app protection policies (MAM)
Why this is correct
App protection policies in Intune protect corporate data at the app level without requiring device enrollment. They can enforce PIN, block copy-paste to personal apps, and enable selective wipe of corporate data from managed apps on iOS and Android. This directly meets the firm's need to secure email, files, and Teams on personal devices without MDM enrollment.
- ✗
Microsoft Defender for Cloud Apps Conditional Access App Control
Why it's wrong here
Conditional Access App Control uses a reverse proxy to monitor and control access to cloud apps, which can block downloads or enforce session policies. However, it does not provide app-level containerization or selective wipe of corporate data on personal devices. The firm needs data protection within the apps without enrollment, which is delivered by app protection policies, not by session control alone.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Governance Policies and Controls
Key term
Mobile application management
Mobile application management (MAM) is the practice of controlling and securing corporate apps and their data on employee-owned or company-provided mobile devices without managing the entire device.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.