MS-900 Describe Microsoft 365 apps and services Practice Question
A global organization uses Microsoft 365 E5 and needs to securely share sensitive documents with external partners. The compliance officer requires that external users can view but not edit, print, or forward the documents, and access must expire after 30 days. Which combination of services should the admin use?
⚠ Common exam trap
Many candidates confuse external sharing controls (like B2B or guest access) with document-level protection, assuming that any external sharing mechanism can enforce granular usage restrictions, but only sensitivity labels with Azure RMS can apply 'View Only' and expiration at the file level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Information Protection with sensitivity labels and SharePoint Online
Microsoft Purview Information Protection with sensitivity labels can enforce 'View Only' permissions that prevent editing, printing, and forwarding, while SharePoint Online allows setting an expiration date for external access via sharing links. Together, they meet the compliance officer's requirements for granular document-level restrictions and time-bound access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SharePoint Online External Sharing and Microsoft Entra B2B
Why it's wrong here
SharePoint Online External Sharing alone controls whether external users can be invited to access a site, and Microsoft Entra B2B supplies the guest identity and authentication lifecycle, but neither mechanism applies or enforces document-level restrictions such as view-only, watermarking, or copy/print blocking. While external sharing can be scoped to specific sites or folders, it does not natively enforce expiration or read-only permissions on the content itself, so a guest with edit permissions could download, print, or forward the document. The combination therefore addresses who can access the site, not how the document may be used after access is granted.
- ✓
Microsoft Purview Information Protection with sensitivity labels and SharePoint Online
Why this is correct
Microsoft Purview Information Protection with sensitivity labels provides the actual protection layer: labels can be configured to apply encryption, set permissions such as View-only, disable printing and copying, and attach expiration dates to the document itself. SharePoint Online then hosts the protected file and enforces these label-based restrictions when the document is opened through Office apps or the web, including for external guests. This combination directly satisfies the requirement to allow viewing only, prevent downloads/prints/forwards, and enforce an automatic access expiration, making it the correct solution.
- ✗
Microsoft Entra B2B collaboration with Conditional Access
Why it's wrong here
Microsoft Entra B2B collaboration with Conditional Access governs the guest user's ability to sign in to Microsoft Entra ID and controls access based on conditions like device compliance, location, or risk during authentication. However, once the guest is authenticated, Conditional Access does not evaluate or enforce permissions on specific documents; it does not know whether a user should be allowed to print, copy, or download a particular file. Even with a compliant device and successful sign-in, the guest could still perform any action the underlying SharePoint/OneDrive permission grants, so this option fails to provide document-level usage restrictions or expiration.
- ✗
Microsoft Teams with guest access and sharing permissions
Why it's wrong here
Microsoft Teams with guest access allows external users to be added to teams and channels, and sharing permissions at the team level control what guests can see or interact with in the team workspace. However, Teams guest access relies on SharePoint Online and OneDrive for file storage, and it does not add an independent document-level protection mechanism. A guest with access to a channel can open files and, depending on the underlying SharePoint permission, can download, print, or forward them; Teams has no built-in way to make a document view-only or automatically expire access to the file itself.
Go deeper
Related to this question
Learn chapter
Azure Information Protection (AIP) Labels
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.