MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A help desk lead is documenting the correct Microsoft 365 approach to require users to approve sign-ins with a mobile app after entering a password. Microsoft security, identity, or compliance capability should it use?
⚠ Common exam trap
A common mix-up: candidates confuse productivity tools (Planner, Forms, Stream) with security capabilities, mistakenly thinking any Microsoft 365 app can enforce authentication policies, when only identity and access management services like MFA in Microsoft Entra ID can do so.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multifactor authentication (MFA)
Multifactor authentication (MFA) is the correct capability because it requires users to provide a second form of verification—such as approving a sign-in via the Microsoft Authenticator mobile app—after entering their password. This aligns with the security best practice of 'something you know' (password) plus 'something you have' (mobile device approval), which is a core MFA scenario in Microsoft Entra ID (formerly Azure AD).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Planner
Why it's wrong here
Microsoft Planner is a task and project management tool within Microsoft 365, designed to organize work into plans and assignments. It does not offer any authentication or conditional access controls, nor does it enforce security policies like multi-factor authentication. Therefore, any requirement for an additional verification factor during sign-in cannot be satisfied by Planner, as it operates at the application layer without interacting with identity security.
- ✓
Multifactor authentication (MFA)
Why this is correct
Multifactor authentication (MFA) is a core identity security feature in Microsoft 365 that requires a user to provide at least two verification methods, such as a password plus a code from an authenticator app or a phone call. This significantly reduces the risk of account compromise because a stolen password alone is insufficient to gain access. MFA is enforced at the identity layer via Microsoft Entra ID, and can be applied globally or through Conditional Access policies, making it the correct capability when documenting a security control for the help desk lead.
- ✗
Microsoft Forms
Why it's wrong here
Microsoft Forms is an online survey and quiz creation tool that allows users to collect responses via forms or polls. It does not provide any identity verification, sign-in security, or access control mechanisms; anyone with the link can respond unless specific settings are applied, and those settings still do not enforce MFA. Consequently, Forms cannot fulfill a security or compliance requirement for multi-factor authentication, as it is purely a data-collection service with no authentication authority.
- ✗
Microsoft Stream
Why it's wrong here
Microsoft Stream is a video hosting and sharing service where organizations upload, manage, and stream video content. It focuses on media management and playback permissions, but it does not implement or enforce security verifications like MFA; access to Stream is governed by the underlying Microsoft Entra ID authentication, not by Stream itself. Thus, Stream is irrelevant to a help desk requirement for stronger sign-in security, because it cannot independently add a second authentication factor or enforce conditional access policies.
Go deeper
Related to this question
Learn chapter
Identity Governance and Entitlement Management
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.