Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A help desk lead is documenting the correct Microsoft 365 approach to allow browser access to SharePoint from unmanaged devices but restrict downloads. Microsoft security, identity, or compliance capability should it use?

⚠ Common exam trap

Many exam-takers confuse Conditional Access with device compliance policies or Intune, but session controls are specifically designed for unmanaged devices where you cannot enforce device-level restrictions, and they operate at the application layer rather than requiring device enrollment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access access/session controls

Conditional Access access/session controls allow administrators to enforce granular restrictions on browser access to SharePoint from unmanaged devices, such as blocking download of sensitive content while still permitting view-only access. This is achieved through session policies that integrate with Microsoft Defender for Cloud Apps (formerly Cloud App Security) to apply real-time controls at the protocol level, without requiring device enrollment or compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conditional Access access/session controls

    Why this is correct

    Conditional Access access/session controls are the correct security mechanism because they enforce organization-defined policies directly at the identity layer of Microsoft 365 and Microsoft Entra ID. Access controls evaluate sign-in signals such as device compliance, user risk, and location to grant or block access, while session controls refine the user experience after authentication—for instance, limiting downloads or forcing reauthentication in cloud apps. Together, they enable a help desk to implement device state–based restrictions such as 'Allow only compliant devices,' which is exactly the documented requirement.

  • ✗

    Microsoft Forms

    Why it's wrong here

    Microsoft Forms is a survey and quiz creation tool used to collect user input via web forms; it has no identity or policy engine to evaluate device compliance, risk, or session context. It might allow restricting who can submit a form, but that is a sharing permission, not a conditional access or session control for the broader Microsoft 365 environment. Therefore, Forms is inappropriate for enforcing device-state–based access restrictions.

  • ✗

    Microsoft Stream

    Why it's wrong here

    Microsoft Stream is a video hosting and sharing service for recording, uploading, and playing organizational videos; its administrative settings control channel permissions and video lifespan, but they do not evaluate authentication signals or device state to conditionally allow or restrict access to apps. Session controls like blocking downloads based on a device's compliance status are not part of Stream's capability set. As a result, Stream fails to meet the security control described by the help desk lead.

  • ✗

    Microsoft Planner

    Why it's wrong here

    Microsoft Planner is a task-management and collaboration application for organizing work, assigning tasks, and tracking project progress within Teams or SharePoint; it does not expose any conditional access policies, session restrictions, or device compliance checks. Planner's sharing and access settings are limited to membership in plans, not dynamic evaluation of user or device context. Thus, Planner is a productivity planner, not a security or compliance control mechanism, making it an incorrect choice here.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.