Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A multinational company uses Microsoft 365 and wants to ensure that data stored in SharePoint Online is only accessible from specific geographic regions. The company has offices in the US, EU, and Asia. You need to implement a solution that restricts access based on the user's physical location. Which feature should you configure?

⚠ Common exam trap

MS-900 often tests the confusion between data residency (where data is stored) and access restrictions based on location; candidates might pick Data Residency thinking it controls access, but it only controls storage location.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access policies in Microsoft Entra ID

Conditional Access policies in Microsoft Entra ID can restrict access based on the user's physical location by using named locations or IP ranges. This allows the company to enforce that SharePoint Online data is only accessible from specific geographic regions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data Residency in Microsoft Purview

    Why it's wrong here

    Data Residency in Microsoft Purview governs where tenant data is stored at rest, not who may reach it from which location; conditional access with named locations enforces the geographic access restriction the scenario requires. It is tempting because residency addresses regional data-storage compliance, which would be correct if the requirement were keeping data within the EU.

  • ✓

    Conditional Access policies in Microsoft Entra ID

    Why this is correct

    Conditional Access policies in Microsoft Entra ID evaluate named locations and sign-in conditions, then block or permit access to SharePoint Online accordingly. This enforces geographic restriction at authentication time, which SharePoint site-level permissions alone cannot achieve.

  • ✗

    Geofencing in Microsoft Intune

    Why it's wrong here

    Intune geofencing applies to managed devices and compliance, not to browser sessions accessing SharePoint Online, so unmanaged or non-compliant clients bypass it. Conditional Access in Microsoft Entra ID enforces location at authentication, which is the correct control for region-restricted SharePoint access.

  • ✗

    Location-Based Policies in SharePoint Admin Center

    Why it's wrong here

    SharePoint Admin Center location-based policies control access from network locations defined by IP ranges, not a user's physical geography, so travelling users on foreign networks are not reliably restricted. Microsoft Entra ID Conditional Access with named locations is the mechanism for geography-based access control.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.