MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A user reports that they cannot access a SharePoint site that contains sensitive data. The administrator confirms the user is licensed and the site permissions are correct. What should the administrator check next?
⚠ Common exam trap
MS-900 often tests the confusion between Intune compliance policies (which only report device state) and Conditional Access (which actually enforces access decisions) — candidates pick Intune when the question is about blocking access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policies in Microsoft Entra ID
Conditional Access policies in Microsoft Entra ID are evaluated at sign-in and can block access to SharePoint Online based on user, device, location, or risk conditions — even when licensing and site permissions are correct. If the user's device is non-compliant, from an untrusted location, or the user fails an MFA requirement, Conditional Access will deny access to the SharePoint resource, which matches the symptom described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Office 365 Safe Attachments
Why it's wrong here
Safe Attachments is part of Microsoft Defender for Office 365 and focuses on scanning email attachments in a detonation sandbox to detect malicious payloads, primarily for Exchange Online mailboxes. It does not apply to web session requests or evaluate authentication signals for SharePoint Online. Consequently, a user being unable to access a SharePoint site would not be caused by Safe Attachments, as this workload neither grants nor blocks interactive access to SharePoint content.
- ✗
Microsoft Purview retention policies
Why it's wrong here
Microsoft Purview retention policies govern how long content is kept and whether it is ultimately deleted or preserved for compliance, legal, or regulatory reasons. They do not participate in access control decisions at sign-in time and do not conditionally block a user from entering a SharePoint site. A user's access problem would stem from permissions, licensing, or authentication policies rather than from retention rules, since retention rules act asynchronously on stored content.
- ✗
Microsoft Intune device compliance policies
Why it's wrong here
Intune device compliance policies define requirements such as OS version, disk encryption, and jailbreak detection, and they report a device's compliance state to Microsoft Entra ID. However, they do not directly enforce a block on SharePoint; that enforcement occurs only when a Conditional Access policy uses the compliance state as a condition. Therefore, even a non-compliant device may continue to access SharePoint unless a Conditional Access policy explicitly denies it.
- ✓
Conditional Access policies in Microsoft Entra ID
Why this is correct
Conditional Access policies in Microsoft Entra ID are designed to evaluate real-time signals, including user identity, IP location, device health, and sign-in risk, before granting access to cloud applications such as SharePoint Online. If the user falls outside policy requirements — for example, coming from an untrusted IP or not satisfying multi-factor authentication — the policy can block access entirely. The correct troubleshooting step is to inspect the Conditional Access tab in the Entra ID sign-in logs to see which policy was applied and why access was denied.
Go deeper
Related to this question
Learn chapter
External Sharing in SharePoint and OneDrive
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.