MS-900 Describe Microsoft 365 apps and services Practice Question
A user reports that they cannot access their Microsoft 365 email on their mobile device. The user can access Outlook on the web. Which Microsoft 365 app should the administrator check to verify the user's mobile device is compliant?
⚠ Common exam trap
A common mix-up: candidates confuse Microsoft Entra ID (which handles conditional access policies) with Intune (which actually performs the device compliance check and reports the status to Entra ID).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Intune
Microsoft Intune is the correct answer because it is the mobile device management (MDM) and mobile application management (MAM) component within Microsoft 365. When a user cannot access email on a mobile device but can via Outlook on the web, the issue is likely a device compliance policy blocking access. Intune enforces conditional access policies by checking device compliance (e.g., encryption, jailbreak status, minimum OS version) before allowing Exchange Online connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Intune
Why this is correct
Microsoft Intune is the cloud-based MDM/MAM service that creates and enforces device compliance policies, such as requiring BitLocker encryption, a minimum OS build, or a passcode. In this scenario, the user’s device is likely non-compliant, so Intune’s compliance state is consumed by Conditional Access in Entra ID, which blocks the user’s session to Microsoft 365 Exchange Online. Thus Intune is the component that determines whether the device meets access requirements.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 (MDO) protects against email-borne threats like phishing, malware, and spoofing in Exchange Online, and it offers Safe Attachments and Safe Links sandboxing. It does not manage device health, enforce mobile device compliance, or make endpoint architecture decisions for Microsoft 365 access. If a user cannot access their tenant, MDO would not be the cause because access denials from non-compliant devices are outside its scope.
- ✗
Microsoft Entra ID
Why it's wrong here
Microsoft Entra ID is the identity and authentication service that validates user credentials and issues tokens for Microsoft 365, but by default it does not know whether a device is compliant unless Intune supplies that signal. Even when a user’s password is correct and the session is authenticated, Conditional Access policies can still require a compliant device, and the compliance result originates from Intune, not from Entra ID’s directory service. So Entra ID alone cannot explain or fix the device-based block.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview covers data security and compliance scenarios — retention labels, eDiscovery, sensitivity labels, data loss prevention, and auditing — rather than device lifecycle management or access control. A non-compliant device blocking a user’s connection to Microsoft 365 is a device management state, not a data governance classification, so Purview policies would have no role in permitting or denying the session. Thus selecting Purview would target the wrong administrative console for this issue.
Go deeper
Related to this question
Learn chapter
Records Management in Microsoft 365
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.