MS-900 Describe Microsoft 365 apps and services Practice Question
A user reports that they cannot access their work email on their mobile device. The admin confirms the user has an Exchange Online license. What is the most likely cause?
⚠ Common exam trap
Candidates often assume a valid license (Exchange Online) guarantees access, but Microsoft 365 security features like Conditional Access can override licensing and block access based on policy requirements, especially on mobile devices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Conditional Access policy requires app protection policies
Conditional Access policies can require app protection policies (e.g., Intune MAM) to enforce data security on mobile devices. If the user's device does not have the required app protection policies applied, access to Exchange Online via mobile apps (including Outlook) will be blocked, even though the user has a valid Exchange Online license. This is a common scenario where licensing alone does not guarantee access when additional security controls are in place.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user is using the Outlook mobile app
Why it's wrong here
Using the Outlook mobile app is not a cause for access failure; Outlook for iOS and Android is Microsoft's recommended mobile client and is specifically designed to work with modern authentication and Intune policy enforcement. It supports Conditional Access through the Microsoft Authenticator and Intune SDK, so it would normally be the compliant way to access work email. Therefore, the app itself is not the reason access is denied.
- ✗
The user is trying to access Outlook on the web
Why it's wrong here
Accessing email through Outlook on the web (OWA) from a mobile browser is a fully supported and functional method, not a triggering failure. OWA uses modern authentication and can be subjected to Conditional Access policies, but a browser session is assessed separately from native apps and may still be allowed if it meets policy requirements. Merely trying to use OWA is not a factor that causes the reported access issue.
- ✗
Exchange ActiveSync is disabled for the user
Why it's wrong here
Exchange ActiveSync (EAS) being disabled would block legacy mobile mail clients, but it does not prevent Outlook for iOS/Android or Outlook on the web from working, because those clients use OAuth and REST/Graph APIs. In a Conditional Access scenario, EAS is just one protocol that can be targeted, and an app protection policy requirement is enforced at the client application level rather than disabling EAS. Since the user is unable to access email across the board, EAS being disabled is not the correct explanation.
- ✓
A Conditional Access policy requires app protection policies
Why this is correct
A Conditional Access policy that requires an app protection policy (Intune MAM) is the likely cause because it blocks access to Exchange Online until the Outlook app has received the required policy from Intune. If the user's device does not have the Company Portal or the policy hasn't been applied, Outlook will indicate that the organization requires app protection and deny sign-in. This is a common conditional access control for personal devices to prevent data leakage without full device enrollment.
Go deeper
Related to this question
Learn chapter
Azure Information Protection (AIP) Labels
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
MAM
Mobile Application Management (MAM) is a set of technologies and policies that allow IT administrators to manage and secure corporate applications on mobile devices without managing the entire device.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.