A large enterprise needs to enforce that all documents containing financial data are automatically classified and encrypted when shared externally. Which combination of Microsoft 365 services should be used?
Microsoft Purview Information Protection provides sensitivity labels that can classify and, when configured, encrypt documents using rights-management templates, while Microsoft Defender for Cloud Apps acts as a cloud access security broker to enforce policies on those labels—such as blocking download or applying visual markings. Together, they create a complete control plane that can conditionally require a label, apply automatic classification, and govern sharing behavior for documents in SharePoint, OneDrive, or third-party cloud apps. This directly enforces the enterprise requirement to protect all documents containing sensitive data.
Why this answer
Microsoft Purview Information Protection provides the classification and labeling capabilities to automatically identify documents containing financial data, while Microsoft Defender for Cloud Apps enables policy-based encryption and protection controls when those documents are shared externally. Together, they enforce data loss prevention (DLP) by applying sensitivity labels that trigger encryption upon external sharing, meeting the enterprise requirement.
Exam trap
The trap here is that candidates confuse security monitoring tools (Sentinel, Defender XDR) with data classification and encryption tools, or they mistakenly think device management (Intune) or identity (Entra ID) can enforce content-level encryption on documents shared externally.
How to eliminate wrong answers
Option A is wrong because Microsoft Forms is a survey tool and Microsoft Stream is a video platform; neither provides document classification, encryption, or external sharing controls. Option B is wrong because Microsoft Sentinel is a SIEM/SOAR for security incident detection and Microsoft Defender XDR is for endpoint, email, and identity threat protection; they do not classify or encrypt documents based on content. Option D is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) solution, and Microsoft Entra ID is an identity and access management service; neither directly classifies or encrypts document content for external sharing.