Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

An organization has users who frequently collaborate on documents across departments. They want to ensure that when a document is shared with external partners, the external users must authenticate using Microsoft Entra ID credentials and cannot download or print the document. Which combination of Microsoft 365 features should they use?

⚠ Common exam trap

It's easy for candidates to confuse SharePoint external sharing settings (which control access) with Microsoft Purview Information Protection (which controls usage rights), and mistakenly think that simply restricting sharing to 'Specific people' alone prevents download/print, or that Sensitivity Labels alone enforce authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SharePoint external sharing with 'Specific people' and Microsoft Purview Information Protection with 'View Only' permission

SharePoint 'Specific people' external sharing restricts access to explicitly invited users who must authenticate with Microsoft Entra ID credentials, while Microsoft Purview Information Protection's 'View Only' permission prevents downloading, printing, and copying of the document. This combination meets both requirements: enforced authentication and restricted document actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Teams guest access and Microsoft Defender for Cloud Apps session policies

    Why it's wrong here

    Microsoft Teams guest access alone does not enforce view-only permissions on files because it relies on the underlying SharePoint site permissions. To restrict download or print activities, you would need to pair it with Microsoft Defender for Cloud Apps session policies, which conditionally control user actions based on app and session conditions. This combination is possible but adds complexity, and Teams guest access does not inherently differentiate between view and download permissions for guests, making it an incomplete solution.

  • ✗

    OneDrive sharing settings with 'Anyone' links and Microsoft Purview Data Loss Prevention

    Why it's wrong here

    OneDrive sharing settings that generate 'Anyone' links grant universal, unauthenticated access to anyone who has the link, so you cannot control who views or prints the document. Microsoft Purview Data Loss Prevention policies are designed to detect and block the sharing of sensitive information by scanning content and applying action rules, but they do not provide fine-grained permission settings like 'View Only' restriction on a per-user basis. Therefore, this combination fails to meet the requirement because the link type lacks authentication and DLP does not enforce persistent view-only restrictions.

  • ✓

    SharePoint external sharing with 'Specific people' and Microsoft Purview Information Protection with 'View Only' permission

    Why this is correct

    SharePoint external sharing configured with 'Specific people' requires each external user to authenticate with a Microsoft account or organizational account before accessing content, ensuring that access is traceable and intended recipients are verified. When combined with Microsoft Purview Information Protection's 'View Only' permission, the sensitivity label enforces restrictive permissions that prevent download, print, or modification of the document, even after it is accessed. This pairing directly satisfies the need to restrict download and print for external collaborators while maintaining controlled, authenticated access.

  • ✗

    SharePoint anonymous sharing links and Microsoft Purview Sensitivity Labels

    Why it's wrong here

    SharePoint anonymous sharing links allow anyone possessing the link to access the resource without signing in, which means there is no identity to assign granular permissions to and no way to enforce user-specific restrictions. While Microsoft Purview Sensitivity Labels can apply encryption and usage restrictions, using them with anonymous links is ineffective because the label cannot map permissions to unauthenticated users. The correct approach requires a sharing mechanism that establishes user identity first, which this option lacks.

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.