MS-900 Describe Microsoft 365 apps and services Practice Question
An organization needs to securely store and manage user identities for Microsoft 365. Which Microsoft service should they use?
⚠ Common exam trap
Many exam-takers confuse Microsoft Purview (data compliance) or Defender for Cloud Apps (security monitoring) with identity management, but only Microsoft Entra ID provides the core directory service for storing and authenticating user identities in Microsoft 365.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID
Microsoft Entra ID (formerly Azure AD) is the correct choice because it is Microsoft's cloud-based identity and access management service, specifically designed to store and manage user identities for Microsoft 365. It provides authentication, single sign-on (SSO), and conditional access policies, ensuring secure access to Microsoft 365 resources. Other options focus on data protection, security monitoring, or device management, not identity storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID
Why this is correct
Microsoft Entra ID is the cloud identity provider that authenticates users and issues tokens for Microsoft 365 services, enforcing conditional access and multifactor authentication. It satisfies the requirement to securely store and manage user identities, unlike Exchange Online or SharePoint Online, which consume identities rather than host them.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview governs data compliance, classification and risk, holding no identity store or authentication service. It is tempting because it is a core Microsoft 365 security service, so it appears identity-adjacent. Microsoft Entra ID is the directory that stores and manages user identities and sign-in.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Defender for Cloud Apps is a cloud access security broker providing shadow-IT discovery, session control and anomaly detection, not an identity store. It is tempting because it consumes identity signals for threat detection, but it cannot hold or manage user accounts; Microsoft Entra ID performs that directory role.
- ✗
Microsoft Intune
Why it's wrong here
Intune performs mobile device management and endpoint configuration compliance, not identity storage. It is tempting because Intune does integrate with identity for conditional access device signals, but it holds no user credential repository; Microsoft Entra ID is the directory that stores and manages those identities.
Go deeper
Related to this question
Learn chapter
Microsoft To Do and Task Management
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.