MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Contoso has Microsoft 365 E3 and a hybrid identity environment with Microsoft Entra Connect. Security policy requires that when a user's on-premises Active Directory account is disabled, their Microsoft 365 access must stop within minutes without an administrator manually touching the cloud account. Which Microsoft 365 capability should you rely on to meet this requirement?
⚠ Common exam trap
The trap here is assuming that disabling an account in on-premises Active Directory immediately blocks every Microsoft 365 service, when the effect actually depends on the directory synchronization cycle.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Connect sync of the on-premises accountEnabled attribute
The requirement is that disabling the authoritative on-premises account must propagate to the cloud quickly. Microsoft Entra Connect continuously synchronizes the accountEnabled state from Active Directory to Microsoft Entra ID, so the next delta sync blocks cloud sign-in without administrator intervention. Controls such as risk policies, device compliance, or client-side Group Policy evaluate other signals and never look at the source AD account status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Protection risk-based sign-in policies
Why it's wrong here
Entra ID Protection evaluates sign-in and user risk signals such as leaked credentials or anomalous travel, not the enabled or disabled state of an on-premises Active Directory object. It cannot detect that an administrator disabled an AD account and will not terminate the user's existing sessions, so it does not satisfy the requirement to cut off access when the on-premises account is disabled.
- ✓
Microsoft Entra Connect sync of the on-premises accountEnabled attribute
Why this is correct
Microsoft Entra Connect synchronizes the on-premises userAccountControl/accountEnabled state to Microsoft Entra ID, so disabling the on-premises account marks the cloud account as blocked for sign-in on the next sync cycle. Because default sync runs every 30 minutes, access stops within minutes rather than requiring manual cloud changes, which is exactly what the policy demands.
- ✗
Microsoft 365 Apps sign-in restrictions configured by using Group Policy
Why it's wrong here
Group Policy settings for Microsoft 365 Apps control how the desktop applications authenticate and cache credentials; they do not revoke a user's ability to sign in to Exchange Online, SharePoint Online, or Teams. Even if the desktop apps were restricted, browser and mobile access would remain, so the account would not actually be cut off within minutes.
- ✗
Conditional Access policies requiring compliant devices
Why it's wrong here
Device compliance Conditional Access gates access based on Intune device state, not on whether the on-premises directory account is enabled. A disabled employee using a compliant laptop would still be granted access, so this control answers a different question and leaves the terminated user able to sign in until someone manually blocks the cloud account.
Go deeper
Related to this question
Learn chapter
Anti-Phishing Policies in Microsoft 365
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.