MS-900 Describe Microsoft 365 apps and services Practice Question
Contoso Ltd. is a medium-sized company with 500 employees using Microsoft 365 E5. They have a mixed environment: 300 Windows 10 devices are managed by Microsoft Intune, and 200 are unmanaged but Microsoft Entra ID joined. The company uses Microsoft Teams for collaboration and SharePoint Online for document storage. The security team wants to implement the following: restrict access to company data from unmanaged devices, require multi-factor authentication (MFA) for all external users accessing SharePoint, and ensure that sensitive documents labeled 'Highly Confidential' are automatically encrypted when shared via email. Currently, the company has no conditional access policies, no MFA enforced, and no data classification policies. The administrator needs to design a solution using Microsoft 365 built-in capabilities without purchasing additional licenses. What should the administrator do?
⚠ Common exam trap
Candidates often assume MFA must be enforced for all users or that DLP policies can encrypt emails, but the scenario specifically requires MFA only for external users and encryption via sensitivity labels, not DLP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a conditional access policy to grant access from compliant devices, require MFA for external users, and configure a sensitivity label with auto-labeling for 'Highly Confidential' documents.
It uses Conditional Access policies to require compliant devices for access (addressing unmanaged devices), requires MFA specifically for external users (not all users, aligning with the requirement), and uses a sensitivity label with auto-labeling to automatically encrypt 'Highly Confidential' documents when shared via email. This leverages built-in Microsoft 365 capabilities without additional licenses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure SharePoint to block access from unmanaged devices, enable MFA for all users, and use Microsoft Purview Data Loss Prevention (DLP) to encrypt sensitive emails.
Why it's wrong here
Blocking all unmanaged devices at the SharePoint level is an overly restrictive approach that prevents employees using personally-owned devices from accessing resources even when those devices could be made compliant through Intune. MFA for all users is excessive because the stated requirement targets external users, not internal staff. Additionally, Microsoft Purview DLP is a monitoring and policy-enforcement tool, not an encryption engine; sensitive email encryption requires sensitivity labels or Office 365 Message Encryption, so this combination fails to meet the stated requirements.
- ✗
Use Intune app protection policies to restrict data access, enable MFA for SharePoint, and use Microsoft Purview auto-labeling for encryption.
Why it's wrong here
Intune app protection policies govern how data is handled inside mobile apps—such as preventing cut/copy/paste or requiring an app PIN—but they do not evaluate device compliance or manage access from desktop browsers, so they cannot enforce the compliant device requirement. Requiring MFA for SharePoint specifically is misaligned with the condition that only external users need MFA, and it would prompt internal users unnecessarily. Auto-labeling in Purview classifies documents but does not itself encrypt; encryption is a separate action applied by sensitivity labels, so merely enabling auto-labeling without configuring label encryption does not secure the files.
- ✗
Create a conditional access policy to require MFA for all users, use Intune compliance policies to mark devices as compliant, and create a sensitivity label to encrypt documents.
Why it's wrong here
This plan correctly includes conditional access and a sensitivity label, but it fails to restrict access to compliant devices; instead, it imposes MFA on all users, which is broader than required and disrupts internal productivity. Intune compliance policies only establish device health criteria—like requiring encryption or a passcode—and do not by themselves block non-compliant devices; a conditional access policy must reference that compliance status to grant access. Creating a sensitivity label without auto-labeling for 'Highly Confidential' documents leaves protection dependent on manual user selection, rather than ensuring automatic encryption of sensitive content.
- ✓
Create a conditional access policy to grant access from compliant devices, require MFA for external users, and configure a sensitivity label with auto-labeling for 'Highly Confidential' documents.
Why this is correct
This solution precisely maps each requirement to the correct Microsoft 365 capability: a Conditional Access policy can require both device compliance (based on Intune compliance policies) and MFA for external users, ensuring only approved, managed devices gain access while external identities are verified. The sensitivity label configured with auto-labeling for 'Highly Confidential' content automatically applies encryption and permissions when documents match the label's pattern, eliminating user error. By combining these two policy layers, the organization enforces least-privilege access and protects sensitive data at the file level, which fully addresses the stated scenario.
Go deeper
Related to this question
Learn chapter
Data Loss Prevention (DLP) in Microsoft 365
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.