Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

Contoso Ltd. is a medium-sized company with 500 employees using Microsoft 365 E5. They have a mixed environment: 300 Windows 10 devices are managed by Microsoft Intune, and 200 are unmanaged but Microsoft Entra ID joined. The company uses Microsoft Teams for collaboration and SharePoint Online for document storage. The security team wants to implement the following: restrict access to company data from unmanaged devices, require multi-factor authentication (MFA) for all external users accessing SharePoint, and ensure that sensitive documents labeled 'Highly Confidential' are automatically encrypted when shared via email. Currently, the company has no conditional access policies, no MFA enforced, and no data classification policies. The administrator needs to design a solution using Microsoft 365 built-in capabilities without purchasing additional licenses. What should the administrator do?

⚠ Common exam trap

Candidates often assume MFA must be enforced for all users or that DLP policies can encrypt emails, but the scenario specifically requires MFA only for external users and encryption via sensitivity labels, not DLP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a conditional access policy to grant access from compliant devices, require MFA for external users, and configure a sensitivity label with auto-labeling for 'Highly Confidential' documents.

It uses Conditional Access policies to require compliant devices for access (addressing unmanaged devices), requires MFA specifically for external users (not all users, aligning with the requirement), and uses a sensitivity label with auto-labeling to automatically encrypt 'Highly Confidential' documents when shared via email. This leverages built-in Microsoft 365 capabilities without additional licenses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure SharePoint to block access from unmanaged devices, enable MFA for all users, and use Microsoft Purview Data Loss Prevention (DLP) to encrypt sensitive emails.

    Why it's wrong here

    Blocking all unmanaged devices at the SharePoint level is an overly restrictive approach that prevents employees using personally-owned devices from accessing resources even when those devices could be made compliant through Intune. MFA for all users is excessive because the stated requirement targets external users, not internal staff. Additionally, Microsoft Purview DLP is a monitoring and policy-enforcement tool, not an encryption engine; sensitive email encryption requires sensitivity labels or Office 365 Message Encryption, so this combination fails to meet the stated requirements.

  • ✗

    Use Intune app protection policies to restrict data access, enable MFA for SharePoint, and use Microsoft Purview auto-labeling for encryption.

    Why it's wrong here

    Intune app protection policies govern how data is handled inside mobile apps—such as preventing cut/copy/paste or requiring an app PIN—but they do not evaluate device compliance or manage access from desktop browsers, so they cannot enforce the compliant device requirement. Requiring MFA for SharePoint specifically is misaligned with the condition that only external users need MFA, and it would prompt internal users unnecessarily. Auto-labeling in Purview classifies documents but does not itself encrypt; encryption is a separate action applied by sensitivity labels, so merely enabling auto-labeling without configuring label encryption does not secure the files.

  • ✗

    Create a conditional access policy to require MFA for all users, use Intune compliance policies to mark devices as compliant, and create a sensitivity label to encrypt documents.

    Why it's wrong here

    This plan correctly includes conditional access and a sensitivity label, but it fails to restrict access to compliant devices; instead, it imposes MFA on all users, which is broader than required and disrupts internal productivity. Intune compliance policies only establish device health criteria—like requiring encryption or a passcode—and do not by themselves block non-compliant devices; a conditional access policy must reference that compliance status to grant access. Creating a sensitivity label without auto-labeling for 'Highly Confidential' documents leaves protection dependent on manual user selection, rather than ensuring automatic encryption of sensitive content.

  • ✓

    Create a conditional access policy to grant access from compliant devices, require MFA for external users, and configure a sensitivity label with auto-labeling for 'Highly Confidential' documents.

    Why this is correct

    This solution precisely maps each requirement to the correct Microsoft 365 capability: a Conditional Access policy can require both device compliance (based on Intune compliance policies) and MFA for external users, ensuring only approved, managed devices gain access while external identities are verified. The sensitivity label configured with auto-labeling for 'Highly Confidential' content automatically applies encryption and permissions when documents match the label's pattern, eliminating user error. By combining these two policy layers, the organization enforces least-privilege access and protects sensitive data at the file level, which fully addresses the stated scenario.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.