Courseiva
Question 68 of 217
Describe cloud conceptsmediumDrag & DropObjective-mapped

MS-900 Describe cloud concepts Practice Question

Drag and drop the steps to configure a Microsoft 365 group expiration policy in the Azure AD admin center into the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Sign in to the Azure AD admin center, then navigate to Groups > Expiration, then configure the expiration policy settings, then save the policy.

To configure a Microsoft 365 group expiration policy, you must first sign in to the Azure AD admin center, then navigate to Groups > Expiration, configure the desired expiration settings, and finally save the policy. This sequence ensures proper access and application of the configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Sign in to the Azure AD admin center, then navigate to Groups > Expiration, then configure the expiration policy settings, then save the policy.

    Why this is correct

    The proper sequence begins with signing in to the Azure AD admin center (https://aad.portal.azure.com) using an account with sufficient privileges, such as a Global Administrator or User Administrator. After authentication, you navigate to the Groups blade and select the Expiration section, which holds the Microsoft 365 group expiration policy settings. You then configure parameters like group lifetime and notification contacts, and finally save the policy to persist and enforce those settings. This order is required because the expiration settings are only available within that specific blade, and saving without configuring would not apply any intended changes.

  • Sign in to the Azure AD admin center, then configure the expiration policy settings, then navigate to Groups > Expiration, then save the policy.

    Why it's wrong here

    This option is incorrect because the expiration policy configuration controls are not accessible immediately after signing in; they are only rendered when you first navigate to Groups > Expiration. The Azure AD admin center's home page does not display expiration settings, and attempting to configure a policy that hasn't been selected would be impossible in the UI. The policy blade must be open before any fields or toggles are available. Without this navigation step, there is nothing to configure, so the sequence is invalid.

  • Sign in to the Azure AD admin center, then navigate to Groups > Expiration, then save the policy, then configure the expiration policy settings.

    Why it's wrong here

    This option fails because you cannot save a policy before configuring its settings; the Save button only persists the current state of the blade, which would be the default expiration settings or your previously unmodified values. In the Azure AD admin center, the Expiration blade loads with default values (e.g., 365 days, no notifications) and saving immediately would enforce those defaults, not any intended custom policy. You must first adjust the expiration period, email notifications, and who receives them, then save to commit your changes. Saving out of order makes the configuration step irrelevant.

  • Navigate to Groups > Expiration, then sign in to the Azure AD admin center, then configure the expiration policy settings, then save the policy.

    Why it's wrong here

    This option is invalid because navigating to Groups > Expiration requires an authenticated session in the Azure AD admin center; without signing in first, the portal will redirect you to the sign-in page and the Expiration blade will not load. Azure AD admin center enforces conditional access and role-based authentication, so you cannot access any management blade, including expiration policies, anonymously. Even if you had a direct URL, the portal's security layer intercepts the request and demands credentials. Therefore, the sign-in must occur before any navigation or configuration steps.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.