Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A security administrator needs to ensure that all guest users who access Microsoft Teams are required to accept a terms of use agreement before accessing any company resources. Which Microsoft 365 identity protection feature should they configure?

⚠ Common exam trap

It's easy for candidates to confuse the general concept of 'Conditional Access' (which is the policy engine) with the specific grant control 'Terms of Use' that must be configured within it, leading candidates to pick Option A instead of C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Terms of Use in Microsoft Entra ID

Microsoft Entra ID Terms of Use is the specific feature designed to present a terms-of-use agreement to users before they can access resources. When combined with a Conditional Access policy that targets guest users and requires acceptance of the terms, it ensures that guests must accept the agreement before accessing Microsoft Teams or any other company resource.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conditional Access policy with session control

    Why it's wrong here

    A Conditional Access session control, such as sign-in frequency or session persistence, governs what happens after a user successfully signs in—for example, how long they can remain signed in or whether their session is restricted to specific apps. It does not include a built-in terms-of-use acceptance mechanism, and requiring users to accept an agreement before accessing Teams cannot be implemented with a session control. You would need a Conditional Access grant control that references a Microsoft Entra ID Terms of Use agreement, not a session control.

  • ✗

    Microsoft Entra ID Identity Protection

    Why it's wrong here

    Microsoft Entra ID Identity Protection focuses on automating the detection and remediation of identity-based risks, such as leaked credentials, impossible travel, or anomalous behavior, and it can trigger responses like requiring MFA, blocking sign-in, or requesting a password change. It does not provide a workflow for end users to accept organizational policies like terms of use, nor does it record a user's consent to an agreement. While risk-based policies complement access controls, they do not replace the need for an explicit, auditable terms-of-use acceptance before a guest user enters Teams.

  • ✓

    Terms of Use in Microsoft Entra ID

    Why this is correct

    Terms of Use in Microsoft Entra ID is the correct mechanism: you can create a PDF-based agreement, assign it to guest users (or groups containing guests) through a Conditional Access policy, and the user must accept it before accessing the target application, including Microsoft Teams. This acceptance is written to Microsoft Entra ID audit logs, and the feature supports versioned agreements with optional periodic re-acceptance, providing a compliant, auditable way to secure guest access. Unlike the other options, this is the only one that directly enforces and tracks consent to your terms.

  • ✗

    Privileged Identity Management

    Why it's wrong here

    Privileged Identity Management (PIM) is designed for just-in-time activation of administrative roles such as Global Administrator or Exchange Administrator, with time-bound assignments, approvals, and audit history for elevated role usage. PIM does not apply to standard guest users who are simply accessing Teams; its entire workflow is tied to privileged-role activation, not to a general terms-of-use acceptance flow. Consequently, PIM would neither enforce nor track a guest user's agreement to your terms of use, and it is not a substitute for a dedicated consent mechanism.

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.