MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A company wants to ensure that only IT administrators can install browser extensions in Microsoft Edge. Which Microsoft 365 security feature should be used?
⚠ Common exam trap
It's easy for candidates to confuse Conditional Access (which controls access to resources) with device management policies (which control software behavior on the device), leading them to incorrectly select Conditional Access instead of Intune.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Intune
Microsoft Intune is the correct choice because it provides mobile device management (MDM) and mobile application management (MAM) capabilities that allow administrators to configure Microsoft Edge settings via configuration profiles. Specifically, Intune can enforce the 'Installation of browser extensions' policy to restrict extension installation to IT administrators only, using the Administrative Templates for Edge within the Settings Catalog.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conditional Access
Why it's wrong here
Conditional Access is an Entra ID policy engine that evaluates signals such as user, location, device compliance, and risk to allow or block access to cloud apps. It can require a device to be compliant, but it does not push device configuration profiles or manage endpoint settings. Restricting browser extension installation is an on-device policy that only an MDM/CDM tool like Intune can enforce, so Conditional Access alone cannot achieve this goal.
- ✓
Microsoft Intune
Why this is correct
Microsoft Intune is a cloud-based endpoint management service (MDM/MAM) that can deploy device configuration profiles to Windows, macOS, iOS, and Android devices. For instance, an Intune configuration profile can apply a Policy CSP to set the "Configure ExtensionSettings" policy for Microsoft Edge, blocking extension installations or allowlisting only approved extensions. Intune also integrates with Entra ID so that Conditional Access can require device compliance, but the actual endpoint restriction is enforced by Intune's policy delivery.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility into cloud app usage, data exfiltration protection, and conditional access app control via reverse proxy. It does not manage device operating systems or browser extensions; that requires a device management agent or MDM profile. Its policies act on cloud app sessions in real time, not on local endpoint configuration, so it cannot restrict who installs browser extensions on a machine.
- ✗
Microsoft Entra ID Identity Protection
Why it's wrong here
Microsoft Entra ID Identity Protection analyzes identity risk indicators such as leaked credentials, impossible travel, and anonymous IP addresses to trigger automated remediation like requiring MFA or blocking sign-in. It operates purely on authentication events and identity risk signals, not on device configuration or installed software. Browser extension installation is an endpoint setting, which lies outside the scope of an identity-driven risk engine, making it an incorrect tool for this requirement.
Go deeper
Related to this question
Learn chapter
Power Apps: Low-Code Application Development
Key term
App protection policy
An app protection policy is a set of rules that controls how data is handled and secured within mobile applications, ensuring corporate information stays safe even on personal devices.
Key term
Mobile application management
Mobile application management (MAM) is the practice of controlling and securing corporate apps and their data on employee-owned or company-provided mobile devices without managing the entire device.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.