MS-900 Describe Microsoft 365 apps and services Practice Question
Exhibit
{
"policy": {
"name": "Block External Sharing",
"type": "SharePoint Online Sharing Policy",
"sharingCapability": "Disabled",
"allowExternalSharing": false,
"externalUserExpirationInDays": 30
}
}Refer to the exhibit. A SharePoint admin is reviewing a policy JSON snippet. Which statement accurately describes the effect of this policy?
⚠ Common exam trap
The trap here is that candidates see the 'expirationTime' of 30 days and assume external sharing is allowed with an expiration, but they overlook that the 'sharingCapability' is set to 'Disabled', which nullifies any expiration settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
External sharing is completely disabled.
The policy JSON snippet sets the 'sharingCapability' to 'Disabled', which completely disables external sharing for the SharePoint environment. This means no external users can be invited, and any existing external sharing links will cease to function. The 'expirationTime' value of 30 days is irrelevant because sharing is disabled entirely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
External sharing is allowed only for existing guests who expire in 30 days.
Why it's wrong here
This option misreads the policy. With 'sharingCapability' set to Disabled and 'allowExternalSharing' set to false, SharePoint blocks all external user invitations and external link sharing. An expiration period for guests is irrelevant because the overall sharing capability is disabled, so even existing guests cannot be extended or added, and their access would be revoked.
- ✗
External sharing is allowed but guests expire after 30 days.
Why it's wrong here
This option incorrectly assumes a guest expiration policy is configured. In the SharePoint admin center, external sharing expansion is governed by the sharing capability setting, not by a timeout. The value 'Disabled' means external sharing is entirely off, and any guest expiration policy would only apply if sharing were allowed, which is false here.
- ✗
External sharing is allowed but only for users in the same tenant.
Why it's wrong here
This option confuses internal collaboration with external sharing. Users in the same tenant are internal users, not external guests. The policy's Disabled setting prevents sharing with any user outside the organization, but internal sharing remains unaffected, so saying external sharing is allowed for same-tenant users is a contradiction and does not describe this policy.
- ✓
External sharing is completely disabled.
Why this is correct
This is correct. The policy sets sharingCapability to Disabled and allowExternalSharing to false, which completely turns off external sharing for the tenant or site. No new guest invites can be sent, no external links can be created, and existing external access will be blocked, while internal sharing continues to work normally.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.