MS-900 Describe Microsoft 365 apps and services Practice Question
Exhibit
Refer to the exhibit.
```xml
<Policy Id="Contoso-ConditionalAccess">
<Conditions>
<Users>
<Include>
<AllUsers></AllUsers>
</Include>
</Users>
<Applications>
<Include>
<AppId>00000003-0000-0ff1-ce00-000000000000</AppId>
</Include>
</Applications>
</Conditions>
<GrantControls>
<RequireMFA>true</RequireMFA>
</GrantControls>
</Policy>
```Refer to the exhibit. An administrator creates a Conditional Access policy in Microsoft Entra ID. The AppId 00000003-0000-0ff1-ce00-000000000000 corresponds to Microsoft Graph. The policy requires MFA for all users accessing Microsoft Graph. However, users report that they are not prompted for MFA when using Microsoft Teams. What is the most likely reason?
⚠ Common exam trap
MS-900 often tests the misconception that Microsoft Graph is a universal app ID that covers all Microsoft 365 services, when in fact each service has its own app ID and must be targeted separately.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy applies only to Microsoft Graph, not to the Teams service itself.
The Conditional Access policy targets the Microsoft Graph app ID (00000003-0000-0ff1-ce00-000000000000), which is used for programmatic access to Microsoft Graph APIs, not for the Microsoft Teams client itself. Teams uses its own service principals and app IDs for authentication, so the policy does not apply to Teams sign-ins, and users are not prompted for MFA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The policy applies only to Microsoft Graph, not to the Teams service itself.
Why this is correct
Conditional Access targets the resource AppId in the token request. Teams requests its own service principal, not Microsoft Graph, so a policy scoped solely to the Graph AppId never evaluates during Teams sign-in, leaving users unprompted for MFA.
- ✗
The policy is not enabled.
Why it's wrong here
An enabled policy targeting only the Microsoft Graph AppId never evaluates Teams sign-ins, because Teams requests its own resource tokens; the policy must target the Teams client app or Office 365. Disabled policies are tempting to blame, but the stem states the policy requires MFA, implying it is switched on.
- ✗
The policy should include the app ID for Office 365 Exchange Online.
Why it's wrong here
Exchange Online is a different resource AppId; Teams sign-ins request a Teams service token, so adding Exchange Online still leaves Teams unscoped. Including Exchange Online is tempting because Teams relies on it for calendar and mail, but token acquisition for those services is separate from the Teams client sign-in.
- ✗
The GrantControls should be set to RequireMFA for all resources.
Why it's wrong here
GrantControls already require MFA; the failure is scope, since the policy targets the Microsoft Graph AppId rather than the Teams resource. Setting RequireMFA across all resources is tempting as a blanket fix, but that is a grant control, not an app-targeting mechanism, so it cannot enrol Teams.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Admin APIs and Graph API Basics
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.