MS-900 Describe Microsoft 365 apps and services Practice Question
Exhibit
{
"displayName": "Block high-risk sign-ins",
"conditions": {
"signInRiskLevel": "high",
"applications": ["Office365"]
},
"grantControls": {
"builtInControls": ["block"]
}
}Refer to the exhibit. You are reviewing a Conditional Access policy in Microsoft Entra ID. What will this policy do?
⚠ Common exam trap
Many candidates confuse 'Block access' with 'Require MFA' or assume the policy applies to all cloud apps, when the exhibit clearly shows the scope is limited to Office 365 apps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Blocks access to Office 365 apps when the sign-in risk is high
The exhibit shows a Conditional Access policy configured with the condition 'Sign-in risk: High' and the control 'Block access'. This combination means that when Microsoft Entra ID detects a high-risk sign-in (e.g., from an anonymous IP address or compromised credentials), access to the targeted cloud apps is denied. The policy specifically targets Office 365 apps (as indicated in the 'Cloud apps or actions' assignment), so it blocks access to those apps when the sign-in risk is high.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allows access but logs the sign-in risk
Why it's wrong here
The Conditional Access policy does not allow access under any circumstances when the sign-on risk is high; its grant control is set to 'Block access', which terminates the authentication session entirely. Therefore, there is no session to log as allowed, and sign-in risk events are recorded separately by Microsoft Entra ID Protection regardless of the policy outcome. Access is denied, not granted.
- ✗
Requires multi-factor authentication for high-risk sign-ins
Why it's wrong here
A grant control of 'Require multi-factor authentication' would challenge the user to complete MFA before access is permitted, but this policy's grant control is 'Block access'. Blocking is an explicit denial—no MFA challenge is issued because the sign-in is rejected based on the configured risk condition. You cannot combine block and MFA as grant controls in the same Conditional Access policy.
- ✗
Blocks access to all cloud apps when sign-in risk is high
Why it's wrong here
This policy's cloud apps assignment is specifically set to 'Office 365', which is a group of apps that includes Exchange Online, SharePoint Online, Teams, and other Office 365 services. It does not target 'All cloud apps', so it will not block access to non-Office 365 resources such as Microsoft Entra ID, Dynamics 365, or third-party SaaS apps. The scope is limited to Office 365 apps only, not the entire catalog of cloud apps.
- ✓
Blocks access to Office 365 apps when the sign-in risk is high
Why this is correct
The policy correctly matches the exhibit: assigned to the 'Office 365' cloud app, condition set to 'High' sign-in risk, and grant control configured to 'Block access'. When a sign-in for any Office 365 app (like OneDrive, Exchange, etc.) is evaluated as high risk, Microsoft Entra ID blocks the authentication and prevents the user from gaining access. This is an effective way to protect against compromised credentials without locking out legitimate low-risk sign-ins.
Go deeper
Related to this question
Learn chapter
MFA and Conditional Access in M365
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.