Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

Exhibit

{
  "displayName": "Block high-risk sign-ins",
  "conditions": {
    "signInRiskLevel": "high",
    "applications": ["Office365"]
  },
  "grantControls": {
    "builtInControls": ["block"]
  }
}

Refer to the exhibit. You are reviewing a Conditional Access policy in Microsoft Entra ID. What will this policy do?

⚠ Common exam trap

Many candidates confuse 'Block access' with 'Require MFA' or assume the policy applies to all cloud apps, when the exhibit clearly shows the scope is limited to Office 365 apps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Blocks access to Office 365 apps when the sign-in risk is high

The exhibit shows a Conditional Access policy configured with the condition 'Sign-in risk: High' and the control 'Block access'. This combination means that when Microsoft Entra ID detects a high-risk sign-in (e.g., from an anonymous IP address or compromised credentials), access to the targeted cloud apps is denied. The policy specifically targets Office 365 apps (as indicated in the 'Cloud apps or actions' assignment), so it blocks access to those apps when the sign-in risk is high.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allows access but logs the sign-in risk

    Why it's wrong here

    The Conditional Access policy does not allow access under any circumstances when the sign-on risk is high; its grant control is set to 'Block access', which terminates the authentication session entirely. Therefore, there is no session to log as allowed, and sign-in risk events are recorded separately by Microsoft Entra ID Protection regardless of the policy outcome. Access is denied, not granted.

  • ✗

    Requires multi-factor authentication for high-risk sign-ins

    Why it's wrong here

    A grant control of 'Require multi-factor authentication' would challenge the user to complete MFA before access is permitted, but this policy's grant control is 'Block access'. Blocking is an explicit denial—no MFA challenge is issued because the sign-in is rejected based on the configured risk condition. You cannot combine block and MFA as grant controls in the same Conditional Access policy.

  • ✗

    Blocks access to all cloud apps when sign-in risk is high

    Why it's wrong here

    This policy's cloud apps assignment is specifically set to 'Office 365', which is a group of apps that includes Exchange Online, SharePoint Online, Teams, and other Office 365 services. It does not target 'All cloud apps', so it will not block access to non-Office 365 resources such as Microsoft Entra ID, Dynamics 365, or third-party SaaS apps. The scope is limited to Office 365 apps only, not the entire catalog of cloud apps.

  • ✓

    Blocks access to Office 365 apps when the sign-in risk is high

    Why this is correct

    The policy correctly matches the exhibit: assigned to the 'Office 365' cloud app, condition set to 'High' sign-in risk, and grant control configured to 'Block access'. When a sign-in for any Office 365 app (like OneDrive, Exchange, etc.) is evaluated as high risk, Microsoft Entra ID blocks the authentication and prevents the user from gaining access. This is an effective way to protect against compromised credentials without locking out legitimate low-risk sign-ins.

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.