MS-900 Describe Microsoft 365 apps and services Practice Question
You are the Microsoft 365 administrator for Contoso Ltd., a multinational company with 5,000 employees. The company uses Microsoft 365 E5 licenses for all users. The HR department has requested a solution to onboard new employees more efficiently. Currently, when a new employee is hired, IT manually creates a user account in Microsoft Entra ID (formerly Azure AD), assigns licenses, creates a mailbox in Exchange Online, and provisions a OneDrive for Business account. This process takes approximately 2 hours per employee and is prone to errors. The HR team uses a third-party HR system (Workday) to manage employee records. When an employee is hired in Workday, HR wants the process to be automated so that within 15 minutes, the employee has a Microsoft 365 account, appropriate licenses based on their department, and access to Microsoft Teams and SharePoint Online. Additionally, the employee should be automatically added to a Microsoft 365 group for their department. The solution must minimize manual intervention and ensure that only authorized HR personnel can trigger the automation. What should you implement?
⚠ Common exam trap
Candidates often confuse on-premises identity tools like MIM with cloud-native provisioning, or they overcomplicate the solution with custom development when a built-in connector exists, failing to recognize that Microsoft 365 E5 includes Entra ID P2 features that support automated HR-driven provisioning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Workday to Microsoft Entra ID user provisioning in the Microsoft Entra admin center.
Workday to Microsoft Entra ID user provisioning is a built-in, cloud-native integration that automates the entire lifecycle of user accounts—creation, license assignment, group membership, and access to apps like Teams and SharePoint—directly from Workday HR events. It meets the 15-minute requirement, minimizes manual intervention, and can be scoped to allow only authorized HR personnel to trigger the automation via role-based access control in Entra ID.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy Microsoft Identity Manager (MIM) to synchronize Workday with on-premises AD, then sync to Entra ID.
Why it's wrong here
Deploying Microsoft Identity Manager to synchronize Workday with on-premises Active Directory and then onward to Microsoft Entra ID is a legacy multi-tier sync pattern. It requires additional on-premises servers, a SQL database, and ongoing maintenance while introducing two separate identity synchronization processes. The cloud-native Workday inbound provisioning connector supersedes this complexity by directly synchronizing from Workday to Entra ID without intermediaries, making MIM an unnecessarily complex choice for a cloud-hosted identity platform.
- ✓
Configure Workday to Microsoft Entra ID user provisioning in the Microsoft Entra admin center.
Why this is correct
Configuring Workday to Microsoft Entra ID user provisioning in the Microsoft Entra admin center is the correct solution because it enables native, automated lifecycle management between Workday as the HR source of truth and Entra ID. This prebuilt connector handles user creation, attribute mapping, group membership, and license assignment based on business rules, and it continuously syncs updates and terminations. It uses the latest provisioning service, which is cloud-native, eliminates the need for on-premises infrastructure, and is the Microsoft-recommended approach for this integration.
- ✗
Create a Power Automate flow that triggers when a new employee is added to a SharePoint Online list, then uses Graph API to create the user.
Why it's wrong here
A Power Automate flow that triggers when a new employee is added to a SharePoint Online list is not a reliable enterprise provisioning solution. It depends on someone manually entering each new employee into the list, introducing a human error point and not reading directly from Workday, so real-time delta changes are not captured. While the Microsoft Graph API could create or update user objects, the flow would lack the scaling, error handling, auditing, and native attribute mapping required for HR-driven provisioning, and cannot support lifecycle operations like automatic deprovisioning without a proper source-of-truth connection.
- ✗
Develop a custom solution using Microsoft Graph API and Azure Functions that polls Workday for changes.
Why it's wrong here
A custom solution using Microsoft Graph API and Azure Functions that polls Workday would require ongoing development, maintenance, and error handling to meet the 15-minute automation window, whereas the correct option—Microsoft Entra ID Workday inbound provisioning—provides a native, policy-driven synchronisation engine that directly maps HR attributes to license assignments and group memberships without custom polling logic. This option is tempting because Graph API and Azure Functions are powerful for bespoke integrations, and they would be the correct choice if the HR system were not supported by Microsoft’s pre-built provisioning connectors, such as when integrating with a custom or niche HR platform.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Azure Virtual Desktop (AVD)
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
Key term
Microsoft Teams
Microsoft Teams is a collaboration platform that integrates chat, video meetings, file storage, and application integration into a single workspace, primarily used within the Microsoft 365 ecosystem.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.