Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

You are the Microsoft 365 administrator for Contoso Ltd., a multinational company with 5,000 employees. The company uses Microsoft 365 E5 licenses for all users. The HR department has requested a solution to onboard new employees more efficiently. Currently, when a new employee is hired, IT manually creates a user account in Microsoft Entra ID (formerly Azure AD), assigns licenses, creates a mailbox in Exchange Online, and provisions a OneDrive for Business account. This process takes approximately 2 hours per employee and is prone to errors. The HR team uses a third-party HR system (Workday) to manage employee records. When an employee is hired in Workday, HR wants the process to be automated so that within 15 minutes, the employee has a Microsoft 365 account, appropriate licenses based on their department, and access to Microsoft Teams and SharePoint Online. Additionally, the employee should be automatically added to a Microsoft 365 group for their department. The solution must minimize manual intervention and ensure that only authorized HR personnel can trigger the automation. What should you implement?

⚠ Common exam trap

Candidates often confuse on-premises identity tools like MIM with cloud-native provisioning, or they overcomplicate the solution with custom development when a built-in connector exists, failing to recognize that Microsoft 365 E5 includes Entra ID P2 features that support automated HR-driven provisioning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Workday to Microsoft Entra ID user provisioning in the Microsoft Entra admin center.

Workday to Microsoft Entra ID user provisioning is a built-in, cloud-native integration that automates the entire lifecycle of user accounts—creation, license assignment, group membership, and access to apps like Teams and SharePoint—directly from Workday HR events. It meets the 15-minute requirement, minimizes manual intervention, and can be scoped to allow only authorized HR personnel to trigger the automation via role-based access control in Entra ID.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy Microsoft Identity Manager (MIM) to synchronize Workday with on-premises AD, then sync to Entra ID.

    Why it's wrong here

    Deploying Microsoft Identity Manager to synchronize Workday with on-premises Active Directory and then onward to Microsoft Entra ID is a legacy multi-tier sync pattern. It requires additional on-premises servers, a SQL database, and ongoing maintenance while introducing two separate identity synchronization processes. The cloud-native Workday inbound provisioning connector supersedes this complexity by directly synchronizing from Workday to Entra ID without intermediaries, making MIM an unnecessarily complex choice for a cloud-hosted identity platform.

  • ✓

    Configure Workday to Microsoft Entra ID user provisioning in the Microsoft Entra admin center.

    Why this is correct

    Configuring Workday to Microsoft Entra ID user provisioning in the Microsoft Entra admin center is the correct solution because it enables native, automated lifecycle management between Workday as the HR source of truth and Entra ID. This prebuilt connector handles user creation, attribute mapping, group membership, and license assignment based on business rules, and it continuously syncs updates and terminations. It uses the latest provisioning service, which is cloud-native, eliminates the need for on-premises infrastructure, and is the Microsoft-recommended approach for this integration.

  • ✗

    Create a Power Automate flow that triggers when a new employee is added to a SharePoint Online list, then uses Graph API to create the user.

    Why it's wrong here

    A Power Automate flow that triggers when a new employee is added to a SharePoint Online list is not a reliable enterprise provisioning solution. It depends on someone manually entering each new employee into the list, introducing a human error point and not reading directly from Workday, so real-time delta changes are not captured. While the Microsoft Graph API could create or update user objects, the flow would lack the scaling, error handling, auditing, and native attribute mapping required for HR-driven provisioning, and cannot support lifecycle operations like automatic deprovisioning without a proper source-of-truth connection.

  • ✗

    Develop a custom solution using Microsoft Graph API and Azure Functions that polls Workday for changes.

    Why it's wrong here

    A custom solution using Microsoft Graph API and Azure Functions that polls Workday would require ongoing development, maintenance, and error handling to meet the 15-minute automation window, whereas the correct option—Microsoft Entra ID Workday inbound provisioning—provides a native, policy-driven synchronisation engine that directly maps HR attributes to license assignments and group memberships without custom polling logic. This option is tempting because Graph API and Azure Functions are powerful for bespoke integrations, and they would be the correct choice if the HR system were not supported by Microsoft’s pre-built provisioning connectors, such as when integrating with a custom or niche HR platform.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.