Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Your company uses Microsoft 365 and wants to ensure that when employees access Microsoft 365 from unmanaged devices, they can only view data but not download or print it. Which technology should you use?

⚠ Common exam trap

MS-900 often tests the difference between data protection technologies, and candidates may confuse DLP or sensitivity labels with session controls, not realizing that only Conditional Access session controls can enforce view-only in real-time for unmanaged devices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Conditional Access with session controls

Microsoft Entra Conditional Access with session controls allows you to restrict access from unmanaged devices to view-only mode, preventing download or print. Session controls like 'Use app enforced restrictions' or 'Use Conditional Access App Control' (with Microsoft Cloud App Security) can enforce limited access. This meets the requirement of allowing view but blocking download/print.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Intune compliance policies

    Why it's wrong here

    Intune compliance policies evaluate device health and configuration, but they do not themselves limit Microsoft 365 web sessions to view-only on unmanaged devices; they feed signals into Conditional Access. They are the right choice when you need to mark devices compliant or non-compliant for access decisions.

  • ✓

    Microsoft Entra Conditional Access with session controls

    Why this is correct

    Conditional Access with session controls applies Cloud App Security policies that restrict unmanaged devices to view-only access, blocking download and print. This satisfies the stem's constraint of allowing viewing while preventing data exfiltration from unmanaged endpoints.

  • ✗

    Sensitivity labels with encryption

    Why it's wrong here

    Sensitivity labels with encryption protect content wherever it travels, but they do not detect an unmanaged device at access time or block download and print actions; they rely on the user's client honouring the label. They are the right choice for persistent classification and encryption of files, not for device-state-based session restrictions.

  • ✗

    Microsoft Purview Data Loss Prevention (DLP) policies

    Why it's wrong here

    DLP policies act on content matching and user actions such as sharing or copying to external locations, not on the managed or unmanaged state of the accessing device. They are correct when you must prevent sensitive data leaving via email, Teams or endpoints based on content rules, rather than restricting browser sessions.

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.