MS-900 Describe Microsoft 365 apps and services Practice Question
Your organization is adopting Microsoft 365 Copilot and wants to ensure that Copilot responses are based only on organizational data that the user has permission to access. Which Microsoft 365 feature ensures this?
⚠ Common exam trap
A common mix-up: candidates confuse identity management (Entra ID) with data-level permission enforcement (Microsoft Graph permissions), assuming that because Entra ID handles authentication, it also controls what data Copilot can access, but the actual data access control is delegated to Graph's permission model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Graph permissions
Microsoft Graph permissions are the correct answer because Copilot uses Microsoft Graph to access organizational data. When a user asks a question, Copilot queries the Microsoft Graph API, which enforces the user's existing permissions (e.g., from Entra ID and SharePoint) to ensure responses are based only on data the user is authorized to see. This is the core mechanism that ties Copilot's responses to the user's access rights.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview Compliance Manager
Why it's wrong here
Microsoft Purview Compliance Manager is a solution for assessing an organization's compliance posture against regulatory standards like GDPR or ISO 27001. It generates risk scores and improvement actions but does not enforce or influence runtime data access for Copilot. Copilot's ability to surface emails, files, or chats is determined solely by the effective permissions of the signed-in user in Microsoft Graph, not by compliance assessments.
- ✗
Microsoft Entra ID
Why it's wrong here
Microsoft Entra ID provides authentication and conditional access, verifying who can sign in and applying policies like MFA or device restrictions. However, it does not define which specific documents or messages a user can view within Copilot; that visibility is governed by the permission scopes and sharing settings evaluated by Microsoft Graph. Entra ID controls the identity boundary, not the data-level authorization boundary that Copilot uses.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune focuses on device management, enforcing compliance policies, and configuring mobile device management (MDM) or mobile application management (MAM). It can block access from non-compliant devices, but it cannot dictate what content Copilot can retrieve from Exchange, SharePoint, or Teams. The data Copilot can include in responses is based on the user's assigned permissions in Microsoft Graph, independent of device-level controls like Intune.
- ✓
Microsoft Graph permissions
Why this is correct
Microsoft Graph permissions are the correct answer because Copilot for Microsoft 365 operates by calling Microsoft Graph APIs on behalf of the signed-in user, inheriting that user's effective permissions. It can only access resources—such as emails, calendar items, documents, and chats—for which the user has at least the appropriate delegated permission scope, and it respects sensitivity labels and other restrictions. This ensures Copilot cannot surface data the user is not already allowed to see, maintaining least-privilege access.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Admin APIs and Graph API Basics
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.