Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

Your organization is migrating from on-premises Exchange to Exchange Online. You need to ensure that users can access their mailboxes using Outlook for Windows without re-entering credentials each time. Which Microsoft 365 service should you configure to enable single sign-on (SSO) and modern authentication?

⚠ Common exam trap

Watch out — candidates often confuse Microsoft Intune (device management) with identity services, or assume that any Microsoft 365 security or management tool can enable SSO, when only the identity provider (Microsoft Entra ID) can issue authentication tokens for modern auth.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID

Microsoft Entra ID (formerly Azure AD) is the identity and access management service that provides single sign-on (SSO) and modern authentication (OAuth 2.0, OpenID Connect) for Exchange Online. When configured, Outlook for Windows can use the Microsoft Entra ID token to authenticate silently, eliminating the need for users to re-enter credentials each time they access their mailbox.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra ID

    Why this is correct

    Microsoft Entra ID is the cloud identity and access management service (previously Azure AD) that provides authentication, single sign-on, and conditional access for Exchange Online. When migrating from on-premises Exchange, you must synchronize and authenticate user identities to access mailboxes, using protocols like OAuth 2.0 and modern authentication. Without Entra ID, Exchange Online cannot verify user credentials or enforce MFA.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is an endpoint management solution that enrolls devices and enforces compliance policies for mobile and desktop endpoints. It does not act as an identity provider or directory service, so it cannot authenticate users or enable single sign-on during an Exchange Online migration. Intune may apply device-based conditional access policies, but identity itself is the missing piece.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Microsoft Purview is a compliance and data governance suite covering sensitivity labels, retention, eDiscovery, and data loss prevention. It does not perform user authentication or directory functions; therefore, it cannot support the identity steps of migrating from on-premises Exchange. Any authentication-related requirement in the migration is handled by Microsoft Entra ID, not Purview.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native security information and event management (SIEM) platform that collects logs and generates alerts for threat detection and response. It consumes sign-in logs from Entra ID but does not issue or validate credentials, so it is irrelevant to authenticating users during an Exchange migration. Its role begins after identity events occur.

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.