Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your organization is designing a secure access solution for a partner company that needs to access specific SharePoint Online sites. You need to implement Microsoft Entra ID B2B collaboration. Which THREE configurations are essential for a secure B2B collaboration setup?

⚠ Common exam trap

Watch out — candidates often confuse B2B direct connect (for Teams shared channels) with B2B collaboration (for SharePoint and other apps), leading candidates to select Option C incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure cross-tenant access settings in Microsoft Entra ID

Option A is correct because cross-tenant access settings in Microsoft Entra ID let you control inbound and outbound B2B collaboration with the partner tenant, including trust settings for MFA and device claims, which is essential for governing partner access to specific SharePoint Online sites. Option B is correct because enabling MFA for guest users strengthens authentication and reduces the risk of compromised credentials being used to access shared SharePoint resources. Option E is correct because Conditional Access policies scoped to guest users enforce sign-in controls such as MFA, compliant devices, and location restrictions, which are critical for securing B2B access. Option C is not essential here because B2B direct connect is designed for Teams shared channels and does not apply to SharePoint site access in this scenario. Option D is incorrect because allowing all external domains without restrictions removes governance and exposes the tenant to unauthorized invitations and access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure cross-tenant access settings in Microsoft Entra ID

    Why this is correct

    Cross-tenant access settings in Microsoft Entra ID are the foundational control for managing B2B collaboration with partner organizations. They let you define granular inbound and outbound policies that govern trust claims (e.g., MFA, device compliance, hybrid Microsoft Entra ID join) and apply Conditional Access scoping per tenant, user, group, or application. This replaces the older, less secure per-tenant manual configurations and provides a cohesive access-control plane for external identities.

  • ✓

    Enable multi-factor authentication (MFA) for guest users

    Why this is correct

    Enabling MFA for guest users directly addresses the common risk of compromised or weak credentials in external identities. When MFA is enforced at the resource tenant, a guest must complete an additional authentication factor even if their home tenant does not enforce MFA or if the trust settings are not configured to consider the home tenant's MFA claims. This measure is necessary but not sufficient by itself and should be enforced alongside Conditional Access to achieve defense-in-depth.

  • ✗

    Use B2B direct connect for SharePoint site access

    Why it's wrong here

    B2B direct connect is designed specifically for Teams shared channels, not for SharePoint site access. It creates a two-way trust relationship that allows external users to participate in shared channels without being provisioned as guest users in your tenant, but it does not create user objects that Microsoft Entra ID or SharePoint can authorize for site-level permissions. For SharePoint, you must use B2B collaboration, which creates a guest user object that can be granted site-specific access rights.

  • ✗

    Allow all external domains to invite users without restrictions

    Why it's wrong here

    Allowing all external domains to invite users without restrictions eliminates the security controls that cross-tenant access settings provide, such as domain allowlists/blocklists, identity trust, and application-specific restrictions. This configuration exposes your organization to phishing, malware, and data exfiltration risks from unvalidated or malicious tenants, and it makes governance impossible because any user from any tenant could be invited. A disciplined approach should restrict invitations to approved partner domains and enforce verification of tenant identity.

  • ✓

    Set Conditional Access policies that apply to guest users

    Why this is correct

    Conditional Access policies that target guest users provide a dynamic, risk-aware enforcement layer for external access to your resources. By scoping policies to the Guest user type and specific cloud apps, you can require MFA, compliant devices, or session controls whenever a guest attempts access. When combined with cross-tenant access settings, these policies can be further scoped to specific external tenants, enabling you to apply stricter requirements to high-risk partners while allowing smoother access for trusted ones.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.