Microsoft 365 Copilot AB-900 SharePoint Sites Libraries Folders Permissions Teams Channels Practice Test

 

Skills 1.1 • 25 original questions

This Microsoft AB-900 Microsoft 365 Copilot and Agent Administration Fundamentals practice test focuses on sharepoint sites libraries folders permissions teams channels and policies through original scenario-based questions aligned to the Skills measured as of July 22, 2026. Use the full ExamSnap AB-900 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft AB-900 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

For a service desk escalation at Tailspin Toys, which Microsoft 365 approach correctly addresses the need to govern a SharePoint site that stores department documents? The team needs a direct administrative answer, not a broad redesign.

  1. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  2. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  3. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  4. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  5. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO

Correct answer: A

Why: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

Option review:

A: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

B: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

C: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

D: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

E: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

Learning point: Use SharePoint administration and the appropriate site, library, or folder object for the requirement. SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly.

Question 2

The Microsoft 365 administrator at Coho Winery is asked to decide whether a person should be an owner, member, or visitor on a team site. What is the most appropriate next step? The administrator wants an action that is easy to audit later.

  1. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  2. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  3. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  4. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  5. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt

Correct answer: A

Why: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

Option review:

A: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

B: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

C: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

D: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

E: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

Learning point: Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement. SharePoint site roles and permissions should be scoped to the content and actions the user actually needs.

Question 3

Humongous Insurance has validated the surrounding services. The remaining requirement is to apply a Teams administrative policy to the intended users. Which choice is correct? The solution should preserve least privilege and existing governance where possible.

  1. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  2. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  3. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  4. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  5. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO

Correct answer: D

Why: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

Option review:

A: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

B: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

C: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

D: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

E: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

Learning point: Use the Teams admin center and configure the relevant team, channel, or Teams policy. Teams administration covers collaboration objects and policies that govern Teams behavior and access.

Question 4

A new administrator at Adventure Works asks which Microsoft 365 feature is intended to govern a SharePoint site that stores department documents. What is the best answer? The team wants the smallest change that directly addresses the requirement.

  1. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  2. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation
  3. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials
  4. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  5. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature

Correct answer: D

Why: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

Option review:

A: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

B: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

C: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

D: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

E: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

Learning point: Use SharePoint administration and the appropriate site, library, or folder object for the requirement. SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly.

Question 5

A design review at Blue Yonder Airlines identifies one specific goal: decide whether a person should be an owner, member, or visitor on a team site. Which option best matches that goal? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation
  2. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  3. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  4. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  5. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement

Correct answer: E

Why: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

Option review:

A: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

B: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

C: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

D: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

E: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

Learning point: Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement. SharePoint site roles and permissions should be scoped to the content and actions the user actually needs.

Question 6

The IT team at Relecloud wants to apply a Teams administrative policy to the intended users. Which Microsoft 365 capability should it use? The team will validate the result immediately after the change.

  1. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  2. Use the Exchange admin center to configure the required mailbox or distribution group
  3. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  4. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  5. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity

Correct answer: A

Why: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

Option review:

A: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

B: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

C: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

D: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

E: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

Learning point: Use the Teams admin center and configure the relevant team, channel, or Teams policy. Teams administration covers collaboration objects and policies that govern Teams behavior and access.

Question 7

While handling a admin-center audit, the IT administrator needs to govern a SharePoint site that stores department documents. Which answer most directly addresses the stated need? No unrelated tenant settings should be changed.

  1. Use the Exchange admin center to configure the required mailbox or distribution group
  2. Use Microsoft Entra ID for cloud identity, authentication, and access management
  3. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  4. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  5. Use SharePoint administration and the appropriate site, library, or folder object for the requirement

Correct answer: E

Why: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

Option review:

A: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

B: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

C: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

D: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

E: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

Learning point: Use SharePoint administration and the appropriate site, library, or folder object for the requirement. SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly.

Question 8

A new administrator at Proseware asks which Microsoft 365 feature is intended to decide whether a person should be an owner, member, or visitor on a team site. What is the best answer? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  2. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  3. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  4. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  5. Use SharePoint administration and the appropriate site, library, or folder object for the requirement

Correct answer: B

Why: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

Option review:

A: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

B: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

C: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

D: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

E: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

Learning point: Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement. SharePoint site roles and permissions should be scoped to the content and actions the user actually needs.

Question 9

Lucerne Publishing is preparing a governance workshop. The team needs to apply a Teams administrative policy to the intended users. What should the SharePoint administrator choose? The choice should follow normal Microsoft 365 administrative practice.

  1. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  2. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation
  3. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  4. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  5. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity

Correct answer: D

Why: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

Option review:

A: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

B: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

C: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

D: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

E: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

Learning point: Use the Teams admin center and configure the relevant team, channel, or Teams policy. Teams administration covers collaboration objects and policies that govern Teams behavior and access.

Question 10

A support case at City Power & Light says administrators must govern a SharePoint site that stores department documents. Which option is the best fit? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  2. Use the Exchange admin center to configure the required mailbox or distribution group
  3. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  4. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  5. Use the Microsoft 365 admin center to review the tenant domain names and organization settings

Correct answer: A

Why: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

Option review:

A: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

B: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

C: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

D: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

E: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

Learning point: Use SharePoint administration and the appropriate site, library, or folder object for the requirement. SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly.

Question 11

For a tenant cleanup at Northwind Traders, which Microsoft 365 approach correctly addresses the need to decide whether a person should be an owner, member, or visitor on a team site? The team needs a direct administrative answer, not a broad redesign.

  1. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  2. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  3. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  4. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  5. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity

Correct answer: C

Why: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

Option review:

A: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

B: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

C: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

D: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

E: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

Learning point: Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement. SharePoint site roles and permissions should be scoped to the content and actions the user actually needs.

Question 12

A new administrator at Fourth Coffee asks which Microsoft 365 feature is intended to apply a Teams administrative policy to the intended users. What is the best answer? The administrator wants an action that is easy to audit later.

  1. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation
  2. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  3. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  4. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  5. Use the Teams admin center and configure the relevant team, channel, or Teams policy

Correct answer: E

Why: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

Option review:

A: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

B: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

C: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

D: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

E: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

Learning point: Use the Teams admin center and configure the relevant team, channel, or Teams policy. Teams administration covers collaboration objects and policies that govern Teams behavior and access.

Question 13

Alpine Ski House has validated the surrounding services. The remaining requirement is to govern a SharePoint site that stores department documents. Which choice is correct? The solution should preserve least privilege and existing governance where possible.

  1. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  2. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  3. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  4. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  5. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control

Correct answer: D

Why: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

Option review:

A: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

B: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

C: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

D: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

E: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

Learning point: Use SharePoint administration and the appropriate site, library, or folder object for the requirement. SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly.

Question 14

An administrator reviewing new-user onboarding for Contoso must decide whether a person should be an owner, member, or visitor on a team site. Which Microsoft 365 control or object should be used? The team wants the smallest change that directly addresses the requirement.

  1. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  2. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  3. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  4. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials
  5. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt

Correct answer: A

Why: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

Option review:

A: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

B: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

C: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

D: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

E: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

Learning point: Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement. SharePoint site roles and permissions should be scoped to the content and actions the user actually needs.

Question 15

A design review at Litware identifies one specific goal: apply a Teams administrative policy to the intended users. Which option best matches that goal? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  2. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  3. Use the Exchange admin center to configure the required mailbox or distribution group
  4. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  5. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities

Correct answer: A

Why: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

Option review:

A: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

B: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

C: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

D: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

E: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

Learning point: Use the Teams admin center and configure the relevant team, channel, or Teams policy. Teams administration covers collaboration objects and policies that govern Teams behavior and access.

Question 16

A new administrator at Trey Research asks which Microsoft 365 feature is intended to govern a SharePoint site that stores department documents. What is the best answer? The team will validate the result immediately after the change.

  1. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  2. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  3. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  4. Use Microsoft Entra ID for cloud identity, authentication, and access management
  5. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity

Correct answer: C

Why: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

Option review:

A: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

B: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

C: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

D: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

E: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

Learning point: Use SharePoint administration and the appropriate site, library, or folder object for the requirement. SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly.

Question 17

While handling a production readiness check, the SharePoint administrator needs to decide whether a person should be an owner, member, or visitor on a team site. Which answer most directly addresses the stated need? No unrelated tenant settings should be changed.

  1. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  2. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  3. Use Microsoft Entra ID for cloud identity, authentication, and access management
  4. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  5. Use Identity Secure Score to review identity-security recommendations and track posture improvements

Correct answer: D

Why: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

Option review:

A: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

B: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

C: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

D: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

E: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

Learning point: Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement. SharePoint site roles and permissions should be scoped to the content and actions the user actually needs.

Question 18

During a security review at Woodgrove Bank, the Microsoft 365 administrator must apply a Teams administrative policy to the intended users. Which Microsoft 365 action or concept most directly satisfies the requirement? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials
  2. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  3. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  4. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  5. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation

Correct answer: D

Why: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

Option review:

A: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

B: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

C: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

D: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

E: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

Learning point: Use the Teams admin center and configure the relevant team, channel, or Teams policy. Teams administration covers collaboration objects and policies that govern Teams behavior and access.

Question 19

Wide World Importers is preparing a compliance assessment. The team needs to govern a SharePoint site that stores department documents. What should the security administrator choose? The choice should follow normal Microsoft 365 administrative practice.

  1. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  2. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  3. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  4. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  5. Use the Exchange admin center to configure the required mailbox or distribution group

Correct answer: A

Why: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

Option review:

A: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

B: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

C: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

D: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

E: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

Learning point: Use SharePoint administration and the appropriate site, library, or folder object for the requirement. SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly.

Question 20

A new administrator at Southridge Video asks which Microsoft 365 feature is intended to decide whether a person should be an owner, member, or visitor on a team site. What is the best answer? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  2. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  3. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  4. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  5. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity

Correct answer: A

Why: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

Option review:

A: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

B: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

C: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

D: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

E: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

Learning point: Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement. SharePoint site roles and permissions should be scoped to the content and actions the user actually needs.

Question 21

For a data protection review at Fabrikam, which Microsoft 365 approach correctly addresses the need to apply a Teams administrative policy to the intended users? The team needs a direct administrative answer, not a broad redesign.

  1. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  2. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  3. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  4. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  5. Use the Teams admin center and configure the relevant team, channel, or Teams policy

Correct answer: E

Why: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

Option review:

A: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

B: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

C: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

D: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

E: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

Learning point: Use the Teams admin center and configure the relevant team, channel, or Teams policy. Teams administration covers collaboration objects and policies that govern Teams behavior and access.

Question 22

The compliance administrator at Wingtip Toys is asked to govern a SharePoint site that stores department documents. What is the most appropriate next step? The administrator wants an action that is easy to audit later.

  1. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials
  2. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  3. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  4. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  5. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity

Correct answer: B

Why: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

Option review:

A: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

B: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

C: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

D: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

E: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

Learning point: Use SharePoint administration and the appropriate site, library, or folder object for the requirement. SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly.

Question 23

VanArsdel has validated the surrounding services. The remaining requirement is to decide whether a person should be an owner, member, or visitor on a team site. Which choice is correct? The solution should preserve least privilege and existing governance where possible.

  1. Use Microsoft Entra ID for cloud identity, authentication, and access management
  2. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  3. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  4. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  5. Use SharePoint administration and the appropriate site, library, or folder object for the requirement

Correct answer: C

Why: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

Option review:

A: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

B: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

C: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This directly addresses the stated requirement.

D: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

E: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to decide whether a person should be an owner, member, or visitor on a team site.

Learning point: Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement. SharePoint site roles and permissions should be scoped to the content and actions the user actually needs.

Question 24

A new administrator at Bellows College asks which Microsoft 365 feature is intended to apply a Teams administrative policy to the intended users. What is the best answer? The team wants the smallest change that directly addresses the requirement.

  1. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  2. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  3. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  4. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  5. Use SharePoint administration and the appropriate site, library, or folder object for the requirement

Correct answer: D

Why: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

Option review:

A: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

B: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

C: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

D: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This directly addresses the stated requirement.

E: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a Teams administrative policy to the intended users.

Learning point: Use the Teams admin center and configure the relevant team, channel, or Teams policy. Teams administration covers collaboration objects and policies that govern Teams behavior and access.

Question 25

A design review at Tailspin Toys identifies one specific goal: govern a SharePoint site that stores department documents. Which option best matches that goal? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  2. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  3. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  4. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  5. Use SharePoint administration and the appropriate site, library, or folder object for the requirement

Correct answer: E

Why: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

Option review:

A: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

B: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

C: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

D: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to govern a SharePoint site that stores department documents.

E: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This directly addresses the stated requirement.

Learning point: Use SharePoint administration and the appropriate site, library, or folder object for the requirement. SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly.

Popular posts

img