MS-100 Case Studies & Practical Application 3 — Questions and Answers
Question 1: Alpine Ski House is planning a hybrid Exchange deployment. Users need to be able to schedule meetings with both on-premises and Exchange Online recipients and see free/busy information. What must be configured?
- Exchange Federation and an Organization Relationship (Correct answer)
- Exchange Hybrid Modern Authentication
- Shared Active Directory forest with Exchange Online
- Exchange Online archiving for on-premises mailboxes
Correct answer: Exchange Federation and an Organization Relationship
Exchange Federation combined with an Organization Relationship allows free/busy calendar sharing between on-premises Exchange and Exchange Online.
Question 2: A company's security team discovers that several Azure AD accounts have been compromised through credential stuffing. They need to automatically block sign-ins from these risky accounts. Which solution addresses this with the least manual effort?
- Manually disable each compromised account in Azure AD
- Configure Azure AD Identity Protection user risk policy to block high-risk users (Correct answer)
- Enable Conditional Access requiring MFA for all users
- Enable Azure AD smart lockout with a low threshold
Correct answer: Configure Azure AD Identity Protection user risk policy to block high-risk users
An Identity Protection user risk policy can automatically block or require password change for accounts flagged as high risk, without manual intervention per account.
Question 3: Tailspin Toys wants to allow partners to access a specific Teams channel without giving them full Microsoft 365 licenses. What feature should be used?
- Teams guest access using Azure AD B2B
- Teams shared channels with external access (Correct answer)
- Azure AD B2C with Teams integration
- Microsoft 365 external sharing policy for Teams
Correct answer: Teams shared channels with external access
Teams shared channels allow external users to collaborate in a specific channel using their own organization's identity without requiring a guest account or full license.
Question 4: Adatum Corporation wants to ensure that devices must be compliant with Intune policies before accessing Exchange Online. Users on non-compliant devices should be blocked. What should be configured?
- Exchange Online mobile device mailbox policies
- Azure AD Conditional Access policy requiring device compliance (Correct answer)
- Intune app protection policies for Outlook Mobile
- Microsoft Defender for Endpoint device risk-based access
Correct answer: Azure AD Conditional Access policy requiring device compliance
A Conditional Access policy with a device compliance grant condition blocks access to Exchange Online from devices not marked compliant by Intune.
Question 5: A company is deploying Microsoft 365 Apps for Enterprise and wants to control which update channel each department receives. Marketing should get the latest features first; Finance should receive only stable builds. Which tool manages this?
- Microsoft Intune app configuration policies
- Office Deployment Tool with a config XML specifying channels per group (Correct answer)
- Microsoft 365 admin center update settings per user
- Group Policy with the Office ADMX templates
Correct answer: Office Deployment Tool with a config XML specifying channels per group
The Office Deployment Tool with a configuration XML allows specifying different update channels (e.g., Current vs. Semi-Annual) for different deployment groups.
Question 6: Proseware Inc. needs to prevent users from forwarding emails to external domains via Outlook rules, while still allowing IT-approved auto-forwarding to a partner. What is the correct approach?
- Disable SMTP AUTH for all mailboxes in Exchange Online
- Create an outbound spam filter policy blocking external forwarding, then use a mail flow rule to allow the approved partner domain (Correct answer)
- Apply a Conditional Access policy for Exchange Online blocking external recipients
- Enable Advanced Threat Protection anti-phishing policies
Correct answer: Create an outbound spam filter policy blocking external forwarding, then use a mail flow rule to allow the approved partner domain
Setting the outbound spam filter to block or redirect external auto-forwarding, then creating a Transport rule to exempt the approved partner domain, enforces the policy with a targeted exception.
Question 7: During an MS-100 audit scenario, auditors require proof that all privileged role activations in Azure AD were reviewed and approved. Which feature provides this capability?
- Azure AD Access Reviews
- Azure AD Privileged Identity Management with approval workflows (Correct answer)
- Azure AD Identity Protection sign-in risk logs
- Microsoft Defender for Cloud Apps activity log
Correct answer: Azure AD Privileged Identity Management with approval workflows
Azure AD PIM with approval workflows requires a designated approver to authorize each just-in-time privileged role activation, creating an auditable approval record.
Alpine Ski House is planning a hybrid Exchange deployment.
Users need to be able to schedule meetings with both on-premises and Exchange Online recipients and see free/busy information.
What must be configured?