MS-100 Quality Control & Assurance 5 — Questions and Answers
Question 1: An organization wants to confirm that external email forwarding from user mailboxes is blocked. Which policy controls this setting tenant-wide?
- Data Loss Prevention policy
- Anti-spam outbound policy in Defender for Office 365 (Correct answer)
- Exchange transport rule
- Microsoft Entra Conditional Access
Correct answer: Anti-spam outbound policy in Defender for Office 365
The outbound anti-spam policy in Microsoft Defender for Office 365 includes an 'Automatic forwarding' setting that can block or audit automatic email forwarding to external domains.
Question 2: A quality review shows that several Azure AD registered devices in the tenant are stale and have not checked in for over 180 days. What is the recommended remediation?
- Re-enroll all devices using Autopilot
- Delete or disable stale device objects in Microsoft Entra ID (Correct answer)
- Apply a Conditional Access policy requiring compliant devices
- Reset all device passwords
Correct answer: Delete or disable stale device objects in Microsoft Entra ID
Stale device objects should be deleted or disabled in Microsoft Entra ID to reduce the attack surface and keep the device inventory accurate.
Question 3: Which Microsoft 365 admin center section provides a readiness check and guided setup for deploying new Microsoft 365 services?
- Health > Service health
- Setup > Guided setup (Correct answer)
- Reports > Usage
- Settings > Org settings
Correct answer: Setup > Guided setup
The Setup section of the Microsoft 365 admin center offers guided, step-by-step deployment wizards for services like Teams, Exchange, and security features.
Question 4: An admin wants to ensure that no user can consent to third-party apps accessing Microsoft 365 data without admin approval. Which setting controls this?
- App registration policy in Microsoft Entra
- User consent settings in Microsoft Entra Enterprise applications (Correct answer)
- Microsoft 365 admin center app policies
- Microsoft Defender for Cloud Apps session policy
Correct answer: User consent settings in Microsoft Entra Enterprise applications
User consent settings under Enterprise applications in Microsoft Entra ID control whether users can grant third-party apps permissions, or whether admin consent is required.
Question 5: During a QA review of Teams governance, an admin finds that any user can create Teams. Which Microsoft 365 feature restricts Teams creation to authorized users only?
- Teams meeting policies
- Microsoft 365 group creation restriction via Microsoft Entra group policy (Correct answer)
- Teams app permission policies
- Conditional Access for Teams
Correct answer: Microsoft 365 group creation restriction via Microsoft Entra group policy
Microsoft 365 group creation is tied to Teams creation; restricting group creation to a specific security group in Microsoft Entra limits who can create new Teams.
Question 6: A Microsoft 365 quality audit requires verifying that self-service password reset (SSPR) is enabled and that users have registered. Which report shows SSPR registration data?
- Microsoft 365 usage report
- Authentication methods activity report in Microsoft Entra (Correct answer)
- Compliance Manager controls assessment
- Microsoft Defender for Identity alerts
Correct answer: Authentication methods activity report in Microsoft Entra
The Authentication methods activity report in Microsoft Entra ID shows which users have registered for SSPR and which methods they have configured.
Question 7: An organization's quality review finds that the Microsoft 365 Message Center has hundreds of unread items. What is the recommended practice for managing Message Center communications?
- Archive all messages older than 30 days
- Assign Message Center readers and use Planner integration to track action items (Correct answer)
- Delegate all messages to the help desk team
- Enable automatic message dismissal after 7 days
Correct answer: Assign Message Center readers and use Planner integration to track action items
Assigning dedicated Message Center readers and using the built-in Planner integration helps track which messages require action and ensures service change communications are not missed.
An organization wants to confirm that external email forwarding from user mailboxes is blocked.
Which policy controls this setting tenant-wide?