MS-700 Teams External Access and Guest Collaboration 1 — Questions and Answers
Question 1: What is the default configuration for external access (federation) in a new Microsoft Teams tenant?
- Disabled for all external domains
- Enabled for all external domains (Correct answer)
- Enabled only for verified Microsoft 365 domains
- Enabled only after admin approval
Correct answer: Enabled for all external domains
By default, external access is enabled for all external domains in Microsoft Teams, allowing users to communicate with people in other organizations using Teams or Skype for Business.
Question 2: Which Microsoft Teams admin center section controls whether users can communicate with people outside the organization who use Teams or Skype for Business without adding them to your tenant?
- Guest access
- External access (Correct answer)
- Teams policies
- Cross-tenant sync
Correct answer: External access
External access (federation) settings in the Teams admin center under Org-wide settings control federation with external Teams and Skype for Business users without requiring them to be added to your Azure AD tenant.
Question 3: An administrator needs to allow Teams communication only with a specific partner company's domain. Which external access configuration should they apply?
- Enable guest access for the partner domain only
- Select 'Allow only specific external domains' and add the partner domain (Correct answer)
- Create a Teams policy package for partner communication
- Use Azure AD B2B direct connect for the partner domain
Correct answer: Select 'Allow only specific external domains' and add the partner domain
In Teams admin center External access settings, selecting 'Allow only specific external domains' and adding the partner domain restricts federation to only that organization.
Question 4: What is the key distinction between Guest access and External access in Microsoft Teams?
- Guest access is free; External access requires licensing
- Guest access adds external users as Azure AD guests in your tenant; External access enables 1:1 communication without joining your tenant (Correct answer)
- External access grants channel membership; Guest access only allows chat
- Guest access is temporary; External access is permanent
Correct answer: Guest access adds external users as Azure AD guests in your tenant; External access enables 1:1 communication without joining your tenant
Guest access provisions an Azure AD guest account in your tenant giving users access to teams and channels, while external access (federation) allows 1:1 chat and calls without the external user joining your tenant directory.
Question 5: Which action can a federated external access user perform in Microsoft Teams?
- Join private channels in your organization's teams
- Search for and initiate 1:1 chat with users in your organization (Correct answer)
- Access SharePoint files shared in your organization's channels
- Create new teams within your organization
Correct answer: Search for and initiate 1:1 chat with users in your organization
Federated external access users can search for and start 1:1 chats and calls with users in your organization, but they cannot join your teams, channels, or access internal SharePoint files.
Question 6: Which PowerShell cmdlet retrieves the tenant-wide federation (external access) configuration in Microsoft Teams?
- Get-CsExternalAccessPolicy
- Get-CsTenantFederationConfiguration (Correct answer)
- Get-CsTeamsFederationSettings
- Get-CsFederationAllowList
Correct answer: Get-CsTenantFederationConfiguration
Get-CsTenantFederationConfiguration returns the federation configuration for the tenant, including whether federation is enabled and which domains are allowed or blocked.
Question 7: A Teams administrator wants to prevent users in their organization from communicating with Skype consumer (personal) accounts. Which setting should be disabled?
- Guest access > Allow guest Skype communication
- External access > Allow users in my organization to communicate with Skype users (Correct answer)
- Teams settings > Skype interoperability
- Meeting policies > Allow Skype for Business interop
Correct answer: External access > Allow users in my organization to communicate with Skype users
In Teams admin center under External access, the option 'Allow users in my organization to communicate with Skype users' controls federation with Skype consumer accounts and should be disabled to block this communication.
What is the default configuration for external access (federation) in a new Microsoft Teams tenant?