MS-700 Teams External Access and Guest Collaboration 2 — Questions and Answers
Question 1: Where in the Microsoft Teams admin center is the primary toggle to enable or disable guest access for the entire organization?
- Org-wide settings > External access
- Org-wide settings > Guest access (Correct answer)
- Teams policies > Guest policy
- Users > Guest management
Correct answer: Org-wide settings > Guest access
Guest access is enabled or disabled organization-wide under Org-wide settings > Guest access in the Microsoft Teams admin center.
Question 2: When a user is invited as a guest to a Microsoft Teams team, which identity do they use to sign in?
- A new account automatically created in the host organization's Azure AD
- A temporary Microsoft account issued by Teams for the session
- Their own Microsoft account or Azure AD account from their home organization (Correct answer)
- A shared service account managed by the host tenant admin
Correct answer: Their own Microsoft account or Azure AD account from their home organization
Guest users authenticate using their own Microsoft account or Azure AD account from their home organization; Azure AD B2B creates a guest record in the host tenant that links to their home identity.
Question 3: Which Azure AD configuration must permit guest invitations for Microsoft Teams guest access to function?
- Azure AD Multi-Factor Authentication policy for external users
- Azure AD External Identities B2B collaboration settings (Correct answer)
- Azure AD Conditional Access named locations
- Azure AD Identity Protection sign-in risk policy
Correct answer: Azure AD External Identities B2B collaboration settings
Azure AD External Identities B2B collaboration settings control whether guest users can be invited to the tenant; if guest invitations are blocked at the Azure AD level, Teams guest access will not work even if enabled in Teams.
Question 4: By default, which of the following can a guest user do in a Microsoft Teams team they have been added to?
- Create new teams within the organization
- Access tenant-wide usage analytics
- Participate in channels, share files, and join meetings within that team (Correct answer)
- Manage other guest users in the team
Correct answer: Participate in channels, share files, and join meetings within that team
By default, guests can participate in channels (post messages, read history), share files, and join meetings within the team they were added to, but they cannot create new teams or access org-wide admin features.
Question 5: Which Teams admin center setting controls whether guest users can use private (1:1) chat outside of team channels?
- Teams policy > Private calling allowed
- Guest access > Messaging > Allow private calling
- Guest access > Calling > Allow private calls
- Guest access > Messaging > Chat (Correct answer)
Correct answer: Guest access > Messaging > Chat
The 'Chat' option under Guest access > Messaging in the Teams admin center controls whether guests can use private chat (1:1 messaging) with other users.
Question 6: An admin wants to prevent guest users from deleting their own channel messages in Teams. Which admin center location should they modify?
- Messaging policies > assign to guest users
- Guest access > Messaging settings (Correct answer)
- Teams settings > Channel management > Guest permissions
- Permission policies > Guest deletion rights
Correct answer: Guest access > Messaging settings
Guest access settings in the Teams admin center under Messaging include options to control whether guests can delete sent messages, and toggling this off prevents guests from deleting their messages.
Question 7: What happens to a guest user's access when the team owner removes them from a Microsoft Teams team?
- They are automatically removed from the host organization's Azure AD directory
- They lose access to the team's resources but their guest record may remain in Azure AD (Correct answer)
- Their Microsoft account is suspended for 30 days
- They are given a 30-day grace period to export their data before access is revoked
Correct answer: They lose access to the team's resources but their guest record may remain in Azure AD
Removing a guest from a team revokes their access to that team and its resources immediately, but the guest object in Azure AD remains until an admin explicitly deletes it from the directory.
Where in the Microsoft Teams admin center is the primary toggle to enable or disable guest access for the entire organization?