{"id":15238,"date":"2026-09-17T11:05:22","date_gmt":"2026-09-17T11:05:22","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15238"},"modified":"2026-09-17T11:05:22","modified_gmt":"2026-09-17T11:05:22","slug":"microsoft-ab-900-practice-test-questions-and-exam-dumps-part17-q321-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-ab-900-practice-test-questions-and-exam-dumps-part17-q321-340\/","title":{"rendered":"Microsoft AB-900 Practice Test Questions and Exam Dumps Part17 Q321-340"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ab-900-exam-dumps\"><b>Microsoft AB-900 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 321<\/b><\/h3>\n<p><b>An administrator wants Exchange Online to require approval before messages sent to a distribution group are delivered to its members. Which feature should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mailbox archive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Distribution group moderation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Distribution group moderation allows an organization to require designated moderators to approve messages before those messages are delivered to members of a moderated distribution group. This can be useful for groups that receive announcements, sensitive communications, or messages that require review before distribution. Message trace is used to investigate mail delivery, mailbox archive stores older email, and Safe Links helps protect users from malicious URLs. Therefore, distribution group moderation is the appropriate Exchange Online feature when messages must be reviewed before being distributed to group members.<\/span><\/p>\n<h3><b>Question 322<\/b><\/h3>\n<p><b>A user wants Exchange Online to automatically respond to incoming messages while they are away from work. Which mailbox feature should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic replies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mail flow connector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DKIM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Exchange Online automatic replies allow users or administrators to configure messages that are automatically sent when the mailbox owner is unavailable. They are commonly used for vacation notices, leave periods, or other situations where the user cannot respond promptly. Administrators can configure appropriate internal and external response behavior according to organizational requirements. Message trace is used to investigate email delivery, mail flow connectors control message routing between systems, and DKIM provides email authentication through digital signatures. Therefore, automatic replies are the appropriate mailbox feature for communicating a user&#8217;s temporary absence.<\/span><\/p>\n<h3><b>Question 323<\/b><\/h3>\n<p><b>An organization wants employees to use the latest supported Microsoft 365 Apps features after they have been tested and approved. Which configuration determines how frequently new Office features are delivered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service health<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Update channel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint template<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device category<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 Apps update channels determine how frequently users receive feature updates for Office applications. Organizations can select an appropriate channel based on their testing, stability, and deployment requirements. Some channels provide newer features sooner, while others prioritize a more controlled release cycle. Service health provides information about Microsoft service conditions, SharePoint templates provide predefined site structures, and device categories help organize Intune-managed devices. Therefore, the update channel is the configuration administrators should review when controlling how and when Microsoft 365 Apps features are delivered.<\/span><\/p>\n<h3><b>Question 324<\/b><\/h3>\n<p><b>An IT department wants to test a new Microsoft 365 Apps feature with a small group of users before deploying it broadly. Which deployment approach is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immediate organization-wide deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pilot deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mailbox delegation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A pilot deployment allows an organization to introduce a Microsoft 365 Apps configuration or update to a limited group before expanding it to the wider user population. IT administrators can monitor compatibility, user experience, and application behavior during the pilot. Problems discovered during testing can be addressed before broad deployment, reducing potential disruption. Immediate organization-wide deployment provides less opportunity for controlled testing, while anonymous sharing and mailbox delegation are unrelated to application deployment. Therefore, a pilot deployment is the appropriate approach when an organization wants to validate a change before wider implementation.<\/span><\/p>\n<h3><b>Question 325<\/b><\/h3>\n<p><b>Which Microsoft 365 Apps management capability provides administrators with information about application versions and update status across organizational devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Apps inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Forms<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint recycle bin<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange quarantine<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 Apps inventory information can help administrators understand which Office application versions are installed across organizational devices and whether systems are receiving expected updates. This visibility can support application management, troubleshooting, and planning for version changes. Microsoft Forms is used for collecting responses, SharePoint recycle bin contains deleted content, and Exchange quarantine contains isolated messages or other suspicious content. Therefore, Microsoft 365 Apps inventory is the appropriate information source when administrators need visibility into installed Office versions and their update status.<\/span><\/p>\n<h3><b>Question 326<\/b><\/h3>\n<p><b>A company wants to reduce the risk of users accidentally sharing sensitive OneDrive files with external recipients. Which setting should administrators review?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OneDrive sharing restrictions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange automatic replies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Search<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows Autopilot<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OneDrive sharing restrictions allow administrators to control how users share files and folders, including restrictions related to external sharing. Organizations can configure sharing policies according to their security and collaboration requirements. Restricting broad sharing options can reduce the likelihood of sensitive files being exposed unintentionally. Exchange automatic replies are designed for absence notifications, Microsoft Search helps locate information, and Windows Autopilot supports Windows deployment. Therefore, OneDrive sharing restrictions are the appropriate settings to review when the goal is to reduce accidental external sharing of sensitive files.<\/span><\/p>\n<h3><b>Question 327<\/b><\/h3>\n<p><b>An organization wants guest access to expire automatically after a defined period unless it is extended. Which Microsoft 365 governance setting can support this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Guest expiration policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mail flow rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device restart<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office update channel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A guest expiration policy can help organizations automatically remove or require review of guest access after a defined period. This supports governance by preventing external accounts from retaining access indefinitely when the original business need may no longer exist. Administrators can establish an appropriate expiration period based on organizational requirements and collaboration practices. Mail flow rules control Exchange message processing, device restart is an Intune action, and Office update channels determine application update delivery. Therefore, a guest expiration policy is the relevant governance capability for time-limited guest access.<\/span><\/p>\n<h3><b>Question 328<\/b><\/h3>\n<p><b>Which Microsoft Teams channel type allows collaboration between members of a team and people who are not members of the parent team, while keeping the collaboration within the organization&#8217;s controlled Teams environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standard channel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private channel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared channel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Announcement post<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A shared channel is designed to allow collaboration with people who may not be members of the parent team. It can provide a focused collaboration space while allowing selected users to participate without adding everyone to the entire team. This can be useful when multiple groups need to collaborate on a specific project or subject. A standard channel is generally available to the team, while a private channel restricts participation to selected members of the parent team. An announcement post is a communication format rather than a channel type. Therefore, a shared channel fits this scenario.<\/span><\/p>\n<h3><b>Question 329<\/b><\/h3>\n<p><b>A Microsoft Teams administrator wants users to have access to a specific application from the Teams interface and wants the application to appear in an appropriate location for users. Which policy area should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Teams app setup policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange retention policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint site template<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intune device category<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Teams app setup policies help administrators control how applications are made available and presented within Microsoft Teams. Organizations can use these policies to configure which applications are installed or made available to users and how they are positioned within the Teams experience, depending on supported policy capabilities. Exchange retention policies govern mailbox information, SharePoint site templates provide predefined site structures, and Intune device categories organize managed devices. Therefore, the Teams app setup policy is the relevant policy area when administrators need to manage application presentation and availability in Teams.<\/span><\/p>\n<h3><b>Question 330<\/b><\/h3>\n<p><b>A company wants users to be able to work with Microsoft 365 applications even when they temporarily lose internet connectivity. Which capability supports offline access to supported desktop applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 desktop apps<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Search<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service health<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 desktop applications such as Word, Excel, and PowerPoint can support offline work when they are installed and appropriately licensed. Users can continue working on supported locally stored documents while disconnected and synchronize changes when connectivity becomes available again, depending on the application and storage configuration. Microsoft Search is designed for finding information, Message center communicates administrative changes, and Service health reports service conditions. Therefore, Microsoft 365 desktop applications are the relevant capability when users need to continue working during temporary internet interruptions.<\/span><\/p>\n<h3><b>Question 331<\/b><\/h3>\n<p><b>Which Microsoft Entra capability allows administrators to automatically add users to a group based on user attributes such as department or job title?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic membership<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mail flow connector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint version history<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic membership allows Microsoft Entra groups to automatically include or remove users according to defined membership rules. Administrators can create rules based on user attributes such as department, job title, location, or other supported properties. This reduces the need to manually maintain group membership when employees&#8217; attributes change. Mail flow connectors handle email routing, Safe Attachments helps detect malicious files, and SharePoint version history preserves previous document versions. Therefore, dynamic membership is the appropriate capability when group membership should automatically reflect user attributes.<\/span><\/p>\n<h3><b>Question 332<\/b><\/h3>\n<p><b>An organization needs an administrator who can manage Exchange Online settings but should not receive full tenant-wide administrative permissions. Which role is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">License Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Teams Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User Administrator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Exchange Administrator role is designed to manage Exchange Online-related settings and services. Assigning this workload-specific role allows an organization to delegate Exchange responsibilities without automatically providing broad administrative access across unrelated Microsoft 365 services. A License Administrator focuses on licensing tasks, a Teams Administrator manages Teams, and a User Administrator focuses on user account administration. Using specialized roles supports least-privilege administration by aligning permissions with the administrator&#8217;s actual responsibilities. Therefore, Exchange Administrator is the appropriate role when the primary responsibility involves managing Exchange Online.<\/span><\/p>\n<h3><b>Question 333<\/b><\/h3>\n<p><b>Which Microsoft 365 administrative role is primarily responsible for managing SharePoint Online settings and administration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">License Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Helpdesk Administrator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The SharePoint Administrator role is designed to manage SharePoint Online administration and settings. Administrators assigned this role can perform supported SharePoint management tasks without necessarily receiving unrelated administrative permissions for other Microsoft 365 workloads. Security Administrator focuses on security-related administration, License Administrator manages licensing tasks, and Helpdesk Administrator is intended for supported help-desk functions. Assigning the appropriate workload-specific role helps organizations follow least-privilege principles. Therefore, SharePoint Administrator is the most appropriate role for someone whose primary responsibility is administering SharePoint Online.<\/span><\/p>\n<h3><b>Question 334<\/b><\/h3>\n<p><b>A help-desk employee needs to assist users with common account and password issues but should not receive broad administrative control. Which role is designed for this type of responsibility?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Helpdesk Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security Administrator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Helpdesk Administrator role is designed for common support tasks involving users and their accounts. It can provide appropriate permissions for help-desk personnel without granting the broad administrative capabilities associated with higher-privilege roles. This supports the principle of least privilege because support staff receive permissions aligned with their responsibilities. SharePoint Administrator manages SharePoint, Exchange Administrator manages Exchange, and Security Administrator handles security-related administration. Therefore, Helpdesk Administrator is the most appropriate role when an employee needs to provide routine account and password assistance without broad tenant administration.<\/span><\/p>\n<h3><b>Question 335<\/b><\/h3>\n<p><b>An organization wants to require users to authenticate with a specific strong method when accessing a sensitive application. Which Microsoft Entra feature should be incorporated into the access policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication strength<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Domain verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service principal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra authentication strengths allow organizations to specify which authentication methods are acceptable for particular access scenarios. Administrators can configure an authentication strength and apply it through appropriate access policies so that sensitive applications require stronger authentication methods. Dynamic groups manage membership automatically, domain verification confirms control over a domain, and service principals represent application identities within a tenant. Therefore, authentication strength is the appropriate Microsoft Entra feature when an organization needs to require a defined level of authentication for access to a sensitive application.<\/span><\/p>\n<h3><b>Question 336<\/b><\/h3>\n<p><b>Which Microsoft Entra capability allows users to register supported authentication methods so those methods can be used for account recovery or stronger sign-in experiences?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication methods<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint hub sites<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange archive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device categories<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra authentication methods allow organizations to manage the ways users can authenticate, including supported methods used for sign-in, verification, and account recovery. Administrators can configure which authentication methods are available and manage related registration experiences according to organizational requirements. SharePoint hub sites connect related SharePoint sites, Exchange archive stores older mailbox content, and device categories organize Intune-managed endpoints. Therefore, authentication methods are the appropriate Microsoft Entra capability when the requirement involves registering and managing user authentication options.<\/span><\/p>\n<h3><b>Question 337<\/b><\/h3>\n<p><b>A company wants users to register Microsoft Authenticator during sign-in rather than waiting for users to configure it manually at an unspecified time. Which capability can help prompt users to complete registration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Registration campaign<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint version history<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OneDrive recycle bin<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Microsoft Authenticator registration campaign can help organizations encourage users to register the Authenticator application during an appropriate sign-in experience. This provides administrators with a structured way to promote registration instead of relying entirely on users to configure the method independently. Exchange message trace investigates email delivery, SharePoint version history preserves previous document versions, and the OneDrive recycle bin contains deleted files. Therefore, a registration campaign is the relevant capability when the goal is to encourage users to set up Microsoft Authenticator.<\/span><\/p>\n<h3><b>Question 338<\/b><\/h3>\n<p><b>An organization wants to ensure that an application can access only the Microsoft Graph permissions it actually requires. Which security principle should guide the application design?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maximum privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open authorization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege requires an application to receive only the permissions necessary to perform its intended functions. Applying this principle to Microsoft Graph helps reduce the potential impact if an application is compromised or misused. Granting broad permissions when they are not required can increase security exposure and make unauthorized access more damaging. Anonymous access and maximum privilege do not provide appropriate security controls, while open authorization is not a suitable principle for application permissions. Therefore, least privilege should guide the selection of Microsoft Graph permissions.<\/span><\/p>\n<h3><b>Question 339<\/b><\/h3>\n<p><b>A Microsoft 365 administrator wants to understand how users are adopting different Microsoft 365 workloads across the organization. Which type of information should be reviewed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Usage analytics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mailbox automatic replies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device restart history<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 usage analytics can provide information about how users are adopting and using different Microsoft 365 workloads. Administrators can use usage information to understand patterns such as active users, application adoption, and service utilization, depending on the available reports and configuration. This information can support training, adoption planning, and administrative decision-making. DNS records configure domain services, automatic replies communicate user availability, and device restart history relates to endpoint management. Therefore, usage analytics is the appropriate information source when administrators need insight into Microsoft 365 workload adoption.<\/span><\/p>\n<h3><b>Question 340<\/b><\/h3>\n<p><b>An organization wants to identify which Microsoft 365 services are actively being used before planning additional user training. Which resource can provide service usage information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 usage reports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange quarantine<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint recycle bin<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender incidents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 usage reports provide information about the adoption and activity of supported Microsoft 365 services. Administrators can review available reports to understand how users are interacting with workloads and identify areas where additional training or adoption support may be useful. Exchange quarantine contains isolated email content, the SharePoint recycle bin contains deleted files, and Defender incidents are used for security investigations. Therefore, Microsoft 365 usage reports are the appropriate resource for identifying service usage patterns before planning targeted user training.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AB-900 Exam Dumps and Practice Test Dumps. &nbsp; Question 321 An administrator wants Exchange Online to require approval before messages sent to a distribution group are delivered to its members. Which feature should be configured? Mailbox archive Message trace Distribution group moderation Safe Links Correct Answer: 3 Explanation Distribution group moderation allows [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15238"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15238"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15238\/revisions"}],"predecessor-version":[{"id":15252,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15238\/revisions\/15252"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}