exam questions

Exam MS-203 All Questions

View all questions & answers for the MS-203 exam

Exam MS-203 topic 1 question 7 discussion

Actual exam question from Microsoft's MS-203
Question #: 7
Topic #: 1
[All MS-203 Questions]

You have a Microsoft Exchange Online tenant.
All users are assigned only an Office 365 Enterprise E3 license.
You need to ensure that the users can use only Microsoft Outlook to connect to their Microsoft 365 mailbox when they connect from an Android device.
What should you create?

  • A. a conditional access policy in Azure Active Directory (Azure AD)
  • B. a data loss prevention (DLP) policy
  • C. an app protection policy Microsoft Endpoint Manager
  • D. a connection filter policy in Exchange Online Protection (EOP)
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Cbruce
Highly Voted 3 years, 4 months ago
I don't think the correct answer is on the list of options. This should be using an ActiveSyncDeviceAccess rule. https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/outlook-for-ios-and-android/secure-outlook-for-ios-and-android New-ActiveSyncDeviceAccessRule -Characteristic DeviceType -QueryString "Android" -AccessLevel Block Answer D - EOP doesn't seem to have a way to block just Android from using ActiveSync. Please let me know if you disagree.
upvoted 15 times
Abdou1604
2 years, 2 months ago
But your access rule will block android devices only from connecting to exchange online but any personnal exemptions will allow any android from admins , but app protection polices for outlook + conditionnal access will make the best solution !
upvoted 1 times
...
...
Miandradee
Highly Voted 2 years, 11 months ago
Selected Answer: A
"To ensure that users of iOS and Android devices can only access work or school content using Outlook for iOS and Android, you need a Conditional Access policy that targets those potential users." https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/secure-email-recommended-policies?view=o365-worldwide#require-that-ios-and-android-devices-must-use-outlook
upvoted 9 times
Miandradee
2 years, 11 months ago
" If you want to limit access to Outlook for iOS and Android, you will need to obtain Azure Active Directory Premium licenses and leverage the conditional access policies" https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/outlook-for-ios-and-android/secure-outlook-for-ios-and-android#leveraging-basic-mobility-and-security-for-microsoft-365
upvoted 5 times
...
...
dcengineer2
Most Recent 10 months, 2 weeks ago
The answer does not appear to be listed. Should be: a mobile device mailbox policy in Exchange Online.
upvoted 1 times
...
[Removed]
11 months, 3 weeks ago
Agree , the correct answer is D since, conditional Access not available in Office 365 E3 Licenses if they used M365 E3, it should be A
upvoted 1 times
...
Hansie078
1 year ago
A is not correct because you need an Azure Premium P1 license for Conditional Access polcies!
upvoted 1 times
...
Jo2241
1 year, 6 months ago
D for sure: Conditional access and Intune or not present in 0365 E3 !
upvoted 1 times
...
nosmanav
1 year, 9 months ago
I think answer A. You will need an Azure AD Premium P1 license to get access to the Microsoft Office 365 conditional access policy feature wich is inclused in Microsoft 365 E3 (https://www.microsoft.com/en-us/microsoft-365/enterprise/e3?rtc=1&activetab=pivot%3aoverviewtab).
upvoted 1 times
Forkbeard
1 year, 9 months ago
Azure Active Directory Premium plan 1 is included in Microsoft 365 E3, not in Office 365 E3. Source: https://www.microsoft.com/en-us/microsoft-365/enterprise/compare-microsoft-365-and-office-365
upvoted 3 times
...
...
45xi
2 years, 2 months ago
C is the correct answer. https://docs.microsoft.com/en-us/mem/intune/apps/app-protection-policy#app-protection-policies-for-microsoft-office-apps
upvoted 3 times
PawelNotts
2 years, 1 month ago
Intune is not free, we only have a O365 E3 license here and neither Intune nor Azure P1 are part of it.
upvoted 1 times
...
...
miul84
2 years, 4 months ago
Approved Application List: This setting stores a list of approved applications that can be run on the mobile device. ApprovedApplicationList: The ApprovedApplicationList parameter specifies a configured list of approved applications for the device The explaination in the revealed solution area doesnt make any sense, because this settings defines what apps are allowed on the mobile and not what apps are allowed to connect to the Mailbox. if you want to do this without CA then this is the way (but its not in the answers): Create the default block rule: Set-ActiveSyncOrganizationSettings -DefaultAccessLevel Block Create an allow rule for Outlook for iOS and Android New-ActiveSyncDeviceAccessRule -Characteristic DeviceModel -QueryString "Outlook for iOS and Android" -AccessLevel Allow
upvoted 2 times
...
UWSFish
2 years, 8 months ago
Selected Answer: D
I think the answer that will be marked correct by Microsoft...is D. This is really a question about CA and licensing.
upvoted 6 times
...
techguy06
2 years, 8 months ago
Selected Answer: A
To benefit from the Conditional Access App Control capabilities in Defender for Cloud Apps, users must also be licensed for Azure Active Directory P1, which is included in Enterprise Mobility + Security F1/F3/E3/A3/G3, Enterprise Mobility + Security E5, Microsoft 365 E3/A3/G3, Microsoft 365 E5/A5/G5, and Microsoft 365 E5/A5/G5/F5 Security and Microsoft 365 F5 Security & Compliance. https://docs.microsoft.com/en-CA/office365/servicedescriptions/microsoft-365-service-descriptions/microsoft-365-tenantlevel-services-licensing-guidance/microsoft-365-security-compliance-licensing-guidance#azure-active-directory-identity-protection
upvoted 3 times
mithikx
2 years, 5 months ago
They said Office 365 E3, not Microsoft 365 E3. Theres a difference
upvoted 5 times
...
...
Baba65Baba
2 years, 8 months ago
Agree with Cbruce, the correct option isn't provided in the list.
upvoted 3 times
Nyamnyam
1 year ago
Agree, baba, "connection filtering" is Allow/Block/Safe IP Lists in EXO. CAP, on the other hand, requires AAD P1 and O365 did NOT have it included. Now, we are speaking about a legacy MSFT exam here. If you answer with D, you will get the credits, but MSFT would know (if they track this somehow) that you were braindumped.
upvoted 1 times
...
...
KennethYY
3 years, 1 month ago
D is not correct, the EOP connection Filter is for add the IP into trust IP E3 already include Azure Active Directory Premium plan 1 and which already have Azure AD Conditional Access https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-licensing#available-versions-of-azure-ad-multi-factor-authentication
upvoted 5 times
psycho202
3 years ago
Office365 E3 does NOT contain Azure AD Premium plan 1, so conditional access is not the solution either. Microsoft365 E3 does contain Azure AD Premium Plan 1.
upvoted 5 times
...
...
tendymadu
3 years, 2 months ago
Answer is A https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/outlook-for-ios-and-android/secure-outlook-for-ios-and-android
upvoted 2 times
...
wainse
3 years, 2 months ago
I think it is A, from the link posted by Cbruce
upvoted 2 times
tochno
3 years, 2 months ago
Agree, correct answer is A Block all email apps except Outlook for iOS and Android using conditional access https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/outlook-for-ios-and-android/secure-outlook-for-ios-and-android#block-all-email-apps-except-outlook-for-ios-and-android-using-conditional-access
upvoted 4 times
...
...
FlyG6
3 years, 2 months ago
could the answer be "A" ?
upvoted 1 times
FlyG6
3 years, 2 months ago
Apologies, the answer is C - an app protection policy Microsoft Endpoint Manager. Definitely Not A.
upvoted 3 times
FlyG6
3 years, 2 months ago
I take that back. The correct answer would be an Exchange ActiveSync device access rule! Which is not listed here at al...
upvoted 5 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago