QuestionQ32

Govern and secure Microsoft 365 tenants and workloads

Contoso, Ltd. is a consulting company with a main office in San Francisco and a branch office in Dallas.

Existing Environment

Microsoft Entra configuration

Contoso has an Azure subscription.

Contoso has a Microsoft 365 E5 subscription.

Contoso has a Microsoft Entra tenant named contoso.com. The tenant includes an administrative unit named AU1 with the following membership rule:

(device.deviceTrustType –eq “Workplace”) and (device.deviceOSType –in [“Windows”, “Android”])

The tenant contains the cloud-only users shown in the following table.

Scenario Image

The tenant contains the groups shown in the following table.

Scenario Image

The tenant contains the devices shown in the following table.

Scenario Image

All devices are managed by using Microsoft Intune.

Microsoft Entra authentication methods

Contoso has an Authentication methods policy for Microsoft Authenticator with the following settings:

  • Include: Group1
  • Exclude: Group3
  • Authentication mode: Passwordless

Privileged Identity Management (PIM) configuration

Privileged roles are managed by using Privileged Identity Management (PIM).

The PIM settings for the AI Administrator role are configured as shown in the following table.

Scenario Image

Email configuration

Each user has a Microsoft Exchange mailbox.

Contoso has an anti-spam outbound policy named Antispam1 with the following configurations:

  • Included groups: Group4
  • Excluded users: User2
  • Set an external message limit: 3
  • Set an internal message limit: 5
  • Set a daily message limit: 13
  • Restriction placed on users who reach the message limit: Restrict the user from sending mail

Microsoft SharePoint configuration

Contoso has a Microsoft SharePoint site named Site1 that stores the following content types and various other documents:

  • Project documents: All documents have a project code that includes the letters PR, followed by a dash and nine digits (for example PR-123456789).
  • Proposal documents: All documents have a customer ID that includes seven to 10 alphanumerical characters. All customer IDs are recorded in a Microsoft Excel workbook.
  • Feedback forms: All documents were created by using the same template.

Microsoft AI services

Contoso implements the following Microsoft AI services:

  • Microsoft 365 Copilot for selected users
  • Microsoft Foundry agents, including an agent named Agent1

Requirements

Planned changes

Contoso plans to implement the following changes:

  • Issue new Android devices to the Group1 users.
  • Assign Microsoft 365 Copilot licenses to the users in Group1.
  • Add an additional email address alias for the users in Group4.
  • Create a Conditional Access policy named CAPolicy1 for Group3.
  • Disable web search for Microsoft 365 Copilot and Microsoft 365 Copilot Chat.
  • Create classifiers to identify project documents and proposal documents stored on Site1.

Technical requirements

Contoso identifies the following technical requirements:

  • The users in Group3 who access Microsoft 365 resources from anonymous IP addresses must complete multifactor authentication (MFA).
  • Microsoft 365 Copilot responses must NOT use content from the project documents stored on Site1.
  • Microsoft 365 Copilot responses must use content from only Microsoft 365 locations.
  • The total costs of Agent1 must be monitored and evaluated monthly.
  • All Android devices must be registered in Microsoft Entra.
  • Administrative effort must be minimized.
  • Administrative costs must be minimized.

You need to assess the configuration of AU1.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Yes or No
StatementsYesNo
Admin1 can add Device1 to AU1 directly.
Device2 is member of AU1.
The devices issued to Group1 will be added to AU1 automatically.
Explanation

AU1’s dynamic rule includes only devices whose trust type is Workplace and whose operating system is Windows or Android. Device2 is Microsoft Entra registered Windows and therefore matches. Device1 is Microsoft Entra joined, not Workplace/registered, and dynamic administrative-unit membership cannot be changed by directly adding the device. Group1 user membership is not part of AU1’s device rule, so devices issued to its users are not automatically included solely for that reason.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!