nerdexam
Microsoft

MS-900 · Question #148

An organization uses Microsoft 365 Business to secure their data. Many users install the organization's data on their personal tablets and phones. You need to protect the organization's data stored…

The correct answer is A. Remotely wiping company data D. Automatically deleting files after 90 days of inactivity E. Requiring users to have a PIN on their device. Microsoft 365 Business provides mobile device management (MDM) features to protect organizational data on personal devices through Intune-based policies. Three key features address data security directly on user devices.

Submitted by yousef_jo· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

An organization uses Microsoft 365 Business to secure their data. Many users install the organization's data on their personal tablets and phones. You need to protect the organization's data stored on users' devices. Which three features support device security? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options

  • ARemotely wiping company data
  • BEnabling Advanced Threat Protection for users
  • CDisabling the device remotely
  • DAutomatically deleting files after 90 days of inactivity
  • ERequiring users to have a PIN on their device

How the community answered

(29 responses)
  • A
    83% (24)
  • B
    7% (2)
  • C
    10% (3)

Why each option

Microsoft 365 Business provides mobile device management (MDM) features to protect organizational data on personal devices through Intune-based policies. Three key features address data security directly on user devices.

ARemotely wiping company dataCorrect

Remote wipe is a core MDM feature in Microsoft 365 Business that allows administrators to selectively remove company data from a user's personal device without affecting personal data, directly protecting organizational data if a device is lost, stolen, or an employee leaves.

BEnabling Advanced Threat Protection for users

Advanced Threat Protection (now Microsoft Defender for Office 365) is an email and collaboration security feature focused on protecting against phishing and malware in messages, not a device-level data protection control for personal tablets and phones.

CDisabling the device remotely

Microsoft 365 Business MDM does not support remotely disabling (locking out) a personal device entirely; full device lock/disable is typically limited to fully managed/enrolled corporate-owned devices and is not a standard feature available for BYOD scenarios in this tier.

DAutomatically deleting files after 90 days of inactivityCorrect

Microsoft 365 Business allows policies that automatically delete company app data after a defined period of inactivity (such as 90 days), ensuring stale or abandoned data on personal devices does not remain accessible indefinitely.

ERequiring users to have a PIN on their deviceCorrect

Requiring a PIN on the device is an app protection policy feature in Microsoft 365 Business/Intune that enforces access controls, preventing unauthorized users from accessing organizational data if a device is left unattended or lost.

Concept tested: Microsoft 365 Business MDM device data protection policies

Source: https://learn.microsoft.com/en-us/microsoft-365/business-premium/m365bp-manage-devices?view=o365-worldwide

Topics

#device security#mobile device management#data protection#remote wipe#PIN enforcement

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice