nerdexam
Microsoft

MS-900 · Question #33

Hotspot Question A company plans to deploy Microsoft Intune. Which scenarios can you implement by using Intune? To answer, select the appropriate answer for the given scenarios. NOTE: Each correct sel

The correct answer is Intune app protection policies can protect access to Exchange Server on-premises mailboxes. = Yes; Intune app protection policies support apps that connect to on-premises Microsoft SharePoint Server. = Yes; Intune app protection policies require a mobile-device management (MDM) solution. = No. Intune App Protection Policies (MAM) can protect Exchange on-premises via Hybrid Modern Authentication, do not support SharePoint on-premises natively, and can operate without device enrollment (MDM).

Submitted by olafpl· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

Hotspot Question A company plans to deploy Microsoft Intune. Which scenarios can you implement by using Intune? To answer, select the appropriate answer for the given scenarios. NOTE: Each correct selection is worth one point. Answer:

Exhibit

MS-900 question #33 exhibit

Answer Area

  • Intune app protection policies can protect access to Exchange Server on-premises mailboxes.Yes
  • Intune app protection policies support apps that connect to on-premises Microsoft SharePoint Server.Yes
  • Intune app protection policies require a mobile-device management (MDM) solution.No

Explanation

Intune App Protection Policies (MAM) can protect Exchange on-premises via Hybrid Modern Authentication, do not support SharePoint on-premises natively, and can operate without device enrollment (MDM).

Approach. 1. 'Yes' for Exchange on-premises: Intune App Protection Policies (APP) can protect access to Exchange Server on-premises mailboxes when using the Outlook mobile app configured with Hybrid Modern Authentication (HMA). 2. 'No' for SharePoint on-premises: Intune APP does not natively support protecting data accessed directly from on-premises SharePoint Servers using standard Microsoft mobile apps. 3. 'No' for requiring MDM: Intune App Protection Policies (MAM) can be applied to unmanaged devices (MAM without enrollment, or MAM-WE). A full Mobile Device Management (MDM) solution is not required, making it ideal for BYOD scenarios.

Common mistakes.

  • common_mistake. Test-takers often confuse MAM with MDM, assuming that any Intune policy requires full device enrollment (MDM), which leads to incorrectly answering 'Yes' to the third statement. Additionally, users might assume that because Exchange on-premises is supported (via HMA), SharePoint on-premises must also be supported, which is incorrect.

Concept tested. Microsoft Intune App Protection Policies (MAM), Mobile Application Management without Enrollment (MAM-WE), and Hybrid Modern Authentication (HMA) integration.

Reference. https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy

Topics

#Intune app protection#Exchange on-premises#SharePoint on-premises#MDM enrollment

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice