MS-900 · Question #9
A company plans to migrate to Microsoft 365. You need to advise the company about how Microsoft provides protection in a multitenancy environment. What are three ways that Microsoft provides…
The correct answer is A. Customer content at rest is encrypted on the server by using BitLocter. B. Microsoft Azure AD provides authorization and role based access control at the tenant layer. F. Mailbox databases in Microsoft Exchange Online contain mailboxes from multiple tenants. Microsoft 365 multitenancy protection relies on encryption at rest via BitLocker, Azure AD for tenant-layer access control, and logical separation of mailboxes across shared databases. Understanding these mechanisms is key to advising on cloud security architecture.
Question
Options
- ACustomer content at rest is encrypted on the server by using BitLocter.
- BMicrosoft Azure AD provides authorization and role based access control at the tenant layer.
- CCustomer content at rest is encrypted on the server by using transport layer security (TLS).
- DMicrosoft Azure AD provides authorization and role based access control at the transport layer.
- EMailbox databases in Microsoft Exchange Online contain only mailboxes from a single tenant.
- FMailbox databases in Microsoft Exchange Online contain mailboxes from multiple tenants.
How the community answered
(47 responses)- A83% (39)
- C9% (4)
- D6% (3)
- E2% (1)
Why each option
Microsoft 365 multitenancy protection relies on encryption at rest via BitLocker, Azure AD for tenant-layer access control, and logical separation of mailboxes across shared databases. Understanding these mechanisms is key to advising on cloud security architecture.
BitLocker is Microsoft's disk-level encryption technology used to encrypt customer content at rest on servers in Microsoft 365 datacenters, providing a baseline layer of data protection even if physical media is compromised.
Microsoft Azure AD enforces authorization and role-based access control (RBAC) at the tenant layer, ensuring that identities and permissions are scoped to a specific tenant and preventing cross-tenant access to resources.
TLS (Transport Layer Security) encrypts data in transit between clients and servers, not data at rest on the server, making it incorrect in the context of server-side at-rest encryption.
Azure AD provides authorization at the tenant layer, not at the transport layer; transport-layer security is handled by TLS/encryption protocols, not identity and access management services.
Exchange Online mailbox databases do not contain only a single tenant's mailboxes; they are shared across multiple tenants, with logical access controls providing the required isolation between tenants.
In Exchange Online, mailbox databases are designed to contain mailboxes from multiple tenants; logical isolation rather than physical separation is used, with Azure AD and Exchange access controls ensuring tenant data boundaries are enforced.
Concept tested: Microsoft 365 multitenancy security and data isolation
Source: https://learn.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-tenant-isolation-overview
Topics
Community Discussion
No community discussion yet for this question.