nerdexam
Microsoft

MS-900 · Question #9

A company plans to migrate to Microsoft 365. You need to advise the company about how Microsoft provides protection in a multitenancy environment. What are three ways that Microsoft provides…

The correct answer is A. Customer content at rest is encrypted on the server by using BitLocter. B. Microsoft Azure AD provides authorization and role based access control at the tenant layer. F. Mailbox databases in Microsoft Exchange Online contain mailboxes from multiple tenants. Microsoft 365 multitenancy protection relies on encryption at rest via BitLocker, Azure AD for tenant-layer access control, and logical separation of mailboxes across shared databases. Understanding these mechanisms is key to advising on cloud security architecture.

Submitted by tarun92· Mar 5, 2026Security

Question

A company plans to migrate to Microsoft 365. You need to advise the company about how Microsoft provides protection in a multitenancy environment. What are three ways that Microsoft provides protection? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • ACustomer content at rest is encrypted on the server by using BitLocter.
  • BMicrosoft Azure AD provides authorization and role based access control at the tenant layer.
  • CCustomer content at rest is encrypted on the server by using transport layer security (TLS).
  • DMicrosoft Azure AD provides authorization and role based access control at the transport layer.
  • EMailbox databases in Microsoft Exchange Online contain only mailboxes from a single tenant.
  • FMailbox databases in Microsoft Exchange Online contain mailboxes from multiple tenants.

How the community answered

(47 responses)
  • A
    83% (39)
  • C
    9% (4)
  • D
    6% (3)
  • E
    2% (1)

Why each option

Microsoft 365 multitenancy protection relies on encryption at rest via BitLocker, Azure AD for tenant-layer access control, and logical separation of mailboxes across shared databases. Understanding these mechanisms is key to advising on cloud security architecture.

ACustomer content at rest is encrypted on the server by using BitLocter.Correct

BitLocker is Microsoft's disk-level encryption technology used to encrypt customer content at rest on servers in Microsoft 365 datacenters, providing a baseline layer of data protection even if physical media is compromised.

BMicrosoft Azure AD provides authorization and role based access control at the tenant layer.Correct

Microsoft Azure AD enforces authorization and role-based access control (RBAC) at the tenant layer, ensuring that identities and permissions are scoped to a specific tenant and preventing cross-tenant access to resources.

CCustomer content at rest is encrypted on the server by using transport layer security (TLS).

TLS (Transport Layer Security) encrypts data in transit between clients and servers, not data at rest on the server, making it incorrect in the context of server-side at-rest encryption.

DMicrosoft Azure AD provides authorization and role based access control at the transport layer.

Azure AD provides authorization at the tenant layer, not at the transport layer; transport-layer security is handled by TLS/encryption protocols, not identity and access management services.

EMailbox databases in Microsoft Exchange Online contain only mailboxes from a single tenant.

Exchange Online mailbox databases do not contain only a single tenant's mailboxes; they are shared across multiple tenants, with logical access controls providing the required isolation between tenants.

FMailbox databases in Microsoft Exchange Online contain mailboxes from multiple tenants.Correct

In Exchange Online, mailbox databases are designed to contain mailboxes from multiple tenants; logical isolation rather than physical separation is used, with Azure AD and Exchange access controls ensuring tenant data boundaries are enforced.

Concept tested: Microsoft 365 multitenancy security and data isolation

Source: https://learn.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-tenant-isolation-overview

Topics

#Multitenancy security#Data encryption#Access control#Shared responsibility

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice