CertavoPrepare. Certify. Excel.
Open menu
AB-900MicrosoftFundamentals

AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals

This exam is intended for candidates who are familiar with Microsoft 365, including core services, security, identity and access, data protection, governance, Microsoft 365 Copilot, and agents. Candidates should understand the admin centers used for Microsoft 365 workloads such as Exchange Online, SharePoint, Teams, Microsoft Entra, and Microsoft Purview, and have experience with AI-driven productivity tools and modern IT management practices. The exam measures knowledge of Microsoft 365 objects and security features, data protection and governance for Microsoft 365 and Copilot, and basic administration of Copilot and agents.

What you get with membership

  • The full AB-900 question bank with detailed explanations
  • Readiness tracking by objective so you know when you're ready
  • Access to every other exam in the Certavo library
  • Content kept in step with the latest exam objectives

AB-900 exam objectives and study guide

The skills measured on the AB-900 exam, by objective domain. Percentages are the share of the exam each domain carries.

Understand data protection and governance tasks for Microsoft 365 and Copilot

37.5% of the exam
  • Understand Microsoft Purview
  • Understand features and capabilities of Microsoft Purview Information Protection, Microsoft Purview Data Loss Prevention (DLP), Microsoft Purview Insider Risk Management, Microsoft Purview Communication Compliance, Microsoft Purview Data Security Posture Management (DSPM) for AI, and Microsoft Purview Data Lifecycle Management
  • Identify the use cases for sensitivity labels in Microsoft Purview
  • Understand data classification in Microsoft Purview
  • Understand retention
  • Understand data security implications of Copilot
  • Understand how Copilot accesses data
  • Understand how Microsoft Graph influences Copilot responses
  • Understand how Copilot uses permissions and other controls in Microsoft 365, Microsoft Purview, and Microsoft Defender to protect against risks
  • Understand responsible AI principles
  • Identify data protection and governance risks for Microsoft 365 and Copilot
  • Identify compliance risks and recommendations by using Microsoft Purview Compliance Manager
  • Identify sensitive information by using Microsoft Purview Data Explorer
  • Identify risks by using Insider Risk Management
  • Identify and respond to alerts generated by Microsoft Purview DLP
  • Identify policy violations generated by Communication Compliance
  • Identify user activities reported by Microsoft Purview activity explorer
  • Discover and manage AI activity by using DSPM for AI
  • Search for files and emails by using Content search in Microsoft Purview eDiscovery
  • Identify and monitor oversharing in SharePoint in Microsoft 365
  • Identify the tools to troubleshoot oversharing in an organization
  • Run a data access governance report in SharePoint
  • Understand features and capabilities of SharePoint Advanced Management, including restricted access control

Identify the core features and objects of Microsoft 365 services

32.5% of the exam
  • Identify the core objects of Microsoft 365 services
  • Explain how license types assigned to users and groups affect access to Microsoft 365 features
  • Explore the organization configurations by using the Microsoft 365 admin center (domain names and org settings)
  • Identify the appropriate objects to configure by using the Exchange admin center (mailboxes and distribution groups)
  • Identify the appropriate objects to configure by using the SharePoint admin center (sites, libraries, and folders)
  • Identify the appropriate roles and permissions for sites in SharePoint in Microsoft 365
  • Identify the appropriate objects to configure by using the Teams admin center (teams, channels, and policies)
  • Understand the Microsoft 365 security principles
  • Explain the core Zero Trust principles
  • Understand authorization
  • Understand authentication methods
  • Understand threat protection and intelligence
  • Understand features and capabilities of Microsoft Defender XDR
  • Identify the core security features of Microsoft 365 services
  • Understand features and capabilities of Microsoft Entra ID
  • Understand conditional access policies
  • Understand the purpose and benefits of SSO
  • Identify the appropriate security object to use in an organization (users and groups)
  • Identify the appropriate tools to troubleshoot common sign-in issues (multifactor authentication [MFA], conditional access, and risky sign-ins)
  • Interpret Identity Secure Score in Microsoft Entra ID
  • Use the appropriate tools to review audit logs for user and admin activity
  • Identify the role of Privileged Identity Management (PIM) in an organization
  • Understand App registrations and Enterprise apps

Perform basic administrative tasks for Copilot and agents

27.5% of the exam
  • Understand features and capabilities of Copilot and agents
  • Compare the built-in capabilities of Copilot and agents
  • Compare Copilot monthly license model to pay-as-you-go, including SharePoint
  • Identify which Copilot features can be enabled or disabled
  • Identify use cases for Researcher
  • Identify use cases for Analyst
  • Identify use cases for custom agents
  • Perform basic administrative tasks for Copilot
  • Assign Copilot licenses
  • Monitor and manage Copilot pay-as-you-go billing policies
  • Monitor Copilot usage and adoption, including Copilot Analytics and the Microsoft 365 admin center
  • Manage prompts, including saving, sharing, scheduling, and deleting
  • Perform basic administrative tasks for agents
  • Identify how to configure user access to agents
  • Create an agent
  • Understand approval process for agents
  • Monitor agents, including usage, operational insights, and agent lifecycle, by working with the Microsoft 365 admin center and the Microsoft Power Platform admin center

AB-900 practice questions and answers

11 free sample questions from the AB-900 bank, with the correct answer and a full explanation for each. These are original questions written to the Microsoft objective domains — not real exam content.

  1. Question 1Identify the core features and objects of Microsoft 365 services

    During a sign-in test, the browser already has active sessions for two organizational users. The authorization request omits optional parameters that influence the user prompt. What is the default behavior?

    • AThe account picker is displayed so the user can choose a session
    • BOne of the current sessions is selected silently
    • CThe login page is shown as if no session exists
    • DThe user is redirected to an admin consent page
    Show answer and explanation

    Correct answer

    • The account picker is displayed so the user can choose a session

    Explanation

    When optional prompt-related parameters are omitted, the Microsoft identity platform uses default behavior. If multiple users are signed in, it shows the account picker.

    • Silently using one account is the default only when there is a sole current user.
    • Showing the login page is the default when no user is signed in.
    • Showing an admin consent page is not the default behavior merely because multiple sessions exist.
    • Restricting selection to personal Microsoft accounts would require a different tenant endpoint choice, such as consumers.

    References:

  2. Question 2Identify the core features and objects of Microsoft 365 services

    A modern SharePoint communication site uses the default SharePoint permission groups. You need to use only those default groups. Auditors must be able to read pages and documents. Content coordinators must be able to create and maintain pages, lists, and documents but must not manage site permissions or site settings. Which two assignments should you make?

    • AAdd the auditors to the site Visitors group.
    • BAdd the content coordinators to the site Members group.
    • CAdd the auditors to the site Members group.
    • DAdd the content coordinators to the site Owners group.
    • EAssign the content coordinators the SharePoint Administrator role.
    Show answer and explanation

    Correct answers

    • Add the auditors to the site Visitors group.
    • Add the content coordinators to the site Members group.

    Explanation

    The auditors should be added to the site's Visitors group because the default permission level is Read. The content coordinators should be added to the site's Members group because the default permission level is Edit, which supports maintaining site content without granting Full Control over the site.

    Adding auditors to Members would grant edit permissions. Adding coordinators to Owners would grant Full Control, including permission management. Assigning the SharePoint Administrator role would be a tenant-level administrative role and is not least privilege for maintaining one site.

    References:

  3. Question 3Perform basic administrative tasks for Copilot and agents

    Best For You Organics wants a first draft of a researched brief that synthesizes several Microsoft 365 documents and current web information. Which capability is designed for this use case?

    • AMicrosoft 365 Copilot Researcher
    • BMicrosoft 365 Copilot Analyst
    • CMicrosoft Copilot Studio
    • DMicrosoft Purview Communication Compliance
    Show answer and explanation

    Correct answer

    • Microsoft 365 Copilot Researcher

    Explanation

    Microsoft 365 Copilot Researcher is designed for researched briefs and other complex synthesis tasks that can combine relevant work content and web information.

    • Analyst is for data analysis and visualizations.
    • Copilot Studio is for creating or extending agents, especially for custom processes.
    • Microsoft Purview Communication Compliance is for compliance review workflows, not research brief generation.

    References:

  4. Question 4Understand data protection and governance tasks for Microsoft 365 and Copilot

    Users report that generative AI adoption is growing faster than the governance team can evaluate it. The team needs a Purview starting point that discovers AI usage across Copilot experiences, enterprise AI apps, and other detected generative AI apps, and then recommends protection and compliance controls. Which solution should the team use first?

    • AMicrosoft Purview Data Security Posture Management for AI
    • BActivity explorer in Microsoft Purview data classification
    • CContent explorer in Microsoft Purview data classification
    • DMicrosoft Purview Data Lifecycle Management
    Show answer and explanation

    Correct answer

    • Microsoft Purview Data Security Posture Management for AI

    Explanation

    Microsoft Purview Data Security Posture Management for AI is designed as the front door for discovering, securing, and applying compliance controls for AI usage. It provides insights, recommendations, and policy actions for supported Copilot experiences, enterprise AI apps, and other detected AI apps.

    • Activity explorer shows user activity on classified, labeled, or protected items, but it is not the AI governance front door.
    • Content explorer helps investigate sensitive content locations; it does not provide the AI-app discovery and recommendation experience described.
    • Data Lifecycle Management manages retention and deletion, not AI usage discovery and posture recommendations.

    References:

  5. Question 5Understand data protection and governance tasks for Microsoft 365 and Copilot

    For an initial information-protection rollout, the security architect lists two needs: detect credit card numbers by using patterns, validation, and supporting evidence; and apply encryption plus visual markings that travel with Office content. Which two Microsoft Purview features fit these needs?

    • ASensitive information types
    • BSensitivity labels
    • CData Lifecycle Management retention policies
    • DCommunication Compliance policies
    • EInsider Risk Management cases
    Show answer and explanation

    Correct answers

    • Sensitive information types
    • Sensitivity labels

    Explanation

    The correct features are sensitive information types and sensitivity labels.

    • Sensitive information types detect data by using patterns such as regular expressions or functions, plus evidence such as keywords, confidence levels, and proximity.
    • Sensitivity labels classify and protect data with actions such as encryption, access restrictions, and visual markings.
    • Data Lifecycle Management retention policies control how long content is kept or deleted.
    • Communication Compliance reviews risky communications.
    • Insider Risk Management detects and investigates risky user behavior.

    References:

  6. Question 6Understand data protection and governance tasks for Microsoft 365 and Copilot

    After Microsoft 365 Copilot is enabled, several employees say Copilot can summarize a merger-planning workbook. The workbook is stored in a Teams-connected SharePoint site where a broad sales group has Read access, but only the legal team should use the content in Copilot or search. Which two actions directly reduce the Microsoft Graph access signals that make that workbook available to unauthorized users while keeping legal access?

    • ARemove the broad sales group from the SharePoint site, library, or item permissions and grant access only to the legal group.
    • BApply a sensitivity label that encrypts the workbook and grants usage rights only to the legal group.
    • CApply a retention label that keeps the workbook for seven years.
    • DEnable mailbox litigation hold for the legal team.
    • ECreate a communication compliance policy to detect messages that mention the merger.
    • FDisable external sharing for the SharePoint site while leaving the internal sales group with Read access.
    Show answer and explanation

    Correct answers

    • Remove the broad sales group from the SharePoint site, library, or item permissions and grant access only to the legal group.
    • Apply a sensitivity label that encrypts the workbook and grants usage rights only to the legal group.

    Explanation

    Copilot is permission-aware because it uses Microsoft Graph and Microsoft 365 access controls to ground responses. Removing the broad sales group from the SharePoint permissions reduces the set of users for whom the workbook is available. Applying a sensitivity label that encrypts the workbook and grants rights only to the legal group adds protection that Copilot honors when evaluating whether a user can access the content.

    • A retention label controls how long content is kept or deleted; it does not remove user access or search visibility.
    • Litigation hold preserves mailbox content and does not control SharePoint workbook permissions.
    • Communication compliance policies help detect and review communications; they do not remove Microsoft Graph access to the workbook.
    • Disabling external sharing does not address the internal sales group that still has Read access.

    References:

  7. Question 7Understand data protection and governance tasks for Microsoft 365 and Copilot

    Mei, a program manager, must map a Copilot adoption requirement to a responsible AI principle. The requirement says users must be told when content is AI-generated, what the tool can and cannot do, and why they should verify important outputs. Which principle is being addressed?

    • AFairness
    • BTransparency
    • CReliability and safety
    • DPrivacy and security
    Show answer and explanation

    Correct answer

    • Transparency

    Explanation

    The requirement addresses transparency. Transparency means people should understand that they are interacting with AI-generated content, the system’s intended use and limitations, and the need to verify outputs.

    • Fairness focuses on avoiding unfair bias and unequal treatment.
    • Reliability and safety focuses on dependable behavior and risk reduction.
    • Privacy and security focuses on protecting data and access.
    • Transparency is the principle that most directly matches disclosure, limitations, and explainability.

    References:

  8. Question 8Understand data protection and governance tasks for Microsoft 365 and Copilot

    A policy review board requires a guardrail for employees who use Microsoft 365 Copilot to summarize regulatory filings and prepare client-ready explanations. The guardrail must address the responsible AI principle of reliability and safety without disabling Copilot or changing existing Microsoft 365 permissions. Which policy statement should be included?

    • AEmployees must verify Copilot summaries against authoritative source documents and remain responsible for final client-ready content.
    • BEmployees may send a Copilot answer without review when the response includes one or more source citations.
    • CAdministrators should disable Microsoft Purview Audit search for Copilot activity to reduce the amount of generated content retained for review.
    • DThe legal team should treat Microsoft Graph-grounded Copilot output as an authoritative legal interpretation of the source filing.
    • ESite owners should grant broad read access to the filings library so Copilot has more context for every employee.
    Show answer and explanation

    Correct answer

    • Employees must verify Copilot summaries against authoritative source documents and remain responsible for final client-ready content.

    Explanation

    The best guardrail is to require human verification against authoritative sources before Copilot-assisted content is used for client communication or decision-making. This addresses reliability and safety because generated responses can be incorrect or incomplete even when grounded in organizational data.

    • Treating cited content as automatically approved is unsafe; a citation helps review but does not replace verification.
    • Disabling audit search would reduce accountability and investigation capability.
    • Assuming Copilot output is legally authoritative because it is grounded in Microsoft Graph confuses grounding with correctness.
    • Removing access controls for a document library would violate privacy and security and increase oversharing risk.

    References:

  9. Question 9Understand data protection and governance tasks for Microsoft 365 and Copilot

    Wide World Importers will publish a Microsoft Copilot Studio agent that answers internal HR policy questions. The agent must be reviewed using responsible AI principles before release. Select the appropriate steps and place them in the correct order.

    Place the correct items in order

    • Define the intended use, affected users, out-of-scope requests, and harms the agent must avoid.
    • Configure approved knowledge sources, actions, authentication, and Power Platform data policies so the agent uses only permitted data.
    • Add safe-response instructions, citation expectations, fallback behavior, and human escalation paths for sensitive or unsupported questions.
    • Test with representative, accessibility, multilingual, and adversarial prompts; remediate biased, unsafe, or unsupported responses.
    • Publish with a named accountable owner and monitor analytics, audit, and feedback for ongoing improvement.
    • Publish the agent first so real user prompts can be collected before the intended use is documented.
    • Remove citations from generated answers so HR policy responses are shorter and easier to read.
    • Add all available connectors to maximize grounding before applying data policies or authentication controls.
    • Grant every maker the Environment Admin role for the pilot so governance reviews do not delay changes.
    Show answer and explanation

    Correct answers

    • 1. Define the intended use, affected users, out-of-scope requests, and harms the agent must avoid.
    • 2. Configure approved knowledge sources, actions, authentication, and Power Platform data policies so the agent uses only permitted data.
    • 3. Add safe-response instructions, citation expectations, fallback behavior, and human escalation paths for sensitive or unsupported questions.
    • 4. Test with representative, accessibility, multilingual, and adversarial prompts; remediate biased, unsafe, or unsupported responses.
    • 5. Publish with a named accountable owner and monitor analytics, audit, and feedback for ongoing improvement.

    Explanation

    A responsible AI review starts by defining the intended use and risks, then configures data and access controls, designs safe behavior, validates the agent, and monitors after release.

    1. Define the intended use, affected users, out-of-scope requests, and harms to avoid.

    2. Configure approved knowledge sources, actions, authentication, and Power Platform data policies so the agent uses only permitted data.

    3. Add safe-response instructions, source citation expectations, fallback behavior, and human escalation paths.

    4. Test with representative, accessibility, multilingual, and adversarial prompts; then remediate biased, unsafe, or unsupported responses.

    5. Publish with an accountable owner and monitor analytics, audit, and feedback so the agent can be improved.

    Publishing first, removing citations, adding every connector, or granting broad environment administration rights would increase risk and undermine responsible AI governance.

    References:

  10. Question 10Understand data protection and governance tasks for Microsoft 365 and Copilot

    Tomasz, an information protection architect, must protect board-pack documents stored in SharePoint. Executives must keep using Microsoft 365 Copilot for meetings and email, and they must still be able to open the board-pack files for viewing. Only board secretaries should be able to use Copilot to summarize or reuse content from those files. The solution must not remove the site from search for the board secretaries. What should Tomasz configure?

    • APublish a sensitivity label that applies encryption; grant board secretaries rights that include content extraction and grant executives view-only rights.
    • BPublish a sensitivity label that applies only a header, footer, and watermark; leave the SharePoint permissions unchanged.
    • CApply a Microsoft Purview retention label with a disposition review to all board-pack files.
    • DRemove the SharePoint site from organization-wide search by using Restricted SharePoint Search.
    • EDisable the Microsoft 365 Copilot service plan for executives and leave the file permissions unchanged.
    Show answer and explanation

    Correct answer

    • Publish a sensitivity label that applies encryption; grant board secretaries rights that include content extraction and grant executives view-only rights.

    Explanation

    A sensitivity label that applies encryption and assigns different usage rights is the best fit.

    • The correct option keeps the files in SharePoint and searchable for authorized users, while using Microsoft Purview Information Protection encryption rights to control how protected content can be used. Copilot respects Microsoft 365 permissions and protection applied to content.
    • A watermark-only label provides a visual marking but does not restrict access or usage rights.
    • A retention label controls lifecycle and disposition; it does not prevent Copilot from using content that a user can access.
    • Restricted search would be a broad search-discovery control and would not provide per-person usage rights for the same files.
    • Removing Copilot licenses from executives violates the requirement that they continue using Copilot for other work and does not protect the documents at the data layer.

    References:

  11. Question 11Understand data protection and governance tasks for Microsoft 365 and Copilot

    As the newly assigned Copilot administrator, you need to answer a basic security question from a department manager: what determines whether a user can ask Microsoft 365 Copilot to summarize a Teams channel file?

    • AThe user’s existing Microsoft 365 permissions to the file, evaluated through Microsoft Graph.
    • BWhether the file content was included in the large language model’s public training data.
    • CWhether the user has the Global Reader role in Microsoft Entra ID.
    • DWhether a Microsoft Purview retention label has been published to the file’s site.
    Show answer and explanation

    Correct answer

    • The user’s existing Microsoft 365 permissions to the file, evaluated through Microsoft Graph.

    Explanation

    Microsoft 365 Copilot uses the signed-in user’s Microsoft 365 identity, Microsoft Graph, and existing permissions to ground responses in organizational data. A Copilot license enables access to the Copilot experience, but it does not grant access to files that the user could not otherwise access.

    The other options confuse Copilot access with model training, admin roles, or retention configuration. Those do not determine whether a specific user can access a Teams channel file through Copilot.

    References:

Membership includes 161 questions and explanations aligned to the AB-900 curriculum.

Other Microsoft certifications

Every one of these is included with the same membership as AB-900.

AB-900 exam FAQ

How many questions are on the AB-900 exam?+

The AB-900 (Microsoft 365 Copilot and Agent Administration Fundamentals) exam has around 45 questions. Question counts vary slightly between exam forms, so treat this as the typical number rather than a guarantee.

How long is the AB-900 exam?+

You get 45 minutes for the AB-900 exam itself. Allow extra time at the test centre or for the online check-in process before the timer starts.

What level is AB-900?+

AB-900 is a Microsoft fundamentals-level certification, so it assumes no prior certification and is a common starting point.

Are there free AB-900 practice questions?+

Yes. 11 free AB-900 practice questions are on this page, each with the correct answer and a full explanation. The complete bank of 161 questions is included with membership.

Are these real AB-900 exam questions?+

No. Every question is original, written to match the published AB-900 objective domains and question styles. Real exam content is confidential, and reusing it would breach Microsoft's exam policies.