Author: thedatacommunity

Identify which Copilot features can be enabled or disabled (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Identify which Copilot features can be enabled or disabled


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

One of the primary responsibilities of a Microsoft 365 Copilot administrator is understanding which Copilot features can be controlled through administrative settings. Organizations often have different security, compliance, and business requirements, so Microsoft provides administrators with the ability to enable or disable various Copilot capabilities at the tenant, service, and user levels.

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand:

  • Which Copilot capabilities administrators can control
  • Where these controls are configured
  • Why organizations may enable or disable specific features
  • Which capabilities are always governed by Microsoft 365 permissions rather than simple on/off settings
  • How licensing affects feature availability

Why Organizations Control Copilot Features

Organizations don’t always want every AI capability immediately available to every employee.

Common reasons include:

  • Meeting regulatory requirements
  • Protecting sensitive information
  • Conducting pilot deployments
  • Managing licensing costs
  • Limiting access to experimental features
  • Preventing users from accessing external AI services
  • Reducing organizational risk

Microsoft allows administrators to gradually introduce Copilot while maintaining governance.


Administrative Control Layers

Copilot features can be managed through several layers.

Control LayerPurpose
LicensingDetermines who is entitled to use Copilot
Microsoft 365 Admin CenterEnables or disables Copilot services and manages user assignments
Microsoft Entra IDControls user and group access
Microsoft PurviewApplies compliance, DLP, retention, sensitivity labels, and governance
SharePoint Advanced ManagementControls content access and oversharing protection
Microsoft DefenderProtects against threats affecting Copilot-accessible content
Individual Microsoft 365 AppsMay provide application-specific Copilot settings

These controls work together rather than independently.


Features That Can Be Enabled or Disabled

Administrators can control several Copilot capabilities.

1. Microsoft 365 Copilot Licenses

The most fundamental control is license assignment.

Without a license:

  • Users cannot access Microsoft 365 Copilot.
  • Copilot chat within Microsoft 365 apps is unavailable.
  • AI-powered productivity experiences remain disabled.

Administrators assign or remove licenses through the Microsoft 365 Admin Center.


2. Copilot Chat Availability

Organizations can choose whether users have access to:

  • Microsoft 365 Copilot Chat
  • Enterprise data grounding
  • AI conversations within Microsoft 365

This allows phased deployments.

Example:

  • IT department enabled
  • Executive team enabled
  • Finance enabled later
  • Entire organization enabled after testing

3. Copilot in Individual Microsoft 365 Apps

Copilot experiences exist across multiple applications, including:

  • Word
  • Excel
  • PowerPoint
  • Outlook
  • Teams
  • OneNote

Organizations may decide when to introduce Copilot features within these workloads depending on readiness and licensing.


4. Intelligent Meeting Features

Some Teams AI features can be managed by administrators, including:

  • Intelligent meeting recap
  • AI-generated meeting summaries
  • Suggested action items
  • Meeting notes
  • Transcript availability

Organizations handling confidential meetings may choose to limit some AI-generated meeting experiences.


5. Plugins and Connectors

Administrators can manage:

  • Microsoft Graph connectors
  • Third-party plugins
  • Custom connectors
  • Agent access to external systems

Disabling unnecessary plugins reduces security risk.


6. Copilot Agents

Administrators can control:

  • Which agents are available
  • Who can create agents
  • Who can publish agents
  • Which departments can access specific agents

For example:

Human Resources might publish an HR Benefits Agent while Finance publishes an Expense Policy Agent.


7. Web Grounding

Some Copilot experiences include information from:

  • Microsoft Graph
  • Public web content
  • Organizational content

Organizations may configure which experiences are available depending on licensing and organizational policies.


Features That Cannot Simply Be “Turned Off”

Some Copilot behaviors are governed by Microsoft 365 security rather than feature switches.

Examples include:

Microsoft Graph Permissions

Copilot never ignores permissions.

If a user lacks permission to a file:

  • Copilot cannot retrieve it.
  • There is no setting that overrides SharePoint permissions.

SharePoint Permissions

Copilot always honors:

  • Site permissions
  • Folder permissions
  • File permissions
  • Restricted SharePoint sites

Administrators manage access by changing SharePoint permissions—not Copilot settings.


Microsoft Purview Policies

If Microsoft Purview blocks data through:

  • Sensitivity labels
  • DLP policies
  • Retention policies

Copilot follows those controls automatically.


Microsoft Defender Policies

Security policies continue protecting data regardless of Copilot.

Examples include:

  • Safe Links
  • Safe Attachments
  • Threat protection
  • Malware detection

Copilot cannot bypass Defender protections.


Enabling Copilot Through Licensing

Most Copilot functionality depends on licensing.

Typical process:

  1. Purchase licenses.
  2. Assign licenses.
  3. Configure organizational settings.
  4. Enable users or groups.
  5. Monitor adoption.
  6. Expand deployment gradually.

Removing the license immediately removes access.


Feature Rollout Strategies

Many organizations deploy Copilot in phases.

Example rollout:

PhaseUsers
PilotIT department
Early adoptersBusiness champions
Department rolloutHR, Finance, Sales
Enterprise rolloutEntire organization

This minimizes disruption and allows administrators to gather feedback.


Feature Controls for Copilot Agents

Agent administrators can typically control:

  • Agent publishing
  • Agent availability
  • Knowledge sources
  • Connector permissions
  • Agent sharing
  • Agent lifecycle
  • Agent retirement

These settings help prevent unauthorized AI experiences.


Managing Experimental Features

Microsoft periodically releases:

  • Preview capabilities
  • Experimental AI experiences
  • Early-access functionality

Organizations can often choose whether these features are available.

Many enterprises disable preview features until internal testing is complete.


Monitoring Enabled Features

Administrators should monitor:

  • License assignments
  • Usage reports
  • Adoption metrics
  • Agent activity
  • Security alerts
  • Compliance reports
  • AI interactions (where supported)

Monitoring helps determine whether enabled features are providing value while remaining compliant.


Best Practices

Microsoft recommends:

  • Start with a pilot group.
  • Assign licenses only to intended users.
  • Review SharePoint permissions before deployment.
  • Apply Microsoft Purview protection policies first.
  • Enable only required plugins.
  • Monitor adoption regularly.
  • Review security settings before enabling new AI capabilities.
  • Use least-privilege access.
  • Periodically review agent permissions.
  • Train users before broad rollout.

Exam Tips

For the AB-900 exam, remember these key points:

  • Licensing is the primary method of enabling Microsoft 365 Copilot.
  • Administrators can enable or disable access for users and groups.
  • Copilot always respects Microsoft Graph permissions.
  • Microsoft Purview protections continue to apply to Copilot.
  • SharePoint permissions cannot be bypassed by Copilot.
  • Administrators can manage plugins, connectors, and agents.
  • Many organizations use phased deployments.
  • Security and governance controls remain in effect regardless of Copilot features.

10 Practice Exam Questions

Question 1

What is the primary requirement for a user to access Microsoft 365 Copilot?

A. Membership in the Global Readers group

B. Assignment of an appropriate Microsoft 365 Copilot license

C. Creation of a Copilot agent

D. A Microsoft Teams Premium license

Correct Answer: B

Explanation: A Microsoft 365 Copilot license is required before users can access Copilot experiences.


Question 2

An administrator wants to introduce Copilot to only the IT department before rolling it out company-wide. What is the recommended approach?

A. Disable Microsoft Graph

B. Remove SharePoint permissions

C. Assign Copilot licenses only to the IT department

D. Create separate Microsoft 365 tenants

Correct Answer: C

Explanation: Administrators commonly pilot Copilot by assigning licenses only to selected users or groups.


Question 3

Which security principle does Microsoft 365 Copilot always follow?

A. It ignores file permissions for administrators.

B. It grants temporary access to files during conversations.

C. It respects existing Microsoft Graph and Microsoft 365 permissions.

D. It automatically shares documents across departments.

Correct Answer: C

Explanation: Copilot only accesses content the user already has permission to view.


Question 4

Which capability can administrators commonly control?

A. Whether users can access Copilot agents

B. Whether Copilot can ignore sensitivity labels

C. Whether Microsoft Graph indexes SharePoint

D. Whether SharePoint stores documents

Correct Answer: A

Explanation: Administrators can manage agent availability, publication, and access permissions.


Question 5

What happens if a user’s Microsoft 365 Copilot license is removed?

A. Existing AI conversations become public.

B. SharePoint permissions are deleted.

C. Copilot access is removed from that user.

D. Microsoft Graph stops indexing organizational content.

Correct Answer: C

Explanation: Removing the Copilot license removes the user’s entitlement to Copilot services.


Question 6

Which Microsoft technology automatically continues enforcing sensitivity labels when users work with Copilot?

A. Microsoft Defender for Endpoint

B. Microsoft Purview

C. Microsoft Intune

D. Microsoft Planner

Correct Answer: B

Explanation: Microsoft Purview applies data protection controls, including sensitivity labels, regardless of whether Copilot is used.


Question 7

Why might an organization disable certain Copilot plugins?

A. To reduce security risks from unnecessary external integrations

B. To increase Microsoft Graph indexing speed

C. To improve Outlook mailbox quotas

D. To eliminate SharePoint storage limits

Correct Answer: A

Explanation: Limiting plugins reduces the organization’s attack surface and helps maintain governance.


Question 8

Which feature continues protecting documents even after Copilot is enabled?

A. Microsoft Graph indexing

B. Microsoft Purview DLP policies

C. Copilot prompts

D. AI-generated summaries

Correct Answer: B

Explanation: Data Loss Prevention policies remain fully enforced when Copilot accesses organizational data.


Question 9

What is a common best practice when deploying Microsoft 365 Copilot?

A. Enable every Copilot feature for all employees immediately.

B. Remove SharePoint permissions before deployment.

C. Begin with a pilot deployment and expand gradually.

D. Disable Microsoft Purview during rollout.

Correct Answer: C

Explanation: A phased rollout allows administrators to validate security, governance, and user adoption before organization-wide deployment.


Question 10

Which statement about SharePoint permissions and Copilot is correct?

A. Copilot can temporarily bypass SharePoint permissions.

B. Copilot automatically grants access to related files.

C. Administrators can disable SharePoint permissions while keeping Copilot enabled.

D. Copilot only accesses SharePoint content the user is already authorized to view.

Correct Answer: D

Explanation: Copilot always honors existing SharePoint permissions and cannot access content beyond the user’s authorized access.


Go to the AB-900 Exam Prep Hub main page

Compare Copilot monthly license model to Pay-as-You-Go, including SharePoint (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Compare Copilot monthly license model to Pay-as-You-Go, including SharePoint


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft offers multiple licensing models for AI experiences across Microsoft 365. Understanding these licensing options is important for administrators who plan deployments, manage costs, and determine which AI capabilities are available to users.

For the AB-900 exam, you should understand the differences between:

  • Microsoft 365 Copilot monthly user licensing
  • Pay-as-you-go (consumption-based) licensing
  • SharePoint Copilot licensing
  • When each licensing model is appropriate

The exam focuses on understanding the concepts rather than memorizing pricing.


Why Multiple Licensing Models Exist

Organizations vary greatly in how employees use AI.

Some organizations:

  • Have employees who use AI all day.
  • Need AI integrated into Microsoft 365 apps.
  • Require predictable monthly costs.

Other organizations:

  • Use AI occasionally.
  • Need specialized agents.
  • Want to pay only when AI is used.

Microsoft therefore offers both subscription-based and consumption-based licensing.


Microsoft 365 Copilot Monthly License Model

The traditional Microsoft 365 Copilot license is assigned to individual users.

Each licensed user receives access to Copilot experiences across supported Microsoft 365 applications.

Examples include:

  • Word
  • Excel
  • PowerPoint
  • Outlook
  • Teams
  • OneNote
  • Microsoft 365 Chat

The license is:

  • Assigned per user
  • Monthly subscription
  • Predictable recurring cost

Characteristics of the Monthly License

The monthly model provides:

  • Full Microsoft 365 Copilot experience
  • Unlimited daily usage (subject to service limits)
  • Personalized AI assistance
  • Microsoft Graph integration
  • Cross-app experiences
  • Enterprise security and compliance

This model is best for employees who regularly use Copilot throughout their workday.


Typical Monthly License Scenario

A financial analyst uses Copilot every day to:

  • Analyze Excel workbooks
  • Draft reports
  • Summarize meetings
  • Create PowerPoint presentations
  • Search organizational knowledge

Because AI is used continuously, a monthly license provides predictable costs.


Benefits of Monthly Licensing

Advantages include:

  • Predictable budgeting
  • No need to monitor consumption
  • Continuous access
  • Simplified administration
  • Consistent user experience
  • Ideal for heavy users

Limitations of Monthly Licensing

Considerations include:

  • Fixed monthly cost regardless of usage
  • Not ideal for occasional users
  • Every user requires their own license
  • Organizations may over-license infrequent users

Pay-as-You-Go Licensing

Pay-as-you-go (PAYG) is a consumption-based licensing model.

Instead of paying for every user every month, organizations pay based on actual AI usage.

Think of it similarly to cloud computing services:

  • More usage = higher cost
  • Less usage = lower cost

Characteristics of Pay-as-You-Go

Pay-as-you-go provides:

  • Usage-based billing
  • Flexible scaling
  • No requirement for every user to have a monthly Copilot license
  • Cost based on AI requests or service consumption (depending on the service)

This model is especially useful for agents and certain AI scenarios.


Benefits of Pay-as-You-Go

Advantages include:

  • Lower upfront costs
  • Pay only for actual usage
  • Flexible deployment
  • Easy experimentation
  • Ideal for seasonal workloads
  • Good for occasional users

Limitations of Pay-as-You-Go

Potential drawbacks include:

  • Variable monthly costs
  • Budget forecasting is more difficult
  • Requires monitoring usage
  • Heavy usage may become more expensive than subscription licensing

Comparing Monthly Licensing and Pay-as-You-Go

Monthly LicensePay-as-You-Go
Fixed monthly costUsage-based cost
Licensed per userConsumption-based
Predictable budgetingVariable spending
Best for daily usersBest for occasional use
Continuous Copilot accessPay only when AI is used
Simpler cost managementRequires usage monitoring

Microsoft 365 Copilot Chat

Organizations should understand that Microsoft offers AI experiences beyond the traditional monthly Copilot license.

For example:

  • Microsoft 365 Copilot Chat is available to Microsoft 365 users.
  • Organizations can extend Copilot Chat with agents.
  • Some agent usage can be billed using pay-as-you-go licensing rather than requiring every user to have a full Copilot subscription.

This provides flexibility for organizations with mixed AI usage patterns.


SharePoint and Copilot

SharePoint includes AI capabilities that help users work with documents, sites, and organizational knowledge.

Examples include:

  • Summarizing documents
  • Answering questions about files
  • Generating page content
  • Assisting with document creation
  • Improving knowledge discovery

SharePoint Agents

One important capability is SharePoint agents.

A SharePoint agent can:

  • Be created from a SharePoint site or document library
  • Answer questions using approved SharePoint content
  • Help users locate organizational knowledge
  • Reduce the need to manually search documents

For example:

A Human Resources SharePoint site may contain:

  • Employee handbook
  • Benefits guide
  • Leave policies
  • Training documents

An HR SharePoint agent can answer employee questions using those documents.


SharePoint Pay-as-You-Go

Organizations can use SharePoint agents without assigning every user a full Microsoft 365 Copilot license.

Instead, administrators can configure consumption-based billing.

Benefits include:

  • Lower cost for occasional users
  • Easy pilot deployments
  • Department-specific AI
  • Flexible scaling

This makes SharePoint agents attractive for organizations wanting targeted AI experiences without licensing every employee.


Choosing the Right Licensing Model

Choose Monthly Licensing When

  • Employees use Copilot every day.
  • AI is integrated into daily workflows.
  • Predictable monthly budgeting is important.
  • Users need full Copilot functionality across Microsoft 365.

Examples:

  • Executives
  • Project managers
  • Analysts
  • Consultants
  • Sales professionals
  • Knowledge workers

Choose Pay-as-You-Go When

  • AI usage is occasional.
  • Organizations are testing AI.
  • Departments need specialized agents.
  • Seasonal usage is expected.
  • Budget flexibility is acceptable.

Examples:

  • HR help desk agent
  • Legal document agent
  • IT support chatbot
  • SharePoint knowledge assistant

Administrative Considerations

Administrators should evaluate:

  • Expected AI usage
  • Number of users
  • Cost predictability
  • Department requirements
  • Governance policies
  • Licensing strategy
  • Agent deployment plans

Security Remains the Same

Regardless of licensing model:

  • Microsoft Entra ID authentication is used.
  • Microsoft Graph permissions are enforced.
  • Microsoft Purview policies apply.
  • Data Loss Prevention (DLP) policies remain active.
  • Sensitivity labels continue protecting content.
  • Microsoft Defender protections remain in effect.

Licensing changes how organizations pay for AI—not how Microsoft secures organizational data.


Best Practices

Microsoft recommends that organizations:

  • License frequent users with Microsoft 365 Copilot subscriptions.
  • Use pay-as-you-go for occasional AI usage.
  • Monitor AI adoption and consumption.
  • Start with pilot deployments.
  • Evaluate SharePoint agents for departmental knowledge scenarios.
  • Review licensing regularly as adoption increases.

Exam Tips

For the AB-900 exam, remember these key points:

  • Microsoft 365 Copilot is commonly licensed per user with a monthly subscription.
  • Pay-as-you-go bills organizations based on AI usage.
  • Monthly licensing provides predictable costs.
  • Pay-as-you-go offers flexibility for occasional or specialized AI use.
  • SharePoint agents can be deployed using consumption-based licensing in supported scenarios.
  • Licensing affects billing—not security or permissions.
  • Microsoft Graph, Microsoft Purview, and Microsoft Entra ID protections apply regardless of licensing model.
  • Heavy AI users are generally better suited to monthly licensing.
  • Departmental or pilot AI deployments often benefit from pay-as-you-go.

Practice Exam Questions

Question 1

Which licensing model provides users with a predictable monthly cost for Microsoft 365 Copilot?

A. Pay-as-you-go
B. Monthly per-user license
C. Azure consumption credits
D. SharePoint storage licensing

Correct Answer: B

Explanation: A monthly per-user license provides continuous access to Microsoft 365 Copilot for a fixed monthly subscription.


Question 2

What is the primary advantage of the pay-as-you-go licensing model?

A. Users receive unlimited AI usage regardless of activity.
B. Organizations pay only for actual AI usage.
C. Every employee automatically receives Microsoft 365 Copilot.
D. It disables Microsoft Graph integration.

Correct Answer: B

Explanation: Pay-as-you-go charges based on consumption, making it suitable for occasional or specialized AI usage.


Question 3

Which type of user is generally the best candidate for a Microsoft 365 Copilot monthly license?

A. An employee who rarely uses Microsoft 365 applications
B. A seasonal contractor who accesses AI once a month
C. A knowledge worker who uses Copilot throughout the workday
D. A visitor with guest access to SharePoint

Correct Answer: C

Explanation: Heavy or daily users benefit from the predictable costs and continuous access provided by the monthly licensing model.


Question 4

An organization wants to deploy an HR SharePoint agent that employees will use occasionally. Which licensing model is often the better fit?

A. Monthly Copilot license for every employee
B. Windows Enterprise licensing
C. Exchange Online licensing
D. Pay-as-you-go

Correct Answer: D

Explanation: Pay-as-you-go is well suited for departmental agents with occasional usage, allowing organizations to pay based on consumption.


Question 5

Which statement about Microsoft 365 Copilot monthly licensing is correct?

A. It charges only when AI is used.
B. It is assigned to individual users as a subscription.
C. It replaces Microsoft Entra ID.
D. It is available only for SharePoint.

Correct Answer: B

Explanation: The traditional Microsoft 365 Copilot model is licensed per user through a recurring subscription.


Question 6

Which capability is commonly associated with SharePoint agents?

A. Managing Windows updates
B. Replacing Microsoft Graph
C. Answering questions using SharePoint content and document libraries
D. Creating Azure virtual machines

Correct Answer: C

Explanation: SharePoint agents are grounded in SharePoint content and help users locate and understand organizational knowledge.


Question 7

How do Microsoft Purview policies behave when an organization switches from monthly licensing to pay-as-you-go?

A. They are automatically disabled.
B. They apply only to SharePoint documents.
C. They require users to purchase additional licenses before functioning.
D. They continue to protect data regardless of the licensing model.

Correct Answer: D

Explanation: Security and compliance controls such as Microsoft Purview continue to protect data regardless of how AI services are licensed.


Question 8

Which licensing model generally provides the most predictable monthly budgeting?

A. Pay-as-you-go
B. Monthly per-user licensing
C. Azure Reserved Instances
D. SharePoint storage quotas

Correct Answer: B

Explanation: Monthly licensing offers a fixed recurring cost, simplifying budgeting and financial planning.


Question 9

What is a potential disadvantage of pay-as-you-go licensing?

A. It cannot be used with agents.
B. It prevents users from accessing SharePoint.
C. Monthly costs may vary depending on AI usage.
D. It disables Microsoft Graph permissions.

Correct Answer: C

Explanation: Consumption-based billing means costs fluctuate according to actual usage, making budgeting less predictable.


Question 10

Which statement best summarizes the difference between Microsoft 365 Copilot monthly licensing and pay-as-you-go?

A. Monthly licensing is subscription-based, while pay-as-you-go is consumption-based.
B. Monthly licensing does not include Microsoft Graph.
C. Pay-as-you-go removes Microsoft Purview protections.
D. Monthly licensing is only available for SharePoint.

Correct Answer: A

Explanation: The fundamental difference is the billing model: monthly licensing charges a fixed subscription per user, whereas pay-as-you-go charges based on actual AI service consumption.


Go to the AB-900 Exam Prep Hub main page

Compare the built-in capabilities of Copilot and agents (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Compare the built-in capabilities of Copilot and agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft 365 provides powerful AI capabilities through Microsoft 365 Copilot and agents. Although they are closely related, they serve different purposes.

A common misconception is that Copilot and agents are the same technology. In reality:

  • Microsoft 365 Copilot is the AI assistant that helps users work across Microsoft 365 applications.
  • Agents are specialized AI assistants designed to perform focused tasks, automate business processes, or provide expertise in specific domains.

Understanding the differences between Copilot and agents is an important objective on the AB-900 exam.


What is Microsoft 365 Copilot?

Microsoft 365 Copilot is Microsoft’s AI assistant integrated throughout Microsoft 365 applications.

It combines:

  • Large Language Models (LLMs)
  • Microsoft Graph
  • Microsoft 365 data
  • User permissions
  • Organizational knowledge

Copilot helps users complete everyday work faster while respecting existing security permissions.

Examples include:

  • Drafting emails
  • Summarizing meetings
  • Creating PowerPoint presentations
  • Analyzing Excel data
  • Writing Word documents
  • Answering natural language questions
  • Summarizing Teams chats

Copilot is designed to improve personal productivity across many different tasks.


What are Microsoft 365 Agents?

Agents are AI assistants created to perform specialized or repeatable business tasks.

Rather than serving as a general assistant, an agent focuses on a specific job.

Examples include:

  • HR policy assistant
  • IT help desk assistant
  • Sales proposal assistant
  • Customer service assistant
  • Legal document assistant
  • Procurement assistant
  • Finance assistant

Agents can:

  • Answer questions from approved knowledge sources
  • Follow business rules
  • Guide users through processes
  • Complete multi-step workflows
  • Connect to business systems

Comparing Copilot and Agents

Microsoft 365 CopilotMicrosoft 365 Agents
General-purpose AI assistantSpecialized AI assistant
Works across Microsoft 365Focuses on a specific business task
Assists individual productivityAssists business processes
Uses Microsoft Graph extensivelyCan use Graph plus additional knowledge sources
Available in Microsoft 365 appsCan be published inside Teams, Microsoft 365, SharePoint, and other experiences
Broad conversational abilitiesDomain-specific expertise

Built-in Capabilities of Microsoft 365 Copilot

Copilot includes many built-in features without requiring customization.

Content Creation

Copilot can:

  • Draft documents
  • Rewrite text
  • Summarize documents
  • Change writing tone
  • Generate presentations
  • Create outlines
  • Brainstorm ideas

Example:

“Create a proposal for a new customer.”


Meeting Intelligence

Within Microsoft Teams, Copilot can:

  • Summarize meetings
  • Capture decisions
  • List action items
  • Answer questions about the meeting
  • Identify unresolved issues

Example:

“What decisions were made during yesterday’s meeting?”


Email Assistance

In Outlook, Copilot can:

  • Draft responses
  • Summarize long email threads
  • Suggest follow-up actions
  • Improve writing style

Data Analysis

Within Excel, Copilot can:

  • Explain formulas
  • Generate charts
  • Analyze trends
  • Identify outliers
  • Create summaries

Example:

“Show quarterly sales trends.”


Knowledge Discovery

Copilot searches organizational knowledge using Microsoft Graph.

It can answer questions such as:

  • “What projects am I working on?”
  • “Summarize documents related to Project Apollo.”
  • “What files has my manager recently shared?”

Cross-Application Context

One major capability is connecting information across applications.

Example:

Copilot may combine information from:

  • Outlook
  • Teams
  • Word
  • OneDrive
  • SharePoint
  • Calendar

to answer a single prompt.


Built-in Capabilities of Agents

Agents focus on completing specialized work.


Task-Specific Expertise

An agent is trained or configured around one topic.

Examples:

HR Agent

  • Vacation policy
  • Benefits
  • Employee handbook

IT Agent

  • Password reset guidance
  • Software installation
  • Device troubleshooting

Finance Agent

  • Expense reimbursement
  • Budget approval
  • Procurement rules

Business Process Guidance

Agents can walk users through business procedures.

Example:

Instead of simply answering a question, an HR onboarding agent can:

  • Explain required forms
  • Guide new employees
  • Answer benefits questions
  • Provide training links

Knowledge Grounding

Agents can use approved organizational knowledge.

Examples include:

  • SharePoint libraries
  • Internal documents
  • Knowledge bases
  • Business manuals
  • Policies
  • FAQs

Unlike general internet chatbots, agents only answer from approved sources.


Workflow Automation

Agents can perform multiple steps automatically.

Example:

A travel request agent might:

  • Collect travel details
  • Validate policy
  • Request manager approval
  • Submit the request
  • Notify the employee

Connectors

Agents can connect to external business systems.

Examples:

  • Dynamics 365
  • ServiceNow
  • Salesforce
  • SAP
  • Workday
  • Microsoft Dataverse

This allows agents to retrieve business information securely.


Consistent Business Responses

Unlike free-form conversations, agents provide consistent answers based on organizational knowledge.

This reduces confusion and improves compliance.


Shared Capabilities

Both Copilot and agents share many AI features.

These include:

  • Natural language interaction
  • Context-aware conversations
  • AI-generated responses
  • Respect for Microsoft Entra ID permissions
  • Security trimming
  • Microsoft Graph integration (where applicable)
  • Use of Large Language Models
  • Support for Microsoft 365 security and compliance controls

Key Differences

Scope

Copilot

Broad productivity assistant.

Agent

Focused business assistant.


Purpose

Copilot

Helps users complete work.

Agent

Helps complete specific business processes.


Knowledge

Copilot

Uses Microsoft Graph plus organizational content.

Agent

Uses selected knowledge sources chosen by administrators or creators.


Customization

Copilot

Little customization required.

Agents

Often customized for departments or business scenarios.


Reusability

Copilot

Same assistant for everyone (subject to permissions).

Agents

Different agents can exist for different teams.

Examples:

  • Legal Agent
  • Sales Agent
  • Finance Agent
  • HR Agent

Copilot vs. Agent Example

A user asks:

“I need to prepare for a customer renewal.”

Copilot might:

  • Summarize recent emails
  • Review meeting notes
  • Draft a proposal
  • Create a PowerPoint

A Sales Agent might:

  • Retrieve CRM information
  • Check renewal status
  • Calculate discounts
  • Recommend pricing
  • Generate renewal documentation

Both assist the user—but in different ways.


Security

Both Copilot and agents follow Microsoft security principles.

They respect:

  • Microsoft Entra ID authentication
  • User permissions
  • Microsoft Graph security trimming
  • Microsoft Purview sensitivity labels
  • Data Loss Prevention (DLP) policies
  • Conditional Access policies
  • Compliance controls

Neither Copilot nor agents expose information users are not authorized to access.


Common Exam Tips

Remember these distinctions:

  • Copilot is a general-purpose AI assistant.
  • Agents are specialized assistants for business scenarios.
  • Copilot improves productivity across Microsoft 365.
  • Agents automate or simplify specific business tasks.
  • Both use natural language.
  • Both respect existing Microsoft 365 permissions.
  • Agents can connect to external business systems.
  • Multiple agents can exist within the same organization.
  • Copilot does not replace business applications—it works with them.
  • Administrators govern both using Microsoft 365 security and compliance controls.

Practice Exam Questions

Question 1

What is the primary purpose of Microsoft 365 Copilot?

A. Replace business applications
B. Provide a general AI assistant across Microsoft 365 applications
C. Manage Microsoft Entra ID users
D. Automatically configure SharePoint permissions

Correct Answer: B

Explanation: Microsoft 365 Copilot is a general-purpose AI assistant that enhances productivity across Microsoft 365 applications.


Question 2

Which scenario is best suited for a Microsoft 365 agent?

A. Creating a PowerPoint presentation from meeting notes
B. Summarizing an Outlook inbox
C. Guiding employees through HR onboarding procedures
D. Drafting a Word document

Correct Answer: C

Explanation: Agents are designed for specialized business tasks such as HR onboarding, IT support, or finance workflows.


Question 3

Which feature is shared by both Microsoft 365 Copilot and agents?

A. They ignore Microsoft Entra permissions.
B. They require internet searches for every response.
C. They automatically grant file access.
D. They support natural language conversations.

Correct Answer: D

Explanation: Both Copilot and agents use conversational AI, allowing users to interact using natural language.


Question 4

Which capability is unique to many business agents?

A. Creating Word documents
B. Summarizing Teams meetings
C. Performing specialized workflows using business systems
D. Rewriting email messages

Correct Answer: C

Explanation: Agents can automate specialized business workflows and connect with enterprise systems.


Question 5

Microsoft 365 Copilot primarily retrieves organizational information through:

A. Microsoft Graph
B. Azure Virtual Desktop
C. Windows Registry
D. Local device storage

Correct Answer: A

Explanation: Microsoft Graph provides Copilot with secure access to organizational data while respecting user permissions.


Question 6

Which statement best describes Microsoft 365 agents?

A. They replace Microsoft Graph.
B. They are designed for focused business scenarios and specialized tasks.
C. They only answer questions about Microsoft products.
D. They are available only in Outlook.

Correct Answer: B

Explanation: Agents are purpose-built AI assistants that support specific business processes or departmental functions.


Question 7

How do Copilot and agents protect organizational data?

A. They bypass file permissions for administrators.
B. They make all SharePoint content searchable.
C. They respect existing Microsoft 365 permissions and compliance controls.
D. They permanently copy data into AI models.

Correct Answer: C

Explanation: Both solutions honor Microsoft Entra ID permissions, Microsoft Graph security trimming, and Microsoft Purview governance policies.


Question 8

Which task would Microsoft 365 Copilot most likely perform?

A. Reset a user’s Active Directory password automatically.
B. Analyze an Excel workbook and explain sales trends.
C. Replace the organization’s CRM system.
D. Configure Conditional Access policies.

Correct Answer: B

Explanation: Copilot excels at productivity tasks such as analyzing Excel data and generating insights.


Question 9

An organization creates separate HR, Legal, and Finance AI assistants. These are examples of:

A. Microsoft Graph connectors
B. SharePoint hubs
C. Copilot prompts
D. Specialized agents

Correct Answer: D

Explanation: Organizations can build multiple specialized agents tailored to different departments and business functions.


Question 10

What is one of the biggest differences between Microsoft 365 Copilot and agents?

A. Copilot is a broad productivity assistant, while agents focus on specific business tasks.
B. Agents do not use AI.
C. Copilot ignores Microsoft 365 permissions.
D. Agents cannot access organizational knowledge.

Correct Answer: A

Explanation: Copilot provides broad productivity assistance across Microsoft 365, whereas agents are designed for specialized business scenarios and targeted workflows.


Go to the AB-900 Exam Prep Hub main page

Understand features and capabilities of SharePoint Advanced Management, including restricted site access (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify and monitor oversharing in SharePoint in Microsoft 365
      --> Understand features and capabilities of SharePoint Advanced Management, including restricted site access


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

As organizations increasingly rely on Microsoft 365, SharePoint Online, Microsoft Teams, and Microsoft 365 Copilot, protecting organizational data has become more important than ever. While collaboration is essential, unrestricted sharing can expose confidential information to unintended users.

To help organizations better govern SharePoint content, Microsoft offers SharePoint Advanced Management (SAM), a collection of advanced governance, reporting, security, and lifecycle management capabilities designed to improve the security of SharePoint and OneDrive environments.

One of its most important features is Restricted Site Access, which allows administrators to temporarily limit access to specific SharePoint sites that may contain highly sensitive or potentially overshared information.

For the AB-900 exam, you should understand the purpose of SharePoint Advanced Management, its major capabilities, and how Restricted Site Access helps reduce data exposure.


What is SharePoint Advanced Management?

SharePoint Advanced Management is a set of administrative capabilities that extends the standard SharePoint Online administration experience.

Its goals include:

  • Improving governance
  • Reducing oversharing
  • Enhancing visibility into permissions
  • Strengthening data protection
  • Supporting Microsoft 365 Copilot readiness
  • Helping organizations adopt Zero Trust security principles

Rather than replacing Microsoft Purview or Microsoft Defender, SharePoint Advanced Management complements these services by focusing specifically on SharePoint and OneDrive administration.


Why SharePoint Advanced Management Is Important

Organizations often have:

  • Thousands of SharePoint sites
  • Millions of documents
  • Numerous external users
  • Complex permission structures
  • Years of accumulated sharing links

As these environments grow, administrators face challenges such as:

  • Overshared files
  • Forgotten external sharing
  • Stale permissions
  • Sensitive documents accessible by too many users
  • Inactive or abandoned sites

SharePoint Advanced Management provides tools to identify and address these issues before they become security incidents.


Key Capabilities of SharePoint Advanced Management

SharePoint Advanced Management includes several capabilities designed to improve governance.

1. Data Access Governance Reporting

Administrators can:

  • Identify overshared sites
  • Review sharing activity
  • Analyze permission configurations
  • Discover external access
  • Locate high-risk collaboration sites

These reports provide visibility into who can access organizational content.


2. Site Lifecycle Management

Organizations frequently create project sites that remain active long after projects end.

SharePoint Advanced Management helps administrators:

  • Identify inactive sites
  • Review site ownership
  • Archive or delete unused sites
  • Reduce unnecessary content exposure

Proper lifecycle management reduces security risks while improving overall governance.


3. Oversharing Insights

Administrators can identify:

  • Sites shared broadly
  • Anonymous sharing links
  • Guest access
  • Sensitive sites with excessive permissions
  • Large-scale permission inheritance issues

These insights are particularly valuable before deploying Microsoft 365 Copilot.


4. Site Ownership Management

SharePoint sites require responsible owners.

Advanced Management helps administrators identify:

  • Sites without owners
  • Inactive owners
  • Ownership inconsistencies

Proper ownership improves accountability and ensures permissions are reviewed regularly.


5. Sharing Governance

Administrators can evaluate:

  • External sharing
  • Anonymous links
  • Organization-wide access
  • Sharing policies
  • Guest permissions

This helps organizations reduce unnecessary collaboration risks.


6. Restricted Site Access

One of the most important SharePoint Advanced Management capabilities is Restricted Site Access.


What is Restricted Site Access?

Restricted Site Access allows administrators to temporarily limit access to a SharePoint site.

When enabled:

  • Most users lose access to the site.
  • Only designated administrators or approved users can access the content.
  • Copilot and Microsoft Search continue to respect the updated permissions because they always honor Microsoft 365 security trimming.

This feature is useful when a site contains highly sensitive information or requires investigation.


Why Use Restricted Site Access?

Organizations may need to immediately reduce access when:

  • Sensitive information has been overshared.
  • A security investigation is underway.
  • Legal or regulatory reviews are occurring.
  • Confidential merger or acquisition documents are stored.
  • Human Resources investigations are active.
  • Executive leadership documents require additional protection.
  • Sensitive intellectual property is being reviewed.

Rather than deleting the site, administrators can quickly restrict access while remediation occurs.


How Restricted Site Access Works

The feature temporarily changes access behavior by allowing only explicitly authorized users to access the site.

Typical workflow:

  1. Administrator identifies a high-risk site.
  2. Restricted Site Access is enabled.
  3. Only approved users retain access.
  4. Administrators investigate permissions.
  5. Oversharing issues are corrected.
  6. Normal access is restored when appropriate.

Benefits of Restricted Site Access

Organizations gain several advantages:

Rapid Risk Reduction

Potential data exposure is reduced immediately.

Supports Investigations

Investigators can examine permissions without widespread user access.

Improves Governance

Administrators gain time to review sharing settings before reopening access.

Protects Sensitive Information

Highly confidential documents remain accessible only to authorized personnel.

Supports Compliance

Temporary restrictions can assist with legal, regulatory, or internal compliance reviews.


Relationship with Microsoft 365 Copilot

Microsoft 365 Copilot respects Microsoft 365 permissions.

If a site becomes restricted:

  • Copilot cannot retrieve information from that site for users who no longer have permission.
  • Microsoft Search also honors the updated permissions.
  • Other Microsoft 365 services continue using the same security model.

Restricted Site Access therefore reduces the likelihood that Copilot will surface sensitive content from that site.


Relationship with Microsoft Purview

SharePoint Advanced Management and Microsoft Purview work together.

Microsoft Purview focuses on:

  • Data classification
  • Sensitivity labels
  • Data Loss Prevention (DLP)
  • Insider Risk Management
  • Data Lifecycle Management
  • Compliance

SharePoint Advanced Management focuses on:

  • Site governance
  • Permissions
  • Oversharing
  • Site administration
  • Access analysis
  • Restricted Site Access

Together they provide comprehensive protection for Microsoft 365 data.


Relationship with Microsoft Defender

Microsoft Defender identifies threats such as:

  • Compromised accounts
  • Suspicious user activity
  • Malware
  • Phishing attacks

If Defender identifies suspicious activity involving a SharePoint site, administrators may choose to enable Restricted Site Access while investigating the incident.


Best Practices

Microsoft recommends the following practices:

  • Regularly review Data Access Governance reports.
  • Minimize broad “Everyone” permissions.
  • Review external sharing frequently.
  • Assign active site owners.
  • Archive inactive sites.
  • Apply sensitivity labels to sensitive content.
  • Use Restricted Site Access only when necessary.
  • Review restricted sites periodically and restore normal access when appropriate.
  • Combine SharePoint Advanced Management with Microsoft Purview and Microsoft Defender for layered protection.
  • Follow the principle of least privilege.

Exam Tips

Remember these key points for the AB-900 exam:

  • SharePoint Advanced Management focuses on governance and security for SharePoint and OneDrive.
  • It helps identify and remediate oversharing.
  • Restricted Site Access temporarily limits access to sensitive SharePoint sites.
  • Copilot always respects SharePoint permissions, including restricted sites.
  • Restricted Site Access is useful during investigations or when sensitive information has been overshared.
  • SharePoint Advanced Management complements Microsoft Purview rather than replacing it.
  • Proper site ownership and lifecycle management reduce long-term security risks.

Practice Exam Questions

Question 1

Which primary problem does SharePoint Advanced Management help organizations address?

A. Windows operating system updates

B. Oversharing and governance of SharePoint content

C. SQL Server performance tuning

D. Microsoft Teams meeting scheduling

Correct Answer: B

Explanation: SharePoint Advanced Management provides governance tools that help identify oversharing, manage permissions, and improve the security of SharePoint and OneDrive environments.


Question 2

What is the purpose of Restricted Site Access?

A. Permanently delete SharePoint sites

B. Encrypt every document within a site

C. Temporarily limit access to a SharePoint site for authorized users only

D. Automatically archive inactive sites

Correct Answer: C

Explanation: Restricted Site Access allows administrators to temporarily restrict access to a site while investigating or protecting sensitive information.


Question 3

Why is SharePoint Advanced Management valuable before deploying Microsoft 365 Copilot?

A. It increases Copilot response speed.

B. It upgrades Microsoft Graph.

C. It removes all external users automatically.

D. It helps identify overshared content that Copilot could otherwise access based on existing permissions.

Correct Answer: D

Explanation: Since Copilot honors existing permissions, reducing oversharing before deployment helps minimize the risk of exposing sensitive information.


Question 4

Which capability is included in SharePoint Advanced Management?

A. Azure virtual machine backup

B. Microsoft Intune device enrollment

C. Data Access Governance reporting

D. Windows Server patch management

Correct Answer: C

Explanation: Data Access Governance reporting is a core capability that helps administrators analyze permissions and identify overshared content.


Question 5

What happens when Restricted Site Access is enabled?

A. Microsoft 365 Copilot ignores the restriction.

B. Only approved users and administrators retain access to the site.

C. All SharePoint sites become read-only.

D. External sharing is permanently disabled across the tenant.

Correct Answer: B

Explanation: Restricted Site Access limits access to authorized users, and Copilot continues to respect those permissions.


Question 6

Which Microsoft service primarily complements SharePoint Advanced Management by classifying and protecting sensitive information?

A. Microsoft Purview

B. Microsoft Paint

C. Windows Defender Firewall

D. Microsoft Project

Correct Answer: A

Explanation: Microsoft Purview provides data classification, labeling, DLP, and compliance capabilities that complement SharePoint governance features.


Question 7

Which scenario is an appropriate use case for Restricted Site Access?

A. Scheduling recurring Teams meetings

B. Updating Microsoft 365 licenses

C. Protecting a SharePoint site containing confidential merger documents during negotiations

D. Increasing SharePoint storage capacity

Correct Answer: C

Explanation: Restricting access to highly confidential content during sensitive business activities helps reduce the risk of accidental exposure.


Question 8

Which governance activity helps reduce long-term security risks in SharePoint?

A. Creating additional anonymous sharing links

B. Allowing all users full control of every site

C. Disabling Microsoft Search

D. Reviewing inactive sites and assigning active site owners

Correct Answer: D

Explanation: Proper site ownership and lifecycle management reduce abandoned sites and improve ongoing governance.


Question 9

How does Microsoft 365 Copilot interact with a site that has Restricted Site Access enabled?

A. Copilot bypasses the restriction for administrators only.

B. Copilot ignores SharePoint permissions.

C. Copilot respects the updated permissions and cannot retrieve content for unauthorized users.

D. Copilot copies restricted files into Microsoft Graph.

Correct Answer: C

Explanation: Copilot always honors Microsoft 365 permissions. If a user cannot access a restricted site, Copilot cannot use its content in responses for that user.


Question 10

Which statement best describes SharePoint Advanced Management?

A. It replaces Microsoft Purview entirely.

B. It is focused on SharePoint and OneDrive governance, permissions, lifecycle management, and oversharing protection.

C. It functions as an antivirus solution.

D. It manages Microsoft Entra ID authentication policies.

Correct Answer: B

Explanation: SharePoint Advanced Management provides advanced governance capabilities for SharePoint and OneDrive, including oversharing detection, site lifecycle management, permission analysis, and Restricted Site Access.


Go to the AB-900 Exam Prep Hub main page

Run a data access governance report in SharePoint (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify and monitor oversharing in SharePoint in Microsoft 365
      --> Run a data access governance report in SharePoint


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

That is an excellent next topic for the AB-900 exam because it combines SharePoint governance, Microsoft Purview, and Copilot data security. Although the feature continues to evolve, the exam focuses on understanding what the report is, when to use it, and what problems it helps administrators solve, rather than memorizing every UI step.


Why Data Access Governance Matters

One of the largest security challenges in Microsoft 365 is oversharing. Over time, organizations accumulate millions of files, thousands of SharePoint sites, and numerous Microsoft Teams workspaces. Permissions often become increasingly complex as users:

  • Share files externally
  • Create anonymous sharing links
  • Grant access to “Everyone”
  • Add guests to Teams
  • Break inheritance on folders
  • Forget to remove temporary permissions

As organizations adopt Microsoft 365 Copilot, overshared content becomes an even greater concern because Copilot can surface information that a user already has permission to access—even if that access was unintentionally granted.

Microsoft provides Data Access Governance (DAG) capabilities in SharePoint to help administrators discover, understand, and remediate excessive access before it becomes a security issue.


What is Data Access Governance?

Data Access Governance is a collection of reporting and analysis capabilities within SharePoint Advanced Management that helps administrators answer questions such as:

  • Which sites are accessible by everyone?
  • Which files are overshared?
  • Which sites have external users?
  • Which sites contain highly sensitive information?
  • Which permissions may expose confidential content?
  • Which sites should be reviewed?

Rather than examining permissions one site at a time, administrators receive organization-wide visibility.


Primary Goals of Data Access Governance

Data Access Governance helps organizations:

  • Discover overshared sites
  • Review permissions
  • Reduce excessive access
  • Identify high-risk collaboration
  • Improve Microsoft 365 security posture
  • Prepare for Microsoft 365 Copilot deployment
  • Reduce accidental data exposure
  • Support compliance initiatives

Why It Is Important for Microsoft 365 Copilot

Microsoft 365 Copilot never ignores permissions.

Instead, it retrieves content using the same security model that governs Microsoft 365.

If a user has permission to open a document manually, Copilot can potentially reference that document when generating responses.

For example:

Suppose Human Resources accidentally grants the entire company read access to salary spreadsheets.

Without Copilot:

  • Most employees may never discover the files.

With Copilot:

A user might ask:

“Summarize employee compensation data.”

Because the files are already accessible, Copilot could retrieve them.

The problem is not Copilot—it is the underlying permissions.

Data Access Governance helps identify these permission problems before they become security risks.


What the Data Access Governance Report Shows

The report provides administrators with visibility into SharePoint permissions and sharing configurations across the tenant.

Common information includes:

  • Site owners
  • Site sensitivity
  • External sharing status
  • Number of members
  • Anonymous links
  • Organization-wide access
  • Guest access
  • Sharing activity
  • Permission inheritance
  • Access patterns
  • High-risk sites
  • Overshared content indicators

Rather than searching manually, administrators can prioritize the highest-risk locations.


Types of Oversharing That Can Be Identified

The report can identify situations such as:

Organization-wide access

Sites accessible by:

  • Everyone
  • Everyone except external users
  • Large security groups

These sites often expose more content than intended.


Anonymous Links

Files shared through links that require no authentication.

These links may remain active long after they are needed.


Guest Access

Sites containing:

  • External users
  • Partner accounts
  • Vendor accounts

Administrators can verify whether guest access is still appropriate.


Excessive Sharing

Examples include:

  • Large numbers of shared files
  • Broad sharing permissions
  • Public document libraries
  • Open collaboration spaces

Sensitive Sites

The report can identify sites that contain:

  • Financial information
  • HR records
  • Legal documents
  • Intellectual property
  • Customer information

Combined with Microsoft Purview sensitivity labels, administrators gain better visibility into where important information resides.


Typical Workflow

Administrators generally follow this process:

Step 1

Open SharePoint administration tools.


Step 2

Generate or review a Data Access Governance report.


Step 3

Review identified risks.

Examples:

  • Overshared sites
  • External sharing
  • Everyone permissions
  • Sensitive content

Step 4

Investigate high-risk sites.

Questions include:

  • Does this access need to exist?
  • Are guests still required?
  • Is inheritance broken?
  • Should permissions be reduced?

Step 5

Take corrective action.

Possible actions include:

  • Remove permissions
  • Restrict sharing
  • Apply sensitivity labels
  • Disable anonymous links
  • Reduce guest access
  • Educate site owners

Step 6

Run reports regularly to verify improvements.


Relationship with Microsoft Purview

Data Access Governance works alongside Microsoft Purview.

Purview answers questions such as:

  • What sensitive data exists?
  • How is it classified?
  • Which labels are applied?
  • Are DLP policies triggered?

SharePoint Data Access Governance answers:

  • Who can access the data?
  • Is the data overshared?
  • Which sites expose information?
  • Which permissions should be reviewed?

Together they provide both:

  • Content awareness
  • Permission awareness

Relationship with Microsoft 365 Copilot

Data Access Governance helps administrators prepare for Copilot by reducing permission-related risks.

Benefits include:

  • Finding overshared SharePoint sites
  • Identifying unnecessary permissions
  • Reducing broad access
  • Reviewing guest sharing
  • Protecting confidential information
  • Improving search security
  • Supporting Zero Trust principles

Best Practices

Microsoft recommends that organizations:

  • Review sharing reports regularly.
  • Audit external access periodically.
  • Minimize “Everyone” permissions.
  • Remove unused guest accounts.
  • Apply sensitivity labels to important sites.
  • Use Microsoft Purview DLP alongside SharePoint governance.
  • Educate site owners on responsible sharing.
  • Review high-risk collaboration sites before deploying Copilot broadly.
  • Follow the principle of least privilege.
  • Continuously monitor permission changes.

Common Exam Tips

Remember these key points:

  • Data Access Governance focuses on permissions and access, not document content.
  • It helps identify oversharing across SharePoint.
  • It is especially valuable before deploying Microsoft 365 Copilot.
  • Copilot respects existing Microsoft 365 permissions.
  • Oversharing is a permissions problem, not a Copilot problem.
  • Reports help administrators prioritize high-risk sites for remediation.
  • Data Access Governance complements Microsoft Purview rather than replacing it.

Practice Exam Questions

Question 1

Why would an administrator run a Data Access Governance report in SharePoint?

A. To update SharePoint servers

B. To identify overshared sites and permission risks

C. To encrypt all documents automatically

D. To generate Microsoft 365 licenses

Correct Answer: B

Explanation: Data Access Governance helps administrators identify sites with excessive permissions, external sharing, and other access-related risks.


Question 2

Which issue is Data Access Governance primarily designed to identify?

A. SQL database corruption

B. Printer failures

C. Oversharing of SharePoint content

D. Network latency

Correct Answer: C

Explanation: The primary purpose is to detect oversharing and excessive permissions across SharePoint.


Question 3

Why is Data Access Governance especially important before deploying Microsoft 365 Copilot?

A. Copilot automatically changes permissions.

B. Copilot ignores SharePoint security.

C. Copilot copies all SharePoint files.

D. Copilot can reference content users already have permission to access.

Correct Answer: D

Explanation: Copilot honors existing permissions. Overshared content may therefore appear in Copilot responses if users already have legitimate access.


Question 4

Which type of access represents a potential oversharing risk?

A. Anonymous sharing links

B. Azure subscription ownership

C. Exchange mailbox size

D. Microsoft Teams background images

Correct Answer: A

Explanation: Anonymous links allow access without authentication and should be reviewed carefully.


Question 5

What question does Data Access Governance primarily help answer?

A. Which users have excessive access to SharePoint content?

B. Which Windows updates are missing?

C. Which devices need antivirus software?

D. Which Microsoft 365 licenses should be purchased?

Correct Answer: A

Explanation: Data Access Governance focuses on permissions, sharing, and access to SharePoint content.


Question 6

Which Microsoft 365 principle is supported by regularly reviewing Data Access Governance reports?

A. Unlimited collaboration

B. Least privilege

C. Maximum storage allocation

D. Unlimited guest access

Correct Answer: B

Explanation: Regular reviews help ensure users have only the permissions necessary to perform their work.


Question 7

Which type of SharePoint site would likely appear as higher risk in a Data Access Governance report?

A. A private HR site with restricted access

B. A site shared with only one administrator

C. A site containing sensitive files that is accessible to everyone

D. A newly created empty site

Correct Answer: C

Explanation: Sensitive information combined with broad permissions represents a significant oversharing risk.


Question 8

How does Data Access Governance complement Microsoft Purview?

A. Both products only classify documents.

B. Data Access Governance focuses on permissions, while Purview focuses on data protection and governance.

C. They perform identical functions.

D. Purview replaces SharePoint permissions.

Correct Answer: B

Explanation: Purview governs and protects data, while Data Access Governance helps administrators understand who has access to that data.


Question 9

Which action should an administrator consider after identifying an overshared SharePoint site?

A. Delete all documents immediately.

B. Disable Microsoft 365 Copilot.

C. Purchase additional SharePoint storage.

D. Review and reduce unnecessary permissions.

Correct Answer: D

Explanation: The appropriate response is to evaluate existing permissions and remove excessive or unnecessary access while maintaining business needs.


Question 10

Which statement about Microsoft 365 Copilot and Data Access Governance is true?

A. Data Access Governance prevents all Copilot responses.

B. Copilot bypasses SharePoint permissions when generating answers.

C. Data Access Governance helps reduce the risk of Copilot surfacing overshared information by identifying excessive permissions.

D. Copilot encrypts all SharePoint documents before using them.

Correct Answer: C

Explanation: By identifying and remediating overshared permissions, Data Access Governance helps ensure Copilot only surfaces information that users are appropriately authorized to access.


Go to the AB-900 Exam Prep Hub main page

Identify the tools to troubleshoot oversharing in an organization (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Identify the tools to troubleshoot oversharing in an organization


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

This topic measures your understanding of how Microsoft 365 administrators can identify, investigate, and reduce oversharing of organizational data. As organizations adopt Microsoft 365 Copilot and AI-powered experiences, ensuring that users only have access to the information they should see becomes increasingly important.

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand:

  • What oversharing is
  • Why oversharing is a security and governance concern
  • The Microsoft tools used to identify and troubleshoot oversharing
  • How these tools work together
  • Best practices for reducing oversharing before and after deploying Microsoft 365 Copilot

You are not expected to configure these tools in detail, but you should know their purpose and common use cases.


What Is Oversharing?

Oversharing occurs when users have access to files, folders, emails, or sites that they do not need to perform their job.

Because Microsoft 365 Copilot respects existing Microsoft 365 permissions, users can potentially discover information through Copilot that they already have permission to access—even if that access was unintentionally granted.

For example:

  • A SharePoint site allows “Everyone except external users” access.
  • A confidential HR folder inherits overly broad permissions.
  • A OneDrive file is shared organization-wide instead of with a specific team.
  • A Teams site contains sensitive documents accessible by unnecessary members.

Copilot does not bypass security—it simply surfaces information users are already authorized to access.


Why Troubleshooting Oversharing Is Important

Oversharing can lead to:

  • Exposure of confidential business information
  • Disclosure of financial data
  • HR privacy issues
  • Intellectual property leaks
  • Increased insider risk
  • Compliance violations
  • Unintentional exposure through Microsoft 365 Copilot

The goal is to identify excessive permissions before sensitive information is exposed.


Common Causes of Oversharing

Oversharing often results from:

  • Incorrect SharePoint permissions
  • Excessive sharing links
  • Broken inheritance
  • Organization-wide sharing
  • Large Microsoft 365 Groups
  • Incorrect Teams membership
  • Overly permissive OneDrive sharing
  • Legacy permissions that were never reviewed
  • Users manually sharing files without understanding permissions

Microsoft Tools Used to Troubleshoot Oversharing

Microsoft provides several complementary tools.


1. SharePoint Advanced Management

One of the primary tools for identifying oversharing is SharePoint Advanced Management.

It helps administrators:

  • Discover overshared sites
  • Identify risky permissions
  • Detect excessive sharing
  • Review permission inheritance
  • Monitor external sharing

Administrators can prioritize remediation efforts before deploying Copilot broadly.


2. SharePoint Site Permissions

Administrators should review:

  • Site Owners
  • Site Members
  • Site Visitors

Questions to ask include:

  • Does everyone need access?
  • Are external users still required?
  • Are permissions inherited correctly?
  • Are there unnecessary site members?

3. Site Access Reviews

Regular permission reviews help identify:

  • Inactive users
  • Former employees
  • Contractors
  • Oversized groups
  • Outdated access

Periodic reviews significantly reduce oversharing.


4. Microsoft Purview Data Security Posture Management (DSPM) for AI

DSPM for AI helps organizations understand AI-related security risks.

It can identify:

  • Sensitive data exposed to Copilot
  • AI usage patterns
  • High-risk data locations
  • Overshared sensitive files
  • Permission-related risks

DSPM combines AI activity with data classification to prioritize remediation.


5. Microsoft Purview Data Explorer

Data Explorer provides visibility into where sensitive information exists.

Administrators can discover:

  • Credit card numbers
  • Passport numbers
  • Financial records
  • Health information
  • Confidential documents

Once sensitive data is identified, administrators can determine whether it is overshared.


6. Microsoft Purview Activity Explorer

Activity Explorer helps investigate how sensitive content is being used.

It displays activities such as:

  • File sharing
  • Downloads
  • Label application
  • Label removal
  • DLP events

This helps identify whether overshared content is actively being accessed.


7. Microsoft Purview Content Search

Content Search helps locate:

  • Emails
  • Documents
  • Teams conversations
  • SharePoint files
  • OneDrive files

Investigators can search for sensitive information and determine whether it resides in overshared locations.


8. Microsoft Purview Audit

Audit logs provide visibility into user actions.

Examples include:

  • File viewed
  • File shared
  • Permission changed
  • Link created
  • Link removed
  • Site membership changed

Audit records help determine:

  • Who shared a document
  • When sharing occurred
  • Which users accessed the content

9. Microsoft Purview Data Loss Prevention (DLP)

Although DLP does not directly identify oversharing, it helps prevent sensitive information from leaving approved locations.

DLP policies can:

  • Block sharing
  • Warn users
  • Prevent uploads
  • Restrict downloads
  • Notify administrators

DLP reduces the impact of accidental oversharing.


10. Microsoft Purview Information Protection

Sensitivity labels classify and protect information.

Labels can:

  • Encrypt documents
  • Restrict access
  • Prevent forwarding
  • Apply visual markings
  • Require authentication

Even if a document is accidentally shared, encryption can prevent unauthorized access.


11. Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps provides insight into cloud file sharing.

Administrators can identify:

  • Publicly shared files
  • Anonymous links
  • External sharing
  • Risky user behavior
  • Unusual downloads

It helps detect cloud-based oversharing risks.


12. Microsoft Entra ID

Microsoft Entra ID helps troubleshoot identity-related oversharing by reviewing:

  • Group memberships
  • Role assignments
  • Dynamic groups
  • Guest users
  • External identities

Sometimes oversharing occurs because users belong to inappropriate security groups.


Reviewing Sharing Links

Sharing links are a common source of oversharing.

Administrators should review whether links are:

  • Anyone links
  • Organization links
  • Specific people links
  • Existing access links

Generally:

  • “Specific people” links are the most restrictive.
  • “Anyone” links present the greatest oversharing risk.

Reviewing Permission Inheritance

SharePoint uses permission inheritance.

A folder may inherit permissions from:

  • Site
  • Library
  • Parent folder

Broken inheritance can accidentally expose sensitive information.

Administrators should verify whether:

  • Inheritance is appropriate
  • Unique permissions are necessary
  • Sensitive folders have restricted access

Using Sensitivity Labels to Reduce Oversharing

Sensitivity labels provide another layer of protection.

Examples include:

  • Public
  • General
  • Confidential
  • Highly Confidential

Labels may automatically:

  • Encrypt content
  • Restrict downloads
  • Prevent printing
  • Block copying
  • Limit sharing

Copilot respects these protections.


Using Audit Logs During Investigations

If oversharing is suspected, administrators often review audit logs.

Audit logs answer questions such as:

  • Who shared the file?
  • When was it shared?
  • Was an anonymous link created?
  • Who opened the document?
  • Was the file downloaded?
  • Were permissions modified?

This information is critical during investigations.


Relationship to Microsoft 365 Copilot

Copilot does not ignore Microsoft 365 security.

Instead, it:

  • Uses Microsoft Graph to retrieve content
  • Honors Microsoft 365 permissions
  • Respects sensitivity labels
  • Honors encryption
  • Respects DLP protections
  • Uses existing access controls

If permissions are too broad, Copilot can surface information to users who already have that access.

Therefore, reducing oversharing before deployment is considered a best practice.


Typical Oversharing Investigation Workflow

A common workflow includes:

  1. Identify sensitive data using Data Explorer.
  2. Review AI exposure using DSPM for AI.
  3. Examine permissions in SharePoint.
  4. Review sharing links.
  5. Check Audit logs.
  6. Investigate user activity in Activity Explorer.
  7. Restrict permissions where necessary.
  8. Apply sensitivity labels.
  9. Implement DLP policies.
  10. Continue monitoring for future risks.

Best Practices

Organizations should:

  • Review SharePoint permissions regularly.
  • Remove unnecessary access.
  • Limit organization-wide sharing.
  • Use “Specific people” sharing links whenever possible.
  • Classify sensitive information.
  • Apply sensitivity labels.
  • Implement DLP policies.
  • Monitor audit logs.
  • Conduct periodic access reviews.
  • Review oversharing before enabling Microsoft 365 Copilot organization-wide.

Key Exam Tips

Remember these important points for the AB-900 exam:

  • Oversharing occurs when users have unnecessary access to data.
  • Microsoft 365 Copilot respects existing permissions—it does not bypass security.
  • SharePoint Advanced Management helps identify overshared sites and permissions.
  • Microsoft Purview DSPM for AI helps identify AI-related exposure risks.
  • Data Explorer identifies where sensitive information resides.
  • Activity Explorer shows how sensitive data is being used.
  • Audit logs reveal sharing and permission changes.
  • Sensitivity labels and DLP help reduce the risks associated with oversharing.
  • Regular permission reviews are one of the most effective ways to prevent oversharing.

Practice Exam Questions

Question 1

Which Microsoft solution is specifically designed to help administrators identify overshared SharePoint sites before deploying Microsoft 365 Copilot?

A. Microsoft Defender Antivirus

B. SharePoint Advanced Management

C. Exchange Online Protection

D. Microsoft Intune

Correct Answer: B

Explanation: SharePoint Advanced Management provides visibility into oversharing risks, site permissions, and excessive access, helping organizations prepare for AI deployments.


Question 2

Why is oversharing considered a concern when using Microsoft 365 Copilot?

A. Copilot ignores Microsoft 365 permissions.

B. Copilot automatically shares documents externally.

C. Copilot can surface information that users already have permission to access.

D. Copilot disables sensitivity labels.

Correct Answer: C

Explanation: Copilot respects existing Microsoft 365 permissions. If permissions are overly broad, users may discover sensitive information they technically have access to but should not.


Question 3

Which Microsoft Purview feature helps identify where sensitive information such as credit card numbers and passport numbers is stored?

A. Compliance Manager

B. Insider Risk Management

C. Data Explorer

D. Communication Compliance

Correct Answer: C

Explanation: Data Explorer provides visibility into the location and distribution of sensitive information across Microsoft 365.


Question 4

An administrator wants to determine who shared a confidential document and when it was shared. Which tool should they use?

A. Microsoft Purview Audit

B. Microsoft Planner

C. Microsoft Viva Insights

D. Microsoft Bookings

Correct Answer: A

Explanation: Audit logs record sharing events, permission changes, and other user activities, making them essential for investigations.


Question 5

Which type of SharePoint sharing link generally presents the greatest oversharing risk?

A. Existing access

B. Specific people

C. Organization

D. Anyone

Correct Answer: D

Explanation: “Anyone” links allow access without authentication (unless restricted by policy), making them the highest-risk sharing option.


Question 6

Which Microsoft Purview solution helps administrators understand AI-related exposure risks and overshared sensitive information?

A. Data Security Posture Management (DSPM) for AI

B. Compliance Manager

C. eDiscovery

D. Message Encryption

Correct Answer: A

Explanation: DSPM for AI identifies sensitive data exposure, AI usage, and risks associated with Microsoft 365 Copilot and other AI applications.


Question 7

Which Microsoft Purview feature helps administrators review how sensitive files have been shared, downloaded, or labeled?

A. Data Lifecycle Management

B. Activity Explorer

C. Content Search

D. Records Management

Correct Answer: B

Explanation: Activity Explorer provides visibility into user activities involving sensitive content, including sharing, labeling, and DLP events.


Question 8

What is one effective way to reduce oversharing in SharePoint?

A. Increase anonymous sharing.

B. Remove all sensitivity labels.

C. Grant every employee site owner permissions.

D. Perform regular permission and access reviews.

Correct Answer: D

Explanation: Periodic permission reviews help identify unnecessary access, outdated memberships, and excessive permissions before they become security risks.


Question 9

Which statement correctly describes Microsoft 365 Copilot?

A. It bypasses Microsoft Purview protections.

B. It ignores SharePoint permissions.

C. It respects existing Microsoft 365 permissions and security controls.

D. It automatically encrypts all documents.

Correct Answer: C

Explanation: Copilot only accesses content that users are already authorized to view and honors permissions, sensitivity labels, encryption, and other Microsoft 365 security controls.


Question 10

Which combination of tools provides the most complete approach to troubleshooting oversharing?

A. Microsoft Paint and Notepad

B. Microsoft Purview Audit, Data Explorer, Activity Explorer, DSPM for AI, and SharePoint Advanced Management

C. Microsoft Teams and Outlook only

D. Microsoft Excel and Word

Correct Answer: B

Explanation: These tools complement one another by identifying sensitive data, monitoring activity, reviewing AI exposure, auditing sharing events, and analyzing SharePoint permissions, enabling administrators to effectively investigate and remediate oversharing risks.


Go to the AB-900 Exam Prep Hub main page

Search for files and emails by using Content Search in Microsoft Purview eDiscovery (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Search for files and emails by using Content Search in Microsoft Purview eDiscovery


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

This topic measures your understanding of how administrators and compliance professionals use Microsoft Purview eDiscovery Content Search to locate emails, documents, Teams conversations, and other Microsoft 365 content during investigations, audits, legal matters, and compliance activities.

For the AB-900 exam, you are not expected to become an eDiscovery specialist. Instead, you should understand:

  • The purpose of Content Search
  • What types of content can be searched
  • How searches work
  • Common search criteria
  • Permissions required
  • Typical use cases
  • How Content Search supports Microsoft 365 Copilot governance

What Is Microsoft Purview eDiscovery?

Microsoft Purview eDiscovery is a Microsoft Purview solution that helps organizations identify, preserve, search, review, and export electronically stored information (ESI).

It is commonly used for:

  • Internal investigations
  • Legal discovery
  • Regulatory compliance
  • Human resources investigations
  • Security investigations
  • Privacy requests
  • Audits

One of the most frequently used capabilities within eDiscovery is Content Search.


What Is Content Search?

Content Search allows administrators and investigators to search across Microsoft 365 for specific information without manually checking each user’s mailbox or files.

Instead of searching one mailbox at a time, Content Search can simultaneously search:

  • Exchange Online mailboxes
  • SharePoint Online sites
  • OneDrive accounts
  • Microsoft Teams messages
  • Viva Engage (Yammer) messages (where supported)
  • Microsoft 365 Groups
  • Copilot-related stored content (through underlying Microsoft 365 data)

Think of it as an enterprise-wide search engine designed for compliance investigations.


Why Organizations Use Content Search

Organizations perform Content Searches to:

  • Locate specific emails
  • Find confidential documents
  • Investigate insider threats
  • Respond to legal requests
  • Prepare evidence for court
  • Support compliance audits
  • Investigate data leaks
  • Review suspicious activity
  • Locate files related to AI-generated work

Where Content Search Is Located

Content Search is available in the Microsoft Purview portal under:

Microsoft Purview → eDiscovery

Administrators can:

  • Create searches
  • Edit searches
  • Run searches
  • Preview results
  • Export results (with appropriate permissions)

Content That Can Be Searched

Content Search supports many Microsoft 365 workloads.

Examples include:

Exchange Online

Searches include:

  • Emails
  • Calendar items
  • Contacts
  • Tasks
  • Attachments

Example:

Find every email containing a specific customer name.


SharePoint Online

Can search:

  • Documents
  • PDFs
  • Word files
  • Excel files
  • PowerPoint presentations
  • Lists

Example:

Locate every document containing a confidential project code.


OneDrive for Business

Searches users’ personal work files.

Example:

Find documents uploaded by an employee before they resigned.


Microsoft Teams

Can search:

  • Chat messages
  • Channel conversations
  • Shared files

Example:

Find Teams conversations discussing a confidential acquisition.


Microsoft 365 Groups

Includes:

  • Group mailboxes
  • Shared documents

How Content Search Works

A Content Search generally follows these steps.

Step 1

Create a search.


Step 2

Select locations.

Examples:

  • Specific mailbox
  • All mailboxes
  • OneDrive sites
  • SharePoint sites
  • Teams

Step 3

Define search conditions.

Examples:

  • Keywords
  • Dates
  • Senders
  • Recipients
  • File types

Step 4

Run the search.

Microsoft indexes the selected content and returns matching results.


Step 5

Review results.

Administrators can:

  • View statistics
  • Preview items
  • Refine search criteria

Step 6

Export results if necessary.

This is common during legal investigations.


Search Locations

Content Search allows searches across:

  • Individual mailboxes
  • Shared mailboxes
  • Distribution groups
  • SharePoint sites
  • OneDrive accounts
  • Microsoft Teams
  • Specific users
  • Entire organization

Common Search Criteria

Administrators can filter searches using many conditions.

Keywords

Search for:

  • Customer names
  • Project names
  • Product codes
  • Sensitive terms

Example:

Confidential

Sender

Locate messages sent by:

john@contoso.com

Recipient

Locate emails received by:

finance@contoso.com

Date Range

Example:

January 1 through March 31.

Useful during investigations.


File Type

Examples:

  • PDF
  • DOCX
  • XLSX
  • PPTX

File Name

Search for a specific document.

Example:

Budget2026.xlsx

Sensitive Information

When combined with Microsoft Purview classifications, administrators can search for:

  • Credit card numbers
  • Social Security numbers
  • Passport numbers
  • Financial records

Keyword Query Language (KQL)

Content Search uses Keyword Query Language (KQL).

Administrators can build more advanced searches.

Examples include:

  • AND
  • OR
  • NOT
  • Parentheses
  • Property filters

Example:

Project AND Budget

Example:

Budget OR Forecast

Example:

Confidential NOT Draft

The AB-900 exam only expects a basic understanding that KQL enables more precise searches.


Search Results

After a search completes, administrators receive:

  • Number of matching items
  • Number of locations searched
  • Total estimated size
  • Search statistics
  • Preview of matching items

The search does not automatically change or delete content.


Previewing Results

Before exporting data, investigators can preview:

  • Emails
  • Documents
  • Teams conversations

Previewing helps determine whether additional filtering is needed.


Exporting Results

Authorized users can export search results.

Exports may include:

  • PST files
  • Native Office documents
  • PDFs
  • Metadata
  • Reports

Exporting is commonly used for:

  • Courts
  • Attorneys
  • Regulatory agencies
  • Internal investigations

Permissions Required

Not every administrator can perform Content Searches.

Organizations typically assign permissions using Microsoft Purview role groups.

Common roles include:

  • eDiscovery Manager
  • eDiscovery Administrator
  • Compliance Administrator

Least privilege should always be followed.


Content Search vs eDiscovery Cases

These concepts are related but different.

Content SearcheDiscovery Case
Searches contentManages investigations
Can be run independentlyOrganizes legal matters
Finds informationStores searches, holds, reviewers, exports
Useful for quick investigationsUseful for complete legal workflows

Think of Content Search as one tool inside the broader eDiscovery process.


How Content Search Supports Microsoft 365 Copilot

Microsoft 365 Copilot retrieves information users already have permission to access.

If sensitive information exists within Microsoft 365:

  • Copilot may surface it to authorized users.
  • Administrators can use Content Search to identify where sensitive information is stored.
  • This helps organizations improve governance before deploying AI widely.

Examples include:

  • Confidential HR files
  • Financial reports
  • Intellectual property
  • Legal documents

Relationship with Other Microsoft Purview Features

Content Search works alongside many Purview capabilities.

Sensitivity Labels

Search labeled documents.


Data Loss Prevention (DLP)

Investigate DLP incidents.


Retention Policies

Locate retained content.


Insider Risk Management

Search content involved in investigations.


Audit

Correlate search results with user activities.


eDiscovery Premium

Use Content Search as part of advanced legal investigations.


Best Practices

Microsoft recommends that organizations:

  • Search only necessary locations.
  • Use descriptive search names.
  • Apply precise filters.
  • Limit access using least privilege.
  • Preview results before exporting.
  • Protect exported evidence.
  • Maintain audit logs.
  • Regularly review permissions.
  • Use Content Search together with retention and sensitivity labels.
  • Govern sensitive data before deploying Microsoft 365 Copilot broadly.

Key Exam Tips

Remember these important points for the AB-900 exam:

  • Content Search is part of Microsoft Purview eDiscovery.
  • It searches across Microsoft 365 services from one interface.
  • It can search Exchange, SharePoint, OneDrive, Teams, and other supported workloads.
  • Searches can be filtered by keywords, users, dates, file types, and other properties.
  • Search results can be previewed before export.
  • Appropriate permissions are required to perform searches.
  • Content Search helps organizations investigate compliance, legal, and security incidents.
  • It supports Microsoft 365 Copilot governance by helping organizations identify where sensitive information exists.

Practice Exam Questions

Question 1

An administrator needs to locate every email containing the phrase “Quarterly Budget” across the organization. Which Microsoft Purview feature should they use?

A. Communication Compliance

B. Content Search in eDiscovery

C. Insider Risk Management

D. Compliance Manager

Correct Answer: B

Explanation: Content Search enables administrators to search mailboxes, SharePoint sites, OneDrive, Teams, and other Microsoft 365 locations for keywords and other search criteria.


Question 2

Which Microsoft 365 workload can be searched by Microsoft Purview Content Search?

A. Exchange Online

B. Microsoft Teams

C. SharePoint Online

D. All of the above

Correct Answer: D

Explanation: Content Search supports multiple Microsoft 365 workloads, including Exchange Online, SharePoint Online, OneDrive, Teams, Microsoft 365 Groups, and more.


Question 3

Before exporting search results, what is the recommended action?

A. Delete duplicate items.

B. Apply a retention policy.

C. Preview the search results.

D. Disable auditing.

Correct Answer: C

Explanation: Previewing results helps verify that the search returned the intended items before exporting data.


Question 4

What is the primary purpose of Microsoft Purview Content Search?

A. Encrypt documents automatically.

B. Create sensitivity labels.

C. Monitor endpoint devices.

D. Locate content across Microsoft 365 for investigations and compliance.

Correct Answer: D

Explanation: Content Search is designed to find emails, files, chats, and other content across Microsoft 365 to support investigations, audits, and legal discovery.


Question 5

Which search criterion could an administrator use to narrow Content Search results?

A. Sender

B. File type

C. Date range

D. All of the above

Correct Answer: D

Explanation: Administrators can filter searches by numerous criteria, including sender, recipient, keywords, dates, and file types.


Question 6

Why is Content Search important for Microsoft 365 Copilot governance?

A. It trains Copilot models.

B. It identifies where sensitive information is stored so organizations can better govern AI access.

C. It automatically blocks Copilot prompts.

D. It creates Copilot licenses.

Correct Answer: B

Explanation: Understanding where sensitive information resides helps organizations apply appropriate governance before broad Copilot deployment.


Question 7

Which language provides advanced query capabilities for Content Search?

A. SQL

B. PowerShell

C. XPath

D. Keyword Query Language (KQL)

Correct Answer: D

Explanation: Content Search uses KQL to build advanced searches using keywords, logical operators, and property filters.


Question 8

Which statement about Content Search permissions is correct?

A. Every Microsoft 365 user can run organization-wide searches.

B. Only Global Administrators can perform Content Searches.

C. Appropriate Microsoft Purview roles are required to perform Content Searches.

D. Content Search requires no administrative permissions.

Correct Answer: C

Explanation: Organizations assign eDiscovery and compliance roles to authorized users who need to perform searches.


Question 9

A compliance investigator wants to search only documents stored in employees’ personal cloud storage. Which location should be selected?

A. Microsoft Teams

B. OneDrive for Business

C. Exchange Online

D. Microsoft Entra ID

Correct Answer: B

Explanation: OneDrive for Business stores users’ personal work files and can be targeted independently during a Content Search.


Question 10

Which statement best describes Microsoft Purview Content Search?

A. It permanently deletes search results after completion.

B. It automatically applies retention labels to matching items.

C. It searches Microsoft 365 content and allows authorized users to review and export matching results.

D. It encrypts all files matching the search query.

Correct Answer: C

Explanation: Content Search is a discovery tool that locates content across Microsoft 365, allowing investigators to preview and export results without modifying the original data.


Go to the AB-900 Exam Prep Hub main page

Discover and manage AI activity by using DSPM for AI (Part 2) (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Discover and manage AI activity by using DSPM for AI


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

In Part 1, you learned how Microsoft Purview Data Security Posture Management (DSPM) for AI helps organizations discover AI activity, identify sensitive data exposure, detect oversharing, and provide visibility into how AI interacts with Microsoft 365 data.

This section (Part 2) focuses on how DSPM for AI helps administrators manage AI-related risks, integrates with other Microsoft security and compliance services, and supports secure AI adoption.


Security Recommendations Generated by DSPM for AI

One of DSPM for AI’s most valuable capabilities is providing actionable security recommendations rather than simply identifying problems.

After analyzing an organization’s AI environment, DSPM highlights areas that should be improved to reduce the likelihood of accidental data exposure or compliance violations.

Examples of recommendations include:

  • Reduce excessive SharePoint permissions.
  • Apply sensitivity labels to unclassified confidential files.
  • Configure Data Loss Prevention (DLP) policies.
  • Limit external sharing.
  • Protect highly confidential document libraries.
  • Enable auditing for AI-related activities.
  • Improve data governance before expanding AI deployments.

These recommendations help administrators prioritize improvements based on potential business impact and security risk.


Risk Prioritization

Not every security finding represents the same level of risk.

DSPM helps prioritize remediation efforts by evaluating factors such as:

  • Amount of sensitive data exposed
  • Number of users with access
  • Business importance of the data
  • Existing protection mechanisms
  • AI usage patterns
  • Permission inheritance
  • Regulatory implications

This enables administrators to address the highest-risk issues first.

For example:

RiskPriority
Public access to executive financial reportsHigh
Sensitive HR documents lacking labelsHigh
Marketing presentations shared internallyMedium
Public training documentsLow

Discovering AI-Related Data Exposure

Organizations often ask:

“If we enable Microsoft 365 Copilot today, what sensitive information could users potentially discover?”

DSPM helps answer this question.

It analyzes:

  • Existing permissions
  • Data classifications
  • Sharing configurations
  • Microsoft Graph relationships
  • Collaboration patterns

This provides insight into which sensitive data could become more discoverable through AI-assisted searches and summaries.

Remember:

Copilot does not bypass security permissions. It only accesses information that the signed-in user is already authorized to access. DSPM helps identify situations where those permissions may already be too broad.


Remediation Recommendations

After identifying risks, DSPM recommends remediation steps.

Common recommendations include:

Reduce Oversharing

Examples include:

  • Remove unnecessary SharePoint permissions.
  • Restrict Microsoft Teams membership.
  • Remove Everyone access.
  • Limit guest sharing.

Improve Data Classification

Examples include:

  • Apply sensitivity labels.
  • Enable automatic labeling.
  • Use trainable classifiers.
  • Configure sensitive information types.

Better classification improves downstream protections across Microsoft Purview.


Strengthen Data Protection Policies

DSPM may recommend:

  • Creating DLP policies
  • Encrypting confidential documents
  • Restricting downloads
  • Blocking external sharing
  • Applying retention labels

Review AI Access

Administrators may decide to:

  • Limit AI rollout to selected departments
  • Review permissions before enabling Copilot broadly
  • Reduce access to legacy repositories
  • Remove stale user accounts

Integration with Microsoft Purview

DSPM for AI does not operate as an isolated product.

Instead, it complements several Microsoft Purview solutions.

Understanding these relationships is important for the AB-900 exam.


Microsoft Purview Information Protection

Information Protection classifies and protects data.

DSPM benefits from these classifications.

For example:

A document labeled:

  • Highly Confidential
  • Internal Only
  • Financial
  • Legal

helps DSPM understand the sensitivity of AI-accessible content.

Without labels, DSPM has less context when evaluating risk.


Microsoft Purview Data Loss Prevention (DLP)

DLP prevents sensitive information from being shared inappropriately.

DSPM identifies potential risks.

DLP helps enforce policies to prevent those risks from becoming incidents.

Example workflow:

  1. DSPM discovers sensitive payroll files.
  2. DLP prevents external sharing.
  3. Organization reduces AI-related exposure.

Microsoft Purview Insider Risk Management

DSPM identifies risky data exposure.

Insider Risk Management identifies risky user behavior.

Together they help answer two different questions:

DSPM asks:

“What sensitive data could AI access?”

Insider Risk asks:

“Is someone attempting to misuse sensitive data?”

These products complement one another.


Microsoft Purview Activity Explorer

Activity Explorer provides visibility into user interactions with sensitive information.

DSPM can use Activity Explorer insights to better understand:

  • Sensitive file access
  • Label usage
  • DLP events
  • Data movement

Administrators gain a clearer understanding of how protected information is being used across Microsoft 365.


Microsoft Purview Compliance Manager

Compliance Manager focuses on regulatory compliance.

DSPM focuses on AI data governance.

Together they help organizations:

  • Reduce compliance risk
  • Improve governance
  • Meet regulatory requirements
  • Protect sensitive information used by AI

Microsoft Defender

Microsoft Defender protects identities, endpoints, applications, and cloud resources.

DSPM complements Defender by focusing specifically on AI-related data risks.

Examples:

Microsoft Defender detects:

  • Malware
  • Credential theft
  • Phishing
  • Device compromise

DSPM identifies:

  • Overshared files
  • AI exposure
  • Sensitive data visibility
  • Permission risks

AI Governance Dashboard

DSPM provides dashboards that help administrators understand their organization’s AI posture.

Typical dashboard information includes:

  • AI adoption trends
  • Sensitive data exposure
  • High-risk repositories
  • Oversharing statistics
  • AI application inventory
  • Policy recommendations
  • Governance posture

Rather than investigating individual files, administrators receive a broad organizational view.


Discovering AI Applications

DSPM helps organizations understand:

  • Which AI tools are in use
  • Which departments use them
  • Adoption trends
  • AI usage over time

Examples include:

  • Microsoft 365 Copilot
  • Microsoft Copilot Chat
  • Supported third-party AI services

This visibility helps organizations establish AI governance policies.


Investigating AI Risks

Administrators typically investigate findings by asking questions such as:

  • Which sensitive files are accessible?
  • Who has access?
  • Why do they have access?
  • Is the data properly labeled?
  • Are permissions appropriate?
  • Is the data externally shared?
  • Should additional protection be applied?

DSPM helps surface this information so administrators can make informed decisions.


Typical Investigation Workflow

A simplified investigation might follow these steps:

Step 1

DSPM identifies an overshared SharePoint site.

Step 2

Administrator reviews permissions.

Step 3

Sensitive files are discovered.

Step 4

Sensitivity labels are applied.

Step 5

Permissions are reduced.

Step 6

DLP policies are enabled.

Step 7

Risk is reduced before broader Copilot deployment.


Best Practices

Organizations implementing Microsoft 365 Copilot should follow several best practices.

Review Permissions Before AI Rollout

Avoid enabling Copilot before understanding existing permissions.


Classify Sensitive Data

Use Microsoft Purview Information Protection to classify important documents.


Apply Least Privilege

Users should only have access to information required for their job.


Reduce Oversharing

Review:

  • SharePoint permissions
  • Teams memberships
  • OneDrive sharing
  • External sharing

Enable DLP

Prevent accidental sharing of confidential information.


Monitor AI Adoption

Understand:

  • Who uses AI
  • Which departments use AI
  • What information AI accesses

Regularly Review Recommendations

DSPM continuously evaluates the environment.

Administrators should regularly review new recommendations as data, permissions, and AI usage evolve.


Licensing Considerations

For the AB-900 exam, you are not expected to memorize licensing details, as licensing can change over time.

However, you should understand these general principles:

  • DSPM for AI is part of the Microsoft Purview family.
  • Advanced governance and AI security capabilities may require appropriate Microsoft licensing.
  • Organizations should verify current licensing requirements before deployment.

Common Exam Scenarios

You may encounter questions like:

Scenario 1

An organization wants to know whether Microsoft 365 Copilot could expose confidential HR documents because of existing permissions.

Relevant technology:

Microsoft Purview DSPM for AI


Scenario 2

Administrators want recommendations to reduce AI-related data exposure before deploying Copilot.

Relevant technology:

Microsoft Purview DSPM for AI


Scenario 3

Security administrators want visibility into AI adoption across Microsoft 365.

Relevant technology:

Microsoft Purview DSPM for AI


Scenario 4

Administrators want to identify overshared SharePoint sites that AI could access.

Relevant technology:

Microsoft Purview DSPM for AI


Scenario 5

An organization wants to understand where sensitive information may be exposed through AI.

Relevant technology:

Microsoft Purview DSPM for AI


Common Misconceptions

Misconception 1

DSPM blocks AI prompts.

Incorrect.

DSPM primarily discovers, assesses, and helps reduce AI-related data risks. It is not a prompt-filtering or AI-blocking solution.


Misconception 2

Copilot ignores permissions.

Incorrect.

Copilot always respects the signed-in user’s existing Microsoft 365 permissions.


Misconception 3

DSPM replaces Microsoft Purview DLP.

Incorrect.

DSPM identifies risks, while DLP enforces policies that help prevent inappropriate sharing of sensitive data.


Misconception 4

DSPM replaces Microsoft Defender.

Incorrect.

Defender focuses on threats and attacks, whereas DSPM focuses on AI-related data exposure and governance.


Misconception 5

DSPM automatically fixes security issues.

Incorrect.

DSPM provides visibility, recommendations, and guidance. Administrators remain responsible for implementing changes such as adjusting permissions, applying labels, or configuring policies.


AB-900 Exam Tips

Focus on these key concepts:

  • Microsoft Purview DSPM for AI is an AI governance and visibility solution.
  • It helps organizations discover AI usage, identify sensitive data exposure, and reduce AI-related risks.
  • DSPM does not bypass or modify Microsoft 365 permissions.
  • It works alongside Information Protection, DLP, Insider Risk Management, Activity Explorer, Compliance Manager, and Microsoft Defender.
  • One of its primary goals is to identify oversharing before it becomes a business risk.
  • DSPM provides recommendations, not automatic remediation.
  • It supports organizations throughout the AI adoption lifecycle by helping them continuously improve their security posture.

Chapter Summary

Microsoft Purview DSPM for AI enables organizations to adopt AI confidently by providing visibility into how AI interacts with organizational data. It discovers AI usage, inventories AI applications, identifies oversharing, evaluates sensitive data exposure, and recommends actions to strengthen governance.

Rather than replacing existing Microsoft Purview or Microsoft Defender capabilities, DSPM for AI enhances them by adding AI-specific insights. It integrates with Information Protection, Data Loss Prevention, Insider Risk Management, Activity Explorer, Compliance Manager, and Microsoft Defender to create a comprehensive approach to AI governance.

For the AB-900 exam, remember that DSPM for AI is fundamentally about discovering, assessing, and managing AI-related data risks. It helps administrators understand where AI could expose sensitive information due to existing permissions and governance gaps, enabling organizations to improve their security posture before and during Microsoft 365 Copilot deployment.


Practice Exam Questions


Question 1

A company plans to deploy Microsoft 365 Copilot across all departments. Before deployment, administrators want to determine whether confidential documents are overly accessible due to existing SharePoint permissions.

Which Microsoft solution should they use?

A. Microsoft Entra Domain Services

B. Microsoft Defender for Endpoint

C. Microsoft Intune

D. Microsoft Purview Data Security Posture Management (DSPM) for AI

Correct Answer: D

Explanation

Microsoft Purview DSPM for AI helps organizations discover overshared content, evaluate AI-related data exposure, and identify permission risks before deploying AI solutions such as Microsoft 365 Copilot.

  • A is correct because DSPM for AI analyzes permissions and identifies AI-related security risks.
  • B is incorrect because Defender for Endpoint protects devices.
  • C is incorrect because Intune manages devices and applications.
  • D is incorrect because Entra Domain Services provides managed domain services rather than AI governance.

Question 2

An administrator wants to understand which departments are actively using Microsoft 365 Copilot and other approved AI applications.

Which capability best addresses this requirement?

A. Microsoft Purview Information Protection

B. Microsoft Purview DSPM for AI

C. Microsoft Defender for Cloud Apps

D. Microsoft Entra Conditional Access

Correct Answer: B

Explanation

DSPM for AI provides visibility into AI adoption, AI application inventory, and usage trends across the organization.

  • B is correct because DSPM for AI discovers AI activity and AI adoption.
  • A classifies and protects data.
  • C monitors cloud applications but is not specifically designed for AI governance.
  • D controls authentication conditions.

Question 3

Which statement best describes how Microsoft 365 Copilot accesses organizational data?

A. It bypasses Microsoft 365 permissions when generating responses.

B. It can access all documents stored in Microsoft 365 regardless of permissions.

C. It only accesses content the signed-in user is already authorized to access.

D. It only accesses files created after Copilot was enabled.

Correct Answer: C

Explanation

Copilot respects existing Microsoft 365 permissions. It never bypasses authorization.

  • C is correct because Copilot only retrieves content the current user can already access.
  • A and B incorrectly imply that Copilot ignores permissions.
  • D is incorrect because file creation date is irrelevant.

Question 4

What is the primary purpose of Microsoft Purview DSPM for AI?

A. Prevent all AI-generated responses

B. Replace Microsoft Defender

C. Automatically encrypt all Microsoft 365 data

D. Discover AI activity and identify AI-related data risks

Correct Answer: D

Explanation

DSPM for AI provides visibility into AI usage and helps identify governance and security risks.

  • D is correct because discovering AI activity and assessing AI-related risks are its primary objectives.
  • A, B, and C describe capabilities DSPM does not provide.

Question 5

An organization discovers that hundreds of employees can access executive financial reports because of inherited SharePoint permissions.

What type of risk has DSPM for AI identified?

A. Malware infection

B. Oversharing

C. Identity synchronization failure

D. Device compliance failure

Correct Answer: B

Explanation

Oversharing occurs when users have broader access to information than intended.

  • B is correct because excessive permissions increase AI-related exposure.
  • A, C, and D are unrelated to data governance.

Question 6

Which Microsoft technology provides much of the contextual relationship information that helps DSPM for AI understand user access to Microsoft 365 content?

A. Microsoft SQL Server

B. Microsoft Defender XDR

C. Microsoft Graph

D. Azure Kubernetes Service

Correct Answer: C

Explanation

Microsoft Graph provides relationships between users, files, emails, Teams, SharePoint, and other Microsoft 365 resources.

  • C is correct because DSPM uses Microsoft Graph signals to understand data access.
  • The remaining options do not provide organizational relationship data.

Question 7

Which Microsoft Purview solution works alongside DSPM for AI by preventing inappropriate sharing of sensitive information?

A. Microsoft Purview Data Loss Prevention (DLP)

B. Microsoft Entra ID Protection

C. Microsoft Intune

D. Windows Autopilot

Correct Answer: A

Explanation

DLP enforces policies that prevent sensitive information from being shared improperly.

  • A is correct because DLP complements DSPM by enforcing protection policies.
  • B, C, and D serve different purposes.

Question 8

An administrator wants recommendations for reducing AI-related security risks before expanding Microsoft 365 Copilot deployment.

What should they use?

A. Microsoft Defender Antivirus

B. Microsoft Purview DSPM for AI

C. Exchange Online Protection

D. Microsoft Entra Connect

Correct Answer: B

Explanation

DSPM for AI evaluates AI-related risks and recommends improvements such as reducing oversharing, improving data classification, and strengthening governance.

  • B is correct because providing security recommendations is one of its core capabilities.
  • The other products address different areas of Microsoft security.

Question 9

Which action would most effectively reduce AI-related data exposure identified by DSPM for AI?

A. Disable Microsoft Teams

B. Increase mailbox quotas

C. Review permissions and apply sensitivity labels to confidential data

D. Upgrade Windows devices

Correct Answer: C

Explanation

Reducing excessive permissions and properly classifying sensitive information significantly reduces AI-related exposure.

  • C is correct because both permission management and data classification are recommended remediation actions.
  • A, B, and D do not directly address AI governance.

Question 10

Which statement best summarizes Microsoft’s approach to AI governance with DSPM for AI?

A. DSPM automatically blocks all AI interactions involving confidential information.

B. DSPM replaces Microsoft Purview Information Protection.

C. DSPM eliminates the need for Microsoft Defender.

D. DSPM provides visibility, identifies risks, and recommends actions that help organizations securely adopt AI.

Correct Answer: D

Explanation

Microsoft Purview DSPM for AI is designed to improve organizational AI security posture by discovering AI usage, identifying risks, and recommending governance improvements.

  • D is correct because it accurately reflects the purpose of DSPM for AI.
  • A is incorrect because DSPM is primarily a discovery and governance solution rather than an AI-blocking mechanism.
  • B is incorrect because Information Protection remains responsible for classifying and protecting data.
  • C is incorrect because Microsoft Defender continues to provide threat protection and complements, rather than is replaced by, DSPM for AI.

Key Takeaways for the AB-900 Exam

After studying this topic, you should be able to:

  • Explain the purpose of Microsoft Purview DSPM for AI.
  • Describe how DSPM for AI helps organizations discover and govern AI activity.
  • Understand that Microsoft 365 Copilot always respects existing user permissions.
  • Explain the concept of oversharing and why it is a significant AI-related risk.
  • Describe how Microsoft Graph provides context that enables DSPM for AI to evaluate data access.
  • Identify how DSPM for AI integrates with Microsoft Purview Information Protection, Data Loss Prevention (DLP), Insider Risk Management, Activity Explorer, Compliance Manager, and Microsoft Defender.
  • Recognize that DSPM for AI provides visibility, risk assessment, and recommendations, but administrators remain responsible for implementing remediation actions.
  • Apply DSPM for AI concepts to common AB-900 scenario-based questions involving Microsoft 365 Copilot deployments and AI governance.

These concepts form an important part of the “Identify data protection and governance risks for Microsoft 365 and Copilot” objective and are frequently tested through scenario-based questions that assess your understanding of secure AI adoption and governance.


Go to the AB-900 Exam Prep Hub main page

Discover and Manage AI activity by using DSPM for AI (Part 1) (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Discover and Manage AI activity by using DSPM for AI


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

As organizations increasingly adopt AI-powered tools such as Microsoft 365 Copilot, administrators face a new challenge: understanding how AI accesses, processes, and exposes organizational data. Traditional security tools focus on protecting users, devices, and data, but AI introduces new considerations. AI assistants can summarize documents, answer questions, generate reports, and analyze data from across an organization’s Microsoft 365 environment. If permissions are overly broad or sensitive information is poorly governed, AI can unintentionally surface information to users who already have access but should not necessarily see it in a summarized or easily discoverable form.

To address these challenges, Microsoft introduced Microsoft Purview Data Security Posture Management (DSPM) for AI, a solution designed to help organizations discover AI usage, identify potential security risks, understand data exposure, and strengthen governance before and during AI adoption.

For the AB-900 exam, you are not expected to configure DSPM for AI. Instead, you should understand:

  • What DSPM for AI is
  • Why organizations use it
  • How it discovers AI activity
  • How it helps identify risks
  • How it integrates with Microsoft Purview
  • The types of recommendations it provides

What Is Microsoft Purview DSPM for AI?

Microsoft Purview DSPM for AI is a governance and security solution that provides visibility into how artificial intelligence applications interact with organizational data.

Rather than preventing AI usage, DSPM for AI helps administrators answer important questions such as:

  • Which AI applications are employees using?
  • What sensitive information is being accessed?
  • Are AI tools exposing confidential content?
  • Are permissions overly broad?
  • Are Microsoft 365 Copilot users accessing highly sensitive data?
  • Where should security controls be strengthened?

Think of DSPM for AI as a risk discovery and governance solution specifically designed for AI workloads.


What Does “Data Security Posture Management” Mean?

The term Data Security Posture Management (DSPM) refers to continuously evaluating an organization’s data environment to identify security weaknesses before they become incidents.

DSPM focuses on questions such as:

  • Where is sensitive data stored?
  • Who has access?
  • Is the data properly classified?
  • Are security policies protecting it?
  • Could AI expose it more easily?

When AI is introduced, DSPM expands these questions to include:

  • Which AI tools are interacting with company data?
  • Which users are using AI?
  • What content is AI accessing?
  • Could AI reveal confidential information?
  • Are there oversharing risks?

Rather than reacting after a breach occurs, DSPM promotes proactive risk management.


Why Organizations Need DSPM for AI

Many organizations begin using AI before fully understanding their existing data environment.

Common issues include:

  • Excessive file permissions
  • Sensitive documents shared too broadly
  • Unlabeled confidential data
  • Legacy SharePoint permissions
  • Public Teams channels
  • Old collaboration sites
  • Inactive security policies

Without visibility into these issues, AI may legally retrieve information based on existing permissions—even though administrators were unaware those permissions existed.

DSPM for AI helps organizations discover these weaknesses before they become security problems.


Core Capabilities of DSPM for AI

Microsoft Purview DSPM for AI provides several major capabilities.

1. Discover AI Usage

DSPM identifies where AI is being used throughout the organization.

Examples include:

  • Microsoft 365 Copilot
  • Microsoft Copilot Chat
  • AI-enabled Microsoft services
  • Supported third-party AI applications

Administrators gain visibility into:

  • AI adoption
  • AI usage trends
  • Departments using AI
  • Types of AI interactions

This helps organizations understand how quickly AI is being adopted.


2. Discover Sensitive Data Exposure

DSPM evaluates whether AI has access to sensitive organizational data.

Examples include:

  • Financial reports
  • HR records
  • Customer information
  • Legal documents
  • Intellectual property
  • Healthcare information
  • Personally identifiable information (PII)

The solution identifies locations where sensitive information may be accessible through AI.


3. Identify Oversharing Risks

One of the most important concepts for the AB-900 exam is oversharing.

Oversharing occurs when users have legitimate permissions to data that administrators did not intend them to have.

For example:

  • A confidential SharePoint library inherits incorrect permissions.
  • Hundreds of employees can read executive documents.
  • Microsoft 365 Copilot can summarize those documents for anyone with existing access.

The problem is not Copilot.

The problem is the underlying permissions.

DSPM helps identify these situations.


4. Inventory AI Applications

Organizations often have many AI applications in use.

DSPM helps administrators discover:

  • Approved AI tools
  • Newly adopted AI tools
  • Shadow AI applications
  • AI usage across departments

This visibility supports governance decisions.


5. Monitor AI Interactions

DSPM can provide insights into how AI interacts with organizational content.

Examples include:

  • Documents accessed
  • Sensitive data locations
  • AI usage frequency
  • Common AI workflows
  • Business units using AI

Administrators gain a better understanding of AI usage patterns without reading users’ private prompts or monitoring employee productivity.


How DSPM for AI Discovers AI Activity

DSPM analyzes signals across Microsoft 365 services to understand AI usage.

These signals may include:

  • User activity
  • Data access
  • File classifications
  • Permissions
  • Labels
  • Microsoft Graph relationships
  • Microsoft Purview metadata

Rather than simply counting AI prompts, DSPM builds a broader picture of how AI interacts with organizational data.


Microsoft Graph’s Role

One important concept for the AB-900 exam is understanding the relationship between Microsoft Graph and DSPM.

Microsoft Graph acts as the intelligence layer connecting Microsoft 365 services.

DSPM uses Microsoft Graph signals to understand:

  • Which files users can access
  • Collaboration relationships
  • SharePoint permissions
  • Teams memberships
  • OneDrive access
  • Email relationships
  • Microsoft 365 activity

This allows DSPM to identify situations where AI could expose sensitive information because users already possess excessive permissions.


Data Sources Evaluated by DSPM

DSPM evaluates multiple Microsoft 365 services.

Examples include:

SharePoint Online

  • Sensitive document libraries
  • Overshared sites
  • Confidential folders
  • File permissions

OneDrive

  • Shared personal files
  • External sharing
  • Sensitive documents
  • Personal work data

Microsoft Teams

  • Shared files
  • Team memberships
  • Collaboration spaces
  • Shared conversations

Exchange Online

  • Email data
  • Mailbox access
  • Shared mailboxes
  • Sensitive communications

Microsoft 365 Copilot

DSPM evaluates how Copilot interacts with organizational data by examining:

  • Available permissions
  • Data sources
  • Sensitive information exposure
  • Governance controls

Types of Risks DSPM Can Identify

DSPM helps identify a variety of AI-related risks.

Overshared Content

Examples include:

  • Everyone can access HR documents.
  • Finance reports are visible to the entire company.
  • Sensitive SharePoint sites inherit incorrect permissions.

Sensitive Information Exposure

Examples include:

  • Credit card numbers
  • Passport numbers
  • Social Security numbers
  • Customer records
  • Healthcare data
  • Intellectual property

Excessive Permissions

Users frequently accumulate permissions over time.

DSPM identifies situations where users have access to more information than necessary.

This supports the principle of least privilege.


Unclassified Sensitive Data

Organizations often possess sensitive information that has never been classified.

DSPM can identify repositories containing:

  • Unlabeled confidential documents
  • Sensitive spreadsheets
  • Legal contracts
  • Financial reports

This allows administrators to apply Microsoft Purview Information Protection labels.


Shadow AI

Shadow AI refers to employees using AI tools that have not been approved by the organization.

Examples might include:

  • Public AI chat services
  • AI writing assistants
  • AI coding assistants
  • AI document summarizers

DSPM helps organizations understand where unmanaged AI usage exists so appropriate governance decisions can be made.


Key Exam Tips

For the AB-900 exam, remember these important points:

  • DSPM for AI is primarily a visibility and governance solution, not an AI blocking solution.
  • It helps organizations discover, understand, and reduce AI-related risks.
  • It identifies oversharing, sensitive data exposure, and permission issues.
  • DSPM works closely with other Microsoft Purview solutions to improve an organization’s overall AI security posture.
  • Microsoft Graph provides much of the contextual information that enables DSPM to evaluate AI data access and potential risks.
  • The goal is not to restrict productive AI use, but to ensure that AI operates within an organization’s existing security, compliance, and governance framework.

Go to Part 2 of this topic.


Go to the AB-900 Exam Prep Hub main page

Identify user activities reported by Microsoft Purview Activity Explorer (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Identify user activities reported by Microsoft Purview Activity Explorer


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand how Microsoft Purview Activity Explorer helps administrators investigate user activities involving sensitive information. Activity Explorer provides visibility into how sensitive data is accessed, shared, modified, labeled, or protected across Microsoft 365 services. It is an important investigative tool for identifying potential data protection and governance risks.


What Is Microsoft Purview Activity Explorer?

Microsoft Purview Activity Explorer is an investigation tool that displays activities involving sensitive information and Microsoft Purview protection technologies across Microsoft 365.

Rather than preventing actions, Activity Explorer helps administrators answer questions such as:

  • Who accessed sensitive information?
  • Which files contained sensitive data?
  • Was a sensitivity label applied or removed?
  • Did a Data Loss Prevention (DLP) policy trigger?
  • Was confidential information shared externally?
  • When did a particular activity occur?

Activity Explorer provides a searchable history of events so administrators can investigate potential compliance and security incidents.


Purpose of Activity Explorer

The primary purpose of Activity Explorer is to provide visibility into how organizational data is being used and protected.

It helps organizations:

  • Investigate compliance incidents
  • Monitor sensitive information usage
  • Validate Microsoft Purview policy effectiveness
  • Support audits
  • Identify risky user behavior
  • Understand how sensitive data moves throughout Microsoft 365

How Activity Explorer Fits into Microsoft Purview

Activity Explorer works alongside several Microsoft Purview solutions.

Microsoft Purview SolutionPurpose
Information ProtectionApplies sensitivity labels
Data Loss Prevention (DLP)Prevents inappropriate sharing of sensitive data
Data ClassificationIdentifies sensitive information
Insider Risk ManagementInvestigates risky user behavior
Activity ExplorerDisplays activities involving protected or sensitive content

Think of Activity Explorer as the investigation dashboard that brings many of these activities together.


User Activities Reported by Activity Explorer

Activity Explorer records many different activities related to sensitive information.

1. Sensitivity Label Activities

Administrators can identify when users:

  • Apply sensitivity labels
  • Remove sensitivity labels
  • Change sensitivity labels
  • Automatically receive labels
  • Manually classify documents

Example:

A user changes a document from Confidential to Public.

Activity Explorer records:

  • User
  • File
  • Previous label
  • New label
  • Time of change

2. Data Loss Prevention (DLP) Activities

Activity Explorer reports when DLP policies detect sensitive information.

Examples include:

  • Email blocked
  • File upload blocked
  • USB copy blocked
  • External sharing blocked
  • Policy warning shown
  • Policy override used

Example:

A user attempts to email customer credit card numbers.

The DLP policy detects the data and Activity Explorer records the event.


3. Sensitive Information Detection

Activity Explorer records when Microsoft identifies sensitive information types such as:

  • Credit card numbers
  • Social Security numbers
  • Passport numbers
  • Driver’s license numbers
  • Bank account numbers
  • Tax identification numbers
  • Healthcare identifiers

The tool helps administrators understand where sensitive information exists.


4. File Activities

Activity Explorer can display events involving files that contain sensitive information.

Examples include:

  • File created
  • File modified
  • File deleted
  • File copied
  • File downloaded
  • File shared
  • File moved

5. Sharing Activities

Administrators can investigate file-sharing behavior.

Examples:

  • Internal sharing
  • External sharing
  • Anonymous sharing links
  • Sharing permission changes
  • Sharing sensitive documents

These activities help identify potential data exposure risks.


6. Email Activities

Activity Explorer can report events involving protected email messages.

Examples include:

  • Email containing sensitive information
  • Protected email
  • Label changes
  • DLP policy matches

7. Teams Activities

Activity Explorer includes activities related to Microsoft Teams when supported by Microsoft Purview policies.

Examples include:

  • Sensitive information shared in Teams chats
  • Files shared in Teams
  • DLP policy matches
  • Protected documents shared

8. SharePoint and OneDrive Activities

Common activities include:

  • Sensitive file uploads
  • Downloads
  • External sharing
  • Label application
  • DLP events
  • File modifications

Information Displayed for Each Activity

Each event typically includes:

  • Date and time
  • User
  • Workload (Exchange, Teams, SharePoint, OneDrive)
  • Activity type
  • Policy involved
  • Sensitive information detected
  • Sensitivity label
  • File name
  • Location
  • Severity (when applicable)

This information helps investigators quickly understand what occurred.


Filtering Activity Explorer

Administrators can filter results by:

  • User
  • Date range
  • Workload
  • Activity type
  • Policy
  • Sensitive information type
  • Sensitivity label
  • Location
  • Service
  • File name

Filtering makes investigations faster and more targeted.


Common Investigation Scenarios

Scenario 1: External File Sharing

Question:

Has confidential information been shared outside the organization?

Activity Explorer allows investigators to:

  • Find externally shared files
  • Identify the user
  • Determine whether a DLP policy triggered
  • Review sensitivity labels

Scenario 2: Sensitive Information Discovery

Question:

Where are customer Social Security numbers stored?

Activity Explorer can identify:

  • Files
  • Users
  • Locations
  • Labels
  • Detection events

Scenario 3: Label Investigation

Question:

Who removed the Confidential label from a document?

Activity Explorer shows:

  • User
  • Time
  • Original label
  • New label
  • File involved

Scenario 4: DLP Policy Review

Question:

Which users triggered the most DLP alerts this week?

Administrators can filter DLP events by:

  • User
  • Policy
  • Date
  • Severity

Relationship to Microsoft 365 Copilot

As organizations deploy Microsoft 365 Copilot, understanding how sensitive information is used becomes increasingly important.

Activity Explorer helps administrators:

  • Verify that sensitivity labels are being applied
  • Review DLP policy activity
  • Monitor how protected information is handled
  • Investigate suspicious sharing activities
  • Support governance for content that Copilot may reference based on users’ existing permissions

Although Activity Explorer does not monitor Copilot prompts or responses directly, it helps administrators understand the underlying data protection activities associated with Microsoft 365 content.


Difference Between Activity Explorer and Audit Logs

These tools are related but serve different purposes.

Activity ExplorerMicrosoft Purview Audit
Focuses on sensitive information activitiesRecords broad user and administrator activities
Highlights DLP and sensitivity label eventsRecords nearly all Microsoft 365 events
Designed for data protection investigationsDesigned for security, compliance, and auditing
Optimized for Microsoft Purview investigationsOptimized for overall audit history

Best Practices

Organizations should:

  • Regularly review Activity Explorer.
  • Investigate repeated DLP policy matches.
  • Monitor external sharing of sensitive files.
  • Review sensitivity label changes.
  • Use filters to focus investigations.
  • Integrate findings with Insider Risk Management when appropriate.
  • Periodically validate that Purview policies are functioning as expected.

AB-900 Exam Tips

Remember these key points for the exam:

  • Activity Explorer is an investigation tool.
  • It reports activities involving sensitive information and Microsoft Purview protections.
  • It displays DLP events, sensitivity label activities, sharing events, and sensitive information detections.
  • It helps administrators investigate compliance and governance risks.
  • Activity Explorer complements Audit logs but focuses specifically on data protection activities.
  • Administrators can filter activities by user, workload, policy, label, activity type, and date.

Practice Exam Questions

Question 1

What is the primary purpose of Microsoft Purview Activity Explorer?

A. Create Microsoft 365 user accounts

B. Display activities involving sensitive information and Microsoft Purview protections

C. Configure Conditional Access policies

D. Reset user passwords

Correct Answer: B

Explanation: Activity Explorer helps administrators investigate activities involving sensitive information, DLP events, sensitivity labels, and other Microsoft Purview protection technologies.


Question 2

Which activity would most likely appear in Activity Explorer?

A. BIOS firmware updates

B. Windows device driver installation

C. A user applies a Confidential sensitivity label to a document

D. Printer toner replacement

Correct Answer: C

Explanation: Applying or changing sensitivity labels is one of the primary activities tracked by Activity Explorer.


Question 3

Which Microsoft Purview feature commonly generates events that are visible in Activity Explorer?

A. Microsoft Intune

B. Windows Update

C. Active Directory Sites and Services

D. Data Loss Prevention (DLP)

Correct Answer: D

Explanation: Activity Explorer records DLP policy matches, alerts, overrides, and other related events.


Question 4

An administrator wants to determine who shared a sensitive document externally. Which Microsoft Purview tool should they use?

A. Activity Explorer

B. Windows Event Viewer

C. Device Manager

D. Microsoft Paint

Correct Answer: A

Explanation: Activity Explorer displays sharing activities involving sensitive information, including external sharing events.


Question 5

Which information can administrators use to filter Activity Explorer results?

A. CPU temperature

B. Printer model

C. User name, activity type, and date range

D. Network cable type

Correct Answer: C

Explanation: Activity Explorer supports filtering by user, workload, activity type, policy, label, location, and date range.


Question 6

Which statement best describes Activity Explorer?

A. It permanently blocks sensitive file sharing.

B. It investigates activities involving protected or sensitive information.

C. It replaces Microsoft Defender Antivirus.

D. It encrypts every Microsoft 365 file automatically.

Correct Answer: B

Explanation: Activity Explorer is designed for investigation and reporting rather than prevention.


Question 7

Which Microsoft 365 workloads can contribute activities to Activity Explorer?

A. Only Microsoft Excel

B. Only Microsoft Teams

C. Only Exchange Online

D. Exchange Online, SharePoint Online, OneDrive, and Microsoft Teams

Correct Answer: D

Explanation: Activity Explorer collects supported events from multiple Microsoft 365 workloads to provide a comprehensive view of sensitive data activities.


Question 8

What can an administrator determine by reviewing Activity Explorer?

A. Which BIOS version users are running

B. Which sensitive information types were detected in organizational content

C. The amount of available disk space on each device

D. Which printer is the default printer

Correct Answer: B

Explanation: Activity Explorer displays detections of sensitive information types such as credit card numbers, Social Security numbers, and other classified data.


Question 9

How does Activity Explorer differ from Microsoft Purview Audit?

A. Activity Explorer focuses on sensitive information and data protection activities, while Audit records a broader range of Microsoft 365 events.

B. Activity Explorer stores passwords.

C. Audit only records Teams activities.

D. Both tools provide identical information.

Correct Answer: A

Explanation: Activity Explorer specializes in Microsoft Purview-related activities, while Audit provides broader auditing across Microsoft 365.


Question 10

Why is Microsoft Purview Activity Explorer valuable in organizations using Microsoft 365 Copilot?

A. It records every Copilot prompt entered by users.

B. It replaces Copilot security permissions.

C. It helps administrators monitor the protection and handling of sensitive Microsoft 365 content that Copilot may access based on existing permissions.

D. It automatically blocks all Copilot responses.

Correct Answer: C

Explanation: Activity Explorer helps administrators understand how sensitive content is protected and used within Microsoft 365, supporting governance for data that Copilot can access according to user permissions.


Go to the AB-900 Exam Prep Hub main page