Category: Cybersecurity

Understand retention in Microsoft Purview (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Understand Microsoft Purview
      --> Understand retention


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Data is one of an organization’s most valuable assets. However, organizations must not only protect data but also manage how long it is kept and when it should be deleted. Regulatory requirements, legal obligations, business needs, and security concerns all influence data retention decisions.

Microsoft Purview provides comprehensive retention capabilities that help organizations retain, preserve, review, and dispose of information across Microsoft 365 services. Retention is a key component of information governance and records management.

For the AB-900 exam, it is important to understand the purpose of retention, the difference between retention policies and retention labels, and how Microsoft Purview helps organizations meet compliance and governance requirements.


What Is Retention?

Retention refers to the process of determining:

  • How long information should be kept
  • Whether information must be preserved
  • When information should be deleted
  • How organizations comply with legal, regulatory, and business requirements

Retention ensures that important information remains available when needed while reducing risks associated with keeping unnecessary data indefinitely.

Examples include:

  • Retaining financial records for seven years
  • Preserving employee communications during legal investigations
  • Automatically deleting outdated project documents
  • Maintaining business records for compliance purposes

Why Retention Matters

Organizations use retention solutions to achieve several goals:

Regulatory Compliance

Many industries have laws requiring data to be retained for specific periods.

Examples include:

  • Financial records
  • Healthcare records
  • Tax documentation
  • Legal contracts

Legal Protection

Organizations may need to preserve information for:

  • Litigation
  • Audits
  • Investigations
  • Regulatory reviews

Information Governance

Retention helps organizations:

  • Reduce data sprawl
  • Improve information quality
  • Eliminate outdated content
  • Manage storage costs

Security Improvement

Keeping unnecessary data increases risk.

Proper retention practices help:

  • Minimize exposure to breaches
  • Reduce attack surfaces
  • Remove outdated sensitive information

Retention in Microsoft Purview

Microsoft Purview provides retention solutions that work across Microsoft 365 services such as:

  • Exchange Online
  • SharePoint Online
  • OneDrive
  • Microsoft Teams
  • Microsoft 365 Groups
  • Viva Engage
  • Copilot-related content stored in Microsoft 365

Purview allows organizations to automatically:

  • Retain content
  • Delete content
  • Retain and then delete content

Retention Policies

A retention policy automatically applies retention settings to locations across Microsoft 365.

Administrators create policies that specify:

  • Where the policy applies
  • How long content is retained
  • What happens after the retention period ends

Example

A policy might:

  • Retain all Teams chat messages for 5 years
  • Automatically delete them afterward

Advantages

Retention policies:

  • Apply automatically
  • Require little user involvement
  • Work at scale
  • Provide consistent compliance

Retention Labels

Retention labels provide more granular control than retention policies.

A retention label can be assigned to individual items such as:

  • Documents
  • Emails
  • Files
  • Records

Labels can be applied:

  • Manually by users
  • Automatically by policies
  • Through sensitive information detection
  • Through trainable classifiers

Example

A document labeled “Financial Record” could:

  • Be retained for 7 years
  • Be declared a record
  • Be deleted after the retention period expires

Retention Policies vs. Retention Labels

FeatureRetention PolicyRetention Label
ScopeBroad locationsIndividual items
User involvementUsually noneMay require user action
GranularityLocation levelItem level
FlexibilityModerateHigh
Records managementLimitedStrong

A useful exam tip is:

Retention policies manage locations, while retention labels manage individual content items.


Retain, Delete, or Retain and Delete

Microsoft Purview supports three primary retention actions.

Retain Only

Content remains available throughout the retention period.

Example:

  • Retain employee records for seven years.

Delete Only

Content is automatically removed after a specified period.

Example:

  • Delete temporary files after one year.

Retain and Then Delete

Content is preserved for a retention period and then automatically removed.

Example:

  • Retain project documents for five years and delete afterward.

Records Management

Records management builds on retention by treating important information as official records.

Organizations can:

  • Declare content as records
  • Restrict modifications
  • Track lifecycle events
  • Preserve compliance evidence

Examples of records:

  • Legal contracts
  • Corporate policies
  • Regulatory filings
  • Financial statements

Retention labels are commonly used to manage records.


Retention and Microsoft Teams

Organizations increasingly need to manage communication data.

Purview retention can manage:

  • Teams chat messages
  • Channel messages
  • Meeting content
  • Shared files

Example:

An organization may retain all Teams conversations for three years to satisfy compliance requirements.


Retention and Exchange Online

Retention can be applied to:

  • Emails
  • Mailboxes
  • Calendar items
  • Contacts

Example:

All employee email messages are retained for seven years and deleted afterward.


Retention and SharePoint/OneDrive

Retention supports:

  • Documents
  • Libraries
  • Files
  • Collaboration content

Example:

Project documentation is retained for five years after project completion.


Retention and Microsoft 365 Copilot

Microsoft 365 Copilot uses organizational data stored in Microsoft 365.

Because Copilot accesses existing organizational content:

  • Retention policies continue to govern underlying data.
  • Retention labels remain effective.
  • Information governance policies still apply.
  • Deleted content generally becomes unavailable after retention requirements are fulfilled.

Organizations should ensure retention strategies are aligned with Copilot usage to maintain compliance and data governance.


Adaptive Scopes

Large organizations often need dynamic retention assignments.

Adaptive scopes allow administrators to target retention policies based on attributes such as:

  • Department
  • Geography
  • User type
  • Business unit

This reduces administrative effort and improves policy accuracy.


Retention and eDiscovery

Retention supports eDiscovery by ensuring content remains available during investigations.

Benefits include:

  • Preserving evidence
  • Supporting legal holds
  • Maintaining compliance records
  • Simplifying investigations

Retained content can remain available even if users attempt to delete it.


Retention Best Practices

Organizations should:

  1. Identify regulatory requirements.
  2. Define retention schedules.
  3. Use retention policies for broad coverage.
  4. Use retention labels for specific content.
  5. Regularly review retention settings.
  6. Apply least-privilege administration.
  7. Align retention with records management processes.
  8. Test policies before large-scale deployment.

Key Exam Takeaways

For the AB-900 exam, remember these important concepts:

  • Retention determines how long data is kept and when it is deleted.
  • Microsoft Purview provides retention policies and retention labels.
  • Retention policies apply broadly to locations and workloads.
  • Retention labels apply to individual content items.
  • Organizations can retain content, delete content, or retain and then delete content.
  • Retention supports compliance, governance, security, and legal requirements.
  • Records management relies heavily on retention labels.
  • Retention applies across Exchange Online, SharePoint, OneDrive, Teams, and other Microsoft 365 services.
  • Copilot content governance relies on the retention controls applied to underlying Microsoft 365 data.

Practice Exam Questions

Question 1

An organization wants all Teams chat messages retained for five years and then automatically deleted. Which Microsoft Purview capability should be used?

A. Sensitivity labels
B. Retention policy
C. Conditional Access
D. Insider Risk Management

Answer: B

Explanation: Retention policies can apply retention settings broadly across Microsoft 365 workloads such as Teams chats and automatically delete content after the retention period expires.


Question 2

What is the primary purpose of retention in Microsoft Purview?

A. Encrypt all files in Microsoft 365
B. Prevent users from sharing documents externally
C. Control how long information is preserved and when it is deleted
D. Monitor user productivity

Answer: C

Explanation: Retention helps organizations manage the lifecycle of information by determining how long content is kept and when it should be removed.


Question 3

Which statement best describes a retention label?

A. It applies retention settings to individual items such as emails and documents.
B. It blocks external access to files.
C. It enforces multifactor authentication.
D. It manages network security rules.

Answer: A

Explanation: Retention labels provide item-level retention management and can be applied to specific documents, emails, and records.


Question 4

A company wants users to classify certain documents as official records that cannot be easily altered. Which solution is most appropriate?

A. Adaptive scopes
B. Conditional Access policies
C. Microsoft Defender XDR
D. Retention labels with records management capabilities

Answer: D

Explanation: Retention labels can declare documents as records and enforce records management requirements.


Question 5

Which retention action preserves content during a specified period and then removes it automatically?

A. Retain only
B. Delete only
C. Retain and then delete
D. Archive only

Answer: C

Explanation: Retain and then delete ensures content remains available during the retention period before automatic deletion occurs.


Question 6

What is a key difference between retention policies and retention labels?

A. Retention policies only work with Exchange Online.
B. Retention labels apply to individual content items.
C. Retention labels cannot be automated.
D. Retention policies require user assignment.

Answer: B

Explanation: Retention labels provide item-level control, while retention policies generally apply to locations or workloads.


Question 7

An administrator wants a retention policy to automatically target users based on department membership. Which feature should be used?

A. Data Loss Prevention
B. eDiscovery
C. Sensitivity labeling
D. Adaptive scopes

Answer: D

Explanation: Adaptive scopes dynamically assign retention policies using organizational attributes such as department or location.


Question 8

Why is retention important for eDiscovery investigations?

A. It automatically encrypts evidence.
B. It prevents users from signing in.
C. It helps ensure relevant information remains available for review.
D. It removes all old content immediately.

Answer: C

Explanation: Retention preserves information that may be required for legal or regulatory investigations.


Question 9

Which Microsoft 365 workload can be governed by Microsoft Purview retention policies?

A. Microsoft Teams only
B. SharePoint Online only
C. Exchange Online only
D. Exchange Online, SharePoint Online, OneDrive, and Teams

Answer: D

Explanation: Retention policies support multiple Microsoft 365 workloads, including Exchange, SharePoint, OneDrive, and Teams.


Question 10

How does Microsoft 365 Copilot relate to retention policies?

A. Copilot bypasses all retention settings.
B. Copilot replaces retention labels.
C. Copilot uses underlying Microsoft 365 content that remains governed by retention controls.
D. Copilot automatically creates retention policies.

Answer: C

Explanation: Copilot accesses organizational data stored in Microsoft 365, and existing retention policies and labels continue to govern that content.


Go to the AB-900 Exam Prep Hub main page

Understand data classification in Microsoft Purview (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Understand Microsoft Purview
      --> Understand data classification in Microsoft Purview


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Data is one of an organization’s most valuable assets. However, not all data carries the same level of sensitivity or business value. Some information can be shared publicly, while other information must be protected because it contains financial records, intellectual property, customer data, healthcare information, or confidential business plans.

Microsoft Purview Data Classification helps organizations identify, categorize, and protect sensitive information throughout Microsoft 365. Data classification is a foundational capability that enables organizations to understand their data landscape, apply appropriate protections, meet compliance requirements, and securely adopt AI technologies such as Microsoft 365 Copilot.

For the AB-900 exam, it is important to understand how Microsoft Purview classifies data, the tools involved, and how classification supports security, compliance, governance, and AI readiness.


What Is Data Classification?

Data classification is the process of identifying and categorizing information based on its:

  • Sensitivity
  • Confidentiality
  • Regulatory requirements
  • Business value
  • Risk level

Classification allows organizations to answer questions such as:

  • Which files contain sensitive information?
  • Where is confidential data stored?
  • Who can access regulated data?
  • Which content should be protected or retained?
  • What data can Copilot safely access?

Microsoft Purview automates much of this process through built-in detection technologies.


Why Data Classification Is Important

Without data classification, organizations often struggle to:

  • Identify sensitive information
  • Apply consistent protections
  • Meet compliance requirements
  • Prevent data loss
  • Govern AI access to information

Benefits of data classification include:

  • Improved data visibility
  • Better security controls
  • Regulatory compliance
  • Reduced risk of data breaches
  • More effective data governance
  • Safer use of Microsoft 365 Copilot

Microsoft Purview Data Classification Components

Microsoft Purview uses several components to classify information.

Sensitive Information Types (SITs)

Sensitive Information Types are predefined patterns used to identify sensitive data.

Examples include:

  • Credit card numbers
  • Social Security numbers
  • Passport numbers
  • Driver’s license numbers
  • Bank account numbers
  • Tax identification numbers

Microsoft provides hundreds of built-in SITs covering numerous countries and regions.

Example

A document containing a U.S. Social Security Number may automatically be detected and classified as sensitive content.


Trainable Classifiers

Trainable classifiers use machine learning to identify content based on context rather than exact patterns.

Examples include:

  • Resumes
  • Source code
  • Contracts
  • Financial documents
  • Healthcare records
  • Intellectual property

Unlike SITs, trainable classifiers examine the meaning and context of content.

Example

A contract may be identified even if it does not contain a specific keyword or sensitive number.


Content Explorer

Content Explorer allows administrators to:

  • View classified content
  • See where sensitive data exists
  • Investigate data locations
  • Analyze classification results

This tool helps organizations understand their data environment.


Activity Explorer

Activity Explorer provides visibility into:

  • Labeling activities
  • Classification actions
  • DLP events
  • User interactions with sensitive data

Administrators can investigate how classified information is being used.


Types of Data Classification

Organizations typically classify data into categories such as:

ClassificationDescription
PublicInformation intended for everyone
GeneralEveryday business information
InternalInformation for employees only
ConfidentialSensitive business information
Highly ConfidentialCritical or restricted information

Organizations can customize classifications based on their requirements.


Classification and Sensitivity Labels

Data classification often works together with Sensitivity Labels.

Classification identifies the data.

Sensitivity labels protect the data.

Example

Microsoft Purview detects:

  • Credit card information
  • Customer account numbers

A sensitivity label is then automatically applied:

  • Confidential
  • Highly Confidential

The label can then:

  • Encrypt the file
  • Restrict access
  • Apply watermarks
  • Block unauthorized sharing

Automatic Data Classification

Microsoft Purview can automatically classify information using:

Pattern Matching

Detects predefined sensitive information.

Examples:

  • Credit card numbers
  • Social Security numbers
  • Passport numbers

Machine Learning

Uses trainable classifiers to recognize content types.

Examples:

  • Contracts
  • Legal documents
  • Source code

Keyword Detection

Identifies content based on specific words or phrases.

Examples:

  • Confidential
  • Internal Use Only
  • Proprietary Information

Data Classification and Microsoft 365 Copilot

Data classification is particularly important for Copilot deployments.

Organizations often ask:

What information can Copilot access?

Copilot respects:

  • User permissions
  • Sensitivity labels
  • Compliance controls

Proper data classification helps organizations:

  • Understand their data
  • Identify overshared content
  • Protect confidential information
  • Reduce AI-related risks

Classification improves confidence when deploying AI solutions.


Data Classification and Compliance

Many regulations require organizations to identify and protect sensitive information.

Examples include:

  • GDPR
  • HIPAA
  • PCI DSS
  • SOX
  • Various privacy laws

Microsoft Purview classification helps organizations:

  • Locate regulated data
  • Apply protections
  • Support audits
  • Demonstrate compliance

Data Classification and Data Loss Prevention (DLP)

Data classification works closely with DLP policies.

Process

  1. Purview identifies sensitive content.
  2. Content is classified.
  3. DLP policies evaluate the classification.
  4. Protective actions occur.

Examples:

  • Block file sharing
  • Restrict email transmission
  • Alert administrators
  • Notify users

Without classification, DLP cannot effectively identify sensitive content.


Data Classification and Insider Risk Management

Classified data helps Insider Risk Management identify risky activities involving:

  • Financial records
  • Intellectual property
  • Customer information
  • Confidential business data

This improves risk detection and investigation capabilities.


Common Data Classification Use Cases

Financial Information Protection

Detect:

  • Credit card numbers
  • Banking information
  • Tax records

Apply protection automatically.


Human Resources Data

Identify:

  • Employee records
  • Salary information
  • Performance reviews

Restrict access to authorized personnel.


Healthcare Information

Classify:

  • Patient records
  • Medical identifiers

Support HIPAA compliance.


Legal Documents

Detect:

  • Contracts
  • Legal agreements

Apply confidentiality protections.


Intellectual Property Protection

Identify:

  • Product designs
  • Research data
  • Source code

Prevent unauthorized sharing.


Key Exam Concepts

For the AB-900 exam, remember:

  • Data classification identifies and categorizes information.
  • Sensitive Information Types detect specific data patterns.
  • Trainable classifiers use machine learning and context.
  • Classification supports sensitivity labels and DLP.
  • Content Explorer helps locate classified content.
  • Activity Explorer helps investigate classification activity.
  • Classification is essential for compliance and governance.
  • Microsoft 365 Copilot benefits from proper data classification.
  • Classification enables automated protection policies.
  • Data classification improves organizational visibility into sensitive information.

Practice Exam Questions

Question 1

What is the primary purpose of data classification in Microsoft Purview?

A. To improve internet connectivity
B. To categorize information based on sensitivity and business value
C. To manage Windows updates
D. To configure virtual machines

Answer: B

Explanation: Data classification identifies and categorizes information so organizations can apply appropriate protections and governance controls.


Question 2

Which Microsoft Purview feature identifies information such as Social Security numbers and credit card numbers?

A. Activity Explorer
B. Sensitive Information Types
C. Compliance Manager
D. Insider Risk Management

Answer: B

Explanation: Sensitive Information Types (SITs) are designed to detect structured sensitive data using predefined patterns.


Question 3

Which technology enables Microsoft Purview to recognize contracts and resumes based on context?

A. Firewall policies
B. Sensitivity labels
C. Trainable classifiers
D. Conditional Access

Answer: C

Explanation: Trainable classifiers use machine learning and contextual analysis to identify content types.


Question 4

An administrator wants to see where sensitive information exists across Microsoft 365. Which tool should they use?

A. Microsoft Defender Portal
B. Teams Admin Center
C. Content Explorer
D. Exchange Admin Center

Answer: C

Explanation: Content Explorer provides visibility into classified content and its locations.


Question 5

What is the relationship between data classification and sensitivity labels?

A. They are unrelated technologies
B. Sensitivity labels identify data while classification encrypts it
C. Classification identifies data and labels protect it
D. Classification replaces sensitivity labels

Answer: C

Explanation: Classification discovers and categorizes information, while sensitivity labels apply protection settings.


Question 6

Which statement about Microsoft 365 Copilot is correct?

A. Copilot ignores classified information
B. Copilot respects permissions and protection controls associated with classified data
C. Copilot automatically removes sensitivity labels
D. Copilot bypasses governance policies

Answer: B

Explanation: Copilot honors existing permissions, labels, and compliance controls.


Question 7

Which Microsoft Purview feature allows administrators to investigate labeling and classification events?

A. Activity Explorer
B. Endpoint Manager
C. SharePoint Admin Center
D. Azure Monitor

Answer: A

Explanation: Activity Explorer provides visibility into classification-related activities and events.


Question 8

Which compliance-related benefit does data classification provide?

A. Faster network performance
B. Reduced storage costs only
C. Automatic hardware replacement
D. Easier identification and protection of regulated data

Answer: D

Explanation: Classification helps organizations locate and protect regulated information to support compliance requirements.


Question 9

A Data Loss Prevention (DLP) policy blocks sharing of files containing credit card numbers. What enables the DLP policy to identify those files?

A. Exchange transport rules only
B. Sensitive Information Types and data classification
C. Network firewalls
D. Device encryption

Answer: B

Explanation: DLP relies on classification mechanisms such as Sensitive Information Types to identify protected content.


Question 10

Which statement best describes trainable classifiers?

A. They only detect file names
B. They require manual review of every document
C. They identify information using contextual machine learning models
D. They replace all sensitivity labels

Answer: C

Explanation: Trainable classifiers use machine learning to recognize content such as contracts, source code, and resumes based on context rather than simple pattern matching.


Go to the AB-900 Exam Prep Hub main page

Understand features and capabilities of Microsoft Purview Information Protection, Microsoft Purview Data Loss Prevention (DLP), Microsoft Purview Insider Risk Management, Microsoft Purview Communication Compliance, Microsoft Purview Data Security Posture Management (DSPM) for AI, and Microsoft Purview Data Lifecycle Management (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Understand Microsoft Purview
      --> Understand features and capabilities of Microsoft Purview Information Protection, Microsoft Purview Data Loss Prevention (DLP), Microsoft Purview Insider Risk Management, Microsoft Purview Communication Compliance, Microsoft Purview Data Security Posture Management (DSPM) for AI, and Microsoft Purview Data Lifecycle Management


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

As organizations adopt Microsoft 365, Copilot, and AI-powered solutions, protecting sensitive information becomes increasingly important. Microsoft provides a unified compliance and governance platform called Microsoft Purview.

Microsoft Purview helps organizations:

  • Protect sensitive information.
  • Prevent accidental or intentional data loss.
  • Manage records and retention.
  • Detect insider risks.
  • Monitor communications.
  • Strengthen AI data governance.
  • Meet regulatory and compliance requirements.

For the AB-900 exam, you should understand the purpose and capabilities of the major Microsoft Purview solutions rather than detailed implementation steps.


What Is Microsoft Purview?

Microsoft Purview is Microsoft’s unified data governance, compliance, and risk management platform.

Purview enables organizations to:

  • Discover and classify data.
  • Protect sensitive information.
  • Govern information throughout its lifecycle.
  • Reduce insider threats.
  • Monitor AI-related risks.
  • Meet legal and regulatory obligations.

Purview works across:

  • Microsoft 365
  • Exchange Online
  • SharePoint Online
  • OneDrive
  • Teams
  • Microsoft Copilot
  • Power Platform
  • Endpoint devices
  • Third-party cloud services

Microsoft Purview Information Protection

Purpose

Microsoft Purview Information Protection (MIP) helps organizations classify and protect sensitive information.

It enables organizations to:

  • Identify sensitive data.
  • Apply sensitivity labels.
  • Encrypt content.
  • Control sharing permissions.
  • Track and monitor protected content.

Sensitivity Labels

Sensitivity labels classify content based on its importance.

Examples:

  • Public
  • General
  • Confidential
  • Highly Confidential

Labels can be applied to:

  • Emails
  • Word documents
  • Excel files
  • PowerPoint presentations
  • SharePoint sites
  • Teams
  • Microsoft 365 Groups

Protection Actions

Sensitivity labels can:

Encrypt Data

Only authorized users can open content.

Restrict Access

Prevent forwarding, printing, or copying.

Apply Visual Markings

Add:

  • Headers
  • Footers
  • Watermarks

Protect Copilot Data

Copilot respects existing permissions and sensitivity labels.


Benefits

Information Protection helps organizations:

  • Reduce accidental exposure.
  • Meet compliance requirements.
  • Maintain consistent classification.
  • Protect confidential information.

Microsoft Purview Data Loss Prevention (DLP)

Purpose

Data Loss Prevention (DLP) helps prevent sensitive information from being shared improperly.

DLP identifies sensitive information and automatically applies protection actions.


Examples of Sensitive Information

  • Credit card numbers
  • Social Security numbers
  • Passport numbers
  • Healthcare records
  • Financial information

DLP Actions

Policies can:

  • Block email transmission.
  • Prevent file sharing.
  • Warn users before sending data.
  • Generate alerts.
  • Create audit records.

Locations Protected by DLP

DLP policies can protect:

  • Exchange Online
  • SharePoint Online
  • OneDrive
  • Microsoft Teams
  • Endpoint devices

Example

A user attempts to email customer credit card information outside the company.

DLP can:

  1. Detect the information.
  2. Display a warning.
  3. Block the message.

Benefits

DLP helps:

  • Prevent accidental leaks.
  • Support compliance requirements.
  • Educate users with policy tips.
  • Reduce organizational risk.

Microsoft Purview Insider Risk Management

Purpose

Insider Risk Management helps detect risky behavior from internal users.

Risks may be:

  • Accidental
  • Negligent
  • Malicious

Examples of Risky Activities

  • Downloading large amounts of files.
  • Sending confidential information externally.
  • Copying data to USB devices.
  • Unusual file access patterns.
  • Data theft before leaving the company.

Risk Indicators

The solution uses:

  • User activities
  • Behavioral signals
  • Microsoft 365 audit logs

Investigation Capabilities

Administrators can:

  • Review alerts.
  • Analyze activities.
  • Escalate incidents.
  • Document investigations.

Benefits

Insider Risk Management helps:

  • Reduce insider threats.
  • Detect suspicious behavior early.
  • Protect intellectual property.

Microsoft Purview Communication Compliance

Purpose

Communication Compliance helps organizations monitor communications for policy violations.


Content Sources

Communication Compliance can monitor:

  • Microsoft Teams chats
  • Emails
  • Copilot interactions
  • Other communication channels

Violations It Can Detect

Examples include:

  • Harassment
  • Threatening language
  • Offensive content
  • Inappropriate sharing
  • Regulatory violations

Review Process

Flagged communications are:

  1. Detected automatically.
  2. Reviewed by authorized reviewers.
  3. Investigated when necessary.

Benefits

Communication Compliance helps:

  • Promote workplace safety.
  • Meet industry regulations.
  • Reduce legal exposure.
  • Enforce organizational policies.

Microsoft Purview Data Security Posture Management (DSPM) for AI

Purpose

DSPM for AI helps organizations understand and secure how AI systems interact with organizational data.

As AI adoption grows, organizations need visibility into:

  • What data AI tools can access.
  • Which users have access to sensitive information.
  • Potential AI-related risks.

DSPM for AI Capabilities

DSPM for AI helps organizations:

Discover AI Usage

Identify where AI tools are being used.

Assess Data Exposure

Understand whether sensitive data may be exposed.

Monitor Copilot Activity

Gain visibility into AI interactions.

Identify Oversharing Risks

Locate files with excessive permissions.

Strengthen AI Governance

Improve controls around AI usage.


Example

DSPM for AI may discover:

  • A SharePoint site containing confidential files.
  • Excessive permissions on the site.
  • Potential exposure to Copilot responses.

Administrators can then reduce permissions and improve security.


Benefits

DSPM for AI supports:

  • Responsible AI adoption.
  • Reduced oversharing risks.
  • Better governance of AI systems.

Microsoft Purview Data Lifecycle Management

Purpose

Data Lifecycle Management governs information throughout its lifecycle.

It ensures that information is:

  • Retained when required.
  • Deleted when no longer needed.
  • Managed according to regulations.

Retention Policies

Retention policies determine how long content should be kept.

Examples:

Content TypeRetention Period
HR records7 years
Financial documents10 years
General emails3 years

Retention Labels

Labels can assign different retention periods to individual documents.

Example:

  • Contract documents retained for 10 years.
  • Project files retained for 5 years.

Automatic Deletion

When retention periods expire, content can be deleted automatically.

Benefits include:

  • Reduced storage costs.
  • Reduced legal risk.
  • Better compliance.

Records Management

Organizations can designate records that must not be altered or deleted before their retention period ends.


How These Purview Solutions Work Together

SolutionPrimary Goal
Information ProtectionClassify and protect content
DLPPrevent data leakage
Insider Risk ManagementDetect risky user behavior
Communication ComplianceMonitor communications
DSPM for AISecure AI data access
Data Lifecycle ManagementRetain and dispose of data appropriately

Together, these capabilities provide a comprehensive governance framework for Microsoft 365 and Copilot.


Importance for Microsoft 365 Copilot

Copilot respects existing Microsoft 365 permissions and compliance controls.

Purview solutions help ensure:

  • Sensitive content is labeled.
  • Oversharing risks are minimized.
  • AI interactions remain compliant.
  • Records are retained appropriately.
  • Users do not accidentally expose confidential data.

Key Exam Points

Remember these AB-900 concepts:

  • Information Protection uses sensitivity labels to classify and protect content.
  • DLP prevents inappropriate sharing of sensitive data.
  • Insider Risk Management detects risky user behavior.
  • Communication Compliance monitors communications for policy violations.
  • DSPM for AI helps organizations govern AI usage and identify oversharing risks.
  • Data Lifecycle Management controls retention and deletion of information.
  • Microsoft Purview supports Microsoft 365, Copilot, and AI governance.

Practice Exam Questions

Question 1

Which Microsoft Purview solution primarily uses sensitivity labels to classify and protect content?

A. Communication Compliance
B. Data Lifecycle Management
C. Information Protection
D. Insider Risk Management

Correct Answer: C

Explanation: Microsoft Purview Information Protection uses sensitivity labels to classify and secure content.


Question 2

Which Microsoft Purview capability helps prevent users from emailing credit card numbers outside the organization?

A. Insider Risk Management
B. Communication Compliance
C. Data Loss Prevention (DLP)
D. Records Management

Correct Answer: C

Explanation: DLP detects sensitive information and can block or warn users before sharing it.


Question 3

Which solution is designed to identify potentially malicious or risky behavior by internal users?

A. Information Protection
B. Sensitivity Labels
C. Data Lifecycle Management
D. Insider Risk Management

Correct Answer: D

Explanation: Insider Risk Management focuses on identifying risky activities performed by users inside the organization.


Question 4

A company wants to monitor Teams messages for harassment and inappropriate language. Which Microsoft Purview solution should they use?

A. DLP
B. Communication Compliance
C. DSPM for AI
D. Information Protection

Correct Answer: B

Explanation: Communication Compliance analyzes communications for policy violations.


Question 5

What is the primary purpose of Microsoft Purview DSPM for AI?

A. Manage mailbox permissions
B. Secure and govern AI-related data exposure
C. Encrypt documents automatically
D. Replace Conditional Access

Correct Answer: B

Explanation: DSPM for AI provides visibility into AI usage and helps identify oversharing risks.


Question 6

Which Microsoft Purview capability determines how long information should be retained?

A. Insider Risk Management
B. Communication Compliance
C. Data Lifecycle Management
D. Information Protection

Correct Answer: C

Explanation: Data Lifecycle Management uses retention policies and labels to manage content over time.


Question 7

Which action can a sensitivity label perform?

A. Create Teams channels automatically
B. Synchronize users with Active Directory
C. Configure Conditional Access policies
D. Encrypt documents and restrict access

Correct Answer: D

Explanation: Sensitivity labels can apply encryption and restrict how information is used.


Question 8

Which Microsoft Purview solution helps identify oversharing risks that may affect Microsoft Copilot responses?

A. DSPM for AI
B. Communication Compliance
C. Data Lifecycle Management
D. Exchange Online Protection

Correct Answer: A

Explanation: DSPM for AI helps organizations understand how AI systems interact with organizational data and identify excessive permissions.


Question 9

A company must retain financial documents for ten years to meet regulatory requirements. Which capability addresses this need?

A. DLP
B. Insider Risk Management
C. Data Lifecycle Management
D. Communication Compliance

Correct Answer: C

Explanation: Retention policies and labels within Data Lifecycle Management ensure information is preserved for required periods.


Question 10

Which statement best describes the relationship between Microsoft Purview and Microsoft 365 Copilot?

A. Copilot ignores Purview policies.
B. Purview replaces Copilot permissions.
C. Copilot stores all data outside Microsoft 365.
D. Copilot works with existing Purview protections and permissions.

Correct Answer: D

Explanation: Microsoft 365 Copilot honors existing permissions, sensitivity labels, and compliance controls established through Microsoft Purview.


Go to the AB-900 Exam Prep Hub main page

Understand App registrations and Enterprise apps (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Identify the core features and objects of Microsoft 365 services (30–35%)
   --> Identify the core security features of Microsoft 365 services
      --> Understand App registrations and Enterprise apps


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Modern organizations rely on applications to access Microsoft 365 resources, integrate with cloud services, and automate business processes. Microsoft Entra ID (formerly Azure Active Directory) provides identity and access management capabilities not only for users but also for applications.

Two important concepts administrators must understand are:

  • App registrations
  • Enterprise applications

Although these terms are closely related, they represent different objects within Microsoft Entra ID. Understanding their purposes and differences is important for the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam.


Why Applications Need Identities

Just as users require identities to sign in and access resources, applications also need identities.

Applications may need to:

  • Access Microsoft Graph APIs.
  • Read SharePoint data.
  • Send email through Exchange Online.
  • Authenticate users.
  • Integrate with Microsoft 365 services.
  • Support Microsoft 365 Copilot and agents.

Microsoft Entra provides these capabilities through app registrations and enterprise applications.


What Is an App Registration?

An App Registration defines an application’s identity within Microsoft Entra ID.

When developers register an application, Entra creates:

  • An Application (client) ID
  • A directory object representing the application
  • Authentication settings
  • Redirect URIs
  • API permissions
  • Secrets or certificates (optional)

Think of an app registration as the blueprint or template for an application.

Common Uses

  • Custom business applications
  • Web applications
  • Mobile applications
  • APIs
  • Microsoft Graph integrations
  • Copilot extensions and agents

Key Components of an App Registration

Application (Client) ID

A globally unique identifier that identifies the application.

Example:

Application ID: 7a12b8c3-xxxx-xxxx-xxxx-xxxxxxxxxxxx

Applications use this ID during authentication.


Directory (Tenant) ID

Identifies the Microsoft Entra tenant where the application resides.


Redirect URI

Specifies where authentication responses are sent after users sign in.

Examples:


Secrets and Certificates

Applications may authenticate themselves using:

  • Client secrets
  • Certificates

These credentials should be protected because they function similarly to passwords.


API Permissions

Applications often require access to Microsoft services.

Examples:

  • Read user profiles
  • Access calendars
  • Read SharePoint files
  • Send email

Permissions can be granted by users or administrators depending on the permission type.


Types of API Permissions

Delegated Permissions

The application acts on behalf of a signed-in user.

Example:

A Teams app reads the user’s calendar using that user’s permissions.

Characteristics:

  • Requires a signed-in user.
  • Limited by the user’s permissions.

Application Permissions

The application runs independently without a user.

Example:

A background process scans SharePoint sites across the organization.

Characteristics:

  • No user sign-in required.
  • Usually requires administrator consent.

What Is an Enterprise Application?

An Enterprise Application is the service principal created from an app registration.

Think of the enterprise application as the instance of the application inside a tenant.

Enterprise applications manage:

  • User assignments
  • Sign-in permissions
  • Single sign-on settings
  • Conditional Access policies
  • Application access controls
  • Monitoring and sign-in logs

Simple Comparison

ObjectPurpose
App RegistrationDefines the application
Enterprise ApplicationRepresents the application inside the tenant

Relationship Between App Registrations and Enterprise Applications

When an application is registered:

  1. An app registration is created.
  2. A corresponding enterprise application (service principal) is created.
  3. Users and permissions are managed through the enterprise application.

One application registration can have multiple enterprise applications across different tenants.


Service Principals

A service principal is the identity used by an application within a specific tenant.

The service principal:

  • Authenticates the application.
  • Receives permissions.
  • Appears as an enterprise application.

For exam purposes:

Enterprise Application = Service Principal


Enterprise Applications and Single Sign-On (SSO)

Enterprise applications support Single Sign-On.

Users can:

  • Sign in once.
  • Access multiple applications.
  • Use Microsoft Entra credentials.

Benefits include:

  • Improved user experience.
  • Reduced password fatigue.
  • Centralized identity management.

Enterprise Applications from External Vendors

Not all enterprise applications originate from your organization.

Examples include:

  • Salesforce
  • ServiceNow
  • Workday
  • Zoom
  • Adobe

These SaaS applications appear as enterprise applications inside Microsoft Entra and can use SSO.


User Assignment

Administrators can control which users may access an enterprise application.

Options include:

Everyone

All users can access the application.

Selected Users or Groups

Only assigned users receive access.

This supports least privilege and Zero Trust principles.


Conditional Access and Enterprise Applications

Conditional Access policies can target applications.

Examples:

  • Require MFA for Salesforce.
  • Block access from unmanaged devices.
  • Restrict access by location.
  • Allow only compliant devices.

This helps secure application access.


Consent and Permissions

Applications request permissions when first used.

Two forms of consent exist:

User Consent

Users approve low-risk delegated permissions.

Example:

Allowing an app to read basic profile information.


Admin Consent

Administrators approve permissions that affect the entire organization.

Example:

Granting an app permission to read all mailboxes.

Admin consent helps protect sensitive organizational data.


Monitoring Enterprise Applications

Administrators can review:

  • Sign-in logs
  • Failed sign-ins
  • User assignments
  • Permission grants
  • Conditional Access results

These tools help troubleshoot and improve security.


Common Administrative Tasks

Administrators frequently:

  • Add enterprise applications.
  • Configure SSO.
  • Assign users and groups.
  • Review permissions.
  • Grant admin consent.
  • Remove unused applications.
  • Investigate sign-in logs.
  • Apply Conditional Access policies.

Security Best Practices

Use Least Privilege

Grant only required permissions.

Review Permissions Regularly

Remove unnecessary permissions.

Require MFA

Protect access to sensitive applications.

Remove Unused Applications

Reduce attack surface.

Use Group Assignments

Simplify management.

Monitor Sign-In Activity

Identify unusual behavior.


App Registrations vs. Enterprise Applications

FeatureApp RegistrationEnterprise Application
Defines application identityYesNo
Contains client IDYesNo
Stores redirect URIsYesNo
Represents app in a tenantNoYes
Supports user assignmentNoYes
Supports SSO configurationNoYes
Receives Conditional Access policiesNoYes
Also known as service principalNoYes

Importance for Microsoft 365 Copilot and Agents

Copilot extensions, plugins, and custom agents often rely on:

  • App registrations
  • Microsoft Graph permissions
  • Enterprise applications
  • User consent
  • Authentication and authorization

Understanding these concepts helps administrators securely deploy AI solutions within Microsoft 365.


Key Exam Points

Remember these AB-900 concepts:

  • App registrations define an application’s identity.
  • Enterprise applications represent applications within a tenant.
  • Enterprise applications are service principals.
  • Delegated permissions act on behalf of users.
  • Application permissions operate without users.
  • Enterprise applications support SSO.
  • Conditional Access policies can target applications.
  • Admin consent is required for high-privilege permissions.
  • User assignments control who can access applications.

Practice Exam Questions

Question 1

Which Microsoft Entra object defines an application’s identity and contains its client ID?

A. App registration
B. Enterprise application
C. Conditional Access policy
D. Security group

Correct Answer: A

Explanation: App registrations define the application and contain identifiers and authentication settings.


Question 2

What is another name for an enterprise application in Microsoft Entra?

A. Managed identity
B. Service principal
C. Tenant object
D. Resource group

Correct Answer: B

Explanation: Enterprise applications are service principals that represent applications inside a tenant.


Question 3

Which permission type allows an application to act on behalf of a signed-in user?

A. Resource permission
B. Admin permission
C. Delegated permission
D. Conditional permission

Correct Answer: C

Explanation: Delegated permissions use the permissions of the signed-in user.


Question 4

Which object is commonly used to configure Single Sign-On for a SaaS application?

A. Security defaults
B. App registration only
C. Mailbox settings
D. Enterprise application

Correct Answer: D

Explanation: SSO settings are configured through enterprise applications.


Question 5

What is the primary purpose of an enterprise application?

A. Define redirect URIs
B. Store the client secret permanently
C. Represent an application inside a tenant and manage access
D. Replace Microsoft Entra users

Correct Answer: C

Explanation: Enterprise applications manage access and represent the app within the tenant.


Question 6

Which permission type usually requires administrator consent because it can affect organizational data?

A. Application permissions
B. Basic profile permissions
C. Redirect permissions
D. Device permissions

Correct Answer: A

Explanation: Application permissions often grant broad access and therefore typically require admin approval.


Question 7

An administrator wants only members of the Finance department to access an application. Which feature should be used?

A. Redirect URIs
B. Client certificates
C. User assignment within the enterprise application
D. Tenant synchronization

Correct Answer: C

Explanation: Enterprise applications allow administrators to assign specific users and groups.


Question 8

Which setting determines where authentication responses are sent after sign-in?

A. Directory ID
B. Redirect URI
C. Conditional Access policy
D. Service principal name

Correct Answer: B

Explanation: Redirect URIs specify where users are returned after successful authentication.


Question 9

A background application that runs without a signed-in user should typically use which permission type?

A. Delegated permissions
B. User permissions
C. Group permissions
D. Application permissions

Correct Answer: D

Explanation: Application permissions enable apps to run independently of users.


Question 10

Why should organizations periodically review enterprise applications and their permissions?

A. To increase mailbox size
B. To reduce unnecessary access and improve security
C. To change domain names automatically
D. To synchronize Teams channels

Correct Answer: B

Explanation: Reviewing applications helps maintain least privilege and reduce security risks.


Go to the AB-900 Exam Prep Hub main page

Identify the role of Privileged Identity Management (PIM) in an organization (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Identify the core features and objects of Microsoft 365 services (30–35%)
   --> Identify the core security features of Microsoft 365 services
      --> Identify the role of Privileged Identity Management (PIM) in an organization


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Organizations using Microsoft 365 and Microsoft Entra ID must protect administrative accounts because these accounts have elevated permissions that can affect users, data, applications, and security settings. Permanent administrator access creates unnecessary risk because compromised accounts can be used to perform harmful actions.

Privileged Identity Management (PIM) is a Microsoft Entra feature that helps organizations manage, control, and monitor privileged access. PIM provides just-in-time (JIT) access to administrative roles so users receive elevated permissions only when they need them and only for a limited period.

For the AB-900 exam, it is important to understand the purpose, benefits, and key capabilities of PIM rather than the detailed configuration steps.


What Is Privileged Identity Management (PIM)?

Microsoft Entra Privileged Identity Management is a service that enables organizations to:

  • Discover privileged accounts
  • Assign roles securely
  • Require approval before activation
  • Limit how long elevated access remains active
  • Audit administrative activities
  • Reduce standing privileges

Instead of granting users permanent administrator rights, PIM allows them to activate privileged roles temporarily when needed.

Example

Without PIM:

  • Alice is permanently assigned the Global Administrator role.

With PIM:

  • Alice is eligible for the Global Administrator role.
  • She activates the role only when performing administrative work.
  • The role automatically expires after a defined period.

This approach follows the principle of least privilege and supports a Zero Trust security model.


Why Organizations Use PIM

Administrative accounts are attractive targets for attackers because they can:

  • Reset passwords
  • Change security settings
  • Access sensitive data
  • Create new accounts
  • Disable protections

PIM helps organizations:

Reduce Security Risks

Users have elevated permissions only when necessary.

Limit Exposure Time

Temporary access decreases the amount of time privileged accounts can be exploited.

Increase Visibility

Organizations can monitor who activated roles and when.

Improve Compliance

Audit records help demonstrate compliance with regulatory requirements.

Support Zero Trust

PIM assumes no account should have continuous privileged access.


Just-in-Time (JIT) Access

One of the most important concepts in PIM is Just-in-Time access.

Traditional Access

User → Permanent Administrator Role

PIM Access

User → Eligible Role → Temporary Activation → Automatic Expiration

With JIT access:

  • Permissions are granted only when needed.
  • Access automatically expires after a specified duration.
  • The attack surface is reduced.

Eligible vs. Active Assignments

PIM uses two assignment types.

Eligible Assignment

The user:

  • Can activate the role when needed.
  • Does not have permissions until activation occurs.

Example:

John is eligible for the Exchange Administrator role but normally has no Exchange administrative permissions.


Active Assignment

The user:

  • Immediately possesses the role.
  • Does not need to activate it.

Active assignments are sometimes used for emergency or service accounts but should be minimized whenever possible.


Role Activation Process

When users need elevated permissions, they activate their eligible role.

Activation can require:

  • Multifactor authentication (MFA)
  • A business justification
  • Approval from another administrator
  • A ticket number
  • Time restrictions

After approval:

  • The role becomes active.
  • Permissions are available temporarily.
  • Access expires automatically.

Approval Workflows

Organizations may require managers or security administrators to approve privileged access requests.

Example workflow:

  1. User requests activation.
  2. PIM sends approval request.
  3. Approver reviews the request.
  4. Access is granted for a limited time.
  5. Role expires automatically.

Approval workflows add another layer of protection.


Time-Limited Access

PIM allows organizations to define activation durations.

Examples:

RoleDuration
Global Administrator1 hour
Exchange Administrator4 hours
SharePoint Administrator2 hours

Benefits include:

  • Reduced attack windows
  • Automatic removal of privileges
  • Better administrative control

Multifactor Authentication (MFA) for Role Activation

Organizations can require MFA before privileged access is activated.

This ensures:

  • The user is verified.
  • Stolen passwords alone cannot activate privileged roles.
  • Additional security protects sensitive operations.

Example:

A Global Administrator may need to:

  1. Sign in.
  2. Complete MFA.
  3. Enter a justification.
  4. Activate the role.

Audit Logs and Activity Tracking

PIM records privileged activities, including:

  • Role assignments
  • Activation requests
  • Approval actions
  • Expiration events
  • Administrative changes

Audit logs help organizations:

  • Investigate incidents.
  • Meet compliance requirements.
  • Understand who performed sensitive actions.

Access Reviews

PIM supports periodic access reviews.

These reviews help organizations determine:

  • Whether users still require privileged access.
  • Whether inactive assignments should be removed.
  • Whether excessive permissions exist.

Access reviews reduce privilege creep over time.


Alerts and Notifications

PIM can generate alerts for risky situations such as:

  • Too many Global Administrators.
  • Permanent role assignments.
  • Suspicious activation activity.
  • Administrators not using MFA.

Notifications can also be sent to administrators when:

  • Roles are activated.
  • Requests are approved.
  • Changes occur.

Resources Protected by PIM

PIM can manage privileged access for:

Microsoft Entra Roles

Examples:

  • Global Administrator
  • User Administrator
  • Security Administrator
  • Exchange Administrator

Azure Resource Roles

Examples:

  • Owner
  • Contributor
  • User Access Administrator

Groups

PIM can manage membership and ownership of privileged groups.


Common Roles Managed by PIM

Examples include:

RolePurpose
Global AdministratorFull Microsoft 365 administration
Exchange AdministratorManage Exchange Online
SharePoint AdministratorManage SharePoint Online
Teams AdministratorManage Microsoft Teams
Security AdministratorConfigure security settings
User AdministratorManage users and groups

Benefits of PIM

Organizations implementing PIM gain:

  • Reduced standing privileges
  • Stronger security
  • Just-in-time access
  • Automatic expiration of permissions
  • Approval workflows
  • Better auditing
  • Compliance support
  • Reduced insider risk
  • Support for Zero Trust principles

Relationship Between PIM and Zero Trust

PIM aligns closely with Zero Trust principles:

Verify Explicitly

Require MFA and approvals.

Use Least Privilege Access

Grant only necessary permissions.

Assume Breach

Limit exposure if an account becomes compromised.

Because of this alignment, PIM is considered an important security control in Microsoft environments.


Key Exam Points

Remember these AB-900 concepts:

  • PIM manages privileged access.
  • PIM reduces permanent administrator permissions.
  • Just-in-time access grants temporary privileges.
  • Users can be eligible or active.
  • MFA can be required before activation.
  • Approvals and justifications may be required.
  • Audit logs record privileged activities.
  • Access reviews help remove unnecessary privileges.
  • PIM supports Zero Trust and least privilege principles.

Practice Exam Questions

Question 1

What is the primary purpose of Microsoft Entra Privileged Identity Management?

A. Increase mailbox storage quotas
B. Configure SharePoint sites
C. Synchronize on-premises users with Microsoft 365
D. Manage and secure privileged access to resources

Correct Answer: D

Explanation: PIM helps organizations manage and secure privileged access by providing temporary, controlled administrator permissions.


Question 2

Which security principle is most closely supported by PIM?

A. Permanent administrative access
B. Open access permissions
C. Least privilege access
D. Shared administrator accounts

Correct Answer: C

Explanation: PIM grants elevated permissions only when needed, supporting least privilege.


Question 3

A user who can activate a role when needed but does not currently possess permissions has which type of assignment?

A. Resource assignment
B. Permanent assignment
C. Dynamic assignment
D. Eligible assignment

Correct Answer: D

Explanation: Eligible users activate roles only when necessary.


Question 4

What does Just-in-Time (JIT) access provide?

A. Permanent access to all services
B. Access only after synchronization occurs
C. Access to guest users only
D. Temporary elevated permissions when required

Correct Answer: D

Explanation: JIT access minimizes risk by limiting how long privileged permissions remain active.


Question 5

Which control can be required before a user activates a privileged role?

A. Disk encryption
B. Multifactor authentication
C. SharePoint versioning
D. Mail flow rules

Correct Answer: B

Explanation: MFA is commonly required before privileged access activation.


Question 6

What happens when the activation period ends?

A. Permissions are automatically removed
B. The account is deleted
C. The role becomes permanent
D. The user is blocked from signing in

Correct Answer: A

Explanation: PIM automatically removes elevated permissions after the configured duration expires.


Question 7

Which feature helps determine whether users still require privileged access?

A. Defender for Endpoint
B. Mail flow rules
C. Access reviews
D. Data loss prevention

Correct Answer: C

Explanation: Access reviews help organizations remove unnecessary privileges.


Question 8

Why do organizations prefer eligible assignments over permanent active assignments?

A. Eligible assignments require fewer licenses
B. Eligible assignments reduce standing administrative access
C. Eligible assignments eliminate the need for MFA
D. Eligible assignments disable audit logs

Correct Answer: B

Explanation: Temporary access reduces the attack surface and lowers risk.


Question 9

Which information can PIM audit logs capture?

A. Printer usage statistics
B. Browser history
C. Employee salaries
D. Role activations and approvals

Correct Answer: D

Explanation: PIM logs privileged activities such as activations, approvals, and assignments.


Question 10

Which role would commonly be managed through PIM?

A. Marketing Coordinator
B. Sales Representative
C. Global Administrator
D. Receptionist

Correct Answer: C

Explanation: Administrative roles with elevated permissions are ideal candidates for PIM management.


Go to the AB-900 Exam Prep Hub main page

Use the appropriate tools to review audit logs for user and admin activity (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Identify the core features and objects of Microsoft 365 services (30–35%)
   --> Identify the core security features of Microsoft 365 services
      --> Use the appropriate tools to review audit logs for user and admin activity


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Monitoring user and administrator actions is an essential part of Microsoft 365 security and governance. Organizations must be able to determine:

  • Who performed an action.
  • What action occurred.
  • When the activity occurred.
  • Which resource was affected.
  • Whether the activity was expected or suspicious.

Microsoft 365 provides several audit and logging tools that help administrators investigate security incidents, track administrative changes, support compliance requirements, and troubleshoot user issues.

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand the purpose of audit logs and know which tools are used to review user and administrator activity.


What Are Audit Logs?

Audit logs are records of activities performed within Microsoft 365 services.

They help organizations:

  • Detect suspicious behavior.
  • Investigate incidents.
  • Meet regulatory requirements.
  • Track administrative changes.
  • Support forensic investigations.
  • Verify user actions.

Audit logs provide visibility into activities occurring across Microsoft 365 environments.


Types of Activities Recorded

Microsoft 365 audit logs can capture actions such as:

User Activities

  • Signing in
  • Accessing files
  • Sharing documents
  • Creating Teams messages
  • Deleting files
  • Downloading content

Administrator Activities

  • Resetting passwords
  • Creating users
  • Assigning licenses
  • Modifying policies
  • Creating groups
  • Changing permissions

Service Activities

  • Mailbox operations
  • SharePoint changes
  • Teams events
  • Security configuration changes

Unified Audit Log

The primary audit tool in Microsoft 365 is the Unified Audit Log.

The Unified Audit Log collects events from multiple Microsoft 365 services, including:

  • Microsoft Entra ID
  • Exchange Online
  • SharePoint Online
  • OneDrive
  • Microsoft Teams
  • Microsoft Purview
  • Microsoft Defender
  • Power Platform services

Instead of reviewing separate logs for every service, administrators can search centrally.


Microsoft Purview Audit

The Unified Audit Log is accessed through Microsoft Purview.

Administrators can:

  • Search activities by user.
  • Search by date range.
  • Filter by workload.
  • Filter by activity type.
  • Export results.

This centralized approach simplifies investigations.


Common Search Filters

Administrators commonly filter audit logs by:

User

Example:

user1@contoso.com

Activity

Examples:

  • File deleted
  • Mailbox accessed
  • User added
  • Password reset

Date and Time

Investigations often focus on a specific period.

Workload

Examples:

  • SharePoint
  • Exchange
  • Teams
  • Entra ID

These filters narrow results and improve efficiency.


Microsoft Entra Sign-In Logs

Sign-in logs are separate from the Unified Audit Log and focus specifically on authentication activity.

Sign-in logs record:

  • Successful sign-ins
  • Failed sign-ins
  • IP addresses
  • Device information
  • Authentication methods used
  • Conditional Access results

Sign-in logs are commonly used to troubleshoot access issues and investigate suspicious login attempts.


Audit Logs vs Sign-In Logs

Students frequently confuse these two tools.

Sign-In Logs

Focus on:

  • Authentication attempts
  • MFA events
  • Conditional Access outcomes
  • Login locations

Audit Logs

Focus on:

  • User actions after authentication
  • Administrative changes
  • File access
  • Configuration modifications

Both are important, but they serve different purposes.


Examples of Audit Events

Exchange Online

Events may include:

  • Mailbox access
  • Email deletions
  • Mailbox permission changes

SharePoint Online

Events may include:

  • File creation
  • File downloads
  • File sharing

Microsoft Teams

Events may include:

  • Team creation
  • Channel creation
  • Membership changes

Microsoft Entra ID

Events may include:

  • User creation
  • Group modifications
  • Role assignments

Reviewing Administrator Activity

Audit logs help determine:

  • Which administrator made a change.
  • When the change occurred.
  • Which object was affected.

Examples include:

  • Password resets.
  • License assignments.
  • Group membership changes.
  • Conditional Access policy modifications.

This provides accountability and supports change tracking.


Reviewing User Activity

Audit logs can help answer questions such as:

  • Did a user delete a file?
  • Was a document downloaded?
  • Was information shared externally?
  • When did the action occur?

This information is valuable during investigations and compliance reviews.


Audit Logs and Microsoft 365 Copilot

Microsoft 365 Copilot relies on Microsoft 365 data sources.

Audit capabilities help organizations monitor:

  • User access to content.
  • Sharing activities.
  • Administrative changes affecting Copilot environments.
  • Compliance investigations involving AI-related workflows.

Copilot itself uses the same Microsoft 365 security and compliance framework.


Microsoft Defender XDR and Advanced Investigations

Microsoft Defender XDR can correlate events across:

  • Identities
  • Devices
  • Email
  • Applications

This provides a broader security perspective when investigating incidents.

While audit logs show individual events, Defender XDR helps connect related activities.


Retention of Audit Logs

Audit logs are retained for a specific period depending on:

  • Subscription level.
  • Licensing.
  • Service configuration.

Organizations with advanced compliance licensing may receive extended retention periods.

For AB-900, understand that retention periods can vary by license type.


Exporting Audit Results

Administrators can export audit results for:

  • Incident response.
  • Compliance reporting.
  • External investigations.
  • Long-term analysis.

Exported data can be reviewed using spreadsheets or SIEM solutions.


Best Practices

Review Logs Regularly

Continuous monitoring helps detect issues early.

Use Filters

Filtering speeds investigations.

Protect Administrator Accounts

Administrative actions should always be auditable.

Enable MFA

Secure accounts that have access to audit data.

Maintain Least Privilege

Limit who can access sensitive logs.

Retain Logs Appropriately

Ensure audit records meet organizational requirements.


Important Exam Tips

Remember these AB-900 concepts:

  • The Unified Audit Log is the primary Microsoft 365 audit tool.
  • Microsoft Purview provides access to audit searches.
  • Audit logs track actions performed after authentication.
  • Sign-in logs focus on authentication events.
  • Audit logs support investigations and compliance.
  • Administrator changes are recorded.
  • User activities can be searched and reviewed.
  • Microsoft 365 Copilot relies on the same audit and compliance framework.
  • Exporting logs supports reporting and analysis.
  • Retention periods vary by license.

Practice Exam Questions

Question 1

Which Microsoft 365 feature provides centralized auditing across multiple services?

A. Microsoft Planner
B. Windows Event Viewer
C. Unified Audit Log
D. Microsoft Lists

Correct Answer: C

Explanation: The Unified Audit Log aggregates events from multiple Microsoft 365 services into a single searchable location.


Question 2

Which portal is commonly used to access audit searches?

A. Exchange admin center
B. Teams admin center
C. Microsoft Purview
D. SharePoint admin center

Correct Answer: C

Explanation: Microsoft Purview provides access to auditing and compliance features, including audit searches.


Question 3

Which activity would typically appear in an audit log?

A. Administrator resets a user’s password.
B. Monitor brightness changes.
C. Printer toner replacement.
D. CPU temperature fluctuations.

Correct Answer: A

Explanation: Administrative actions such as password resets are recorded in audit logs.


Question 4

Which log type focuses primarily on authentication events?

A. Microsoft Entra sign-in logs
B. SharePoint recycle bin logs
C. Unified Audit Log
D. Exchange message trace logs

Correct Answer: A

Explanation: Sign-in logs capture authentication attempts, MFA information, and Conditional Access outcomes.


Question 5

Which Microsoft 365 service records file downloads and sharing activities?

A. SharePoint Online audit events
B. Windows Registry
C. BIOS settings
D. Active Directory Sites and Services

Correct Answer: A

Explanation: SharePoint audit events track document-related activities.


Question 6

An administrator wants to determine who changed a Conditional Access policy. Which tool should be used?

A. Windows Device Manager
B. Unified Audit Log
C. Outlook rules wizard
D. Microsoft Paint

Correct Answer: B

Explanation: Administrative changes are captured within Microsoft 365 audit records.


Question 7

What is a major difference between audit logs and sign-in logs?

A. Audit logs only store Exchange events.
B. Sign-in logs are used exclusively for Teams.
C. Audit logs track actions after authentication, while sign-in logs track authentication attempts.
D. Sign-in logs cannot be searched.

Correct Answer: C

Explanation: Sign-in logs focus on access attempts, while audit logs record actions performed after access is granted.


Question 8

Which filter can help narrow audit search results?

A. User name
B. Date range
C. Activity type
D. All of the above

Correct Answer: D

Explanation: Audit searches support multiple filters to improve investigation efficiency.


Question 9

Why are audit logs important for compliance investigations?

A. They increase internet bandwidth.
B. They provide records of user and administrator actions.
C. They automatically block attacks.
D. They create Conditional Access policies.

Correct Answer: B

Explanation: Audit records provide evidence of activities that occurred within Microsoft 365.


Question 10

Which statement about Microsoft 365 Copilot and auditing is correct?

A. Copilot bypasses audit logging.
B. Copilot disables Microsoft Purview.
C. Copilot uses a separate audit system unrelated to Microsoft 365.
D. Copilot operates within the existing Microsoft 365 compliance and auditing framework.

Correct Answer: D

Explanation: Microsoft 365 Copilot relies on the same security, compliance, and audit infrastructure used throughout Microsoft 365.


Go to the AB-900 Exam Prep Hub main page

Interpret Identity Secure Score in Microsoft Entra ID (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Identify the core features and objects of Microsoft 365 services (30–35%)
   --> Identify the core security features of Microsoft 365 services
      --> Interpret Identity Secure Score in Microsoft Entra ID


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Modern organizations face increasing identity-related threats such as password attacks, credential theft, phishing, and unauthorized access attempts. To help organizations measure and improve their identity security posture, Microsoft provides Identity Secure Score within Microsoft Entra ID.

Identity Secure Score gives administrators a numerical representation of how well identity security best practices are being implemented. It also provides actionable recommendations that can strengthen security and reduce risk.

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand:

  • What Identity Secure Score is.
  • Where it is located.
  • How scores are calculated.
  • What recommendations are provided.
  • How administrators can use the score to improve identity security.

What Is Identity Secure Score?

Identity Secure Score is a feature in Microsoft Entra ID that measures the effectiveness of an organization’s identity security controls.

It:

  • Evaluates current identity configurations.
  • Assigns points for implemented security controls.
  • Provides recommendations for improvements.
  • Helps organizations prioritize security actions.
  • Tracks progress over time.

Identity Secure Score focuses specifically on identity-related security rather than overall Microsoft 365 security.


Purpose of Identity Secure Score

The primary goals are to:

  • Reduce identity-based risks.
  • Encourage adoption of security best practices.
  • Provide visibility into security weaknesses.
  • Help administrators prioritize improvements.
  • Measure progress over time.

Identity Secure Score serves as both an assessment tool and a roadmap for improving identity security.


Where to Find Identity Secure Score

Identity Secure Score is available in the Microsoft Entra admin center.

Administrators can:

  1. Open Microsoft Entra admin center.
  2. Navigate to Protection.
  3. Select Identity Secure Score.

The dashboard displays:

  • Current score
  • Maximum possible score
  • Percentage achieved
  • Improvement actions
  • Trends over time

How the Score Is Calculated

The score is based on the implementation of recommended identity security controls.

Examples include:

  • Enabling multifactor authentication (MFA)
  • Using Conditional Access policies
  • Eliminating legacy authentication
  • Protecting privileged accounts
  • Registering authentication methods
  • Using passwordless authentication

Each completed recommendation contributes points toward the overall score.

Example

Suppose an organization:

  • Enables MFA for administrators.
  • Disables legacy authentication.
  • Implements Conditional Access.

These completed actions increase the Identity Secure Score.


Understanding the Score

A higher score generally indicates stronger identity protection.

However:

  • Identity Secure Score is not a guarantee of security.
  • A lower score does not necessarily mean the organization is compromised.
  • The score should be viewed as guidance rather than a compliance requirement.

The goal is continuous improvement rather than achieving a perfect score.


Improvement Actions

Identity Secure Score provides recommendations called improvement actions.

Each action includes:

  • Description of the recommendation.
  • Security benefits.
  • Number of points available.
  • Current implementation status.
  • Links to documentation.

Administrators can prioritize actions with the greatest security impact.


Examples of Improvement Actions

Common recommendations include:

Enable MFA for Administrators

Protects highly privileged accounts from compromise.

Enable MFA for Users

Reduces risks associated with stolen passwords.

Require Authentication Method Registration

Ensures users can complete MFA challenges.

Block Legacy Authentication

Prevents older protocols that bypass modern security controls.

Use Conditional Access Policies

Provides risk-based access control.

Protect Privileged Roles

Adds additional protection to administrator accounts.


Score Categories

Recommendations are grouped into categories such as:

Identity Protection

Improves defenses against compromised identities.

Authentication

Strengthens user sign-in methods.

Privileged Access

Secures administrative accounts.

Access Control

Implements Conditional Access and related protections.

Device Security

Ensures devices meet required standards.

These categories help administrators focus on specific security areas.


Trending and Historical Views

Identity Secure Score tracks changes over time.

Administrators can:

  • Monitor improvements.
  • Measure progress after implementing controls.
  • Demonstrate security enhancements to leadership.
  • Identify periods when scores decreased.

Historical trends support long-term security planning.


Comparing with Similar Organizations

Microsoft may provide benchmark information showing how an organization’s score compares with similar tenants.

This allows organizations to:

  • Understand industry averages.
  • Identify areas needing attention.
  • Set realistic improvement goals.

These comparisons are informational and should not replace security requirements specific to the organization.


Relationship to Microsoft Secure Score

Students often confuse these two tools.

Identity Secure Score

Focuses specifically on:

  • Users
  • Authentication
  • Identity protection
  • Conditional Access
  • Privileged access

Microsoft Secure Score

Measures security across Microsoft 365 services, including:

  • Identity
  • Devices
  • Applications
  • Data
  • Email
  • Collaboration services

Identity Secure Score is therefore a subset of overall security improvement efforts.


Identity Secure Score and Microsoft 365 Copilot

Microsoft 365 Copilot relies on Microsoft Entra identities for access.

Weak identity controls can increase the risk of:

  • Unauthorized access to Copilot.
  • Exposure of sensitive organizational data.
  • Compromised accounts using AI tools improperly.

Improving Identity Secure Score indirectly strengthens the security posture of Microsoft 365 Copilot environments.


Best Practices

Enable Multifactor Authentication

MFA is one of the most valuable security controls.

Protect Administrator Accounts

Privileged users should have additional safeguards.

Eliminate Legacy Authentication

Older protocols often bypass modern protections.

Use Conditional Access

Apply adaptive access policies based on risk.

Review Recommendations Regularly

Identity threats evolve continuously.

Focus on High-Impact Actions First

Not all recommendations provide equal security value.


Important Exam Tips

For AB-900, remember:

  • Identity Secure Score is found in Microsoft Entra ID.
  • It measures identity security posture.
  • Scores increase when recommended controls are implemented.
  • Improvement actions provide guidance and point values.
  • Identity Secure Score is different from Microsoft Secure Score.
  • MFA and Conditional Access commonly improve the score.
  • The score helps prioritize security improvements.
  • Historical trends show progress over time.
  • A perfect score is not required.
  • Microsoft 365 Copilot security depends on strong identities.

Practice Exam Questions

Question 1

What is the primary purpose of Identity Secure Score?

A. Measure and improve identity security posture
B. Track SharePoint storage usage
C. Monitor Exchange mailbox size
D. Manage Teams channels

Correct Answer: A

Explanation: Identity Secure Score evaluates identity security controls and provides recommendations for improvement.


Question 2

Where can administrators access Identity Secure Score?

A. Teams admin center
B. Exchange admin center
C. Microsoft Entra admin center
D. SharePoint admin center

Correct Answer: C

Explanation: Identity Secure Score is located within the Microsoft Entra admin center under Protection.


Question 3

Which action would typically increase Identity Secure Score?

A. Deleting Teams channels
B. Enabling multifactor authentication
C. Creating additional mailboxes
D. Increasing OneDrive storage

Correct Answer: B

Explanation: MFA is a recommended identity security control and contributes points to the score.


Question 4

What does a higher Identity Secure Score generally indicate?

A. Increased mailbox capacity
B. Stronger identity security posture
C. More SharePoint sites
D. Better Teams performance

Correct Answer: B

Explanation: Higher scores reflect the implementation of more recommended identity protections.


Question 5

Which information is provided with an improvement action?

A. Available point value and security benefit
B. Teams meeting recordings
C. Exchange message traces
D. OneDrive storage quotas

Correct Answer: A

Explanation: Improvement actions include descriptions, benefits, and associated points.


Question 6

Which recommendation commonly appears in Identity Secure Score?

A. Increase mailbox size limits
B. Add Teams emojis
C. Disable legacy authentication
D. Create more SharePoint libraries

Correct Answer: C

Explanation: Legacy authentication is a common attack vector, and disabling it improves security.


Question 7

What is one benefit of historical trend information?

A. It increases license counts automatically.
B. It allows organizations to track security improvements over time.
C. It creates Conditional Access policies automatically.
D. It backs up SharePoint sites.

Correct Answer: B

Explanation: Historical trends help administrators measure progress and evaluate changes.


Question 8

How does Identity Secure Score differ from Microsoft Secure Score?

A. Identity Secure Score measures device storage.
B. Microsoft Secure Score only evaluates Exchange Online.
C. Identity Secure Score focuses specifically on identity security controls.
D. Microsoft Secure Score only applies to Copilot.

Correct Answer: C

Explanation: Identity Secure Score concentrates on authentication and identity protection, while Microsoft Secure Score covers broader Microsoft 365 security.


Question 9

Which statement about a perfect Identity Secure Score is correct?

A. It guarantees the organization cannot be compromised.
B. It is legally required for Microsoft 365 tenants.
C. It automatically enables all security features.
D. It is not required; continuous improvement is the goal.

Correct Answer: D

Explanation: Secure Score is intended as guidance and a tool for ongoing security enhancement.


Question 10

Why is Identity Secure Score important for Microsoft 365 Copilot?

A. Copilot stores Secure Score values inside Word documents.
B. Copilot uses Microsoft Entra identities for access to organizational data.
C. Copilot disables Conditional Access policies.
D. Copilot replaces Microsoft Entra authentication.

Correct Answer: B

Explanation: Strong identity controls help protect Copilot and the data it can access.


Go to the AB-900 Exam Prep Hub main page

Identify the appropriate tools to troubleshoot common sign-in issues (multifactor authentication [MFA], conditional access, and risky sign-ins) (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Identify the core features and objects of Microsoft 365 services (30–35%)
   –> Identify the core security features of Microsoft 365 services
      –> Identify the appropriate tools to troubleshoot common sign-in issues (multifactor authentication [MFA], conditional access, and risky sign-ins)


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub’s main page below the exam topics section.


Introduction

Identity security is one of the foundations of Microsoft 365. Users depend on secure and reliable access to services such as Outlook, Teams, SharePoint, OneDrive, and Microsoft 365 Copilot. When users cannot sign in, administrators must determine the cause and resolve the issue quickly.

Microsoft provides several tools within Microsoft Entra, Microsoft 365, and Microsoft Defender to diagnose and troubleshoot sign-in problems related to:

  • Multi-Factor Authentication (MFA)
  • Conditional Access policies
  • Risky sign-ins
  • Identity Protection alerts
  • Account lockouts
  • Authentication failures

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand which tools are used to investigate and resolve these common issues.


Common Causes of Sign-In Problems

Users may experience sign-in failures because of:

  • Incorrect passwords
  • Expired credentials
  • Multi-Factor Authentication failures
  • Conditional Access policies
  • Blocked locations
  • Device compliance requirements
  • Risky sign-ins detected by Microsoft Entra
  • Account lockouts
  • Disabled user accounts

Troubleshooting begins by identifying which security control is preventing access.


Microsoft Entra Admin Center

The Microsoft Entra admin center is the primary location for troubleshooting identity-related problems.

Administrators can:

  • View users and groups.
  • Reset passwords.
  • Review authentication methods.
  • Investigate sign-in activity.
  • Examine Conditional Access policies.
  • Review risky users and risky sign-ins.

Many sign-in investigations begin here.


Sign-In Logs

One of the most important troubleshooting tools is the Sign-In Logs page in Microsoft Entra.

Sign-in logs provide information such as:

  • User account involved
  • Time of sign-in attempt
  • Success or failure status
  • IP address
  • Location
  • Device information
  • Authentication method used
  • Applications being accessed
  • Conditional Access results

Example

A user reports they cannot access Teams.

The sign-in log may show:

Failure reason: Conditional Access policy requires a compliant device.

This immediately points administrators toward the root cause.


Authentication Methods

Administrators can review a user’s configured authentication methods.

Examples include:

  • Microsoft Authenticator app
  • SMS verification
  • Phone calls
  • FIDO2 security keys
  • Passkeys

Problems may occur if:

  • A user changes phones.
  • The Authenticator app is deleted.
  • Authentication methods are not registered.

Administrators can help users re-register their methods if necessary.


Troubleshooting Multi-Factor Authentication (MFA)

MFA issues commonly involve:

Missing Registration

The user never enrolled in MFA.

Lost Device

The user replaced or lost their phone.

Notification Problems

Push notifications are not being received.

Incorrect Verification Method

The user is attempting to use an outdated authentication method.

Blocked Authentication

Security policies may prevent certain authentication methods.


Authentication Methods Policy

Administrators can review authentication method policies to verify:

  • Which methods are allowed.
  • Which users are targeted.
  • Whether a method has been disabled.

If SMS authentication has been disabled, users relying on text messages may be unable to complete MFA.


Conditional Access Troubleshooting

Conditional Access policies are a common source of access problems.

Examples include:

  • Requiring MFA
  • Blocking certain countries
  • Requiring compliant devices
  • Restricting specific applications

A user may have valid credentials but still be denied access because a policy condition is not satisfied.


Conditional Access Insights

The Conditional Access tab in sign-in logs helps administrators understand:

  • Which policies were evaluated.
  • Which policies applied.
  • Why access was granted or denied.

Example

The log may indicate:

Access blocked because device is not compliant.

This allows administrators to identify the exact policy causing the issue.


What-If Tool

The Conditional Access What-If tool allows administrators to simulate access scenarios.

Administrators can test:

  • User identity
  • Device platform
  • Location
  • Application

The tool predicts which policies would apply without affecting production users.

This is extremely helpful when diagnosing policy conflicts.


Risky Sign-Ins

Microsoft Entra Identity Protection analyzes sign-in behavior and detects suspicious activity.

Examples include:

  • Impossible travel
  • Anonymous IP addresses
  • Malware-linked addresses
  • Unfamiliar locations

A sign-in may be blocked even when the password is correct.


Risky Users

A user may be flagged as risky because:

  • Credentials were leaked.
  • Suspicious activity was detected.
  • Malware activity was associated with the account.

Risk levels include:

  • Low
  • Medium
  • High

Administrators can review and remediate risky users.


Identity Protection Dashboard

The Identity Protection dashboard helps administrators investigate:

  • Risky users
  • Risky sign-ins
  • Risk detections

Administrators can:

  • Confirm compromise.
  • Dismiss false positives.
  • Require password resets.
  • Restore access.

Password Reset Tools

Users who forget passwords can use:

Self-Service Password Reset (SSPR)

Allows users to reset passwords without contacting IT.

Benefits include:

  • Faster recovery
  • Reduced help desk workload
  • Improved productivity

Administrators can also manually reset passwords when necessary.


Account Status

Administrators should verify whether:

  • The account is enabled.
  • The user license is assigned.
  • The account has been deleted.
  • Sign-in is blocked.

Sometimes the simplest explanation is the correct one.


Device Compliance Issues

Conditional Access often integrates with Microsoft Intune.

Users may be blocked because:

  • Device encryption is disabled.
  • Operating systems are outdated.
  • Antivirus requirements are unmet.
  • Devices are unmanaged.

Administrators can review compliance status in Intune.


Common Troubleshooting Workflow

Step 1: Verify User Account

  • Is the account active?
  • Is the correct license assigned?

Step 2: Review Sign-In Logs

  • Determine why authentication failed.

Step 3: Check MFA

  • Verify authentication methods.

Step 4: Review Conditional Access

  • Identify policies that blocked access.

Step 5: Review Risk Detections

  • Investigate risky users or risky sign-ins.

Step 6: Remediate

  • Reset password.
  • Re-register MFA.
  • Update device compliance.
  • Modify policy if appropriate.

Microsoft 365 Copilot Sign-In Issues

Microsoft 365 Copilot uses the same identity infrastructure as Microsoft 365.

Therefore, problems involving:

  • MFA
  • Conditional Access
  • User permissions
  • Risky sign-ins

can also affect access to Copilot.

Copilot does not bypass Microsoft Entra security controls.


Best Practices

Enable Self-Service Password Reset

Reduce support calls and improve user productivity.

Require MFA

Protect accounts from password theft.

Review Sign-In Logs First

They often reveal the root cause quickly.

Test Policies Before Deployment

Use the What-If tool to avoid accidental lockouts.

Monitor Risk Detections

Respond quickly to compromised accounts.

Apply Least Privilege

Avoid overly broad permissions and exceptions.


Exam Tips

Remember these AB-900 concepts:

  • The Microsoft Entra admin center is the primary identity troubleshooting portal.
  • Sign-in logs provide detailed authentication information.
  • MFA problems often involve authentication methods.
  • Conditional Access policies can block otherwise valid sign-ins.
  • The What-If tool simulates policy results.
  • Risky sign-ins are detected by Identity Protection.
  • Risky users may require password resets.
  • Self-Service Password Reset helps users recover accounts.
  • Device compliance can affect access.
  • Microsoft 365 Copilot relies on the same identity controls as Microsoft 365.

Practice Exam Questions

Question 1

A user reports they cannot access Microsoft Teams even though their password is correct. Which tool should an administrator review first?

A. Microsoft Planner
B. SharePoint recycle bin
C. Exchange message trace
D. Sign-in logs in Microsoft Entra

Correct Answer: D

Explanation: Sign-in logs provide details about authentication attempts and often reveal the reason access failed.


Question 2

Which Microsoft portal is the primary location for investigating identity-related sign-in problems?

A. SharePoint admin center
B. Microsoft Entra admin center
C. Teams admin center
D. Exchange admin center

Correct Answer: B

Explanation: Microsoft Entra provides identity management and troubleshooting capabilities.


Question 3

A user receives an MFA prompt but no longer has their old phone. Which area should an administrator review?

A. Distribution groups
B. Shared mailboxes
C. Authentication methods
D. Mail flow rules

Correct Answer: C

Explanation: Authentication methods determine which MFA options are available to users.


Question 4

Which feature allows administrators to simulate how Conditional Access policies would affect a user?

A. Risk detections dashboard
B. Sign-in diagnostics
C. Password reset portal
D. Conditional Access What-If tool

Correct Answer: D

Explanation: The What-If tool predicts policy outcomes without affecting users.


Question 5

Which Microsoft capability identifies suspicious activities such as impossible travel?

A. Exchange Online Protection
B. Microsoft Lists
C. Identity Protection
D. SharePoint Syntex

Correct Answer: C

Explanation: Identity Protection analyzes sign-in behavior and detects potential compromises.


Question 6

A sign-in log shows that access was denied because the device is not compliant. Which Microsoft service commonly provides compliance information?

A. Microsoft Intune
B. Outlook
C. Planner
D. Word

Correct Answer: A

Explanation: Intune manages devices and reports compliance status used by Conditional Access.


Question 7

Which feature allows users to reset their own passwords without contacting IT?

A. Password Protection
B. Self-Service Password Reset (SSPR)
C. Secure Score
D. Message Encryption

Correct Answer: B

Explanation: SSPR enables users to recover access independently.


Question 8

Which information can administrators view in sign-in logs?

A. Printer serial numbers
B. Monitor resolutions
C. CPU temperatures
D. Authentication success or failure details

Correct Answer: D

Explanation: Sign-in logs contain information about sign-in attempts and their outcomes.


Question 9

Which type of event may cause Microsoft Entra to classify a sign-in as risky?

A. Impossible travel between locations
B. A full mailbox
C. Duplicate Teams channels
D. Deleted SharePoint folders

Correct Answer: A

Explanation: Impossible travel is one of the risk signals analyzed by Identity Protection.


Question 10

How are Microsoft 365 Copilot sign-in problems typically investigated?

A. Copilot uses a separate identity system.
B. Copilot bypasses Conditional Access.
C. Copilot relies on the same Microsoft Entra identity controls as Microsoft 365.
D. Copilot does not use MFA.

Correct Answer: C

Explanation: Copilot uses the same authentication and security infrastructure as other Microsoft 365 services.


Go to the AB-900 Exam Prep Hub main page

Identify the appropriate security object to use in an organization (users and groups) (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Identify the core features and objects of Microsoft 365 services (30–35%)
   --> Identify the core security features of Microsoft 365 services
      --> Identify the appropriate security object to use in an organization (users and groups)


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft 365 uses identities and group memberships to control access to resources, applications, and data. Two of the most important security objects in Microsoft Entra ID and Microsoft 365 are users and groups.

Understanding when to use users and groups is fundamental to administering Microsoft 365 and securing resources. Rather than assigning permissions individually to every person, administrators can use groups to simplify access management and improve security.

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand the purpose of users and groups, their differences, and common scenarios for using each object.


Understanding Security Objects

A security object represents an identity or a collection of identities that can receive permissions and access rights.

Common Microsoft 365 security objects include:

  • Users
  • Groups
  • Service principals
  • Devices

For the AB-900 exam, the focus is primarily on users and groups.


Users

A user represents an individual identity that can authenticate and access Microsoft 365 resources.

Examples include:

  • Employees
  • Contractors
  • Students
  • Administrators

Each user account contains information such as:

  • Username (User Principal Name)
  • Display name
  • Email address
  • Assigned licenses
  • Group memberships
  • Authentication settings

Types of User Accounts

Member Users

Member users belong to the organization’s Microsoft Entra tenant.

Examples:

  • Employees
  • IT administrators
  • Internal staff

Member users typically receive:

  • Microsoft 365 licenses
  • Mailboxes
  • Teams access
  • SharePoint permissions

Guest Users

Guest users are external users invited into the organization through Microsoft Entra B2B collaboration.

Examples:

  • Vendors
  • Consultants
  • Business partners

Guest users:

  • Use their own credentials.
  • Access only resources that have been shared with them.
  • Typically do not require full Microsoft 365 licenses.

Why User Accounts Are Important

User accounts provide:

Authentication

Verifying identity during sign-in.

Authorization

Determining what resources users can access.

Auditing

Tracking activities performed by specific individuals.

Personalization

Providing personalized experiences across Microsoft 365.


Groups

A group is a collection of users that simplifies management.

Instead of assigning permissions individually to many users, administrators assign permissions to the group and then add users to that group.

Benefits include:

  • Easier administration
  • Consistent permissions
  • Reduced errors
  • Faster onboarding and offboarding

Why Groups Improve Security

Suppose 100 employees need access to a SharePoint site.

Without groups:

  • Permissions must be assigned to 100 individual users.

With groups:

  1. Create a group.
  2. Assign permissions once.
  3. Add users to the group.

This approach is:

  • Easier to manage.
  • More scalable.
  • Less likely to produce permission mistakes.

Types of Groups in Microsoft 365

Security Groups

Security groups are used primarily for assigning permissions.

Common uses:

  • SharePoint access
  • Conditional Access targeting
  • Application permissions
  • Device management

Example:

Finance Security Group

Members automatically inherit permissions assigned to the group.


Microsoft 365 Groups

Microsoft 365 groups provide collaboration capabilities in addition to membership management.

They can automatically provide:

  • Shared mailbox
  • Shared calendar
  • Teams workspace
  • SharePoint site
  • Planner resources

Example:

Marketing Team

Distribution Groups

Distribution groups are used mainly for email communication.

Purpose:

  • Send one email to multiple recipients.

Examples:

  • All Employees
  • Human Resources
  • Sales Department

Distribution groups do not provide collaboration resources like Teams or SharePoint sites.


Mail-Enabled Security Groups

These groups combine:

  • Security permissions
  • Email distribution capabilities

They are useful when a group needs both access permissions and email functionality.


Users vs Groups

UsersGroups
Represent individualsRepresent collections of users
Authenticate directlyDo not sign in
Receive licensesUsually do not receive licenses
Have personal settingsShare common permissions
Used for identityUsed for access management

When to Use Individual Users

Use user objects when:

  • Assigning licenses.
  • Managing authentication methods.
  • Configuring MFA.
  • Reviewing sign-in logs.
  • Managing personal mailboxes.

Examples:

  • Assigning a Microsoft 365 Copilot license.
  • Resetting a password.
  • Enabling MFA.

When to Use Groups

Use groups when:

  • Granting access to resources.
  • Assigning SharePoint permissions.
  • Managing Teams membership.
  • Applying Conditional Access policies.
  • Organizing departments.

Examples:

  • Finance team access to a SharePoint site.
  • Sales department access to Teams channels.
  • Applying a security policy to all administrators.

Group-Based Management

Microsoft Entra supports group-based administration.

Advantages include:

Simplified Administration

One change affects many users.

Reduced Errors

Permissions are applied consistently.

Faster Employee Onboarding

Adding a new employee to the correct groups automatically provides needed access.

Easier Offboarding

Removing users from groups quickly revokes access.


Dynamic Groups

Dynamic groups automatically add or remove users based on attributes.

Examples:

  • Department = Sales
  • Country = United States
  • Job title = Manager

Benefits:

  • Automation
  • Reduced administrative effort
  • Consistent membership

Groups and Conditional Access

Conditional Access policies often target:

  • Users
  • Groups

Example:

Require MFA for all members of the IT Administrators group.

This is more efficient than configuring each administrator individually.


Groups and Microsoft 365 Copilot

Groups help manage access to resources used by Microsoft 365 Copilot.

Examples:

  • Teams membership
  • SharePoint permissions
  • Collaboration resources
  • Departmental content access

Because Copilot respects existing permissions, group memberships indirectly influence what content users can access through Copilot.


Best Practices

Assign Permissions to Groups Instead of Individuals

This improves scalability and consistency.

Use Security Groups for Access Management

Avoid assigning permissions directly to users whenever possible.

Use Microsoft 365 Groups for Collaboration

These groups support Teams, SharePoint, and Outlook integration.

Follow Least Privilege

Provide only the permissions users require.

Review Group Membership Regularly

Remove unnecessary access and outdated memberships.


Exam Tips

Remember these AB-900 concepts:

  • Users represent individual identities.
  • Groups represent collections of users.
  • Users authenticate; groups do not.
  • Security groups manage permissions.
  • Microsoft 365 groups support collaboration resources.
  • Distribution groups are primarily used for email.
  • Group-based management simplifies administration.
  • Dynamic groups automate membership.
  • Conditional Access policies can target groups.
  • Microsoft 365 Copilot respects permissions inherited through groups.

Practice Exam Questions

Question 1

Which security object represents an individual identity in Microsoft 365?

A. Distribution group
B. Microsoft 365 group
C. User account
D. Shared mailbox

Correct Answer: C

Explanation: A user account represents an individual who can authenticate and access Microsoft 365 resources.


Question 2

What is the primary advantage of using groups instead of assigning permissions individually?

A. Groups eliminate authentication requirements.
B. Groups simplify administration and provide consistent access.
C. Groups automatically assign licenses.
D. Groups replace Microsoft Entra ID.

Correct Answer: B

Explanation: Groups allow administrators to manage permissions for multiple users at once.


Question 3

Which type of group is primarily used for email distribution?

A. Security group
B. Microsoft 365 group
C. Dynamic group
D. Distribution group

Correct Answer: D

Explanation: Distribution groups are designed mainly for sending email messages to multiple recipients.


Question 4

Which object can sign in to Microsoft 365?

A. User account
B. Security group
C. Distribution group
D. Microsoft 365 group

Correct Answer: A

Explanation: Users authenticate directly, while groups are collections of users and cannot sign in.


Question 5

Which group type automatically provides collaboration resources such as a shared mailbox and SharePoint site?

A. Security group
B. Distribution group
C. Mail-enabled security group
D. Microsoft 365 group

Correct Answer: D

Explanation: Microsoft 365 groups provide collaboration services including Teams and SharePoint.


Question 6

A company wants to grant SharePoint access to an entire department. Which approach is recommended?

A. Assign permissions to each employee individually.
B. Create a security group and assign permissions to the group.
C. Create separate user accounts for each site.
D. Use a distribution group only.

Correct Answer: B

Explanation: Security groups simplify access management and reduce administrative effort.


Question 7

What is a dynamic group?

A. A group used only for Teams meetings.
B. A group with manually maintained memberships.
C. A group that sends email externally.
D. A group whose membership is automatically managed based on user attributes.

Correct Answer: D

Explanation: Dynamic groups automatically update membership according to configured rules.


Question 8

Which object is typically assigned Microsoft 365 licenses?

A. Security groups
B. Distribution groups
C. User accounts
D. Shared calendars

Correct Answer: C

Explanation: Licenses are generally assigned to individual users.


Question 9

Which statement about guest users is correct?

A. Guest users must always have Microsoft 365 licenses.
B. Guest users are external users invited to collaborate with the organization.
C. Guest users replace security groups.
D. Guest users cannot access SharePoint resources.

Correct Answer: B

Explanation: Guest users are external identities that can be granted access to shared resources.


Question 10

How do groups influence Microsoft 365 Copilot?

A. Groups allow Copilot to bypass permissions.
B. Groups disable Conditional Access.
C. Groups determine resource permissions that Copilot respects.
D. Groups automatically generate Copilot prompts.

Correct Answer: C

Explanation: Copilot uses existing Microsoft 365 permissions, many of which are granted through group memberships.


Go to the AB-900 Exam Prep Hub main page

Understand the purpose and benefits of Single Sign-On (SSO) (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Identify the core features and objects of Microsoft 365 services (30–35%)
   --> Identify the core security features of Microsoft 365 services
      --> Understand the purpose and benefits of SSO


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Modern organizations use many applications and services, including Microsoft 365, Teams, SharePoint, Exchange Online, and third-party cloud applications. Without a centralized authentication system, users would need to maintain separate usernames and passwords for every application they use.

Single Sign-On (SSO) simplifies the user experience and improves security by allowing users to authenticate once and then access multiple applications without repeatedly signing in.

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, understanding the purpose and benefits of SSO is an important identity and security concept.


What Is Single Sign-On (SSO)?

Single Sign-On (SSO) is an authentication capability that allows users to sign in one time and gain access to multiple applications and services without entering credentials again for each application.

Instead of managing separate accounts for every service, users rely on a single identity managed through Microsoft Entra ID.

Example

A user signs in once and can then access:

  • Outlook
  • Microsoft Teams
  • SharePoint Online
  • OneDrive
  • Microsoft 365 Copilot
  • Third-party applications integrated with Microsoft Entra

SSO improves both convenience and security.


Why SSO Is Important

Without SSO, users often:

  • Maintain many passwords.
  • Reuse passwords across applications.
  • Forget credentials.
  • Require frequent password resets.

SSO addresses these challenges by providing a centralized authentication experience.


How Single Sign-On Works

The SSO process generally follows these steps:

Step 1: User Signs In

The user authenticates with Microsoft Entra ID.

Step 2: Identity Is Verified

Microsoft Entra confirms the user’s identity.

Step 3: Authentication Token Is Issued

A secure token is generated.

Step 4: Applications Trust the Token

Integrated applications accept the token and grant access without requiring another sign-in.

This process allows users to move seamlessly between applications.


SSO and Microsoft Entra ID

Microsoft Entra ID serves as the identity provider for Microsoft 365.

It provides:

  • Authentication
  • Authorization
  • Identity management
  • Access policies

Because Microsoft 365 services trust Microsoft Entra ID, users can access multiple services after a single sign-in.


Applications That Support SSO

SSO can be used with:

Microsoft 365 Applications

Examples:

  • Outlook
  • Teams
  • SharePoint Online
  • OneDrive
  • Word
  • Excel
  • PowerPoint

Third-Party Applications

Examples:

  • Salesforce
  • ServiceNow
  • Workday
  • Thousands of SaaS applications

Custom Applications

Organizations can integrate internally developed applications with Microsoft Entra.


Benefits of Single Sign-On

Improved User Experience

Users sign in once instead of repeatedly entering passwords.

Benefits include:

  • Less frustration.
  • Faster access to applications.
  • Improved productivity.

Reduced Password Fatigue

Managing many passwords can be difficult.

SSO reduces:

  • Forgotten passwords.
  • Password reuse.
  • User frustration.

Fewer Help Desk Requests

Password resets are one of the most common support issues.

SSO reduces:

  • Password-related tickets.
  • Administrative overhead.
  • Support costs.

Increased Productivity

Employees spend less time signing in and more time working.

Users can move easily between:

  • Teams
  • Outlook
  • SharePoint
  • Copilot

without repeated authentication prompts.


Improved Security

Although SSO simplifies access, security can actually improve because organizations can enforce:

  • Multi-Factor Authentication (MFA)
  • Conditional Access
  • Identity Protection
  • Centralized authentication policies

Centralized Access Management

Administrators can manage identities from one location instead of configuring authentication separately for every application.

Benefits include:

  • Easier administration.
  • Consistent security controls.
  • Faster onboarding and offboarding.

SSO and Multi-Factor Authentication

SSO does not replace MFA.

Instead, they work together.

Example:

  1. User signs in once.
  2. User completes MFA.
  3. Access is granted to multiple applications.

This provides:

  • Convenience
  • Strong security

SSO and Conditional Access

Conditional Access policies can still apply even when SSO is used.

Examples:

  • Require MFA outside the corporate network.
  • Block risky sign-ins.
  • Require compliant devices.

SSO and Conditional Access complement each other.


SSO and Zero Trust

Single Sign-On supports Zero Trust when combined with modern security controls.

Verify Explicitly

Authentication still occurs before access is granted.

Use Least Privileged Access

Permissions are still enforced.

Assume Breach

Additional controls such as MFA and Conditional Access continue to evaluate risk.


SSO Does Not Mean Unlimited Access

A common misconception is that SSO gives users access to everything.

This is incorrect.

SSO:

  • Simplifies authentication.

Authorization still determines:

  • Which applications users can access.
  • What permissions they have.
  • Which resources they can view.

Users only receive access to resources they are authorized to use.


SSO and Microsoft 365 Copilot

Microsoft 365 Copilot relies on Microsoft Entra identities and benefits from SSO.

After users authenticate, they can move between:

  • Outlook
  • Teams
  • SharePoint
  • Word
  • Copilot experiences

without repeatedly entering credentials.

Copilot still respects existing permissions and security controls.


SSO vs Multiple Sign-Ins

Without SSOWith SSO
Multiple passwordsOne identity
Repeated sign-insSingle sign-in
Higher password fatigueBetter user experience
More password reset requestsFewer support calls
Greater password reuse riskImproved security

Best Practices

Enable Multi-Factor Authentication

SSO should be combined with MFA for stronger security.

Use Conditional Access

Evaluate sign-in risk and device compliance.

Follow Least Privilege

Users should only access necessary resources.

Centralize Identity Management

Use Microsoft Entra ID to manage users and applications.

Educate Users

Help users understand the difference between authentication and authorization.


Exam Tips

Remember these AB-900 concepts:

  • SSO stands for Single Sign-On.
  • SSO allows one sign-in to access multiple applications.
  • Microsoft Entra ID provides SSO for Microsoft 365.
  • SSO improves productivity and user experience.
  • SSO reduces password fatigue and help desk requests.
  • SSO does not replace authorization.
  • MFA and Conditional Access continue to function with SSO.
  • SSO supports Zero Trust when combined with additional security controls.
  • Microsoft 365 Copilot benefits from SSO.
  • Users only access resources they are authorized to use.

Practice Exam Questions

Question 1

What is the primary purpose of Single Sign-On (SSO)?

A. Encrypt documents automatically
B. Allow one authentication event to provide access to multiple applications
C. Replace authorization controls
D. Eliminate passwords completely

Correct Answer: B

Explanation: SSO enables users to authenticate once and access multiple applications without repeatedly entering credentials.


Question 2

Which Microsoft service provides Single Sign-On capabilities for Microsoft 365?

A. Microsoft Entra ID
B. Exchange Online
C. Microsoft Defender XDR
D. Microsoft Purview

Correct Answer: A

Explanation: Microsoft Entra ID acts as the identity provider for Microsoft 365 applications.


Question 3

Which problem does SSO help reduce?

A. SharePoint storage limitations
B. Teams meeting duration limits
C. Password fatigue
D. Mailbox quotas

Correct Answer: C

Explanation: Users no longer need to remember numerous passwords for different applications.


Question 4

What typically decreases when organizations implement SSO?

A. File version history
B. Help desk password reset requests
C. Device compliance policies
D. Multi-Factor Authentication

Correct Answer: B

Explanation: Fewer passwords usually lead to fewer password-related support requests.


Question 5

Which security control commonly works together with SSO?

A. Multi-Factor Authentication
B. Shared mailboxes
C. Distribution lists
D. Public folders

Correct Answer: A

Explanation: MFA strengthens security while maintaining the convenience of SSO.


Question 6

Does SSO automatically grant users access to every application?

A. Yes, if they know their password.
B. Yes, after one successful sign-in.
C. No, authorization and permissions still determine access.
D. No, unless Teams is installed.

Correct Answer: C

Explanation: SSO simplifies authentication but does not bypass authorization.


Question 7

Which statement best describes the relationship between SSO and Conditional Access?

A. SSO disables Conditional Access.
B. Conditional Access only works without SSO.
C. SSO replaces Conditional Access.
D. SSO and Conditional Access work together to secure access.

Correct Answer: D

Explanation: Conditional Access policies continue to evaluate users and devices even when SSO is used.


Question 8

Which benefit of SSO improves employee productivity?

A. Automatic mailbox backups
B. Elimination of file permissions
C. Reduced repeated sign-ins
D. Increased SharePoint storage

Correct Answer: C

Explanation: Users spend less time authenticating and more time working.


Question 9

Which Microsoft 365 services can benefit from SSO?

A. Outlook only
B. Teams only
C. SharePoint only
D. Outlook, Teams, SharePoint, and other Microsoft 365 applications

Correct Answer: D

Explanation: SSO supports access across multiple Microsoft 365 services.


Question 10

How does Microsoft 365 Copilot use Single Sign-On?

A. Copilot bypasses Microsoft Entra authentication.
B. Copilot requires separate credentials from Microsoft 365.
C. Copilot benefits from the same sign-in experience used by Microsoft 365 services.
D. Copilot disables Multi-Factor Authentication.

Correct Answer: C

Explanation: Copilot relies on Microsoft Entra identities and participates in the same SSO experience as other Microsoft 365 applications.


Go to the AB-900 Exam Prep Hub main page