Tag: AI Agents

Plan channels and deployment (AB-620 Exam Prep)

This post is a part of the AB-620: Designing and Building Integrated AI Agent Solutions in Copilot Studio Exam Prep Hub.
This topic falls under these sections:
Plan and configure agent solutions (30–35%)
   --> Plan an agent solution
      --> Plan channels and deployment


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

One of the final planning activities before building an AI agent is determining where users will interact with the agent and how the solution will be deployed. Even the most intelligent AI agent will not deliver business value if it is deployed to the wrong audience, through the wrong communication channels, or without proper governance.

In Microsoft Copilot Studio, channels are the communication platforms through which users interact with an agent, while deployment is the process of publishing, distributing, updating, and managing the agent across those channels.

For the AB-620 exam, you should understand how to:

  • Select the appropriate communication channels
  • Determine deployment strategies
  • Plan environments and lifecycle management
  • Consider authentication and security requirements
  • Plan for scalability and governance
  • Choose deployment approaches that align with business requirements

Planning these elements before implementation helps ensure that the agent reaches the intended users while remaining secure, manageable, and maintainable.


What Are Channels?

A channel is the interface through which users communicate with a Copilot Studio agent.

Examples include:

  • Microsoft Teams
  • Microsoft 365 Copilot
  • Web sites
  • Mobile applications
  • Custom applications
  • Omnichannel for Customer Service
  • Direct Line API
  • Custom integrations

Different channels serve different business needs and user experiences.


Why Channel Planning Is Important

Selecting the correct channel affects:

  • User adoption
  • Accessibility
  • Security
  • Authentication
  • User experience
  • Integration requirements
  • Deployment complexity
  • Maintenance

Choosing the wrong channel may result in poor usability, unnecessary development work, or security challenges.


Factors to Consider When Selecting Channels

When planning deployment channels, consider the following questions:

  • Who are the users?
  • Where do they already work?
  • What devices do they use?
  • Do they need authentication?
  • Is the audience internal or external?
  • Will users interact through text, voice, or both?
  • Does the channel support required features?
  • Are compliance requirements met?

These questions guide architects toward the most appropriate deployment strategy.


Common Deployment Channels

Microsoft Teams

Microsoft Teams is one of the most common deployment targets for Copilot Studio agents.

Typical scenarios include:

  • Employee self-service
  • IT help desk
  • HR support
  • Finance assistance
  • Internal knowledge search
  • Project management

Advantages include:

  • Integrated authentication with Microsoft Entra ID
  • Familiar user experience
  • Easy access for employees
  • Integration with Microsoft 365 services

Teams is generally the preferred channel for internal organizational agents.


Microsoft 365 Copilot

Organizations can integrate agents with Microsoft 365 Copilot to extend user capabilities across Microsoft applications.

Users may interact with agents while working in:

  • Outlook
  • Word
  • Excel
  • PowerPoint
  • Teams

Benefits include:

  • Seamless productivity workflows
  • Context-aware assistance
  • Access to Microsoft Graph data (subject to permissions)
  • Consistent user experience

Websites

Agents can be embedded into public or private websites.

Common uses include:

  • Customer support
  • Product information
  • FAQs
  • Sales assistance
  • Appointment scheduling

Website deployment is ideal for customer-facing solutions.


Mobile Applications

Organizations may embed agents into mobile apps.

Example scenarios:

  • Banking
  • Healthcare
  • Retail
  • Travel
  • Field service

Benefits include:

  • Convenient mobile access
  • Personalized experiences
  • Integration with mobile app functionality

Custom Applications

Organizations often integrate Copilot Studio agents into existing business applications.

Examples include:

  • ERP systems
  • CRM systems
  • Employee portals
  • Partner portals
  • Internal dashboards

This approach creates a unified experience without requiring users to switch applications.


Omnichannel for Customer Service

Customer service organizations often deploy agents through Omnichannel.

Benefits include:

  • Live agent handoff
  • Customer service routing
  • Persistent conversations
  • Integration with Dynamics 365 Customer Service

Direct Line API

The Direct Line API allows developers to integrate Copilot Studio agents into custom applications.

Advantages include:

  • Flexible deployment
  • Custom user interfaces
  • Mobile integration
  • Enterprise application integration

This option is best suited for organizations requiring customized experiences.


Internal vs. External Deployment

One of the first planning decisions is identifying the intended audience.

Internal Deployment

Internal users include:

  • Employees
  • Contractors
  • Business partners

Characteristics:

  • Microsoft Entra ID authentication
  • Enterprise security policies
  • Internal business systems
  • Sensitive organizational data

Examples:

  • HR assistant
  • IT help desk
  • Finance support

External Deployment

External users include:

  • Customers
  • Vendors
  • Citizens
  • Website visitors

Characteristics:

  • Public accessibility
  • Customer authentication (if required)
  • Strong security controls
  • High scalability

Examples:

  • Customer support
  • Product assistant
  • Service request agent

Authentication Considerations

Deployment planning should consider authentication requirements.

Examples:

Internal agents often use:

  • Microsoft Entra ID
  • Single Sign-On

Customer-facing agents may use:

  • Customer identity providers
  • OAuth
  • Anonymous access (when appropriate)

Authentication requirements often influence channel selection.


Deployment Environments

Copilot Studio solutions typically move through multiple environments during their lifecycle.

Common environments include:

Development

Purpose:

  • Build features
  • Experiment
  • Initial testing

Test

Purpose:

  • Functional testing
  • Integration testing
  • User acceptance testing (UAT)

Production

Purpose:

  • Live users
  • Business operations
  • Stable deployments

Separating environments reduces the risk of introducing untested changes into production.


Solution Lifecycle Management (ALM)

Deployment planning should include Application Lifecycle Management (ALM).

ALM includes:

  • Source control
  • Version management
  • Testing
  • Deployment
  • Rollback
  • Monitoring
  • Continuous improvement

A structured ALM process improves quality and reduces deployment risks.


Publishing an Agent

Before users can access an agent, it must be published.

Publishing typically includes:

  • Validating configuration
  • Saving changes
  • Publishing the latest version
  • Making updates available to deployment channels

Publishing does not automatically make every change visible until the updated version is deployed.


Version Management

Organizations should maintain multiple versions of their agents.

Benefits include:

  • Safe updates
  • Rollback capability
  • Controlled releases
  • Easier troubleshooting

Versioning is especially important for enterprise solutions with large user bases.


Environment Variables

Environment variables allow deployment configurations to change between environments without modifying the agent.

Examples:

  • API URLs
  • Database connections
  • Authentication endpoints
  • Service identifiers

Using environment variables simplifies deployments across development, testing, and production.


Security Considerations

Deployment planning should address:

  • Authentication
  • Authorization
  • Least privilege
  • Data protection
  • Conditional Access
  • Compliance
  • Data Loss Prevention (DLP)
  • Secure connectors

Security should be considered before deployment rather than after deployment.


Scalability Planning

Deployment planning should consider future growth.

Questions include:

  • How many users will access the agent?
  • Will usage spike during business hours?
  • Will multiple regions be supported?
  • How many enterprise integrations are involved?
  • Will additional channels be added later?

Planning for scalability helps prevent future redesigns.


User Experience Considerations

Choose channels based on how users naturally work.

Examples:

Employees:

  • Microsoft Teams
  • Microsoft 365

Customers:

  • Company website
  • Mobile application

Developers:

  • Custom applications
  • Direct Line API

A familiar interface increases adoption.


Monitoring After Deployment

Deployment planning should include monitoring.

Monitor:

  • Usage statistics
  • Conversation success rates
  • Escalations
  • Failed authentications
  • Connector failures
  • API errors
  • User satisfaction
  • Performance metrics

Monitoring provides insight into how the agent performs in production and supports continuous improvement.


Governance Considerations

Enterprise deployments should follow governance policies.

These include:

  • Environment management
  • Connector governance
  • DLP policies
  • Identity management
  • Approval processes
  • Version control
  • Compliance requirements

Proper governance ensures that deployments remain secure and manageable over time.


Common Deployment Mistakes

Avoid these common mistakes:

  • Deploying directly to production without testing
  • Using production for development
  • Ignoring authentication requirements
  • Choosing channels unfamiliar to users
  • Failing to plan for scalability
  • Publishing without user acceptance testing
  • Ignoring governance policies
  • Deploying with excessive permissions
  • Not monitoring post-deployment performance

Best Practices

When planning channels and deployment:

  • Choose channels based on user needs and business scenarios.
  • Use Microsoft Teams for many internal employee solutions.
  • Use websites or mobile apps for customer-facing experiences.
  • Separate development, test, and production environments.
  • Implement a structured ALM process.
  • Use environment variables to simplify deployments.
  • Plan authentication before deployment.
  • Apply least-privilege security.
  • Monitor deployments continuously.
  • Plan for future scalability and expansion.

Exam Tips

For the AB-620 exam, remember the following:

  • A channel is where users interact with an AI agent.
  • Microsoft Teams is commonly used for internal employee-facing agents.
  • Websites and mobile applications are common channels for customer-facing agents.
  • Direct Line API enables integration into custom applications.
  • Separate development, test, and production environments.
  • Publishing makes updated agent versions available for deployment.
  • ALM includes version control, testing, deployment, and monitoring.
  • Environment variables simplify deployments across environments.
  • Authentication requirements often influence channel selection.
  • Governance and monitoring are essential components of deployment planning.

Practice Exam Questions

Question 1

A company wants employees to access an HR assistant without leaving their daily collaboration platform. Which deployment channel is the most appropriate?

A. Public website

B. Microsoft Teams

C. Direct Line API

D. Mobile banking application

Correct Answer: B

Explanation: Microsoft Teams is the preferred deployment channel for many internal employee-facing agents because employees already use Teams for daily collaboration and authentication is integrated with Microsoft Entra ID.


Question 2

Which deployment approach best supports safe testing before an AI agent is made available to production users?

A. Develop and publish directly to production

B. Use only a single production environment

C. Use separate development, test, and production environments

D. Allow users to test new features in production before validation

Correct Answer: C

Explanation: Separate environments allow developers to build, test, validate, and approve changes before they reach production users, reducing deployment risk.


Question 3

An organization wants to integrate a Copilot Studio agent into a custom-built enterprise application with its own user interface. Which deployment option is most appropriate?

A. Microsoft Teams

B. Microsoft 365 Copilot

C. Omnichannel for Customer Service

D. Direct Line API

Correct Answer: D

Explanation: The Direct Line API enables developers to embed Copilot Studio agents into custom applications while maintaining complete control over the user experience.


Question 4

Which factor should be considered first when selecting deployment channels for an AI agent?

A. The preferred programming language of the development team

B. The color scheme of the organization’s website

C. The storage size of the deployment package

D. The users who will interact with the agent and where they work

Correct Answer: D

Explanation: Channel selection should be driven by business requirements and user needs, including where users work and how they prefer to access the agent.


Question 5

What is the primary purpose of publishing an agent in Copilot Studio?

A. To permanently archive the current version

B. To enable the latest validated version for deployment to configured channels

C. To delete previous versions of the agent

D. To automatically create a backup of all enterprise systems

Correct Answer: B

Explanation: Publishing makes the latest approved version of the agent available for deployment and use through its configured channels.


Question 6

Which deployment scenario is most appropriate for a customer support chatbot available to anyone visiting a company’s public website?

A. Microsoft Teams deployment

B. Internal employee portal

C. Website deployment

D. Microsoft Outlook add-in

Correct Answer: C

Explanation: Public websites are commonly used for customer-facing AI agents that provide product information, FAQs, and customer support.


Question 7

Why are environment variables recommended when planning deployments across development, test, and production environments?

A. They eliminate the need for authentication.

B. They allow environment-specific settings, such as API endpoints, without modifying the agent.

C. They automatically publish new agent versions.

D. They replace version control systems.

Correct Answer: B

Explanation: Environment variables store configuration values that differ between environments, making deployments easier and reducing the need to modify application logic.


Question 8

Which activity is part of Application Lifecycle Management (ALM)?

A. Limiting conversations to one deployment channel

B. Removing authentication requirements

C. Disabling monitoring after deployment

D. Managing version control, testing, deployment, and updates

Correct Answer: D

Explanation: ALM encompasses the processes required to develop, test, deploy, maintain, and improve applications throughout their lifecycle.


Question 9

Which consideration is most important when selecting a deployment channel for an internal finance agent that accesses sensitive company information?

A. Entertainment features available on the platform

B. Number of emojis supported

C. Authentication, authorization, and enterprise security integration

D. The number of background themes available

Correct Answer: C

Explanation: Internal agents that access sensitive data must support strong authentication, authorization, and enterprise security controls to protect organizational information.


Question 10

After deploying an AI agent to production, which practice best supports continuous improvement?

A. Prevent users from submitting feedback.

B. Disable logging to improve performance.

C. Republish the agent every day regardless of changes.

D. Monitor usage, failures, user satisfaction, and performance metrics.

Correct Answer: D

Explanation: Monitoring production usage and operational metrics helps identify issues, measure adoption, optimize performance, and guide future enhancements to the agent.


Go to the AB-620 Exam Prep Hub main page

Plan identity strategy (AB-620 Exam Prep)

This post is a part of the AB-620: Designing and Building Integrated AI Agent Solutions in Copilot Studio Exam Prep Hub.
This topic falls under these sections:
Plan and configure agent solutions (30–35%)
   --> Plan an agent solution
      --> Plan identity strategy


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

One of the most important planning activities when designing an AI agent is determining how the agent and its users will be identified, authenticated, and authorized. An effective identity strategy ensures that agents securely access enterprise resources while protecting sensitive organizational data.

In Microsoft Copilot Studio, an identity strategy defines:

  • How users sign in
  • How the agent authenticates to external systems
  • What permissions users and agents receive
  • How identities are managed across enterprise applications
  • How security policies are enforced
  • How compliance requirements are met

Identity planning is closely related to security planning. Before integrating an agent with Microsoft 365, Dynamics 365, SharePoint, Azure AI Search, REST APIs, or other enterprise systems, architects must determine how identities will be established and trusted.

For the AB-620 exam, you should understand the principles of identity management, authentication methods, authorization models, Microsoft Entra ID, delegated versus application permissions, service principals, managed identities, and least-privilege access.


Why an Identity Strategy Is Important

Without a well-designed identity strategy, an AI agent could:

  • Access unauthorized information
  • Perform actions it should not perform
  • Expose sensitive data
  • Violate compliance requirements
  • Create security vulnerabilities
  • Fail to authenticate with enterprise systems

A properly planned identity strategy ensures:

  • Secure user authentication
  • Secure system authentication
  • Appropriate authorization
  • Protection of enterprise resources
  • Regulatory compliance
  • Consistent user experiences

Identity should be planned before any integrations are implemented.


Key Identity Concepts

Understanding several core identity concepts is essential.

Identity

An identity represents a person, application, service, or device.

Examples include:

  • Employee
  • Customer
  • Administrator
  • AI agent
  • Service account
  • Application

Every identity has unique characteristics that distinguish it from others.


Authentication

Authentication answers the question:

Who are you?

Authentication verifies the identity of a user or application before granting access.

Common authentication methods include:

  • Username and password
  • Multi-factor authentication (MFA)
  • OAuth 2.0
  • OpenID Connect
  • Microsoft Entra ID sign-in
  • Certificate-based authentication

Successful authentication establishes trust.


Authorization

Authorization answers the question:

What are you allowed to do?

After authentication, authorization determines which resources the identity can access.

Examples:

  • View customer records
  • Create support tickets
  • Modify invoices
  • Delete files
  • Approve purchase requests

Authentication occurs first; authorization occurs second.


Microsoft Entra ID

Microsoft Entra ID (formerly Azure Active Directory) is Microsoft’s cloud-based identity and access management service.

It provides:

  • User authentication
  • Single Sign-On (SSO)
  • Conditional Access
  • Identity governance
  • Application registration
  • OAuth authorization
  • Enterprise identity management

Most enterprise Copilot Studio solutions use Microsoft Entra ID as their identity provider.


Single Sign-On (SSO)

Single Sign-On allows users to authenticate once and access multiple applications without repeatedly entering credentials.

Benefits include:

  • Better user experience
  • Reduced password fatigue
  • Improved security
  • Simplified administration

Example:

A user signs into Microsoft 365 and can then access a Copilot Studio agent, SharePoint, Outlook, and Dynamics 365 without additional sign-ins.


Multi-Factor Authentication (MFA)

MFA requires users to provide two or more forms of verification.

Examples include:

  • Password
  • Mobile authentication app
  • Text message
  • Hardware token
  • Biometric verification

MFA significantly reduces the risk of compromised credentials.

Organizations commonly require MFA for AI agents accessing sensitive business systems.


Delegated Permissions

Delegated permissions allow an application or agent to perform actions on behalf of a signed-in user.

The agent can only perform actions that the user is already authorized to perform.

Example:

An employee asks:

“Show me my support tickets.”

The agent retrieves only that employee’s tickets because it uses the employee’s delegated permissions.

Advantages:

  • User-specific security
  • Respects existing permissions
  • Simplifies auditing

Application Permissions

Application permissions allow an application to access resources independently of a signed-in user.

The application acts using its own identity.

Example:

A scheduled AI process updates inventory overnight.

No user is signed in.

The application authenticates using its own credentials.

Application permissions are common for background services and automation.


Service Principals

A service principal is the security identity created for an application within Microsoft Entra ID.

Rather than using a user account, applications authenticate using their own service principal.

Benefits include:

  • Secure application identity
  • Better auditing
  • Easier permission management
  • Reduced reliance on user accounts

Many enterprise integrations use service principals.


Managed Identities

Managed identities provide Azure services with automatically managed identities in Microsoft Entra ID.

Advantages include:

  • No password management
  • No stored credentials
  • Automatic credential rotation
  • Simplified security

Managed identities are recommended for Azure-hosted services whenever supported.


OAuth 2.0

OAuth 2.0 is the primary authorization framework used by many Microsoft services and external APIs.

Rather than sharing passwords, OAuth issues access tokens.

Typical OAuth flow:

  1. User signs in.
  2. Identity provider authenticates the user.
  3. An access token is issued.
  4. The agent presents the token to the target service.
  5. The service validates the token and authorizes access.

OAuth improves security by avoiding direct password sharing.


Access Tokens

An access token is a temporary credential issued after successful authentication.

Tokens contain information such as:

  • User identity
  • Application identity
  • Granted permissions (scopes)
  • Expiration time

Because tokens expire, they reduce the risk associated with stolen credentials.


Identity Providers

An identity provider (IdP) authenticates users and applications.

Examples include:

  • Microsoft Entra ID
  • Active Directory Federation Services (AD FS)
  • External OAuth providers
  • OpenID Connect providers

The identity provider establishes trust between the user and enterprise applications.


Planning Authentication for Enterprise Integrations

Every enterprise integration requires an authentication strategy.

Examples:

SystemTypical Authentication Method
Microsoft 365Microsoft Entra ID
Dynamics 365Microsoft Entra ID
SharePointMicrosoft Entra ID
Azure AI SearchMicrosoft Entra ID or API key
REST APIsOAuth, API key, or certificate
Custom applicationsOAuth or custom authentication

Architects should choose authentication methods supported by both Copilot Studio and the target system.


API Keys

Some external systems authenticate using API keys.

Advantages:

  • Simple implementation
  • Common with third-party APIs

Disadvantages:

  • Harder to rotate securely
  • Less granular permissions
  • Must be protected carefully

Whenever possible, OAuth is generally preferred over API keys because it provides stronger security and more flexible authorization.


Conditional Access

Conditional Access allows organizations to apply security policies based on specific conditions.

Policies may evaluate:

  • User identity
  • Device compliance
  • Geographic location
  • Risk level
  • Application
  • Network location

Examples:

  • Require MFA outside the corporate network.
  • Block access from high-risk countries.
  • Require managed devices for sensitive applications.

Conditional Access enhances security without changing application logic.


Least Privilege Principle

One of the most important identity planning principles is least privilege.

Grant only the permissions necessary to perform required tasks.

For example:

Instead of allowing an agent to modify every customer record, grant permission only to update support case statuses if that is all the agent requires.

Benefits include:

  • Reduced attack surface
  • Lower risk of accidental changes
  • Improved compliance
  • Easier auditing

Role-Based Access Control (RBAC)

RBAC assigns permissions based on roles instead of individual users.

Examples of roles:

  • Sales Representative
  • HR Manager
  • Finance Administrator
  • Customer Service Agent

The AI agent inherits permissions associated with the user’s assigned role.

RBAC simplifies administration and supports consistent security.


Identity for Multi-Agent Solutions

In multi-agent architectures, each agent may have its own identity and permissions.

Example:

  • HR agent accesses HR systems only.
  • Finance agent accesses accounting systems only.
  • IT agent accesses service management systems only.

Separating identities improves:

  • Security
  • Auditing
  • Governance
  • Maintainability

Avoid using one highly privileged identity for every agent.


Identity and Enterprise Knowledge

When agents retrieve enterprise knowledge from sources such as SharePoint or Azure AI Search, identity determines which documents users can access.

For example:

An HR employee may see personnel policies, while a sales employee sees only sales documentation.

Identity-aware retrieval helps ensure that users receive only the information they are authorized to access.


Compliance Considerations

Identity strategies often support compliance with organizational and regulatory requirements.

Examples include:

  • Audit logging
  • User accountability
  • Access reviews
  • Data protection
  • Separation of duties
  • Identity governance

Strong identity management helps organizations satisfy security and compliance standards.


Common Identity Planning Mistakes

Avoid these common mistakes:

  • Using shared user accounts for applications
  • Granting excessive permissions
  • Ignoring MFA requirements
  • Hardcoding credentials in applications
  • Failing to rotate API keys
  • Choosing application permissions when delegated permissions are sufficient
  • Forgetting Conditional Access requirements
  • Not documenting identity architecture
  • Giving every agent identical permissions

Best Practices

When planning an identity strategy:

  • Use Microsoft Entra ID whenever possible.
  • Enable Single Sign-On for a seamless user experience.
  • Require Multi-Factor Authentication for sensitive resources.
  • Prefer delegated permissions for user-driven interactions.
  • Use application permissions only when necessary.
  • Use managed identities for Azure-hosted services.
  • Apply the principle of least privilege.
  • Implement Role-Based Access Control.
  • Use OAuth instead of API keys whenever supported.
  • Separate identities for different agents and services.
  • Monitor authentication failures and access logs regularly.

Exam Tips

For the AB-620 exam, remember these key points:

  • Authentication verifies identity; authorization determines permissions.
  • Microsoft Entra ID is the primary identity provider for Microsoft cloud services.
  • Single Sign-On improves both usability and security.
  • MFA adds an additional layer of protection.
  • Delegated permissions operate on behalf of a signed-in user.
  • Application permissions allow applications to act independently.
  • Managed identities eliminate the need to manage credentials for Azure services.
  • Service principals represent applications in Microsoft Entra ID.
  • OAuth is generally preferred over API keys.
  • Always apply the principle of least privilege.

Practice Exam Questions

Question 1

A company wants its AI agent to access Microsoft 365 resources using the identity of the signed-in employee. Which permission model should be used?

A. Application permissions

B. Delegated permissions

C. Anonymous access

D. API key authentication

Correct Answer: B

Explanation: Delegated permissions allow the AI agent to perform actions on behalf of the signed-in user and respect that user’s existing permissions.


Question 2

What is the primary purpose of authentication?

A. Determine which resources a user can modify

B. Encrypt all enterprise data

C. Verify the identity of a user or application

D. Record audit logs

Correct Answer: C

Explanation: Authentication establishes who the user or application is before access decisions are made. Authorization determines what the authenticated identity can access.


Question 3

An Azure-hosted service needs to authenticate to Azure resources without storing passwords or secrets. Which identity solution is recommended?

A. Managed identity

B. API key

C. Shared service account

D. Username and password

Correct Answer: A

Explanation: Managed identities automatically manage credentials for Azure services, eliminating the need to store or rotate secrets.


Question 4

Which Microsoft service is the primary identity provider for Microsoft cloud applications and Copilot Studio integrations?

A. Azure AI Search

B. Microsoft Defender for Cloud

C. Microsoft Dataverse

D. Microsoft Entra ID

Correct Answer: D

Explanation: Microsoft Entra ID provides authentication, authorization, Single Sign-On, Conditional Access, and identity management for Microsoft cloud services.


Question 5

A background process updates inventory records every night without any user interaction. Which permission model is most appropriate?

A. Delegated permissions

B. Anonymous authentication

C. Application permissions

D. Guest user permissions

Correct Answer: C

Explanation: Application permissions allow applications to operate independently of a signed-in user, making them appropriate for scheduled or automated processes.


Question 6

Which security principle recommends granting only the permissions required to perform a specific task?

A. Defense in depth

B. Separation of duties

C. Zero Trust

D. Least privilege

Correct Answer: D

Explanation: The principle of least privilege minimizes security risks by limiting permissions to only those necessary for the required operations.


Question 7

Which authentication mechanism is generally preferred over API keys because it provides temporary access tokens and granular authorization?

A. Basic Authentication

B. OAuth 2.0

C. NTLM

D. Windows Authentication

Correct Answer: B

Explanation: OAuth 2.0 issues temporary access tokens instead of sharing passwords and supports fine-grained authorization scopes.


Question 8

What is the primary benefit of Single Sign-On (SSO)?

A. It permanently stores user credentials in every application.

B. It replaces authorization policies.

C. It allows users to authenticate once and access multiple trusted applications.

D. It eliminates the need for user identities.

Correct Answer: C

Explanation: Single Sign-On improves user experience and security by allowing one authentication session to provide access to multiple authorized applications.


Question 9

What is the purpose of a service principal in Microsoft Entra ID?

A. It represents an application or service as a security identity.

B. It stores enterprise knowledge for AI agents.

C. It replaces Conditional Access policies.

D. It creates Power Automate workflows.

Correct Answer: A

Explanation: A service principal is the identity used by an application or service to authenticate and access resources securely in Microsoft Entra ID.


Question 10

An organization requires users connecting from unmanaged devices to complete additional verification before accessing sensitive AI agents. Which capability addresses this requirement?

A. Role-Based Access Control

B. Managed identities

C. Conditional Access

D. Delegated permissions

Correct Answer: C

Explanation: Conditional Access evaluates conditions such as device compliance, location, and risk level to enforce security requirements like Multi-Factor Authentication before granting access.


Go to the AB-620 Exam Prep Hub main page

Monitor agents, including usage, operational insights, and agent lifecycle, by working with the Microsoft 365 Admin Center and the Microsoft Power Platform Admin Center (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for agents
      --> Monitor agents, including usage, operational insights, and agent lifecycle, by working with the Microsoft 365 Admin Center and the Microsoft Power Platform Admin Center


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

As organizations deploy more Microsoft 365 Copilot agents, effective administration extends beyond simply creating and publishing them. Administrators must continuously monitor agent usage, operational health, adoption, security, and lifecycle to ensure that agents continue to provide business value while meeting organizational governance and compliance requirements.

Microsoft provides two primary administrative portals for monitoring and managing agents:

  • Microsoft 365 admin center
  • Microsoft Power Platform admin center

Each portal serves a different purpose. The Microsoft 365 admin center focuses on Microsoft 365 services, Copilot adoption, licensing, and organizational administration, while the Power Platform admin center focuses on environments, Copilot Studio, Power Platform resources, and operational management of custom agents.

For the AB-900 exam, you should understand which portal is used for which administrative tasks, the types of monitoring information available, and the basic lifecycle of an agent.


Why Monitoring Agents Is Important

Monitoring helps administrators answer questions such as:

  • Are users actually using the agent?
  • Is the agent providing business value?
  • Are there operational issues?
  • Is adoption increasing?
  • Are users encountering errors?
  • Should the agent be updated or retired?
  • Are governance policies being followed?

Without monitoring, organizations cannot determine whether their AI investments are successful.


Administrative Portals

Microsoft 365 Admin Center

The Microsoft 365 admin center provides organization-wide administration for Microsoft 365 services, including Copilot.

Administrators commonly use it to:

  • View Copilot adoption
  • Monitor Copilot usage
  • Assign licenses
  • Manage users
  • Manage billing
  • View service health
  • Review reports
  • Monitor tenant-wide administration

It provides a business-level view of how Microsoft 365 Copilot is being used across the organization.


Microsoft Power Platform Admin Center

The Power Platform admin center focuses on the operational management of Power Platform resources, including custom agents created with Copilot Studio.

Administrators use it to:

  • Manage environments
  • Monitor agent health
  • Manage Dataverse resources
  • Review capacity
  • Configure security
  • Manage connectors
  • Review operational information
  • Manage Power Platform policies

It provides technical administration for custom AI solutions.


Monitoring Agent Usage

Usage monitoring helps organizations understand adoption.

Common usage metrics include:

  • Number of users
  • Active users
  • Conversations
  • Sessions
  • Frequency of use
  • Popular agents
  • Usage trends over time

These metrics help determine whether users are benefiting from the deployed agents.


Usage Scenarios

An administrator might monitor:

  • Daily active users
  • Weekly adoption growth
  • Monthly conversation counts
  • Frequently used agents
  • Least-used agents

Low adoption may indicate:

  • Lack of awareness
  • Poor training
  • Limited usefulness
  • Difficult user experience

Operational Insights

Operational insights help administrators understand how agents are performing.

Examples include:

  • Agent availability
  • Service status
  • Response success
  • Failed requests
  • Processing errors
  • Environment health
  • Connector status
  • Workflow execution

Operational monitoring focuses on technical performance rather than business adoption.


Examples of Operational Issues

Administrators may investigate:

  • Failed API connections
  • Broken Power Automate flows
  • Authentication failures
  • Connector problems
  • Environment capacity limits
  • Dataverse issues

Identifying these issues early minimizes disruption for users.


Monitoring Agent Lifecycle

Every agent follows a lifecycle from creation to retirement.

Typical lifecycle stages include:

  1. Planning
  2. Design
  3. Development
  4. Testing
  5. Approval
  6. Publishing
  7. Monitoring
  8. Updating
  9. Republishing
  10. Retirement

Administrators monitor agents throughout this lifecycle.


Lifecycle Management Activities

During an agent’s lifecycle, administrators may:

  • Update instructions
  • Improve prompts
  • Add new knowledge sources
  • Remove outdated content
  • Modify connectors
  • Improve security
  • Publish new versions
  • Disable obsolete agents
  • Archive retired agents

Lifecycle management is an ongoing process rather than a one-time task.


Adoption Monitoring

One important responsibility is measuring adoption.

Organizations often monitor:

  • Licensed users
  • Active users
  • Usage growth
  • Conversation volume
  • Department adoption
  • Business impact

High adoption generally indicates that users find the agent valuable.


Performance Monitoring

Performance monitoring focuses on the quality of the user experience.

Administrators may evaluate:

  • Response times
  • Reliability
  • Availability
  • Error rates
  • Successful interactions
  • Failed interactions

Consistent performance builds user confidence in AI solutions.


Security Monitoring

Monitoring also includes security.

Administrators watch for:

  • Unauthorized access
  • Permission issues
  • Authentication failures
  • Suspicious activity
  • Compliance alerts
  • Data access concerns

Security monitoring helps ensure that agents continue to comply with organizational policies.


Governance Monitoring

Governance activities include monitoring:

  • Approved agents
  • Published agents
  • Ownership
  • Data sources
  • Permissions
  • Connector usage
  • Compliance policies

Organizations should periodically review whether agents still meet governance requirements.


Environment Monitoring

The Power Platform admin center allows administrators to monitor environments that host agents.

Typical information includes:

  • Environment health
  • Capacity usage
  • Storage
  • Dataverse utilization
  • Resource allocation

Healthy environments help ensure reliable agent performance.


Monitoring Connectors

Many agents rely on connectors to access business systems.

Administrators may monitor:

  • Connector availability
  • Authentication status
  • Connection errors
  • Connector permissions
  • External system connectivity

Problems with connectors often result in incomplete or failed agent responses.


Monitoring User Feedback

Organizations should also gather user feedback.

Useful indicators include:

  • User satisfaction
  • Reported issues
  • Feature requests
  • Accuracy concerns
  • Suggested improvements

Feedback helps guide future improvements to the agent.


Retirement of Agents

Not every agent remains useful forever.

Administrators may retire agents when:

  • Business needs change.
  • New agents replace older versions.
  • Information becomes outdated.
  • Security risks increase.
  • Adoption declines significantly.

Retired agents should be archived or removed according to organizational governance policies.


Best Practices

Organizations should:

  • Monitor usage regularly.
  • Review adoption reports.
  • Monitor operational health.
  • Investigate errors promptly.
  • Review security frequently.
  • Track lifecycle status.
  • Keep documentation current.
  • Update agents regularly.
  • Remove obsolete agents.
  • Use both Microsoft 365 and Power Platform administration tools appropriately.

Microsoft 365 Admin Center vs. Power Platform Admin Center

Microsoft 365 Admin CenterPower Platform Admin Center
User administrationEnvironment administration
License managementDataverse management
Copilot adoptionAgent operations
Usage reportingEnvironment health
BillingConnector management
Service healthCapacity monitoring
Organization-wide administrationPower Platform governance
Copilot reportsOperational insights

Exam Tips

For the AB-900 exam, remember these key points:

  • The Microsoft 365 admin center focuses on Microsoft 365 administration, licensing, Copilot usage, adoption, and organizational reporting.
  • The Power Platform admin center focuses on operational management of custom agents, environments, connectors, Dataverse, and Power Platform resources.
  • Usage monitoring measures adoption and business value.
  • Operational insights focus on technical health and performance.
  • Agents should be monitored throughout their entire lifecycle.
  • Administrators should regularly review performance, governance, and security after an agent is deployed.

Practice Exam Questions

Question 1

Which administrative portal is primarily used to monitor Microsoft 365 Copilot adoption and licensing?

A. Microsoft 365 admin center

B. Microsoft Defender portal

C. Azure Portal

D. Microsoft Purview portal

Answer: A

Explanation: The Microsoft 365 admin center provides organization-wide administration, including Copilot licensing, adoption reports, and usage monitoring.


Question 2

What is the primary purpose of monitoring agent usage?

A. To increase internet bandwidth

B. To determine adoption and business value

C. To install software updates

D. To configure SharePoint permissions

Answer: B

Explanation: Usage metrics help organizations understand whether agents are delivering value and being actively used.


Question 3

Which portal is primarily responsible for monitoring environments, connectors, and Dataverse resources for custom agents?

A. Microsoft Entra admin center

B. Microsoft Purview portal

C. Microsoft Power Platform admin center

D. Exchange admin center

Answer: C

Explanation: The Power Platform admin center manages environments, Dataverse, connectors, capacity, and operational aspects of custom agents.


Question 4

Which metric best represents agent adoption?

A. CPU utilization

B. Network latency

C. Number of active users

D. Available storage space

Answer: C

Explanation: Active users are a key indicator of how widely an agent is being adopted.


Question 5

Which activity is part of an agent’s lifecycle after publication?

A. Ongoing monitoring and updates

B. Automatic deletion

C. Disabling Microsoft 365

D. Removing all connectors

Answer: A

Explanation: Administrators continuously monitor, update, and improve agents after they are deployed.


Question 6

Which of the following is considered an operational insight?

A. Number of licensed users

B. Employee vacation requests

C. Failed connector authentication

D. SharePoint storage quota purchase

Answer: C

Explanation: Operational insights include technical issues such as connector failures, authentication problems, and service errors.


Question 7

Why should administrators monitor agent performance?

A. To increase hardware prices

B. To ensure reliable responses and a positive user experience

C. To disable audit logs

D. To reduce Microsoft 365 storage

Answer: B

Explanation: Performance monitoring helps ensure agents remain reliable, responsive, and useful.


Question 8

Which administrative activity helps identify agents that are no longer providing business value?

A. Monitoring adoption trends

B. Updating Windows drivers

C. Installing Office applications

D. Configuring printers

Answer: A

Explanation: Declining adoption trends may indicate that an agent should be improved or retired.


Question 9

What should administrators monitor to help identify security concerns related to agents?

A. Desktop wallpaper settings

B. Keyboard layouts

C. Unauthorized access attempts and permission issues

D. Browser home pages

Answer: C

Explanation: Monitoring permissions, authentication failures, and unauthorized access helps maintain security.


Question 10

Which statement best describes the relationship between the Microsoft 365 admin center and the Microsoft Power Platform admin center?

A. Both portals perform exactly the same administrative functions.

B. The Microsoft 365 admin center is used only for Exchange Online.

C. The Power Platform admin center replaces the Microsoft 365 admin center for all administration.

D. The Microsoft 365 admin center focuses on organizational Microsoft 365 administration and Copilot usage, while the Power Platform admin center focuses on environments and operational management of custom agents.

Answer: D

Explanation: The two portals complement one another. The Microsoft 365 admin center provides tenant-wide administration, licensing, and adoption reporting, while the Power Platform admin center provides operational management of environments, connectors, Dataverse resources, and custom agents built with Copilot Studio.


Go to the AB-900 Exam Prep Hub main page

Understand the approval process for agents (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for agents
      --> Understand the approval process for agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

As organizations increasingly adopt Microsoft 365 Copilot and AI-powered agents, governance becomes just as important as functionality. Without proper oversight, users could inadvertently create agents that expose sensitive information, perform unintended actions, or fail to comply with organizational policies.

For this reason, Microsoft provides an approval process that enables organizations to review, validate, and govern agents before they are made available to users. While the exact approval workflow depends on the type of agent, the organization’s governance policies, and the deployment platform (such as Microsoft Copilot Studio), administrators should understand how approval processes help ensure that agents are secure, compliant, and aligned with business requirements.

For the AB-900 exam, you are not expected to know every detailed configuration step, but you should understand why approvals exist, when they are required, who participates in the approval process, and what happens before and after an agent is approved.


Why Agent Approval is Important

Unlike general-purpose Microsoft 365 Copilot experiences, custom agents often:

  • Access organizational knowledge
  • Connect to business systems
  • Trigger automated workflows
  • Perform business-specific tasks
  • Use sensitive organizational data

Because of these capabilities, organizations typically require an approval process before an agent is published to production.

Approval helps ensure that:

  • The agent performs its intended function.
  • Security requirements are met.
  • Compliance policies are followed.
  • Data access is appropriate.
  • Users receive a trustworthy AI experience.

Goals of the Approval Process

An effective approval process helps organizations:

  • Reduce security risks
  • Prevent accidental oversharing
  • Ensure regulatory compliance
  • Improve quality of AI responses
  • Validate business usefulness
  • Maintain organizational standards
  • Establish accountability

Typical Agent Lifecycle

A simplified lifecycle includes:

  1. Design
  2. Build
  3. Configure
  4. Test
  5. Review
  6. Approve
  7. Publish
  8. Monitor
  9. Update
  10. Retire

Approval occurs after testing but before broad deployment.


Typical Approval Workflow

Although every organization may customize the workflow, the process generally follows these steps.

Step 1: Agent Creation

A developer or business user creates the agent.

They configure:

  • Instructions
  • Knowledge sources
  • Actions
  • Connectors
  • Conversation flow

Step 2: Initial Testing

Before requesting approval, the creator tests the agent.

Typical testing includes:

  • Prompt accuracy
  • Correct responses
  • Hallucination reduction
  • Data grounding
  • Error handling
  • Business logic

Step 3: Security Review

Security administrators verify that:

  • Permissions are appropriate.
  • Data sources are approved.
  • Authentication is configured correctly.
  • Sensitive information is protected.
  • Least-privilege access is maintained.

Step 4: Compliance Review

Compliance teams evaluate whether the agent aligns with organizational governance policies.

Areas reviewed include:

  • Data Loss Prevention (DLP)
  • Sensitivity labels
  • Microsoft Purview policies
  • Data retention
  • Regulatory requirements
  • Audit logging

Step 5: Business Review

Business owners determine whether:

  • The agent solves the intended problem.
  • Responses are accurate.
  • Business terminology is correct.
  • Processes are followed correctly.
  • Users will benefit from the solution.

Step 6: Approval

Once reviews are complete, the designated approver authorizes publication.

Only approved agents should become available to end users.


Step 7: Publishing

After approval, the agent can be:

  • Published
  • Assigned to users
  • Shared with groups
  • Made available in Microsoft Teams
  • Integrated into Microsoft 365 Copilot

Who May Participate in the Approval Process?

Several roles may be involved depending on the organization.

Agent Creator

Responsible for:

  • Designing the agent
  • Testing functionality
  • Fixing issues
  • Submitting for review

Business Owner

Responsible for:

  • Verifying business value
  • Confirming correct business logic
  • Approving organizational use

IT Administrator

Responsible for:

  • Platform administration
  • Environment configuration
  • Deployment
  • User access

Security Administrator

Responsible for:

  • Permission validation
  • Identity verification
  • Connector review
  • Security assessment

Compliance Administrator

Responsible for:

  • Governance policies
  • Data protection
  • Microsoft Purview compliance
  • Regulatory alignment

What is Reviewed During Approval?

Reviewers typically examine:

Purpose

Does the agent solve a legitimate business problem?


Instructions

Are system instructions clear?

Do they prevent inappropriate behavior?


Knowledge Sources

Are approved sources used?

Examples include:

  • SharePoint
  • Microsoft Graph
  • Dataverse
  • Internal documentation

Actions

Can the agent:

  • Send emails?
  • Update records?
  • Trigger workflows?
  • Access external systems?

Higher-risk actions usually require more careful review.


Permissions

Does the agent only access information users are already authorized to see?

Microsoft 365 security trimming should remain intact.


Connectors

Reviewers verify that external connectors:

  • Are trusted
  • Are approved
  • Meet organizational policies

Privacy

Organizations verify that:

  • Personal data is protected.
  • Confidential information is handled appropriately.
  • AI responses do not expose sensitive content.

Governance During Approval

Agent approval is part of broader AI governance.

Organizations often require:

  • Data classification
  • Sensitivity labels
  • DLP policies
  • Audit logs
  • Risk assessments
  • Periodic reviews

These controls help ensure responsible AI deployment.


Approval vs Publishing

These concepts are different.

Approval means the organization authorizes the agent for deployment.

Publishing makes the approved agent available to users.

An approved agent is not necessarily published immediately.

Likewise, a draft agent cannot be published without completing required approvals (if organizational policies require them).


What Happens After Approval?

Approval is not the end of governance.

Administrators continue to monitor:

  • Usage
  • Adoption
  • Errors
  • User feedback
  • Performance
  • Security events
  • Compliance alerts

Agents may later be:

  • Updated
  • Republished
  • Disabled
  • Archived
  • Deleted

Best Practices

Organizations should:

  • Define a formal approval workflow.
  • Require business ownership.
  • Review data access carefully.
  • Test before publishing.
  • Limit permissions using least privilege.
  • Monitor production usage.
  • Periodically review existing agents.
  • Remove unused or outdated agents.
  • Maintain documentation for governance and auditing.

Exam Tips

For the AB-900 exam, remember these key points:

  • Approval helps ensure agents are secure, compliant, and useful before deployment.
  • Multiple stakeholders—including creators, business owners, IT administrators, security administrators, and compliance administrators—may participate in the approval process.
  • Testing occurs before approval.
  • Publishing occurs after approval.
  • Organizations can customize approval workflows based on governance requirements.
  • Security, permissions, data access, compliance, and business value are common review areas.
  • Agent governance continues after publication through ongoing monitoring and management.

Practice Exam Questions

Question 1

Why do organizations typically require an approval process before publishing custom agents?

A. To reduce deployment speed

B. To ensure the agent meets security, compliance, and business requirements

C. To prevent Microsoft 365 licensing

D. To disable Microsoft Graph access

Answer: B

Explanation: Approval ensures agents are reviewed for security, compliance, data access, and business value before being made available to users.


Question 2

Which activity normally occurs immediately before an agent is submitted for approval?

A. Assigning licenses

B. Deleting old agents

C. Testing the agent

D. Archiving the environment

Answer: C

Explanation: Creators typically validate the agent through testing before requesting formal approval.


Question 3

Which team is primarily responsible for reviewing whether an agent complies with data governance requirements?

A. Marketing

B. Finance

C. Human Resources

D. Compliance administrators

Answer: D

Explanation: Compliance administrators review governance policies, regulatory requirements, data protection, and Microsoft Purview controls.


Question 4

Which aspect is most likely reviewed during an agent approval process?

A. The color theme of Microsoft Teams

B. The Windows desktop wallpaper

C. The user’s internet browser

D. The agent’s permissions and data sources

Answer: D

Explanation: Reviewers verify that permissions and knowledge sources comply with organizational security policies.


Question 5

What is the primary purpose of reviewing an agent’s knowledge sources?

A. To increase processor speed

B. To ensure the agent uses approved organizational information

C. To update Windows

D. To install Microsoft Office

Answer: B

Explanation: Approved knowledge sources help ensure accurate responses while protecting sensitive information.


Question 6

Which statement correctly describes approval and publishing?

A. Publishing always occurs before approval.

B. Approval and publishing are identical.

C. Approval authorizes deployment, while publishing makes the agent available to users.

D. Approval permanently locks the agent.

Answer: C

Explanation: Approval authorizes the agent for release, while publishing distributes it to its intended audience.


Question 7

Who is primarily responsible for confirming that an agent solves the intended business problem?

A. Business owner

B. Printer administrator

C. Network technician

D. Database operator

Answer: A

Explanation: Business owners validate that the agent provides value and meets organizational objectives.


Question 8

Which security principle should agents follow when accessing organizational information?

A. Unlimited access

B. Anonymous authentication

C. Guest-only permissions

D. Least privilege

Answer: D

Explanation: Agents should only access the information necessary for their intended function, following the principle of least privilege.


Question 9

After an agent has been approved and published, what should administrators continue to do?

A. Disable audit logging

B. Ignore user feedback

C. Monitor usage, performance, and compliance

D. Remove all permissions

Answer: C

Explanation: Ongoing monitoring helps ensure the agent remains secure, compliant, and effective as business needs evolve.


Question 10

Which statement best describes organizational approval workflows for agents?

A. Every Microsoft 365 tenant uses the exact same approval process.

B. Approval is optional for all organizations.

C. Approval workflows are fixed and cannot be customized.

D. Organizations can customize approval workflows to meet their governance requirements.

Answer: D

Explanation: Microsoft provides flexible governance capabilities, allowing organizations to implement approval workflows that align with their security, compliance, and operational policies.


Go to the AB-900 Exam Prep Hub main page

Create an agent (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for agents
      --> Create an agent


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

(Microsoft 365 Copilot & Agent Administration Fundamentals)

Agents in the Microsoft 365 Copilot ecosystem are AI-powered assistants that extend Copilot’s capabilities by focusing on specific tasks, organizational knowledge, or business processes. Creating an agent involves defining its purpose, selecting its data sources, configuring its behavior, and publishing it so users can interact with it securely within Microsoft 365 apps.

This topic is central to understanding how administrators and power users enable tailored AI experiences using tools such as Microsoft Copilot Studio and the broader Microsoft 365 ecosystem.


1. What an agent is in Microsoft 365

An agent is a configurable AI experience built on top of Microsoft Copilot that can:

  • Answer domain-specific questions (HR, IT, finance, etc.)
  • Perform guided tasks (ticket creation, policy lookup, onboarding steps)
  • Use organizational data securely (SharePoint, Microsoft Graph, Dataverse)
  • Follow defined instructions and guardrails

Agents can be:

  • Declarative agents (configured with minimal or no-code settings)
  • Custom agents (built and extended in Copilot Studio)
  • Embedded agents (used within apps like Teams or Microsoft 365 Copilot experiences)

2. Where agents are created

Agents can be created in several Microsoft 365-aligned environments:

a. Copilot Studio

The primary tool for building and customizing agents.

Key capabilities:

  • Define agent purpose and instructions
  • Connect knowledge sources
  • Add actions (Power Automate, APIs)
  • Test and publish agents

b. Microsoft 365 Copilot experience

Admins can enable or manage prebuilt or organizational agents that appear in Copilot surfaces.

c. Power Platform environment (under the hood)

Agents often rely on Power Platform components such as:

  • Dataverse
  • Connectors
  • Power Automate flows

3. Prerequisites for creating an agent

Before creating an agent, ensure:

  • Appropriate licensing (Copilot and/or Copilot Studio access)
  • Permissions in the Power Platform environment
  • Access to organizational data sources (e.g., SharePoint sites)
  • Governance policies configured in Microsoft Purview

4. Key steps to create an agent

Step 1: Define the agent purpose

  • Identify the business scenario
  • Determine scope (e.g., HR helpdesk, IT support, sales assistant)

Step 2: Configure instructions

  • Provide system-level behavior guidance
  • Define tone, boundaries, and response rules
  • Specify what the agent should NOT do (important for compliance)

Step 3: Add knowledge sources

Common sources include:

  • SharePoint sites
  • Microsoft Graph data
  • Uploaded documents
  • Structured data (Dataverse tables)

Step 4: Add actions (optional)

Actions extend agent capability:

  • Create tickets in service systems
  • Trigger workflows via Power Automate
  • Query external APIs

Step 5: Test the agent

  • Validate responses in Copilot Studio test environment
  • Check grounding accuracy and hallucination risk
  • Adjust prompts or data sources

Step 6: Publish and share

  • Publish to organizational catalog
  • Assign user or group access
  • Make available in Microsoft 365 Copilot or Teams

5. Governance and control considerations

When creating agents, administrators must ensure:

  • Data access aligns with Microsoft 365 security policies
  • Sensitive data is protected using Purview labels and DLP rules
  • Only authorized users can access specific agents
  • Activity is monitored through Microsoft 365 admin and compliance tools

Agents inherit security trimming, meaning users only see data they already have permission to access.


6. Common exam focus points

You should understand:

  • Difference between Copilot and custom agents
  • Role of Copilot Studio in agent creation
  • Data sources used by agents (SharePoint, Graph, connectors)
  • Publishing and access control methods
  • Governance and compliance alignment

Practice Exam Questions (10)

1. Which tool is primarily used to build and customize Microsoft 365 Copilot agents?

A. Microsoft Teams Admin Center
B. Copilot Studio
C. Microsoft Entra ID
D. SharePoint Admin Center

Answer: B
Copilot Studio is the primary platform for creating and configuring custom Copilot agents, including instructions, knowledge sources, and actions.


2. What is the primary purpose of defining instructions when creating an agent?

A. To assign licenses to users
B. To configure data retention policies
C. To control agent behavior and response style
D. To enable Power BI integration

Answer: C
Instructions define how the agent behaves, including tone, boundaries, and response rules.


3. Which data source is commonly used by agents for organizational knowledge?

A. Microsoft Paint files
B. SharePoint sites
C. Windows Registry
D. Local desktop folders

Answer: B
SharePoint is a primary structured knowledge source used by Copilot agents.


4. What is a key benefit of adding actions to an agent?

A. They replace Microsoft 365 licensing requirements
B. They allow agents to execute workflows and integrate systems
C. They disable security trimming
D. They remove the need for testing

Answer: B
Actions enable agents to perform tasks such as triggering Power Automate flows or calling APIs.


5. Which platform component is commonly used behind agent workflows?

A. Dataverse
B. Windows Defender Firewall
C. Internet Information Services (IIS)
D. Microsoft Paint

Answer: A
Dataverse is often used as part of the Power Platform foundation supporting agents.


6. What happens when an agent is published?

A. It becomes available to assigned users or groups
B. It deletes previous versions automatically
C. It disables Copilot globally
D. It removes SharePoint permissions

Answer: A
Publishing makes the agent available for consumption based on assigned access controls.


7. What principle ensures users only see data they are allowed to access through an agent?

A. Data duplication
B. Security trimming
C. Token caching
D. Load balancing

Answer: B
Security trimming ensures agents respect existing Microsoft 365 permissions.


8. Which Microsoft service helps enforce compliance for data used in agents?

A. Microsoft Purview
B. Microsoft Edge
C. Windows Update
D. Azure DevTest Labs

Answer: A
Microsoft Purview provides governance, labeling, and compliance controls for data used in AI systems.


9. What is the first recommended step when creating a new agent?

A. Publish the agent immediately
B. Define the agent’s purpose and scope
C. Assign users to the agent
D. Add external APIs

Answer: B
Defining purpose ensures the agent is scoped correctly before configuration begins.


10. Where can agents be made available to end users after creation?

A. Only in Power BI dashboards
B. Only in Outlook desktop client
C. Across Microsoft 365 Copilot and integrated apps like Teams
D. Only in Azure portal

Answer: C
Agents can be deployed across Microsoft 365 Copilot experiences and integrated apps such as Teams.


Go to the AB-900 Exam Prep Hub main page

Identify how to configure user access to agents (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for agents
      --> Identify how to configure user access to agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

In Microsoft 365 Copilot, agents are specialized AI assistants designed to perform focused tasks such as answering domain-specific questions, retrieving organizational knowledge, or executing workflows. Because agents can access organizational data and systems, controlling who can use them and under what conditions is a critical administrative responsibility.

Configuring user access ensures that the right users can interact with the right agents while maintaining security, compliance, and least-privilege principles.


1. What “agent access” means

User access to agents determines:

  • Which users can discover an agent
  • Which users can interact with or run an agent
  • Whether an agent is available organization-wide or restricted to specific groups
  • Whether external or guest users can use agents (if allowed)

Access is typically controlled through a combination of:

  • Microsoft 365 identity and access controls
  • Entra ID (Azure AD) group membership
  • Copilot and agent-specific policies

2. Key methods to configure access to agents

A. Assigning access via Microsoft Entra ID groups

One of the most common approaches is group-based access control.

Administrators can:

  • Assign an agent to specific security groups or Microsoft 365 groups
  • Restrict usage to departments (e.g., HR, Finance, IT)
  • Manage access at scale without assigning users individually

Benefits:

  • Scalable management
  • Easier onboarding/offboarding
  • Centralized governance

B. Tenant-wide vs scoped availability

Agents can be configured as:

1. Tenant-wide agents

  • Available to all licensed users in the organization
  • Used for general productivity scenarios (e.g., company policy assistant)

2. Scoped agents

  • Limited to specific users or groups
  • Used for sensitive or department-specific data (e.g., HR policy agent)

C. Role-based access control (RBAC)

Some agent administration actions require specific roles in Microsoft 365 or Entra ID:

  • Global Administrator
  • AI Administrator / Copilot Administrator
  • Service-specific admin roles

RBAC ensures:

  • Only authorized admins can publish or modify agents
  • Governance over agent deployment lifecycle

D. Conditional Access policies

Conditional Access can indirectly control agent usage by enforcing:

  • Device compliance requirements
  • Multi-factor authentication (MFA)
  • Location-based restrictions
  • Risk-based sign-in rules

This ensures that even if a user has access to an agent, they must meet security requirements before using it.


E. Application and permission scopes

Agents may require access to:

  • Microsoft 365 data (SharePoint, Outlook, Teams)
  • External connectors or APIs
  • Graph permissions

Administrators control:

  • What data the agent can access
  • Whether consent is required
  • Whether permissions are user-delegated or app-level

3. Lifecycle considerations for agent access

Provisioning

  • Define target audience (group or tenant-wide)
  • Assign initial permissions
  • Validate compliance requirements

Modification

  • Update group membership to change access
  • Adjust policies as organizational needs evolve

Deprovisioning

  • Remove users or groups when no longer needed
  • Disable or retire the agent if required
  • Ensure data access is revoked appropriately

4. Governance best practices

To securely manage agent access:

  • Use least privilege access (only necessary users/groups)
  • Prefer group-based assignment over individual assignment
  • Regularly review agent usage and permissions
  • Restrict sensitive agents to controlled departments
  • Monitor access logs for unusual activity
  • Align with Microsoft Purview policies where applicable

5. Common use cases

  • HR agent accessible only to HR staff
  • IT helpdesk agent available to all employees
  • Finance reporting agent restricted to finance team
  • Executive summary agent limited to leadership group

6. Key exam takeaway

For AB-900, remember:

  • Agent access is primarily controlled through Entra ID groups, roles, and policies
  • Access can be tenant-wide or scoped
  • Security is enforced through RBAC and Conditional Access
  • Governance ensures agents are only available to the appropriate users

Practice Exam Questions (10)

1.

What is the most common method used to manage user access to Microsoft 365 agents at scale?

A. Individual user assignment
B. Local device policies
C. Entra ID group-based assignment
D. DNS configuration

Answer: C
Explanation: Entra ID group-based assignment is the scalable and recommended way to manage agent access.


2.

Which configuration limits an agent to only HR department users?

A. Tenant-wide publishing
B. Scoped group assignment
C. Public sharing link
D. Guest user activation

Answer: B
Explanation: Scoped assignment using groups restricts access to specific departments like HR.


3.

Which role is typically required to manage Copilot or agent deployment settings?

A. SharePoint Site Owner
B. Global Administrator
C. Teams Guest User
D. Exchange Recipient User

Answer: B
Explanation: Global Administrators (or similar privileged roles) manage high-level agent deployment settings.


4.

What is the purpose of Conditional Access in relation to agent usage?

A. To increase storage capacity
B. To control data indexing speed
C. To enforce security requirements before access
D. To create new agents automatically

Answer: C
Explanation: Conditional Access ensures users meet security conditions like MFA or device compliance.


5.

What happens when a user is removed from an Entra ID group assigned to an agent?

A. They retain permanent access
B. Their access is automatically revoked
C. The agent is deleted
D. The entire tenant loses access

Answer: B
Explanation: Group membership changes immediately affect access to assigned resources, including agents.


6.

Which access model makes an agent available to all licensed users in a tenant?

A. Scoped access
B. Tenant-wide access
C. External sharing mode
D. Device-based access

Answer: B
Explanation: Tenant-wide access allows all licensed users to use the agent.


7.

Which control helps restrict what data an agent can access?

A. Network firewall rules
B. Permission scopes and Graph permissions
C. Printer access policies
D. Windows registry settings

Answer: B
Explanation: Permission scopes define what data and services an agent can access.


8.

What is a key benefit of using group-based access for agents?

A. It disables auditing
B. It simplifies scalable management
C. It removes the need for authentication
D. It bypasses licensing requirements

Answer: B
Explanation: Group-based access simplifies administration, especially in large organizations.


9.

Which scenario best describes proper agent governance?

A. All users can create unrestricted agents
B. Agents are available without authentication
C. Sensitive agents are limited to specific departments
D. Agents bypass compliance policies

Answer: C
Explanation: Sensitive agents should be restricted to appropriate departments for security and compliance.


10.

What is a recommended best practice when configuring access to agents?

A. Assign access individually to each user
B. Use least privilege access principles
C. Allow anonymous access by default
D. Disable group usage entirely

Answer: B
Explanation: Least privilege ensures users only get the access they need, improving security and governance.


Go to the AB-900 Exam Prep Hub main page

Identify use cases for custom agents (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Identify use cases for custom agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Custom agents in Microsoft 365 Copilot extend Copilot’s built-in capabilities by allowing organizations to create tailored AI assistants focused on specific business processes, data sources, and workflows. Unlike general Copilot experiences, custom agents are designed to operate within defined boundaries, grounded in organizational knowledge and governed data.

What are custom agents?

A custom agent is a specialized AI assistant built on top of Microsoft 365 Copilot that can:

  • Use organization-specific knowledge sources (SharePoint sites, files, Dataverse, web connectors, etc.)
  • Follow predefined instructions and behaviors
  • Perform scoped tasks such as answering domain questions, generating structured outputs, or assisting workflows
  • Operate with Microsoft 365 identity and security controls

They are typically built using tools like Copilot Studio and integrated into Microsoft 365 experiences such as Teams, SharePoint, or Copilot chat.


Key characteristics of custom agents

Custom agents differ from general Copilot usage in several important ways:

They are purpose-built, meaning they are designed for a specific function such as HR support or IT helpdesk assistance. They are also data-grounded, relying on selected enterprise knowledge sources rather than broad internet knowledge.

They are governed, meaning they respect Microsoft 365 permissions, Microsoft Purview policies, and organizational compliance boundaries.

Finally, they are interactive and task-oriented, often guiding users through structured processes rather than only responding to ad-hoc questions.


Common use cases for custom agents

1. HR and employee support agents

Custom HR agents are commonly used to:

  • Answer questions about leave policies, benefits, and onboarding
  • Guide employees through HR workflows
  • Retrieve policy documents from SharePoint or HR systems

This reduces HR ticket volume and improves employee self-service.


2. IT helpdesk and support agents

IT-focused agents can:

  • Troubleshoot common issues (password resets, device setup, VPN access)
  • Provide step-by-step remediation guidance
  • Surface knowledge base articles from internal documentation

These agents help reduce repetitive IT support requests.


3. Sales and customer support agents

Sales agents are used to:

  • Summarize customer accounts and opportunities
  • Retrieve CRM data and product information
  • Generate sales emails or proposals

Customer support agents can also respond to common inquiries using approved knowledge bases.


4. Knowledge management agents

Organizations use agents to:

  • Provide structured access to company policies and documentation
  • Answer questions across multiple SharePoint sites
  • Improve search and discovery of internal content

These agents are especially valuable in large enterprises with distributed knowledge.


5. Finance and operations agents

Custom agents in finance or operations can:

  • Assist with budget tracking queries
  • Explain financial reporting definitions
  • Summarize operational KPIs or dashboards

They typically connect to controlled datasets and reporting systems.


6. Project and workflow assistants

These agents help teams by:

  • Tracking project status updates
  • Summarizing meeting notes
  • Guiding users through standardized workflows (e.g., project intake, approvals)

When to use custom agents vs standard Copilot

Custom agents are most appropriate when:

  • A repeatable business process exists
  • The organization has curated knowledge sources
  • Responses must follow strict formatting or rules
  • Domain-specific accuracy is required (HR, finance, IT, legal)

Standard Copilot is better for:

  • General productivity tasks (writing, summarizing, brainstorming)
  • Ad hoc questions that do not require structured workflows or specialized data

Governance considerations

Custom agents inherit Microsoft 365 security and compliance controls, including:

  • Microsoft Entra ID authentication
  • Microsoft Purview sensitivity labels and DLP policies
  • Role-based access control (RBAC)
  • Data access restricted by user permissions

This ensures agents do not expose information beyond what a user is authorized to see.


Summary

Custom agents in Microsoft 365 Copilot are specialized AI assistants designed for targeted business scenarios. They extend Copilot by adding organizational knowledge, structured workflows, and governance controls. Their primary value lies in automating repetitive tasks, improving knowledge access, and supporting domain-specific processes across departments such as HR, IT, finance, and operations.


Practice Exam Questions (10)

1.

A company wants an assistant that can answer employee questions about vacation policies using only internal HR documents stored in SharePoint. What is the best solution?

A. Use a custom Copilot agent grounded in HR SharePoint content
B. Use Microsoft Excel Copilot only
C. Use a Power BI dashboard
D. Use a generic web Copilot chat

Answer: A
Explanation: A custom agent can be grounded in specific SharePoint HR content and provide controlled, policy-based responses.


2.

Which scenario best represents a use case for a custom agent?

A. Writing a marketing email from scratch
B. Generating creative ideas for a product name
C. Answering general trivia questions
D. Guiding users through an IT password reset workflow

Answer: D
Explanation: IT helpdesk workflows are structured, repeatable, and ideal for custom agents.


3.

What is a key benefit of using custom agents in Microsoft 365 Copilot?

A. They bypass Microsoft security controls for faster responses
B. They only use public internet data
C. They enforce organizational policies and use approved data sources
D. They eliminate the need for user authentication

Answer: C
Explanation: Custom agents respect Microsoft 365 governance and use controlled enterprise data.


4.

A finance team wants an AI tool that summarizes monthly budget reports stored in controlled datasets. Which capability is most appropriate?

A. Custom finance agent grounded in approved financial data
B. Personal Microsoft Word Copilot
C. Bing search integration
D. Email auto-responder rules

Answer: A
Explanation: Finance use cases require structured, governed access to internal datasets.


5.

Which tool is commonly used to create custom agents for Microsoft 365 Copilot?

A. Power Automate only
B. Copilot Studio
C. Azure DevOps
D. Microsoft Access

Answer: B
Explanation: Copilot Studio is used to build and configure custom agents.


6.

What distinguishes a custom agent from standard Microsoft 365 Copilot?

A. It can only work offline
B. It uses only unstructured internet data
C. It is built for specific business scenarios and uses curated data sources
D. It replaces all Microsoft 365 applications

Answer: C
Explanation: Custom agents are scoped to specific business needs and data sources.


7.

Which is a valid HR-related use case for a custom agent?

A. Generating random social media posts
B. Answering employee benefit questions from policy documents
C. Editing video content
D. Running system diagnostics on servers

Answer: B
Explanation: HR agents provide policy-based answers from controlled documentation.


8.

What ensures a custom agent does NOT expose unauthorized data?

A. Internet firewall rules
B. Microsoft Defender antivirus only
C. User identity and Microsoft 365 permissions
D. Manual approval of every prompt

Answer: C
Explanation: Access is controlled through Microsoft Entra ID and existing permissions.


9.

When should a custom agent be preferred over standard Copilot?

A. When tasks are ad hoc and creative
B. When structured workflows and specific business rules are required
C. When browsing public websites
D. When no data sources are needed

Answer: B
Explanation: Custom agents are ideal for structured, repeatable workflows.


10.

Which department would most likely benefit from a knowledge management agent?

A. HR requesting policy document access
B. Users playing games
C. Graphic design teams creating artwork
D. Hardware repair technicians fixing printers

Answer: A
Explanation: Knowledge management agents help retrieve and summarize internal policies and documentation.


Go to the AB-900 Exam Prep Hub main page

Compare Copilot monthly license model to Pay-as-You-Go, including SharePoint (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Compare Copilot monthly license model to Pay-as-You-Go, including SharePoint


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft offers multiple licensing models for AI experiences across Microsoft 365. Understanding these licensing options is important for administrators who plan deployments, manage costs, and determine which AI capabilities are available to users.

For the AB-900 exam, you should understand the differences between:

  • Microsoft 365 Copilot monthly user licensing
  • Pay-as-you-go (consumption-based) licensing
  • SharePoint Copilot licensing
  • When each licensing model is appropriate

The exam focuses on understanding the concepts rather than memorizing pricing.


Why Multiple Licensing Models Exist

Organizations vary greatly in how employees use AI.

Some organizations:

  • Have employees who use AI all day.
  • Need AI integrated into Microsoft 365 apps.
  • Require predictable monthly costs.

Other organizations:

  • Use AI occasionally.
  • Need specialized agents.
  • Want to pay only when AI is used.

Microsoft therefore offers both subscription-based and consumption-based licensing.


Microsoft 365 Copilot Monthly License Model

The traditional Microsoft 365 Copilot license is assigned to individual users.

Each licensed user receives access to Copilot experiences across supported Microsoft 365 applications.

Examples include:

  • Word
  • Excel
  • PowerPoint
  • Outlook
  • Teams
  • OneNote
  • Microsoft 365 Chat

The license is:

  • Assigned per user
  • Monthly subscription
  • Predictable recurring cost

Characteristics of the Monthly License

The monthly model provides:

  • Full Microsoft 365 Copilot experience
  • Unlimited daily usage (subject to service limits)
  • Personalized AI assistance
  • Microsoft Graph integration
  • Cross-app experiences
  • Enterprise security and compliance

This model is best for employees who regularly use Copilot throughout their workday.


Typical Monthly License Scenario

A financial analyst uses Copilot every day to:

  • Analyze Excel workbooks
  • Draft reports
  • Summarize meetings
  • Create PowerPoint presentations
  • Search organizational knowledge

Because AI is used continuously, a monthly license provides predictable costs.


Benefits of Monthly Licensing

Advantages include:

  • Predictable budgeting
  • No need to monitor consumption
  • Continuous access
  • Simplified administration
  • Consistent user experience
  • Ideal for heavy users

Limitations of Monthly Licensing

Considerations include:

  • Fixed monthly cost regardless of usage
  • Not ideal for occasional users
  • Every user requires their own license
  • Organizations may over-license infrequent users

Pay-as-You-Go Licensing

Pay-as-you-go (PAYG) is a consumption-based licensing model.

Instead of paying for every user every month, organizations pay based on actual AI usage.

Think of it similarly to cloud computing services:

  • More usage = higher cost
  • Less usage = lower cost

Characteristics of Pay-as-You-Go

Pay-as-you-go provides:

  • Usage-based billing
  • Flexible scaling
  • No requirement for every user to have a monthly Copilot license
  • Cost based on AI requests or service consumption (depending on the service)

This model is especially useful for agents and certain AI scenarios.


Benefits of Pay-as-You-Go

Advantages include:

  • Lower upfront costs
  • Pay only for actual usage
  • Flexible deployment
  • Easy experimentation
  • Ideal for seasonal workloads
  • Good for occasional users

Limitations of Pay-as-You-Go

Potential drawbacks include:

  • Variable monthly costs
  • Budget forecasting is more difficult
  • Requires monitoring usage
  • Heavy usage may become more expensive than subscription licensing

Comparing Monthly Licensing and Pay-as-You-Go

Monthly LicensePay-as-You-Go
Fixed monthly costUsage-based cost
Licensed per userConsumption-based
Predictable budgetingVariable spending
Best for daily usersBest for occasional use
Continuous Copilot accessPay only when AI is used
Simpler cost managementRequires usage monitoring

Microsoft 365 Copilot Chat

Organizations should understand that Microsoft offers AI experiences beyond the traditional monthly Copilot license.

For example:

  • Microsoft 365 Copilot Chat is available to Microsoft 365 users.
  • Organizations can extend Copilot Chat with agents.
  • Some agent usage can be billed using pay-as-you-go licensing rather than requiring every user to have a full Copilot subscription.

This provides flexibility for organizations with mixed AI usage patterns.


SharePoint and Copilot

SharePoint includes AI capabilities that help users work with documents, sites, and organizational knowledge.

Examples include:

  • Summarizing documents
  • Answering questions about files
  • Generating page content
  • Assisting with document creation
  • Improving knowledge discovery

SharePoint Agents

One important capability is SharePoint agents.

A SharePoint agent can:

  • Be created from a SharePoint site or document library
  • Answer questions using approved SharePoint content
  • Help users locate organizational knowledge
  • Reduce the need to manually search documents

For example:

A Human Resources SharePoint site may contain:

  • Employee handbook
  • Benefits guide
  • Leave policies
  • Training documents

An HR SharePoint agent can answer employee questions using those documents.


SharePoint Pay-as-You-Go

Organizations can use SharePoint agents without assigning every user a full Microsoft 365 Copilot license.

Instead, administrators can configure consumption-based billing.

Benefits include:

  • Lower cost for occasional users
  • Easy pilot deployments
  • Department-specific AI
  • Flexible scaling

This makes SharePoint agents attractive for organizations wanting targeted AI experiences without licensing every employee.


Choosing the Right Licensing Model

Choose Monthly Licensing When

  • Employees use Copilot every day.
  • AI is integrated into daily workflows.
  • Predictable monthly budgeting is important.
  • Users need full Copilot functionality across Microsoft 365.

Examples:

  • Executives
  • Project managers
  • Analysts
  • Consultants
  • Sales professionals
  • Knowledge workers

Choose Pay-as-You-Go When

  • AI usage is occasional.
  • Organizations are testing AI.
  • Departments need specialized agents.
  • Seasonal usage is expected.
  • Budget flexibility is acceptable.

Examples:

  • HR help desk agent
  • Legal document agent
  • IT support chatbot
  • SharePoint knowledge assistant

Administrative Considerations

Administrators should evaluate:

  • Expected AI usage
  • Number of users
  • Cost predictability
  • Department requirements
  • Governance policies
  • Licensing strategy
  • Agent deployment plans

Security Remains the Same

Regardless of licensing model:

  • Microsoft Entra ID authentication is used.
  • Microsoft Graph permissions are enforced.
  • Microsoft Purview policies apply.
  • Data Loss Prevention (DLP) policies remain active.
  • Sensitivity labels continue protecting content.
  • Microsoft Defender protections remain in effect.

Licensing changes how organizations pay for AI—not how Microsoft secures organizational data.


Best Practices

Microsoft recommends that organizations:

  • License frequent users with Microsoft 365 Copilot subscriptions.
  • Use pay-as-you-go for occasional AI usage.
  • Monitor AI adoption and consumption.
  • Start with pilot deployments.
  • Evaluate SharePoint agents for departmental knowledge scenarios.
  • Review licensing regularly as adoption increases.

Exam Tips

For the AB-900 exam, remember these key points:

  • Microsoft 365 Copilot is commonly licensed per user with a monthly subscription.
  • Pay-as-you-go bills organizations based on AI usage.
  • Monthly licensing provides predictable costs.
  • Pay-as-you-go offers flexibility for occasional or specialized AI use.
  • SharePoint agents can be deployed using consumption-based licensing in supported scenarios.
  • Licensing affects billing—not security or permissions.
  • Microsoft Graph, Microsoft Purview, and Microsoft Entra ID protections apply regardless of licensing model.
  • Heavy AI users are generally better suited to monthly licensing.
  • Departmental or pilot AI deployments often benefit from pay-as-you-go.

Practice Exam Questions

Question 1

Which licensing model provides users with a predictable monthly cost for Microsoft 365 Copilot?

A. Pay-as-you-go
B. Monthly per-user license
C. Azure consumption credits
D. SharePoint storage licensing

Correct Answer: B

Explanation: A monthly per-user license provides continuous access to Microsoft 365 Copilot for a fixed monthly subscription.


Question 2

What is the primary advantage of the pay-as-you-go licensing model?

A. Users receive unlimited AI usage regardless of activity.
B. Organizations pay only for actual AI usage.
C. Every employee automatically receives Microsoft 365 Copilot.
D. It disables Microsoft Graph integration.

Correct Answer: B

Explanation: Pay-as-you-go charges based on consumption, making it suitable for occasional or specialized AI usage.


Question 3

Which type of user is generally the best candidate for a Microsoft 365 Copilot monthly license?

A. An employee who rarely uses Microsoft 365 applications
B. A seasonal contractor who accesses AI once a month
C. A knowledge worker who uses Copilot throughout the workday
D. A visitor with guest access to SharePoint

Correct Answer: C

Explanation: Heavy or daily users benefit from the predictable costs and continuous access provided by the monthly licensing model.


Question 4

An organization wants to deploy an HR SharePoint agent that employees will use occasionally. Which licensing model is often the better fit?

A. Monthly Copilot license for every employee
B. Windows Enterprise licensing
C. Exchange Online licensing
D. Pay-as-you-go

Correct Answer: D

Explanation: Pay-as-you-go is well suited for departmental agents with occasional usage, allowing organizations to pay based on consumption.


Question 5

Which statement about Microsoft 365 Copilot monthly licensing is correct?

A. It charges only when AI is used.
B. It is assigned to individual users as a subscription.
C. It replaces Microsoft Entra ID.
D. It is available only for SharePoint.

Correct Answer: B

Explanation: The traditional Microsoft 365 Copilot model is licensed per user through a recurring subscription.


Question 6

Which capability is commonly associated with SharePoint agents?

A. Managing Windows updates
B. Replacing Microsoft Graph
C. Answering questions using SharePoint content and document libraries
D. Creating Azure virtual machines

Correct Answer: C

Explanation: SharePoint agents are grounded in SharePoint content and help users locate and understand organizational knowledge.


Question 7

How do Microsoft Purview policies behave when an organization switches from monthly licensing to pay-as-you-go?

A. They are automatically disabled.
B. They apply only to SharePoint documents.
C. They require users to purchase additional licenses before functioning.
D. They continue to protect data regardless of the licensing model.

Correct Answer: D

Explanation: Security and compliance controls such as Microsoft Purview continue to protect data regardless of how AI services are licensed.


Question 8

Which licensing model generally provides the most predictable monthly budgeting?

A. Pay-as-you-go
B. Monthly per-user licensing
C. Azure Reserved Instances
D. SharePoint storage quotas

Correct Answer: B

Explanation: Monthly licensing offers a fixed recurring cost, simplifying budgeting and financial planning.


Question 9

What is a potential disadvantage of pay-as-you-go licensing?

A. It cannot be used with agents.
B. It prevents users from accessing SharePoint.
C. Monthly costs may vary depending on AI usage.
D. It disables Microsoft Graph permissions.

Correct Answer: C

Explanation: Consumption-based billing means costs fluctuate according to actual usage, making budgeting less predictable.


Question 10

Which statement best summarizes the difference between Microsoft 365 Copilot monthly licensing and pay-as-you-go?

A. Monthly licensing is subscription-based, while pay-as-you-go is consumption-based.
B. Monthly licensing does not include Microsoft Graph.
C. Pay-as-you-go removes Microsoft Purview protections.
D. Monthly licensing is only available for SharePoint.

Correct Answer: A

Explanation: The fundamental difference is the billing model: monthly licensing charges a fixed subscription per user, whereas pay-as-you-go charges based on actual AI service consumption.


Go to the AB-900 Exam Prep Hub main page

Share an agent with team members (AB-730 Exam Prep)

This post is a part of the AB-730: AI Business Professional Exam Prep Hub.
This topic falls under these sections:
Manage prompts and conversations by using AI (35–40%)
   --> Create and manage Microsoft 365 Copilot agents
      --> Share an agent with team members


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 2 practice tests with 60 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft 365 Copilot agents are designed to help individuals and teams perform specialized tasks more efficiently. Once an agent has been created and configured, the next step is often to make it available to other users.

Sharing an agent allows organizations to:

  • Standardize business processes.
  • Promote collaboration.
  • Reduce duplicate work.
  • Provide consistent answers and guidance.
  • Increase productivity across teams.

For the AB-730 exam, it is important to understand why organizations share agents, the different sharing scenarios, and the considerations involved when making agents available to others.


Why Share a Copilot Agent?

Many business scenarios involve information or processes that multiple people use regularly. Instead of each employee creating separate agents, organizations can share a single agent that serves the needs of an entire department or team.

Examples include:

Human Resources

An HR Benefits Agent can answer common employee questions about:

  • Paid time off
  • Benefits
  • Expense policies
  • Remote work guidelines

Sales

A Sales Assistant Agent can help:

  • Summarize product information
  • Prepare customer responses
  • Generate proposals

IT Support

An IT Agent can provide:

  • Password reset instructions
  • Device setup procedures
  • Software installation guidance

Sharing enables these resources to be reused by many users.


Benefits of Sharing Agents

Consistency

Everyone receives responses based on the same instructions and knowledge sources.


Time Savings

Employees do not need to recreate identical agents.


Better User Adoption

Teams can immediately begin using an existing agent rather than building one from scratch.


Collaboration

Departments can maintain and improve a shared resource together.


Reduced Errors

Centralized instructions and knowledge help ensure that users receive accurate and consistent guidance.


Common Sharing Scenarios

Organizations may share agents with:

Individual Users

A creator shares an agent directly with selected coworkers.

Example:

A finance manager shares a budgeting agent with two analysts.


Teams or Departments

Entire groups can access the same agent.

Example:

The HR department uses a common employee policy agent.


Larger Organizational Audiences

Some agents may be available to many users throughout the organization.

Example:

An onboarding agent available to all employees.


What Users Receive When an Agent Is Shared

When users gain access to a shared agent, they can typically:

  • Open and use the agent.
  • Ask questions.
  • Benefit from its instructions and knowledge sources.
  • Use suggested prompts.

However, access to information remains governed by permissions.

Users only receive responses based on content they are authorized to access.


Sharing Does Not Override Security

One important exam concept is that sharing an agent does not bypass Microsoft 365 security.

Even if two employees use the same agent:

  • Employee A may see certain documents.
  • Employee B may not.

The agent respects:

  • Existing Microsoft 365 permissions.
  • Data access policies.
  • Security boundaries.

Sharing an agent does not automatically grant access to underlying files.


Permissions Still Matter

Suppose an HR agent references confidential salary documents.

If a user does not have permission to those documents:

  • The agent cannot reveal the information.
  • Responses remain restricted.

This security model helps protect sensitive business data.


Updating Shared Agents

One advantage of sharing is centralized maintenance.

When the owner updates:

  • Instructions,
  • Knowledge sources,
  • Suggested prompts,
  • Agent settings,

all users benefit from the improvements.

This prevents multiple versions from becoming inconsistent.


Ownership Responsibilities

Agent creators should:

Keep Instructions Current

Outdated instructions can produce inaccurate responses.

Review Knowledge Sources

Ensure information remains relevant.

Test Changes

Verify that updates improve results.

Monitor Feedback

Team feedback helps refine the agent over time.


Best Practices for Sharing Agents

Share Only When There Is Business Value

Not every personal agent needs to be shared.

Good candidates include:

  • Frequently used processes.
  • Department knowledge.
  • Common employee questions.
  • Reusable workflows.

Use Clear Names

Examples:

  • HR Benefits Assistant
  • Sales Proposal Helper
  • IT Onboarding Agent

Clear names help users find the correct agent.


Provide Good Descriptions

Descriptions explain:

  • What the agent does.
  • Who should use it.
  • Which problems it solves.

Include Suggested Prompts

Suggested prompts help users start conversations effectively.

Examples:

  • “Summarize the PTO policy.”
  • “Explain remote work procedures.”
  • “How do I submit expenses?”

Avoid Sharing Incomplete Agents

Before sharing:

  • Test the agent.
  • Verify instructions.
  • Confirm knowledge sources.
  • Ensure responses are accurate.

Sharing vs. Creating Duplicate Agents

Creating duplicate agents can lead to:

  • Conflicting instructions.
  • Inconsistent answers.
  • Maintenance challenges.

Sharing a single, well-maintained agent is usually more efficient.


Example Scenario

Situation

The Human Resources department receives dozens of questions each week regarding benefits.

Solution

HR creates a Benefits Agent that:

  • Uses HR documents as knowledge.
  • Includes instructions for professional responses.
  • Provides suggested prompts.
  • Is shared with all employees.

Result

Employees receive faster answers, and HR staff spend less time responding to repetitive questions.


Potential Limitations

Shared agents still depend on:

User Permissions

Agents cannot expose information users are not authorized to access.

Knowledge Quality

Poor or outdated information produces poor responses.

Proper Configuration

Bad instructions can reduce usefulness.

Maintenance

Agents should be reviewed periodically.


Key Exam Points

Remember these concepts for the AB-730 exam:

  • Agents can be shared with individuals, teams, or larger audiences.
  • Sharing promotes collaboration and consistency.
  • Shared agents help reduce duplicate work.
  • Security permissions are still enforced.
  • Sharing an agent does not grant access to restricted files.
  • Updates made by the owner benefit all users.
  • Good names, descriptions, and suggested prompts improve adoption.
  • Shared agents should be tested before deployment.

Practice Questions


Question 1

Why would an organization share a Copilot agent with team members?

A. To standardize processes and reduce duplicate work
B. To disable Microsoft 365 permissions
C. To increase internet bandwidth
D. To replace user accounts

Answer: A

Explanation:
Sharing agents promotes consistency and prevents multiple employees from creating identical solutions.


Question 2

Which statement about shared agents is true?

A. Sharing automatically grants access to every file used by the agent.
B. Users can only use shared agents in Outlook.
C. Existing Microsoft 365 permissions are still enforced.
D. Shared agents ignore security policies.

Answer: C

Explanation:
Agents respect existing permissions and cannot reveal information users are not authorized to access.


Question 3

What is a major benefit of maintaining one shared agent instead of several duplicate agents?

A. Increased hardware performance
B. Easier updates and more consistent responses
C. Elimination of licensing requirements
D. Removal of security settings

Answer: B

Explanation:
Centralized maintenance ensures everyone receives the same instructions and improvements.


Question 4

A user receives access to a shared HR agent. Which capability do they typically gain?

A. Full administrator privileges
B. Ownership of all HR documents
C. Automatic access to payroll files
D. The ability to use the agent and ask questions

Answer: D

Explanation:
Users gain access to interact with the agent, not unrestricted access to underlying resources.


Question 5

Which shared agent would most likely benefit an entire organization?

A. A personal vacation planner
B. A private shopping assistant
C. An employee onboarding agent
D. A game recommendation assistant

Answer: C

Explanation:
Organization-wide processes are excellent candidates for shared agents.


Question 6

Why should shared agents include suggested prompts?

A. To increase storage capacity
B. To help users understand how to interact with the agent
C. To bypass instructions
D. To remove security restrictions

Answer: B

Explanation:
Suggested prompts improve user adoption and make agents easier to use.


Question 7

Who benefits when the agent owner updates instructions or knowledge sources?

A. Only the creator
B. Only administrators
C. Nobody until the agent is recreated
D. All users of the shared agent

Answer: D

Explanation:
Shared agents provide centralized updates that automatically benefit users.


Question 8

Which practice is recommended before sharing an agent?

A. Disable all permissions.
B. Remove suggested prompts.
C. Test the agent and verify its responses.
D. Delete the knowledge sources.

Answer: C

Explanation:
Testing ensures the agent provides useful and accurate responses before users begin relying on it.


Question 9

What remains true after an agent is shared?

A. Security permissions still apply.
B. Every user receives administrator rights.
C. All files become publicly visible.
D. Users can edit the creator’s settings automatically.

Answer: A

Explanation:
Sharing an agent does not override Microsoft 365 access controls.


Question 10

Which naming convention would make a shared agent easiest to discover?

A. Agent 7
B. Test123
C. Assistant
D. HR Benefits Assistant

Answer: D

Explanation:
Clear and descriptive names help users quickly understand the agent’s purpose and locate the correct resource.


Go to the AB-730 Exam Prep Hub main page

Configure agent settings such as instructions, capabilities, and suggested prompts (AB-730 Exam Prep)

This post is a part of the AB-730: AI Business Professional Exam Prep Hub.
This topic falls under these sections:
Manage prompts and conversations by using AI (35–40%)
   --> Create and manage Microsoft 365 Copilot agents
      --> Configure agent settings such as instructions, capabilities, and suggested prompts


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 2 practice tests with 60 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft 365 Copilot agents are specialized AI assistants designed to perform specific tasks, provide domain-specific knowledge, and support business workflows. After creating an agent, one of the most important steps is configuring its settings.

Proper configuration helps ensure that the agent:

  • Behaves consistently.
  • Produces relevant responses.
  • Uses the appropriate knowledge and tools.
  • Guides users toward effective interactions.
  • Aligns with organizational goals and business processes.

For the AB-730 exam, it is important to understand the purpose of the major agent settings and how they influence user experiences.


Why Agent Configuration Matters

An agent’s quality depends heavily on its configuration. Two agents with access to the same information may provide very different results depending on:

  • Instructions provided to the agent.
  • Enabled capabilities.
  • Available knowledge sources.
  • Suggested prompts offered to users.

Good configuration improves:

  • Accuracy.
  • Consistency.
  • User adoption.
  • Productivity.
  • Ease of use.

Poor configuration can lead to:

  • Generic answers.
  • Inconsistent behavior.
  • User confusion.
  • Irrelevant outputs.

Main Agent Configuration Areas

Microsoft 365 Copilot agents typically include several configurable components:

  1. Instructions
  2. Capabilities
  3. Knowledge sources
  4. Suggested prompts
  5. Identity and description settings

Configuring Instructions

What Are Instructions?

Instructions tell the agent how it should behave.

They act as the agent’s permanent guidance and define:

  • Purpose.
  • Tone.
  • Scope.
  • Expected response style.
  • Business rules.

Instructions are similar to system prompts that remain active for every interaction.


Examples of Instructions

Customer Support Agent

Instruction:

Answer questions politely and professionally. Use information from company policies. If information is unavailable, recommend contacting support.

HR Agent

Instruction:

Provide responses based on HR documentation. Avoid legal advice and direct employees to HR specialists for exceptions.

Sales Agent

Instruction:

Emphasize product benefits and summarize information clearly for customers.


Effective Instruction Characteristics

Good instructions are:

Specific

Instead of:

“Help employees.”

Use:

“Answer employee PTO questions using HR documents.”

Clear

Avoid vague language.

Role-Oriented

Define the agent’s purpose.

Consistent

Establish expected formatting and tone.

Limited in Scope

Prevent the agent from attempting tasks outside its intended purpose.


Examples of Poor Instructions

Poor:

Be helpful.

Better:

Summarize policy documents in plain language and provide references to official resources.

Poor:

Answer anything.

Better:

Answer questions related to product documentation only.


Configuring Capabilities

What Are Capabilities?

Capabilities determine what the agent is allowed to do.

Capabilities may include:

  • Searching knowledge sources.
  • Answering questions.
  • Summarizing information.
  • Using connected tools.
  • Performing specialized actions.

Capabilities extend the agent beyond simple conversation.


Purpose of Capabilities

Capabilities help ensure that:

  • The agent performs only necessary functions.
  • Responses remain focused.
  • Users receive more relevant results.
  • Risk is reduced by limiting unnecessary access.

Example

Procurement Agent

Capabilities:

  • Search procurement policies.
  • Summarize supplier procedures.
  • Provide onboarding guidance.

Capabilities not enabled:

  • Financial forecasting.
  • HR policy support.

This keeps the agent focused on procurement tasks.


Knowledge Sources and Capabilities Work Together

Knowledge provides information.

Capabilities determine how that information can be used.

For example:

Knowledge Source

Employee handbook.

Capability

Answer employee policy questions.

Without knowledge, the agent lacks information.

Without capabilities, the information cannot be effectively used.


Suggested Prompts

What Are Suggested Prompts?

Suggested prompts are example questions presented to users when they start interacting with an agent.

They help users understand:

  • What the agent can do.
  • Which types of questions work best.
  • How to begin conversations.

Benefits of Suggested Prompts

Suggested prompts:

Improve User Adoption

Users immediately understand the agent’s purpose.

Reduce Confusion

People know what kinds of requests are supported.

Encourage Better Prompting

Examples guide users toward effective interactions.

Save Time

Users can start with a single click.


Example Suggested Prompts for an HR Agent

  • “How many vacation days do employees receive?”
  • “Summarize the parental leave policy.”
  • “Where can I find the expense reimbursement process?”
  • “Explain remote work guidelines.”

These examples help users quickly understand the agent’s role.


Designing Effective Suggested Prompts

Good suggested prompts should:

Be Realistic

Use questions users actually ask.

Demonstrate Agent Value

Highlight common scenarios.

Be Short and Clear

Avoid complicated wording.

Cover Multiple Use Cases

Provide examples for different situations.


Poor Suggested Prompt Example

“Ask me anything.”

This provides little guidance.

Better:

“Summarize the employee benefits policy.”


Identity and Description Settings

Agents usually include:

Name

Clearly identifies the agent.

Examples:

  • HR Assistant
  • Sales Coach
  • Procurement Advisor

Description

Explains what the agent does.

Example:

Helps employees find answers about company policies and benefits.

Good names and descriptions improve discoverability and user confidence.


Best Practices for Configuring Agents

Define a Clear Purpose

Agents work best when focused on a specific domain.


Write Precise Instructions

Detailed instructions produce more consistent responses.


Limit Capabilities to Necessary Functions

Avoid enabling unnecessary features.


Provide Helpful Suggested Prompts

Show users exactly how the agent should be used.


Test and Refine

Monitor agent behavior and adjust:

  • Instructions.
  • Prompt examples.
  • Capabilities.
  • Knowledge sources.

Configuration is an iterative process.


Example: Complete HR Agent Configuration

Name

HR Benefits Assistant

Description

Answers questions about employee benefits and company policies.

Instructions

  • Respond professionally.
  • Use HR documentation.
  • Summarize information clearly.
  • Refer complex situations to HR staff.

Capabilities

  • Search HR knowledge.
  • Summarize documents.
  • Answer policy questions.

Suggested Prompts

  • “What benefits are available to new employees?”
  • “Explain parental leave.”
  • “Summarize the PTO policy.”
  • “How do I submit expense reimbursements?”

This combination creates a focused and easy-to-use agent.


Key Exam Points

Remember these concepts for AB-730:

  • Instructions define how an agent behaves.
  • Capabilities determine what the agent can do.
  • Knowledge sources provide information.
  • Suggested prompts help users start conversations.
  • Good configuration improves accuracy and usability.
  • Limiting scope reduces confusion and risk.
  • Names and descriptions help users discover and understand agents.
  • Agent settings can be refined over time.

Practice Questions


Question 1

What is the primary purpose of agent instructions?

A. To store files for the agent
B. To define how the agent should behave and respond
C. To increase network bandwidth
D. To manage user licenses

Answer: B

Explanation:
Instructions provide ongoing guidance that determines the agent’s role, tone, and response behavior.


Question 2

Which setting controls what functions an agent is allowed to perform?

A. Suggested prompts
B. Agent description
C. Capabilities
D. Conversation history

Answer: C

Explanation:
Capabilities determine the actions and functions available to the agent.


Question 3

Why are suggested prompts useful?

A. They replace knowledge sources.
B. They automatically generate reports.
C. They improve storage capacity.
D. They help users understand how to interact with the agent.

Answer: D

Explanation:
Suggested prompts provide examples that guide users toward effective conversations.


Question 4

Which instruction is most effective?

A. “Be helpful.”
B. “Answer everything.”
C. “Respond using HR policies and summarize information clearly.”
D. “Do whatever the user requests.”

Answer: C

Explanation:
Specific instructions produce more consistent and relevant responses.


Question 5

What is the relationship between knowledge sources and capabilities?

A. Knowledge provides information, while capabilities determine how the agent uses it.
B. They are identical features.
C. Capabilities replace knowledge sources.
D. Knowledge sources control licensing.

Answer: A

Explanation:
Knowledge supplies content, while capabilities determine how the agent can work with that content.


Question 6

Which suggested prompt is best for an expense policy agent?

A. “Anything.”
B. “Ask me a question.”
C. “Use the internet.”
D. “How do I submit an expense reimbursement request?”

Answer: D

Explanation:
A realistic example helps users understand the agent’s intended purpose.


Question 7

Why should unnecessary capabilities be avoided?

A. They increase user licenses.
B. They may create confusion and broaden the agent beyond its intended role.
C. They prevent knowledge from being used.
D. They delete conversation history.

Answer: B

Explanation:
Limiting capabilities helps maintain focus and reduce complexity.


Question 8

Which setting most directly influences the tone and style of responses?

A. Instructions
B. Suggested prompts
C. Conversation history
D. Agent icon

Answer: A

Explanation:
Instructions define response style, tone, and expected behavior.


Question 9

What is the purpose of an agent description?

A. To assign licenses
B. To manage permissions
C. To explain the agent’s purpose to users
D. To store chat history

Answer: C

Explanation:
Descriptions help users understand what the agent is designed to do.


Question 10

After deploying an agent, what should organizations do next?

A. Never change the settings again.
B. Delete previous versions immediately.
C. Disable suggested prompts.
D. Continuously evaluate and refine the configuration.

Answer: D

Explanation:
Agent development is iterative. Adjusting instructions, capabilities, and prompts over time improves performance and user satisfaction.


Go to the AB-730 Exam Prep Hub main page