Tag: Microsoft 365 Copilot Agents

Exam Prep Hub for AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals

Welcome to the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub!

Welcome to the one-stop hub with information for preparing for the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals certification exam. The content for this exam helps prepare you to “understand Microsoft 365 services, admin tools, core objects, core security features, and modern AI-driven IT management practices”.
Upon successful completion of the exam, you earn the Microsoft 365 Certified: Copilot and Agent Administration Fundamentals certification.

This hub provides information directly here (topic-by-topic as outlined in the official study guide), links to a number of external resources, tips for preparing for the exam, practice tests, and section questions to help you prepare. Bookmark this page and use it as a guide to ensure that you are fully covering all relevant topics for the AB-900 exam and making use of as many of the resources available as possible.


Audience profile (from Microsoft’s site)

As a candidate for this Microsoft Certification, you should be familiar with Microsoft 365, including core services, security, identity and access, data protection, and governance, along with Microsoft 365 Copilot and agents.
Additionally, you should be familiar with the admin centers used to access Microsoft 365 workloads, such as Exchange Online, SharePoint in Microsoft 365, Microsoft Teams, Microsoft Entra, and Microsoft Purview. You need to have experience with AI-driven productivity tools and modern IT management practices.
You must be able to identify the roles of the core features and objects available in Microsoft 365, such as users, groups, teams, sites, and libraries. Plus, you should understand the core security features of Microsoft 365, such as authentication methods, conditional access policies, and single sign-on (SSO).

Skills at a glance (as specified in the official study guide)

  • Identify the core features and objects of Microsoft 365 services (30–35%)
  • Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
  • Perform basic administrative tasks for Copilot and agents (25–30%)

Topic-by-Topic Exam Content

[click a topic link to access the content and practice questions for that topic]

Identify the core features and objects of Microsoft 365 services (30–35%)

Identify the core objects of Microsoft 365 services

Understand the Microsoft 365 security principles

Identify the core security features of Microsoft 365 services

Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)

Understand Microsoft Purview

Understand data security implications of Copilot

Identify data protection and governance risks for Microsoft 365 and Copilot

Identify and monitor oversharing in SharePoint in Microsoft 365

Perform basic administrative tasks for Copilot and agents (25–30%)

Understand features and capabilities of Copilot and agents

Perform basic administrative tasks for Copilot

Perform basic administrative tasks for agents


AB-900 Practice Exams


Important AB-900 Resources

Link to the free, comprehensive, self-paced course on Microsoft Learn: Introduction to Microsoft 365 and AI administration

https://learn.microsoft.com/en-us/training/courses/ab-900t00

This course has two learning paths:

(1) The first learning path is: Explore Microsoft 365 administration, located at this URL:
https://learn.microsoft.com/en-us/training/paths/explore-microsoft-365-administration

This learning path has 3 modules, located at the below URLs:

(2) The second learning path is: Explore Microsoft 365 Copilot and agent administration, located at this URL:
https://learn.microsoft.com/en-us/training/paths/explore-microsoft-365-copilot-agent-administration

This learning path has 3 modules, located at the below URLs:

Link to the certification page:

Link to the study guide:


YouTube resources:

Courses: There are several highly rated courses for AB-900 on Udemy:

Check out the previews of each course to decide which trainer is best for you. And a tip for you … if your timeline allows it, wait for the occasional Udemy sale and buy your course(s) then.


Good luck to you passing the AB-900 Exam!
However, the more preparation you have, the less luck you will need. 🙂

Visit this post to see the list of all the certification preparation hubs available on The Data Community.

Monitor agents, including usage, operational insights, and agent lifecycle, by working with the Microsoft 365 Admin Center and the Microsoft Power Platform Admin Center (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for agents
      --> Monitor agents, including usage, operational insights, and agent lifecycle, by working with the Microsoft 365 Admin Center and the Microsoft Power Platform Admin Center


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

As organizations deploy more Microsoft 365 Copilot agents, effective administration extends beyond simply creating and publishing them. Administrators must continuously monitor agent usage, operational health, adoption, security, and lifecycle to ensure that agents continue to provide business value while meeting organizational governance and compliance requirements.

Microsoft provides two primary administrative portals for monitoring and managing agents:

  • Microsoft 365 admin center
  • Microsoft Power Platform admin center

Each portal serves a different purpose. The Microsoft 365 admin center focuses on Microsoft 365 services, Copilot adoption, licensing, and organizational administration, while the Power Platform admin center focuses on environments, Copilot Studio, Power Platform resources, and operational management of custom agents.

For the AB-900 exam, you should understand which portal is used for which administrative tasks, the types of monitoring information available, and the basic lifecycle of an agent.


Why Monitoring Agents Is Important

Monitoring helps administrators answer questions such as:

  • Are users actually using the agent?
  • Is the agent providing business value?
  • Are there operational issues?
  • Is adoption increasing?
  • Are users encountering errors?
  • Should the agent be updated or retired?
  • Are governance policies being followed?

Without monitoring, organizations cannot determine whether their AI investments are successful.


Administrative Portals

Microsoft 365 Admin Center

The Microsoft 365 admin center provides organization-wide administration for Microsoft 365 services, including Copilot.

Administrators commonly use it to:

  • View Copilot adoption
  • Monitor Copilot usage
  • Assign licenses
  • Manage users
  • Manage billing
  • View service health
  • Review reports
  • Monitor tenant-wide administration

It provides a business-level view of how Microsoft 365 Copilot is being used across the organization.


Microsoft Power Platform Admin Center

The Power Platform admin center focuses on the operational management of Power Platform resources, including custom agents created with Copilot Studio.

Administrators use it to:

  • Manage environments
  • Monitor agent health
  • Manage Dataverse resources
  • Review capacity
  • Configure security
  • Manage connectors
  • Review operational information
  • Manage Power Platform policies

It provides technical administration for custom AI solutions.


Monitoring Agent Usage

Usage monitoring helps organizations understand adoption.

Common usage metrics include:

  • Number of users
  • Active users
  • Conversations
  • Sessions
  • Frequency of use
  • Popular agents
  • Usage trends over time

These metrics help determine whether users are benefiting from the deployed agents.


Usage Scenarios

An administrator might monitor:

  • Daily active users
  • Weekly adoption growth
  • Monthly conversation counts
  • Frequently used agents
  • Least-used agents

Low adoption may indicate:

  • Lack of awareness
  • Poor training
  • Limited usefulness
  • Difficult user experience

Operational Insights

Operational insights help administrators understand how agents are performing.

Examples include:

  • Agent availability
  • Service status
  • Response success
  • Failed requests
  • Processing errors
  • Environment health
  • Connector status
  • Workflow execution

Operational monitoring focuses on technical performance rather than business adoption.


Examples of Operational Issues

Administrators may investigate:

  • Failed API connections
  • Broken Power Automate flows
  • Authentication failures
  • Connector problems
  • Environment capacity limits
  • Dataverse issues

Identifying these issues early minimizes disruption for users.


Monitoring Agent Lifecycle

Every agent follows a lifecycle from creation to retirement.

Typical lifecycle stages include:

  1. Planning
  2. Design
  3. Development
  4. Testing
  5. Approval
  6. Publishing
  7. Monitoring
  8. Updating
  9. Republishing
  10. Retirement

Administrators monitor agents throughout this lifecycle.


Lifecycle Management Activities

During an agent’s lifecycle, administrators may:

  • Update instructions
  • Improve prompts
  • Add new knowledge sources
  • Remove outdated content
  • Modify connectors
  • Improve security
  • Publish new versions
  • Disable obsolete agents
  • Archive retired agents

Lifecycle management is an ongoing process rather than a one-time task.


Adoption Monitoring

One important responsibility is measuring adoption.

Organizations often monitor:

  • Licensed users
  • Active users
  • Usage growth
  • Conversation volume
  • Department adoption
  • Business impact

High adoption generally indicates that users find the agent valuable.


Performance Monitoring

Performance monitoring focuses on the quality of the user experience.

Administrators may evaluate:

  • Response times
  • Reliability
  • Availability
  • Error rates
  • Successful interactions
  • Failed interactions

Consistent performance builds user confidence in AI solutions.


Security Monitoring

Monitoring also includes security.

Administrators watch for:

  • Unauthorized access
  • Permission issues
  • Authentication failures
  • Suspicious activity
  • Compliance alerts
  • Data access concerns

Security monitoring helps ensure that agents continue to comply with organizational policies.


Governance Monitoring

Governance activities include monitoring:

  • Approved agents
  • Published agents
  • Ownership
  • Data sources
  • Permissions
  • Connector usage
  • Compliance policies

Organizations should periodically review whether agents still meet governance requirements.


Environment Monitoring

The Power Platform admin center allows administrators to monitor environments that host agents.

Typical information includes:

  • Environment health
  • Capacity usage
  • Storage
  • Dataverse utilization
  • Resource allocation

Healthy environments help ensure reliable agent performance.


Monitoring Connectors

Many agents rely on connectors to access business systems.

Administrators may monitor:

  • Connector availability
  • Authentication status
  • Connection errors
  • Connector permissions
  • External system connectivity

Problems with connectors often result in incomplete or failed agent responses.


Monitoring User Feedback

Organizations should also gather user feedback.

Useful indicators include:

  • User satisfaction
  • Reported issues
  • Feature requests
  • Accuracy concerns
  • Suggested improvements

Feedback helps guide future improvements to the agent.


Retirement of Agents

Not every agent remains useful forever.

Administrators may retire agents when:

  • Business needs change.
  • New agents replace older versions.
  • Information becomes outdated.
  • Security risks increase.
  • Adoption declines significantly.

Retired agents should be archived or removed according to organizational governance policies.


Best Practices

Organizations should:

  • Monitor usage regularly.
  • Review adoption reports.
  • Monitor operational health.
  • Investigate errors promptly.
  • Review security frequently.
  • Track lifecycle status.
  • Keep documentation current.
  • Update agents regularly.
  • Remove obsolete agents.
  • Use both Microsoft 365 and Power Platform administration tools appropriately.

Microsoft 365 Admin Center vs. Power Platform Admin Center

Microsoft 365 Admin CenterPower Platform Admin Center
User administrationEnvironment administration
License managementDataverse management
Copilot adoptionAgent operations
Usage reportingEnvironment health
BillingConnector management
Service healthCapacity monitoring
Organization-wide administrationPower Platform governance
Copilot reportsOperational insights

Exam Tips

For the AB-900 exam, remember these key points:

  • The Microsoft 365 admin center focuses on Microsoft 365 administration, licensing, Copilot usage, adoption, and organizational reporting.
  • The Power Platform admin center focuses on operational management of custom agents, environments, connectors, Dataverse, and Power Platform resources.
  • Usage monitoring measures adoption and business value.
  • Operational insights focus on technical health and performance.
  • Agents should be monitored throughout their entire lifecycle.
  • Administrators should regularly review performance, governance, and security after an agent is deployed.

Practice Exam Questions

Question 1

Which administrative portal is primarily used to monitor Microsoft 365 Copilot adoption and licensing?

A. Microsoft 365 admin center

B. Microsoft Defender portal

C. Azure Portal

D. Microsoft Purview portal

Answer: A

Explanation: The Microsoft 365 admin center provides organization-wide administration, including Copilot licensing, adoption reports, and usage monitoring.


Question 2

What is the primary purpose of monitoring agent usage?

A. To increase internet bandwidth

B. To determine adoption and business value

C. To install software updates

D. To configure SharePoint permissions

Answer: B

Explanation: Usage metrics help organizations understand whether agents are delivering value and being actively used.


Question 3

Which portal is primarily responsible for monitoring environments, connectors, and Dataverse resources for custom agents?

A. Microsoft Entra admin center

B. Microsoft Purview portal

C. Microsoft Power Platform admin center

D. Exchange admin center

Answer: C

Explanation: The Power Platform admin center manages environments, Dataverse, connectors, capacity, and operational aspects of custom agents.


Question 4

Which metric best represents agent adoption?

A. CPU utilization

B. Network latency

C. Number of active users

D. Available storage space

Answer: C

Explanation: Active users are a key indicator of how widely an agent is being adopted.


Question 5

Which activity is part of an agent’s lifecycle after publication?

A. Ongoing monitoring and updates

B. Automatic deletion

C. Disabling Microsoft 365

D. Removing all connectors

Answer: A

Explanation: Administrators continuously monitor, update, and improve agents after they are deployed.


Question 6

Which of the following is considered an operational insight?

A. Number of licensed users

B. Employee vacation requests

C. Failed connector authentication

D. SharePoint storage quota purchase

Answer: C

Explanation: Operational insights include technical issues such as connector failures, authentication problems, and service errors.


Question 7

Why should administrators monitor agent performance?

A. To increase hardware prices

B. To ensure reliable responses and a positive user experience

C. To disable audit logs

D. To reduce Microsoft 365 storage

Answer: B

Explanation: Performance monitoring helps ensure agents remain reliable, responsive, and useful.


Question 8

Which administrative activity helps identify agents that are no longer providing business value?

A. Monitoring adoption trends

B. Updating Windows drivers

C. Installing Office applications

D. Configuring printers

Answer: A

Explanation: Declining adoption trends may indicate that an agent should be improved or retired.


Question 9

What should administrators monitor to help identify security concerns related to agents?

A. Desktop wallpaper settings

B. Keyboard layouts

C. Unauthorized access attempts and permission issues

D. Browser home pages

Answer: C

Explanation: Monitoring permissions, authentication failures, and unauthorized access helps maintain security.


Question 10

Which statement best describes the relationship between the Microsoft 365 admin center and the Microsoft Power Platform admin center?

A. Both portals perform exactly the same administrative functions.

B. The Microsoft 365 admin center is used only for Exchange Online.

C. The Power Platform admin center replaces the Microsoft 365 admin center for all administration.

D. The Microsoft 365 admin center focuses on organizational Microsoft 365 administration and Copilot usage, while the Power Platform admin center focuses on environments and operational management of custom agents.

Answer: D

Explanation: The two portals complement one another. The Microsoft 365 admin center provides tenant-wide administration, licensing, and adoption reporting, while the Power Platform admin center provides operational management of environments, connectors, Dataverse resources, and custom agents built with Copilot Studio.


Go to the AB-900 Exam Prep Hub main page

Understand the approval process for agents (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for agents
      --> Understand the approval process for agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

As organizations increasingly adopt Microsoft 365 Copilot and AI-powered agents, governance becomes just as important as functionality. Without proper oversight, users could inadvertently create agents that expose sensitive information, perform unintended actions, or fail to comply with organizational policies.

For this reason, Microsoft provides an approval process that enables organizations to review, validate, and govern agents before they are made available to users. While the exact approval workflow depends on the type of agent, the organization’s governance policies, and the deployment platform (such as Microsoft Copilot Studio), administrators should understand how approval processes help ensure that agents are secure, compliant, and aligned with business requirements.

For the AB-900 exam, you are not expected to know every detailed configuration step, but you should understand why approvals exist, when they are required, who participates in the approval process, and what happens before and after an agent is approved.


Why Agent Approval is Important

Unlike general-purpose Microsoft 365 Copilot experiences, custom agents often:

  • Access organizational knowledge
  • Connect to business systems
  • Trigger automated workflows
  • Perform business-specific tasks
  • Use sensitive organizational data

Because of these capabilities, organizations typically require an approval process before an agent is published to production.

Approval helps ensure that:

  • The agent performs its intended function.
  • Security requirements are met.
  • Compliance policies are followed.
  • Data access is appropriate.
  • Users receive a trustworthy AI experience.

Goals of the Approval Process

An effective approval process helps organizations:

  • Reduce security risks
  • Prevent accidental oversharing
  • Ensure regulatory compliance
  • Improve quality of AI responses
  • Validate business usefulness
  • Maintain organizational standards
  • Establish accountability

Typical Agent Lifecycle

A simplified lifecycle includes:

  1. Design
  2. Build
  3. Configure
  4. Test
  5. Review
  6. Approve
  7. Publish
  8. Monitor
  9. Update
  10. Retire

Approval occurs after testing but before broad deployment.


Typical Approval Workflow

Although every organization may customize the workflow, the process generally follows these steps.

Step 1: Agent Creation

A developer or business user creates the agent.

They configure:

  • Instructions
  • Knowledge sources
  • Actions
  • Connectors
  • Conversation flow

Step 2: Initial Testing

Before requesting approval, the creator tests the agent.

Typical testing includes:

  • Prompt accuracy
  • Correct responses
  • Hallucination reduction
  • Data grounding
  • Error handling
  • Business logic

Step 3: Security Review

Security administrators verify that:

  • Permissions are appropriate.
  • Data sources are approved.
  • Authentication is configured correctly.
  • Sensitive information is protected.
  • Least-privilege access is maintained.

Step 4: Compliance Review

Compliance teams evaluate whether the agent aligns with organizational governance policies.

Areas reviewed include:

  • Data Loss Prevention (DLP)
  • Sensitivity labels
  • Microsoft Purview policies
  • Data retention
  • Regulatory requirements
  • Audit logging

Step 5: Business Review

Business owners determine whether:

  • The agent solves the intended problem.
  • Responses are accurate.
  • Business terminology is correct.
  • Processes are followed correctly.
  • Users will benefit from the solution.

Step 6: Approval

Once reviews are complete, the designated approver authorizes publication.

Only approved agents should become available to end users.


Step 7: Publishing

After approval, the agent can be:

  • Published
  • Assigned to users
  • Shared with groups
  • Made available in Microsoft Teams
  • Integrated into Microsoft 365 Copilot

Who May Participate in the Approval Process?

Several roles may be involved depending on the organization.

Agent Creator

Responsible for:

  • Designing the agent
  • Testing functionality
  • Fixing issues
  • Submitting for review

Business Owner

Responsible for:

  • Verifying business value
  • Confirming correct business logic
  • Approving organizational use

IT Administrator

Responsible for:

  • Platform administration
  • Environment configuration
  • Deployment
  • User access

Security Administrator

Responsible for:

  • Permission validation
  • Identity verification
  • Connector review
  • Security assessment

Compliance Administrator

Responsible for:

  • Governance policies
  • Data protection
  • Microsoft Purview compliance
  • Regulatory alignment

What is Reviewed During Approval?

Reviewers typically examine:

Purpose

Does the agent solve a legitimate business problem?


Instructions

Are system instructions clear?

Do they prevent inappropriate behavior?


Knowledge Sources

Are approved sources used?

Examples include:

  • SharePoint
  • Microsoft Graph
  • Dataverse
  • Internal documentation

Actions

Can the agent:

  • Send emails?
  • Update records?
  • Trigger workflows?
  • Access external systems?

Higher-risk actions usually require more careful review.


Permissions

Does the agent only access information users are already authorized to see?

Microsoft 365 security trimming should remain intact.


Connectors

Reviewers verify that external connectors:

  • Are trusted
  • Are approved
  • Meet organizational policies

Privacy

Organizations verify that:

  • Personal data is protected.
  • Confidential information is handled appropriately.
  • AI responses do not expose sensitive content.

Governance During Approval

Agent approval is part of broader AI governance.

Organizations often require:

  • Data classification
  • Sensitivity labels
  • DLP policies
  • Audit logs
  • Risk assessments
  • Periodic reviews

These controls help ensure responsible AI deployment.


Approval vs Publishing

These concepts are different.

Approval means the organization authorizes the agent for deployment.

Publishing makes the approved agent available to users.

An approved agent is not necessarily published immediately.

Likewise, a draft agent cannot be published without completing required approvals (if organizational policies require them).


What Happens After Approval?

Approval is not the end of governance.

Administrators continue to monitor:

  • Usage
  • Adoption
  • Errors
  • User feedback
  • Performance
  • Security events
  • Compliance alerts

Agents may later be:

  • Updated
  • Republished
  • Disabled
  • Archived
  • Deleted

Best Practices

Organizations should:

  • Define a formal approval workflow.
  • Require business ownership.
  • Review data access carefully.
  • Test before publishing.
  • Limit permissions using least privilege.
  • Monitor production usage.
  • Periodically review existing agents.
  • Remove unused or outdated agents.
  • Maintain documentation for governance and auditing.

Exam Tips

For the AB-900 exam, remember these key points:

  • Approval helps ensure agents are secure, compliant, and useful before deployment.
  • Multiple stakeholders—including creators, business owners, IT administrators, security administrators, and compliance administrators—may participate in the approval process.
  • Testing occurs before approval.
  • Publishing occurs after approval.
  • Organizations can customize approval workflows based on governance requirements.
  • Security, permissions, data access, compliance, and business value are common review areas.
  • Agent governance continues after publication through ongoing monitoring and management.

Practice Exam Questions

Question 1

Why do organizations typically require an approval process before publishing custom agents?

A. To reduce deployment speed

B. To ensure the agent meets security, compliance, and business requirements

C. To prevent Microsoft 365 licensing

D. To disable Microsoft Graph access

Answer: B

Explanation: Approval ensures agents are reviewed for security, compliance, data access, and business value before being made available to users.


Question 2

Which activity normally occurs immediately before an agent is submitted for approval?

A. Assigning licenses

B. Deleting old agents

C. Testing the agent

D. Archiving the environment

Answer: C

Explanation: Creators typically validate the agent through testing before requesting formal approval.


Question 3

Which team is primarily responsible for reviewing whether an agent complies with data governance requirements?

A. Marketing

B. Finance

C. Human Resources

D. Compliance administrators

Answer: D

Explanation: Compliance administrators review governance policies, regulatory requirements, data protection, and Microsoft Purview controls.


Question 4

Which aspect is most likely reviewed during an agent approval process?

A. The color theme of Microsoft Teams

B. The Windows desktop wallpaper

C. The user’s internet browser

D. The agent’s permissions and data sources

Answer: D

Explanation: Reviewers verify that permissions and knowledge sources comply with organizational security policies.


Question 5

What is the primary purpose of reviewing an agent’s knowledge sources?

A. To increase processor speed

B. To ensure the agent uses approved organizational information

C. To update Windows

D. To install Microsoft Office

Answer: B

Explanation: Approved knowledge sources help ensure accurate responses while protecting sensitive information.


Question 6

Which statement correctly describes approval and publishing?

A. Publishing always occurs before approval.

B. Approval and publishing are identical.

C. Approval authorizes deployment, while publishing makes the agent available to users.

D. Approval permanently locks the agent.

Answer: C

Explanation: Approval authorizes the agent for release, while publishing distributes it to its intended audience.


Question 7

Who is primarily responsible for confirming that an agent solves the intended business problem?

A. Business owner

B. Printer administrator

C. Network technician

D. Database operator

Answer: A

Explanation: Business owners validate that the agent provides value and meets organizational objectives.


Question 8

Which security principle should agents follow when accessing organizational information?

A. Unlimited access

B. Anonymous authentication

C. Guest-only permissions

D. Least privilege

Answer: D

Explanation: Agents should only access the information necessary for their intended function, following the principle of least privilege.


Question 9

After an agent has been approved and published, what should administrators continue to do?

A. Disable audit logging

B. Ignore user feedback

C. Monitor usage, performance, and compliance

D. Remove all permissions

Answer: C

Explanation: Ongoing monitoring helps ensure the agent remains secure, compliant, and effective as business needs evolve.


Question 10

Which statement best describes organizational approval workflows for agents?

A. Every Microsoft 365 tenant uses the exact same approval process.

B. Approval is optional for all organizations.

C. Approval workflows are fixed and cannot be customized.

D. Organizations can customize approval workflows to meet their governance requirements.

Answer: D

Explanation: Microsoft provides flexible governance capabilities, allowing organizations to implement approval workflows that align with their security, compliance, and operational policies.


Go to the AB-900 Exam Prep Hub main page

Create an agent (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for agents
      --> Create an agent


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

(Microsoft 365 Copilot & Agent Administration Fundamentals)

Agents in the Microsoft 365 Copilot ecosystem are AI-powered assistants that extend Copilot’s capabilities by focusing on specific tasks, organizational knowledge, or business processes. Creating an agent involves defining its purpose, selecting its data sources, configuring its behavior, and publishing it so users can interact with it securely within Microsoft 365 apps.

This topic is central to understanding how administrators and power users enable tailored AI experiences using tools such as Microsoft Copilot Studio and the broader Microsoft 365 ecosystem.


1. What an agent is in Microsoft 365

An agent is a configurable AI experience built on top of Microsoft Copilot that can:

  • Answer domain-specific questions (HR, IT, finance, etc.)
  • Perform guided tasks (ticket creation, policy lookup, onboarding steps)
  • Use organizational data securely (SharePoint, Microsoft Graph, Dataverse)
  • Follow defined instructions and guardrails

Agents can be:

  • Declarative agents (configured with minimal or no-code settings)
  • Custom agents (built and extended in Copilot Studio)
  • Embedded agents (used within apps like Teams or Microsoft 365 Copilot experiences)

2. Where agents are created

Agents can be created in several Microsoft 365-aligned environments:

a. Copilot Studio

The primary tool for building and customizing agents.

Key capabilities:

  • Define agent purpose and instructions
  • Connect knowledge sources
  • Add actions (Power Automate, APIs)
  • Test and publish agents

b. Microsoft 365 Copilot experience

Admins can enable or manage prebuilt or organizational agents that appear in Copilot surfaces.

c. Power Platform environment (under the hood)

Agents often rely on Power Platform components such as:

  • Dataverse
  • Connectors
  • Power Automate flows

3. Prerequisites for creating an agent

Before creating an agent, ensure:

  • Appropriate licensing (Copilot and/or Copilot Studio access)
  • Permissions in the Power Platform environment
  • Access to organizational data sources (e.g., SharePoint sites)
  • Governance policies configured in Microsoft Purview

4. Key steps to create an agent

Step 1: Define the agent purpose

  • Identify the business scenario
  • Determine scope (e.g., HR helpdesk, IT support, sales assistant)

Step 2: Configure instructions

  • Provide system-level behavior guidance
  • Define tone, boundaries, and response rules
  • Specify what the agent should NOT do (important for compliance)

Step 3: Add knowledge sources

Common sources include:

  • SharePoint sites
  • Microsoft Graph data
  • Uploaded documents
  • Structured data (Dataverse tables)

Step 4: Add actions (optional)

Actions extend agent capability:

  • Create tickets in service systems
  • Trigger workflows via Power Automate
  • Query external APIs

Step 5: Test the agent

  • Validate responses in Copilot Studio test environment
  • Check grounding accuracy and hallucination risk
  • Adjust prompts or data sources

Step 6: Publish and share

  • Publish to organizational catalog
  • Assign user or group access
  • Make available in Microsoft 365 Copilot or Teams

5. Governance and control considerations

When creating agents, administrators must ensure:

  • Data access aligns with Microsoft 365 security policies
  • Sensitive data is protected using Purview labels and DLP rules
  • Only authorized users can access specific agents
  • Activity is monitored through Microsoft 365 admin and compliance tools

Agents inherit security trimming, meaning users only see data they already have permission to access.


6. Common exam focus points

You should understand:

  • Difference between Copilot and custom agents
  • Role of Copilot Studio in agent creation
  • Data sources used by agents (SharePoint, Graph, connectors)
  • Publishing and access control methods
  • Governance and compliance alignment

Practice Exam Questions (10)

1. Which tool is primarily used to build and customize Microsoft 365 Copilot agents?

A. Microsoft Teams Admin Center
B. Copilot Studio
C. Microsoft Entra ID
D. SharePoint Admin Center

Answer: B
Copilot Studio is the primary platform for creating and configuring custom Copilot agents, including instructions, knowledge sources, and actions.


2. What is the primary purpose of defining instructions when creating an agent?

A. To assign licenses to users
B. To configure data retention policies
C. To control agent behavior and response style
D. To enable Power BI integration

Answer: C
Instructions define how the agent behaves, including tone, boundaries, and response rules.


3. Which data source is commonly used by agents for organizational knowledge?

A. Microsoft Paint files
B. SharePoint sites
C. Windows Registry
D. Local desktop folders

Answer: B
SharePoint is a primary structured knowledge source used by Copilot agents.


4. What is a key benefit of adding actions to an agent?

A. They replace Microsoft 365 licensing requirements
B. They allow agents to execute workflows and integrate systems
C. They disable security trimming
D. They remove the need for testing

Answer: B
Actions enable agents to perform tasks such as triggering Power Automate flows or calling APIs.


5. Which platform component is commonly used behind agent workflows?

A. Dataverse
B. Windows Defender Firewall
C. Internet Information Services (IIS)
D. Microsoft Paint

Answer: A
Dataverse is often used as part of the Power Platform foundation supporting agents.


6. What happens when an agent is published?

A. It becomes available to assigned users or groups
B. It deletes previous versions automatically
C. It disables Copilot globally
D. It removes SharePoint permissions

Answer: A
Publishing makes the agent available for consumption based on assigned access controls.


7. What principle ensures users only see data they are allowed to access through an agent?

A. Data duplication
B. Security trimming
C. Token caching
D. Load balancing

Answer: B
Security trimming ensures agents respect existing Microsoft 365 permissions.


8. Which Microsoft service helps enforce compliance for data used in agents?

A. Microsoft Purview
B. Microsoft Edge
C. Windows Update
D. Azure DevTest Labs

Answer: A
Microsoft Purview provides governance, labeling, and compliance controls for data used in AI systems.


9. What is the first recommended step when creating a new agent?

A. Publish the agent immediately
B. Define the agent’s purpose and scope
C. Assign users to the agent
D. Add external APIs

Answer: B
Defining purpose ensures the agent is scoped correctly before configuration begins.


10. Where can agents be made available to end users after creation?

A. Only in Power BI dashboards
B. Only in Outlook desktop client
C. Across Microsoft 365 Copilot and integrated apps like Teams
D. Only in Azure portal

Answer: C
Agents can be deployed across Microsoft 365 Copilot experiences and integrated apps such as Teams.


Go to the AB-900 Exam Prep Hub main page

Identify how to configure user access to agents (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for agents
      --> Identify how to configure user access to agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

In Microsoft 365 Copilot, agents are specialized AI assistants designed to perform focused tasks such as answering domain-specific questions, retrieving organizational knowledge, or executing workflows. Because agents can access organizational data and systems, controlling who can use them and under what conditions is a critical administrative responsibility.

Configuring user access ensures that the right users can interact with the right agents while maintaining security, compliance, and least-privilege principles.


1. What “agent access” means

User access to agents determines:

  • Which users can discover an agent
  • Which users can interact with or run an agent
  • Whether an agent is available organization-wide or restricted to specific groups
  • Whether external or guest users can use agents (if allowed)

Access is typically controlled through a combination of:

  • Microsoft 365 identity and access controls
  • Entra ID (Azure AD) group membership
  • Copilot and agent-specific policies

2. Key methods to configure access to agents

A. Assigning access via Microsoft Entra ID groups

One of the most common approaches is group-based access control.

Administrators can:

  • Assign an agent to specific security groups or Microsoft 365 groups
  • Restrict usage to departments (e.g., HR, Finance, IT)
  • Manage access at scale without assigning users individually

Benefits:

  • Scalable management
  • Easier onboarding/offboarding
  • Centralized governance

B. Tenant-wide vs scoped availability

Agents can be configured as:

1. Tenant-wide agents

  • Available to all licensed users in the organization
  • Used for general productivity scenarios (e.g., company policy assistant)

2. Scoped agents

  • Limited to specific users or groups
  • Used for sensitive or department-specific data (e.g., HR policy agent)

C. Role-based access control (RBAC)

Some agent administration actions require specific roles in Microsoft 365 or Entra ID:

  • Global Administrator
  • AI Administrator / Copilot Administrator
  • Service-specific admin roles

RBAC ensures:

  • Only authorized admins can publish or modify agents
  • Governance over agent deployment lifecycle

D. Conditional Access policies

Conditional Access can indirectly control agent usage by enforcing:

  • Device compliance requirements
  • Multi-factor authentication (MFA)
  • Location-based restrictions
  • Risk-based sign-in rules

This ensures that even if a user has access to an agent, they must meet security requirements before using it.


E. Application and permission scopes

Agents may require access to:

  • Microsoft 365 data (SharePoint, Outlook, Teams)
  • External connectors or APIs
  • Graph permissions

Administrators control:

  • What data the agent can access
  • Whether consent is required
  • Whether permissions are user-delegated or app-level

3. Lifecycle considerations for agent access

Provisioning

  • Define target audience (group or tenant-wide)
  • Assign initial permissions
  • Validate compliance requirements

Modification

  • Update group membership to change access
  • Adjust policies as organizational needs evolve

Deprovisioning

  • Remove users or groups when no longer needed
  • Disable or retire the agent if required
  • Ensure data access is revoked appropriately

4. Governance best practices

To securely manage agent access:

  • Use least privilege access (only necessary users/groups)
  • Prefer group-based assignment over individual assignment
  • Regularly review agent usage and permissions
  • Restrict sensitive agents to controlled departments
  • Monitor access logs for unusual activity
  • Align with Microsoft Purview policies where applicable

5. Common use cases

  • HR agent accessible only to HR staff
  • IT helpdesk agent available to all employees
  • Finance reporting agent restricted to finance team
  • Executive summary agent limited to leadership group

6. Key exam takeaway

For AB-900, remember:

  • Agent access is primarily controlled through Entra ID groups, roles, and policies
  • Access can be tenant-wide or scoped
  • Security is enforced through RBAC and Conditional Access
  • Governance ensures agents are only available to the appropriate users

Practice Exam Questions (10)

1.

What is the most common method used to manage user access to Microsoft 365 agents at scale?

A. Individual user assignment
B. Local device policies
C. Entra ID group-based assignment
D. DNS configuration

Answer: C
Explanation: Entra ID group-based assignment is the scalable and recommended way to manage agent access.


2.

Which configuration limits an agent to only HR department users?

A. Tenant-wide publishing
B. Scoped group assignment
C. Public sharing link
D. Guest user activation

Answer: B
Explanation: Scoped assignment using groups restricts access to specific departments like HR.


3.

Which role is typically required to manage Copilot or agent deployment settings?

A. SharePoint Site Owner
B. Global Administrator
C. Teams Guest User
D. Exchange Recipient User

Answer: B
Explanation: Global Administrators (or similar privileged roles) manage high-level agent deployment settings.


4.

What is the purpose of Conditional Access in relation to agent usage?

A. To increase storage capacity
B. To control data indexing speed
C. To enforce security requirements before access
D. To create new agents automatically

Answer: C
Explanation: Conditional Access ensures users meet security conditions like MFA or device compliance.


5.

What happens when a user is removed from an Entra ID group assigned to an agent?

A. They retain permanent access
B. Their access is automatically revoked
C. The agent is deleted
D. The entire tenant loses access

Answer: B
Explanation: Group membership changes immediately affect access to assigned resources, including agents.


6.

Which access model makes an agent available to all licensed users in a tenant?

A. Scoped access
B. Tenant-wide access
C. External sharing mode
D. Device-based access

Answer: B
Explanation: Tenant-wide access allows all licensed users to use the agent.


7.

Which control helps restrict what data an agent can access?

A. Network firewall rules
B. Permission scopes and Graph permissions
C. Printer access policies
D. Windows registry settings

Answer: B
Explanation: Permission scopes define what data and services an agent can access.


8.

What is a key benefit of using group-based access for agents?

A. It disables auditing
B. It simplifies scalable management
C. It removes the need for authentication
D. It bypasses licensing requirements

Answer: B
Explanation: Group-based access simplifies administration, especially in large organizations.


9.

Which scenario best describes proper agent governance?

A. All users can create unrestricted agents
B. Agents are available without authentication
C. Sensitive agents are limited to specific departments
D. Agents bypass compliance policies

Answer: C
Explanation: Sensitive agents should be restricted to appropriate departments for security and compliance.


10.

What is a recommended best practice when configuring access to agents?

A. Assign access individually to each user
B. Use least privilege access principles
C. Allow anonymous access by default
D. Disable group usage entirely

Answer: B
Explanation: Least privilege ensures users only get the access they need, improving security and governance.


Go to the AB-900 Exam Prep Hub main page

Monitor and manage Copilot Pay-as-You-Go billing policies (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for Copilot
      --> Monitor and manage Copilot Pay-as-You-Go billing policies


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft 365 Copilot pay-as-you-go (PAYG) billing policies allow organizations to consume Copilot-related services based on usage rather than only per-user licensing. This model is commonly used for features such as Copilot in SharePoint or other metered AI capabilities where consumption is tracked and billed through an Azure subscription.

Administrators are responsible for configuring, monitoring, and controlling these billing policies to ensure predictable costs, governance, and proper usage.


What is Copilot pay-as-you-go billing?

Pay-as-you-go billing in Microsoft 365 Copilot scenarios enables:

  • Usage-based billing instead of fixed per-user licensing
  • Cost tracking through Azure subscription meters
  • Flexible adoption for specific workloads (for example, SharePoint-based Copilot experiences)
  • Centralized financial control via Azure billing tools

This model is typically associated with Microsoft Copilot experiences that rely on Azure-backed metering.


Key components of PAYG billing policies

1. Azure subscription

All PAYG Copilot usage is billed through an Azure subscription. The subscription:

  • Acts as the billing container
  • Hosts cost management and usage tracking
  • Must be linked to the Microsoft 365 tenant

2. Billing policy configuration

Admins define policies that determine:

  • Which users or groups are enabled for PAYG usage
  • Which Copilot features are billable under PAYG
  • Scope of usage (tenant-wide, group-based, or service-specific)

3. Metered services

Pay-as-you-go applies to specific Copilot capabilities such as:

  • Copilot experiences in SharePoint
  • AI-powered content generation or summarization in supported workloads
  • Feature-specific AI consumption events

Each usage event contributes to measurable consumption units.


How administrators monitor PAYG Copilot usage

Azure Cost Management + Billing

Primary tool used to monitor consumption:

  • Tracks cost per service
  • Shows usage trends
  • Provides budget alerts and forecasting

Microsoft 365 admin center

Used for:

  • Viewing service-level Copilot usage
  • Monitoring adoption and activity reports
  • Understanding organizational usage patterns

Usage analytics dashboards

Administrators can review:

  • Active users consuming PAYG Copilot features
  • Feature-level consumption breakdown
  • Trends over time for optimization

Managing PAYG billing policies

1. Create or configure billing policies

Admins define policies to:

  • Enable PAYG for specific services (e.g., SharePoint Copilot)
  • Assign eligible user groups
  • Control feature access scope

2. Assign policies to users or groups

Instead of enabling all users, organizations often:

  • Assign PAYG access to pilot groups
  • Restrict usage to departments or projects
  • Expand gradually based on adoption

3. Set budgets and alerts

Using Azure Cost Management, administrators can:

  • Set monthly budgets
  • Configure alerts for threshold breaches
  • Prevent unexpected overuse

4. Review and optimize usage

Admins regularly:

  • Identify high-cost usage patterns
  • Adjust policies to reduce unnecessary consumption
  • Disable PAYG access for inactive users or groups

Governance and control considerations

Monitoring PAYG Copilot billing is not only financial—it also includes governance:

  • Ensuring only authorized users can consume metered services
  • Aligning usage with organizational policies
  • Applying Microsoft Entra ID group-based access controls
  • Ensuring compliance with Microsoft Purview policies where applicable

Key differences: PAYG vs per-user Copilot licensing

ModelDescription
Per-user licensingFixed monthly cost per licensed user
Pay-as-you-goUsage-based billing tied to Azure consumption

PAYG is typically more flexible but requires closer monitoring to avoid unexpected costs.


Summary

Monitoring and managing Copilot pay-as-you-go billing policies involves configuring Azure-based billing structures, assigning usage scopes through policies, and continuously tracking consumption using Azure Cost Management and Microsoft 365 reporting tools. Administrators must balance flexibility with cost control and governance to ensure efficient and compliant use of Copilot services.


Practice Exam Questions (10)

1.

Where is Copilot pay-as-you-go usage primarily billed?

A. Microsoft Teams admin center
B. Azure subscription
C. Windows Update service
D. Microsoft Defender portal

Answer: B
Explanation: PAYG Copilot usage is billed through an Azure subscription linked to the tenant.


2.

What is the main purpose of a Copilot pay-as-you-go billing policy?

A. To disable Copilot features globally
B. To assign static per-user licenses
C. To control and define usage-based billing scope
D. To store Copilot chat history

Answer: C
Explanation: Billing policies define who can use PAYG features and how usage is tracked.


3.

Which tool is primarily used to monitor PAYG Copilot costs?

A. Microsoft Word
B. Azure Cost Management + Billing
C. PowerPoint Designer
D. OneDrive sync client

Answer: B
Explanation: Azure Cost Management provides cost tracking, alerts, and reporting.


4.

What is a common use case for Copilot PAYG billing?

A. Permanent licensing for all employees
B. SharePoint-based Copilot experiences with metered usage
C. Offline document editing
D. Local file encryption

Answer: B
Explanation: PAYG is often used for metered Copilot features like SharePoint integration.


5.

What should an administrator configure to control which users can use PAYG Copilot features?

A. Microsoft Teams channels
B. Azure DevOps pipelines
C. Billing policies and assigned user groups
D. Windows Registry settings

Answer: C
Explanation: Policies and group assignments define access to PAYG usage.


6.

What is a key benefit of PAYG billing compared to per-user licensing?

A. Unlimited free usage
B. No need for Microsoft 365 accounts
C. Flexible, usage-based cost model
D. Automatic removal of security policies

Answer: C
Explanation: PAYG provides flexibility by charging based on actual usage.


7.

Which action helps prevent unexpected PAYG Copilot costs?

A. Disabling Microsoft Outlook
B. Setting Azure budgets and alerts
C. Removing all SharePoint sites
D. Turning off Microsoft Entra ID

Answer: B
Explanation: Budgeting and alerts help control spending.


8.

What type of identity is required for users consuming PAYG Copilot features?

A. Local Windows account only
B. Microsoft Entra ID identity
C. Anonymous guest browsing
D. External VPN identity only

Answer: B
Explanation: Copilot services require authenticated Microsoft Entra ID users.


9.

What should administrators regularly review in PAYG billing management?

A. Email signatures
B. Usage trends and cost reports
C. Device firmware versions
D. Printer configurations

Answer: B
Explanation: Usage and cost trends help optimize billing policies.


10.

Which statement best describes PAYG Copilot billing?

A. Fixed monthly cost per organization
B. Free usage for all Microsoft 365 users
C. One-time purchase for lifetime access
D. Consumption-based billing through Azure

Answer: D
Explanation: PAYG is based on measured usage and billed via Azure.


Go to the AB-900 Exam Prep Hub main page

Identify use cases for custom agents (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Identify use cases for custom agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Custom agents in Microsoft 365 Copilot extend Copilot’s built-in capabilities by allowing organizations to create tailored AI assistants focused on specific business processes, data sources, and workflows. Unlike general Copilot experiences, custom agents are designed to operate within defined boundaries, grounded in organizational knowledge and governed data.

What are custom agents?

A custom agent is a specialized AI assistant built on top of Microsoft 365 Copilot that can:

  • Use organization-specific knowledge sources (SharePoint sites, files, Dataverse, web connectors, etc.)
  • Follow predefined instructions and behaviors
  • Perform scoped tasks such as answering domain questions, generating structured outputs, or assisting workflows
  • Operate with Microsoft 365 identity and security controls

They are typically built using tools like Copilot Studio and integrated into Microsoft 365 experiences such as Teams, SharePoint, or Copilot chat.


Key characteristics of custom agents

Custom agents differ from general Copilot usage in several important ways:

They are purpose-built, meaning they are designed for a specific function such as HR support or IT helpdesk assistance. They are also data-grounded, relying on selected enterprise knowledge sources rather than broad internet knowledge.

They are governed, meaning they respect Microsoft 365 permissions, Microsoft Purview policies, and organizational compliance boundaries.

Finally, they are interactive and task-oriented, often guiding users through structured processes rather than only responding to ad-hoc questions.


Common use cases for custom agents

1. HR and employee support agents

Custom HR agents are commonly used to:

  • Answer questions about leave policies, benefits, and onboarding
  • Guide employees through HR workflows
  • Retrieve policy documents from SharePoint or HR systems

This reduces HR ticket volume and improves employee self-service.


2. IT helpdesk and support agents

IT-focused agents can:

  • Troubleshoot common issues (password resets, device setup, VPN access)
  • Provide step-by-step remediation guidance
  • Surface knowledge base articles from internal documentation

These agents help reduce repetitive IT support requests.


3. Sales and customer support agents

Sales agents are used to:

  • Summarize customer accounts and opportunities
  • Retrieve CRM data and product information
  • Generate sales emails or proposals

Customer support agents can also respond to common inquiries using approved knowledge bases.


4. Knowledge management agents

Organizations use agents to:

  • Provide structured access to company policies and documentation
  • Answer questions across multiple SharePoint sites
  • Improve search and discovery of internal content

These agents are especially valuable in large enterprises with distributed knowledge.


5. Finance and operations agents

Custom agents in finance or operations can:

  • Assist with budget tracking queries
  • Explain financial reporting definitions
  • Summarize operational KPIs or dashboards

They typically connect to controlled datasets and reporting systems.


6. Project and workflow assistants

These agents help teams by:

  • Tracking project status updates
  • Summarizing meeting notes
  • Guiding users through standardized workflows (e.g., project intake, approvals)

When to use custom agents vs standard Copilot

Custom agents are most appropriate when:

  • A repeatable business process exists
  • The organization has curated knowledge sources
  • Responses must follow strict formatting or rules
  • Domain-specific accuracy is required (HR, finance, IT, legal)

Standard Copilot is better for:

  • General productivity tasks (writing, summarizing, brainstorming)
  • Ad hoc questions that do not require structured workflows or specialized data

Governance considerations

Custom agents inherit Microsoft 365 security and compliance controls, including:

  • Microsoft Entra ID authentication
  • Microsoft Purview sensitivity labels and DLP policies
  • Role-based access control (RBAC)
  • Data access restricted by user permissions

This ensures agents do not expose information beyond what a user is authorized to see.


Summary

Custom agents in Microsoft 365 Copilot are specialized AI assistants designed for targeted business scenarios. They extend Copilot by adding organizational knowledge, structured workflows, and governance controls. Their primary value lies in automating repetitive tasks, improving knowledge access, and supporting domain-specific processes across departments such as HR, IT, finance, and operations.


Practice Exam Questions (10)

1.

A company wants an assistant that can answer employee questions about vacation policies using only internal HR documents stored in SharePoint. What is the best solution?

A. Use a custom Copilot agent grounded in HR SharePoint content
B. Use Microsoft Excel Copilot only
C. Use a Power BI dashboard
D. Use a generic web Copilot chat

Answer: A
Explanation: A custom agent can be grounded in specific SharePoint HR content and provide controlled, policy-based responses.


2.

Which scenario best represents a use case for a custom agent?

A. Writing a marketing email from scratch
B. Generating creative ideas for a product name
C. Answering general trivia questions
D. Guiding users through an IT password reset workflow

Answer: D
Explanation: IT helpdesk workflows are structured, repeatable, and ideal for custom agents.


3.

What is a key benefit of using custom agents in Microsoft 365 Copilot?

A. They bypass Microsoft security controls for faster responses
B. They only use public internet data
C. They enforce organizational policies and use approved data sources
D. They eliminate the need for user authentication

Answer: C
Explanation: Custom agents respect Microsoft 365 governance and use controlled enterprise data.


4.

A finance team wants an AI tool that summarizes monthly budget reports stored in controlled datasets. Which capability is most appropriate?

A. Custom finance agent grounded in approved financial data
B. Personal Microsoft Word Copilot
C. Bing search integration
D. Email auto-responder rules

Answer: A
Explanation: Finance use cases require structured, governed access to internal datasets.


5.

Which tool is commonly used to create custom agents for Microsoft 365 Copilot?

A. Power Automate only
B. Copilot Studio
C. Azure DevOps
D. Microsoft Access

Answer: B
Explanation: Copilot Studio is used to build and configure custom agents.


6.

What distinguishes a custom agent from standard Microsoft 365 Copilot?

A. It can only work offline
B. It uses only unstructured internet data
C. It is built for specific business scenarios and uses curated data sources
D. It replaces all Microsoft 365 applications

Answer: C
Explanation: Custom agents are scoped to specific business needs and data sources.


7.

Which is a valid HR-related use case for a custom agent?

A. Generating random social media posts
B. Answering employee benefit questions from policy documents
C. Editing video content
D. Running system diagnostics on servers

Answer: B
Explanation: HR agents provide policy-based answers from controlled documentation.


8.

What ensures a custom agent does NOT expose unauthorized data?

A. Internet firewall rules
B. Microsoft Defender antivirus only
C. User identity and Microsoft 365 permissions
D. Manual approval of every prompt

Answer: C
Explanation: Access is controlled through Microsoft Entra ID and existing permissions.


9.

When should a custom agent be preferred over standard Copilot?

A. When tasks are ad hoc and creative
B. When structured workflows and specific business rules are required
C. When browsing public websites
D. When no data sources are needed

Answer: B
Explanation: Custom agents are ideal for structured, repeatable workflows.


10.

Which department would most likely benefit from a knowledge management agent?

A. HR requesting policy document access
B. Users playing games
C. Graphic design teams creating artwork
D. Hardware repair technicians fixing printers

Answer: A
Explanation: Knowledge management agents help retrieve and summarize internal policies and documentation.


Go to the AB-900 Exam Prep Hub main page

Identify use cases for Researcher (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Identify use cases for Researcher


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Researcher is an advanced AI-powered reasoning capability available within the Microsoft 365 Copilot ecosystem. It is designed to perform multi-step, in-depth research tasks that require gathering information from multiple sources, analyzing large amounts of data, synthesizing findings, and presenting comprehensive, well-organized results.

Unlike standard Copilot experiences, which typically generate responses from a single prompt, Researcher performs more sophisticated reasoning by combining enterprise knowledge stored in Microsoft 365 with, when appropriate and permitted, external information sources. It is intended to help users complete tasks that would normally require hours of manual research.

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand:

  • What Researcher is
  • How it differs from standard Microsoft 365 Copilot experiences
  • Typical business scenarios where Researcher provides value
  • The types of data Researcher uses
  • How Microsoft 365 security, permissions, and governance continue to apply
  • The limitations and best practices for using Researcher

What Is Researcher?

Researcher is an advanced AI capability that helps users perform complex research tasks by:

  • Collecting information from multiple sources
  • Comparing information
  • Identifying patterns
  • Summarizing findings
  • Producing structured reports
  • Citing supporting information where applicable
  • Performing iterative reasoning before generating a final response

Rather than simply answering a question, Researcher can develop a complete research workflow.

Example request:

“Prepare a report comparing our organization’s cloud migration strategy with current industry best practices and identify potential risks.”

Instead of providing a brief summary, Researcher may:

  • Review internal project documentation
  • Examine meeting notes
  • Analyze SharePoint documents
  • Review emails
  • Compare current practices with publicly available information (when configured)
  • Produce a detailed report with recommendations

How Researcher Differs from Standard Copilot

Standard Microsoft 365 Copilot focuses primarily on helping users complete everyday productivity tasks such as:

  • Drafting emails
  • Summarizing meetings
  • Creating presentations
  • Rewriting documents
  • Generating tables
  • Answering questions

Researcher extends these capabilities by emphasizing:

  • Multi-step reasoning
  • Long-form research
  • Deep analysis
  • Information synthesis
  • Strategic recommendations
  • Comprehensive reporting

Think of standard Copilot as an AI assistant, while Researcher functions more like an AI research analyst.


Data Sources Used by Researcher

Researcher can analyze information from multiple Microsoft 365 sources, including:

  • SharePoint sites
  • OneDrive files
  • Microsoft Teams conversations
  • Outlook emails
  • Microsoft Word documents
  • Excel workbooks
  • PowerPoint presentations
  • OneNote notebooks
  • Microsoft Graph organizational relationships

Depending on organizational configuration and licensing, Researcher may also incorporate approved external information sources.


Microsoft Graph and Researcher

Researcher relies heavily on Microsoft Graph.

Microsoft Graph provides:

  • Organizational relationships
  • User permissions
  • File locations
  • Emails
  • Meetings
  • Calendar events
  • Conversations
  • Shared documents
  • Collaboration history

Researcher uses Microsoft Graph to locate relevant information efficiently.

Importantly, Researcher never bypasses Microsoft Graph permissions.

If a user cannot access a document, Researcher cannot use it.


Common Business Use Cases

1. Market Research

Researcher can help organizations:

  • Compare competitors
  • Analyze market trends
  • Summarize industry reports
  • Identify emerging technologies
  • Evaluate customer behavior

Example:

“Research the latest AI adoption trends in financial services.”


2. Executive Briefings

Executives often require concise summaries from large volumes of information.

Researcher can:

  • Summarize multiple meetings
  • Combine reports
  • Review emails
  • Produce executive-ready briefing documents

3. Project Research

Large projects often generate hundreds of documents.

Researcher can help summarize:

  • Requirements
  • Risks
  • Decisions
  • Milestones
  • Meeting notes
  • Design documents

Instead of reading dozens of files manually, Researcher consolidates the information.


4. Policy Analysis

Organizations frequently maintain hundreds of internal policies.

Researcher can:

  • Compare policies
  • Identify inconsistencies
  • Summarize requirements
  • Highlight missing documentation

5. Compliance Research

Researcher can assist with:

  • Reviewing compliance documentation
  • Summarizing regulatory guidance
  • Comparing policies against standards
  • Organizing compliance evidence

It does not replace formal compliance or legal reviews.


6. Sales Preparation

Sales teams can use Researcher to prepare for customer meetings by combining:

  • Previous emails
  • Meeting notes
  • Proposal documents
  • Customer presentations
  • Product documentation

The result is a comprehensive customer briefing.


7. Product Research

Product managers may ask Researcher to:

  • Compare product requirements
  • Analyze customer feedback
  • Summarize bug reports
  • Review feature requests
  • Recommend priorities

8. Knowledge Discovery

Employees often spend significant time searching for information.

Researcher can locate and combine information from:

  • Multiple SharePoint sites
  • Teams chats
  • Emails
  • Documents
  • Internal knowledge bases

This significantly reduces research time.


9. Strategic Planning

Leadership teams may ask Researcher to:

  • Compare business strategies
  • Analyze organizational performance
  • Review previous planning documents
  • Summarize lessons learned
  • Generate strategic recommendations

10. Report Generation

Researcher can generate:

  • Research reports
  • Project summaries
  • Risk analyses
  • Business cases
  • Recommendation documents
  • Decision-support reports

How Researcher Protects Organizational Data

Researcher follows the same Microsoft 365 security model as Microsoft 365 Copilot.

It respects:

  • Microsoft Graph permissions
  • SharePoint permissions
  • OneDrive permissions
  • Teams permissions
  • Microsoft Purview sensitivity labels
  • Data Loss Prevention (DLP) policies
  • Retention policies
  • Microsoft Defender protections

Researcher cannot retrieve information users are not authorized to access.


Benefits of Researcher

Organizations benefit because Researcher can:

  • Reduce manual research time
  • Improve decision-making
  • Consolidate information from multiple sources
  • Produce consistent reports
  • Improve knowledge discovery
  • Increase employee productivity
  • Reduce duplicate work
  • Accelerate project planning

Limitations of Researcher

Although powerful, Researcher has limitations.

It:

  • Only accesses authorized data.
  • Depends on data quality.
  • Cannot invent missing information.
  • May produce incomplete answers if source data is incomplete.
  • Does not replace human judgment.
  • Does not override organizational permissions.
  • Cannot bypass compliance policies.
  • Should not be considered a legal or regulatory authority.

Users should always review AI-generated conclusions before making important business decisions.


Best Practices

Microsoft recommends that organizations:

  • Ensure SharePoint permissions are accurate before deployment.
  • Apply Microsoft Purview sensitivity labels consistently.
  • Implement DLP policies.
  • Organize content with meaningful names and metadata.
  • Maintain high-quality documentation.
  • Encourage users to write specific research prompts.
  • Review AI-generated reports before distribution.
  • Train employees on responsible AI usage.
  • Monitor adoption and usage.
  • Continuously improve information governance.

Exam Tips

For the AB-900 exam, remember these key points:

  • Researcher is designed for complex, multi-step research tasks, not simple productivity tasks.
  • It uses Microsoft Graph to locate organizational information.
  • It respects all existing Microsoft 365 permissions.
  • Microsoft Purview policies continue to protect data.
  • Researcher can combine information from multiple Microsoft 365 services.
  • It supports report creation, analysis, and decision-making.
  • Human review remains important for critical decisions.
  • Researcher improves productivity but does not replace subject matter expertise.

10 Practice Exam Questions

Question 1

Which type of task is Researcher primarily designed to perform?

A. Multi-step research and analysis across multiple data sources

B. Installing Microsoft 365 applications

C. Managing user licenses

D. Configuring SharePoint permissions

Correct Answer: A

Explanation: Researcher is intended for advanced research, reasoning, and analysis that combines information from multiple sources into comprehensive results.


Question 2

How does Researcher locate relevant organizational content?

A. By ignoring file permissions

B. By using Microsoft Graph to identify accessible organizational data

C. By copying data into a separate database

D. By downloading every SharePoint site locally

Correct Answer: B

Explanation: Researcher relies on Microsoft Graph to discover relationships, files, emails, meetings, and other Microsoft 365 content while respecting user permissions.


Question 3

Which scenario is the best use case for Researcher?

A. Changing a user’s password

B. Assigning Microsoft 365 licenses

C. Comparing multiple project documents and generating a strategic summary

D. Creating a new SharePoint site

Correct Answer: C

Explanation: Researcher excels at analyzing multiple documents and producing synthesized reports or recommendations.


Question 4

Which Microsoft 365 security principle applies to Researcher?

A. Researcher automatically grants access to restricted documents.

B. Researcher temporarily elevates user permissions.

C. Researcher ignores sensitivity labels during analysis.

D. Researcher only accesses content the user is already authorized to view.

Correct Answer: D

Explanation: Researcher follows the same permission model as Microsoft 365 Copilot and cannot access unauthorized content.


Question 5

Which Microsoft technology provides the organizational relationships that Researcher uses?

A. Microsoft Defender

B. Microsoft Entra ID

C. Microsoft Graph

D. Microsoft Intune

Correct Answer: C

Explanation: Microsoft Graph connects users, files, meetings, emails, calendars, and collaboration data that Researcher uses during analysis.


Question 6

Which business activity is a common use case for Researcher?

A. Replacing Microsoft Purview

B. Producing executive briefing reports by combining information from multiple Microsoft 365 sources

C. Managing Azure subscriptions

D. Configuring firewall rules

Correct Answer: B

Explanation: Researcher can consolidate organizational information into executive-ready reports and summaries.


Question 7

What limits the information that Researcher can include in its responses?

A. Internet bandwidth only

B. Microsoft licensing costs only

C. The amount of SharePoint storage available

D. The user’s existing Microsoft 365 permissions and governance policies

Correct Answer: D

Explanation: Researcher can only use data that the requesting user is authorized to access, and it remains subject to governance controls.


Question 8

Which Microsoft Purview capability continues protecting organizational information when Researcher accesses documents?

A. Sensitivity labels and Data Loss Prevention (DLP) policies

B. Printer management

C. Windows Update

D. Device drivers

Correct Answer: A

Explanation: Microsoft Purview policies, including sensitivity labels and DLP, remain fully enforced when Researcher accesses organizational content.


Question 9

Why should users review Researcher-generated reports before acting on them?

A. Researcher cannot create reports.

B. AI-generated findings should be validated because human judgment is still required for important decisions.

C. Researcher always produces incorrect results.

D. Researcher automatically changes organizational data.

Correct Answer: B

Explanation: While Researcher can significantly accelerate analysis, users remain responsible for verifying conclusions and making informed decisions.


Question 10

Which statement best describes Researcher compared to standard Microsoft 365 Copilot?

A. Researcher replaces Microsoft Graph.

B. Researcher is only available in Microsoft Teams.

C. Researcher focuses on deep research, multi-step reasoning, and comprehensive analysis rather than routine productivity tasks.

D. Researcher only summarizes email messages.

Correct Answer: C

Explanation: Standard Copilot primarily assists with day-to-day productivity, whereas Researcher specializes in complex analysis, reasoning, and report generation.


Go to the AB-900 Exam Prep Hub main page

Compare Copilot monthly license model to Pay-as-You-Go, including SharePoint (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Compare Copilot monthly license model to Pay-as-You-Go, including SharePoint


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft offers multiple licensing models for AI experiences across Microsoft 365. Understanding these licensing options is important for administrators who plan deployments, manage costs, and determine which AI capabilities are available to users.

For the AB-900 exam, you should understand the differences between:

  • Microsoft 365 Copilot monthly user licensing
  • Pay-as-you-go (consumption-based) licensing
  • SharePoint Copilot licensing
  • When each licensing model is appropriate

The exam focuses on understanding the concepts rather than memorizing pricing.


Why Multiple Licensing Models Exist

Organizations vary greatly in how employees use AI.

Some organizations:

  • Have employees who use AI all day.
  • Need AI integrated into Microsoft 365 apps.
  • Require predictable monthly costs.

Other organizations:

  • Use AI occasionally.
  • Need specialized agents.
  • Want to pay only when AI is used.

Microsoft therefore offers both subscription-based and consumption-based licensing.


Microsoft 365 Copilot Monthly License Model

The traditional Microsoft 365 Copilot license is assigned to individual users.

Each licensed user receives access to Copilot experiences across supported Microsoft 365 applications.

Examples include:

  • Word
  • Excel
  • PowerPoint
  • Outlook
  • Teams
  • OneNote
  • Microsoft 365 Chat

The license is:

  • Assigned per user
  • Monthly subscription
  • Predictable recurring cost

Characteristics of the Monthly License

The monthly model provides:

  • Full Microsoft 365 Copilot experience
  • Unlimited daily usage (subject to service limits)
  • Personalized AI assistance
  • Microsoft Graph integration
  • Cross-app experiences
  • Enterprise security and compliance

This model is best for employees who regularly use Copilot throughout their workday.


Typical Monthly License Scenario

A financial analyst uses Copilot every day to:

  • Analyze Excel workbooks
  • Draft reports
  • Summarize meetings
  • Create PowerPoint presentations
  • Search organizational knowledge

Because AI is used continuously, a monthly license provides predictable costs.


Benefits of Monthly Licensing

Advantages include:

  • Predictable budgeting
  • No need to monitor consumption
  • Continuous access
  • Simplified administration
  • Consistent user experience
  • Ideal for heavy users

Limitations of Monthly Licensing

Considerations include:

  • Fixed monthly cost regardless of usage
  • Not ideal for occasional users
  • Every user requires their own license
  • Organizations may over-license infrequent users

Pay-as-You-Go Licensing

Pay-as-you-go (PAYG) is a consumption-based licensing model.

Instead of paying for every user every month, organizations pay based on actual AI usage.

Think of it similarly to cloud computing services:

  • More usage = higher cost
  • Less usage = lower cost

Characteristics of Pay-as-You-Go

Pay-as-you-go provides:

  • Usage-based billing
  • Flexible scaling
  • No requirement for every user to have a monthly Copilot license
  • Cost based on AI requests or service consumption (depending on the service)

This model is especially useful for agents and certain AI scenarios.


Benefits of Pay-as-You-Go

Advantages include:

  • Lower upfront costs
  • Pay only for actual usage
  • Flexible deployment
  • Easy experimentation
  • Ideal for seasonal workloads
  • Good for occasional users

Limitations of Pay-as-You-Go

Potential drawbacks include:

  • Variable monthly costs
  • Budget forecasting is more difficult
  • Requires monitoring usage
  • Heavy usage may become more expensive than subscription licensing

Comparing Monthly Licensing and Pay-as-You-Go

Monthly LicensePay-as-You-Go
Fixed monthly costUsage-based cost
Licensed per userConsumption-based
Predictable budgetingVariable spending
Best for daily usersBest for occasional use
Continuous Copilot accessPay only when AI is used
Simpler cost managementRequires usage monitoring

Microsoft 365 Copilot Chat

Organizations should understand that Microsoft offers AI experiences beyond the traditional monthly Copilot license.

For example:

  • Microsoft 365 Copilot Chat is available to Microsoft 365 users.
  • Organizations can extend Copilot Chat with agents.
  • Some agent usage can be billed using pay-as-you-go licensing rather than requiring every user to have a full Copilot subscription.

This provides flexibility for organizations with mixed AI usage patterns.


SharePoint and Copilot

SharePoint includes AI capabilities that help users work with documents, sites, and organizational knowledge.

Examples include:

  • Summarizing documents
  • Answering questions about files
  • Generating page content
  • Assisting with document creation
  • Improving knowledge discovery

SharePoint Agents

One important capability is SharePoint agents.

A SharePoint agent can:

  • Be created from a SharePoint site or document library
  • Answer questions using approved SharePoint content
  • Help users locate organizational knowledge
  • Reduce the need to manually search documents

For example:

A Human Resources SharePoint site may contain:

  • Employee handbook
  • Benefits guide
  • Leave policies
  • Training documents

An HR SharePoint agent can answer employee questions using those documents.


SharePoint Pay-as-You-Go

Organizations can use SharePoint agents without assigning every user a full Microsoft 365 Copilot license.

Instead, administrators can configure consumption-based billing.

Benefits include:

  • Lower cost for occasional users
  • Easy pilot deployments
  • Department-specific AI
  • Flexible scaling

This makes SharePoint agents attractive for organizations wanting targeted AI experiences without licensing every employee.


Choosing the Right Licensing Model

Choose Monthly Licensing When

  • Employees use Copilot every day.
  • AI is integrated into daily workflows.
  • Predictable monthly budgeting is important.
  • Users need full Copilot functionality across Microsoft 365.

Examples:

  • Executives
  • Project managers
  • Analysts
  • Consultants
  • Sales professionals
  • Knowledge workers

Choose Pay-as-You-Go When

  • AI usage is occasional.
  • Organizations are testing AI.
  • Departments need specialized agents.
  • Seasonal usage is expected.
  • Budget flexibility is acceptable.

Examples:

  • HR help desk agent
  • Legal document agent
  • IT support chatbot
  • SharePoint knowledge assistant

Administrative Considerations

Administrators should evaluate:

  • Expected AI usage
  • Number of users
  • Cost predictability
  • Department requirements
  • Governance policies
  • Licensing strategy
  • Agent deployment plans

Security Remains the Same

Regardless of licensing model:

  • Microsoft Entra ID authentication is used.
  • Microsoft Graph permissions are enforced.
  • Microsoft Purview policies apply.
  • Data Loss Prevention (DLP) policies remain active.
  • Sensitivity labels continue protecting content.
  • Microsoft Defender protections remain in effect.

Licensing changes how organizations pay for AI—not how Microsoft secures organizational data.


Best Practices

Microsoft recommends that organizations:

  • License frequent users with Microsoft 365 Copilot subscriptions.
  • Use pay-as-you-go for occasional AI usage.
  • Monitor AI adoption and consumption.
  • Start with pilot deployments.
  • Evaluate SharePoint agents for departmental knowledge scenarios.
  • Review licensing regularly as adoption increases.

Exam Tips

For the AB-900 exam, remember these key points:

  • Microsoft 365 Copilot is commonly licensed per user with a monthly subscription.
  • Pay-as-you-go bills organizations based on AI usage.
  • Monthly licensing provides predictable costs.
  • Pay-as-you-go offers flexibility for occasional or specialized AI use.
  • SharePoint agents can be deployed using consumption-based licensing in supported scenarios.
  • Licensing affects billing—not security or permissions.
  • Microsoft Graph, Microsoft Purview, and Microsoft Entra ID protections apply regardless of licensing model.
  • Heavy AI users are generally better suited to monthly licensing.
  • Departmental or pilot AI deployments often benefit from pay-as-you-go.

Practice Exam Questions

Question 1

Which licensing model provides users with a predictable monthly cost for Microsoft 365 Copilot?

A. Pay-as-you-go
B. Monthly per-user license
C. Azure consumption credits
D. SharePoint storage licensing

Correct Answer: B

Explanation: A monthly per-user license provides continuous access to Microsoft 365 Copilot for a fixed monthly subscription.


Question 2

What is the primary advantage of the pay-as-you-go licensing model?

A. Users receive unlimited AI usage regardless of activity.
B. Organizations pay only for actual AI usage.
C. Every employee automatically receives Microsoft 365 Copilot.
D. It disables Microsoft Graph integration.

Correct Answer: B

Explanation: Pay-as-you-go charges based on consumption, making it suitable for occasional or specialized AI usage.


Question 3

Which type of user is generally the best candidate for a Microsoft 365 Copilot monthly license?

A. An employee who rarely uses Microsoft 365 applications
B. A seasonal contractor who accesses AI once a month
C. A knowledge worker who uses Copilot throughout the workday
D. A visitor with guest access to SharePoint

Correct Answer: C

Explanation: Heavy or daily users benefit from the predictable costs and continuous access provided by the monthly licensing model.


Question 4

An organization wants to deploy an HR SharePoint agent that employees will use occasionally. Which licensing model is often the better fit?

A. Monthly Copilot license for every employee
B. Windows Enterprise licensing
C. Exchange Online licensing
D. Pay-as-you-go

Correct Answer: D

Explanation: Pay-as-you-go is well suited for departmental agents with occasional usage, allowing organizations to pay based on consumption.


Question 5

Which statement about Microsoft 365 Copilot monthly licensing is correct?

A. It charges only when AI is used.
B. It is assigned to individual users as a subscription.
C. It replaces Microsoft Entra ID.
D. It is available only for SharePoint.

Correct Answer: B

Explanation: The traditional Microsoft 365 Copilot model is licensed per user through a recurring subscription.


Question 6

Which capability is commonly associated with SharePoint agents?

A. Managing Windows updates
B. Replacing Microsoft Graph
C. Answering questions using SharePoint content and document libraries
D. Creating Azure virtual machines

Correct Answer: C

Explanation: SharePoint agents are grounded in SharePoint content and help users locate and understand organizational knowledge.


Question 7

How do Microsoft Purview policies behave when an organization switches from monthly licensing to pay-as-you-go?

A. They are automatically disabled.
B. They apply only to SharePoint documents.
C. They require users to purchase additional licenses before functioning.
D. They continue to protect data regardless of the licensing model.

Correct Answer: D

Explanation: Security and compliance controls such as Microsoft Purview continue to protect data regardless of how AI services are licensed.


Question 8

Which licensing model generally provides the most predictable monthly budgeting?

A. Pay-as-you-go
B. Monthly per-user licensing
C. Azure Reserved Instances
D. SharePoint storage quotas

Correct Answer: B

Explanation: Monthly licensing offers a fixed recurring cost, simplifying budgeting and financial planning.


Question 9

What is a potential disadvantage of pay-as-you-go licensing?

A. It cannot be used with agents.
B. It prevents users from accessing SharePoint.
C. Monthly costs may vary depending on AI usage.
D. It disables Microsoft Graph permissions.

Correct Answer: C

Explanation: Consumption-based billing means costs fluctuate according to actual usage, making budgeting less predictable.


Question 10

Which statement best summarizes the difference between Microsoft 365 Copilot monthly licensing and pay-as-you-go?

A. Monthly licensing is subscription-based, while pay-as-you-go is consumption-based.
B. Monthly licensing does not include Microsoft Graph.
C. Pay-as-you-go removes Microsoft Purview protections.
D. Monthly licensing is only available for SharePoint.

Correct Answer: A

Explanation: The fundamental difference is the billing model: monthly licensing charges a fixed subscription per user, whereas pay-as-you-go charges based on actual AI service consumption.


Go to the AB-900 Exam Prep Hub main page

Compare the built-in capabilities of Copilot and agents (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Compare the built-in capabilities of Copilot and agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft 365 provides powerful AI capabilities through Microsoft 365 Copilot and agents. Although they are closely related, they serve different purposes.

A common misconception is that Copilot and agents are the same technology. In reality:

  • Microsoft 365 Copilot is the AI assistant that helps users work across Microsoft 365 applications.
  • Agents are specialized AI assistants designed to perform focused tasks, automate business processes, or provide expertise in specific domains.

Understanding the differences between Copilot and agents is an important objective on the AB-900 exam.


What is Microsoft 365 Copilot?

Microsoft 365 Copilot is Microsoft’s AI assistant integrated throughout Microsoft 365 applications.

It combines:

  • Large Language Models (LLMs)
  • Microsoft Graph
  • Microsoft 365 data
  • User permissions
  • Organizational knowledge

Copilot helps users complete everyday work faster while respecting existing security permissions.

Examples include:

  • Drafting emails
  • Summarizing meetings
  • Creating PowerPoint presentations
  • Analyzing Excel data
  • Writing Word documents
  • Answering natural language questions
  • Summarizing Teams chats

Copilot is designed to improve personal productivity across many different tasks.


What are Microsoft 365 Agents?

Agents are AI assistants created to perform specialized or repeatable business tasks.

Rather than serving as a general assistant, an agent focuses on a specific job.

Examples include:

  • HR policy assistant
  • IT help desk assistant
  • Sales proposal assistant
  • Customer service assistant
  • Legal document assistant
  • Procurement assistant
  • Finance assistant

Agents can:

  • Answer questions from approved knowledge sources
  • Follow business rules
  • Guide users through processes
  • Complete multi-step workflows
  • Connect to business systems

Comparing Copilot and Agents

Microsoft 365 CopilotMicrosoft 365 Agents
General-purpose AI assistantSpecialized AI assistant
Works across Microsoft 365Focuses on a specific business task
Assists individual productivityAssists business processes
Uses Microsoft Graph extensivelyCan use Graph plus additional knowledge sources
Available in Microsoft 365 appsCan be published inside Teams, Microsoft 365, SharePoint, and other experiences
Broad conversational abilitiesDomain-specific expertise

Built-in Capabilities of Microsoft 365 Copilot

Copilot includes many built-in features without requiring customization.

Content Creation

Copilot can:

  • Draft documents
  • Rewrite text
  • Summarize documents
  • Change writing tone
  • Generate presentations
  • Create outlines
  • Brainstorm ideas

Example:

“Create a proposal for a new customer.”


Meeting Intelligence

Within Microsoft Teams, Copilot can:

  • Summarize meetings
  • Capture decisions
  • List action items
  • Answer questions about the meeting
  • Identify unresolved issues

Example:

“What decisions were made during yesterday’s meeting?”


Email Assistance

In Outlook, Copilot can:

  • Draft responses
  • Summarize long email threads
  • Suggest follow-up actions
  • Improve writing style

Data Analysis

Within Excel, Copilot can:

  • Explain formulas
  • Generate charts
  • Analyze trends
  • Identify outliers
  • Create summaries

Example:

“Show quarterly sales trends.”


Knowledge Discovery

Copilot searches organizational knowledge using Microsoft Graph.

It can answer questions such as:

  • “What projects am I working on?”
  • “Summarize documents related to Project Apollo.”
  • “What files has my manager recently shared?”

Cross-Application Context

One major capability is connecting information across applications.

Example:

Copilot may combine information from:

  • Outlook
  • Teams
  • Word
  • OneDrive
  • SharePoint
  • Calendar

to answer a single prompt.


Built-in Capabilities of Agents

Agents focus on completing specialized work.


Task-Specific Expertise

An agent is trained or configured around one topic.

Examples:

HR Agent

  • Vacation policy
  • Benefits
  • Employee handbook

IT Agent

  • Password reset guidance
  • Software installation
  • Device troubleshooting

Finance Agent

  • Expense reimbursement
  • Budget approval
  • Procurement rules

Business Process Guidance

Agents can walk users through business procedures.

Example:

Instead of simply answering a question, an HR onboarding agent can:

  • Explain required forms
  • Guide new employees
  • Answer benefits questions
  • Provide training links

Knowledge Grounding

Agents can use approved organizational knowledge.

Examples include:

  • SharePoint libraries
  • Internal documents
  • Knowledge bases
  • Business manuals
  • Policies
  • FAQs

Unlike general internet chatbots, agents only answer from approved sources.


Workflow Automation

Agents can perform multiple steps automatically.

Example:

A travel request agent might:

  • Collect travel details
  • Validate policy
  • Request manager approval
  • Submit the request
  • Notify the employee

Connectors

Agents can connect to external business systems.

Examples:

  • Dynamics 365
  • ServiceNow
  • Salesforce
  • SAP
  • Workday
  • Microsoft Dataverse

This allows agents to retrieve business information securely.


Consistent Business Responses

Unlike free-form conversations, agents provide consistent answers based on organizational knowledge.

This reduces confusion and improves compliance.


Shared Capabilities

Both Copilot and agents share many AI features.

These include:

  • Natural language interaction
  • Context-aware conversations
  • AI-generated responses
  • Respect for Microsoft Entra ID permissions
  • Security trimming
  • Microsoft Graph integration (where applicable)
  • Use of Large Language Models
  • Support for Microsoft 365 security and compliance controls

Key Differences

Scope

Copilot

Broad productivity assistant.

Agent

Focused business assistant.


Purpose

Copilot

Helps users complete work.

Agent

Helps complete specific business processes.


Knowledge

Copilot

Uses Microsoft Graph plus organizational content.

Agent

Uses selected knowledge sources chosen by administrators or creators.


Customization

Copilot

Little customization required.

Agents

Often customized for departments or business scenarios.


Reusability

Copilot

Same assistant for everyone (subject to permissions).

Agents

Different agents can exist for different teams.

Examples:

  • Legal Agent
  • Sales Agent
  • Finance Agent
  • HR Agent

Copilot vs. Agent Example

A user asks:

“I need to prepare for a customer renewal.”

Copilot might:

  • Summarize recent emails
  • Review meeting notes
  • Draft a proposal
  • Create a PowerPoint

A Sales Agent might:

  • Retrieve CRM information
  • Check renewal status
  • Calculate discounts
  • Recommend pricing
  • Generate renewal documentation

Both assist the user—but in different ways.


Security

Both Copilot and agents follow Microsoft security principles.

They respect:

  • Microsoft Entra ID authentication
  • User permissions
  • Microsoft Graph security trimming
  • Microsoft Purview sensitivity labels
  • Data Loss Prevention (DLP) policies
  • Conditional Access policies
  • Compliance controls

Neither Copilot nor agents expose information users are not authorized to access.


Common Exam Tips

Remember these distinctions:

  • Copilot is a general-purpose AI assistant.
  • Agents are specialized assistants for business scenarios.
  • Copilot improves productivity across Microsoft 365.
  • Agents automate or simplify specific business tasks.
  • Both use natural language.
  • Both respect existing Microsoft 365 permissions.
  • Agents can connect to external business systems.
  • Multiple agents can exist within the same organization.
  • Copilot does not replace business applications—it works with them.
  • Administrators govern both using Microsoft 365 security and compliance controls.

Practice Exam Questions

Question 1

What is the primary purpose of Microsoft 365 Copilot?

A. Replace business applications
B. Provide a general AI assistant across Microsoft 365 applications
C. Manage Microsoft Entra ID users
D. Automatically configure SharePoint permissions

Correct Answer: B

Explanation: Microsoft 365 Copilot is a general-purpose AI assistant that enhances productivity across Microsoft 365 applications.


Question 2

Which scenario is best suited for a Microsoft 365 agent?

A. Creating a PowerPoint presentation from meeting notes
B. Summarizing an Outlook inbox
C. Guiding employees through HR onboarding procedures
D. Drafting a Word document

Correct Answer: C

Explanation: Agents are designed for specialized business tasks such as HR onboarding, IT support, or finance workflows.


Question 3

Which feature is shared by both Microsoft 365 Copilot and agents?

A. They ignore Microsoft Entra permissions.
B. They require internet searches for every response.
C. They automatically grant file access.
D. They support natural language conversations.

Correct Answer: D

Explanation: Both Copilot and agents use conversational AI, allowing users to interact using natural language.


Question 4

Which capability is unique to many business agents?

A. Creating Word documents
B. Summarizing Teams meetings
C. Performing specialized workflows using business systems
D. Rewriting email messages

Correct Answer: C

Explanation: Agents can automate specialized business workflows and connect with enterprise systems.


Question 5

Microsoft 365 Copilot primarily retrieves organizational information through:

A. Microsoft Graph
B. Azure Virtual Desktop
C. Windows Registry
D. Local device storage

Correct Answer: A

Explanation: Microsoft Graph provides Copilot with secure access to organizational data while respecting user permissions.


Question 6

Which statement best describes Microsoft 365 agents?

A. They replace Microsoft Graph.
B. They are designed for focused business scenarios and specialized tasks.
C. They only answer questions about Microsoft products.
D. They are available only in Outlook.

Correct Answer: B

Explanation: Agents are purpose-built AI assistants that support specific business processes or departmental functions.


Question 7

How do Copilot and agents protect organizational data?

A. They bypass file permissions for administrators.
B. They make all SharePoint content searchable.
C. They respect existing Microsoft 365 permissions and compliance controls.
D. They permanently copy data into AI models.

Correct Answer: C

Explanation: Both solutions honor Microsoft Entra ID permissions, Microsoft Graph security trimming, and Microsoft Purview governance policies.


Question 8

Which task would Microsoft 365 Copilot most likely perform?

A. Reset a user’s Active Directory password automatically.
B. Analyze an Excel workbook and explain sales trends.
C. Replace the organization’s CRM system.
D. Configure Conditional Access policies.

Correct Answer: B

Explanation: Copilot excels at productivity tasks such as analyzing Excel data and generating insights.


Question 9

An organization creates separate HR, Legal, and Finance AI assistants. These are examples of:

A. Microsoft Graph connectors
B. SharePoint hubs
C. Copilot prompts
D. Specialized agents

Correct Answer: D

Explanation: Organizations can build multiple specialized agents tailored to different departments and business functions.


Question 10

What is one of the biggest differences between Microsoft 365 Copilot and agents?

A. Copilot is a broad productivity assistant, while agents focus on specific business tasks.
B. Agents do not use AI.
C. Copilot ignores Microsoft 365 permissions.
D. Agents cannot access organizational knowledge.

Correct Answer: A

Explanation: Copilot provides broad productivity assistance across Microsoft 365, whereas agents are designed for specialized business scenarios and targeted workflows.


Go to the AB-900 Exam Prep Hub main page