Tag: Microsoft 365 Copilot

Exam Prep Hub for AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals

Welcome to the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub!

Welcome to the one-stop hub with information for preparing for the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals certification exam. The content for this exam helps prepare you to “understand Microsoft 365 services, admin tools, core objects, core security features, and modern AI-driven IT management practices”.
Upon successful completion of the exam, you earn the Microsoft 365 Certified: Copilot and Agent Administration Fundamentals certification.

This hub provides information directly here (topic-by-topic as outlined in the official study guide), links to a number of external resources, tips for preparing for the exam, practice tests, and section questions to help you prepare. Bookmark this page and use it as a guide to ensure that you are fully covering all relevant topics for the AB-900 exam and making use of as many of the resources available as possible.


Audience profile (from Microsoft’s site)

As a candidate for this Microsoft Certification, you should be familiar with Microsoft 365, including core services, security, identity and access, data protection, and governance, along with Microsoft 365 Copilot and agents.
Additionally, you should be familiar with the admin centers used to access Microsoft 365 workloads, such as Exchange Online, SharePoint in Microsoft 365, Microsoft Teams, Microsoft Entra, and Microsoft Purview. You need to have experience with AI-driven productivity tools and modern IT management practices.
You must be able to identify the roles of the core features and objects available in Microsoft 365, such as users, groups, teams, sites, and libraries. Plus, you should understand the core security features of Microsoft 365, such as authentication methods, conditional access policies, and single sign-on (SSO).

Skills at a glance (as specified in the official study guide)

  • Identify the core features and objects of Microsoft 365 services (30–35%)
  • Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
  • Perform basic administrative tasks for Copilot and agents (25–30%)

Topic-by-Topic Exam Content

[click a topic link to access the content and practice questions for that topic]

Identify the core features and objects of Microsoft 365 services (30–35%)

Identify the core objects of Microsoft 365 services

Understand the Microsoft 365 security principles

Identify the core security features of Microsoft 365 services

Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)

Understand Microsoft Purview

Understand data security implications of Copilot

Identify data protection and governance risks for Microsoft 365 and Copilot

Identify and monitor oversharing in SharePoint in Microsoft 365

Perform basic administrative tasks for Copilot and agents (25–30%)

Understand features and capabilities of Copilot and agents

Perform basic administrative tasks for Copilot

Perform basic administrative tasks for agents


AB-900 Practice Exams


Important AB-900 Resources

Link to the free, comprehensive, self-paced course on Microsoft Learn: Introduction to Microsoft 365 and AI administration

https://learn.microsoft.com/en-us/training/courses/ab-900t00

This course has two learning paths:

(1) The first learning path is: Explore Microsoft 365 administration, located at this URL:
https://learn.microsoft.com/en-us/training/paths/explore-microsoft-365-administration

This learning path has 3 modules, located at the below URLs:

(2) The second learning path is: Explore Microsoft 365 Copilot and agent administration, located at this URL:
https://learn.microsoft.com/en-us/training/paths/explore-microsoft-365-copilot-agent-administration

This learning path has 3 modules, located at the below URLs:

Link to the certification page:

Link to the study guide:


YouTube resources:

Courses: There are several highly rated courses for AB-900 on Udemy:

Check out the previews of each course to decide which trainer is best for you. And a tip for you … if your timeline allows it, wait for the occasional Udemy sale and buy your course(s) then.


Good luck to you passing the AB-900 Exam!
However, the more preparation you have, the less luck you will need. 🙂

Visit this post to see the list of all the certification preparation hubs available on The Data Community.

Understand the approval process for agents (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for agents
      --> Understand the approval process for agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

As organizations increasingly adopt Microsoft 365 Copilot and AI-powered agents, governance becomes just as important as functionality. Without proper oversight, users could inadvertently create agents that expose sensitive information, perform unintended actions, or fail to comply with organizational policies.

For this reason, Microsoft provides an approval process that enables organizations to review, validate, and govern agents before they are made available to users. While the exact approval workflow depends on the type of agent, the organization’s governance policies, and the deployment platform (such as Microsoft Copilot Studio), administrators should understand how approval processes help ensure that agents are secure, compliant, and aligned with business requirements.

For the AB-900 exam, you are not expected to know every detailed configuration step, but you should understand why approvals exist, when they are required, who participates in the approval process, and what happens before and after an agent is approved.


Why Agent Approval is Important

Unlike general-purpose Microsoft 365 Copilot experiences, custom agents often:

  • Access organizational knowledge
  • Connect to business systems
  • Trigger automated workflows
  • Perform business-specific tasks
  • Use sensitive organizational data

Because of these capabilities, organizations typically require an approval process before an agent is published to production.

Approval helps ensure that:

  • The agent performs its intended function.
  • Security requirements are met.
  • Compliance policies are followed.
  • Data access is appropriate.
  • Users receive a trustworthy AI experience.

Goals of the Approval Process

An effective approval process helps organizations:

  • Reduce security risks
  • Prevent accidental oversharing
  • Ensure regulatory compliance
  • Improve quality of AI responses
  • Validate business usefulness
  • Maintain organizational standards
  • Establish accountability

Typical Agent Lifecycle

A simplified lifecycle includes:

  1. Design
  2. Build
  3. Configure
  4. Test
  5. Review
  6. Approve
  7. Publish
  8. Monitor
  9. Update
  10. Retire

Approval occurs after testing but before broad deployment.


Typical Approval Workflow

Although every organization may customize the workflow, the process generally follows these steps.

Step 1: Agent Creation

A developer or business user creates the agent.

They configure:

  • Instructions
  • Knowledge sources
  • Actions
  • Connectors
  • Conversation flow

Step 2: Initial Testing

Before requesting approval, the creator tests the agent.

Typical testing includes:

  • Prompt accuracy
  • Correct responses
  • Hallucination reduction
  • Data grounding
  • Error handling
  • Business logic

Step 3: Security Review

Security administrators verify that:

  • Permissions are appropriate.
  • Data sources are approved.
  • Authentication is configured correctly.
  • Sensitive information is protected.
  • Least-privilege access is maintained.

Step 4: Compliance Review

Compliance teams evaluate whether the agent aligns with organizational governance policies.

Areas reviewed include:

  • Data Loss Prevention (DLP)
  • Sensitivity labels
  • Microsoft Purview policies
  • Data retention
  • Regulatory requirements
  • Audit logging

Step 5: Business Review

Business owners determine whether:

  • The agent solves the intended problem.
  • Responses are accurate.
  • Business terminology is correct.
  • Processes are followed correctly.
  • Users will benefit from the solution.

Step 6: Approval

Once reviews are complete, the designated approver authorizes publication.

Only approved agents should become available to end users.


Step 7: Publishing

After approval, the agent can be:

  • Published
  • Assigned to users
  • Shared with groups
  • Made available in Microsoft Teams
  • Integrated into Microsoft 365 Copilot

Who May Participate in the Approval Process?

Several roles may be involved depending on the organization.

Agent Creator

Responsible for:

  • Designing the agent
  • Testing functionality
  • Fixing issues
  • Submitting for review

Business Owner

Responsible for:

  • Verifying business value
  • Confirming correct business logic
  • Approving organizational use

IT Administrator

Responsible for:

  • Platform administration
  • Environment configuration
  • Deployment
  • User access

Security Administrator

Responsible for:

  • Permission validation
  • Identity verification
  • Connector review
  • Security assessment

Compliance Administrator

Responsible for:

  • Governance policies
  • Data protection
  • Microsoft Purview compliance
  • Regulatory alignment

What is Reviewed During Approval?

Reviewers typically examine:

Purpose

Does the agent solve a legitimate business problem?


Instructions

Are system instructions clear?

Do they prevent inappropriate behavior?


Knowledge Sources

Are approved sources used?

Examples include:

  • SharePoint
  • Microsoft Graph
  • Dataverse
  • Internal documentation

Actions

Can the agent:

  • Send emails?
  • Update records?
  • Trigger workflows?
  • Access external systems?

Higher-risk actions usually require more careful review.


Permissions

Does the agent only access information users are already authorized to see?

Microsoft 365 security trimming should remain intact.


Connectors

Reviewers verify that external connectors:

  • Are trusted
  • Are approved
  • Meet organizational policies

Privacy

Organizations verify that:

  • Personal data is protected.
  • Confidential information is handled appropriately.
  • AI responses do not expose sensitive content.

Governance During Approval

Agent approval is part of broader AI governance.

Organizations often require:

  • Data classification
  • Sensitivity labels
  • DLP policies
  • Audit logs
  • Risk assessments
  • Periodic reviews

These controls help ensure responsible AI deployment.


Approval vs Publishing

These concepts are different.

Approval means the organization authorizes the agent for deployment.

Publishing makes the approved agent available to users.

An approved agent is not necessarily published immediately.

Likewise, a draft agent cannot be published without completing required approvals (if organizational policies require them).


What Happens After Approval?

Approval is not the end of governance.

Administrators continue to monitor:

  • Usage
  • Adoption
  • Errors
  • User feedback
  • Performance
  • Security events
  • Compliance alerts

Agents may later be:

  • Updated
  • Republished
  • Disabled
  • Archived
  • Deleted

Best Practices

Organizations should:

  • Define a formal approval workflow.
  • Require business ownership.
  • Review data access carefully.
  • Test before publishing.
  • Limit permissions using least privilege.
  • Monitor production usage.
  • Periodically review existing agents.
  • Remove unused or outdated agents.
  • Maintain documentation for governance and auditing.

Exam Tips

For the AB-900 exam, remember these key points:

  • Approval helps ensure agents are secure, compliant, and useful before deployment.
  • Multiple stakeholders—including creators, business owners, IT administrators, security administrators, and compliance administrators—may participate in the approval process.
  • Testing occurs before approval.
  • Publishing occurs after approval.
  • Organizations can customize approval workflows based on governance requirements.
  • Security, permissions, data access, compliance, and business value are common review areas.
  • Agent governance continues after publication through ongoing monitoring and management.

Practice Exam Questions

Question 1

Why do organizations typically require an approval process before publishing custom agents?

A. To reduce deployment speed

B. To ensure the agent meets security, compliance, and business requirements

C. To prevent Microsoft 365 licensing

D. To disable Microsoft Graph access

Answer: B

Explanation: Approval ensures agents are reviewed for security, compliance, data access, and business value before being made available to users.


Question 2

Which activity normally occurs immediately before an agent is submitted for approval?

A. Assigning licenses

B. Deleting old agents

C. Testing the agent

D. Archiving the environment

Answer: C

Explanation: Creators typically validate the agent through testing before requesting formal approval.


Question 3

Which team is primarily responsible for reviewing whether an agent complies with data governance requirements?

A. Marketing

B. Finance

C. Human Resources

D. Compliance administrators

Answer: D

Explanation: Compliance administrators review governance policies, regulatory requirements, data protection, and Microsoft Purview controls.


Question 4

Which aspect is most likely reviewed during an agent approval process?

A. The color theme of Microsoft Teams

B. The Windows desktop wallpaper

C. The user’s internet browser

D. The agent’s permissions and data sources

Answer: D

Explanation: Reviewers verify that permissions and knowledge sources comply with organizational security policies.


Question 5

What is the primary purpose of reviewing an agent’s knowledge sources?

A. To increase processor speed

B. To ensure the agent uses approved organizational information

C. To update Windows

D. To install Microsoft Office

Answer: B

Explanation: Approved knowledge sources help ensure accurate responses while protecting sensitive information.


Question 6

Which statement correctly describes approval and publishing?

A. Publishing always occurs before approval.

B. Approval and publishing are identical.

C. Approval authorizes deployment, while publishing makes the agent available to users.

D. Approval permanently locks the agent.

Answer: C

Explanation: Approval authorizes the agent for release, while publishing distributes it to its intended audience.


Question 7

Who is primarily responsible for confirming that an agent solves the intended business problem?

A. Business owner

B. Printer administrator

C. Network technician

D. Database operator

Answer: A

Explanation: Business owners validate that the agent provides value and meets organizational objectives.


Question 8

Which security principle should agents follow when accessing organizational information?

A. Unlimited access

B. Anonymous authentication

C. Guest-only permissions

D. Least privilege

Answer: D

Explanation: Agents should only access the information necessary for their intended function, following the principle of least privilege.


Question 9

After an agent has been approved and published, what should administrators continue to do?

A. Disable audit logging

B. Ignore user feedback

C. Monitor usage, performance, and compliance

D. Remove all permissions

Answer: C

Explanation: Ongoing monitoring helps ensure the agent remains secure, compliant, and effective as business needs evolve.


Question 10

Which statement best describes organizational approval workflows for agents?

A. Every Microsoft 365 tenant uses the exact same approval process.

B. Approval is optional for all organizations.

C. Approval workflows are fixed and cannot be customized.

D. Organizations can customize approval workflows to meet their governance requirements.

Answer: D

Explanation: Microsoft provides flexible governance capabilities, allowing organizations to implement approval workflows that align with their security, compliance, and operational policies.


Go to the AB-900 Exam Prep Hub main page

Identify how to configure user access to agents (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for agents
      --> Identify how to configure user access to agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

In Microsoft 365 Copilot, agents are specialized AI assistants designed to perform focused tasks such as answering domain-specific questions, retrieving organizational knowledge, or executing workflows. Because agents can access organizational data and systems, controlling who can use them and under what conditions is a critical administrative responsibility.

Configuring user access ensures that the right users can interact with the right agents while maintaining security, compliance, and least-privilege principles.


1. What “agent access” means

User access to agents determines:

  • Which users can discover an agent
  • Which users can interact with or run an agent
  • Whether an agent is available organization-wide or restricted to specific groups
  • Whether external or guest users can use agents (if allowed)

Access is typically controlled through a combination of:

  • Microsoft 365 identity and access controls
  • Entra ID (Azure AD) group membership
  • Copilot and agent-specific policies

2. Key methods to configure access to agents

A. Assigning access via Microsoft Entra ID groups

One of the most common approaches is group-based access control.

Administrators can:

  • Assign an agent to specific security groups or Microsoft 365 groups
  • Restrict usage to departments (e.g., HR, Finance, IT)
  • Manage access at scale without assigning users individually

Benefits:

  • Scalable management
  • Easier onboarding/offboarding
  • Centralized governance

B. Tenant-wide vs scoped availability

Agents can be configured as:

1. Tenant-wide agents

  • Available to all licensed users in the organization
  • Used for general productivity scenarios (e.g., company policy assistant)

2. Scoped agents

  • Limited to specific users or groups
  • Used for sensitive or department-specific data (e.g., HR policy agent)

C. Role-based access control (RBAC)

Some agent administration actions require specific roles in Microsoft 365 or Entra ID:

  • Global Administrator
  • AI Administrator / Copilot Administrator
  • Service-specific admin roles

RBAC ensures:

  • Only authorized admins can publish or modify agents
  • Governance over agent deployment lifecycle

D. Conditional Access policies

Conditional Access can indirectly control agent usage by enforcing:

  • Device compliance requirements
  • Multi-factor authentication (MFA)
  • Location-based restrictions
  • Risk-based sign-in rules

This ensures that even if a user has access to an agent, they must meet security requirements before using it.


E. Application and permission scopes

Agents may require access to:

  • Microsoft 365 data (SharePoint, Outlook, Teams)
  • External connectors or APIs
  • Graph permissions

Administrators control:

  • What data the agent can access
  • Whether consent is required
  • Whether permissions are user-delegated or app-level

3. Lifecycle considerations for agent access

Provisioning

  • Define target audience (group or tenant-wide)
  • Assign initial permissions
  • Validate compliance requirements

Modification

  • Update group membership to change access
  • Adjust policies as organizational needs evolve

Deprovisioning

  • Remove users or groups when no longer needed
  • Disable or retire the agent if required
  • Ensure data access is revoked appropriately

4. Governance best practices

To securely manage agent access:

  • Use least privilege access (only necessary users/groups)
  • Prefer group-based assignment over individual assignment
  • Regularly review agent usage and permissions
  • Restrict sensitive agents to controlled departments
  • Monitor access logs for unusual activity
  • Align with Microsoft Purview policies where applicable

5. Common use cases

  • HR agent accessible only to HR staff
  • IT helpdesk agent available to all employees
  • Finance reporting agent restricted to finance team
  • Executive summary agent limited to leadership group

6. Key exam takeaway

For AB-900, remember:

  • Agent access is primarily controlled through Entra ID groups, roles, and policies
  • Access can be tenant-wide or scoped
  • Security is enforced through RBAC and Conditional Access
  • Governance ensures agents are only available to the appropriate users

Practice Exam Questions (10)

1.

What is the most common method used to manage user access to Microsoft 365 agents at scale?

A. Individual user assignment
B. Local device policies
C. Entra ID group-based assignment
D. DNS configuration

Answer: C
Explanation: Entra ID group-based assignment is the scalable and recommended way to manage agent access.


2.

Which configuration limits an agent to only HR department users?

A. Tenant-wide publishing
B. Scoped group assignment
C. Public sharing link
D. Guest user activation

Answer: B
Explanation: Scoped assignment using groups restricts access to specific departments like HR.


3.

Which role is typically required to manage Copilot or agent deployment settings?

A. SharePoint Site Owner
B. Global Administrator
C. Teams Guest User
D. Exchange Recipient User

Answer: B
Explanation: Global Administrators (or similar privileged roles) manage high-level agent deployment settings.


4.

What is the purpose of Conditional Access in relation to agent usage?

A. To increase storage capacity
B. To control data indexing speed
C. To enforce security requirements before access
D. To create new agents automatically

Answer: C
Explanation: Conditional Access ensures users meet security conditions like MFA or device compliance.


5.

What happens when a user is removed from an Entra ID group assigned to an agent?

A. They retain permanent access
B. Their access is automatically revoked
C. The agent is deleted
D. The entire tenant loses access

Answer: B
Explanation: Group membership changes immediately affect access to assigned resources, including agents.


6.

Which access model makes an agent available to all licensed users in a tenant?

A. Scoped access
B. Tenant-wide access
C. External sharing mode
D. Device-based access

Answer: B
Explanation: Tenant-wide access allows all licensed users to use the agent.


7.

Which control helps restrict what data an agent can access?

A. Network firewall rules
B. Permission scopes and Graph permissions
C. Printer access policies
D. Windows registry settings

Answer: B
Explanation: Permission scopes define what data and services an agent can access.


8.

What is a key benefit of using group-based access for agents?

A. It disables auditing
B. It simplifies scalable management
C. It removes the need for authentication
D. It bypasses licensing requirements

Answer: B
Explanation: Group-based access simplifies administration, especially in large organizations.


9.

Which scenario best describes proper agent governance?

A. All users can create unrestricted agents
B. Agents are available without authentication
C. Sensitive agents are limited to specific departments
D. Agents bypass compliance policies

Answer: C
Explanation: Sensitive agents should be restricted to appropriate departments for security and compliance.


10.

What is a recommended best practice when configuring access to agents?

A. Assign access individually to each user
B. Use least privilege access principles
C. Allow anonymous access by default
D. Disable group usage entirely

Answer: B
Explanation: Least privilege ensures users only get the access they need, improving security and governance.


Go to the AB-900 Exam Prep Hub main page

Manage prompts, in Microsoft Copilot, including saving, sharing, scheduling, and deleting (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for Copilot
      --> Manage prompts, in Microsoft Copilot, including saving, sharing, scheduling, and deleting


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft 365 Copilot allows users to create and reuse prompts to streamline repetitive work such as drafting emails, summarizing documents, generating reports, or analyzing data. From an administrative perspective, understanding how prompts are managed is important for governance, productivity, and consistency across an organization.

Prompts can be treated as reusable productivity assets that users can store, distribute, and manage over time—especially when Copilot is used at scale across Microsoft 365 apps.


1. What are Copilot prompts?

A Copilot prompt is a natural language instruction given to Copilot to generate output. For example:

  • “Summarize this meeting in five bullet points.”
  • “Draft a project update email for stakeholders.”
  • “Analyze this Excel dataset and highlight trends.”

Prompts can be:

  • One-time (ad hoc usage)
  • Saved for reuse
  • Shared across users or teams
  • Scheduled for recurring execution (in supported scenarios)

2. Saving prompts

Saving prompts allows users to reuse effective instructions without rewriting them.

Key characteristics:

  • Stored in a user-accessible prompt library or prompt experience
  • Can be reused across Microsoft 365 apps (Word, Teams, Outlook, etc.)
  • Helps standardize repetitive business tasks

Benefits:

  • Increases productivity
  • Encourages consistent output formatting
  • Reduces time spent recreating complex prompts

Example:

A finance analyst saves a prompt:

“Summarize quarterly revenue performance and highlight anomalies.”


3. Sharing prompts

Prompts can be shared with other users or teams to promote consistency.

Sharing capabilities include:

  • Sharing with individuals or groups
  • Embedding prompts into team workflows
  • Distributing best-practice prompts across departments

Use cases:

  • Standard HR onboarding email drafts
  • Sales proposal templates
  • IT troubleshooting responses

Governance consideration:

Shared prompts should align with organizational policies to avoid:

  • Exposure of sensitive instructions
  • Use of non-compliant content templates

4. Scheduling prompts

Scheduling allows prompts to be executed at defined intervals or triggered conditions (depending on Copilot capabilities and integration context).

Examples of scheduled prompt usage:

  • Daily summary of emails in Outlook
  • Weekly project status report generation
  • Regular data analysis summaries in Excel

Benefits:

  • Automates repetitive reporting tasks
  • Ensures timely information delivery
  • Reduces manual effort

Important note:

Scheduling capabilities may depend on:

  • Copilot-enabled workflows
  • Microsoft 365 integrations (Power Automate or agent-based automation)

5. Deleting prompts

Prompts can be deleted when they are no longer needed or are outdated.

Reasons for deletion:

  • Prompt is obsolete or inaccurate
  • Organizational standards have changed
  • Security or compliance concerns
  • User no longer needs the prompt

Administrative considerations:

  • Deleted prompts may not be recoverable depending on retention policies
  • Enterprises may enforce governance policies around prompt lifecycle management

6. Administrative and governance considerations

When managing prompts at scale, administrators should consider:

Security

  • Prevent sharing of sensitive prompts containing confidential logic
  • Ensure prompts do not encourage data leakage

Compliance

  • Align prompt usage with Microsoft Purview policies
  • Ensure prompts do not bypass organizational controls

Lifecycle management

  • Define rules for retention, reuse, and deletion
  • Standardize prompt libraries for departments

User enablement

  • Provide curated prompt libraries
  • Encourage adoption of approved prompt templates

7. Key exam takeaway

For AB-900, focus on the fact that Copilot prompt management includes:

  • Saving prompts for reuse
  • Sharing prompts across users or teams
  • Scheduling prompts for recurring tasks (where supported)
  • Deleting prompts for governance and lifecycle control

These capabilities support productivity while requiring governance oversight in enterprise environments.


Practice Exam Questions (10)

1.

What is the primary benefit of saving Copilot prompts?

A. It increases network bandwidth usage
B. It allows reuse of effective instructions
C. It disables prompt security controls
D. It deletes old conversations automatically

Answer: B
Explanation: Saving prompts enables reuse of effective instructions, improving productivity and consistency.


2.

An organization wants to standardize email drafts across departments. Which feature supports this goal?

A. Prompt deletion
B. Prompt sharing
C. Device enrollment
D. Data loss prevention

Answer: B
Explanation: Sharing prompts allows standardized templates and instructions to be distributed across teams.


3.

Which scenario best represents a scheduled Copilot prompt?

A. A one-time email draft request
B. A manually typed search query
C. A daily summary report generated automatically
D. A deleted conversation thread

Answer: C
Explanation: Scheduled prompts run at defined intervals, such as daily report generation.


4.

Why might an administrator enforce governance rules on shared prompts?

A. To increase storage capacity
B. To reduce CPU usage
C. To prevent exposure of sensitive or non-compliant content
D. To disable Copilot licensing

Answer: C
Explanation: Shared prompts may contain sensitive logic, so governance ensures compliance and security.


5.

What typically happens when a prompt is deleted?

A. It is permanently removed from the prompt library
B. It becomes read-only
C. It is converted into a system alert
D. It is automatically shared with all users

Answer: A
Explanation: Deleting a prompt removes it from the library, although retention policies may affect recoverability.


6.

Which of the following is a valid use case for saved prompts?

A. Running antivirus scans
B. Reusing a formatted project status report request
C. Managing device drivers
D. Configuring network routing

Answer: B
Explanation: Saved prompts are used for repeatable tasks like structured reports or summaries.


7.

What is a key risk of unmanaged prompt sharing?

A. Increased CPU performance
B. Exposure of sensitive instructions or business logic
C. Faster email delivery
D. Reduced storage costs

Answer: B
Explanation: Unmanaged sharing can expose sensitive organizational logic or data-handling instructions.


8.

Which Microsoft 365 principle is most relevant to managing Copilot prompts?

A. Hardware lifecycle management
B. Identity federation
C. Information governance
D. Network segmentation

Answer: C
Explanation: Prompt management relates to information governance, including control over content and usage.


9.

What is a benefit of scheduling prompts in Copilot-enabled workflows?

A. It eliminates user authentication
B. It automates repetitive reporting tasks
C. It disables Microsoft 365 apps
D. It increases manual effort

Answer: B
Explanation: Scheduled prompts automate recurring tasks like reports and summaries.


10.

Which action supports prompt lifecycle management in an enterprise environment?

A. Random prompt duplication
B. Unrestricted external sharing
C. Deleting outdated prompts based on policy
D. Disabling all Copilot features

Answer: C
Explanation: Removing outdated prompts helps maintain compliance and ensures only relevant prompts are retained.


Go to the AB-900 Exam Prep Hub main page

Monitor Copilot usage and adoption, including Copilot Analytics and Microsoft 365 admin center (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for Copilot
      --> Monitor Copilot usage and adoption, including Copilot Analytics and Microsoft 365 admin center


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Monitoring Microsoft 365 Copilot usage is a key administrative responsibility because it helps organizations understand adoption trends, measure business value, and identify areas where users may need additional training or enablement. Microsoft provides built-in visibility through the Microsoft 365 admin center and Copilot Analytics experiences, which together give insights into how Copilot is being used across apps like Word, Excel, Outlook, Teams, and SharePoint.


1. Why monitoring Copilot usage matters

Administrators monitor Copilot adoption to:

  • Measure return on investment (ROI) for Copilot licenses
  • Identify departments or users actively using Copilot
  • Detect underutilization or lack of adoption
  • Support training and change management initiatives
  • Ensure responsible and compliant use of AI tools
  • Inform licensing and capacity planning decisions

2. Copilot usage data in Microsoft 365 admin center

The Microsoft 365 admin center provides tenant-level reporting for Copilot usage.

Key capabilities include:

Usage reporting dashboards

Admins can view:

  • Number of licensed users
  • Active Copilot users over time
  • Usage trends across Microsoft 365 apps
  • App-specific usage (Word, Excel, Outlook, Teams)

Adoption insights

  • New vs returning users
  • Frequency of Copilot interactions
  • Organizational adoption trends

License-based visibility

  • Shows usage segmented by licensed users
  • Helps identify unused or underused licenses

Export capabilities

  • Data can be exported for deeper analysis in Power BI or Excel

3. Copilot Analytics (advanced insights)

Copilot Analytics provides deeper behavioral insights beyond basic usage metrics.

What Copilot Analytics helps you understand:

Business impact signals

  • Time saved (estimated productivity gains)
  • Task completion patterns using Copilot
  • Adoption maturity across teams

Engagement depth

  • Simple prompts vs advanced multi-step prompts
  • Frequency of Copilot-assisted document creation
  • Collaboration patterns influenced by Copilot

Department-level insights

  • Usage by business unit (e.g., Finance, HR, Sales)
  • Comparison between teams or regions

Trend analysis

  • Adoption growth over weeks/months
  • Seasonal or campaign-driven usage spikes

4. Key Copilot usage metrics to track

Administrators commonly focus on:

  • Active Copilot users (daily/weekly/monthly)
  • Copilot interactions per user
  • Prompt volume and complexity
  • Most-used Microsoft 365 apps with Copilot
  • Retention of Copilot usage over time

5. Microsoft 365 apps included in reporting

Copilot usage insights are typically broken down across:

  • Microsoft Word – document drafting, summarization
  • Microsoft Excel – data analysis, formula generation
  • Microsoft Outlook – email summarization and drafting
  • Microsoft Teams – meeting recap, chat summarization
  • SharePoint – content summarization and knowledge discovery

6. Administrative use cases for monitoring Copilot

Adoption planning

  • Identify early adopters to act as champions
  • Target training for low-adoption teams

Licensing optimization

  • Reclaim unused licenses
  • Forecast future licensing needs

Governance oversight

  • Ensure Copilot is used within acceptable use policies
  • Monitor for unusual or unexpected usage patterns

Organizational enablement

  • Measure effectiveness of Copilot rollout campaigns
  • Improve user enablement programs based on usage patterns

7. Relationship between admin center and Copilot Analytics

CapabilityMicrosoft 365 Admin CenterCopilot Analytics
Basic usage reportingYesLimited
App-level usage breakdownYesYes
Behavioral insightsLimitedYes
Productivity impact insightsNoYes
Trend reportingYesYes (more advanced)

8. Key exam takeaway

For AB-900, understand that:

  • The Microsoft 365 admin center provides baseline usage and adoption reports.
  • Copilot Analytics provides deeper behavioral and productivity insights.
  • Together, they help administrators measure adoption, value, and readiness at scale.

Practice Exam Questions (10)

1.

An organization wants to view how many users are actively using Copilot in Microsoft Word and Outlook. Where should the administrator go first?

A. Microsoft Entra admin center
B. Microsoft 365 admin center
C. Microsoft Purview compliance portal
D. Microsoft Defender portal

Answer: B
Explanation: The Microsoft 365 admin center provides Copilot usage reports, including app-level adoption data such as Word and Outlook usage.


2.

Which Copilot Analytics capability provides insight into productivity improvements?

A. License assignment tracking
B. Email delivery monitoring
C. Estimated time saved by users
D. Device compliance reporting

Answer: C
Explanation: Copilot Analytics includes business impact metrics such as estimated time saved through AI-assisted work.


3.

What is a key benefit of combining Microsoft 365 admin center reports with Copilot Analytics?

A. It replaces the need for licensing
B. It enables deeper behavioral and adoption insights
C. It blocks unauthorized Copilot usage
D. It automates license purchasing

Answer: B
Explanation: The admin center provides usage data, while Copilot Analytics adds deeper behavioral and productivity insights.


4.

Which metric is MOST commonly used to measure Copilot adoption?

A. Number of inactive devices
B. Active Copilot users over time
C. Number of Teams channels created
D. Email attachment size

Answer: B
Explanation: Active users over time is a core adoption metric for Copilot usage tracking.


5.

An administrator wants to identify departments with the lowest Copilot usage. Which insight is most relevant?

A. Geographic IP logs
B. User mailbox size
C. Department-level usage reporting
D. DNS resolution reports

Answer: C
Explanation: Copilot Analytics can segment usage by department or business unit.


6.

What type of Copilot usage data is typically available in the Microsoft 365 admin center?

A. Advanced prompt sentiment analysis
B. Basic usage and adoption metrics
C. Source code execution logs
D. Endpoint vulnerability scans

Answer: B
Explanation: The admin center provides high-level usage and adoption metrics, not deep behavioral analysis.


7.

Which Copilot usage trend would indicate strong adoption?

A. Declining active users over time
B. Zero usage across all apps
C. Increasing active users across multiple apps
D. Only one department using Copilot

Answer: C
Explanation: Increasing usage across apps indicates growing adoption and engagement.


8.

Which Microsoft 365 apps are typically included in Copilot usage reporting?

A. Word, Excel, Outlook, Teams
B. SQL Server, Power BI Desktop, Visual Studio
C. Windows Explorer, Notepad, Paint
D. Azure VM, Azure Storage, Azure Functions

Answer: A
Explanation: Copilot usage reporting focuses on Microsoft 365 productivity apps.


9.

What is a common administrative action based on Copilot usage reports?

A. Disabling all user accounts
B. Reclaiming unused licenses
C. Deleting Teams channels
D. Blocking internet access

Answer: B
Explanation: Low usage can indicate unused licenses that may be reassigned or reclaimed.


10.

What does Copilot Analytics primarily provide beyond basic reporting?

A. Network firewall configuration
B. Behavioral and productivity insights
C. Hardware inventory tracking
D. Email encryption keys

Answer: B
Explanation: Copilot Analytics provides deeper insights into user behavior and productivity impact.


Go to the AB-900 Exam Prep Hub main page

Monitor and manage Copilot Pay-as-You-Go billing policies (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for Copilot
      --> Monitor and manage Copilot Pay-as-You-Go billing policies


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft 365 Copilot pay-as-you-go (PAYG) billing policies allow organizations to consume Copilot-related services based on usage rather than only per-user licensing. This model is commonly used for features such as Copilot in SharePoint or other metered AI capabilities where consumption is tracked and billed through an Azure subscription.

Administrators are responsible for configuring, monitoring, and controlling these billing policies to ensure predictable costs, governance, and proper usage.


What is Copilot pay-as-you-go billing?

Pay-as-you-go billing in Microsoft 365 Copilot scenarios enables:

  • Usage-based billing instead of fixed per-user licensing
  • Cost tracking through Azure subscription meters
  • Flexible adoption for specific workloads (for example, SharePoint-based Copilot experiences)
  • Centralized financial control via Azure billing tools

This model is typically associated with Microsoft Copilot experiences that rely on Azure-backed metering.


Key components of PAYG billing policies

1. Azure subscription

All PAYG Copilot usage is billed through an Azure subscription. The subscription:

  • Acts as the billing container
  • Hosts cost management and usage tracking
  • Must be linked to the Microsoft 365 tenant

2. Billing policy configuration

Admins define policies that determine:

  • Which users or groups are enabled for PAYG usage
  • Which Copilot features are billable under PAYG
  • Scope of usage (tenant-wide, group-based, or service-specific)

3. Metered services

Pay-as-you-go applies to specific Copilot capabilities such as:

  • Copilot experiences in SharePoint
  • AI-powered content generation or summarization in supported workloads
  • Feature-specific AI consumption events

Each usage event contributes to measurable consumption units.


How administrators monitor PAYG Copilot usage

Azure Cost Management + Billing

Primary tool used to monitor consumption:

  • Tracks cost per service
  • Shows usage trends
  • Provides budget alerts and forecasting

Microsoft 365 admin center

Used for:

  • Viewing service-level Copilot usage
  • Monitoring adoption and activity reports
  • Understanding organizational usage patterns

Usage analytics dashboards

Administrators can review:

  • Active users consuming PAYG Copilot features
  • Feature-level consumption breakdown
  • Trends over time for optimization

Managing PAYG billing policies

1. Create or configure billing policies

Admins define policies to:

  • Enable PAYG for specific services (e.g., SharePoint Copilot)
  • Assign eligible user groups
  • Control feature access scope

2. Assign policies to users or groups

Instead of enabling all users, organizations often:

  • Assign PAYG access to pilot groups
  • Restrict usage to departments or projects
  • Expand gradually based on adoption

3. Set budgets and alerts

Using Azure Cost Management, administrators can:

  • Set monthly budgets
  • Configure alerts for threshold breaches
  • Prevent unexpected overuse

4. Review and optimize usage

Admins regularly:

  • Identify high-cost usage patterns
  • Adjust policies to reduce unnecessary consumption
  • Disable PAYG access for inactive users or groups

Governance and control considerations

Monitoring PAYG Copilot billing is not only financial—it also includes governance:

  • Ensuring only authorized users can consume metered services
  • Aligning usage with organizational policies
  • Applying Microsoft Entra ID group-based access controls
  • Ensuring compliance with Microsoft Purview policies where applicable

Key differences: PAYG vs per-user Copilot licensing

ModelDescription
Per-user licensingFixed monthly cost per licensed user
Pay-as-you-goUsage-based billing tied to Azure consumption

PAYG is typically more flexible but requires closer monitoring to avoid unexpected costs.


Summary

Monitoring and managing Copilot pay-as-you-go billing policies involves configuring Azure-based billing structures, assigning usage scopes through policies, and continuously tracking consumption using Azure Cost Management and Microsoft 365 reporting tools. Administrators must balance flexibility with cost control and governance to ensure efficient and compliant use of Copilot services.


Practice Exam Questions (10)

1.

Where is Copilot pay-as-you-go usage primarily billed?

A. Microsoft Teams admin center
B. Azure subscription
C. Windows Update service
D. Microsoft Defender portal

Answer: B
Explanation: PAYG Copilot usage is billed through an Azure subscription linked to the tenant.


2.

What is the main purpose of a Copilot pay-as-you-go billing policy?

A. To disable Copilot features globally
B. To assign static per-user licenses
C. To control and define usage-based billing scope
D. To store Copilot chat history

Answer: C
Explanation: Billing policies define who can use PAYG features and how usage is tracked.


3.

Which tool is primarily used to monitor PAYG Copilot costs?

A. Microsoft Word
B. Azure Cost Management + Billing
C. PowerPoint Designer
D. OneDrive sync client

Answer: B
Explanation: Azure Cost Management provides cost tracking, alerts, and reporting.


4.

What is a common use case for Copilot PAYG billing?

A. Permanent licensing for all employees
B. SharePoint-based Copilot experiences with metered usage
C. Offline document editing
D. Local file encryption

Answer: B
Explanation: PAYG is often used for metered Copilot features like SharePoint integration.


5.

What should an administrator configure to control which users can use PAYG Copilot features?

A. Microsoft Teams channels
B. Azure DevOps pipelines
C. Billing policies and assigned user groups
D. Windows Registry settings

Answer: C
Explanation: Policies and group assignments define access to PAYG usage.


6.

What is a key benefit of PAYG billing compared to per-user licensing?

A. Unlimited free usage
B. No need for Microsoft 365 accounts
C. Flexible, usage-based cost model
D. Automatic removal of security policies

Answer: C
Explanation: PAYG provides flexibility by charging based on actual usage.


7.

Which action helps prevent unexpected PAYG Copilot costs?

A. Disabling Microsoft Outlook
B. Setting Azure budgets and alerts
C. Removing all SharePoint sites
D. Turning off Microsoft Entra ID

Answer: B
Explanation: Budgeting and alerts help control spending.


8.

What type of identity is required for users consuming PAYG Copilot features?

A. Local Windows account only
B. Microsoft Entra ID identity
C. Anonymous guest browsing
D. External VPN identity only

Answer: B
Explanation: Copilot services require authenticated Microsoft Entra ID users.


9.

What should administrators regularly review in PAYG billing management?

A. Email signatures
B. Usage trends and cost reports
C. Device firmware versions
D. Printer configurations

Answer: B
Explanation: Usage and cost trends help optimize billing policies.


10.

Which statement best describes PAYG Copilot billing?

A. Fixed monthly cost per organization
B. Free usage for all Microsoft 365 users
C. One-time purchase for lifetime access
D. Consumption-based billing through Azure

Answer: D
Explanation: PAYG is based on measured usage and billed via Azure.


Go to the AB-900 Exam Prep Hub main page

Assign Copilot licenses (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Perform basic administrative tasks for Copilot
      --> Assign Copilot licenses


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Assigning Microsoft 365 Copilot licenses is a core administrative task that ensures users can access Copilot capabilities within supported Microsoft 365 apps. Licensing directly controls who can use Copilot features in apps such as Word, Excel, Outlook, Teams, and other Microsoft 365 services.


What is a Copilot license?

A Microsoft 365 Copilot license is a per-user add-on license that enables AI-powered assistance across Microsoft 365 applications. It works alongside required base licenses such as:

  • Microsoft 365 E3 or E5
  • Microsoft 365 Business Standard or Business Premium (depending on eligibility)

Without a Copilot license, users may still access Microsoft 365 apps but will not have Copilot capabilities embedded in those apps.


Prerequisites before assigning Copilot licenses

Before assigning licenses, an administrator must ensure:

  • The user has a supported Microsoft 365 base license
  • The organization has available Copilot licenses purchased through the Microsoft 365 admin center
  • The user is in a valid Microsoft Entra ID tenant
  • The required service plans for Copilot are enabled

Methods to assign Copilot licenses

1. Microsoft 365 admin center (most common method)

Admins can assign licenses manually:

Steps:

  • Navigate to the Microsoft 365 admin center
  • Go to Users > Active users
  • Select one or more users
  • Choose Licenses and apps
  • Enable Microsoft 365 Copilot
  • Save changes

This method is typically used for small or targeted assignments.


2. Group-based licensing via Microsoft Entra ID

For larger organizations, licenses are assigned through security groups:

Steps:

  • Create or select a Microsoft Entra security group
  • Assign Copilot license to the group
  • Add users to the group

Benefits:

  • Automated license assignment
  • Scalable for large organizations
  • Reduces administrative overhead

3. Microsoft 365 admin bulk assignment

Admins can:

  • Upload a CSV file of users
  • Assign Copilot licenses in bulk
  • Apply changes across many accounts at once

This is useful during onboarding or large-scale rollouts.


4. Microsoft Graph or PowerShell automation

Advanced administrators can use:

  • Microsoft Graph API
  • Microsoft Graph PowerShell SDK

This allows:

  • Automated provisioning
  • Integration with HR systems
  • Dynamic license assignment based on attributes

How Copilot licensing works across Microsoft 365 apps

Once assigned, the license enables Copilot features in:

  • Microsoft Word (content generation, rewriting, summarization)
  • Microsoft Excel (data analysis, formulas, insights)
  • Microsoft Outlook (email drafting and summarization)
  • Microsoft Teams (meeting summaries, chat assistance)
  • Microsoft Loop and other integrated apps

The license is tenant-aware and respects organizational data boundaries.


License assignment considerations

When assigning Copilot licenses, administrators should consider:

1. Data access permissions

Copilot does not grant new data access. It only uses what the user already has permission to view.

2. Cost and allocation strategy

Since Copilot is a premium add-on, organizations often:

  • Start with pilot groups
  • Expand based on usage metrics
  • Prioritize high-impact roles

3. Role-based rollout

Common rollout groups include:

  • Executives
  • Sales and marketing teams
  • Analysts and knowledge workers

Monitoring license usage

Admins can track:

  • Active Copilot users
  • License assignment status
  • Adoption metrics via Microsoft 365 admin center and usage reports

This helps optimize license distribution and ROI.


Common issues during license assignment

  • User lacks a required base Microsoft 365 license
  • Copilot service plan is not enabled
  • Delay in license propagation across services
  • User not signed out/in after assignment

Summary

Assigning Copilot licenses involves ensuring users have the correct Microsoft 365 base license, selecting an appropriate assignment method (manual, group-based, bulk, or automated), and monitoring adoption. Proper license management ensures controlled rollout, cost efficiency, and readiness for Copilot-enabled productivity across Microsoft 365 applications.


Practice Exam Questions (10)

1.

What is required before assigning a Microsoft 365 Copilot license to a user?

A. The user must have a Microsoft Teams phone system license
B. The user must have a supported Microsoft 365 base license
C. The user must be a global administrator
D. The user must install Copilot locally

Answer: B
Explanation: Copilot requires a base Microsoft 365 license such as E3 or E5.


2.

Which method is best for assigning Copilot licenses to a large group of users automatically?

A. Manual assignment in the admin center
B. CSV upload only
C. Group-based licensing in Microsoft Entra ID
D. Email-based activation requests

Answer: C
Explanation: Group-based licensing automates assignment at scale through Entra ID groups.


3.

Where can an administrator assign Copilot licenses directly to individual users?

A. Microsoft Defender portal
B. Microsoft 365 admin center
C. Azure DevOps
D. Power BI service

Answer: B
Explanation: User-level license assignment is performed in the Microsoft 365 admin center.


4.

What happens if a user does not have a Microsoft 365 Copilot license?

A. They lose access to Microsoft 365 apps entirely
B. They can still use apps but without Copilot features
C. They automatically receive a trial license
D. They can use Copilot through web search

Answer: B
Explanation: Copilot is an add-on; core apps still function without it.


5.

Which tool can be used for automated Copilot license assignment based on user attributes?

A. Microsoft Graph API
B. Microsoft Paint
C. Microsoft Forms only
D. SharePoint Designer

Answer: A
Explanation: Microsoft Graph enables automation and dynamic license management.


6.

What is a key benefit of group-based licensing?

A. It removes the need for Microsoft 365 licenses
B. It allows Copilot to bypass permissions
C. It enables scalable and automated license assignment
D. It disables admin control over users

Answer: C
Explanation: Group-based licensing simplifies large-scale management.


7.

Which of the following is NOT a valid method for assigning Copilot licenses?

A. Microsoft 365 admin center
B. Microsoft Entra group-based licensing
C. Bulk CSV upload
D. Direct assignment through Windows Registry edits

Answer: D
Explanation: Registry edits are not used for Microsoft 365 licensing.


8.

After assigning a Copilot license, what may users need to do?

A. Reinstall Microsoft 365 apps
B. Restart their device immediately
C. Sign out and sign back into Microsoft 365 apps
D. Change their password

Answer: C
Explanation: License changes often require sign-out/sign-in to take effect.


9.

What does a Copilot license enable in Microsoft 365 apps?

A. Access to encrypted storage only
B. AI-powered assistance features within supported apps
C. Additional storage space in OneDrive
D. Automatic data backup services

Answer: B
Explanation: Copilot provides AI assistance across Microsoft 365 apps.


10.

What is a recommended strategy when initially deploying Copilot licenses?

A. Assign to all users immediately
B. Disable Microsoft 365 security policies
C. Start with pilot groups before broad rollout
D. Assign only to guest users

Answer: C
Explanation: Pilot deployments help organizations manage cost and adoption effectively.


Go to the AB-900 Exam Prep Hub main page

Identify use cases for custom agents (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Identify use cases for custom agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Custom agents in Microsoft 365 Copilot extend Copilot’s built-in capabilities by allowing organizations to create tailored AI assistants focused on specific business processes, data sources, and workflows. Unlike general Copilot experiences, custom agents are designed to operate within defined boundaries, grounded in organizational knowledge and governed data.

What are custom agents?

A custom agent is a specialized AI assistant built on top of Microsoft 365 Copilot that can:

  • Use organization-specific knowledge sources (SharePoint sites, files, Dataverse, web connectors, etc.)
  • Follow predefined instructions and behaviors
  • Perform scoped tasks such as answering domain questions, generating structured outputs, or assisting workflows
  • Operate with Microsoft 365 identity and security controls

They are typically built using tools like Copilot Studio and integrated into Microsoft 365 experiences such as Teams, SharePoint, or Copilot chat.


Key characteristics of custom agents

Custom agents differ from general Copilot usage in several important ways:

They are purpose-built, meaning they are designed for a specific function such as HR support or IT helpdesk assistance. They are also data-grounded, relying on selected enterprise knowledge sources rather than broad internet knowledge.

They are governed, meaning they respect Microsoft 365 permissions, Microsoft Purview policies, and organizational compliance boundaries.

Finally, they are interactive and task-oriented, often guiding users through structured processes rather than only responding to ad-hoc questions.


Common use cases for custom agents

1. HR and employee support agents

Custom HR agents are commonly used to:

  • Answer questions about leave policies, benefits, and onboarding
  • Guide employees through HR workflows
  • Retrieve policy documents from SharePoint or HR systems

This reduces HR ticket volume and improves employee self-service.


2. IT helpdesk and support agents

IT-focused agents can:

  • Troubleshoot common issues (password resets, device setup, VPN access)
  • Provide step-by-step remediation guidance
  • Surface knowledge base articles from internal documentation

These agents help reduce repetitive IT support requests.


3. Sales and customer support agents

Sales agents are used to:

  • Summarize customer accounts and opportunities
  • Retrieve CRM data and product information
  • Generate sales emails or proposals

Customer support agents can also respond to common inquiries using approved knowledge bases.


4. Knowledge management agents

Organizations use agents to:

  • Provide structured access to company policies and documentation
  • Answer questions across multiple SharePoint sites
  • Improve search and discovery of internal content

These agents are especially valuable in large enterprises with distributed knowledge.


5. Finance and operations agents

Custom agents in finance or operations can:

  • Assist with budget tracking queries
  • Explain financial reporting definitions
  • Summarize operational KPIs or dashboards

They typically connect to controlled datasets and reporting systems.


6. Project and workflow assistants

These agents help teams by:

  • Tracking project status updates
  • Summarizing meeting notes
  • Guiding users through standardized workflows (e.g., project intake, approvals)

When to use custom agents vs standard Copilot

Custom agents are most appropriate when:

  • A repeatable business process exists
  • The organization has curated knowledge sources
  • Responses must follow strict formatting or rules
  • Domain-specific accuracy is required (HR, finance, IT, legal)

Standard Copilot is better for:

  • General productivity tasks (writing, summarizing, brainstorming)
  • Ad hoc questions that do not require structured workflows or specialized data

Governance considerations

Custom agents inherit Microsoft 365 security and compliance controls, including:

  • Microsoft Entra ID authentication
  • Microsoft Purview sensitivity labels and DLP policies
  • Role-based access control (RBAC)
  • Data access restricted by user permissions

This ensures agents do not expose information beyond what a user is authorized to see.


Summary

Custom agents in Microsoft 365 Copilot are specialized AI assistants designed for targeted business scenarios. They extend Copilot by adding organizational knowledge, structured workflows, and governance controls. Their primary value lies in automating repetitive tasks, improving knowledge access, and supporting domain-specific processes across departments such as HR, IT, finance, and operations.


Practice Exam Questions (10)

1.

A company wants an assistant that can answer employee questions about vacation policies using only internal HR documents stored in SharePoint. What is the best solution?

A. Use a custom Copilot agent grounded in HR SharePoint content
B. Use Microsoft Excel Copilot only
C. Use a Power BI dashboard
D. Use a generic web Copilot chat

Answer: A
Explanation: A custom agent can be grounded in specific SharePoint HR content and provide controlled, policy-based responses.


2.

Which scenario best represents a use case for a custom agent?

A. Writing a marketing email from scratch
B. Generating creative ideas for a product name
C. Answering general trivia questions
D. Guiding users through an IT password reset workflow

Answer: D
Explanation: IT helpdesk workflows are structured, repeatable, and ideal for custom agents.


3.

What is a key benefit of using custom agents in Microsoft 365 Copilot?

A. They bypass Microsoft security controls for faster responses
B. They only use public internet data
C. They enforce organizational policies and use approved data sources
D. They eliminate the need for user authentication

Answer: C
Explanation: Custom agents respect Microsoft 365 governance and use controlled enterprise data.


4.

A finance team wants an AI tool that summarizes monthly budget reports stored in controlled datasets. Which capability is most appropriate?

A. Custom finance agent grounded in approved financial data
B. Personal Microsoft Word Copilot
C. Bing search integration
D. Email auto-responder rules

Answer: A
Explanation: Finance use cases require structured, governed access to internal datasets.


5.

Which tool is commonly used to create custom agents for Microsoft 365 Copilot?

A. Power Automate only
B. Copilot Studio
C. Azure DevOps
D. Microsoft Access

Answer: B
Explanation: Copilot Studio is used to build and configure custom agents.


6.

What distinguishes a custom agent from standard Microsoft 365 Copilot?

A. It can only work offline
B. It uses only unstructured internet data
C. It is built for specific business scenarios and uses curated data sources
D. It replaces all Microsoft 365 applications

Answer: C
Explanation: Custom agents are scoped to specific business needs and data sources.


7.

Which is a valid HR-related use case for a custom agent?

A. Generating random social media posts
B. Answering employee benefit questions from policy documents
C. Editing video content
D. Running system diagnostics on servers

Answer: B
Explanation: HR agents provide policy-based answers from controlled documentation.


8.

What ensures a custom agent does NOT expose unauthorized data?

A. Internet firewall rules
B. Microsoft Defender antivirus only
C. User identity and Microsoft 365 permissions
D. Manual approval of every prompt

Answer: C
Explanation: Access is controlled through Microsoft Entra ID and existing permissions.


9.

When should a custom agent be preferred over standard Copilot?

A. When tasks are ad hoc and creative
B. When structured workflows and specific business rules are required
C. When browsing public websites
D. When no data sources are needed

Answer: B
Explanation: Custom agents are ideal for structured, repeatable workflows.


10.

Which department would most likely benefit from a knowledge management agent?

A. HR requesting policy document access
B. Users playing games
C. Graphic design teams creating artwork
D. Hardware repair technicians fixing printers

Answer: A
Explanation: Knowledge management agents help retrieve and summarize internal policies and documentation.


Go to the AB-900 Exam Prep Hub main page

Identify use cases for Researcher (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Identify use cases for Researcher


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Researcher is an advanced AI-powered reasoning capability available within the Microsoft 365 Copilot ecosystem. It is designed to perform multi-step, in-depth research tasks that require gathering information from multiple sources, analyzing large amounts of data, synthesizing findings, and presenting comprehensive, well-organized results.

Unlike standard Copilot experiences, which typically generate responses from a single prompt, Researcher performs more sophisticated reasoning by combining enterprise knowledge stored in Microsoft 365 with, when appropriate and permitted, external information sources. It is intended to help users complete tasks that would normally require hours of manual research.

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand:

  • What Researcher is
  • How it differs from standard Microsoft 365 Copilot experiences
  • Typical business scenarios where Researcher provides value
  • The types of data Researcher uses
  • How Microsoft 365 security, permissions, and governance continue to apply
  • The limitations and best practices for using Researcher

What Is Researcher?

Researcher is an advanced AI capability that helps users perform complex research tasks by:

  • Collecting information from multiple sources
  • Comparing information
  • Identifying patterns
  • Summarizing findings
  • Producing structured reports
  • Citing supporting information where applicable
  • Performing iterative reasoning before generating a final response

Rather than simply answering a question, Researcher can develop a complete research workflow.

Example request:

“Prepare a report comparing our organization’s cloud migration strategy with current industry best practices and identify potential risks.”

Instead of providing a brief summary, Researcher may:

  • Review internal project documentation
  • Examine meeting notes
  • Analyze SharePoint documents
  • Review emails
  • Compare current practices with publicly available information (when configured)
  • Produce a detailed report with recommendations

How Researcher Differs from Standard Copilot

Standard Microsoft 365 Copilot focuses primarily on helping users complete everyday productivity tasks such as:

  • Drafting emails
  • Summarizing meetings
  • Creating presentations
  • Rewriting documents
  • Generating tables
  • Answering questions

Researcher extends these capabilities by emphasizing:

  • Multi-step reasoning
  • Long-form research
  • Deep analysis
  • Information synthesis
  • Strategic recommendations
  • Comprehensive reporting

Think of standard Copilot as an AI assistant, while Researcher functions more like an AI research analyst.


Data Sources Used by Researcher

Researcher can analyze information from multiple Microsoft 365 sources, including:

  • SharePoint sites
  • OneDrive files
  • Microsoft Teams conversations
  • Outlook emails
  • Microsoft Word documents
  • Excel workbooks
  • PowerPoint presentations
  • OneNote notebooks
  • Microsoft Graph organizational relationships

Depending on organizational configuration and licensing, Researcher may also incorporate approved external information sources.


Microsoft Graph and Researcher

Researcher relies heavily on Microsoft Graph.

Microsoft Graph provides:

  • Organizational relationships
  • User permissions
  • File locations
  • Emails
  • Meetings
  • Calendar events
  • Conversations
  • Shared documents
  • Collaboration history

Researcher uses Microsoft Graph to locate relevant information efficiently.

Importantly, Researcher never bypasses Microsoft Graph permissions.

If a user cannot access a document, Researcher cannot use it.


Common Business Use Cases

1. Market Research

Researcher can help organizations:

  • Compare competitors
  • Analyze market trends
  • Summarize industry reports
  • Identify emerging technologies
  • Evaluate customer behavior

Example:

“Research the latest AI adoption trends in financial services.”


2. Executive Briefings

Executives often require concise summaries from large volumes of information.

Researcher can:

  • Summarize multiple meetings
  • Combine reports
  • Review emails
  • Produce executive-ready briefing documents

3. Project Research

Large projects often generate hundreds of documents.

Researcher can help summarize:

  • Requirements
  • Risks
  • Decisions
  • Milestones
  • Meeting notes
  • Design documents

Instead of reading dozens of files manually, Researcher consolidates the information.


4. Policy Analysis

Organizations frequently maintain hundreds of internal policies.

Researcher can:

  • Compare policies
  • Identify inconsistencies
  • Summarize requirements
  • Highlight missing documentation

5. Compliance Research

Researcher can assist with:

  • Reviewing compliance documentation
  • Summarizing regulatory guidance
  • Comparing policies against standards
  • Organizing compliance evidence

It does not replace formal compliance or legal reviews.


6. Sales Preparation

Sales teams can use Researcher to prepare for customer meetings by combining:

  • Previous emails
  • Meeting notes
  • Proposal documents
  • Customer presentations
  • Product documentation

The result is a comprehensive customer briefing.


7. Product Research

Product managers may ask Researcher to:

  • Compare product requirements
  • Analyze customer feedback
  • Summarize bug reports
  • Review feature requests
  • Recommend priorities

8. Knowledge Discovery

Employees often spend significant time searching for information.

Researcher can locate and combine information from:

  • Multiple SharePoint sites
  • Teams chats
  • Emails
  • Documents
  • Internal knowledge bases

This significantly reduces research time.


9. Strategic Planning

Leadership teams may ask Researcher to:

  • Compare business strategies
  • Analyze organizational performance
  • Review previous planning documents
  • Summarize lessons learned
  • Generate strategic recommendations

10. Report Generation

Researcher can generate:

  • Research reports
  • Project summaries
  • Risk analyses
  • Business cases
  • Recommendation documents
  • Decision-support reports

How Researcher Protects Organizational Data

Researcher follows the same Microsoft 365 security model as Microsoft 365 Copilot.

It respects:

  • Microsoft Graph permissions
  • SharePoint permissions
  • OneDrive permissions
  • Teams permissions
  • Microsoft Purview sensitivity labels
  • Data Loss Prevention (DLP) policies
  • Retention policies
  • Microsoft Defender protections

Researcher cannot retrieve information users are not authorized to access.


Benefits of Researcher

Organizations benefit because Researcher can:

  • Reduce manual research time
  • Improve decision-making
  • Consolidate information from multiple sources
  • Produce consistent reports
  • Improve knowledge discovery
  • Increase employee productivity
  • Reduce duplicate work
  • Accelerate project planning

Limitations of Researcher

Although powerful, Researcher has limitations.

It:

  • Only accesses authorized data.
  • Depends on data quality.
  • Cannot invent missing information.
  • May produce incomplete answers if source data is incomplete.
  • Does not replace human judgment.
  • Does not override organizational permissions.
  • Cannot bypass compliance policies.
  • Should not be considered a legal or regulatory authority.

Users should always review AI-generated conclusions before making important business decisions.


Best Practices

Microsoft recommends that organizations:

  • Ensure SharePoint permissions are accurate before deployment.
  • Apply Microsoft Purview sensitivity labels consistently.
  • Implement DLP policies.
  • Organize content with meaningful names and metadata.
  • Maintain high-quality documentation.
  • Encourage users to write specific research prompts.
  • Review AI-generated reports before distribution.
  • Train employees on responsible AI usage.
  • Monitor adoption and usage.
  • Continuously improve information governance.

Exam Tips

For the AB-900 exam, remember these key points:

  • Researcher is designed for complex, multi-step research tasks, not simple productivity tasks.
  • It uses Microsoft Graph to locate organizational information.
  • It respects all existing Microsoft 365 permissions.
  • Microsoft Purview policies continue to protect data.
  • Researcher can combine information from multiple Microsoft 365 services.
  • It supports report creation, analysis, and decision-making.
  • Human review remains important for critical decisions.
  • Researcher improves productivity but does not replace subject matter expertise.

10 Practice Exam Questions

Question 1

Which type of task is Researcher primarily designed to perform?

A. Multi-step research and analysis across multiple data sources

B. Installing Microsoft 365 applications

C. Managing user licenses

D. Configuring SharePoint permissions

Correct Answer: A

Explanation: Researcher is intended for advanced research, reasoning, and analysis that combines information from multiple sources into comprehensive results.


Question 2

How does Researcher locate relevant organizational content?

A. By ignoring file permissions

B. By using Microsoft Graph to identify accessible organizational data

C. By copying data into a separate database

D. By downloading every SharePoint site locally

Correct Answer: B

Explanation: Researcher relies on Microsoft Graph to discover relationships, files, emails, meetings, and other Microsoft 365 content while respecting user permissions.


Question 3

Which scenario is the best use case for Researcher?

A. Changing a user’s password

B. Assigning Microsoft 365 licenses

C. Comparing multiple project documents and generating a strategic summary

D. Creating a new SharePoint site

Correct Answer: C

Explanation: Researcher excels at analyzing multiple documents and producing synthesized reports or recommendations.


Question 4

Which Microsoft 365 security principle applies to Researcher?

A. Researcher automatically grants access to restricted documents.

B. Researcher temporarily elevates user permissions.

C. Researcher ignores sensitivity labels during analysis.

D. Researcher only accesses content the user is already authorized to view.

Correct Answer: D

Explanation: Researcher follows the same permission model as Microsoft 365 Copilot and cannot access unauthorized content.


Question 5

Which Microsoft technology provides the organizational relationships that Researcher uses?

A. Microsoft Defender

B. Microsoft Entra ID

C. Microsoft Graph

D. Microsoft Intune

Correct Answer: C

Explanation: Microsoft Graph connects users, files, meetings, emails, calendars, and collaboration data that Researcher uses during analysis.


Question 6

Which business activity is a common use case for Researcher?

A. Replacing Microsoft Purview

B. Producing executive briefing reports by combining information from multiple Microsoft 365 sources

C. Managing Azure subscriptions

D. Configuring firewall rules

Correct Answer: B

Explanation: Researcher can consolidate organizational information into executive-ready reports and summaries.


Question 7

What limits the information that Researcher can include in its responses?

A. Internet bandwidth only

B. Microsoft licensing costs only

C. The amount of SharePoint storage available

D. The user’s existing Microsoft 365 permissions and governance policies

Correct Answer: D

Explanation: Researcher can only use data that the requesting user is authorized to access, and it remains subject to governance controls.


Question 8

Which Microsoft Purview capability continues protecting organizational information when Researcher accesses documents?

A. Sensitivity labels and Data Loss Prevention (DLP) policies

B. Printer management

C. Windows Update

D. Device drivers

Correct Answer: A

Explanation: Microsoft Purview policies, including sensitivity labels and DLP, remain fully enforced when Researcher accesses organizational content.


Question 9

Why should users review Researcher-generated reports before acting on them?

A. Researcher cannot create reports.

B. AI-generated findings should be validated because human judgment is still required for important decisions.

C. Researcher always produces incorrect results.

D. Researcher automatically changes organizational data.

Correct Answer: B

Explanation: While Researcher can significantly accelerate analysis, users remain responsible for verifying conclusions and making informed decisions.


Question 10

Which statement best describes Researcher compared to standard Microsoft 365 Copilot?

A. Researcher replaces Microsoft Graph.

B. Researcher is only available in Microsoft Teams.

C. Researcher focuses on deep research, multi-step reasoning, and comprehensive analysis rather than routine productivity tasks.

D. Researcher only summarizes email messages.

Correct Answer: C

Explanation: Standard Copilot primarily assists with day-to-day productivity, whereas Researcher specializes in complex analysis, reasoning, and report generation.


Go to the AB-900 Exam Prep Hub main page

Identify which Copilot features can be enabled or disabled (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Identify which Copilot features can be enabled or disabled


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

One of the primary responsibilities of a Microsoft 365 Copilot administrator is understanding which Copilot features can be controlled through administrative settings. Organizations often have different security, compliance, and business requirements, so Microsoft provides administrators with the ability to enable or disable various Copilot capabilities at the tenant, service, and user levels.

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand:

  • Which Copilot capabilities administrators can control
  • Where these controls are configured
  • Why organizations may enable or disable specific features
  • Which capabilities are always governed by Microsoft 365 permissions rather than simple on/off settings
  • How licensing affects feature availability

Why Organizations Control Copilot Features

Organizations don’t always want every AI capability immediately available to every employee.

Common reasons include:

  • Meeting regulatory requirements
  • Protecting sensitive information
  • Conducting pilot deployments
  • Managing licensing costs
  • Limiting access to experimental features
  • Preventing users from accessing external AI services
  • Reducing organizational risk

Microsoft allows administrators to gradually introduce Copilot while maintaining governance.


Administrative Control Layers

Copilot features can be managed through several layers.

Control LayerPurpose
LicensingDetermines who is entitled to use Copilot
Microsoft 365 Admin CenterEnables or disables Copilot services and manages user assignments
Microsoft Entra IDControls user and group access
Microsoft PurviewApplies compliance, DLP, retention, sensitivity labels, and governance
SharePoint Advanced ManagementControls content access and oversharing protection
Microsoft DefenderProtects against threats affecting Copilot-accessible content
Individual Microsoft 365 AppsMay provide application-specific Copilot settings

These controls work together rather than independently.


Features That Can Be Enabled or Disabled

Administrators can control several Copilot capabilities.

1. Microsoft 365 Copilot Licenses

The most fundamental control is license assignment.

Without a license:

  • Users cannot access Microsoft 365 Copilot.
  • Copilot chat within Microsoft 365 apps is unavailable.
  • AI-powered productivity experiences remain disabled.

Administrators assign or remove licenses through the Microsoft 365 Admin Center.


2. Copilot Chat Availability

Organizations can choose whether users have access to:

  • Microsoft 365 Copilot Chat
  • Enterprise data grounding
  • AI conversations within Microsoft 365

This allows phased deployments.

Example:

  • IT department enabled
  • Executive team enabled
  • Finance enabled later
  • Entire organization enabled after testing

3. Copilot in Individual Microsoft 365 Apps

Copilot experiences exist across multiple applications, including:

  • Word
  • Excel
  • PowerPoint
  • Outlook
  • Teams
  • OneNote

Organizations may decide when to introduce Copilot features within these workloads depending on readiness and licensing.


4. Intelligent Meeting Features

Some Teams AI features can be managed by administrators, including:

  • Intelligent meeting recap
  • AI-generated meeting summaries
  • Suggested action items
  • Meeting notes
  • Transcript availability

Organizations handling confidential meetings may choose to limit some AI-generated meeting experiences.


5. Plugins and Connectors

Administrators can manage:

  • Microsoft Graph connectors
  • Third-party plugins
  • Custom connectors
  • Agent access to external systems

Disabling unnecessary plugins reduces security risk.


6. Copilot Agents

Administrators can control:

  • Which agents are available
  • Who can create agents
  • Who can publish agents
  • Which departments can access specific agents

For example:

Human Resources might publish an HR Benefits Agent while Finance publishes an Expense Policy Agent.


7. Web Grounding

Some Copilot experiences include information from:

  • Microsoft Graph
  • Public web content
  • Organizational content

Organizations may configure which experiences are available depending on licensing and organizational policies.


Features That Cannot Simply Be “Turned Off”

Some Copilot behaviors are governed by Microsoft 365 security rather than feature switches.

Examples include:

Microsoft Graph Permissions

Copilot never ignores permissions.

If a user lacks permission to a file:

  • Copilot cannot retrieve it.
  • There is no setting that overrides SharePoint permissions.

SharePoint Permissions

Copilot always honors:

  • Site permissions
  • Folder permissions
  • File permissions
  • Restricted SharePoint sites

Administrators manage access by changing SharePoint permissions—not Copilot settings.


Microsoft Purview Policies

If Microsoft Purview blocks data through:

  • Sensitivity labels
  • DLP policies
  • Retention policies

Copilot follows those controls automatically.


Microsoft Defender Policies

Security policies continue protecting data regardless of Copilot.

Examples include:

  • Safe Links
  • Safe Attachments
  • Threat protection
  • Malware detection

Copilot cannot bypass Defender protections.


Enabling Copilot Through Licensing

Most Copilot functionality depends on licensing.

Typical process:

  1. Purchase licenses.
  2. Assign licenses.
  3. Configure organizational settings.
  4. Enable users or groups.
  5. Monitor adoption.
  6. Expand deployment gradually.

Removing the license immediately removes access.


Feature Rollout Strategies

Many organizations deploy Copilot in phases.

Example rollout:

PhaseUsers
PilotIT department
Early adoptersBusiness champions
Department rolloutHR, Finance, Sales
Enterprise rolloutEntire organization

This minimizes disruption and allows administrators to gather feedback.


Feature Controls for Copilot Agents

Agent administrators can typically control:

  • Agent publishing
  • Agent availability
  • Knowledge sources
  • Connector permissions
  • Agent sharing
  • Agent lifecycle
  • Agent retirement

These settings help prevent unauthorized AI experiences.


Managing Experimental Features

Microsoft periodically releases:

  • Preview capabilities
  • Experimental AI experiences
  • Early-access functionality

Organizations can often choose whether these features are available.

Many enterprises disable preview features until internal testing is complete.


Monitoring Enabled Features

Administrators should monitor:

  • License assignments
  • Usage reports
  • Adoption metrics
  • Agent activity
  • Security alerts
  • Compliance reports
  • AI interactions (where supported)

Monitoring helps determine whether enabled features are providing value while remaining compliant.


Best Practices

Microsoft recommends:

  • Start with a pilot group.
  • Assign licenses only to intended users.
  • Review SharePoint permissions before deployment.
  • Apply Microsoft Purview protection policies first.
  • Enable only required plugins.
  • Monitor adoption regularly.
  • Review security settings before enabling new AI capabilities.
  • Use least-privilege access.
  • Periodically review agent permissions.
  • Train users before broad rollout.

Exam Tips

For the AB-900 exam, remember these key points:

  • Licensing is the primary method of enabling Microsoft 365 Copilot.
  • Administrators can enable or disable access for users and groups.
  • Copilot always respects Microsoft Graph permissions.
  • Microsoft Purview protections continue to apply to Copilot.
  • SharePoint permissions cannot be bypassed by Copilot.
  • Administrators can manage plugins, connectors, and agents.
  • Many organizations use phased deployments.
  • Security and governance controls remain in effect regardless of Copilot features.

10 Practice Exam Questions

Question 1

What is the primary requirement for a user to access Microsoft 365 Copilot?

A. Membership in the Global Readers group

B. Assignment of an appropriate Microsoft 365 Copilot license

C. Creation of a Copilot agent

D. A Microsoft Teams Premium license

Correct Answer: B

Explanation: A Microsoft 365 Copilot license is required before users can access Copilot experiences.


Question 2

An administrator wants to introduce Copilot to only the IT department before rolling it out company-wide. What is the recommended approach?

A. Disable Microsoft Graph

B. Remove SharePoint permissions

C. Assign Copilot licenses only to the IT department

D. Create separate Microsoft 365 tenants

Correct Answer: C

Explanation: Administrators commonly pilot Copilot by assigning licenses only to selected users or groups.


Question 3

Which security principle does Microsoft 365 Copilot always follow?

A. It ignores file permissions for administrators.

B. It grants temporary access to files during conversations.

C. It respects existing Microsoft Graph and Microsoft 365 permissions.

D. It automatically shares documents across departments.

Correct Answer: C

Explanation: Copilot only accesses content the user already has permission to view.


Question 4

Which capability can administrators commonly control?

A. Whether users can access Copilot agents

B. Whether Copilot can ignore sensitivity labels

C. Whether Microsoft Graph indexes SharePoint

D. Whether SharePoint stores documents

Correct Answer: A

Explanation: Administrators can manage agent availability, publication, and access permissions.


Question 5

What happens if a user’s Microsoft 365 Copilot license is removed?

A. Existing AI conversations become public.

B. SharePoint permissions are deleted.

C. Copilot access is removed from that user.

D. Microsoft Graph stops indexing organizational content.

Correct Answer: C

Explanation: Removing the Copilot license removes the user’s entitlement to Copilot services.


Question 6

Which Microsoft technology automatically continues enforcing sensitivity labels when users work with Copilot?

A. Microsoft Defender for Endpoint

B. Microsoft Purview

C. Microsoft Intune

D. Microsoft Planner

Correct Answer: B

Explanation: Microsoft Purview applies data protection controls, including sensitivity labels, regardless of whether Copilot is used.


Question 7

Why might an organization disable certain Copilot plugins?

A. To reduce security risks from unnecessary external integrations

B. To increase Microsoft Graph indexing speed

C. To improve Outlook mailbox quotas

D. To eliminate SharePoint storage limits

Correct Answer: A

Explanation: Limiting plugins reduces the organization’s attack surface and helps maintain governance.


Question 8

Which feature continues protecting documents even after Copilot is enabled?

A. Microsoft Graph indexing

B. Microsoft Purview DLP policies

C. Copilot prompts

D. AI-generated summaries

Correct Answer: B

Explanation: Data Loss Prevention policies remain fully enforced when Copilot accesses organizational data.


Question 9

What is a common best practice when deploying Microsoft 365 Copilot?

A. Enable every Copilot feature for all employees immediately.

B. Remove SharePoint permissions before deployment.

C. Begin with a pilot deployment and expand gradually.

D. Disable Microsoft Purview during rollout.

Correct Answer: C

Explanation: A phased rollout allows administrators to validate security, governance, and user adoption before organization-wide deployment.


Question 10

Which statement about SharePoint permissions and Copilot is correct?

A. Copilot can temporarily bypass SharePoint permissions.

B. Copilot automatically grants access to related files.

C. Administrators can disable SharePoint permissions while keeping Copilot enabled.

D. Copilot only accesses SharePoint content the user is already authorized to view.

Correct Answer: D

Explanation: Copilot always honors existing SharePoint permissions and cannot access content beyond the user’s authorized access.


Go to the AB-900 Exam Prep Hub main page