Tag: Microsoft 365 Copilot

Compare Copilot monthly license model to Pay-as-You-Go, including SharePoint (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Compare Copilot monthly license model to Pay-as-You-Go, including SharePoint


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft offers multiple licensing models for AI experiences across Microsoft 365. Understanding these licensing options is important for administrators who plan deployments, manage costs, and determine which AI capabilities are available to users.

For the AB-900 exam, you should understand the differences between:

  • Microsoft 365 Copilot monthly user licensing
  • Pay-as-you-go (consumption-based) licensing
  • SharePoint Copilot licensing
  • When each licensing model is appropriate

The exam focuses on understanding the concepts rather than memorizing pricing.


Why Multiple Licensing Models Exist

Organizations vary greatly in how employees use AI.

Some organizations:

  • Have employees who use AI all day.
  • Need AI integrated into Microsoft 365 apps.
  • Require predictable monthly costs.

Other organizations:

  • Use AI occasionally.
  • Need specialized agents.
  • Want to pay only when AI is used.

Microsoft therefore offers both subscription-based and consumption-based licensing.


Microsoft 365 Copilot Monthly License Model

The traditional Microsoft 365 Copilot license is assigned to individual users.

Each licensed user receives access to Copilot experiences across supported Microsoft 365 applications.

Examples include:

  • Word
  • Excel
  • PowerPoint
  • Outlook
  • Teams
  • OneNote
  • Microsoft 365 Chat

The license is:

  • Assigned per user
  • Monthly subscription
  • Predictable recurring cost

Characteristics of the Monthly License

The monthly model provides:

  • Full Microsoft 365 Copilot experience
  • Unlimited daily usage (subject to service limits)
  • Personalized AI assistance
  • Microsoft Graph integration
  • Cross-app experiences
  • Enterprise security and compliance

This model is best for employees who regularly use Copilot throughout their workday.


Typical Monthly License Scenario

A financial analyst uses Copilot every day to:

  • Analyze Excel workbooks
  • Draft reports
  • Summarize meetings
  • Create PowerPoint presentations
  • Search organizational knowledge

Because AI is used continuously, a monthly license provides predictable costs.


Benefits of Monthly Licensing

Advantages include:

  • Predictable budgeting
  • No need to monitor consumption
  • Continuous access
  • Simplified administration
  • Consistent user experience
  • Ideal for heavy users

Limitations of Monthly Licensing

Considerations include:

  • Fixed monthly cost regardless of usage
  • Not ideal for occasional users
  • Every user requires their own license
  • Organizations may over-license infrequent users

Pay-as-You-Go Licensing

Pay-as-you-go (PAYG) is a consumption-based licensing model.

Instead of paying for every user every month, organizations pay based on actual AI usage.

Think of it similarly to cloud computing services:

  • More usage = higher cost
  • Less usage = lower cost

Characteristics of Pay-as-You-Go

Pay-as-you-go provides:

  • Usage-based billing
  • Flexible scaling
  • No requirement for every user to have a monthly Copilot license
  • Cost based on AI requests or service consumption (depending on the service)

This model is especially useful for agents and certain AI scenarios.


Benefits of Pay-as-You-Go

Advantages include:

  • Lower upfront costs
  • Pay only for actual usage
  • Flexible deployment
  • Easy experimentation
  • Ideal for seasonal workloads
  • Good for occasional users

Limitations of Pay-as-You-Go

Potential drawbacks include:

  • Variable monthly costs
  • Budget forecasting is more difficult
  • Requires monitoring usage
  • Heavy usage may become more expensive than subscription licensing

Comparing Monthly Licensing and Pay-as-You-Go

Monthly LicensePay-as-You-Go
Fixed monthly costUsage-based cost
Licensed per userConsumption-based
Predictable budgetingVariable spending
Best for daily usersBest for occasional use
Continuous Copilot accessPay only when AI is used
Simpler cost managementRequires usage monitoring

Microsoft 365 Copilot Chat

Organizations should understand that Microsoft offers AI experiences beyond the traditional monthly Copilot license.

For example:

  • Microsoft 365 Copilot Chat is available to Microsoft 365 users.
  • Organizations can extend Copilot Chat with agents.
  • Some agent usage can be billed using pay-as-you-go licensing rather than requiring every user to have a full Copilot subscription.

This provides flexibility for organizations with mixed AI usage patterns.


SharePoint and Copilot

SharePoint includes AI capabilities that help users work with documents, sites, and organizational knowledge.

Examples include:

  • Summarizing documents
  • Answering questions about files
  • Generating page content
  • Assisting with document creation
  • Improving knowledge discovery

SharePoint Agents

One important capability is SharePoint agents.

A SharePoint agent can:

  • Be created from a SharePoint site or document library
  • Answer questions using approved SharePoint content
  • Help users locate organizational knowledge
  • Reduce the need to manually search documents

For example:

A Human Resources SharePoint site may contain:

  • Employee handbook
  • Benefits guide
  • Leave policies
  • Training documents

An HR SharePoint agent can answer employee questions using those documents.


SharePoint Pay-as-You-Go

Organizations can use SharePoint agents without assigning every user a full Microsoft 365 Copilot license.

Instead, administrators can configure consumption-based billing.

Benefits include:

  • Lower cost for occasional users
  • Easy pilot deployments
  • Department-specific AI
  • Flexible scaling

This makes SharePoint agents attractive for organizations wanting targeted AI experiences without licensing every employee.


Choosing the Right Licensing Model

Choose Monthly Licensing When

  • Employees use Copilot every day.
  • AI is integrated into daily workflows.
  • Predictable monthly budgeting is important.
  • Users need full Copilot functionality across Microsoft 365.

Examples:

  • Executives
  • Project managers
  • Analysts
  • Consultants
  • Sales professionals
  • Knowledge workers

Choose Pay-as-You-Go When

  • AI usage is occasional.
  • Organizations are testing AI.
  • Departments need specialized agents.
  • Seasonal usage is expected.
  • Budget flexibility is acceptable.

Examples:

  • HR help desk agent
  • Legal document agent
  • IT support chatbot
  • SharePoint knowledge assistant

Administrative Considerations

Administrators should evaluate:

  • Expected AI usage
  • Number of users
  • Cost predictability
  • Department requirements
  • Governance policies
  • Licensing strategy
  • Agent deployment plans

Security Remains the Same

Regardless of licensing model:

  • Microsoft Entra ID authentication is used.
  • Microsoft Graph permissions are enforced.
  • Microsoft Purview policies apply.
  • Data Loss Prevention (DLP) policies remain active.
  • Sensitivity labels continue protecting content.
  • Microsoft Defender protections remain in effect.

Licensing changes how organizations pay for AI—not how Microsoft secures organizational data.


Best Practices

Microsoft recommends that organizations:

  • License frequent users with Microsoft 365 Copilot subscriptions.
  • Use pay-as-you-go for occasional AI usage.
  • Monitor AI adoption and consumption.
  • Start with pilot deployments.
  • Evaluate SharePoint agents for departmental knowledge scenarios.
  • Review licensing regularly as adoption increases.

Exam Tips

For the AB-900 exam, remember these key points:

  • Microsoft 365 Copilot is commonly licensed per user with a monthly subscription.
  • Pay-as-you-go bills organizations based on AI usage.
  • Monthly licensing provides predictable costs.
  • Pay-as-you-go offers flexibility for occasional or specialized AI use.
  • SharePoint agents can be deployed using consumption-based licensing in supported scenarios.
  • Licensing affects billing—not security or permissions.
  • Microsoft Graph, Microsoft Purview, and Microsoft Entra ID protections apply regardless of licensing model.
  • Heavy AI users are generally better suited to monthly licensing.
  • Departmental or pilot AI deployments often benefit from pay-as-you-go.

Practice Exam Questions

Question 1

Which licensing model provides users with a predictable monthly cost for Microsoft 365 Copilot?

A. Pay-as-you-go
B. Monthly per-user license
C. Azure consumption credits
D. SharePoint storage licensing

Correct Answer: B

Explanation: A monthly per-user license provides continuous access to Microsoft 365 Copilot for a fixed monthly subscription.


Question 2

What is the primary advantage of the pay-as-you-go licensing model?

A. Users receive unlimited AI usage regardless of activity.
B. Organizations pay only for actual AI usage.
C. Every employee automatically receives Microsoft 365 Copilot.
D. It disables Microsoft Graph integration.

Correct Answer: B

Explanation: Pay-as-you-go charges based on consumption, making it suitable for occasional or specialized AI usage.


Question 3

Which type of user is generally the best candidate for a Microsoft 365 Copilot monthly license?

A. An employee who rarely uses Microsoft 365 applications
B. A seasonal contractor who accesses AI once a month
C. A knowledge worker who uses Copilot throughout the workday
D. A visitor with guest access to SharePoint

Correct Answer: C

Explanation: Heavy or daily users benefit from the predictable costs and continuous access provided by the monthly licensing model.


Question 4

An organization wants to deploy an HR SharePoint agent that employees will use occasionally. Which licensing model is often the better fit?

A. Monthly Copilot license for every employee
B. Windows Enterprise licensing
C. Exchange Online licensing
D. Pay-as-you-go

Correct Answer: D

Explanation: Pay-as-you-go is well suited for departmental agents with occasional usage, allowing organizations to pay based on consumption.


Question 5

Which statement about Microsoft 365 Copilot monthly licensing is correct?

A. It charges only when AI is used.
B. It is assigned to individual users as a subscription.
C. It replaces Microsoft Entra ID.
D. It is available only for SharePoint.

Correct Answer: B

Explanation: The traditional Microsoft 365 Copilot model is licensed per user through a recurring subscription.


Question 6

Which capability is commonly associated with SharePoint agents?

A. Managing Windows updates
B. Replacing Microsoft Graph
C. Answering questions using SharePoint content and document libraries
D. Creating Azure virtual machines

Correct Answer: C

Explanation: SharePoint agents are grounded in SharePoint content and help users locate and understand organizational knowledge.


Question 7

How do Microsoft Purview policies behave when an organization switches from monthly licensing to pay-as-you-go?

A. They are automatically disabled.
B. They apply only to SharePoint documents.
C. They require users to purchase additional licenses before functioning.
D. They continue to protect data regardless of the licensing model.

Correct Answer: D

Explanation: Security and compliance controls such as Microsoft Purview continue to protect data regardless of how AI services are licensed.


Question 8

Which licensing model generally provides the most predictable monthly budgeting?

A. Pay-as-you-go
B. Monthly per-user licensing
C. Azure Reserved Instances
D. SharePoint storage quotas

Correct Answer: B

Explanation: Monthly licensing offers a fixed recurring cost, simplifying budgeting and financial planning.


Question 9

What is a potential disadvantage of pay-as-you-go licensing?

A. It cannot be used with agents.
B. It prevents users from accessing SharePoint.
C. Monthly costs may vary depending on AI usage.
D. It disables Microsoft Graph permissions.

Correct Answer: C

Explanation: Consumption-based billing means costs fluctuate according to actual usage, making budgeting less predictable.


Question 10

Which statement best summarizes the difference between Microsoft 365 Copilot monthly licensing and pay-as-you-go?

A. Monthly licensing is subscription-based, while pay-as-you-go is consumption-based.
B. Monthly licensing does not include Microsoft Graph.
C. Pay-as-you-go removes Microsoft Purview protections.
D. Monthly licensing is only available for SharePoint.

Correct Answer: A

Explanation: The fundamental difference is the billing model: monthly licensing charges a fixed subscription per user, whereas pay-as-you-go charges based on actual AI service consumption.


Go to the AB-900 Exam Prep Hub main page

Compare the built-in capabilities of Copilot and agents (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Compare the built-in capabilities of Copilot and agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft 365 provides powerful AI capabilities through Microsoft 365 Copilot and agents. Although they are closely related, they serve different purposes.

A common misconception is that Copilot and agents are the same technology. In reality:

  • Microsoft 365 Copilot is the AI assistant that helps users work across Microsoft 365 applications.
  • Agents are specialized AI assistants designed to perform focused tasks, automate business processes, or provide expertise in specific domains.

Understanding the differences between Copilot and agents is an important objective on the AB-900 exam.


What is Microsoft 365 Copilot?

Microsoft 365 Copilot is Microsoft’s AI assistant integrated throughout Microsoft 365 applications.

It combines:

  • Large Language Models (LLMs)
  • Microsoft Graph
  • Microsoft 365 data
  • User permissions
  • Organizational knowledge

Copilot helps users complete everyday work faster while respecting existing security permissions.

Examples include:

  • Drafting emails
  • Summarizing meetings
  • Creating PowerPoint presentations
  • Analyzing Excel data
  • Writing Word documents
  • Answering natural language questions
  • Summarizing Teams chats

Copilot is designed to improve personal productivity across many different tasks.


What are Microsoft 365 Agents?

Agents are AI assistants created to perform specialized or repeatable business tasks.

Rather than serving as a general assistant, an agent focuses on a specific job.

Examples include:

  • HR policy assistant
  • IT help desk assistant
  • Sales proposal assistant
  • Customer service assistant
  • Legal document assistant
  • Procurement assistant
  • Finance assistant

Agents can:

  • Answer questions from approved knowledge sources
  • Follow business rules
  • Guide users through processes
  • Complete multi-step workflows
  • Connect to business systems

Comparing Copilot and Agents

Microsoft 365 CopilotMicrosoft 365 Agents
General-purpose AI assistantSpecialized AI assistant
Works across Microsoft 365Focuses on a specific business task
Assists individual productivityAssists business processes
Uses Microsoft Graph extensivelyCan use Graph plus additional knowledge sources
Available in Microsoft 365 appsCan be published inside Teams, Microsoft 365, SharePoint, and other experiences
Broad conversational abilitiesDomain-specific expertise

Built-in Capabilities of Microsoft 365 Copilot

Copilot includes many built-in features without requiring customization.

Content Creation

Copilot can:

  • Draft documents
  • Rewrite text
  • Summarize documents
  • Change writing tone
  • Generate presentations
  • Create outlines
  • Brainstorm ideas

Example:

“Create a proposal for a new customer.”


Meeting Intelligence

Within Microsoft Teams, Copilot can:

  • Summarize meetings
  • Capture decisions
  • List action items
  • Answer questions about the meeting
  • Identify unresolved issues

Example:

“What decisions were made during yesterday’s meeting?”


Email Assistance

In Outlook, Copilot can:

  • Draft responses
  • Summarize long email threads
  • Suggest follow-up actions
  • Improve writing style

Data Analysis

Within Excel, Copilot can:

  • Explain formulas
  • Generate charts
  • Analyze trends
  • Identify outliers
  • Create summaries

Example:

“Show quarterly sales trends.”


Knowledge Discovery

Copilot searches organizational knowledge using Microsoft Graph.

It can answer questions such as:

  • “What projects am I working on?”
  • “Summarize documents related to Project Apollo.”
  • “What files has my manager recently shared?”

Cross-Application Context

One major capability is connecting information across applications.

Example:

Copilot may combine information from:

  • Outlook
  • Teams
  • Word
  • OneDrive
  • SharePoint
  • Calendar

to answer a single prompt.


Built-in Capabilities of Agents

Agents focus on completing specialized work.


Task-Specific Expertise

An agent is trained or configured around one topic.

Examples:

HR Agent

  • Vacation policy
  • Benefits
  • Employee handbook

IT Agent

  • Password reset guidance
  • Software installation
  • Device troubleshooting

Finance Agent

  • Expense reimbursement
  • Budget approval
  • Procurement rules

Business Process Guidance

Agents can walk users through business procedures.

Example:

Instead of simply answering a question, an HR onboarding agent can:

  • Explain required forms
  • Guide new employees
  • Answer benefits questions
  • Provide training links

Knowledge Grounding

Agents can use approved organizational knowledge.

Examples include:

  • SharePoint libraries
  • Internal documents
  • Knowledge bases
  • Business manuals
  • Policies
  • FAQs

Unlike general internet chatbots, agents only answer from approved sources.


Workflow Automation

Agents can perform multiple steps automatically.

Example:

A travel request agent might:

  • Collect travel details
  • Validate policy
  • Request manager approval
  • Submit the request
  • Notify the employee

Connectors

Agents can connect to external business systems.

Examples:

  • Dynamics 365
  • ServiceNow
  • Salesforce
  • SAP
  • Workday
  • Microsoft Dataverse

This allows agents to retrieve business information securely.


Consistent Business Responses

Unlike free-form conversations, agents provide consistent answers based on organizational knowledge.

This reduces confusion and improves compliance.


Shared Capabilities

Both Copilot and agents share many AI features.

These include:

  • Natural language interaction
  • Context-aware conversations
  • AI-generated responses
  • Respect for Microsoft Entra ID permissions
  • Security trimming
  • Microsoft Graph integration (where applicable)
  • Use of Large Language Models
  • Support for Microsoft 365 security and compliance controls

Key Differences

Scope

Copilot

Broad productivity assistant.

Agent

Focused business assistant.


Purpose

Copilot

Helps users complete work.

Agent

Helps complete specific business processes.


Knowledge

Copilot

Uses Microsoft Graph plus organizational content.

Agent

Uses selected knowledge sources chosen by administrators or creators.


Customization

Copilot

Little customization required.

Agents

Often customized for departments or business scenarios.


Reusability

Copilot

Same assistant for everyone (subject to permissions).

Agents

Different agents can exist for different teams.

Examples:

  • Legal Agent
  • Sales Agent
  • Finance Agent
  • HR Agent

Copilot vs. Agent Example

A user asks:

“I need to prepare for a customer renewal.”

Copilot might:

  • Summarize recent emails
  • Review meeting notes
  • Draft a proposal
  • Create a PowerPoint

A Sales Agent might:

  • Retrieve CRM information
  • Check renewal status
  • Calculate discounts
  • Recommend pricing
  • Generate renewal documentation

Both assist the user—but in different ways.


Security

Both Copilot and agents follow Microsoft security principles.

They respect:

  • Microsoft Entra ID authentication
  • User permissions
  • Microsoft Graph security trimming
  • Microsoft Purview sensitivity labels
  • Data Loss Prevention (DLP) policies
  • Conditional Access policies
  • Compliance controls

Neither Copilot nor agents expose information users are not authorized to access.


Common Exam Tips

Remember these distinctions:

  • Copilot is a general-purpose AI assistant.
  • Agents are specialized assistants for business scenarios.
  • Copilot improves productivity across Microsoft 365.
  • Agents automate or simplify specific business tasks.
  • Both use natural language.
  • Both respect existing Microsoft 365 permissions.
  • Agents can connect to external business systems.
  • Multiple agents can exist within the same organization.
  • Copilot does not replace business applications—it works with them.
  • Administrators govern both using Microsoft 365 security and compliance controls.

Practice Exam Questions

Question 1

What is the primary purpose of Microsoft 365 Copilot?

A. Replace business applications
B. Provide a general AI assistant across Microsoft 365 applications
C. Manage Microsoft Entra ID users
D. Automatically configure SharePoint permissions

Correct Answer: B

Explanation: Microsoft 365 Copilot is a general-purpose AI assistant that enhances productivity across Microsoft 365 applications.


Question 2

Which scenario is best suited for a Microsoft 365 agent?

A. Creating a PowerPoint presentation from meeting notes
B. Summarizing an Outlook inbox
C. Guiding employees through HR onboarding procedures
D. Drafting a Word document

Correct Answer: C

Explanation: Agents are designed for specialized business tasks such as HR onboarding, IT support, or finance workflows.


Question 3

Which feature is shared by both Microsoft 365 Copilot and agents?

A. They ignore Microsoft Entra permissions.
B. They require internet searches for every response.
C. They automatically grant file access.
D. They support natural language conversations.

Correct Answer: D

Explanation: Both Copilot and agents use conversational AI, allowing users to interact using natural language.


Question 4

Which capability is unique to many business agents?

A. Creating Word documents
B. Summarizing Teams meetings
C. Performing specialized workflows using business systems
D. Rewriting email messages

Correct Answer: C

Explanation: Agents can automate specialized business workflows and connect with enterprise systems.


Question 5

Microsoft 365 Copilot primarily retrieves organizational information through:

A. Microsoft Graph
B. Azure Virtual Desktop
C. Windows Registry
D. Local device storage

Correct Answer: A

Explanation: Microsoft Graph provides Copilot with secure access to organizational data while respecting user permissions.


Question 6

Which statement best describes Microsoft 365 agents?

A. They replace Microsoft Graph.
B. They are designed for focused business scenarios and specialized tasks.
C. They only answer questions about Microsoft products.
D. They are available only in Outlook.

Correct Answer: B

Explanation: Agents are purpose-built AI assistants that support specific business processes or departmental functions.


Question 7

How do Copilot and agents protect organizational data?

A. They bypass file permissions for administrators.
B. They make all SharePoint content searchable.
C. They respect existing Microsoft 365 permissions and compliance controls.
D. They permanently copy data into AI models.

Correct Answer: C

Explanation: Both solutions honor Microsoft Entra ID permissions, Microsoft Graph security trimming, and Microsoft Purview governance policies.


Question 8

Which task would Microsoft 365 Copilot most likely perform?

A. Reset a user’s Active Directory password automatically.
B. Analyze an Excel workbook and explain sales trends.
C. Replace the organization’s CRM system.
D. Configure Conditional Access policies.

Correct Answer: B

Explanation: Copilot excels at productivity tasks such as analyzing Excel data and generating insights.


Question 9

An organization creates separate HR, Legal, and Finance AI assistants. These are examples of:

A. Microsoft Graph connectors
B. SharePoint hubs
C. Copilot prompts
D. Specialized agents

Correct Answer: D

Explanation: Organizations can build multiple specialized agents tailored to different departments and business functions.


Question 10

What is one of the biggest differences between Microsoft 365 Copilot and agents?

A. Copilot is a broad productivity assistant, while agents focus on specific business tasks.
B. Agents do not use AI.
C. Copilot ignores Microsoft 365 permissions.
D. Agents cannot access organizational knowledge.

Correct Answer: A

Explanation: Copilot provides broad productivity assistance across Microsoft 365, whereas agents are designed for specialized business scenarios and targeted workflows.


Go to the AB-900 Exam Prep Hub main page

Identify policy violations generated by Communication Compliance (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Identify policy violations generated by Communication Compliance


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand how Microsoft Purview Communication Compliance helps organizations detect, investigate, and respond to inappropriate communications that may violate corporate policies, legal requirements, or regulatory standards. You should also understand how administrators review policy matches, investigate alerts, and take appropriate remediation actions.


What is Microsoft Purview Communication Compliance?

Microsoft Purview Communication Compliance is a Microsoft Purview solution that helps organizations detect and investigate inappropriate or risky communications across Microsoft 365 services.

Rather than preventing users from communicating, Communication Compliance monitors communications and alerts authorized reviewers when messages match organizational policies.

It helps organizations detect communications involving:

  • Harassment
  • Discrimination
  • Offensive language
  • Threats
  • Confidential information sharing
  • Regulatory violations
  • Inappropriate behavior
  • Insider risks

Communication Compliance is designed to reduce legal, compliance, and reputational risks while helping organizations meet industry regulations.


Why Communication Compliance Is Important

Organizations communicate constantly using:

  • Microsoft Teams chats
  • Teams channel messages
  • Outlook emails
  • Viva Engage (Yammer)
  • Third-party communication platforms (through supported connectors)

Without monitoring, inappropriate communications may:

  • Create hostile work environments
  • Lead to lawsuits
  • Violate government regulations
  • Expose confidential information
  • Damage an organization’s reputation

Communication Compliance provides visibility into these risks.


What Are Policy Violations?

A policy violation occurs when a communication matches conditions defined within a Communication Compliance policy.

Examples include:

  • Use of offensive language
  • Bullying or harassment
  • Sharing confidential customer information
  • Threatening another employee
  • Insider trading discussions
  • Regulatory compliance violations
  • Sharing protected intellectual property

A policy violation does not automatically mean misconduct occurred.

Instead, it means the communication requires human review.


How Communication Compliance Works

The workflow follows several stages.

Step 1: Create a Policy

Administrators create policies that define:

  • Users or groups to monitor
  • Communication locations
  • Types of violations
  • Detection conditions
  • Review workflow

Step 2: Monitor Communications

Communication Compliance continuously analyzes supported communications.

Examples include:

  • Teams messages
  • Emails
  • Viva Engage posts

Content is evaluated against policy conditions.


Step 3: Generate Alerts

If content matches a policy:

  • An alert is generated.
  • The alert appears in the Communication Compliance dashboard.
  • Reviewers receive notification.

Step 4: Human Review

Authorized reviewers investigate:

  • Original message
  • Conversation context
  • Users involved
  • Severity
  • Previous incidents

Reviewers determine whether the communication truly violated policy.


Step 5: Resolution

Reviewers choose an appropriate action, such as:

  • Resolve as compliant
  • Confirm violation
  • Escalate investigation
  • Notify HR
  • Notify legal
  • Train employee
  • Document findings

Common Types of Policy Violations

Harassment

Detects communications containing:

  • Insults
  • Bullying
  • Abusive language
  • Threats

Example:

“You’re completely useless and should quit.”


Discrimination

Detects language involving:

  • Race
  • Gender
  • Religion
  • Disability
  • Age
  • Protected characteristics

Offensive Language

Identifies:

  • Profanity
  • Hate speech
  • Offensive expressions

Sensitive Information Sharing

Detects messages containing:

  • Credit card numbers
  • Social Security numbers
  • Customer information
  • Financial records
  • Medical information

Regulatory Compliance Violations

Organizations in regulated industries monitor communications involving:

  • Insider trading
  • Market manipulation
  • Financial misconduct
  • Unauthorized disclosures

Confidential Information

Detects unauthorized sharing of:

  • Trade secrets
  • Product designs
  • Internal reports
  • Source code
  • Financial forecasts

Policy Alerts

A Communication Compliance alert contains information such as:

  • Policy name
  • Date and time
  • Severity
  • User involved
  • Communication type
  • Matched rule
  • Review status

Alerts help reviewers prioritize investigations.


Alert Severity

Organizations often classify alerts as:

Low

Minor language concerns.

Example:

A mildly inappropriate joke.


Medium

Behavior that may violate company policy.

Example:

Repeated offensive language.


High

Serious compliance concern.

Example:

Threats of violence or disclosure of confidential data.


Reviewing Policy Violations

Authorized reviewers access the Communication Compliance portal.

During review they can examine:

  • Conversation history
  • Message participants
  • Attachments
  • Policy triggered
  • Matching keywords
  • Previous incidents
  • Related alerts

Context is important because individual messages may appear harmless without surrounding conversation.


Investigation Workflow

A typical investigation includes:

  1. Open the alert.
  2. Review message details.
  3. Examine conversation context.
  4. Determine whether policy was actually violated.
  5. Assign a review outcome.
  6. Document findings.
  7. Close or escalate the case.

Possible Review Outcomes

Reviewers may classify alerts as:

  • No violation
  • Violation confirmed
  • Needs escalation
  • False positive
  • Resolved

These outcomes help improve future policy effectiveness.


False Positives

Not every alert represents an actual violation.

Examples include:

  • Educational discussions
  • Medical terminology
  • Technical documentation
  • Quoted material
  • Sarcasm
  • Context misunderstood by automated analysis

Human review remains essential.


Improving Detection Accuracy

Organizations can improve policy effectiveness by:

  • Updating keyword dictionaries
  • Using machine learning classifiers
  • Adjusting policy thresholds
  • Creating separate policies for departments
  • Reviewing false positives
  • Refining monitored user groups

Who Reviews Violations?

Communication Compliance uses role-based access control.

Typical reviewers include:

  • Compliance administrators
  • Compliance officers
  • Human Resources
  • Legal teams
  • Risk investigators

Only authorized personnel can review sensitive communications.


Privacy Considerations

Communication Compliance is designed with privacy controls.

Organizations can:

  • Limit reviewer access
  • Use pseudonymization (where supported)
  • Restrict investigations
  • Audit reviewer actions
  • Follow regional privacy laws

Integration with Other Microsoft Security Solutions

Communication Compliance works alongside several Microsoft security solutions.

Microsoft Purview Insider Risk Management

Communication Compliance findings may support insider risk investigations involving suspicious employee behavior.


Microsoft Purview Data Loss Prevention (DLP)

DLP prevents unauthorized sharing of sensitive information, while Communication Compliance reviews the content and context of communications.


Microsoft Purview Information Protection

Sensitivity labels applied to documents help reviewers understand the sensitivity of shared information.


Microsoft Defender

Security incidents and user risk signals can complement Communication Compliance investigations.


Communication Compliance and Microsoft 365 Copilot

As organizations adopt Microsoft 365 Copilot, Communication Compliance remains important because users increasingly collaborate through Teams, Outlook, and other Microsoft 365 services that Copilot can reference based on existing permissions.

If inappropriate communications occur, Communication Compliance can:

  • Detect policy violations
  • Assist investigations
  • Support regulatory compliance
  • Help protect organizational reputation
  • Complement broader Microsoft Purview governance capabilities

Best Practices

For the AB-900 exam, remember these best practices:

  • Monitor communications using clearly defined policies.
  • Review alerts promptly.
  • Always investigate message context before making decisions.
  • Use authorized reviewers only.
  • Tune policies to reduce false positives.
  • Protect employee privacy while maintaining compliance.
  • Integrate Communication Compliance with broader Microsoft Purview governance.

AB-900 Exam Tips

Remember these key points:

  • Communication Compliance monitors communications—it does not block them.
  • Policy violations generate alerts, not automatic disciplinary actions.
  • Human reviewers determine whether a true violation occurred.
  • Context matters when reviewing communications.
  • Communication Compliance supports compliance, legal, HR, and risk management teams.
  • Alerts can detect harassment, discrimination, offensive language, regulatory violations, and sensitive information sharing.
  • Communication Compliance works together with Insider Risk Management, DLP, Information Protection, and Microsoft Defender.

Practice Exam Questions

Question 1

What is the primary purpose of Microsoft Purview Communication Compliance?

A. Encrypt all Microsoft Teams messages

B. Detect and investigate communications that may violate organizational policies

C. Prevent users from sending emails

D. Back up Microsoft 365 communications

Correct Answer: B

Explanation: Communication Compliance monitors supported communications and generates alerts when messages match configured compliance policies.


Question 2

A Communication Compliance alert indicates that a Teams message matched a harassment policy. What should happen next?

A. The user account is automatically disabled.

B. The message is permanently deleted.

C. An authorized reviewer investigates the communication.

D. The policy is automatically removed.

Correct Answer: C

Explanation: Communication Compliance generates alerts for human review rather than taking automatic disciplinary actions.


Question 3

Which type of communication can Microsoft Purview Communication Compliance monitor?

A. BIOS startup messages

B. Local Windows Event Logs

C. Microsoft Teams chats

D. Printer configuration files

Correct Answer: C

Explanation: Teams chats are one of the primary communication sources monitored by Communication Compliance.


Question 4

Why is conversation context important when reviewing alerts?

A. It determines network bandwidth.

B. It identifies device drivers.

C. It encrypts communications.

D. It helps reviewers determine whether a message truly violates policy.

Correct Answer: D

Explanation: Individual messages may appear inappropriate when viewed alone but may be acceptable within the full conversation.


Question 5

Which activity is an example of a Communication Compliance policy violation?

A. Updating Windows patches

B. Sharing vacation schedules

C. Sending offensive or harassing messages to coworkers

D. Resetting a forgotten password

Correct Answer: C

Explanation: Offensive or harassing communications are common scenarios monitored by Communication Compliance.


Question 6

Who should review Communication Compliance alerts?

A. Any employee

B. Only authorized compliance reviewers

C. External customers

D. Guest users

Correct Answer: B

Explanation: Access to Communication Compliance investigations is limited through role-based access control.


Question 7

What is a false positive in Communication Compliance?

A. A communication incorrectly identified as violating policy

B. A deleted user account

C. An expired Microsoft 365 license

D. A successful malware scan

Correct Answer: A

Explanation: False positives occur when automated detection flags communications that are ultimately determined not to violate policy.


Question 8

Which Microsoft Purview solution focuses primarily on preventing sensitive information from leaving the organization?

A. Communication Compliance

B. Insider Risk Management

C. Data Loss Prevention (DLP)

D. Compliance Manager

Correct Answer: C

Explanation: DLP is designed to detect and prevent unauthorized sharing of sensitive information, while Communication Compliance focuses on reviewing communications.


Question 9

What does a Communication Compliance alert indicate?

A. A confirmed policy violation requiring disciplinary action

B. A communication matched a configured policy and should be reviewed

C. The user’s account has been compromised

D. Microsoft 365 licensing has expired

Correct Answer: B

Explanation: Alerts indicate potential policy matches that require investigation; they are not proof of wrongdoing.


Question 10

Which statement best describes Microsoft Purview Communication Compliance?

A. It replaces antivirus software.

B. It automatically blocks every risky message.

C. It permanently archives all Microsoft 365 files.

D. It helps organizations identify, investigate, and respond to inappropriate communications.

Correct Answer: D

Explanation: Communication Compliance helps organizations manage communication-related compliance risks through monitoring, alerting, investigation, and response.


Go to the AB-900 Exam Prep Hub main page

Identify risks by using Microsoft Purview Insider Risk Management (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Identify risks by using Microsoft Purview Insider Risk Management


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft Purview Insider Risk Management (IRM) helps organizations detect, investigate, and respond to insider risks before they result in significant business damage. Unlike external cyberattacks, insider risks originate from individuals who already have authorized access to organizational resources. These individuals may intentionally misuse data or unintentionally expose sensitive information through careless actions.

For the AB-900 exam, you should understand:

  • What Insider Risk Management is
  • The types of risks it helps identify
  • The components used to detect insider risks
  • How risk indicators and policies work
  • How investigations are performed
  • How Insider Risk Management integrates with other Microsoft 365 security solutions
  • Common use cases

What Is Microsoft Purview Insider Risk Management?

Microsoft Purview Insider Risk Management is a Microsoft Purview solution that uses machine learning, analytics, user activity signals, and built-in privacy protections to identify potentially risky user behavior.

Its purpose is not to assume users are malicious. Instead, it identifies behaviors that could indicate:

  • Data theft
  • Intellectual property loss
  • Security violations
  • Compliance violations
  • Accidental data exposure
  • Policy violations

The solution helps security, compliance, HR, and legal teams investigate suspicious activities while respecting employee privacy.


What Is an Insider Risk?

An insider risk is any situation where someone with legitimate access to organizational systems creates risk for the organization.

Examples include:

  • An employee downloading thousands of confidential files before resigning
  • A contractor copying customer information to a USB drive
  • A user emailing sensitive documents to a personal email account
  • An employee sharing confidential information through unauthorized cloud storage
  • A user repeatedly accessing data unrelated to their job responsibilities

Not every insider risk is malicious.

Many incidents are accidental.

Examples include:

  • Sending confidential files to the wrong recipient
  • Uploading sensitive documents to public cloud storage
  • Accidentally sharing confidential Teams files

Types of Insider Risks

Microsoft categorizes insider risks into several common scenarios.

Data Theft

Occurs when users attempt to remove valuable organizational information.

Examples include:

  • Downloading confidential files
  • Copying files to USB devices
  • Printing sensitive documents
  • Emailing proprietary information externally

Data Leakage

Sensitive information leaves the organization unintentionally.

Examples include:

  • Uploading files to personal cloud storage
  • Sending confidential documents externally
  • Sharing protected files publicly

Security Policy Violations

Users violate established organizational security rules.

Examples include:

  • Disabling security controls
  • Using unauthorized applications
  • Circumventing compliance policies

Compliance Violations

Employees violate legal or regulatory requirements.

Examples include:

  • Sharing regulated financial records
  • Mishandling healthcare information
  • Improperly accessing customer records

Departing Employee Risks

A common scenario involves employees preparing to leave the organization.

Potential indicators include:

  • Large file downloads
  • Increased file copying
  • Unusual external sharing
  • Mass printing
  • Accessing previously unused repositories

How Insider Risk Management Works

Insider Risk Management follows a multi-stage process.

Step 1: Collect Activity Signals

Microsoft collects activity information from supported Microsoft 365 services.

Examples include:

  • SharePoint Online
  • OneDrive
  • Exchange Online
  • Microsoft Teams
  • Microsoft Defender
  • Microsoft Entra ID
  • Endpoint activity
  • Microsoft Defender for Endpoint

Step 2: Analyze User Activity

Machine learning compares current activity against:

  • Normal behavior
  • Organizational policies
  • Risk indicators
  • User context

This reduces false positives.


Step 3: Generate Risk Alerts

If suspicious behavior exceeds configured thresholds:

  • An alert is created.
  • The alert receives a severity level.
  • Investigators can review supporting evidence.

Step 4: Investigate

Compliance administrators review:

  • Timeline of events
  • User activities
  • File operations
  • Email actions
  • Device activities
  • Related alerts

Step 5: Respond

Possible actions include:

  • Escalating investigations
  • Assigning cases
  • Collecting evidence
  • Alerting management
  • Applying additional protections
  • Closing false positives

Risk Indicators

Risk indicators are behaviors that contribute to a user’s overall risk score.

Examples include:

File Activities

  • Downloading files
  • Deleting files
  • Printing documents
  • Copying files
  • Uploading files

Email Activities

  • Sending attachments externally
  • Forwarding confidential emails
  • Mass emailing sensitive information

Device Activities

  • USB device usage
  • File transfers
  • Printing
  • Local file copying

Collaboration Activities

  • Sharing Teams files externally
  • Creating anonymous sharing links
  • Public document sharing

User Behavior

Examples include:

  • Working unusual hours
  • Accessing unusual locations
  • Accessing excessive numbers of files
  • Sudden changes in behavior

Insider Risk Policies

Policies determine:

  • Which users are monitored
  • What behaviors are evaluated
  • Alert thresholds
  • Investigation rules

Policies are based on templates.

Common templates include:

  • Data leaks
  • Data theft
  • Security policy violations
  • Departing employees
  • Risky browser usage
  • Priority user monitoring

Policies allow organizations to customize detection based on their business needs.


Risk Scores

Each user activity contributes to a risk score.

Higher scores indicate more concerning activity.

Factors influencing scores include:

  • Number of risky actions
  • Severity of activities
  • Frequency
  • Historical behavior
  • Machine learning analysis

Risk scores help investigators prioritize the most serious incidents.


Alerts

When policy thresholds are exceeded, alerts are created.

Alerts typically include:

  • User involved
  • Policy triggered
  • Activity timeline
  • Risk level
  • Supporting evidence
  • Recommended investigation steps

Alert severity may include:

  • Low
  • Medium
  • High

Cases

Investigators can promote alerts into investigation cases.

Cases centralize:

  • Evidence
  • User activity
  • Timeline
  • Notes
  • Investigation status
  • Assigned investigators

This allows multiple reviewers to collaborate.


Privacy by Design

Microsoft designed Insider Risk Management with employee privacy in mind.

Privacy protections include:

  • Role-based access control
  • User pseudonymization (where supported)
  • Audit logging
  • Configurable privacy settings
  • Limited investigator access

Organizations control who can view personally identifiable information.


Integration with Microsoft 365 Services

Insider Risk Management integrates with many Microsoft security solutions.

Microsoft Purview Data Loss Prevention (DLP)

Provides sensitivity information about protected files.

Example:

A user emailing a document containing credit card numbers may trigger both DLP and Insider Risk Management.


Microsoft Purview Information Protection

Sensitivity labels provide additional context.

Example:

Downloading dozens of “Highly Confidential” documents creates greater risk than downloading public documents.


Microsoft Defender

Endpoint signals include:

  • USB usage
  • File copying
  • Application activity
  • Device events

These signals improve risk detection.


Microsoft Entra ID

Identity information provides context, including:

  • User identity
  • Sign-in behavior
  • Account changes
  • Risk signals

Microsoft 365 Audit Logs

User activities across Microsoft 365 workloads provide evidence for investigations.


AI and Machine Learning

Machine learning helps reduce false positives by:

  • Understanding normal behavior
  • Detecting unusual activity
  • Correlating multiple signals
  • Prioritizing serious incidents

This allows investigators to focus on the highest-risk alerts.


Common Use Cases

Protecting Intellectual Property

Identify employees copying engineering documents before leaving the company.


Detecting Insider Data Theft

Identify users downloading large numbers of confidential files.


Monitoring High-Risk Users

Monitor executives or privileged administrators who have access to sensitive information.


Investigating Data Leaks

Determine how confidential information left the organization.


Supporting HR Investigations

Provide evidence when investigating employee misconduct.


Benefits of Insider Risk Management

Organizations benefit by:

  • Detecting insider threats early
  • Protecting confidential information
  • Reducing compliance violations
  • Improving investigations
  • Prioritizing high-risk incidents
  • Using AI to reduce false positives
  • Integrating with Microsoft Purview and Microsoft Defender
  • Supporting regulatory compliance
  • Protecting intellectual property
  • Providing centralized case management

Exam Tips

For the AB-900 exam, remember these key points:

  • Insider Risk Management focuses on user behavior, not external attackers.
  • It detects both malicious and accidental risky activities.
  • Policies determine what activities are monitored.
  • Machine learning helps reduce false positives.
  • Alerts can be promoted into investigation cases.
  • Insider Risk Management integrates with DLP, Information Protection, Microsoft Defender, Microsoft Entra ID, and Microsoft 365 audit logs.
  • Risk scores help prioritize investigations.
  • Privacy protections are built into the solution.

10 Practice Exam Questions

Question 1

An employee uploads several confidential engineering documents to a personal cloud storage account shortly before resigning.

Which Microsoft Purview solution is specifically designed to investigate this type of behavior?

A. Microsoft Purview eDiscovery

B. Microsoft Purview Insider Risk Management

C. Microsoft Defender for Cloud Apps

D. Microsoft Intune

Correct Answer: B

Explanation: Insider Risk Management is specifically designed to identify potentially risky insider behavior such as data theft, data leakage, and activities performed by departing employees.


Question 2

Which activity is most likely to increase a user’s insider risk score?

A. Viewing the company homepage

B. Logging into Microsoft Teams during normal working hours

C. Downloading hundreds of confidential files before leaving the company

D. Changing a desktop wallpaper

Correct Answer: C

Explanation: Large-scale downloads of sensitive information—especially by departing employees—are common indicators of insider risk.


Question 3

What is the primary purpose of Insider Risk Management policies?

A. Encrypt all Microsoft 365 data

B. Replace antivirus software

C. Control Microsoft licensing

D. Define which users, activities, and risk indicators should be monitored

Correct Answer: D

Explanation: Policies specify monitored users, monitored activities, thresholds, and investigation settings.


Question 4

Which Microsoft technology helps Insider Risk Management reduce false positives?

A. Static firewall rules

B. Manual investigations only

C. Machine learning and behavioral analytics

D. Network packet inspection

Correct Answer: C

Explanation: Machine learning evaluates user behavior patterns and distinguishes normal activity from potentially risky behavior.


Question 5

What happens after Insider Risk Management determines that user activity exceeds a configured policy threshold?

A. The user account is automatically deleted.

B. The organization’s Microsoft 365 subscription is suspended.

C. All user devices are immediately wiped.

D. An insider risk alert is generated for investigation.

Correct Answer: D

Explanation: Alerts are created when monitored activities exceed policy thresholds and can later be investigated or promoted into cases.


Question 6

Which Microsoft solution provides endpoint signals such as USB usage and local file copying to Insider Risk Management?

A. Microsoft Defender for Endpoint

B. Microsoft Outlook

C. Microsoft Planner

D. Microsoft Bookings

Correct Answer: A

Explanation: Microsoft Defender for Endpoint supplies valuable endpoint telemetry that strengthens insider risk detection.


Question 7

Which statement best describes Microsoft’s approach to employee privacy within Insider Risk Management?

A. Every administrator automatically sees all employee information.

B. Employee privacy protections such as role-based access and pseudonymization are built into the solution.

C. All investigations are anonymous and cannot identify users.

D. Privacy settings cannot be customized.

Correct Answer: B

Explanation: Insider Risk Management incorporates privacy-by-design principles, including role-based access, pseudonymization where supported, and configurable privacy controls.


Question 8

Which scenario is an example of an accidental insider risk?

A. A hacker exploits an internet-facing server.

B. An attacker launches a ransomware attack.

C. An employee mistakenly emails confidential information to the wrong external recipient.

D. A distributed denial-of-service (DDoS) attack targets a website.

Correct Answer: C

Explanation: Insider risks include accidental actions, such as unintentionally sharing sensitive information with unauthorized recipients.


Question 9

What information helps investigators prioritize which alerts should be reviewed first?

A. The user’s mailbox size

B. Microsoft licensing level

C. The user’s department name

D. The insider risk score and alert severity

Correct Answer: D

Explanation: Risk scores and alert severity help investigators focus on the most significant potential threats first.


Question 10

Which Microsoft Purview capability most directly complements Insider Risk Management by identifying and protecting sensitive content through labeling?

A. Microsoft Purview Information Protection

B. Microsoft Exchange Online Protection

C. Microsoft Intune

D. Windows Firewall

Correct Answer: A

Explanation: Microsoft Purview Information Protection classifies and labels sensitive information. Those labels provide valuable context that Insider Risk Management can use when assessing the risk associated with user activities.


Go to the AB-900 Exam Prep Hub main page

Identify sensitive information by using Microsoft Purview Data Explorer (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Identify sensitive information by using Microsoft Purview Data Explorer


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

As organizations increasingly rely on Microsoft 365 and Microsoft 365 Copilot, understanding where sensitive information resides has become a critical governance and security requirement. Sensitive data such as credit card numbers, Social Security numbers, health records, financial information, intellectual property, and confidential business documents can create significant compliance and security risks if not properly managed.

Microsoft Purview Data Explorer helps organizations discover, analyze, and understand sensitive information stored across Microsoft 365 services. It provides visibility into the location, volume, and classification of sensitive data, enabling administrators to make informed decisions about data protection, governance, compliance, and Copilot readiness.

For the AB-900 exam, you should understand the purpose of Data Explorer, how it identifies sensitive information, the types of information it can discover, and how organizations use its insights to reduce compliance and governance risks.


What Is Microsoft Purview Data Explorer?

Microsoft Purview Data Explorer is a reporting and investigation tool within Microsoft Purview that helps administrators visualize and analyze sensitive data across Microsoft 365 environments.

Data Explorer enables organizations to:

  • Discover sensitive information
  • Understand where sensitive data is stored
  • Analyze data classification results
  • Identify compliance risks
  • Support data governance initiatives
  • Validate Microsoft Purview policy effectiveness
  • Improve Microsoft 365 Copilot readiness

Rather than protecting data directly, Data Explorer provides visibility into an organization’s data landscape so administrators can take appropriate actions.


Why Data Discovery Is Important

Organizations often accumulate large amounts of data over time. Without visibility into that data, administrators may not know:

  • What sensitive information exists
  • Where the information is stored
  • Who has access to it
  • Whether it is properly protected
  • Whether regulatory requirements are being met

For example:

  • Customer records may contain personally identifiable information (PII).
  • Financial documents may contain account numbers.
  • Healthcare records may contain protected health information (PHI).
  • Contracts may contain confidential business information.

Data Explorer helps identify these risks before they become security or compliance issues.


How Data Explorer Works

Data Explorer analyzes Microsoft 365 content using classification technologies available in Microsoft Purview.

The system scans content stored in supported locations and identifies:

  • Sensitive information types
  • Sensitivity labels
  • Trainable classifiers
  • Retention labels
  • Data classifications

The results are then presented through visual dashboards and detailed reports.

Administrators can use these reports to understand the organization’s sensitive data footprint.


Data Sources Analyzed by Data Explorer

Data Explorer can analyze content across Microsoft 365 services, including:

SharePoint Online

Examples:

  • Documents
  • Team sites
  • Department sites
  • Project repositories

OneDrive for Business

Examples:

  • Personal work files
  • Shared documents
  • Business records

Exchange Online

Examples:

  • Email messages
  • Attachments
  • Mailbox content

Microsoft Teams

Examples:

  • Shared files
  • Team documents
  • Collaboration content

These locations often contain the information that Microsoft 365 Copilot accesses when generating responses.


Sensitive Information Types (SITs)

One of the primary ways Data Explorer identifies sensitive information is through Sensitive Information Types (SITs).

Sensitive Information Types are predefined patterns that identify specific categories of sensitive data.

Examples include:

  • Social Security Numbers
  • Credit Card Numbers
  • Driver’s License Numbers
  • Passport Numbers
  • Tax Identification Numbers
  • Bank Account Numbers
  • Healthcare Information

Microsoft provides hundreds of built-in sensitive information types.

Organizations can also create custom sensitive information types.


Trainable Classifiers

Data Explorer can also identify information using trainable classifiers.

Unlike pattern matching, trainable classifiers use machine learning to recognize content based on context.

Examples include:

  • Resumes
  • Contracts
  • Invoices
  • Financial documents
  • Source code
  • Intellectual property

This helps organizations classify content that may not contain obvious patterns such as account numbers or IDs.


Sensitivity Labels and Data Explorer

Organizations often use sensitivity labels to classify and protect information.

Examples of labels include:

  • Public
  • General
  • Confidential
  • Highly Confidential

Data Explorer can show:

  • Which files have sensitivity labels
  • Label distribution across the organization
  • Unlabeled sensitive content
  • Areas where additional labeling may be needed

This visibility helps improve data governance and security.


Retention Labels and Data Explorer

Retention labels determine how long content should be retained and when it should be deleted.

Data Explorer can help organizations understand:

  • Which files have retention labels
  • Which files lack retention labels
  • Data that may require retention controls
  • Potential records management gaps

Data Classification Overview

Data classification is the process of identifying and categorizing information according to its sensitivity and business value.

Data Explorer supports classification efforts by helping organizations:

  • Locate sensitive data
  • Understand risk exposure
  • Apply appropriate protections
  • Improve compliance programs

The classification process typically includes:

  1. Discover data
  2. Classify data
  3. Protect data
  4. Monitor data
  5. Govern data

Data Explorer primarily supports the discovery and analysis phases.


Visualizations and Reporting

Data Explorer provides dashboards and reports that help administrators quickly understand sensitive data trends.

Reports can show:

  • Number of sensitive items
  • Sensitive information types detected
  • Label usage
  • Data locations
  • Content trends
  • Classification coverage

These visualizations help administrators identify areas requiring additional protection.


Data Explorer and Microsoft 365 Copilot

Data Explorer plays an important role in Copilot readiness assessments.

Because Microsoft 365 Copilot uses existing permissions and accesses organizational data through Microsoft Graph, organizations should understand what data exists before deploying Copilot broadly.

Data Explorer helps identify:

  • Overexposed sensitive data
  • Unclassified content
  • Excessively shared files
  • Confidential documents lacking protection
  • Data governance gaps

Administrators can use these insights to improve security before expanding Copilot adoption.


Common Governance Risks Identified by Data Explorer

Unlabeled Sensitive Data

Sensitive documents may exist without sensitivity labels.

Risk:

  • Users may accidentally share confidential information.

Recommended Action:

  • Apply sensitivity labels.

Excessive Data Exposure

Sensitive files may be accessible to too many users.

Risk:

  • Unauthorized access.

Recommended Action:

  • Review permissions and sharing settings.

Missing Retention Controls

Important records may lack retention policies.

Risk:

  • Regulatory violations.

Recommended Action:

  • Implement retention labels and policies.

Sensitive Data in Unexpected Locations

Data may be stored outside approved repositories.

Risk:

  • Governance challenges.

Recommended Action:

  • Review storage practices and apply controls.

Relationship with Other Microsoft Purview Solutions

Data Explorer works alongside other Microsoft Purview solutions.

Information Protection

Provides:

  • Sensitivity labels
  • Encryption
  • Classification

Data Explorer shows where protected and unprotected content exists.


Data Loss Prevention (DLP)

Provides:

  • Policy enforcement
  • Data movement restrictions

Data Explorer helps identify data that may require DLP protection.


Insider Risk Management

Provides:

  • Risk detection
  • Insider threat analysis

Data Explorer helps identify sensitive data that could be targeted.


Compliance Manager

Provides:

  • Compliance assessments
  • Risk reduction recommendations

Data Explorer provides visibility into the data that compliance programs are designed to protect.


Benefits of Using Data Explorer

Organizations use Data Explorer to:

  • Discover sensitive information
  • Improve data governance
  • Support regulatory compliance
  • Prepare for Copilot deployment
  • Validate classification strategies
  • Identify protection gaps
  • Reduce organizational risk
  • Improve visibility into data assets

Key Exam Tips

For the AB-900 exam, remember the following:

  • Data Explorer helps organizations discover and analyze sensitive information.
  • It provides visibility into sensitive data locations across Microsoft 365.
  • Sensitive Information Types identify structured sensitive data such as Social Security numbers and credit card numbers.
  • Trainable classifiers identify content based on context and machine learning.
  • Data Explorer supports governance, compliance, and Copilot readiness initiatives.
  • It helps identify unlabeled, unprotected, or overexposed sensitive information.
  • Data Explorer is primarily a discovery and analysis tool, not a protection or enforcement tool.
  • Data Explorer works with sensitivity labels, retention labels, DLP, and other Microsoft Purview solutions.

Practice Exam Questions

Question 1

What is the primary purpose of Microsoft Purview Data Explorer?

A. Generate AI responses for users

B. Discover and analyze sensitive information across Microsoft 365

C. Encrypt all organizational files

D. Replace Microsoft Defender

Answer: B

Explanation: Data Explorer is designed to help organizations discover, analyze, and understand sensitive information stored across Microsoft 365 services.


Question 2

Which Microsoft 365 service can be analyzed by Data Explorer?

A. SharePoint Online

B. Windows Server

C. Hyper-V

D. Microsoft Intune only

Answer: A

Explanation: Data Explorer can analyze content stored in SharePoint Online, OneDrive, Exchange Online, Teams, and other supported Microsoft 365 locations.


Question 3

What is a Sensitive Information Type (SIT)?

A. A method for creating Teams meetings

B. A licensing model for Microsoft Purview

C. A predefined pattern used to identify sensitive information

D. A backup technology

Answer: C

Explanation: Sensitive Information Types are predefined detectors that identify sensitive data such as Social Security numbers and credit card numbers.


Question 4

Which technology helps identify content such as contracts and resumes using context rather than pattern matching?

A. DLP policies

B. Retention labels

C. Sensitivity labels

D. Trainable classifiers

Answer: D

Explanation: Trainable classifiers use machine learning and contextual analysis to identify document types such as contracts, resumes, and invoices.


Question 5

An administrator wants to determine whether confidential files lack sensitivity labels. Which tool should they use?

A. Microsoft Planner

B. Microsoft Lists

C. Microsoft Purview Data Explorer

D. Microsoft Whiteboard

Answer: C

Explanation: Data Explorer can identify sensitive content and show whether appropriate sensitivity labels have been applied.


Question 6

Which statement best describes Data Explorer?

A. It automatically blocks all file sharing.

B. It discovers and reports on sensitive information.

C. It replaces retention policies.

D. It automatically deletes noncompliant content.

Answer: B

Explanation: Data Explorer focuses on visibility and analysis rather than directly enforcing protection actions.


Question 7

Why is Data Explorer valuable before deploying Microsoft 365 Copilot broadly?

A. It upgrades Copilot licenses.

B. It improves Teams meeting quality.

C. It increases mailbox storage.

D. It helps identify sensitive or overexposed data that Copilot could potentially access.

Answer: D

Explanation: Understanding data exposure and classification gaps helps organizations prepare for secure Copilot adoption.


Question 8

Which item would most likely be identified through a built-in Sensitive Information Type?

A. A company strategy presentation

B. A software design diagram

C. A credit card number

D. A project timeline

Answer: C

Explanation: Sensitive Information Types are designed to detect structured data such as credit card numbers, passport numbers, and Social Security numbers.


Question 9

What governance risk might Data Explorer help identify?

A. Unlabeled sensitive documents

B. Printer driver issues

C. Network latency

D. Browser compatibility problems

Answer: A

Explanation: Data Explorer helps identify sensitive content that lacks classification or protection controls.


Question 10

How does Data Explorer support data governance?

A. By replacing all security controls

B. By automatically enforcing compliance regulations

C. By eliminating the need for sensitivity labels

D. By providing visibility into sensitive data and classification coverage

Answer: D

Explanation: Data Explorer supports governance efforts by helping organizations understand where sensitive information exists and whether appropriate classifications and protections are in place.


Exam Summary

Microsoft Purview Data Explorer is a discovery and analysis tool that helps organizations identify sensitive information across Microsoft 365. It uses Sensitive Information Types, trainable classifiers, sensitivity labels, and retention labels to provide visibility into data risks and governance gaps. Data Explorer is particularly important for compliance initiatives and Microsoft 365 Copilot readiness because it helps organizations understand what sensitive information exists, where it is stored, and whether it is properly protected. Understanding how Data Explorer identifies and reports sensitive information is an important objective for the AB-900 certification exam.


Go to the AB-900 Exam Prep Hub main page

Identify compliance risks and recommendations by using Microsoft Purview Compliance Manager (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Identify compliance risks and recommendations by using Microsoft Purview Compliance Manager


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Organizations today face increasing regulatory and compliance requirements related to data privacy, security, records management, and governance. Regulations such as GDPR, HIPAA, ISO 27001, NIST, PCI DSS, and many others require organizations to implement controls that protect sensitive information and demonstrate compliance.

Microsoft Purview Compliance Manager is a solution within Microsoft Purview that helps organizations assess, manage, and improve their compliance posture. It provides a risk-based approach to compliance by measuring how well an organization has implemented controls and by offering actionable recommendations to reduce compliance risks.

For the AB-900 exam, you should understand the purpose of Compliance Manager, how it identifies compliance risks, how compliance scores are calculated, and how organizations can use recommendations to improve their compliance posture.


What Is Microsoft Purview Compliance Manager?

Microsoft Purview Compliance Manager is a compliance management solution that helps organizations:

  • Assess compliance risks
  • Monitor compliance status
  • Track implementation of compliance controls
  • Improve regulatory compliance
  • Generate evidence for audits
  • Prioritize remediation efforts

Compliance Manager translates complex regulatory requirements into manageable improvement actions that administrators can implement within Microsoft 365.

Rather than simply reporting compliance status, Compliance Manager helps organizations actively improve compliance through continuous assessment and risk reduction.


Why Compliance Manager Is Important

Organizations must comply with numerous regulations and standards. Managing compliance manually can be difficult because:

  • Regulations frequently change
  • Multiple frameworks may apply simultaneously
  • Compliance controls span many systems
  • Evidence collection can be time-consuming
  • Auditors require documentation

Compliance Manager helps centralize compliance activities and provides visibility into compliance readiness.

Benefits include:

  • Reduced compliance risk
  • Improved governance
  • Simplified audit preparation
  • Better visibility into regulatory requirements
  • Continuous compliance monitoring
  • Prioritized remediation efforts

Understanding Compliance Risk

Compliance risk refers to the possibility that an organization fails to meet legal, regulatory, or internal policy requirements.

Examples include:

  • Improper handling of personal data
  • Missing security controls
  • Lack of retention policies
  • Inadequate access controls
  • Failure to encrypt sensitive information
  • Insufficient auditing and monitoring

Compliance Manager helps identify these risks by comparing organizational practices against compliance requirements.


Compliance Score

One of the most important concepts in Compliance Manager is the Compliance Score.

The Compliance Score is a measurement that reflects the organization’s progress toward meeting selected compliance requirements.

The score:

  • Is risk-based
  • Measures completed controls
  • Helps prioritize work
  • Changes as actions are completed

A higher score generally indicates that more compliance controls have been implemented.

However, the score does not guarantee compliance with a regulation. It serves as a management tool for tracking progress and reducing risk.


How Compliance Score Is Calculated

Compliance Manager assigns points to improvement actions.

Points are awarded when actions are completed.

Examples of actions include:

  • Enabling multifactor authentication
  • Configuring retention policies
  • Applying sensitivity labels
  • Enabling audit logging
  • Implementing access controls

Higher-risk controls typically receive more points because they contribute more significantly to risk reduction.


Assessments in Compliance Manager

An assessment measures compliance against a specific regulation, standard, or framework.

Examples include:

  • GDPR
  • ISO 27001
  • NIST
  • HIPAA
  • PCI DSS
  • Microsoft Data Protection Baseline

Each assessment contains:

  • Control objectives
  • Improvement actions
  • Testing guidance
  • Documentation requirements
  • Compliance status tracking

Organizations can use multiple assessments simultaneously.


Types of Controls

Compliance Manager evaluates different types of controls.

Microsoft-Managed Controls

These controls are implemented and managed by Microsoft.

Examples include:

  • Physical datacenter security
  • Infrastructure protections
  • Platform-level safeguards

Microsoft provides evidence showing how these controls are implemented.


Customer-Managed Controls

These controls are the responsibility of the organization.

Examples include:

  • MFA configuration
  • Retention policies
  • Access management
  • User training
  • Data classification

Administrators must implement and document these controls.


Shared Controls

Shared controls involve responsibilities divided between Microsoft and the customer.

Examples include:

  • Identity management
  • Security monitoring
  • Data protection configurations

Both parties contribute to compliance.


Improvement Actions

Improvement actions are recommendations that help organizations reduce compliance risk.

An improvement action typically includes:

  • Description of the requirement
  • Implementation guidance
  • Testing procedures
  • Documentation requirements
  • Risk impact

Examples include:

  • Enable multifactor authentication
  • Configure audit logging
  • Apply sensitivity labels
  • Restrict external sharing
  • Implement retention policies
  • Enable Data Loss Prevention policies

Completing improvement actions increases the compliance score.


Recommendations in Compliance Manager

Compliance Manager provides actionable recommendations that help organizations improve compliance.

Recommendations may involve:

Identity Security

Examples:

  • Enable MFA
  • Implement Conditional Access
  • Review privileged accounts
  • Use least-privilege access

Data Protection

Examples:

  • Configure sensitivity labels
  • Encrypt sensitive content
  • Implement DLP policies
  • Protect confidential information

Monitoring and Auditing

Examples:

  • Enable auditing
  • Review activity logs
  • Investigate suspicious behavior
  • Maintain audit records

Information Governance

Examples:

  • Create retention policies
  • Define retention labels
  • Manage records
  • Implement deletion schedules

Testing and Evidence Collection

Compliance Manager supports audit preparation through evidence collection.

Organizations can:

  • Upload documentation
  • Store screenshots
  • Attach policy documents
  • Record test results
  • Maintain audit evidence

This makes audits easier because evidence is stored alongside compliance controls.


Regulatory Templates

Compliance Manager includes built-in templates for many regulations and standards.

Examples include:

  • GDPR
  • HIPAA
  • ISO 27001
  • NIST CSF
  • SOC 2
  • PCI DSS

Templates reduce the effort required to build compliance programs from scratch.


Monitoring Compliance Over Time

Compliance is not a one-time activity.

Compliance Manager supports continuous monitoring by:

  • Tracking score changes
  • Updating assessment status
  • Identifying new risks
  • Monitoring action completion
  • Highlighting outstanding requirements

Organizations can regularly review their compliance posture and address gaps.


Compliance Manager and Microsoft 365 Copilot

As organizations adopt Microsoft 365 Copilot, governance and compliance become increasingly important.

Compliance Manager can help organizations:

  • Evaluate data protection readiness
  • Review access controls
  • Verify sensitivity label deployment
  • Assess retention policies
  • Confirm audit logging is enabled
  • Measure compliance maturity

These controls help ensure Copilot operates within established governance and compliance frameworks.


Key Exam Tips

For the AB-900 exam, remember:

  • Compliance Manager helps assess and improve compliance posture.
  • Compliance Score measures progress toward implementing controls.
  • Improvement actions provide recommendations for reducing risk.
  • Assessments measure compliance against regulations and standards.
  • Controls may be Microsoft-managed, customer-managed, or shared.
  • Compliance Manager supports evidence collection and audit readiness.
  • A higher Compliance Score indicates improved compliance posture but does not guarantee regulatory compliance.
  • Compliance Manager helps organizations identify and prioritize compliance risks.

Practice Exam Questions

Question 1

What is the primary purpose of Microsoft Purview Compliance Manager?

A. Create SharePoint sites automatically

B. Assess and improve an organization’s compliance posture

C. Replace Microsoft Defender

D. Manage Windows updates

Answer: B

Explanation: Compliance Manager helps organizations assess compliance risks, track controls, and improve compliance posture through assessments and recommendations.


Question 2

What does the Compliance Score primarily represent?

A. The number of licensed users

B. The percentage of completed support tickets

C. Progress toward implementing compliance controls

D. The amount of storage consumed

Answer: C

Explanation: Compliance Score measures the organization’s progress in implementing controls that reduce compliance risk.


Question 3

Which type of control is managed entirely by Microsoft?

A. Customer-managed control

B. Shared control

C. Administrative control

D. Microsoft-managed control

Answer: D

Explanation: Microsoft-managed controls are implemented and maintained by Microsoft, such as datacenter security and infrastructure protections.


Question 4

An administrator wants to increase the organization’s Compliance Score. What should they do?

A. Purchase more Microsoft licenses

B. Increase mailbox storage limits

C. Complete improvement actions

D. Delete old assessments

Answer: C

Explanation: Improvement actions contribute points to the Compliance Score and help reduce compliance risk.


Question 5

Which feature helps organizations prepare for audits?

A. Microsoft Forms

B. Evidence collection and documentation storage

C. Viva Engage

D. Power Automate approvals

Answer: B

Explanation: Compliance Manager allows organizations to upload documentation, screenshots, and evidence needed for audits.


Question 6

Which of the following is an example of a customer-managed control?

A. Physical datacenter security

B. Network backbone management

C. Global infrastructure redundancy

D. Configuring multifactor authentication

Answer: D

Explanation: Customers are responsible for implementing controls such as MFA, retention policies, and access controls.


Question 7

What is an assessment in Compliance Manager?

A. A financial audit report

B. A measurement of compliance against a regulation or standard

C. A SharePoint permission review

D. A Microsoft support case

Answer: B

Explanation: Assessments evaluate compliance requirements associated with regulations, standards, or frameworks.


Question 8

Which compliance framework could be evaluated using Compliance Manager?

A. HIPAA

B. DHCP

C. SMTP

D. DNS

Answer: A

Explanation: Compliance Manager includes templates and assessments for frameworks such as HIPAA, GDPR, ISO 27001, and NIST.


Question 9

What is the purpose of improvement actions?

A. To reduce compliance risk and guide remediation efforts

B. To create Teams channels automatically

C. To increase internet bandwidth

D. To manage printer deployments

Answer: A

Explanation: Improvement actions provide guidance for implementing controls that reduce compliance risk and improve compliance posture.


Question 10

Which statement about Compliance Score is correct?

A. A perfect score guarantees regulatory compliance.

B. The score measures storage utilization.

C. The score reflects progress toward implementing compliance controls but does not guarantee compliance.

D. The score only applies to Microsoft-managed controls.

Answer: C

Explanation: Compliance Score is a risk-based measurement of implemented controls and progress, but it does not guarantee compliance with any specific regulation.


Exam Summary

Microsoft Purview Compliance Manager is a risk-based compliance management solution that helps organizations assess regulatory requirements, identify compliance gaps, implement recommended controls, collect audit evidence, and continuously improve compliance posture. Understanding Compliance Score, assessments, improvement actions, and risk reduction recommendations is essential for success on the AB-900 exam and for administering Microsoft 365 and Copilot environments responsibly.


Go to the AB-900 Exam Prep Hub main page

Understand how Copilot uses permissions and other controls in Microsoft 365, Microsoft Purview, and Microsoft Defender to protect against risks (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Understand data security implications of Copilot
      --> Understand how Copilot uses permissions and other controls in Microsoft 365, Microsoft Purview, and Microsoft Defender to protect against risks


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

One of the most important security concepts for the AB-900 exam is understanding how Microsoft 365 Copilot protects organizational data. Because Copilot can access and summarize information from across Microsoft 365, organizations must ensure that sensitive information remains protected and that users only receive information they are authorized to access.

Microsoft 365 Copilot does not operate independently of an organization’s security framework. Instead, it inherits and respects the security, compliance, governance, and protection controls already configured in Microsoft 365. These controls come primarily from:

  • Microsoft 365 permissions
  • Microsoft Entra ID
  • Microsoft Purview
  • Microsoft Defender
  • SharePoint and OneDrive security
  • Teams security controls

Together, these technologies ensure that Copilot delivers useful responses while minimizing the risk of unauthorized access, data leakage, compliance violations, and insider threats.


The Security Foundation of Copilot

Microsoft 365 Copilot is built on three key principles:

  1. Access only authorized data
  2. Respect existing security controls
  3. Apply compliance and governance policies automatically

Copilot does not create new permissions.

Instead, it uses the permissions already assigned to users and resources throughout Microsoft 365.

This means that if a user cannot access a file directly, they also cannot access that file through Copilot.


Permission Trimming: The Core Security Mechanism

The most important security concept related to Copilot is permission trimming.

Permission trimming ensures that Copilot only retrieves information the user is authorized to access.

When a user submits a prompt:

  1. Microsoft Graph searches organizational data.
  2. Existing permissions are evaluated.
  3. Unauthorized content is excluded.
  4. Only authorized information is sent to the large language model.

For example:

  • HR files are accessible only to HR employees.
  • Finance reports are accessible only to finance personnel.
  • Confidential legal documents remain restricted to legal teams.

If another employee asks Copilot about those documents, the information is not included in the response.


How Microsoft 365 Permissions Protect Data

Microsoft 365 permissions form the first layer of Copilot security.

Permissions are inherited from services such as:

  • SharePoint Online
  • OneDrive for Business
  • Microsoft Teams
  • Exchange Online
  • Microsoft Loop

Examples include:

SharePoint Permissions

Users can only access sites, libraries, folders, and files for which they have permissions.

OneDrive Permissions

Users can access their own files and content explicitly shared with them.

Teams Permissions

Copilot respects team membership and channel access.

Exchange Permissions

Emails and calendar data are only available to authorized users.

Because Copilot uses Microsoft Graph, these permissions are automatically enforced.


Role of Microsoft Entra ID

Microsoft Entra ID provides identity and access management for Microsoft 365.

Copilot relies on Entra ID to verify:

  • User identity
  • Group membership
  • Role assignments
  • Conditional Access policies
  • Authentication status

Entra ID ensures that only authenticated and authorized users can access Microsoft 365 resources.

Examples

A Conditional Access policy may require:

  • Multifactor authentication (MFA)
  • Compliant devices
  • Approved locations

If requirements are not met, users may be blocked from accessing Microsoft 365 resources and Copilot.


How Microsoft Purview Protects Data Used by Copilot

Microsoft Purview provides compliance, governance, and data protection controls.

Because Copilot works with organizational content, Purview protections automatically apply to data used by Copilot.


Sensitivity Labels

Sensitivity labels classify and protect content.

Common labels include:

  • Public
  • General
  • Confidential
  • Highly Confidential

Labels can enforce:

  • Encryption
  • Access restrictions
  • Watermarking
  • Content markings

If a document is protected by a sensitivity label, Copilot respects those protections.


Data Loss Prevention (DLP)

DLP policies help prevent sensitive information from being exposed.

Examples include:

  • Credit card numbers
  • Social Security numbers
  • Healthcare records
  • Financial information

DLP policies can:

  • Detect sensitive data
  • Block sharing
  • Generate alerts
  • Notify administrators

Copilot interactions remain subject to DLP protections.


Data Classification

Microsoft Purview can automatically classify content based on:

  • Sensitive information types
  • Trainable classifiers
  • Custom classifications

This classification helps organizations understand what information exists and where risks may be present.


Retention Policies

Retention policies ensure information is retained or deleted according to organizational requirements.

Copilot only works with content that remains available within Microsoft 365 according to retention settings.


Data Security Posture Management (DSPM) for AI

DSPM for AI helps organizations identify and reduce AI-related risks.

DSPM can:

  • Discover overshared content
  • Identify risky permissions
  • Detect exposure of sensitive data
  • Recommend remediation actions

This is especially important because Copilot may reveal risks that already exist due to improper permissions.


How Microsoft Defender Protects Copilot Environments

Microsoft Defender provides threat detection, prevention, and response capabilities.

Defender helps protect both the data Copilot accesses and the users interacting with Copilot.


Microsoft Defender XDR

Microsoft Defender XDR provides:

  • Cross-domain threat detection
  • Incident correlation
  • Security investigation
  • Automated response

It helps security teams identify attacks that may affect Copilot-accessible data.


Identity Protection

Microsoft Defender and Entra ID can detect:

  • Risky sign-ins
  • Credential theft
  • Impossible travel events
  • Suspicious account activity

Compromised identities can be blocked before attackers access Copilot.


Endpoint Protection

Microsoft Defender for Endpoint protects devices used to access Copilot.

It helps detect:

  • Malware
  • Ransomware
  • Unauthorized access attempts
  • Device compromise

Threat Intelligence

Microsoft Defender uses global threat intelligence to identify:

  • Known malicious actors
  • Emerging threats
  • Attack techniques

This helps reduce the likelihood that attackers gain access to sensitive organizational information.


Oversharing Risks and Copilot

Copilot does not create oversharing problems.

However, it can expose existing oversharing issues more efficiently.

For example:

If a confidential SharePoint folder has accidentally been shared with all employees:

  • Employees may not discover the folder manually.
  • Copilot may locate relevant content and summarize it.

Because of this, organizations should regularly review:

  • File permissions
  • Site permissions
  • Group memberships
  • Sharing settings

DSPM for AI helps identify these risks.


Security Controls Working Together

The protection of Copilot data relies on multiple layers:

Security LayerPurpose
Microsoft Entra IDIdentity verification and access control
Conditional AccessRestrict access based on risk and conditions
Microsoft 365 PermissionsControl resource access
Microsoft GraphApplies permission trimming
Microsoft PurviewGovernance, compliance, and data protection
Microsoft DefenderThreat detection and response
DSPM for AIAI-specific risk identification

These controls work together to create a secure AI environment.


Key Exam Tips

For the AB-900 exam, remember the following:

  • Copilot does not bypass existing permissions.
  • Permission trimming ensures users only see authorized content.
  • Microsoft Graph enforces access controls during data retrieval.
  • Microsoft Entra ID provides identity and access management.
  • Conditional Access can restrict Copilot access based on organizational policies.
  • Microsoft Purview protects data through sensitivity labels, DLP, classification, retention, and DSPM for AI.
  • Microsoft Defender protects identities, endpoints, and organizational resources from threats.
  • Copilot may reveal existing oversharing risks but does not create them.
  • DSPM for AI helps organizations identify and remediate AI-related data exposure risks.

Practice Exam Questions

Question 1

What security mechanism ensures that Copilot only retrieves information a user is authorized to access?

A. Endpoint isolation
B. Data retention
C. Data replication
D. Permission trimming

Answer: D

Explanation: Permission trimming evaluates a user’s permissions and excludes unauthorized content from Copilot responses.


Question 2

A user asks Copilot about a confidential HR document they do not have permission to view. What will happen?

A. Copilot summarizes the document anyway
B. Copilot requests administrator approval automatically
C. The document is excluded from the response due to permission trimming
D. The document is copied into the user’s OneDrive

Answer: C

Explanation: Copilot respects existing permissions and cannot retrieve content users are not authorized to access.


Question 3

Which Microsoft service provides the identity platform that Copilot relies on for authentication and authorization?

A. Microsoft Defender XDR
B. Microsoft Entra ID
C. Microsoft Purview Insider Risk Management
D. Microsoft Intune

Answer: B

Explanation: Microsoft Entra ID manages identities, authentication, authorization, and access controls for Microsoft 365 services.


Question 4

Which Microsoft Purview capability helps prevent sensitive information such as credit card numbers from being improperly shared?

A. Retention policies
B. Conditional Access
C. Privileged Identity Management
D. Data Loss Prevention (DLP)

Answer: D

Explanation: DLP policies detect and protect sensitive information by blocking or monitoring risky sharing activities.


Question 5

What is the primary purpose of sensitivity labels in Microsoft Purview?

A. Manage operating system updates
B. Monitor network performance
C. Classify and protect content based on sensitivity levels
D. Create backup copies of documents

Answer: C

Explanation: Sensitivity labels classify content and can apply protections such as encryption and access restrictions.


Question 6

Which Microsoft Purview solution helps organizations discover overshared content that may present AI-related risks?

A. Data Security Posture Management (DSPM) for AI
B. Microsoft Planner
C. Exchange Online Protection
D. Windows Defender Firewall

Answer: A

Explanation: DSPM for AI identifies sensitive data exposure risks and recommends remediation actions.


Question 7

How does Microsoft Defender help protect environments that use Copilot?

A. By creating user accounts automatically
B. By replacing Microsoft Entra ID permissions
C. By detecting threats, compromised identities, and suspicious activities
D. By bypassing DLP policies

Answer: C

Explanation: Microsoft Defender provides threat detection, investigation, and response capabilities that protect organizational resources.


Question 8

Which statement best describes the relationship between Copilot and oversharing?

A. Copilot automatically fixes overshared content
B. Copilot creates oversharing by default
C. Copilot ignores shared permissions entirely
D. Copilot may reveal existing oversharing issues because it can efficiently locate accessible content

Answer: D

Explanation: Copilot does not create oversharing problems but can make improperly shared content easier to discover.


Question 9

Which security control can require multifactor authentication before a user accesses Microsoft 365 resources and Copilot?

A. SharePoint version history
B. Conditional Access
C. Retention labels
D. Exchange journaling

Answer: B

Explanation: Conditional Access policies can require MFA, compliant devices, or other conditions before granting access.


Question 10

Which statement about Copilot security is correct?

A. Copilot has unrestricted access to all tenant data.
B. Copilot ignores Microsoft Purview protections.
C. Copilot only follows Microsoft Defender policies.
D. Copilot inherits existing Microsoft 365 permissions and compliance controls.

Answer: D

Explanation: Copilot respects permissions, security settings, compliance policies, and governance controls already configured within Microsoft 365.


Go to the AB-900 Exam Prep Hub main page

Understand how Microsoft Graph influences Copilot responses (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Understand data security implications of Copilot
      --> Understand how Microsoft Graph influences Copilot responses


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

One of the most important concepts for the AB-900 exam is understanding how Microsoft 365 Copilot generates responses. Many users assume that Copilot simply searches documents and emails. In reality, Microsoft 365 Copilot relies heavily on Microsoft Graph to provide personalized, context-aware, and permission-trimmed responses.

Understanding the relationship between Microsoft Graph and Copilot is essential because it explains why Copilot can provide relevant answers, summarize organizational information, and generate content based on a user’s work data while maintaining security boundaries.


What Is Microsoft Graph?

Microsoft Graph is Microsoft’s unified API and data layer that connects information across Microsoft 365 services.

It serves as a central gateway to organizational data stored in services such as:

  • Microsoft Outlook
  • Microsoft Teams
  • Microsoft SharePoint
  • Microsoft OneDrive
  • Microsoft Exchange Online
  • Microsoft Planner
  • Microsoft To Do
  • Microsoft Entra ID
  • Microsoft Loop
  • Microsoft Viva

Microsoft Graph not only stores references to data but also understands the relationships between people, files, meetings, emails, chats, and organizational activities.

Think of Microsoft Graph as the intelligence layer that helps Microsoft 365 understand:

  • Who users are
  • What content they can access
  • Which colleagues they work with
  • What meetings they attend
  • Which documents they frequently use
  • How information is connected across the organization

How Microsoft 365 Copilot Uses Microsoft Graph

Microsoft 365 Copilot combines:

  1. Large Language Models (LLMs)
  2. Microsoft Graph
  3. Microsoft 365 applications

When a user submits a prompt, Copilot does not rely solely on the LLM’s pre-trained knowledge.

Instead, Copilot uses Microsoft Graph to retrieve relevant organizational data and then grounds the LLM’s response using that data.

This process helps ensure responses are:

  • Relevant
  • Up-to-date
  • Personalized
  • Context-aware
  • Based on enterprise data

The Copilot Response Process

A simplified workflow looks like this:

Step 1: User Submits a Prompt

Example:

“Summarize the project status for the Contoso migration project.”


Step 2: Copilot Queries Microsoft Graph

Microsoft Graph searches organizational data that the user is permitted to access, including:

  • Project documents
  • Emails
  • Teams conversations
  • Meeting notes
  • SharePoint files

Step 3: Relevant Information Is Retrieved

Graph identifies content related to:

  • The project
  • Team members
  • Recent updates
  • Supporting documents

Step 4: Grounding Occurs

The retrieved business information is provided to the LLM.

This process is known as grounding.

Grounding helps ensure the response is based on actual organizational data rather than relying only on the model’s training data.


Step 5: Copilot Generates a Response

The LLM combines:

  • User prompt
  • Retrieved Graph data
  • Application context

to generate a final response.


What Is Grounding?

Grounding is one of the most important concepts for the AB-900 exam.

Grounding refers to supplying real organizational data from Microsoft Graph to the large language model before it generates a response.

Without grounding:

  • Responses could be generic
  • Information could be outdated
  • Answers would lack organizational context

With grounding:

  • Responses are more accurate
  • Responses are personalized
  • Responses reflect current business information

Why Microsoft Graph Improves Copilot Responses

Microsoft Graph helps Copilot provide responses that are:

Personalized

Different users receive different answers because they have access to different data.

Example:

A manager may receive a project summary containing budget information.

A team member may receive the same summary without budget details if they lack permission.


Context-Aware

Graph understands relationships between:

  • People
  • Teams
  • Projects
  • Meetings
  • Documents

Example:

When a user asks:

“What happened in yesterday’s meeting?”

Copilot can locate:

  • Meeting recordings
  • Meeting transcripts
  • Chat discussions
  • Shared files

and generate a summary.


Current

Unlike the LLM’s training data, Microsoft Graph accesses live Microsoft 365 information.

This allows Copilot to work with:

  • Today’s emails
  • Current documents
  • Recent chats
  • New meeting notes

Relevant

Graph helps prioritize information most closely related to the user’s work activities.

As a result, Copilot can identify content likely to be useful rather than searching randomly across the organization.


Microsoft Graph Connectors

Organizations often store information outside Microsoft 365.

Microsoft Graph Connectors allow external content to be indexed and accessed through Microsoft Graph.

Examples include:

  • ServiceNow
  • Salesforce
  • Confluence
  • Jira
  • File shares
  • Custom business systems

When properly configured, Copilot can use connected external data as part of its grounding process.

This expands the knowledge available to Copilot beyond Microsoft 365 content.


Security and Permission Trimming

A critical exam concept is that Microsoft Graph enforces existing permissions.

Copilot cannot bypass security controls.

This is called permission trimming.

When Graph retrieves data:

  • User permissions are evaluated.
  • Only accessible content is returned.
  • Unauthorized content is excluded.

As a result:

  • Copilot only sees what the user can see.
  • Users cannot retrieve restricted documents through Copilot.
  • Existing Microsoft 365 security controls remain in effect.

Examples of Microsoft Graph Influencing Copilot

Example 1: Meeting Summaries

Prompt:

“Summarize my meetings from this week.”

Graph provides:

  • Calendar events
  • Meeting transcripts
  • Chat messages
  • Shared files

Copilot generates a personalized summary.


Example 2: Document Creation

Prompt:

“Create a proposal using our latest marketing plan.”

Graph retrieves:

  • Marketing documents
  • Recent presentations
  • Strategy files

Copilot uses this information to draft the proposal.


Example 3: Team Updates

Prompt:

“What is the latest status of the migration project?”

Graph gathers:

  • Team conversations
  • Project files
  • Status reports
  • Meeting notes

Copilot generates an informed status summary.


Benefits of Microsoft Graph for Copilot

Microsoft Graph provides several advantages:

Better Accuracy

Responses are grounded in organizational data.

Personalization

Responses reflect the user’s work context.

Real-Time Information

Current business data can be used.

Security

Permission trimming protects sensitive information.

Cross-Application Insights

Information can be gathered from multiple Microsoft 365 services.


Key Exam Tips

For the AB-900 exam, remember:

  • Microsoft Graph is the data and relationship layer of Microsoft 365.
  • Copilot combines LLMs with Microsoft Graph data.
  • Grounding provides organizational data to improve response quality.
  • Microsoft Graph retrieves information from Microsoft 365 services.
  • Copilot respects existing permissions.
  • Permission trimming ensures users only receive data they are authorized to access.
  • Microsoft Graph Connectors can extend Copilot to external systems.
  • Microsoft Graph enables personalized and context-aware responses.

Practice Exam Questions

Question 1

What is the primary role of Microsoft Graph in Microsoft 365 Copilot?

A. Train large language models
B. Store Copilot prompts permanently
C. Provide organizational data and context for responses
D. Replace Microsoft Entra ID authentication

Answer: C

Explanation: Microsoft Graph provides organizational data and relationships that Copilot uses to generate personalized and grounded responses.


Question 2

What process occurs when Copilot uses organizational data to improve the accuracy of a response?

A. Classification
B. Grounding
C. Encryption
D. Federation

Answer: B

Explanation: Grounding is the process of supplying relevant organizational data from Microsoft Graph to the language model before generating a response.


Question 3

Which Microsoft 365 service helps Copilot understand relationships among people, files, meetings, and communications?

A. Microsoft Defender XDR
B. Microsoft Purview
C. Microsoft Intune
D. Microsoft Graph

Answer: D

Explanation: Microsoft Graph provides relationship intelligence across Microsoft 365 services and organizational data.


Question 4

A user asks Copilot to summarize a project. Which source is most likely retrieved through Microsoft Graph?

A. Public internet websites only
B. Operating system registry settings
C. Organizational emails, files, and chats the user can access
D. Device firmware information

Answer: C

Explanation: Microsoft Graph retrieves relevant Microsoft 365 content that the user is authorized to access.


Question 5

Why might two users receive different Copilot responses to the same prompt?

A. Microsoft Graph uses permission-trimmed access to data
B. Copilot randomly changes responses
C. Different users run different operating systems
D. Copilot ignores organizational security controls

Answer: A

Explanation: Responses depend on what data each user is authorized to access through Microsoft Graph.


Question 6

What is the benefit of grounding in Microsoft 365 Copilot?

A. Reduces storage requirements
B. Disables user permissions
C. Makes responses more relevant and based on current business data
D. Eliminates the need for Microsoft Graph

Answer: C

Explanation: Grounding helps ensure responses are accurate, contextual, and based on organizational information.


Question 7

Which statement best describes permission trimming?

A. Copilot grants temporary administrative access to users
B. Copilot can access all organizational content regardless of permissions
C. Permissions are evaluated only after a response is generated
D. Only content a user is authorized to access is available to Copilot

Answer: D

Explanation: Permission trimming ensures that Copilot only retrieves and uses data that the user already has permission to view.


Question 8

What can Microsoft Graph Connectors enable?

A. Replacement of Microsoft Entra ID
B. Access to external business data sources through Microsoft Graph
C. Automatic deletion of all external content
D. Disabling Microsoft 365 search

Answer: B

Explanation: Graph Connectors allow organizations to bring external content sources into Microsoft Graph for search and Copilot experiences.


Question 9

Which Microsoft Graph capability most directly helps Copilot create personalized responses?

A. Relationship awareness across users, documents, meetings, and activities
B. Operating system patch management
C. Network packet inspection
D. Hardware monitoring

Answer: A

Explanation: Microsoft Graph understands relationships among organizational resources and activities, enabling personalized responses.


Question 10

When a user submits a prompt to Microsoft 365 Copilot, what generally happens first?

A. Copilot immediately generates a response without retrieving data
B. The user’s device is scanned for malware
C. Microsoft Graph retrieves relevant authorized organizational information
D. All tenant data is copied into the language model

Answer: C

Explanation: Before generating a response, Copilot typically retrieves relevant data through Microsoft Graph to ground the response in current organizational context.


Go to the AB-900 Exam Prep Hub main page

Understand how Copilot accesses data (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Understand data security implications of Copilot
      --> Understand how Copilot accesses data


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

One of the most important concepts for the AB-900 exam is understanding how Microsoft 365 Copilot accesses and uses organizational data. Many organizations are excited about the productivity benefits of Copilot but also want assurance that sensitive information remains protected.

Microsoft 365 Copilot is designed to work within an organization’s existing Microsoft 365 security, compliance, identity, and permission boundaries. Rather than creating a separate copy of organizational data, Copilot accesses information that users already have permission to access.

Understanding how Copilot retrieves, processes, and presents data is critical for administrators responsible for security, governance, and compliance.


What Is Microsoft 365 Copilot?

Microsoft 365 Copilot is an AI-powered assistant that combines:

  • Large Language Models (LLMs)
  • Microsoft Graph
  • Microsoft 365 applications
  • Organizational data

Copilot helps users:

  • Draft documents
  • Summarize meetings
  • Analyze data
  • Generate presentations
  • Answer questions
  • Perform business tasks more efficiently

The intelligence of Copilot comes from combining AI reasoning with an organization’s business data.


The Three Main Components of Copilot Data Access

Microsoft 365 Copilot relies on three major components:

Large Language Models (LLMs)

LLMs provide:

  • Natural language understanding
  • Reasoning capabilities
  • Content generation
  • Summarization

The LLM interprets the user’s prompt and generates responses.


Microsoft Graph

Microsoft Graph serves as the bridge between Copilot and organizational data.

Microsoft Graph connects to resources such as:

  • Emails
  • Calendars
  • Teams chats
  • Teams meetings
  • SharePoint documents
  • OneDrive files
  • Contacts
  • Tasks

Graph provides context that allows Copilot to generate relevant and personalized responses.


Microsoft 365 Data

Copilot accesses information stored within Microsoft 365 services.

Examples include:

  • Exchange Online mailboxes
  • SharePoint sites
  • OneDrive content
  • Teams conversations
  • Meeting transcripts
  • Microsoft Loop content

This organizational content provides the business context used to answer user requests.


How Copilot Processes a User Request

When a user submits a prompt, several steps occur.

Step 1: User Enters a Prompt

Example:

“Summarize the latest project updates from my team.”


Step 2: Copilot Interprets the Request

The LLM analyzes:

  • User intent
  • Context
  • Required information

Step 3: Microsoft Graph Retrieves Relevant Data

Microsoft Graph searches content the user is authorized to access.

Potential sources include:

  • Emails
  • Documents
  • Teams messages
  • Meeting notes

Step 4: Security Permissions Are Checked

Before data is returned:

  • Existing permissions are evaluated
  • Access controls are enforced
  • Security boundaries remain intact

If a user cannot access content directly, Copilot cannot use it in a response.


Step 5: Response Generation

The LLM combines:

  • User prompt
  • Retrieved business data
  • Organizational context

A response is generated and returned to the user.


Copilot Respects Existing Permissions

One of the most important exam concepts is:

Copilot Does Not Grant Additional Access

Copilot only accesses information a user already has permission to access.

For example:

  • If User A can view a SharePoint document, Copilot may use that document.
  • If User B cannot view the document, Copilot cannot expose it.

Copilot does not bypass:

  • SharePoint permissions
  • OneDrive permissions
  • Teams permissions
  • Microsoft 365 security controls

A common Microsoft phrase is:

“Copilot honors existing permissions.”


Role of Microsoft Graph

Microsoft Graph is central to Copilot’s operation.

Microsoft Graph:

  • Connects Microsoft 365 services
  • Provides contextual information
  • Retrieves relevant content
  • Applies user permissions

Without Microsoft Graph, Copilot would not have access to organizational context.

Think of Microsoft Graph as the intelligence layer that helps Copilot locate relevant business information.


Grounding

A key Copilot concept is grounding.

Grounding means enriching AI responses with organizational data retrieved through Microsoft Graph.

Without grounding:

  • Responses are based primarily on general AI knowledge.

With grounding:

  • Responses include organization-specific information.

Example:

A user asks:

“What decisions were made during yesterday’s budget meeting?”

Copilot can retrieve:

  • Meeting transcripts
  • Notes
  • Shared documents

The response is grounded in actual organizational content.


Data Sources Used by Copilot

Common Microsoft 365 data sources include:

Exchange Online

Provides:

  • Emails
  • Calendars
  • Contacts

SharePoint Online

Provides:

  • Team documents
  • Knowledge repositories
  • Project files

OneDrive

Provides:

  • Personal work files
  • User-owned documents

Microsoft Teams

Provides:

  • Chat messages
  • Meeting transcripts
  • Channel conversations
  • Shared files

Microsoft Loop

Provides:

  • Collaborative workspaces
  • Shared project information

Security Boundaries and Data Access

Copilot operates within existing Microsoft 365 security boundaries.

These include:

  • User permissions
  • Group memberships
  • SharePoint access controls
  • Teams membership
  • Sensitivity labels
  • Conditional Access policies

Security controls continue to function exactly as they would without Copilot.


Copilot and Sensitivity Labels

Sensitivity labels remain effective when Copilot accesses content.

If a document is protected with a sensitivity label:

  • Existing protections remain in place.
  • Access restrictions continue to apply.
  • Users without permission cannot access protected information through Copilot.

This helps maintain compliance and data security.


Copilot and Data Loss Prevention (DLP)

Microsoft Purview DLP policies continue to protect data.

DLP can help:

  • Detect sensitive information
  • Restrict inappropriate sharing
  • Prevent data leakage

Copilot operates within these governance controls.


Copilot and Retention Policies

Retention settings remain active for Copilot-accessed content.

If content:

  • Is retained, Copilot may use it if the user has access.
  • Has been deleted according to retention policies, it generally becomes unavailable for Copilot use.

Organizations should understand that Copilot relies on content already stored in Microsoft 365.


Copilot and Identity Management

Microsoft Entra ID plays a critical role in determining what data Copilot can access.

Entra ID provides:

  • Authentication
  • Authorization
  • User identity verification
  • Access control enforcement

Every Copilot interaction is tied to an authenticated user identity.


Why Permission Management Matters

Because Copilot honors existing permissions, organizations should regularly review:

  • Excessive access rights
  • Oversharing
  • Legacy permissions
  • Inactive accounts
  • SharePoint permissions
  • Teams memberships

Poor permission management can expose information through both traditional access methods and Copilot.

Many organizations conduct permission reviews before deploying Microsoft 365 Copilot.


Data Privacy and Copilot

Microsoft states that organizational prompts, responses, and data used by Microsoft 365 Copilot:

  • Stay within the Microsoft 365 service boundary
  • Are protected by existing Microsoft 365 compliance controls
  • Are not used to train foundation models for other customers

This helps organizations maintain privacy and regulatory compliance.


Common Misconceptions

Misconception 1: Copilot Can See Everything

False.

Copilot only accesses data the current user is authorized to access.


Misconception 2: Copilot Creates New Security Risks by Itself

Not exactly.

Copilot exposes existing permission issues more visibly, but it does not bypass security controls.


Misconception 3: Copilot Stores Separate Copies of All Data

False.

Copilot primarily retrieves information from existing Microsoft 365 sources through Microsoft Graph.


Misconception 4: Copilot Ignores Compliance Controls

False.

Copilot respects:

  • Permissions
  • Sensitivity labels
  • DLP policies
  • Retention policies
  • Identity controls

Key Exam Takeaways

For the AB-900 exam, remember the following:

  • Microsoft 365 Copilot combines LLMs, Microsoft Graph, and Microsoft 365 data.
  • Microsoft Graph retrieves organizational information used to ground responses.
  • Copilot only accesses data a user is authorized to access.
  • Copilot honors existing permissions and access controls.
  • Authentication and authorization are enforced through Microsoft Entra ID.
  • SharePoint, OneDrive, Exchange, Teams, and other Microsoft 365 services provide Copilot’s data sources.
  • Sensitivity labels, DLP policies, and retention policies continue to apply.
  • Copilot does not bypass security boundaries.
  • Permission management is critical for successful Copilot deployments.
  • Grounding improves response quality by incorporating organizational data.

Practice Exam Questions

Question 1

What component connects Microsoft 365 Copilot to organizational data stored across Microsoft 365 services?

A. Microsoft Graph
B. Microsoft Defender XDR
C. Microsoft Intune
D. Azure Virtual Network

Answer: A

Explanation: Microsoft Graph retrieves organizational data and provides context that Copilot uses to generate responses.


Question 2

A user asks Copilot to summarize a document stored in SharePoint. What determines whether Copilot can access the document?

A. The user’s existing permissions to the document
B. Whether the document is larger than 100 MB
C. Whether Microsoft Defender is enabled
D. Whether the document was created in Word

Answer: A

Explanation: Copilot honors existing permissions and can only access content the user is already authorized to view.


Question 3

Which Microsoft 365 service is commonly used as a source of files that Copilot can reference?

A. Active Directory Domain Services
B. Hyper-V
C. SharePoint Online
D. DNS Manager

Answer: C

Explanation: SharePoint Online is a major repository for organizational documents and content accessed by Copilot.


Question 4

What is the purpose of grounding in Microsoft 365 Copilot?

A. Encrypting prompts before submission
B. Backing up user data automatically
C. Monitoring administrator activity
D. Enhancing AI responses with organizational data

Answer: D

Explanation: Grounding enriches AI-generated responses with relevant organizational information retrieved through Microsoft Graph.


Question 5

Which statement best describes how Copilot handles security permissions?

A. It grants temporary access to protected documents.
B. It bypasses SharePoint permissions when necessary.
C. It honors existing Microsoft 365 permissions.
D. It automatically makes all team content available.

Answer: C

Explanation: Copilot respects existing permissions and does not provide access to content users cannot already access.


Question 6

Which Microsoft service provides authentication and authorization for Copilot users?

A. Microsoft Entra ID
B. Microsoft Defender for Endpoint
C. Microsoft Purview Data Map
D. Microsoft Fabric

Answer: A

Explanation: Microsoft Entra ID authenticates users and enforces authorization decisions that determine accessible content.


Question 7

A company applies sensitivity labels to confidential documents. How does Copilot interact with those documents?

A. Copilot removes the labels before processing.
B. Copilot ignores label protections.
C. Copilot can share the documents with any employee.
D. Copilot continues to respect the protections enforced by the labels.

Answer: D

Explanation: Sensitivity labels remain effective and continue governing access to protected content.


Question 8

Which Microsoft 365 workload can provide meeting transcripts that Copilot may use when generating responses?

A. Microsoft Teams
B. Microsoft Project Server
C. Windows Server
D. Microsoft Endpoint Configuration Manager

Answer: A

Explanation: Teams meeting transcripts are one of the organizational data sources that Copilot can use when users have access.


Question 9

What happens when a user asks Copilot about information stored in a file they do not have permission to access?

A. Copilot grants temporary access.
B. Copilot can still summarize the file.
C. Copilot cannot access or expose the file’s contents.
D. Copilot sends an approval request automatically.

Answer: C

Explanation: Copilot enforces existing access controls and cannot retrieve information from content the user is not authorized to access.


Question 10

Why do organizations often review permissions before deploying Microsoft 365 Copilot?

A. Copilot requires every file to be reuploaded.
B. Overshared content may become more discoverable through AI-assisted interactions.
C. Copilot disables SharePoint security.
D. Microsoft Graph cannot function without permission reviews.

Answer: B

Explanation: Because Copilot honors existing permissions, organizations often review and reduce oversharing to ensure users only have access to appropriate information.


Go to the AB-900 Exam Prep Hub main page

Explore the organization configurations by using the Microsoft 365 Admin Center (domain names and organization settings) (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Identify the core features and objects of Microsoft 365 services (30–35%)
   --> Identify the core objects of Microsoft 365 services
      --> Explore the organization configurations by using the Microsoft 365 Admin Center (domain names and organization settings)


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

The Microsoft 365 admin center is the primary portal used by administrators to manage an organization’s Microsoft 365 environment. It provides centralized access to users, licenses, subscriptions, domains, security settings, billing information, and organizational preferences.

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, administrators should understand how organizational settings and domain names are configured because these settings affect user identities, collaboration, email addresses, branding, and overall tenant behavior.


What Is the Microsoft 365 Admin Center?

The Microsoft 365 admin center is a web-based portal that allows administrators to manage Microsoft 365 services from a single location.

Administrators can:

  • Manage users and groups.
  • Assign licenses.
  • Configure domains.
  • Modify organization settings.
  • View health and service status.
  • Manage billing and subscriptions.
  • Access specialized admin centers.

The admin center serves as the central management interface for a Microsoft 365 tenant.


Understanding the Microsoft 365 Organization (Tenant)

When an organization subscribes to Microsoft 365, Microsoft creates a unique cloud environment called a tenant.

A tenant contains:

  • Users
  • Groups
  • Licenses
  • Applications
  • Data
  • Organizational settings
  • Domain names

Example:

A company named Contoso might initially receive:

contoso.onmicrosoft.com

This default domain becomes part of the organization’s Microsoft 365 tenant.


Default Domain Names

Every Microsoft 365 tenant receives a default domain ending in:

.onmicrosoft.com

Examples:

  • contoso.onmicrosoft.com
  • fabrikam.onmicrosoft.com

Characteristics of the default domain:

  • Automatically created during tenant creation.
  • Cannot be removed.
  • Used internally by Microsoft 365.
  • Can be used for user sign-in.
  • Serves as a fallback domain.

Although organizations can continue using the default domain, most add their own custom domains.


Custom Domains

Organizations commonly add their own internet domains to Microsoft 365.

Examples:

  • contoso.com
  • fabrikam.org
  • wingtiptoys.com

Benefits of custom domains include:

  • Professional email addresses.
  • Consistent branding.
  • Simplified user sign-in.
  • Improved user experience.

Example:

Instead of:

john@contoso.onmicrosoft.com

Users can sign in with:

john@contoso.com

Adding a Domain

Administrators can add domains from:

Settings → Domains

The general process includes:

Step 1: Add the Domain Name

Example:

contoso.com

Step 2: Verify Ownership

Microsoft requires proof that the organization owns the domain.

Verification usually involves adding a DNS TXT record through the domain registrar.

Step 3: Configure DNS Records

Common records include:

Record TypePurpose
MXEmail routing
TXTVerification
CNAMEService connections
SRVSome communication services

Step 4: Assign the Domain to Users

After configuration, users can receive email addresses and sign-in names based on the new domain.


Multiple Domains

Organizations may use several domains simultaneously.

Example:

  • contoso.com
  • contoso.org
  • contosoeurope.com

Benefits include:

  • Supporting multiple business units.
  • Supporting mergers or acquisitions.
  • Serving international locations.
  • Maintaining legacy domains.

A single tenant can manage multiple domains.


Primary Domain

Among all configured domains, one domain is designated as the default (primary) domain.

The primary domain is used automatically when:

  • Creating new users.
  • Creating mailboxes.
  • Assigning email addresses.

Example:

If the default domain is:

contoso.com

New users might automatically receive:

alex@contoso.com

Organization Settings in Microsoft 365

Organization settings define how the tenant behaves and how users interact with Microsoft 365 services.

These settings are located under:

Settings → Org settings

Common categories include:

  • Organization profile
  • Security and privacy
  • Services
  • User-owned apps and services

Organization Profile Settings

The organization profile contains information about the company.

Examples include:

  • Organization name
  • Address
  • Contact information
  • Preferred language
  • Release preferences

These settings help identify the tenant and support Microsoft services.


Release Preferences

Administrators can control how Microsoft updates are delivered.

Options include:

Standard Release

  • Most users receive updates after broad testing.
  • Provides greater stability.

Targeted Release

  • Selected users receive new features earlier.
  • Useful for testing and evaluation.

Organizations often assign IT personnel to targeted release before deploying updates to everyone.


Privacy Settings

Administrators can configure privacy-related options such as:

  • Data sharing preferences.
  • Feedback collection settings.
  • Diagnostic information settings.

These options help organizations align with internal policies and compliance requirements.


User-Owned Apps and Services

Organizations can determine whether users are allowed to:

  • Purchase trial subscriptions.
  • Create self-service sign-ups.
  • Install certain services.

Restricting these capabilities helps maintain governance and control.


Microsoft Viva Settings

The organization can configure experiences related to Microsoft Viva services and employee engagement features.

Depending on licensing, administrators can control:

  • Feature availability.
  • Access to Viva experiences.
  • Organizational preferences.

Calendar and Scheduling Settings

Some organization settings affect scheduling behavior, such as:

  • Shared calendar improvements.
  • Meeting options.
  • Availability settings.

These settings improve collaboration across the organization.


Security and Collaboration Settings

Organizations can configure settings that influence:

  • External sharing.
  • Guest access.
  • Communication policies.
  • Service availability.

These settings help balance productivity with security requirements.


Specialized Admin Centers

The Microsoft 365 admin center provides links to workload-specific portals, including:

Admin CenterPurpose
Exchange Admin CenterEmail management
SharePoint Admin CenterSharePoint and OneDrive settings
Teams Admin CenterTeams management
Microsoft Entra Admin CenterIdentity and access
Purview PortalCompliance and governance
Defender PortalSecurity operations

These specialized portals provide deeper configuration options.


Why Organization Settings Matter for Microsoft 365 Copilot

Microsoft 365 Copilot relies on organizational data and services.

Proper tenant configuration helps ensure:

  • Users authenticate correctly.
  • Data sources are available.
  • Domains are configured properly.
  • Collaboration services function normally.
  • Security and governance requirements are met.

A poorly configured tenant can affect Copilot experiences.


Best Practices

Use Custom Domains

Custom domains provide a professional identity and improve user experience.

Verify DNS Carefully

Incorrect DNS records can disrupt email and other services.

Limit Targeted Release Users

Test new features with IT staff before broader deployment.

Review Organization Settings Periodically

Business requirements and compliance needs may change over time.

Maintain Accurate Organization Information

Accurate profile information supports Microsoft services and administration.


Exam Tips

Remember the following for AB-900:

  • Every tenant receives a default .onmicrosoft.com domain.
  • Custom domains must be verified before use.
  • DNS records connect Microsoft services to the domain.
  • Multiple domains can exist within one tenant.
  • The primary domain becomes the default for new users.
  • Organization settings are managed from Settings → Org settings.
  • Standard Release provides stable updates.
  • Targeted Release delivers features earlier to selected users.
  • Specialized admin centers provide service-specific management capabilities.

Practice Exam Questions

Question 1

A new Microsoft 365 tenant is automatically created with which type of domain?

A. .azure.com
B. .microsoft.net
C. .onmicrosoft.com
D. .office365.org

Correct Answer: C

Explanation: Every Microsoft 365 tenant receives a default domain ending in .onmicrosoft.com, which cannot be removed.


Question 2

Why do organizations commonly add custom domains to Microsoft 365?

A. To increase storage capacity
B. To replace Microsoft Entra ID
C. To provide professional email addresses and branding
D. To eliminate licensing requirements

Correct Answer: C

Explanation: Custom domains provide a professional identity and allow users to sign in and receive email using the organization’s own domain name.


Question 3

Before a custom domain can be used in Microsoft 365, what must occur?

A. Users must be recreated.
B. A SharePoint site must be created.
C. Teams must be enabled.
D. Domain ownership must be verified.

Correct Answer: D

Explanation: Microsoft requires proof of ownership, typically through a DNS TXT record.


Question 4

Which DNS record is commonly used to route email to Microsoft 365?

A. MX record
B. TXT record
C. SRV record
D. PTR record

Correct Answer: A

Explanation: MX records direct incoming email to the proper mail servers.


Question 5

An organization has several business divisions and wants to maintain multiple email domains. Which statement is true?

A. Only one domain is supported per tenant.
B. Multiple domains can exist within a single tenant.
C. Additional tenants are required.
D. Domains can only be added with E5 licenses.

Correct Answer: B

Explanation: Microsoft 365 supports multiple verified domains in one tenant.


Question 6

What is the purpose of the default domain in a Microsoft 365 tenant?

A. It replaces all custom domains.
B. It serves as a fallback and internal domain.
C. It stores backups.
D. It controls billing.

Correct Answer: B

Explanation: The default .onmicrosoft.com domain remains with the tenant and can be used internally and for sign-in.


Question 7

Which release option allows selected users to receive Microsoft 365 features earlier than the rest of the organization?

A. Standard Release
B. Global Release
C. Targeted Release
D. Preview Release

Correct Answer: C

Explanation: Targeted Release allows organizations to test new features before broad deployment.


Question 8

Where are organization-wide settings configured in the Microsoft 365 admin center?

A. Settings → Org settings
B. Billing → Subscriptions
C. Users → Active users
D. Health → Service health

Correct Answer: A

Explanation: Organization-level preferences are managed from the Org settings section.


Question 9

Which specialized admin center is primarily responsible for managing user identities and access?

A. Exchange Admin Center
B. Teams Admin Center
C. SharePoint Admin Center
D. Microsoft Entra Admin Center

Correct Answer: D

Explanation: Microsoft Entra Admin Center manages identities, authentication, and access policies.


Question 10

What happens when a domain is designated as the primary domain?

A. Existing domains are deleted.
B. Licensing costs increase.
C. New users automatically receive that domain by default.
D. The .onmicrosoft.com domain is removed.

Correct Answer: C

Explanation: The primary domain becomes the default domain used when new users and email addresses are created.


Go to the AB-900 Exam Prep Hub main page