Tag: Microsoft Certification

Compare Copilot monthly license model to Pay-as-You-Go, including SharePoint (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Compare Copilot monthly license model to Pay-as-You-Go, including SharePoint


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft offers multiple licensing models for AI experiences across Microsoft 365. Understanding these licensing options is important for administrators who plan deployments, manage costs, and determine which AI capabilities are available to users.

For the AB-900 exam, you should understand the differences between:

  • Microsoft 365 Copilot monthly user licensing
  • Pay-as-you-go (consumption-based) licensing
  • SharePoint Copilot licensing
  • When each licensing model is appropriate

The exam focuses on understanding the concepts rather than memorizing pricing.


Why Multiple Licensing Models Exist

Organizations vary greatly in how employees use AI.

Some organizations:

  • Have employees who use AI all day.
  • Need AI integrated into Microsoft 365 apps.
  • Require predictable monthly costs.

Other organizations:

  • Use AI occasionally.
  • Need specialized agents.
  • Want to pay only when AI is used.

Microsoft therefore offers both subscription-based and consumption-based licensing.


Microsoft 365 Copilot Monthly License Model

The traditional Microsoft 365 Copilot license is assigned to individual users.

Each licensed user receives access to Copilot experiences across supported Microsoft 365 applications.

Examples include:

  • Word
  • Excel
  • PowerPoint
  • Outlook
  • Teams
  • OneNote
  • Microsoft 365 Chat

The license is:

  • Assigned per user
  • Monthly subscription
  • Predictable recurring cost

Characteristics of the Monthly License

The monthly model provides:

  • Full Microsoft 365 Copilot experience
  • Unlimited daily usage (subject to service limits)
  • Personalized AI assistance
  • Microsoft Graph integration
  • Cross-app experiences
  • Enterprise security and compliance

This model is best for employees who regularly use Copilot throughout their workday.


Typical Monthly License Scenario

A financial analyst uses Copilot every day to:

  • Analyze Excel workbooks
  • Draft reports
  • Summarize meetings
  • Create PowerPoint presentations
  • Search organizational knowledge

Because AI is used continuously, a monthly license provides predictable costs.


Benefits of Monthly Licensing

Advantages include:

  • Predictable budgeting
  • No need to monitor consumption
  • Continuous access
  • Simplified administration
  • Consistent user experience
  • Ideal for heavy users

Limitations of Monthly Licensing

Considerations include:

  • Fixed monthly cost regardless of usage
  • Not ideal for occasional users
  • Every user requires their own license
  • Organizations may over-license infrequent users

Pay-as-You-Go Licensing

Pay-as-you-go (PAYG) is a consumption-based licensing model.

Instead of paying for every user every month, organizations pay based on actual AI usage.

Think of it similarly to cloud computing services:

  • More usage = higher cost
  • Less usage = lower cost

Characteristics of Pay-as-You-Go

Pay-as-you-go provides:

  • Usage-based billing
  • Flexible scaling
  • No requirement for every user to have a monthly Copilot license
  • Cost based on AI requests or service consumption (depending on the service)

This model is especially useful for agents and certain AI scenarios.


Benefits of Pay-as-You-Go

Advantages include:

  • Lower upfront costs
  • Pay only for actual usage
  • Flexible deployment
  • Easy experimentation
  • Ideal for seasonal workloads
  • Good for occasional users

Limitations of Pay-as-You-Go

Potential drawbacks include:

  • Variable monthly costs
  • Budget forecasting is more difficult
  • Requires monitoring usage
  • Heavy usage may become more expensive than subscription licensing

Comparing Monthly Licensing and Pay-as-You-Go

Monthly LicensePay-as-You-Go
Fixed monthly costUsage-based cost
Licensed per userConsumption-based
Predictable budgetingVariable spending
Best for daily usersBest for occasional use
Continuous Copilot accessPay only when AI is used
Simpler cost managementRequires usage monitoring

Microsoft 365 Copilot Chat

Organizations should understand that Microsoft offers AI experiences beyond the traditional monthly Copilot license.

For example:

  • Microsoft 365 Copilot Chat is available to Microsoft 365 users.
  • Organizations can extend Copilot Chat with agents.
  • Some agent usage can be billed using pay-as-you-go licensing rather than requiring every user to have a full Copilot subscription.

This provides flexibility for organizations with mixed AI usage patterns.


SharePoint and Copilot

SharePoint includes AI capabilities that help users work with documents, sites, and organizational knowledge.

Examples include:

  • Summarizing documents
  • Answering questions about files
  • Generating page content
  • Assisting with document creation
  • Improving knowledge discovery

SharePoint Agents

One important capability is SharePoint agents.

A SharePoint agent can:

  • Be created from a SharePoint site or document library
  • Answer questions using approved SharePoint content
  • Help users locate organizational knowledge
  • Reduce the need to manually search documents

For example:

A Human Resources SharePoint site may contain:

  • Employee handbook
  • Benefits guide
  • Leave policies
  • Training documents

An HR SharePoint agent can answer employee questions using those documents.


SharePoint Pay-as-You-Go

Organizations can use SharePoint agents without assigning every user a full Microsoft 365 Copilot license.

Instead, administrators can configure consumption-based billing.

Benefits include:

  • Lower cost for occasional users
  • Easy pilot deployments
  • Department-specific AI
  • Flexible scaling

This makes SharePoint agents attractive for organizations wanting targeted AI experiences without licensing every employee.


Choosing the Right Licensing Model

Choose Monthly Licensing When

  • Employees use Copilot every day.
  • AI is integrated into daily workflows.
  • Predictable monthly budgeting is important.
  • Users need full Copilot functionality across Microsoft 365.

Examples:

  • Executives
  • Project managers
  • Analysts
  • Consultants
  • Sales professionals
  • Knowledge workers

Choose Pay-as-You-Go When

  • AI usage is occasional.
  • Organizations are testing AI.
  • Departments need specialized agents.
  • Seasonal usage is expected.
  • Budget flexibility is acceptable.

Examples:

  • HR help desk agent
  • Legal document agent
  • IT support chatbot
  • SharePoint knowledge assistant

Administrative Considerations

Administrators should evaluate:

  • Expected AI usage
  • Number of users
  • Cost predictability
  • Department requirements
  • Governance policies
  • Licensing strategy
  • Agent deployment plans

Security Remains the Same

Regardless of licensing model:

  • Microsoft Entra ID authentication is used.
  • Microsoft Graph permissions are enforced.
  • Microsoft Purview policies apply.
  • Data Loss Prevention (DLP) policies remain active.
  • Sensitivity labels continue protecting content.
  • Microsoft Defender protections remain in effect.

Licensing changes how organizations pay for AI—not how Microsoft secures organizational data.


Best Practices

Microsoft recommends that organizations:

  • License frequent users with Microsoft 365 Copilot subscriptions.
  • Use pay-as-you-go for occasional AI usage.
  • Monitor AI adoption and consumption.
  • Start with pilot deployments.
  • Evaluate SharePoint agents for departmental knowledge scenarios.
  • Review licensing regularly as adoption increases.

Exam Tips

For the AB-900 exam, remember these key points:

  • Microsoft 365 Copilot is commonly licensed per user with a monthly subscription.
  • Pay-as-you-go bills organizations based on AI usage.
  • Monthly licensing provides predictable costs.
  • Pay-as-you-go offers flexibility for occasional or specialized AI use.
  • SharePoint agents can be deployed using consumption-based licensing in supported scenarios.
  • Licensing affects billing—not security or permissions.
  • Microsoft Graph, Microsoft Purview, and Microsoft Entra ID protections apply regardless of licensing model.
  • Heavy AI users are generally better suited to monthly licensing.
  • Departmental or pilot AI deployments often benefit from pay-as-you-go.

Practice Exam Questions

Question 1

Which licensing model provides users with a predictable monthly cost for Microsoft 365 Copilot?

A. Pay-as-you-go
B. Monthly per-user license
C. Azure consumption credits
D. SharePoint storage licensing

Correct Answer: B

Explanation: A monthly per-user license provides continuous access to Microsoft 365 Copilot for a fixed monthly subscription.


Question 2

What is the primary advantage of the pay-as-you-go licensing model?

A. Users receive unlimited AI usage regardless of activity.
B. Organizations pay only for actual AI usage.
C. Every employee automatically receives Microsoft 365 Copilot.
D. It disables Microsoft Graph integration.

Correct Answer: B

Explanation: Pay-as-you-go charges based on consumption, making it suitable for occasional or specialized AI usage.


Question 3

Which type of user is generally the best candidate for a Microsoft 365 Copilot monthly license?

A. An employee who rarely uses Microsoft 365 applications
B. A seasonal contractor who accesses AI once a month
C. A knowledge worker who uses Copilot throughout the workday
D. A visitor with guest access to SharePoint

Correct Answer: C

Explanation: Heavy or daily users benefit from the predictable costs and continuous access provided by the monthly licensing model.


Question 4

An organization wants to deploy an HR SharePoint agent that employees will use occasionally. Which licensing model is often the better fit?

A. Monthly Copilot license for every employee
B. Windows Enterprise licensing
C. Exchange Online licensing
D. Pay-as-you-go

Correct Answer: D

Explanation: Pay-as-you-go is well suited for departmental agents with occasional usage, allowing organizations to pay based on consumption.


Question 5

Which statement about Microsoft 365 Copilot monthly licensing is correct?

A. It charges only when AI is used.
B. It is assigned to individual users as a subscription.
C. It replaces Microsoft Entra ID.
D. It is available only for SharePoint.

Correct Answer: B

Explanation: The traditional Microsoft 365 Copilot model is licensed per user through a recurring subscription.


Question 6

Which capability is commonly associated with SharePoint agents?

A. Managing Windows updates
B. Replacing Microsoft Graph
C. Answering questions using SharePoint content and document libraries
D. Creating Azure virtual machines

Correct Answer: C

Explanation: SharePoint agents are grounded in SharePoint content and help users locate and understand organizational knowledge.


Question 7

How do Microsoft Purview policies behave when an organization switches from monthly licensing to pay-as-you-go?

A. They are automatically disabled.
B. They apply only to SharePoint documents.
C. They require users to purchase additional licenses before functioning.
D. They continue to protect data regardless of the licensing model.

Correct Answer: D

Explanation: Security and compliance controls such as Microsoft Purview continue to protect data regardless of how AI services are licensed.


Question 8

Which licensing model generally provides the most predictable monthly budgeting?

A. Pay-as-you-go
B. Monthly per-user licensing
C. Azure Reserved Instances
D. SharePoint storage quotas

Correct Answer: B

Explanation: Monthly licensing offers a fixed recurring cost, simplifying budgeting and financial planning.


Question 9

What is a potential disadvantage of pay-as-you-go licensing?

A. It cannot be used with agents.
B. It prevents users from accessing SharePoint.
C. Monthly costs may vary depending on AI usage.
D. It disables Microsoft Graph permissions.

Correct Answer: C

Explanation: Consumption-based billing means costs fluctuate according to actual usage, making budgeting less predictable.


Question 10

Which statement best summarizes the difference between Microsoft 365 Copilot monthly licensing and pay-as-you-go?

A. Monthly licensing is subscription-based, while pay-as-you-go is consumption-based.
B. Monthly licensing does not include Microsoft Graph.
C. Pay-as-you-go removes Microsoft Purview protections.
D. Monthly licensing is only available for SharePoint.

Correct Answer: A

Explanation: The fundamental difference is the billing model: monthly licensing charges a fixed subscription per user, whereas pay-as-you-go charges based on actual AI service consumption.


Go to the AB-900 Exam Prep Hub main page

Compare the built-in capabilities of Copilot and agents (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Perform basic administrative tasks for Copilot and agents (25–30%)
   --> Understand features and capabilities of Copilot and agents
      --> Compare the built-in capabilities of Copilot and agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft 365 provides powerful AI capabilities through Microsoft 365 Copilot and agents. Although they are closely related, they serve different purposes.

A common misconception is that Copilot and agents are the same technology. In reality:

  • Microsoft 365 Copilot is the AI assistant that helps users work across Microsoft 365 applications.
  • Agents are specialized AI assistants designed to perform focused tasks, automate business processes, or provide expertise in specific domains.

Understanding the differences between Copilot and agents is an important objective on the AB-900 exam.


What is Microsoft 365 Copilot?

Microsoft 365 Copilot is Microsoft’s AI assistant integrated throughout Microsoft 365 applications.

It combines:

  • Large Language Models (LLMs)
  • Microsoft Graph
  • Microsoft 365 data
  • User permissions
  • Organizational knowledge

Copilot helps users complete everyday work faster while respecting existing security permissions.

Examples include:

  • Drafting emails
  • Summarizing meetings
  • Creating PowerPoint presentations
  • Analyzing Excel data
  • Writing Word documents
  • Answering natural language questions
  • Summarizing Teams chats

Copilot is designed to improve personal productivity across many different tasks.


What are Microsoft 365 Agents?

Agents are AI assistants created to perform specialized or repeatable business tasks.

Rather than serving as a general assistant, an agent focuses on a specific job.

Examples include:

  • HR policy assistant
  • IT help desk assistant
  • Sales proposal assistant
  • Customer service assistant
  • Legal document assistant
  • Procurement assistant
  • Finance assistant

Agents can:

  • Answer questions from approved knowledge sources
  • Follow business rules
  • Guide users through processes
  • Complete multi-step workflows
  • Connect to business systems

Comparing Copilot and Agents

Microsoft 365 CopilotMicrosoft 365 Agents
General-purpose AI assistantSpecialized AI assistant
Works across Microsoft 365Focuses on a specific business task
Assists individual productivityAssists business processes
Uses Microsoft Graph extensivelyCan use Graph plus additional knowledge sources
Available in Microsoft 365 appsCan be published inside Teams, Microsoft 365, SharePoint, and other experiences
Broad conversational abilitiesDomain-specific expertise

Built-in Capabilities of Microsoft 365 Copilot

Copilot includes many built-in features without requiring customization.

Content Creation

Copilot can:

  • Draft documents
  • Rewrite text
  • Summarize documents
  • Change writing tone
  • Generate presentations
  • Create outlines
  • Brainstorm ideas

Example:

“Create a proposal for a new customer.”


Meeting Intelligence

Within Microsoft Teams, Copilot can:

  • Summarize meetings
  • Capture decisions
  • List action items
  • Answer questions about the meeting
  • Identify unresolved issues

Example:

“What decisions were made during yesterday’s meeting?”


Email Assistance

In Outlook, Copilot can:

  • Draft responses
  • Summarize long email threads
  • Suggest follow-up actions
  • Improve writing style

Data Analysis

Within Excel, Copilot can:

  • Explain formulas
  • Generate charts
  • Analyze trends
  • Identify outliers
  • Create summaries

Example:

“Show quarterly sales trends.”


Knowledge Discovery

Copilot searches organizational knowledge using Microsoft Graph.

It can answer questions such as:

  • “What projects am I working on?”
  • “Summarize documents related to Project Apollo.”
  • “What files has my manager recently shared?”

Cross-Application Context

One major capability is connecting information across applications.

Example:

Copilot may combine information from:

  • Outlook
  • Teams
  • Word
  • OneDrive
  • SharePoint
  • Calendar

to answer a single prompt.


Built-in Capabilities of Agents

Agents focus on completing specialized work.


Task-Specific Expertise

An agent is trained or configured around one topic.

Examples:

HR Agent

  • Vacation policy
  • Benefits
  • Employee handbook

IT Agent

  • Password reset guidance
  • Software installation
  • Device troubleshooting

Finance Agent

  • Expense reimbursement
  • Budget approval
  • Procurement rules

Business Process Guidance

Agents can walk users through business procedures.

Example:

Instead of simply answering a question, an HR onboarding agent can:

  • Explain required forms
  • Guide new employees
  • Answer benefits questions
  • Provide training links

Knowledge Grounding

Agents can use approved organizational knowledge.

Examples include:

  • SharePoint libraries
  • Internal documents
  • Knowledge bases
  • Business manuals
  • Policies
  • FAQs

Unlike general internet chatbots, agents only answer from approved sources.


Workflow Automation

Agents can perform multiple steps automatically.

Example:

A travel request agent might:

  • Collect travel details
  • Validate policy
  • Request manager approval
  • Submit the request
  • Notify the employee

Connectors

Agents can connect to external business systems.

Examples:

  • Dynamics 365
  • ServiceNow
  • Salesforce
  • SAP
  • Workday
  • Microsoft Dataverse

This allows agents to retrieve business information securely.


Consistent Business Responses

Unlike free-form conversations, agents provide consistent answers based on organizational knowledge.

This reduces confusion and improves compliance.


Shared Capabilities

Both Copilot and agents share many AI features.

These include:

  • Natural language interaction
  • Context-aware conversations
  • AI-generated responses
  • Respect for Microsoft Entra ID permissions
  • Security trimming
  • Microsoft Graph integration (where applicable)
  • Use of Large Language Models
  • Support for Microsoft 365 security and compliance controls

Key Differences

Scope

Copilot

Broad productivity assistant.

Agent

Focused business assistant.


Purpose

Copilot

Helps users complete work.

Agent

Helps complete specific business processes.


Knowledge

Copilot

Uses Microsoft Graph plus organizational content.

Agent

Uses selected knowledge sources chosen by administrators or creators.


Customization

Copilot

Little customization required.

Agents

Often customized for departments or business scenarios.


Reusability

Copilot

Same assistant for everyone (subject to permissions).

Agents

Different agents can exist for different teams.

Examples:

  • Legal Agent
  • Sales Agent
  • Finance Agent
  • HR Agent

Copilot vs. Agent Example

A user asks:

“I need to prepare for a customer renewal.”

Copilot might:

  • Summarize recent emails
  • Review meeting notes
  • Draft a proposal
  • Create a PowerPoint

A Sales Agent might:

  • Retrieve CRM information
  • Check renewal status
  • Calculate discounts
  • Recommend pricing
  • Generate renewal documentation

Both assist the user—but in different ways.


Security

Both Copilot and agents follow Microsoft security principles.

They respect:

  • Microsoft Entra ID authentication
  • User permissions
  • Microsoft Graph security trimming
  • Microsoft Purview sensitivity labels
  • Data Loss Prevention (DLP) policies
  • Conditional Access policies
  • Compliance controls

Neither Copilot nor agents expose information users are not authorized to access.


Common Exam Tips

Remember these distinctions:

  • Copilot is a general-purpose AI assistant.
  • Agents are specialized assistants for business scenarios.
  • Copilot improves productivity across Microsoft 365.
  • Agents automate or simplify specific business tasks.
  • Both use natural language.
  • Both respect existing Microsoft 365 permissions.
  • Agents can connect to external business systems.
  • Multiple agents can exist within the same organization.
  • Copilot does not replace business applications—it works with them.
  • Administrators govern both using Microsoft 365 security and compliance controls.

Practice Exam Questions

Question 1

What is the primary purpose of Microsoft 365 Copilot?

A. Replace business applications
B. Provide a general AI assistant across Microsoft 365 applications
C. Manage Microsoft Entra ID users
D. Automatically configure SharePoint permissions

Correct Answer: B

Explanation: Microsoft 365 Copilot is a general-purpose AI assistant that enhances productivity across Microsoft 365 applications.


Question 2

Which scenario is best suited for a Microsoft 365 agent?

A. Creating a PowerPoint presentation from meeting notes
B. Summarizing an Outlook inbox
C. Guiding employees through HR onboarding procedures
D. Drafting a Word document

Correct Answer: C

Explanation: Agents are designed for specialized business tasks such as HR onboarding, IT support, or finance workflows.


Question 3

Which feature is shared by both Microsoft 365 Copilot and agents?

A. They ignore Microsoft Entra permissions.
B. They require internet searches for every response.
C. They automatically grant file access.
D. They support natural language conversations.

Correct Answer: D

Explanation: Both Copilot and agents use conversational AI, allowing users to interact using natural language.


Question 4

Which capability is unique to many business agents?

A. Creating Word documents
B. Summarizing Teams meetings
C. Performing specialized workflows using business systems
D. Rewriting email messages

Correct Answer: C

Explanation: Agents can automate specialized business workflows and connect with enterprise systems.


Question 5

Microsoft 365 Copilot primarily retrieves organizational information through:

A. Microsoft Graph
B. Azure Virtual Desktop
C. Windows Registry
D. Local device storage

Correct Answer: A

Explanation: Microsoft Graph provides Copilot with secure access to organizational data while respecting user permissions.


Question 6

Which statement best describes Microsoft 365 agents?

A. They replace Microsoft Graph.
B. They are designed for focused business scenarios and specialized tasks.
C. They only answer questions about Microsoft products.
D. They are available only in Outlook.

Correct Answer: B

Explanation: Agents are purpose-built AI assistants that support specific business processes or departmental functions.


Question 7

How do Copilot and agents protect organizational data?

A. They bypass file permissions for administrators.
B. They make all SharePoint content searchable.
C. They respect existing Microsoft 365 permissions and compliance controls.
D. They permanently copy data into AI models.

Correct Answer: C

Explanation: Both solutions honor Microsoft Entra ID permissions, Microsoft Graph security trimming, and Microsoft Purview governance policies.


Question 8

Which task would Microsoft 365 Copilot most likely perform?

A. Reset a user’s Active Directory password automatically.
B. Analyze an Excel workbook and explain sales trends.
C. Replace the organization’s CRM system.
D. Configure Conditional Access policies.

Correct Answer: B

Explanation: Copilot excels at productivity tasks such as analyzing Excel data and generating insights.


Question 9

An organization creates separate HR, Legal, and Finance AI assistants. These are examples of:

A. Microsoft Graph connectors
B. SharePoint hubs
C. Copilot prompts
D. Specialized agents

Correct Answer: D

Explanation: Organizations can build multiple specialized agents tailored to different departments and business functions.


Question 10

What is one of the biggest differences between Microsoft 365 Copilot and agents?

A. Copilot is a broad productivity assistant, while agents focus on specific business tasks.
B. Agents do not use AI.
C. Copilot ignores Microsoft 365 permissions.
D. Agents cannot access organizational knowledge.

Correct Answer: A

Explanation: Copilot provides broad productivity assistance across Microsoft 365, whereas agents are designed for specialized business scenarios and targeted workflows.


Go to the AB-900 Exam Prep Hub main page

Understand features and capabilities of SharePoint Advanced Management, including restricted site access (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify and monitor oversharing in SharePoint in Microsoft 365
      --> Understand features and capabilities of SharePoint Advanced Management, including restricted site access


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

As organizations increasingly rely on Microsoft 365, SharePoint Online, Microsoft Teams, and Microsoft 365 Copilot, protecting organizational data has become more important than ever. While collaboration is essential, unrestricted sharing can expose confidential information to unintended users.

To help organizations better govern SharePoint content, Microsoft offers SharePoint Advanced Management (SAM), a collection of advanced governance, reporting, security, and lifecycle management capabilities designed to improve the security of SharePoint and OneDrive environments.

One of its most important features is Restricted Site Access, which allows administrators to temporarily limit access to specific SharePoint sites that may contain highly sensitive or potentially overshared information.

For the AB-900 exam, you should understand the purpose of SharePoint Advanced Management, its major capabilities, and how Restricted Site Access helps reduce data exposure.


What is SharePoint Advanced Management?

SharePoint Advanced Management is a set of administrative capabilities that extends the standard SharePoint Online administration experience.

Its goals include:

  • Improving governance
  • Reducing oversharing
  • Enhancing visibility into permissions
  • Strengthening data protection
  • Supporting Microsoft 365 Copilot readiness
  • Helping organizations adopt Zero Trust security principles

Rather than replacing Microsoft Purview or Microsoft Defender, SharePoint Advanced Management complements these services by focusing specifically on SharePoint and OneDrive administration.


Why SharePoint Advanced Management Is Important

Organizations often have:

  • Thousands of SharePoint sites
  • Millions of documents
  • Numerous external users
  • Complex permission structures
  • Years of accumulated sharing links

As these environments grow, administrators face challenges such as:

  • Overshared files
  • Forgotten external sharing
  • Stale permissions
  • Sensitive documents accessible by too many users
  • Inactive or abandoned sites

SharePoint Advanced Management provides tools to identify and address these issues before they become security incidents.


Key Capabilities of SharePoint Advanced Management

SharePoint Advanced Management includes several capabilities designed to improve governance.

1. Data Access Governance Reporting

Administrators can:

  • Identify overshared sites
  • Review sharing activity
  • Analyze permission configurations
  • Discover external access
  • Locate high-risk collaboration sites

These reports provide visibility into who can access organizational content.


2. Site Lifecycle Management

Organizations frequently create project sites that remain active long after projects end.

SharePoint Advanced Management helps administrators:

  • Identify inactive sites
  • Review site ownership
  • Archive or delete unused sites
  • Reduce unnecessary content exposure

Proper lifecycle management reduces security risks while improving overall governance.


3. Oversharing Insights

Administrators can identify:

  • Sites shared broadly
  • Anonymous sharing links
  • Guest access
  • Sensitive sites with excessive permissions
  • Large-scale permission inheritance issues

These insights are particularly valuable before deploying Microsoft 365 Copilot.


4. Site Ownership Management

SharePoint sites require responsible owners.

Advanced Management helps administrators identify:

  • Sites without owners
  • Inactive owners
  • Ownership inconsistencies

Proper ownership improves accountability and ensures permissions are reviewed regularly.


5. Sharing Governance

Administrators can evaluate:

  • External sharing
  • Anonymous links
  • Organization-wide access
  • Sharing policies
  • Guest permissions

This helps organizations reduce unnecessary collaboration risks.


6. Restricted Site Access

One of the most important SharePoint Advanced Management capabilities is Restricted Site Access.


What is Restricted Site Access?

Restricted Site Access allows administrators to temporarily limit access to a SharePoint site.

When enabled:

  • Most users lose access to the site.
  • Only designated administrators or approved users can access the content.
  • Copilot and Microsoft Search continue to respect the updated permissions because they always honor Microsoft 365 security trimming.

This feature is useful when a site contains highly sensitive information or requires investigation.


Why Use Restricted Site Access?

Organizations may need to immediately reduce access when:

  • Sensitive information has been overshared.
  • A security investigation is underway.
  • Legal or regulatory reviews are occurring.
  • Confidential merger or acquisition documents are stored.
  • Human Resources investigations are active.
  • Executive leadership documents require additional protection.
  • Sensitive intellectual property is being reviewed.

Rather than deleting the site, administrators can quickly restrict access while remediation occurs.


How Restricted Site Access Works

The feature temporarily changes access behavior by allowing only explicitly authorized users to access the site.

Typical workflow:

  1. Administrator identifies a high-risk site.
  2. Restricted Site Access is enabled.
  3. Only approved users retain access.
  4. Administrators investigate permissions.
  5. Oversharing issues are corrected.
  6. Normal access is restored when appropriate.

Benefits of Restricted Site Access

Organizations gain several advantages:

Rapid Risk Reduction

Potential data exposure is reduced immediately.

Supports Investigations

Investigators can examine permissions without widespread user access.

Improves Governance

Administrators gain time to review sharing settings before reopening access.

Protects Sensitive Information

Highly confidential documents remain accessible only to authorized personnel.

Supports Compliance

Temporary restrictions can assist with legal, regulatory, or internal compliance reviews.


Relationship with Microsoft 365 Copilot

Microsoft 365 Copilot respects Microsoft 365 permissions.

If a site becomes restricted:

  • Copilot cannot retrieve information from that site for users who no longer have permission.
  • Microsoft Search also honors the updated permissions.
  • Other Microsoft 365 services continue using the same security model.

Restricted Site Access therefore reduces the likelihood that Copilot will surface sensitive content from that site.


Relationship with Microsoft Purview

SharePoint Advanced Management and Microsoft Purview work together.

Microsoft Purview focuses on:

  • Data classification
  • Sensitivity labels
  • Data Loss Prevention (DLP)
  • Insider Risk Management
  • Data Lifecycle Management
  • Compliance

SharePoint Advanced Management focuses on:

  • Site governance
  • Permissions
  • Oversharing
  • Site administration
  • Access analysis
  • Restricted Site Access

Together they provide comprehensive protection for Microsoft 365 data.


Relationship with Microsoft Defender

Microsoft Defender identifies threats such as:

  • Compromised accounts
  • Suspicious user activity
  • Malware
  • Phishing attacks

If Defender identifies suspicious activity involving a SharePoint site, administrators may choose to enable Restricted Site Access while investigating the incident.


Best Practices

Microsoft recommends the following practices:

  • Regularly review Data Access Governance reports.
  • Minimize broad “Everyone” permissions.
  • Review external sharing frequently.
  • Assign active site owners.
  • Archive inactive sites.
  • Apply sensitivity labels to sensitive content.
  • Use Restricted Site Access only when necessary.
  • Review restricted sites periodically and restore normal access when appropriate.
  • Combine SharePoint Advanced Management with Microsoft Purview and Microsoft Defender for layered protection.
  • Follow the principle of least privilege.

Exam Tips

Remember these key points for the AB-900 exam:

  • SharePoint Advanced Management focuses on governance and security for SharePoint and OneDrive.
  • It helps identify and remediate oversharing.
  • Restricted Site Access temporarily limits access to sensitive SharePoint sites.
  • Copilot always respects SharePoint permissions, including restricted sites.
  • Restricted Site Access is useful during investigations or when sensitive information has been overshared.
  • SharePoint Advanced Management complements Microsoft Purview rather than replacing it.
  • Proper site ownership and lifecycle management reduce long-term security risks.

Practice Exam Questions

Question 1

Which primary problem does SharePoint Advanced Management help organizations address?

A. Windows operating system updates

B. Oversharing and governance of SharePoint content

C. SQL Server performance tuning

D. Microsoft Teams meeting scheduling

Correct Answer: B

Explanation: SharePoint Advanced Management provides governance tools that help identify oversharing, manage permissions, and improve the security of SharePoint and OneDrive environments.


Question 2

What is the purpose of Restricted Site Access?

A. Permanently delete SharePoint sites

B. Encrypt every document within a site

C. Temporarily limit access to a SharePoint site for authorized users only

D. Automatically archive inactive sites

Correct Answer: C

Explanation: Restricted Site Access allows administrators to temporarily restrict access to a site while investigating or protecting sensitive information.


Question 3

Why is SharePoint Advanced Management valuable before deploying Microsoft 365 Copilot?

A. It increases Copilot response speed.

B. It upgrades Microsoft Graph.

C. It removes all external users automatically.

D. It helps identify overshared content that Copilot could otherwise access based on existing permissions.

Correct Answer: D

Explanation: Since Copilot honors existing permissions, reducing oversharing before deployment helps minimize the risk of exposing sensitive information.


Question 4

Which capability is included in SharePoint Advanced Management?

A. Azure virtual machine backup

B. Microsoft Intune device enrollment

C. Data Access Governance reporting

D. Windows Server patch management

Correct Answer: C

Explanation: Data Access Governance reporting is a core capability that helps administrators analyze permissions and identify overshared content.


Question 5

What happens when Restricted Site Access is enabled?

A. Microsoft 365 Copilot ignores the restriction.

B. Only approved users and administrators retain access to the site.

C. All SharePoint sites become read-only.

D. External sharing is permanently disabled across the tenant.

Correct Answer: B

Explanation: Restricted Site Access limits access to authorized users, and Copilot continues to respect those permissions.


Question 6

Which Microsoft service primarily complements SharePoint Advanced Management by classifying and protecting sensitive information?

A. Microsoft Purview

B. Microsoft Paint

C. Windows Defender Firewall

D. Microsoft Project

Correct Answer: A

Explanation: Microsoft Purview provides data classification, labeling, DLP, and compliance capabilities that complement SharePoint governance features.


Question 7

Which scenario is an appropriate use case for Restricted Site Access?

A. Scheduling recurring Teams meetings

B. Updating Microsoft 365 licenses

C. Protecting a SharePoint site containing confidential merger documents during negotiations

D. Increasing SharePoint storage capacity

Correct Answer: C

Explanation: Restricting access to highly confidential content during sensitive business activities helps reduce the risk of accidental exposure.


Question 8

Which governance activity helps reduce long-term security risks in SharePoint?

A. Creating additional anonymous sharing links

B. Allowing all users full control of every site

C. Disabling Microsoft Search

D. Reviewing inactive sites and assigning active site owners

Correct Answer: D

Explanation: Proper site ownership and lifecycle management reduce abandoned sites and improve ongoing governance.


Question 9

How does Microsoft 365 Copilot interact with a site that has Restricted Site Access enabled?

A. Copilot bypasses the restriction for administrators only.

B. Copilot ignores SharePoint permissions.

C. Copilot respects the updated permissions and cannot retrieve content for unauthorized users.

D. Copilot copies restricted files into Microsoft Graph.

Correct Answer: C

Explanation: Copilot always honors Microsoft 365 permissions. If a user cannot access a restricted site, Copilot cannot use its content in responses for that user.


Question 10

Which statement best describes SharePoint Advanced Management?

A. It replaces Microsoft Purview entirely.

B. It is focused on SharePoint and OneDrive governance, permissions, lifecycle management, and oversharing protection.

C. It functions as an antivirus solution.

D. It manages Microsoft Entra ID authentication policies.

Correct Answer: B

Explanation: SharePoint Advanced Management provides advanced governance capabilities for SharePoint and OneDrive, including oversharing detection, site lifecycle management, permission analysis, and Restricted Site Access.


Go to the AB-900 Exam Prep Hub main page

Run a data access governance report in SharePoint (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify and monitor oversharing in SharePoint in Microsoft 365
      --> Run a data access governance report in SharePoint


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

That is an excellent next topic for the AB-900 exam because it combines SharePoint governance, Microsoft Purview, and Copilot data security. Although the feature continues to evolve, the exam focuses on understanding what the report is, when to use it, and what problems it helps administrators solve, rather than memorizing every UI step.


Why Data Access Governance Matters

One of the largest security challenges in Microsoft 365 is oversharing. Over time, organizations accumulate millions of files, thousands of SharePoint sites, and numerous Microsoft Teams workspaces. Permissions often become increasingly complex as users:

  • Share files externally
  • Create anonymous sharing links
  • Grant access to “Everyone”
  • Add guests to Teams
  • Break inheritance on folders
  • Forget to remove temporary permissions

As organizations adopt Microsoft 365 Copilot, overshared content becomes an even greater concern because Copilot can surface information that a user already has permission to access—even if that access was unintentionally granted.

Microsoft provides Data Access Governance (DAG) capabilities in SharePoint to help administrators discover, understand, and remediate excessive access before it becomes a security issue.


What is Data Access Governance?

Data Access Governance is a collection of reporting and analysis capabilities within SharePoint Advanced Management that helps administrators answer questions such as:

  • Which sites are accessible by everyone?
  • Which files are overshared?
  • Which sites have external users?
  • Which sites contain highly sensitive information?
  • Which permissions may expose confidential content?
  • Which sites should be reviewed?

Rather than examining permissions one site at a time, administrators receive organization-wide visibility.


Primary Goals of Data Access Governance

Data Access Governance helps organizations:

  • Discover overshared sites
  • Review permissions
  • Reduce excessive access
  • Identify high-risk collaboration
  • Improve Microsoft 365 security posture
  • Prepare for Microsoft 365 Copilot deployment
  • Reduce accidental data exposure
  • Support compliance initiatives

Why It Is Important for Microsoft 365 Copilot

Microsoft 365 Copilot never ignores permissions.

Instead, it retrieves content using the same security model that governs Microsoft 365.

If a user has permission to open a document manually, Copilot can potentially reference that document when generating responses.

For example:

Suppose Human Resources accidentally grants the entire company read access to salary spreadsheets.

Without Copilot:

  • Most employees may never discover the files.

With Copilot:

A user might ask:

“Summarize employee compensation data.”

Because the files are already accessible, Copilot could retrieve them.

The problem is not Copilot—it is the underlying permissions.

Data Access Governance helps identify these permission problems before they become security risks.


What the Data Access Governance Report Shows

The report provides administrators with visibility into SharePoint permissions and sharing configurations across the tenant.

Common information includes:

  • Site owners
  • Site sensitivity
  • External sharing status
  • Number of members
  • Anonymous links
  • Organization-wide access
  • Guest access
  • Sharing activity
  • Permission inheritance
  • Access patterns
  • High-risk sites
  • Overshared content indicators

Rather than searching manually, administrators can prioritize the highest-risk locations.


Types of Oversharing That Can Be Identified

The report can identify situations such as:

Organization-wide access

Sites accessible by:

  • Everyone
  • Everyone except external users
  • Large security groups

These sites often expose more content than intended.


Anonymous Links

Files shared through links that require no authentication.

These links may remain active long after they are needed.


Guest Access

Sites containing:

  • External users
  • Partner accounts
  • Vendor accounts

Administrators can verify whether guest access is still appropriate.


Excessive Sharing

Examples include:

  • Large numbers of shared files
  • Broad sharing permissions
  • Public document libraries
  • Open collaboration spaces

Sensitive Sites

The report can identify sites that contain:

  • Financial information
  • HR records
  • Legal documents
  • Intellectual property
  • Customer information

Combined with Microsoft Purview sensitivity labels, administrators gain better visibility into where important information resides.


Typical Workflow

Administrators generally follow this process:

Step 1

Open SharePoint administration tools.


Step 2

Generate or review a Data Access Governance report.


Step 3

Review identified risks.

Examples:

  • Overshared sites
  • External sharing
  • Everyone permissions
  • Sensitive content

Step 4

Investigate high-risk sites.

Questions include:

  • Does this access need to exist?
  • Are guests still required?
  • Is inheritance broken?
  • Should permissions be reduced?

Step 5

Take corrective action.

Possible actions include:

  • Remove permissions
  • Restrict sharing
  • Apply sensitivity labels
  • Disable anonymous links
  • Reduce guest access
  • Educate site owners

Step 6

Run reports regularly to verify improvements.


Relationship with Microsoft Purview

Data Access Governance works alongside Microsoft Purview.

Purview answers questions such as:

  • What sensitive data exists?
  • How is it classified?
  • Which labels are applied?
  • Are DLP policies triggered?

SharePoint Data Access Governance answers:

  • Who can access the data?
  • Is the data overshared?
  • Which sites expose information?
  • Which permissions should be reviewed?

Together they provide both:

  • Content awareness
  • Permission awareness

Relationship with Microsoft 365 Copilot

Data Access Governance helps administrators prepare for Copilot by reducing permission-related risks.

Benefits include:

  • Finding overshared SharePoint sites
  • Identifying unnecessary permissions
  • Reducing broad access
  • Reviewing guest sharing
  • Protecting confidential information
  • Improving search security
  • Supporting Zero Trust principles

Best Practices

Microsoft recommends that organizations:

  • Review sharing reports regularly.
  • Audit external access periodically.
  • Minimize “Everyone” permissions.
  • Remove unused guest accounts.
  • Apply sensitivity labels to important sites.
  • Use Microsoft Purview DLP alongside SharePoint governance.
  • Educate site owners on responsible sharing.
  • Review high-risk collaboration sites before deploying Copilot broadly.
  • Follow the principle of least privilege.
  • Continuously monitor permission changes.

Common Exam Tips

Remember these key points:

  • Data Access Governance focuses on permissions and access, not document content.
  • It helps identify oversharing across SharePoint.
  • It is especially valuable before deploying Microsoft 365 Copilot.
  • Copilot respects existing Microsoft 365 permissions.
  • Oversharing is a permissions problem, not a Copilot problem.
  • Reports help administrators prioritize high-risk sites for remediation.
  • Data Access Governance complements Microsoft Purview rather than replacing it.

Practice Exam Questions

Question 1

Why would an administrator run a Data Access Governance report in SharePoint?

A. To update SharePoint servers

B. To identify overshared sites and permission risks

C. To encrypt all documents automatically

D. To generate Microsoft 365 licenses

Correct Answer: B

Explanation: Data Access Governance helps administrators identify sites with excessive permissions, external sharing, and other access-related risks.


Question 2

Which issue is Data Access Governance primarily designed to identify?

A. SQL database corruption

B. Printer failures

C. Oversharing of SharePoint content

D. Network latency

Correct Answer: C

Explanation: The primary purpose is to detect oversharing and excessive permissions across SharePoint.


Question 3

Why is Data Access Governance especially important before deploying Microsoft 365 Copilot?

A. Copilot automatically changes permissions.

B. Copilot ignores SharePoint security.

C. Copilot copies all SharePoint files.

D. Copilot can reference content users already have permission to access.

Correct Answer: D

Explanation: Copilot honors existing permissions. Overshared content may therefore appear in Copilot responses if users already have legitimate access.


Question 4

Which type of access represents a potential oversharing risk?

A. Anonymous sharing links

B. Azure subscription ownership

C. Exchange mailbox size

D. Microsoft Teams background images

Correct Answer: A

Explanation: Anonymous links allow access without authentication and should be reviewed carefully.


Question 5

What question does Data Access Governance primarily help answer?

A. Which users have excessive access to SharePoint content?

B. Which Windows updates are missing?

C. Which devices need antivirus software?

D. Which Microsoft 365 licenses should be purchased?

Correct Answer: A

Explanation: Data Access Governance focuses on permissions, sharing, and access to SharePoint content.


Question 6

Which Microsoft 365 principle is supported by regularly reviewing Data Access Governance reports?

A. Unlimited collaboration

B. Least privilege

C. Maximum storage allocation

D. Unlimited guest access

Correct Answer: B

Explanation: Regular reviews help ensure users have only the permissions necessary to perform their work.


Question 7

Which type of SharePoint site would likely appear as higher risk in a Data Access Governance report?

A. A private HR site with restricted access

B. A site shared with only one administrator

C. A site containing sensitive files that is accessible to everyone

D. A newly created empty site

Correct Answer: C

Explanation: Sensitive information combined with broad permissions represents a significant oversharing risk.


Question 8

How does Data Access Governance complement Microsoft Purview?

A. Both products only classify documents.

B. Data Access Governance focuses on permissions, while Purview focuses on data protection and governance.

C. They perform identical functions.

D. Purview replaces SharePoint permissions.

Correct Answer: B

Explanation: Purview governs and protects data, while Data Access Governance helps administrators understand who has access to that data.


Question 9

Which action should an administrator consider after identifying an overshared SharePoint site?

A. Delete all documents immediately.

B. Disable Microsoft 365 Copilot.

C. Purchase additional SharePoint storage.

D. Review and reduce unnecessary permissions.

Correct Answer: D

Explanation: The appropriate response is to evaluate existing permissions and remove excessive or unnecessary access while maintaining business needs.


Question 10

Which statement about Microsoft 365 Copilot and Data Access Governance is true?

A. Data Access Governance prevents all Copilot responses.

B. Copilot bypasses SharePoint permissions when generating answers.

C. Data Access Governance helps reduce the risk of Copilot surfacing overshared information by identifying excessive permissions.

D. Copilot encrypts all SharePoint documents before using them.

Correct Answer: C

Explanation: By identifying and remediating overshared permissions, Data Access Governance helps ensure Copilot only surfaces information that users are appropriately authorized to access.


Go to the AB-900 Exam Prep Hub main page

Identify the tools to troubleshoot oversharing in an organization (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Identify the tools to troubleshoot oversharing in an organization


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

This topic measures your understanding of how Microsoft 365 administrators can identify, investigate, and reduce oversharing of organizational data. As organizations adopt Microsoft 365 Copilot and AI-powered experiences, ensuring that users only have access to the information they should see becomes increasingly important.

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand:

  • What oversharing is
  • Why oversharing is a security and governance concern
  • The Microsoft tools used to identify and troubleshoot oversharing
  • How these tools work together
  • Best practices for reducing oversharing before and after deploying Microsoft 365 Copilot

You are not expected to configure these tools in detail, but you should know their purpose and common use cases.


What Is Oversharing?

Oversharing occurs when users have access to files, folders, emails, or sites that they do not need to perform their job.

Because Microsoft 365 Copilot respects existing Microsoft 365 permissions, users can potentially discover information through Copilot that they already have permission to access—even if that access was unintentionally granted.

For example:

  • A SharePoint site allows “Everyone except external users” access.
  • A confidential HR folder inherits overly broad permissions.
  • A OneDrive file is shared organization-wide instead of with a specific team.
  • A Teams site contains sensitive documents accessible by unnecessary members.

Copilot does not bypass security—it simply surfaces information users are already authorized to access.


Why Troubleshooting Oversharing Is Important

Oversharing can lead to:

  • Exposure of confidential business information
  • Disclosure of financial data
  • HR privacy issues
  • Intellectual property leaks
  • Increased insider risk
  • Compliance violations
  • Unintentional exposure through Microsoft 365 Copilot

The goal is to identify excessive permissions before sensitive information is exposed.


Common Causes of Oversharing

Oversharing often results from:

  • Incorrect SharePoint permissions
  • Excessive sharing links
  • Broken inheritance
  • Organization-wide sharing
  • Large Microsoft 365 Groups
  • Incorrect Teams membership
  • Overly permissive OneDrive sharing
  • Legacy permissions that were never reviewed
  • Users manually sharing files without understanding permissions

Microsoft Tools Used to Troubleshoot Oversharing

Microsoft provides several complementary tools.


1. SharePoint Advanced Management

One of the primary tools for identifying oversharing is SharePoint Advanced Management.

It helps administrators:

  • Discover overshared sites
  • Identify risky permissions
  • Detect excessive sharing
  • Review permission inheritance
  • Monitor external sharing

Administrators can prioritize remediation efforts before deploying Copilot broadly.


2. SharePoint Site Permissions

Administrators should review:

  • Site Owners
  • Site Members
  • Site Visitors

Questions to ask include:

  • Does everyone need access?
  • Are external users still required?
  • Are permissions inherited correctly?
  • Are there unnecessary site members?

3. Site Access Reviews

Regular permission reviews help identify:

  • Inactive users
  • Former employees
  • Contractors
  • Oversized groups
  • Outdated access

Periodic reviews significantly reduce oversharing.


4. Microsoft Purview Data Security Posture Management (DSPM) for AI

DSPM for AI helps organizations understand AI-related security risks.

It can identify:

  • Sensitive data exposed to Copilot
  • AI usage patterns
  • High-risk data locations
  • Overshared sensitive files
  • Permission-related risks

DSPM combines AI activity with data classification to prioritize remediation.


5. Microsoft Purview Data Explorer

Data Explorer provides visibility into where sensitive information exists.

Administrators can discover:

  • Credit card numbers
  • Passport numbers
  • Financial records
  • Health information
  • Confidential documents

Once sensitive data is identified, administrators can determine whether it is overshared.


6. Microsoft Purview Activity Explorer

Activity Explorer helps investigate how sensitive content is being used.

It displays activities such as:

  • File sharing
  • Downloads
  • Label application
  • Label removal
  • DLP events

This helps identify whether overshared content is actively being accessed.


7. Microsoft Purview Content Search

Content Search helps locate:

  • Emails
  • Documents
  • Teams conversations
  • SharePoint files
  • OneDrive files

Investigators can search for sensitive information and determine whether it resides in overshared locations.


8. Microsoft Purview Audit

Audit logs provide visibility into user actions.

Examples include:

  • File viewed
  • File shared
  • Permission changed
  • Link created
  • Link removed
  • Site membership changed

Audit records help determine:

  • Who shared a document
  • When sharing occurred
  • Which users accessed the content

9. Microsoft Purview Data Loss Prevention (DLP)

Although DLP does not directly identify oversharing, it helps prevent sensitive information from leaving approved locations.

DLP policies can:

  • Block sharing
  • Warn users
  • Prevent uploads
  • Restrict downloads
  • Notify administrators

DLP reduces the impact of accidental oversharing.


10. Microsoft Purview Information Protection

Sensitivity labels classify and protect information.

Labels can:

  • Encrypt documents
  • Restrict access
  • Prevent forwarding
  • Apply visual markings
  • Require authentication

Even if a document is accidentally shared, encryption can prevent unauthorized access.


11. Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps provides insight into cloud file sharing.

Administrators can identify:

  • Publicly shared files
  • Anonymous links
  • External sharing
  • Risky user behavior
  • Unusual downloads

It helps detect cloud-based oversharing risks.


12. Microsoft Entra ID

Microsoft Entra ID helps troubleshoot identity-related oversharing by reviewing:

  • Group memberships
  • Role assignments
  • Dynamic groups
  • Guest users
  • External identities

Sometimes oversharing occurs because users belong to inappropriate security groups.


Reviewing Sharing Links

Sharing links are a common source of oversharing.

Administrators should review whether links are:

  • Anyone links
  • Organization links
  • Specific people links
  • Existing access links

Generally:

  • “Specific people” links are the most restrictive.
  • “Anyone” links present the greatest oversharing risk.

Reviewing Permission Inheritance

SharePoint uses permission inheritance.

A folder may inherit permissions from:

  • Site
  • Library
  • Parent folder

Broken inheritance can accidentally expose sensitive information.

Administrators should verify whether:

  • Inheritance is appropriate
  • Unique permissions are necessary
  • Sensitive folders have restricted access

Using Sensitivity Labels to Reduce Oversharing

Sensitivity labels provide another layer of protection.

Examples include:

  • Public
  • General
  • Confidential
  • Highly Confidential

Labels may automatically:

  • Encrypt content
  • Restrict downloads
  • Prevent printing
  • Block copying
  • Limit sharing

Copilot respects these protections.


Using Audit Logs During Investigations

If oversharing is suspected, administrators often review audit logs.

Audit logs answer questions such as:

  • Who shared the file?
  • When was it shared?
  • Was an anonymous link created?
  • Who opened the document?
  • Was the file downloaded?
  • Were permissions modified?

This information is critical during investigations.


Relationship to Microsoft 365 Copilot

Copilot does not ignore Microsoft 365 security.

Instead, it:

  • Uses Microsoft Graph to retrieve content
  • Honors Microsoft 365 permissions
  • Respects sensitivity labels
  • Honors encryption
  • Respects DLP protections
  • Uses existing access controls

If permissions are too broad, Copilot can surface information to users who already have that access.

Therefore, reducing oversharing before deployment is considered a best practice.


Typical Oversharing Investigation Workflow

A common workflow includes:

  1. Identify sensitive data using Data Explorer.
  2. Review AI exposure using DSPM for AI.
  3. Examine permissions in SharePoint.
  4. Review sharing links.
  5. Check Audit logs.
  6. Investigate user activity in Activity Explorer.
  7. Restrict permissions where necessary.
  8. Apply sensitivity labels.
  9. Implement DLP policies.
  10. Continue monitoring for future risks.

Best Practices

Organizations should:

  • Review SharePoint permissions regularly.
  • Remove unnecessary access.
  • Limit organization-wide sharing.
  • Use “Specific people” sharing links whenever possible.
  • Classify sensitive information.
  • Apply sensitivity labels.
  • Implement DLP policies.
  • Monitor audit logs.
  • Conduct periodic access reviews.
  • Review oversharing before enabling Microsoft 365 Copilot organization-wide.

Key Exam Tips

Remember these important points for the AB-900 exam:

  • Oversharing occurs when users have unnecessary access to data.
  • Microsoft 365 Copilot respects existing permissions—it does not bypass security.
  • SharePoint Advanced Management helps identify overshared sites and permissions.
  • Microsoft Purview DSPM for AI helps identify AI-related exposure risks.
  • Data Explorer identifies where sensitive information resides.
  • Activity Explorer shows how sensitive data is being used.
  • Audit logs reveal sharing and permission changes.
  • Sensitivity labels and DLP help reduce the risks associated with oversharing.
  • Regular permission reviews are one of the most effective ways to prevent oversharing.

Practice Exam Questions

Question 1

Which Microsoft solution is specifically designed to help administrators identify overshared SharePoint sites before deploying Microsoft 365 Copilot?

A. Microsoft Defender Antivirus

B. SharePoint Advanced Management

C. Exchange Online Protection

D. Microsoft Intune

Correct Answer: B

Explanation: SharePoint Advanced Management provides visibility into oversharing risks, site permissions, and excessive access, helping organizations prepare for AI deployments.


Question 2

Why is oversharing considered a concern when using Microsoft 365 Copilot?

A. Copilot ignores Microsoft 365 permissions.

B. Copilot automatically shares documents externally.

C. Copilot can surface information that users already have permission to access.

D. Copilot disables sensitivity labels.

Correct Answer: C

Explanation: Copilot respects existing Microsoft 365 permissions. If permissions are overly broad, users may discover sensitive information they technically have access to but should not.


Question 3

Which Microsoft Purview feature helps identify where sensitive information such as credit card numbers and passport numbers is stored?

A. Compliance Manager

B. Insider Risk Management

C. Data Explorer

D. Communication Compliance

Correct Answer: C

Explanation: Data Explorer provides visibility into the location and distribution of sensitive information across Microsoft 365.


Question 4

An administrator wants to determine who shared a confidential document and when it was shared. Which tool should they use?

A. Microsoft Purview Audit

B. Microsoft Planner

C. Microsoft Viva Insights

D. Microsoft Bookings

Correct Answer: A

Explanation: Audit logs record sharing events, permission changes, and other user activities, making them essential for investigations.


Question 5

Which type of SharePoint sharing link generally presents the greatest oversharing risk?

A. Existing access

B. Specific people

C. Organization

D. Anyone

Correct Answer: D

Explanation: “Anyone” links allow access without authentication (unless restricted by policy), making them the highest-risk sharing option.


Question 6

Which Microsoft Purview solution helps administrators understand AI-related exposure risks and overshared sensitive information?

A. Data Security Posture Management (DSPM) for AI

B. Compliance Manager

C. eDiscovery

D. Message Encryption

Correct Answer: A

Explanation: DSPM for AI identifies sensitive data exposure, AI usage, and risks associated with Microsoft 365 Copilot and other AI applications.


Question 7

Which Microsoft Purview feature helps administrators review how sensitive files have been shared, downloaded, or labeled?

A. Data Lifecycle Management

B. Activity Explorer

C. Content Search

D. Records Management

Correct Answer: B

Explanation: Activity Explorer provides visibility into user activities involving sensitive content, including sharing, labeling, and DLP events.


Question 8

What is one effective way to reduce oversharing in SharePoint?

A. Increase anonymous sharing.

B. Remove all sensitivity labels.

C. Grant every employee site owner permissions.

D. Perform regular permission and access reviews.

Correct Answer: D

Explanation: Periodic permission reviews help identify unnecessary access, outdated memberships, and excessive permissions before they become security risks.


Question 9

Which statement correctly describes Microsoft 365 Copilot?

A. It bypasses Microsoft Purview protections.

B. It ignores SharePoint permissions.

C. It respects existing Microsoft 365 permissions and security controls.

D. It automatically encrypts all documents.

Correct Answer: C

Explanation: Copilot only accesses content that users are already authorized to view and honors permissions, sensitivity labels, encryption, and other Microsoft 365 security controls.


Question 10

Which combination of tools provides the most complete approach to troubleshooting oversharing?

A. Microsoft Paint and Notepad

B. Microsoft Purview Audit, Data Explorer, Activity Explorer, DSPM for AI, and SharePoint Advanced Management

C. Microsoft Teams and Outlook only

D. Microsoft Excel and Word

Correct Answer: B

Explanation: These tools complement one another by identifying sensitive data, monitoring activity, reviewing AI exposure, auditing sharing events, and analyzing SharePoint permissions, enabling administrators to effectively investigate and remediate oversharing risks.


Go to the AB-900 Exam Prep Hub main page

Search for files and emails by using Content Search in Microsoft Purview eDiscovery (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Search for files and emails by using Content Search in Microsoft Purview eDiscovery


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

This topic measures your understanding of how administrators and compliance professionals use Microsoft Purview eDiscovery Content Search to locate emails, documents, Teams conversations, and other Microsoft 365 content during investigations, audits, legal matters, and compliance activities.

For the AB-900 exam, you are not expected to become an eDiscovery specialist. Instead, you should understand:

  • The purpose of Content Search
  • What types of content can be searched
  • How searches work
  • Common search criteria
  • Permissions required
  • Typical use cases
  • How Content Search supports Microsoft 365 Copilot governance

What Is Microsoft Purview eDiscovery?

Microsoft Purview eDiscovery is a Microsoft Purview solution that helps organizations identify, preserve, search, review, and export electronically stored information (ESI).

It is commonly used for:

  • Internal investigations
  • Legal discovery
  • Regulatory compliance
  • Human resources investigations
  • Security investigations
  • Privacy requests
  • Audits

One of the most frequently used capabilities within eDiscovery is Content Search.


What Is Content Search?

Content Search allows administrators and investigators to search across Microsoft 365 for specific information without manually checking each user’s mailbox or files.

Instead of searching one mailbox at a time, Content Search can simultaneously search:

  • Exchange Online mailboxes
  • SharePoint Online sites
  • OneDrive accounts
  • Microsoft Teams messages
  • Viva Engage (Yammer) messages (where supported)
  • Microsoft 365 Groups
  • Copilot-related stored content (through underlying Microsoft 365 data)

Think of it as an enterprise-wide search engine designed for compliance investigations.


Why Organizations Use Content Search

Organizations perform Content Searches to:

  • Locate specific emails
  • Find confidential documents
  • Investigate insider threats
  • Respond to legal requests
  • Prepare evidence for court
  • Support compliance audits
  • Investigate data leaks
  • Review suspicious activity
  • Locate files related to AI-generated work

Where Content Search Is Located

Content Search is available in the Microsoft Purview portal under:

Microsoft Purview → eDiscovery

Administrators can:

  • Create searches
  • Edit searches
  • Run searches
  • Preview results
  • Export results (with appropriate permissions)

Content That Can Be Searched

Content Search supports many Microsoft 365 workloads.

Examples include:

Exchange Online

Searches include:

  • Emails
  • Calendar items
  • Contacts
  • Tasks
  • Attachments

Example:

Find every email containing a specific customer name.


SharePoint Online

Can search:

  • Documents
  • PDFs
  • Word files
  • Excel files
  • PowerPoint presentations
  • Lists

Example:

Locate every document containing a confidential project code.


OneDrive for Business

Searches users’ personal work files.

Example:

Find documents uploaded by an employee before they resigned.


Microsoft Teams

Can search:

  • Chat messages
  • Channel conversations
  • Shared files

Example:

Find Teams conversations discussing a confidential acquisition.


Microsoft 365 Groups

Includes:

  • Group mailboxes
  • Shared documents

How Content Search Works

A Content Search generally follows these steps.

Step 1

Create a search.


Step 2

Select locations.

Examples:

  • Specific mailbox
  • All mailboxes
  • OneDrive sites
  • SharePoint sites
  • Teams

Step 3

Define search conditions.

Examples:

  • Keywords
  • Dates
  • Senders
  • Recipients
  • File types

Step 4

Run the search.

Microsoft indexes the selected content and returns matching results.


Step 5

Review results.

Administrators can:

  • View statistics
  • Preview items
  • Refine search criteria

Step 6

Export results if necessary.

This is common during legal investigations.


Search Locations

Content Search allows searches across:

  • Individual mailboxes
  • Shared mailboxes
  • Distribution groups
  • SharePoint sites
  • OneDrive accounts
  • Microsoft Teams
  • Specific users
  • Entire organization

Common Search Criteria

Administrators can filter searches using many conditions.

Keywords

Search for:

  • Customer names
  • Project names
  • Product codes
  • Sensitive terms

Example:

Confidential

Sender

Locate messages sent by:

john@contoso.com

Recipient

Locate emails received by:

finance@contoso.com

Date Range

Example:

January 1 through March 31.

Useful during investigations.


File Type

Examples:

  • PDF
  • DOCX
  • XLSX
  • PPTX

File Name

Search for a specific document.

Example:

Budget2026.xlsx

Sensitive Information

When combined with Microsoft Purview classifications, administrators can search for:

  • Credit card numbers
  • Social Security numbers
  • Passport numbers
  • Financial records

Keyword Query Language (KQL)

Content Search uses Keyword Query Language (KQL).

Administrators can build more advanced searches.

Examples include:

  • AND
  • OR
  • NOT
  • Parentheses
  • Property filters

Example:

Project AND Budget

Example:

Budget OR Forecast

Example:

Confidential NOT Draft

The AB-900 exam only expects a basic understanding that KQL enables more precise searches.


Search Results

After a search completes, administrators receive:

  • Number of matching items
  • Number of locations searched
  • Total estimated size
  • Search statistics
  • Preview of matching items

The search does not automatically change or delete content.


Previewing Results

Before exporting data, investigators can preview:

  • Emails
  • Documents
  • Teams conversations

Previewing helps determine whether additional filtering is needed.


Exporting Results

Authorized users can export search results.

Exports may include:

  • PST files
  • Native Office documents
  • PDFs
  • Metadata
  • Reports

Exporting is commonly used for:

  • Courts
  • Attorneys
  • Regulatory agencies
  • Internal investigations

Permissions Required

Not every administrator can perform Content Searches.

Organizations typically assign permissions using Microsoft Purview role groups.

Common roles include:

  • eDiscovery Manager
  • eDiscovery Administrator
  • Compliance Administrator

Least privilege should always be followed.


Content Search vs eDiscovery Cases

These concepts are related but different.

Content SearcheDiscovery Case
Searches contentManages investigations
Can be run independentlyOrganizes legal matters
Finds informationStores searches, holds, reviewers, exports
Useful for quick investigationsUseful for complete legal workflows

Think of Content Search as one tool inside the broader eDiscovery process.


How Content Search Supports Microsoft 365 Copilot

Microsoft 365 Copilot retrieves information users already have permission to access.

If sensitive information exists within Microsoft 365:

  • Copilot may surface it to authorized users.
  • Administrators can use Content Search to identify where sensitive information is stored.
  • This helps organizations improve governance before deploying AI widely.

Examples include:

  • Confidential HR files
  • Financial reports
  • Intellectual property
  • Legal documents

Relationship with Other Microsoft Purview Features

Content Search works alongside many Purview capabilities.

Sensitivity Labels

Search labeled documents.


Data Loss Prevention (DLP)

Investigate DLP incidents.


Retention Policies

Locate retained content.


Insider Risk Management

Search content involved in investigations.


Audit

Correlate search results with user activities.


eDiscovery Premium

Use Content Search as part of advanced legal investigations.


Best Practices

Microsoft recommends that organizations:

  • Search only necessary locations.
  • Use descriptive search names.
  • Apply precise filters.
  • Limit access using least privilege.
  • Preview results before exporting.
  • Protect exported evidence.
  • Maintain audit logs.
  • Regularly review permissions.
  • Use Content Search together with retention and sensitivity labels.
  • Govern sensitive data before deploying Microsoft 365 Copilot broadly.

Key Exam Tips

Remember these important points for the AB-900 exam:

  • Content Search is part of Microsoft Purview eDiscovery.
  • It searches across Microsoft 365 services from one interface.
  • It can search Exchange, SharePoint, OneDrive, Teams, and other supported workloads.
  • Searches can be filtered by keywords, users, dates, file types, and other properties.
  • Search results can be previewed before export.
  • Appropriate permissions are required to perform searches.
  • Content Search helps organizations investigate compliance, legal, and security incidents.
  • It supports Microsoft 365 Copilot governance by helping organizations identify where sensitive information exists.

Practice Exam Questions

Question 1

An administrator needs to locate every email containing the phrase “Quarterly Budget” across the organization. Which Microsoft Purview feature should they use?

A. Communication Compliance

B. Content Search in eDiscovery

C. Insider Risk Management

D. Compliance Manager

Correct Answer: B

Explanation: Content Search enables administrators to search mailboxes, SharePoint sites, OneDrive, Teams, and other Microsoft 365 locations for keywords and other search criteria.


Question 2

Which Microsoft 365 workload can be searched by Microsoft Purview Content Search?

A. Exchange Online

B. Microsoft Teams

C. SharePoint Online

D. All of the above

Correct Answer: D

Explanation: Content Search supports multiple Microsoft 365 workloads, including Exchange Online, SharePoint Online, OneDrive, Teams, Microsoft 365 Groups, and more.


Question 3

Before exporting search results, what is the recommended action?

A. Delete duplicate items.

B. Apply a retention policy.

C. Preview the search results.

D. Disable auditing.

Correct Answer: C

Explanation: Previewing results helps verify that the search returned the intended items before exporting data.


Question 4

What is the primary purpose of Microsoft Purview Content Search?

A. Encrypt documents automatically.

B. Create sensitivity labels.

C. Monitor endpoint devices.

D. Locate content across Microsoft 365 for investigations and compliance.

Correct Answer: D

Explanation: Content Search is designed to find emails, files, chats, and other content across Microsoft 365 to support investigations, audits, and legal discovery.


Question 5

Which search criterion could an administrator use to narrow Content Search results?

A. Sender

B. File type

C. Date range

D. All of the above

Correct Answer: D

Explanation: Administrators can filter searches by numerous criteria, including sender, recipient, keywords, dates, and file types.


Question 6

Why is Content Search important for Microsoft 365 Copilot governance?

A. It trains Copilot models.

B. It identifies where sensitive information is stored so organizations can better govern AI access.

C. It automatically blocks Copilot prompts.

D. It creates Copilot licenses.

Correct Answer: B

Explanation: Understanding where sensitive information resides helps organizations apply appropriate governance before broad Copilot deployment.


Question 7

Which language provides advanced query capabilities for Content Search?

A. SQL

B. PowerShell

C. XPath

D. Keyword Query Language (KQL)

Correct Answer: D

Explanation: Content Search uses KQL to build advanced searches using keywords, logical operators, and property filters.


Question 8

Which statement about Content Search permissions is correct?

A. Every Microsoft 365 user can run organization-wide searches.

B. Only Global Administrators can perform Content Searches.

C. Appropriate Microsoft Purview roles are required to perform Content Searches.

D. Content Search requires no administrative permissions.

Correct Answer: C

Explanation: Organizations assign eDiscovery and compliance roles to authorized users who need to perform searches.


Question 9

A compliance investigator wants to search only documents stored in employees’ personal cloud storage. Which location should be selected?

A. Microsoft Teams

B. OneDrive for Business

C. Exchange Online

D. Microsoft Entra ID

Correct Answer: B

Explanation: OneDrive for Business stores users’ personal work files and can be targeted independently during a Content Search.


Question 10

Which statement best describes Microsoft Purview Content Search?

A. It permanently deletes search results after completion.

B. It automatically applies retention labels to matching items.

C. It searches Microsoft 365 content and allows authorized users to review and export matching results.

D. It encrypts all files matching the search query.

Correct Answer: C

Explanation: Content Search is a discovery tool that locates content across Microsoft 365, allowing investigators to preview and export results without modifying the original data.


Go to the AB-900 Exam Prep Hub main page

Discover and manage AI activity by using DSPM for AI (Part 2) (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Discover and manage AI activity by using DSPM for AI


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

In Part 1, you learned how Microsoft Purview Data Security Posture Management (DSPM) for AI helps organizations discover AI activity, identify sensitive data exposure, detect oversharing, and provide visibility into how AI interacts with Microsoft 365 data.

This section (Part 2) focuses on how DSPM for AI helps administrators manage AI-related risks, integrates with other Microsoft security and compliance services, and supports secure AI adoption.


Security Recommendations Generated by DSPM for AI

One of DSPM for AI’s most valuable capabilities is providing actionable security recommendations rather than simply identifying problems.

After analyzing an organization’s AI environment, DSPM highlights areas that should be improved to reduce the likelihood of accidental data exposure or compliance violations.

Examples of recommendations include:

  • Reduce excessive SharePoint permissions.
  • Apply sensitivity labels to unclassified confidential files.
  • Configure Data Loss Prevention (DLP) policies.
  • Limit external sharing.
  • Protect highly confidential document libraries.
  • Enable auditing for AI-related activities.
  • Improve data governance before expanding AI deployments.

These recommendations help administrators prioritize improvements based on potential business impact and security risk.


Risk Prioritization

Not every security finding represents the same level of risk.

DSPM helps prioritize remediation efforts by evaluating factors such as:

  • Amount of sensitive data exposed
  • Number of users with access
  • Business importance of the data
  • Existing protection mechanisms
  • AI usage patterns
  • Permission inheritance
  • Regulatory implications

This enables administrators to address the highest-risk issues first.

For example:

RiskPriority
Public access to executive financial reportsHigh
Sensitive HR documents lacking labelsHigh
Marketing presentations shared internallyMedium
Public training documentsLow

Discovering AI-Related Data Exposure

Organizations often ask:

“If we enable Microsoft 365 Copilot today, what sensitive information could users potentially discover?”

DSPM helps answer this question.

It analyzes:

  • Existing permissions
  • Data classifications
  • Sharing configurations
  • Microsoft Graph relationships
  • Collaboration patterns

This provides insight into which sensitive data could become more discoverable through AI-assisted searches and summaries.

Remember:

Copilot does not bypass security permissions. It only accesses information that the signed-in user is already authorized to access. DSPM helps identify situations where those permissions may already be too broad.


Remediation Recommendations

After identifying risks, DSPM recommends remediation steps.

Common recommendations include:

Reduce Oversharing

Examples include:

  • Remove unnecessary SharePoint permissions.
  • Restrict Microsoft Teams membership.
  • Remove Everyone access.
  • Limit guest sharing.

Improve Data Classification

Examples include:

  • Apply sensitivity labels.
  • Enable automatic labeling.
  • Use trainable classifiers.
  • Configure sensitive information types.

Better classification improves downstream protections across Microsoft Purview.


Strengthen Data Protection Policies

DSPM may recommend:

  • Creating DLP policies
  • Encrypting confidential documents
  • Restricting downloads
  • Blocking external sharing
  • Applying retention labels

Review AI Access

Administrators may decide to:

  • Limit AI rollout to selected departments
  • Review permissions before enabling Copilot broadly
  • Reduce access to legacy repositories
  • Remove stale user accounts

Integration with Microsoft Purview

DSPM for AI does not operate as an isolated product.

Instead, it complements several Microsoft Purview solutions.

Understanding these relationships is important for the AB-900 exam.


Microsoft Purview Information Protection

Information Protection classifies and protects data.

DSPM benefits from these classifications.

For example:

A document labeled:

  • Highly Confidential
  • Internal Only
  • Financial
  • Legal

helps DSPM understand the sensitivity of AI-accessible content.

Without labels, DSPM has less context when evaluating risk.


Microsoft Purview Data Loss Prevention (DLP)

DLP prevents sensitive information from being shared inappropriately.

DSPM identifies potential risks.

DLP helps enforce policies to prevent those risks from becoming incidents.

Example workflow:

  1. DSPM discovers sensitive payroll files.
  2. DLP prevents external sharing.
  3. Organization reduces AI-related exposure.

Microsoft Purview Insider Risk Management

DSPM identifies risky data exposure.

Insider Risk Management identifies risky user behavior.

Together they help answer two different questions:

DSPM asks:

“What sensitive data could AI access?”

Insider Risk asks:

“Is someone attempting to misuse sensitive data?”

These products complement one another.


Microsoft Purview Activity Explorer

Activity Explorer provides visibility into user interactions with sensitive information.

DSPM can use Activity Explorer insights to better understand:

  • Sensitive file access
  • Label usage
  • DLP events
  • Data movement

Administrators gain a clearer understanding of how protected information is being used across Microsoft 365.


Microsoft Purview Compliance Manager

Compliance Manager focuses on regulatory compliance.

DSPM focuses on AI data governance.

Together they help organizations:

  • Reduce compliance risk
  • Improve governance
  • Meet regulatory requirements
  • Protect sensitive information used by AI

Microsoft Defender

Microsoft Defender protects identities, endpoints, applications, and cloud resources.

DSPM complements Defender by focusing specifically on AI-related data risks.

Examples:

Microsoft Defender detects:

  • Malware
  • Credential theft
  • Phishing
  • Device compromise

DSPM identifies:

  • Overshared files
  • AI exposure
  • Sensitive data visibility
  • Permission risks

AI Governance Dashboard

DSPM provides dashboards that help administrators understand their organization’s AI posture.

Typical dashboard information includes:

  • AI adoption trends
  • Sensitive data exposure
  • High-risk repositories
  • Oversharing statistics
  • AI application inventory
  • Policy recommendations
  • Governance posture

Rather than investigating individual files, administrators receive a broad organizational view.


Discovering AI Applications

DSPM helps organizations understand:

  • Which AI tools are in use
  • Which departments use them
  • Adoption trends
  • AI usage over time

Examples include:

  • Microsoft 365 Copilot
  • Microsoft Copilot Chat
  • Supported third-party AI services

This visibility helps organizations establish AI governance policies.


Investigating AI Risks

Administrators typically investigate findings by asking questions such as:

  • Which sensitive files are accessible?
  • Who has access?
  • Why do they have access?
  • Is the data properly labeled?
  • Are permissions appropriate?
  • Is the data externally shared?
  • Should additional protection be applied?

DSPM helps surface this information so administrators can make informed decisions.


Typical Investigation Workflow

A simplified investigation might follow these steps:

Step 1

DSPM identifies an overshared SharePoint site.

Step 2

Administrator reviews permissions.

Step 3

Sensitive files are discovered.

Step 4

Sensitivity labels are applied.

Step 5

Permissions are reduced.

Step 6

DLP policies are enabled.

Step 7

Risk is reduced before broader Copilot deployment.


Best Practices

Organizations implementing Microsoft 365 Copilot should follow several best practices.

Review Permissions Before AI Rollout

Avoid enabling Copilot before understanding existing permissions.


Classify Sensitive Data

Use Microsoft Purview Information Protection to classify important documents.


Apply Least Privilege

Users should only have access to information required for their job.


Reduce Oversharing

Review:

  • SharePoint permissions
  • Teams memberships
  • OneDrive sharing
  • External sharing

Enable DLP

Prevent accidental sharing of confidential information.


Monitor AI Adoption

Understand:

  • Who uses AI
  • Which departments use AI
  • What information AI accesses

Regularly Review Recommendations

DSPM continuously evaluates the environment.

Administrators should regularly review new recommendations as data, permissions, and AI usage evolve.


Licensing Considerations

For the AB-900 exam, you are not expected to memorize licensing details, as licensing can change over time.

However, you should understand these general principles:

  • DSPM for AI is part of the Microsoft Purview family.
  • Advanced governance and AI security capabilities may require appropriate Microsoft licensing.
  • Organizations should verify current licensing requirements before deployment.

Common Exam Scenarios

You may encounter questions like:

Scenario 1

An organization wants to know whether Microsoft 365 Copilot could expose confidential HR documents because of existing permissions.

Relevant technology:

Microsoft Purview DSPM for AI


Scenario 2

Administrators want recommendations to reduce AI-related data exposure before deploying Copilot.

Relevant technology:

Microsoft Purview DSPM for AI


Scenario 3

Security administrators want visibility into AI adoption across Microsoft 365.

Relevant technology:

Microsoft Purview DSPM for AI


Scenario 4

Administrators want to identify overshared SharePoint sites that AI could access.

Relevant technology:

Microsoft Purview DSPM for AI


Scenario 5

An organization wants to understand where sensitive information may be exposed through AI.

Relevant technology:

Microsoft Purview DSPM for AI


Common Misconceptions

Misconception 1

DSPM blocks AI prompts.

Incorrect.

DSPM primarily discovers, assesses, and helps reduce AI-related data risks. It is not a prompt-filtering or AI-blocking solution.


Misconception 2

Copilot ignores permissions.

Incorrect.

Copilot always respects the signed-in user’s existing Microsoft 365 permissions.


Misconception 3

DSPM replaces Microsoft Purview DLP.

Incorrect.

DSPM identifies risks, while DLP enforces policies that help prevent inappropriate sharing of sensitive data.


Misconception 4

DSPM replaces Microsoft Defender.

Incorrect.

Defender focuses on threats and attacks, whereas DSPM focuses on AI-related data exposure and governance.


Misconception 5

DSPM automatically fixes security issues.

Incorrect.

DSPM provides visibility, recommendations, and guidance. Administrators remain responsible for implementing changes such as adjusting permissions, applying labels, or configuring policies.


AB-900 Exam Tips

Focus on these key concepts:

  • Microsoft Purview DSPM for AI is an AI governance and visibility solution.
  • It helps organizations discover AI usage, identify sensitive data exposure, and reduce AI-related risks.
  • DSPM does not bypass or modify Microsoft 365 permissions.
  • It works alongside Information Protection, DLP, Insider Risk Management, Activity Explorer, Compliance Manager, and Microsoft Defender.
  • One of its primary goals is to identify oversharing before it becomes a business risk.
  • DSPM provides recommendations, not automatic remediation.
  • It supports organizations throughout the AI adoption lifecycle by helping them continuously improve their security posture.

Chapter Summary

Microsoft Purview DSPM for AI enables organizations to adopt AI confidently by providing visibility into how AI interacts with organizational data. It discovers AI usage, inventories AI applications, identifies oversharing, evaluates sensitive data exposure, and recommends actions to strengthen governance.

Rather than replacing existing Microsoft Purview or Microsoft Defender capabilities, DSPM for AI enhances them by adding AI-specific insights. It integrates with Information Protection, Data Loss Prevention, Insider Risk Management, Activity Explorer, Compliance Manager, and Microsoft Defender to create a comprehensive approach to AI governance.

For the AB-900 exam, remember that DSPM for AI is fundamentally about discovering, assessing, and managing AI-related data risks. It helps administrators understand where AI could expose sensitive information due to existing permissions and governance gaps, enabling organizations to improve their security posture before and during Microsoft 365 Copilot deployment.


Practice Exam Questions


Question 1

A company plans to deploy Microsoft 365 Copilot across all departments. Before deployment, administrators want to determine whether confidential documents are overly accessible due to existing SharePoint permissions.

Which Microsoft solution should they use?

A. Microsoft Entra Domain Services

B. Microsoft Defender for Endpoint

C. Microsoft Intune

D. Microsoft Purview Data Security Posture Management (DSPM) for AI

Correct Answer: D

Explanation

Microsoft Purview DSPM for AI helps organizations discover overshared content, evaluate AI-related data exposure, and identify permission risks before deploying AI solutions such as Microsoft 365 Copilot.

  • A is correct because DSPM for AI analyzes permissions and identifies AI-related security risks.
  • B is incorrect because Defender for Endpoint protects devices.
  • C is incorrect because Intune manages devices and applications.
  • D is incorrect because Entra Domain Services provides managed domain services rather than AI governance.

Question 2

An administrator wants to understand which departments are actively using Microsoft 365 Copilot and other approved AI applications.

Which capability best addresses this requirement?

A. Microsoft Purview Information Protection

B. Microsoft Purview DSPM for AI

C. Microsoft Defender for Cloud Apps

D. Microsoft Entra Conditional Access

Correct Answer: B

Explanation

DSPM for AI provides visibility into AI adoption, AI application inventory, and usage trends across the organization.

  • B is correct because DSPM for AI discovers AI activity and AI adoption.
  • A classifies and protects data.
  • C monitors cloud applications but is not specifically designed for AI governance.
  • D controls authentication conditions.

Question 3

Which statement best describes how Microsoft 365 Copilot accesses organizational data?

A. It bypasses Microsoft 365 permissions when generating responses.

B. It can access all documents stored in Microsoft 365 regardless of permissions.

C. It only accesses content the signed-in user is already authorized to access.

D. It only accesses files created after Copilot was enabled.

Correct Answer: C

Explanation

Copilot respects existing Microsoft 365 permissions. It never bypasses authorization.

  • C is correct because Copilot only retrieves content the current user can already access.
  • A and B incorrectly imply that Copilot ignores permissions.
  • D is incorrect because file creation date is irrelevant.

Question 4

What is the primary purpose of Microsoft Purview DSPM for AI?

A. Prevent all AI-generated responses

B. Replace Microsoft Defender

C. Automatically encrypt all Microsoft 365 data

D. Discover AI activity and identify AI-related data risks

Correct Answer: D

Explanation

DSPM for AI provides visibility into AI usage and helps identify governance and security risks.

  • D is correct because discovering AI activity and assessing AI-related risks are its primary objectives.
  • A, B, and C describe capabilities DSPM does not provide.

Question 5

An organization discovers that hundreds of employees can access executive financial reports because of inherited SharePoint permissions.

What type of risk has DSPM for AI identified?

A. Malware infection

B. Oversharing

C. Identity synchronization failure

D. Device compliance failure

Correct Answer: B

Explanation

Oversharing occurs when users have broader access to information than intended.

  • B is correct because excessive permissions increase AI-related exposure.
  • A, C, and D are unrelated to data governance.

Question 6

Which Microsoft technology provides much of the contextual relationship information that helps DSPM for AI understand user access to Microsoft 365 content?

A. Microsoft SQL Server

B. Microsoft Defender XDR

C. Microsoft Graph

D. Azure Kubernetes Service

Correct Answer: C

Explanation

Microsoft Graph provides relationships between users, files, emails, Teams, SharePoint, and other Microsoft 365 resources.

  • C is correct because DSPM uses Microsoft Graph signals to understand data access.
  • The remaining options do not provide organizational relationship data.

Question 7

Which Microsoft Purview solution works alongside DSPM for AI by preventing inappropriate sharing of sensitive information?

A. Microsoft Purview Data Loss Prevention (DLP)

B. Microsoft Entra ID Protection

C. Microsoft Intune

D. Windows Autopilot

Correct Answer: A

Explanation

DLP enforces policies that prevent sensitive information from being shared improperly.

  • A is correct because DLP complements DSPM by enforcing protection policies.
  • B, C, and D serve different purposes.

Question 8

An administrator wants recommendations for reducing AI-related security risks before expanding Microsoft 365 Copilot deployment.

What should they use?

A. Microsoft Defender Antivirus

B. Microsoft Purview DSPM for AI

C. Exchange Online Protection

D. Microsoft Entra Connect

Correct Answer: B

Explanation

DSPM for AI evaluates AI-related risks and recommends improvements such as reducing oversharing, improving data classification, and strengthening governance.

  • B is correct because providing security recommendations is one of its core capabilities.
  • The other products address different areas of Microsoft security.

Question 9

Which action would most effectively reduce AI-related data exposure identified by DSPM for AI?

A. Disable Microsoft Teams

B. Increase mailbox quotas

C. Review permissions and apply sensitivity labels to confidential data

D. Upgrade Windows devices

Correct Answer: C

Explanation

Reducing excessive permissions and properly classifying sensitive information significantly reduces AI-related exposure.

  • C is correct because both permission management and data classification are recommended remediation actions.
  • A, B, and D do not directly address AI governance.

Question 10

Which statement best summarizes Microsoft’s approach to AI governance with DSPM for AI?

A. DSPM automatically blocks all AI interactions involving confidential information.

B. DSPM replaces Microsoft Purview Information Protection.

C. DSPM eliminates the need for Microsoft Defender.

D. DSPM provides visibility, identifies risks, and recommends actions that help organizations securely adopt AI.

Correct Answer: D

Explanation

Microsoft Purview DSPM for AI is designed to improve organizational AI security posture by discovering AI usage, identifying risks, and recommending governance improvements.

  • D is correct because it accurately reflects the purpose of DSPM for AI.
  • A is incorrect because DSPM is primarily a discovery and governance solution rather than an AI-blocking mechanism.
  • B is incorrect because Information Protection remains responsible for classifying and protecting data.
  • C is incorrect because Microsoft Defender continues to provide threat protection and complements, rather than is replaced by, DSPM for AI.

Key Takeaways for the AB-900 Exam

After studying this topic, you should be able to:

  • Explain the purpose of Microsoft Purview DSPM for AI.
  • Describe how DSPM for AI helps organizations discover and govern AI activity.
  • Understand that Microsoft 365 Copilot always respects existing user permissions.
  • Explain the concept of oversharing and why it is a significant AI-related risk.
  • Describe how Microsoft Graph provides context that enables DSPM for AI to evaluate data access.
  • Identify how DSPM for AI integrates with Microsoft Purview Information Protection, Data Loss Prevention (DLP), Insider Risk Management, Activity Explorer, Compliance Manager, and Microsoft Defender.
  • Recognize that DSPM for AI provides visibility, risk assessment, and recommendations, but administrators remain responsible for implementing remediation actions.
  • Apply DSPM for AI concepts to common AB-900 scenario-based questions involving Microsoft 365 Copilot deployments and AI governance.

These concepts form an important part of the “Identify data protection and governance risks for Microsoft 365 and Copilot” objective and are frequently tested through scenario-based questions that assess your understanding of secure AI adoption and governance.


Go to the AB-900 Exam Prep Hub main page

Identify user activities reported by Microsoft Purview Activity Explorer (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Identify user activities reported by Microsoft Purview Activity Explorer


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand how Microsoft Purview Activity Explorer helps administrators investigate user activities involving sensitive information. Activity Explorer provides visibility into how sensitive data is accessed, shared, modified, labeled, or protected across Microsoft 365 services. It is an important investigative tool for identifying potential data protection and governance risks.


What Is Microsoft Purview Activity Explorer?

Microsoft Purview Activity Explorer is an investigation tool that displays activities involving sensitive information and Microsoft Purview protection technologies across Microsoft 365.

Rather than preventing actions, Activity Explorer helps administrators answer questions such as:

  • Who accessed sensitive information?
  • Which files contained sensitive data?
  • Was a sensitivity label applied or removed?
  • Did a Data Loss Prevention (DLP) policy trigger?
  • Was confidential information shared externally?
  • When did a particular activity occur?

Activity Explorer provides a searchable history of events so administrators can investigate potential compliance and security incidents.


Purpose of Activity Explorer

The primary purpose of Activity Explorer is to provide visibility into how organizational data is being used and protected.

It helps organizations:

  • Investigate compliance incidents
  • Monitor sensitive information usage
  • Validate Microsoft Purview policy effectiveness
  • Support audits
  • Identify risky user behavior
  • Understand how sensitive data moves throughout Microsoft 365

How Activity Explorer Fits into Microsoft Purview

Activity Explorer works alongside several Microsoft Purview solutions.

Microsoft Purview SolutionPurpose
Information ProtectionApplies sensitivity labels
Data Loss Prevention (DLP)Prevents inappropriate sharing of sensitive data
Data ClassificationIdentifies sensitive information
Insider Risk ManagementInvestigates risky user behavior
Activity ExplorerDisplays activities involving protected or sensitive content

Think of Activity Explorer as the investigation dashboard that brings many of these activities together.


User Activities Reported by Activity Explorer

Activity Explorer records many different activities related to sensitive information.

1. Sensitivity Label Activities

Administrators can identify when users:

  • Apply sensitivity labels
  • Remove sensitivity labels
  • Change sensitivity labels
  • Automatically receive labels
  • Manually classify documents

Example:

A user changes a document from Confidential to Public.

Activity Explorer records:

  • User
  • File
  • Previous label
  • New label
  • Time of change

2. Data Loss Prevention (DLP) Activities

Activity Explorer reports when DLP policies detect sensitive information.

Examples include:

  • Email blocked
  • File upload blocked
  • USB copy blocked
  • External sharing blocked
  • Policy warning shown
  • Policy override used

Example:

A user attempts to email customer credit card numbers.

The DLP policy detects the data and Activity Explorer records the event.


3. Sensitive Information Detection

Activity Explorer records when Microsoft identifies sensitive information types such as:

  • Credit card numbers
  • Social Security numbers
  • Passport numbers
  • Driver’s license numbers
  • Bank account numbers
  • Tax identification numbers
  • Healthcare identifiers

The tool helps administrators understand where sensitive information exists.


4. File Activities

Activity Explorer can display events involving files that contain sensitive information.

Examples include:

  • File created
  • File modified
  • File deleted
  • File copied
  • File downloaded
  • File shared
  • File moved

5. Sharing Activities

Administrators can investigate file-sharing behavior.

Examples:

  • Internal sharing
  • External sharing
  • Anonymous sharing links
  • Sharing permission changes
  • Sharing sensitive documents

These activities help identify potential data exposure risks.


6. Email Activities

Activity Explorer can report events involving protected email messages.

Examples include:

  • Email containing sensitive information
  • Protected email
  • Label changes
  • DLP policy matches

7. Teams Activities

Activity Explorer includes activities related to Microsoft Teams when supported by Microsoft Purview policies.

Examples include:

  • Sensitive information shared in Teams chats
  • Files shared in Teams
  • DLP policy matches
  • Protected documents shared

8. SharePoint and OneDrive Activities

Common activities include:

  • Sensitive file uploads
  • Downloads
  • External sharing
  • Label application
  • DLP events
  • File modifications

Information Displayed for Each Activity

Each event typically includes:

  • Date and time
  • User
  • Workload (Exchange, Teams, SharePoint, OneDrive)
  • Activity type
  • Policy involved
  • Sensitive information detected
  • Sensitivity label
  • File name
  • Location
  • Severity (when applicable)

This information helps investigators quickly understand what occurred.


Filtering Activity Explorer

Administrators can filter results by:

  • User
  • Date range
  • Workload
  • Activity type
  • Policy
  • Sensitive information type
  • Sensitivity label
  • Location
  • Service
  • File name

Filtering makes investigations faster and more targeted.


Common Investigation Scenarios

Scenario 1: External File Sharing

Question:

Has confidential information been shared outside the organization?

Activity Explorer allows investigators to:

  • Find externally shared files
  • Identify the user
  • Determine whether a DLP policy triggered
  • Review sensitivity labels

Scenario 2: Sensitive Information Discovery

Question:

Where are customer Social Security numbers stored?

Activity Explorer can identify:

  • Files
  • Users
  • Locations
  • Labels
  • Detection events

Scenario 3: Label Investigation

Question:

Who removed the Confidential label from a document?

Activity Explorer shows:

  • User
  • Time
  • Original label
  • New label
  • File involved

Scenario 4: DLP Policy Review

Question:

Which users triggered the most DLP alerts this week?

Administrators can filter DLP events by:

  • User
  • Policy
  • Date
  • Severity

Relationship to Microsoft 365 Copilot

As organizations deploy Microsoft 365 Copilot, understanding how sensitive information is used becomes increasingly important.

Activity Explorer helps administrators:

  • Verify that sensitivity labels are being applied
  • Review DLP policy activity
  • Monitor how protected information is handled
  • Investigate suspicious sharing activities
  • Support governance for content that Copilot may reference based on users’ existing permissions

Although Activity Explorer does not monitor Copilot prompts or responses directly, it helps administrators understand the underlying data protection activities associated with Microsoft 365 content.


Difference Between Activity Explorer and Audit Logs

These tools are related but serve different purposes.

Activity ExplorerMicrosoft Purview Audit
Focuses on sensitive information activitiesRecords broad user and administrator activities
Highlights DLP and sensitivity label eventsRecords nearly all Microsoft 365 events
Designed for data protection investigationsDesigned for security, compliance, and auditing
Optimized for Microsoft Purview investigationsOptimized for overall audit history

Best Practices

Organizations should:

  • Regularly review Activity Explorer.
  • Investigate repeated DLP policy matches.
  • Monitor external sharing of sensitive files.
  • Review sensitivity label changes.
  • Use filters to focus investigations.
  • Integrate findings with Insider Risk Management when appropriate.
  • Periodically validate that Purview policies are functioning as expected.

AB-900 Exam Tips

Remember these key points for the exam:

  • Activity Explorer is an investigation tool.
  • It reports activities involving sensitive information and Microsoft Purview protections.
  • It displays DLP events, sensitivity label activities, sharing events, and sensitive information detections.
  • It helps administrators investigate compliance and governance risks.
  • Activity Explorer complements Audit logs but focuses specifically on data protection activities.
  • Administrators can filter activities by user, workload, policy, label, activity type, and date.

Practice Exam Questions

Question 1

What is the primary purpose of Microsoft Purview Activity Explorer?

A. Create Microsoft 365 user accounts

B. Display activities involving sensitive information and Microsoft Purview protections

C. Configure Conditional Access policies

D. Reset user passwords

Correct Answer: B

Explanation: Activity Explorer helps administrators investigate activities involving sensitive information, DLP events, sensitivity labels, and other Microsoft Purview protection technologies.


Question 2

Which activity would most likely appear in Activity Explorer?

A. BIOS firmware updates

B. Windows device driver installation

C. A user applies a Confidential sensitivity label to a document

D. Printer toner replacement

Correct Answer: C

Explanation: Applying or changing sensitivity labels is one of the primary activities tracked by Activity Explorer.


Question 3

Which Microsoft Purview feature commonly generates events that are visible in Activity Explorer?

A. Microsoft Intune

B. Windows Update

C. Active Directory Sites and Services

D. Data Loss Prevention (DLP)

Correct Answer: D

Explanation: Activity Explorer records DLP policy matches, alerts, overrides, and other related events.


Question 4

An administrator wants to determine who shared a sensitive document externally. Which Microsoft Purview tool should they use?

A. Activity Explorer

B. Windows Event Viewer

C. Device Manager

D. Microsoft Paint

Correct Answer: A

Explanation: Activity Explorer displays sharing activities involving sensitive information, including external sharing events.


Question 5

Which information can administrators use to filter Activity Explorer results?

A. CPU temperature

B. Printer model

C. User name, activity type, and date range

D. Network cable type

Correct Answer: C

Explanation: Activity Explorer supports filtering by user, workload, activity type, policy, label, location, and date range.


Question 6

Which statement best describes Activity Explorer?

A. It permanently blocks sensitive file sharing.

B. It investigates activities involving protected or sensitive information.

C. It replaces Microsoft Defender Antivirus.

D. It encrypts every Microsoft 365 file automatically.

Correct Answer: B

Explanation: Activity Explorer is designed for investigation and reporting rather than prevention.


Question 7

Which Microsoft 365 workloads can contribute activities to Activity Explorer?

A. Only Microsoft Excel

B. Only Microsoft Teams

C. Only Exchange Online

D. Exchange Online, SharePoint Online, OneDrive, and Microsoft Teams

Correct Answer: D

Explanation: Activity Explorer collects supported events from multiple Microsoft 365 workloads to provide a comprehensive view of sensitive data activities.


Question 8

What can an administrator determine by reviewing Activity Explorer?

A. Which BIOS version users are running

B. Which sensitive information types were detected in organizational content

C. The amount of available disk space on each device

D. Which printer is the default printer

Correct Answer: B

Explanation: Activity Explorer displays detections of sensitive information types such as credit card numbers, Social Security numbers, and other classified data.


Question 9

How does Activity Explorer differ from Microsoft Purview Audit?

A. Activity Explorer focuses on sensitive information and data protection activities, while Audit records a broader range of Microsoft 365 events.

B. Activity Explorer stores passwords.

C. Audit only records Teams activities.

D. Both tools provide identical information.

Correct Answer: A

Explanation: Activity Explorer specializes in Microsoft Purview-related activities, while Audit provides broader auditing across Microsoft 365.


Question 10

Why is Microsoft Purview Activity Explorer valuable in organizations using Microsoft 365 Copilot?

A. It records every Copilot prompt entered by users.

B. It replaces Copilot security permissions.

C. It helps administrators monitor the protection and handling of sensitive Microsoft 365 content that Copilot may access based on existing permissions.

D. It automatically blocks all Copilot responses.

Correct Answer: C

Explanation: Activity Explorer helps administrators understand how sensitive content is protected and used within Microsoft 365, supporting governance for data that Copilot can access according to user permissions.


Go to the AB-900 Exam Prep Hub main page

Identify policy violations generated by Communication Compliance (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Identify policy violations generated by Communication Compliance


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

For the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, you should understand how Microsoft Purview Communication Compliance helps organizations detect, investigate, and respond to inappropriate communications that may violate corporate policies, legal requirements, or regulatory standards. You should also understand how administrators review policy matches, investigate alerts, and take appropriate remediation actions.


What is Microsoft Purview Communication Compliance?

Microsoft Purview Communication Compliance is a Microsoft Purview solution that helps organizations detect and investigate inappropriate or risky communications across Microsoft 365 services.

Rather than preventing users from communicating, Communication Compliance monitors communications and alerts authorized reviewers when messages match organizational policies.

It helps organizations detect communications involving:

  • Harassment
  • Discrimination
  • Offensive language
  • Threats
  • Confidential information sharing
  • Regulatory violations
  • Inappropriate behavior
  • Insider risks

Communication Compliance is designed to reduce legal, compliance, and reputational risks while helping organizations meet industry regulations.


Why Communication Compliance Is Important

Organizations communicate constantly using:

  • Microsoft Teams chats
  • Teams channel messages
  • Outlook emails
  • Viva Engage (Yammer)
  • Third-party communication platforms (through supported connectors)

Without monitoring, inappropriate communications may:

  • Create hostile work environments
  • Lead to lawsuits
  • Violate government regulations
  • Expose confidential information
  • Damage an organization’s reputation

Communication Compliance provides visibility into these risks.


What Are Policy Violations?

A policy violation occurs when a communication matches conditions defined within a Communication Compliance policy.

Examples include:

  • Use of offensive language
  • Bullying or harassment
  • Sharing confidential customer information
  • Threatening another employee
  • Insider trading discussions
  • Regulatory compliance violations
  • Sharing protected intellectual property

A policy violation does not automatically mean misconduct occurred.

Instead, it means the communication requires human review.


How Communication Compliance Works

The workflow follows several stages.

Step 1: Create a Policy

Administrators create policies that define:

  • Users or groups to monitor
  • Communication locations
  • Types of violations
  • Detection conditions
  • Review workflow

Step 2: Monitor Communications

Communication Compliance continuously analyzes supported communications.

Examples include:

  • Teams messages
  • Emails
  • Viva Engage posts

Content is evaluated against policy conditions.


Step 3: Generate Alerts

If content matches a policy:

  • An alert is generated.
  • The alert appears in the Communication Compliance dashboard.
  • Reviewers receive notification.

Step 4: Human Review

Authorized reviewers investigate:

  • Original message
  • Conversation context
  • Users involved
  • Severity
  • Previous incidents

Reviewers determine whether the communication truly violated policy.


Step 5: Resolution

Reviewers choose an appropriate action, such as:

  • Resolve as compliant
  • Confirm violation
  • Escalate investigation
  • Notify HR
  • Notify legal
  • Train employee
  • Document findings

Common Types of Policy Violations

Harassment

Detects communications containing:

  • Insults
  • Bullying
  • Abusive language
  • Threats

Example:

“You’re completely useless and should quit.”


Discrimination

Detects language involving:

  • Race
  • Gender
  • Religion
  • Disability
  • Age
  • Protected characteristics

Offensive Language

Identifies:

  • Profanity
  • Hate speech
  • Offensive expressions

Sensitive Information Sharing

Detects messages containing:

  • Credit card numbers
  • Social Security numbers
  • Customer information
  • Financial records
  • Medical information

Regulatory Compliance Violations

Organizations in regulated industries monitor communications involving:

  • Insider trading
  • Market manipulation
  • Financial misconduct
  • Unauthorized disclosures

Confidential Information

Detects unauthorized sharing of:

  • Trade secrets
  • Product designs
  • Internal reports
  • Source code
  • Financial forecasts

Policy Alerts

A Communication Compliance alert contains information such as:

  • Policy name
  • Date and time
  • Severity
  • User involved
  • Communication type
  • Matched rule
  • Review status

Alerts help reviewers prioritize investigations.


Alert Severity

Organizations often classify alerts as:

Low

Minor language concerns.

Example:

A mildly inappropriate joke.


Medium

Behavior that may violate company policy.

Example:

Repeated offensive language.


High

Serious compliance concern.

Example:

Threats of violence or disclosure of confidential data.


Reviewing Policy Violations

Authorized reviewers access the Communication Compliance portal.

During review they can examine:

  • Conversation history
  • Message participants
  • Attachments
  • Policy triggered
  • Matching keywords
  • Previous incidents
  • Related alerts

Context is important because individual messages may appear harmless without surrounding conversation.


Investigation Workflow

A typical investigation includes:

  1. Open the alert.
  2. Review message details.
  3. Examine conversation context.
  4. Determine whether policy was actually violated.
  5. Assign a review outcome.
  6. Document findings.
  7. Close or escalate the case.

Possible Review Outcomes

Reviewers may classify alerts as:

  • No violation
  • Violation confirmed
  • Needs escalation
  • False positive
  • Resolved

These outcomes help improve future policy effectiveness.


False Positives

Not every alert represents an actual violation.

Examples include:

  • Educational discussions
  • Medical terminology
  • Technical documentation
  • Quoted material
  • Sarcasm
  • Context misunderstood by automated analysis

Human review remains essential.


Improving Detection Accuracy

Organizations can improve policy effectiveness by:

  • Updating keyword dictionaries
  • Using machine learning classifiers
  • Adjusting policy thresholds
  • Creating separate policies for departments
  • Reviewing false positives
  • Refining monitored user groups

Who Reviews Violations?

Communication Compliance uses role-based access control.

Typical reviewers include:

  • Compliance administrators
  • Compliance officers
  • Human Resources
  • Legal teams
  • Risk investigators

Only authorized personnel can review sensitive communications.


Privacy Considerations

Communication Compliance is designed with privacy controls.

Organizations can:

  • Limit reviewer access
  • Use pseudonymization (where supported)
  • Restrict investigations
  • Audit reviewer actions
  • Follow regional privacy laws

Integration with Other Microsoft Security Solutions

Communication Compliance works alongside several Microsoft security solutions.

Microsoft Purview Insider Risk Management

Communication Compliance findings may support insider risk investigations involving suspicious employee behavior.


Microsoft Purview Data Loss Prevention (DLP)

DLP prevents unauthorized sharing of sensitive information, while Communication Compliance reviews the content and context of communications.


Microsoft Purview Information Protection

Sensitivity labels applied to documents help reviewers understand the sensitivity of shared information.


Microsoft Defender

Security incidents and user risk signals can complement Communication Compliance investigations.


Communication Compliance and Microsoft 365 Copilot

As organizations adopt Microsoft 365 Copilot, Communication Compliance remains important because users increasingly collaborate through Teams, Outlook, and other Microsoft 365 services that Copilot can reference based on existing permissions.

If inappropriate communications occur, Communication Compliance can:

  • Detect policy violations
  • Assist investigations
  • Support regulatory compliance
  • Help protect organizational reputation
  • Complement broader Microsoft Purview governance capabilities

Best Practices

For the AB-900 exam, remember these best practices:

  • Monitor communications using clearly defined policies.
  • Review alerts promptly.
  • Always investigate message context before making decisions.
  • Use authorized reviewers only.
  • Tune policies to reduce false positives.
  • Protect employee privacy while maintaining compliance.
  • Integrate Communication Compliance with broader Microsoft Purview governance.

AB-900 Exam Tips

Remember these key points:

  • Communication Compliance monitors communications—it does not block them.
  • Policy violations generate alerts, not automatic disciplinary actions.
  • Human reviewers determine whether a true violation occurred.
  • Context matters when reviewing communications.
  • Communication Compliance supports compliance, legal, HR, and risk management teams.
  • Alerts can detect harassment, discrimination, offensive language, regulatory violations, and sensitive information sharing.
  • Communication Compliance works together with Insider Risk Management, DLP, Information Protection, and Microsoft Defender.

Practice Exam Questions

Question 1

What is the primary purpose of Microsoft Purview Communication Compliance?

A. Encrypt all Microsoft Teams messages

B. Detect and investigate communications that may violate organizational policies

C. Prevent users from sending emails

D. Back up Microsoft 365 communications

Correct Answer: B

Explanation: Communication Compliance monitors supported communications and generates alerts when messages match configured compliance policies.


Question 2

A Communication Compliance alert indicates that a Teams message matched a harassment policy. What should happen next?

A. The user account is automatically disabled.

B. The message is permanently deleted.

C. An authorized reviewer investigates the communication.

D. The policy is automatically removed.

Correct Answer: C

Explanation: Communication Compliance generates alerts for human review rather than taking automatic disciplinary actions.


Question 3

Which type of communication can Microsoft Purview Communication Compliance monitor?

A. BIOS startup messages

B. Local Windows Event Logs

C. Microsoft Teams chats

D. Printer configuration files

Correct Answer: C

Explanation: Teams chats are one of the primary communication sources monitored by Communication Compliance.


Question 4

Why is conversation context important when reviewing alerts?

A. It determines network bandwidth.

B. It identifies device drivers.

C. It encrypts communications.

D. It helps reviewers determine whether a message truly violates policy.

Correct Answer: D

Explanation: Individual messages may appear inappropriate when viewed alone but may be acceptable within the full conversation.


Question 5

Which activity is an example of a Communication Compliance policy violation?

A. Updating Windows patches

B. Sharing vacation schedules

C. Sending offensive or harassing messages to coworkers

D. Resetting a forgotten password

Correct Answer: C

Explanation: Offensive or harassing communications are common scenarios monitored by Communication Compliance.


Question 6

Who should review Communication Compliance alerts?

A. Any employee

B. Only authorized compliance reviewers

C. External customers

D. Guest users

Correct Answer: B

Explanation: Access to Communication Compliance investigations is limited through role-based access control.


Question 7

What is a false positive in Communication Compliance?

A. A communication incorrectly identified as violating policy

B. A deleted user account

C. An expired Microsoft 365 license

D. A successful malware scan

Correct Answer: A

Explanation: False positives occur when automated detection flags communications that are ultimately determined not to violate policy.


Question 8

Which Microsoft Purview solution focuses primarily on preventing sensitive information from leaving the organization?

A. Communication Compliance

B. Insider Risk Management

C. Data Loss Prevention (DLP)

D. Compliance Manager

Correct Answer: C

Explanation: DLP is designed to detect and prevent unauthorized sharing of sensitive information, while Communication Compliance focuses on reviewing communications.


Question 9

What does a Communication Compliance alert indicate?

A. A confirmed policy violation requiring disciplinary action

B. A communication matched a configured policy and should be reviewed

C. The user’s account has been compromised

D. Microsoft 365 licensing has expired

Correct Answer: B

Explanation: Alerts indicate potential policy matches that require investigation; they are not proof of wrongdoing.


Question 10

Which statement best describes Microsoft Purview Communication Compliance?

A. It replaces antivirus software.

B. It automatically blocks every risky message.

C. It permanently archives all Microsoft 365 files.

D. It helps organizations identify, investigate, and respond to inappropriate communications.

Correct Answer: D

Explanation: Communication Compliance helps organizations manage communication-related compliance risks through monitoring, alerting, investigation, and response.


Go to the AB-900 Exam Prep Hub main page

Identify and respond to alerts generated by Microsoft Purview Data Loss Prevention (DLP) (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Identify and respond to alerts generated by Microsoft Purview Data Loss Prevention (DLP)


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft Purview Data Loss Prevention (DLP) helps organizations prevent the accidental or intentional exposure of sensitive information. DLP continuously monitors user activities across Microsoft 365 services and generates alerts when users violate data protection policies.

For the AB-900 exam, you should understand:

  • What Microsoft Purview DLP alerts are
  • When DLP alerts are generated
  • How administrators review alerts
  • Alert severity and prioritization
  • Investigation workflows
  • How to respond to DLP alerts
  • Integration with other Microsoft Purview and Microsoft Defender solutions
  • Best practices for managing alerts

What Is Microsoft Purview Data Loss Prevention (DLP)?

Microsoft Purview Data Loss Prevention (DLP) is a Microsoft Purview solution that helps organizations identify, monitor, and protect sensitive information from unauthorized sharing or exposure.

DLP policies monitor data stored in Microsoft 365 services such as:

  • Microsoft Exchange Online
  • Microsoft SharePoint Online
  • Microsoft OneDrive for Business
  • Microsoft Teams
  • Microsoft Defender for Cloud Apps
  • Endpoint devices (with Endpoint DLP)
  • Power BI (supported scenarios)

When a user performs an action that violates a DLP policy, the system can generate an alert.


What Is a DLP Alert?

A DLP alert is a notification generated when a DLP policy detects activity that violates organizational data protection rules.

Alerts help administrators:

  • Detect risky user behavior
  • Investigate policy violations
  • Respond to incidents quickly
  • Reduce data leakage
  • Demonstrate compliance

Alerts are one of the primary tools compliance administrators use to monitor organizational data protection.


When Are DLP Alerts Generated?

Alerts are generated when users perform actions that violate configured DLP policies.

Examples include:

  • Emailing confidential documents externally
  • Uploading sensitive files to unauthorized cloud storage
  • Copying protected files to USB devices
  • Printing highly confidential documents
  • Sharing files publicly
  • Downloading sensitive files from SharePoint
  • Copying confidential information into unmanaged applications

Not every policy generates an alert. Alert generation depends on the configured policy actions.


How DLP Detects Sensitive Information

Before generating alerts, DLP identifies sensitive content using several methods.

Sensitive Information Types (SITs)

Built-in detectors identify information such as:

  • Credit card numbers
  • Social Security numbers
  • Passport numbers
  • Driver’s license numbers
  • Bank account numbers
  • Tax identification numbers
  • Healthcare identifiers

Sensitivity Labels

Microsoft Purview Information Protection labels can identify:

  • Public
  • General
  • Confidential
  • Highly Confidential

Policies can generate alerts whenever protected documents are shared improperly.


Trainable Classifiers

Machine learning can recognize documents such as:

  • Resumes
  • Contracts
  • Source code
  • Financial reports
  • Legal documents

Exact Data Match (EDM)

Organizations can detect exact records such as:

  • Customer databases
  • Employee IDs
  • Payroll records

Components of a DLP Alert

Each alert contains detailed information to help administrators investigate the incident.

Typical alert details include:

  • User involved
  • Date and time
  • Policy name
  • Rule triggered
  • Sensitive information detected
  • File name
  • File location
  • Service involved
  • Severity level
  • User activity
  • Recommended actions

Alert Severity

DLP alerts are assigned severity levels to help prioritize investigations.

Typical levels include:

Low

Examples:

  • Minor policy violations
  • First-time incidents
  • Low-risk data exposure

Medium

Examples:

  • Multiple policy violations
  • Larger quantities of sensitive information
  • Repeated risky behavior

High

Examples:

  • Large-scale data exfiltration
  • Highly confidential information
  • Repeated attempts to bypass policies
  • Executive or privileged account violations

Administrators generally investigate High severity alerts first.


Reviewing DLP Alerts

Administrators review alerts in the Microsoft Purview portal.

The alert dashboard allows administrators to:

  • View all active alerts
  • Filter alerts
  • Search alerts
  • Sort by severity
  • Review alert details
  • Assign alerts
  • Track investigation status

Information Available During Investigation

Selecting an alert provides additional information.

Examples include:

User Information

  • Username
  • Department
  • Device
  • Location

Activity Timeline

Investigators can review:

  • File creation
  • Downloads
  • Sharing
  • Email activity
  • Printing
  • USB transfers

Policy Information

The alert identifies:

  • Which DLP policy triggered
  • Which rule matched
  • Sensitive information detected
  • Confidence level

File Details

Investigators may see:

  • File name
  • Location
  • File owner
  • Label applied
  • Number of sensitive items detected

Responding to DLP Alerts

After reviewing an alert, administrators choose an appropriate response.

Possible actions include:

Close the Alert

If the activity is determined to be legitimate or a false positive.


Investigate Further

Review:

  • User behavior
  • Related alerts
  • Audit logs
  • Endpoint activities

Escalate

Escalate high-risk alerts to:

  • Security teams
  • Compliance officers
  • Legal departments
  • Human Resources

Adjust Policies

If alerts indicate:

  • Too many false positives
  • Policy gaps
  • Incorrect thresholds

Administrators can modify DLP policies accordingly.


Educate Users

Many violations are accidental.

Organizations often:

  • Notify users
  • Provide training
  • Improve awareness

User Notifications (Policy Tips)

Instead of immediately blocking users, DLP can display Policy Tips.

Policy Tips inform users that:

  • Sensitive information was detected
  • Their action violates policy
  • They should modify their behavior

Examples include:

  • “This email contains confidential information.”
  • “Sharing this document externally violates company policy.”

Policy Tips reduce accidental violations.


Alert Lifecycle

A typical DLP alert progresses through several stages.

  1. Sensitive data is detected.
  2. DLP policy evaluates the activity.
  3. Alert is generated.
  4. Administrator reviews the alert.
  5. Investigation begins.
  6. Response action is taken.
  7. Alert is closed.

Integration with Microsoft Purview Solutions

DLP works closely with other Microsoft Purview capabilities.

Microsoft Purview Information Protection

Sensitivity labels provide additional context for DLP decisions.

Example:

A “Highly Confidential” document shared externally generates a higher-priority alert.


Microsoft Purview Insider Risk Management

Repeated DLP violations can contribute to insider risk investigations.

Example:

An employee repeatedly emailing confidential documents externally may trigger both DLP and Insider Risk Management alerts.


Microsoft Purview Audit

Audit logs provide additional evidence.

Investigators can review:

  • File access
  • Sharing history
  • Administrative changes
  • User activities

Microsoft Purview Compliance Manager

Compliance Manager helps organizations improve their compliance posture by recommending controls that reduce DLP-related risks.


Integration with Microsoft Defender

DLP integrates with Microsoft Defender solutions.

Examples include:

  • Endpoint DLP
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Cloud Apps

These integrations provide additional context, including:

  • Device information
  • Endpoint activities
  • Application usage
  • USB activity
  • Browser uploads

Common DLP Alert Scenarios

Scenario 1

A user emails a spreadsheet containing hundreds of customer credit card numbers to a personal Gmail account.

Result:

A High severity DLP alert is generated.


Scenario 2

An employee uploads payroll records to an unauthorized cloud storage provider.

Result:

A DLP alert identifies unauthorized data movement.


Scenario 3

A contractor copies confidential engineering documents onto a USB drive.

Result:

Endpoint DLP generates an alert.


Scenario 4

A user attempts to publicly share a SharePoint folder containing confidential HR records.

Result:

The sharing attempt triggers a DLP alert.


Best Practices

Organizations should:

  • Create well-designed DLP policies
  • Use sensitivity labels
  • Enable Policy Tips
  • Review alerts regularly
  • Prioritize High severity alerts
  • Investigate repeated violations
  • Reduce false positives through policy tuning
  • Integrate DLP with Insider Risk Management
  • Monitor trends over time
  • Train users on proper data handling

Exam Tips

For the AB-900 exam, remember the following:

  • DLP alerts are generated when users violate DLP policies.
  • Alerts help administrators detect potential data leakage.
  • Alerts contain details about users, files, policies, and detected sensitive information.
  • Severity levels help prioritize investigations.
  • Administrators can investigate, escalate, close, or remediate alerts.
  • DLP integrates with Microsoft Purview Information Protection, Insider Risk Management, Audit, Compliance Manager, and Microsoft Defender.
  • Policy Tips help reduce accidental policy violations.
  • Endpoint DLP extends protection to Windows devices.

10 Practice Exam Questions

Question 1

A user attempts to email a document containing multiple credit card numbers to an external recipient. A Microsoft Purview DLP policy blocks the email.

What additional action can the policy perform?

A. Remove the user’s Microsoft 365 license

B. Disable the user’s account

C. Delete the user’s mailbox

D. Automatically create a DLP alert for administrators

Correct Answer: D

Explanation: DLP policies can generate alerts whenever sensitive information triggers configured policy rules, allowing administrators to investigate the incident.


Question 2

Which information is typically included in a Microsoft Purview DLP alert?

A. The organization’s annual revenue

B. The user involved, policy triggered, sensitive information detected, and activity details

C. The user’s payroll information

D. The organization’s Active Directory schema

Correct Answer: B

Explanation: DLP alerts include detailed information such as the user, file, policy, rule, sensitive information detected, and the action that triggered the alert.


Question 3

An administrator wants to focus first on the most critical potential data leakage incidents.

Which alert characteristic should they prioritize?

A. Oldest alert

B. Alphabetical order

C. Alert severity

D. File size

Correct Answer: C

Explanation: Alert severity (Low, Medium, High) helps administrators prioritize investigations based on potential business impact.


Question 4

What is the primary purpose of Policy Tips in Microsoft Purview DLP?

A. Replace DLP policies

B. Notify users that their actions may violate data protection policies

C. Automatically encrypt all files

D. Prevent administrators from reviewing alerts

Correct Answer: B

Explanation: Policy Tips educate users in real time about potential policy violations, reducing accidental exposure of sensitive information.


Question 5

Which Microsoft Purview solution commonly works with DLP by applying sensitivity labels to documents?

A. Microsoft Purview Information Protection

B. Microsoft Intune

C. Microsoft Planner

D. Microsoft Bookings

Correct Answer: A

Explanation: Information Protection applies sensitivity labels that DLP can use when evaluating and protecting sensitive content.


Question 6

What is an appropriate response after reviewing a DLP alert that is determined to be a false positive?

A. Delete the user’s Microsoft account

B. Close the alert and, if necessary, refine the DLP policy

C. Block all external email permanently

D. Remove all DLP policies

Correct Answer: B

Explanation: Administrators should close false-positive alerts and may adjust policy conditions to reduce unnecessary alerts.


Question 7

Which scenario is most likely to generate a High severity DLP alert?

A. A user changes their Teams profile picture

B. A user updates a calendar meeting

C. A user downloads a public marketing brochure

D. A user sends a file containing hundreds of customer Social Security numbers to a personal email account

Correct Answer: D

Explanation: Attempting to send large amounts of highly sensitive personal information externally is a common High severity DLP event.


Question 8

Which Microsoft solution provides additional endpoint information, such as USB activity, that can complement DLP investigations?

A. Microsoft Defender for Endpoint

B. Microsoft Word

C. Microsoft Visio

D. Microsoft Lists

Correct Answer: A

Explanation: Microsoft Defender for Endpoint provides endpoint telemetry that enhances DLP investigations, especially for Endpoint DLP scenarios.


Question 9

What is the first event that typically occurs in the DLP alert lifecycle?

A. An administrator closes the alert

B. A DLP policy detects sensitive information during a monitored user activity

C. Human Resources opens an investigation

D. The user account is suspended

Correct Answer: B

Explanation: The process begins when DLP identifies sensitive information and evaluates the activity against configured policies. If a violation is detected, an alert can be generated.


Question 10

Why would an organization integrate Microsoft Purview Insider Risk Management with DLP?

A. To replace all DLP policies

B. To reduce Microsoft 365 licensing costs

C. To correlate repeated DLP violations with broader patterns of risky user behavior

D. To manage Windows software updates

Correct Answer: C

Explanation: Insider Risk Management can use repeated DLP incidents as signals when identifying users who may present elevated insider risks, helping investigators understand behavior patterns rather than isolated events.


Go to the AB-900 Exam Prep Hub main page