Tag: Microsoft Certification

Identify risks by using Microsoft Purview Insider Risk Management (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Identify risks by using Microsoft Purview Insider Risk Management


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft Purview Insider Risk Management (IRM) helps organizations detect, investigate, and respond to insider risks before they result in significant business damage. Unlike external cyberattacks, insider risks originate from individuals who already have authorized access to organizational resources. These individuals may intentionally misuse data or unintentionally expose sensitive information through careless actions.

For the AB-900 exam, you should understand:

  • What Insider Risk Management is
  • The types of risks it helps identify
  • The components used to detect insider risks
  • How risk indicators and policies work
  • How investigations are performed
  • How Insider Risk Management integrates with other Microsoft 365 security solutions
  • Common use cases

What Is Microsoft Purview Insider Risk Management?

Microsoft Purview Insider Risk Management is a Microsoft Purview solution that uses machine learning, analytics, user activity signals, and built-in privacy protections to identify potentially risky user behavior.

Its purpose is not to assume users are malicious. Instead, it identifies behaviors that could indicate:

  • Data theft
  • Intellectual property loss
  • Security violations
  • Compliance violations
  • Accidental data exposure
  • Policy violations

The solution helps security, compliance, HR, and legal teams investigate suspicious activities while respecting employee privacy.


What Is an Insider Risk?

An insider risk is any situation where someone with legitimate access to organizational systems creates risk for the organization.

Examples include:

  • An employee downloading thousands of confidential files before resigning
  • A contractor copying customer information to a USB drive
  • A user emailing sensitive documents to a personal email account
  • An employee sharing confidential information through unauthorized cloud storage
  • A user repeatedly accessing data unrelated to their job responsibilities

Not every insider risk is malicious.

Many incidents are accidental.

Examples include:

  • Sending confidential files to the wrong recipient
  • Uploading sensitive documents to public cloud storage
  • Accidentally sharing confidential Teams files

Types of Insider Risks

Microsoft categorizes insider risks into several common scenarios.

Data Theft

Occurs when users attempt to remove valuable organizational information.

Examples include:

  • Downloading confidential files
  • Copying files to USB devices
  • Printing sensitive documents
  • Emailing proprietary information externally

Data Leakage

Sensitive information leaves the organization unintentionally.

Examples include:

  • Uploading files to personal cloud storage
  • Sending confidential documents externally
  • Sharing protected files publicly

Security Policy Violations

Users violate established organizational security rules.

Examples include:

  • Disabling security controls
  • Using unauthorized applications
  • Circumventing compliance policies

Compliance Violations

Employees violate legal or regulatory requirements.

Examples include:

  • Sharing regulated financial records
  • Mishandling healthcare information
  • Improperly accessing customer records

Departing Employee Risks

A common scenario involves employees preparing to leave the organization.

Potential indicators include:

  • Large file downloads
  • Increased file copying
  • Unusual external sharing
  • Mass printing
  • Accessing previously unused repositories

How Insider Risk Management Works

Insider Risk Management follows a multi-stage process.

Step 1: Collect Activity Signals

Microsoft collects activity information from supported Microsoft 365 services.

Examples include:

  • SharePoint Online
  • OneDrive
  • Exchange Online
  • Microsoft Teams
  • Microsoft Defender
  • Microsoft Entra ID
  • Endpoint activity
  • Microsoft Defender for Endpoint

Step 2: Analyze User Activity

Machine learning compares current activity against:

  • Normal behavior
  • Organizational policies
  • Risk indicators
  • User context

This reduces false positives.


Step 3: Generate Risk Alerts

If suspicious behavior exceeds configured thresholds:

  • An alert is created.
  • The alert receives a severity level.
  • Investigators can review supporting evidence.

Step 4: Investigate

Compliance administrators review:

  • Timeline of events
  • User activities
  • File operations
  • Email actions
  • Device activities
  • Related alerts

Step 5: Respond

Possible actions include:

  • Escalating investigations
  • Assigning cases
  • Collecting evidence
  • Alerting management
  • Applying additional protections
  • Closing false positives

Risk Indicators

Risk indicators are behaviors that contribute to a user’s overall risk score.

Examples include:

File Activities

  • Downloading files
  • Deleting files
  • Printing documents
  • Copying files
  • Uploading files

Email Activities

  • Sending attachments externally
  • Forwarding confidential emails
  • Mass emailing sensitive information

Device Activities

  • USB device usage
  • File transfers
  • Printing
  • Local file copying

Collaboration Activities

  • Sharing Teams files externally
  • Creating anonymous sharing links
  • Public document sharing

User Behavior

Examples include:

  • Working unusual hours
  • Accessing unusual locations
  • Accessing excessive numbers of files
  • Sudden changes in behavior

Insider Risk Policies

Policies determine:

  • Which users are monitored
  • What behaviors are evaluated
  • Alert thresholds
  • Investigation rules

Policies are based on templates.

Common templates include:

  • Data leaks
  • Data theft
  • Security policy violations
  • Departing employees
  • Risky browser usage
  • Priority user monitoring

Policies allow organizations to customize detection based on their business needs.


Risk Scores

Each user activity contributes to a risk score.

Higher scores indicate more concerning activity.

Factors influencing scores include:

  • Number of risky actions
  • Severity of activities
  • Frequency
  • Historical behavior
  • Machine learning analysis

Risk scores help investigators prioritize the most serious incidents.


Alerts

When policy thresholds are exceeded, alerts are created.

Alerts typically include:

  • User involved
  • Policy triggered
  • Activity timeline
  • Risk level
  • Supporting evidence
  • Recommended investigation steps

Alert severity may include:

  • Low
  • Medium
  • High

Cases

Investigators can promote alerts into investigation cases.

Cases centralize:

  • Evidence
  • User activity
  • Timeline
  • Notes
  • Investigation status
  • Assigned investigators

This allows multiple reviewers to collaborate.


Privacy by Design

Microsoft designed Insider Risk Management with employee privacy in mind.

Privacy protections include:

  • Role-based access control
  • User pseudonymization (where supported)
  • Audit logging
  • Configurable privacy settings
  • Limited investigator access

Organizations control who can view personally identifiable information.


Integration with Microsoft 365 Services

Insider Risk Management integrates with many Microsoft security solutions.

Microsoft Purview Data Loss Prevention (DLP)

Provides sensitivity information about protected files.

Example:

A user emailing a document containing credit card numbers may trigger both DLP and Insider Risk Management.


Microsoft Purview Information Protection

Sensitivity labels provide additional context.

Example:

Downloading dozens of “Highly Confidential” documents creates greater risk than downloading public documents.


Microsoft Defender

Endpoint signals include:

  • USB usage
  • File copying
  • Application activity
  • Device events

These signals improve risk detection.


Microsoft Entra ID

Identity information provides context, including:

  • User identity
  • Sign-in behavior
  • Account changes
  • Risk signals

Microsoft 365 Audit Logs

User activities across Microsoft 365 workloads provide evidence for investigations.


AI and Machine Learning

Machine learning helps reduce false positives by:

  • Understanding normal behavior
  • Detecting unusual activity
  • Correlating multiple signals
  • Prioritizing serious incidents

This allows investigators to focus on the highest-risk alerts.


Common Use Cases

Protecting Intellectual Property

Identify employees copying engineering documents before leaving the company.


Detecting Insider Data Theft

Identify users downloading large numbers of confidential files.


Monitoring High-Risk Users

Monitor executives or privileged administrators who have access to sensitive information.


Investigating Data Leaks

Determine how confidential information left the organization.


Supporting HR Investigations

Provide evidence when investigating employee misconduct.


Benefits of Insider Risk Management

Organizations benefit by:

  • Detecting insider threats early
  • Protecting confidential information
  • Reducing compliance violations
  • Improving investigations
  • Prioritizing high-risk incidents
  • Using AI to reduce false positives
  • Integrating with Microsoft Purview and Microsoft Defender
  • Supporting regulatory compliance
  • Protecting intellectual property
  • Providing centralized case management

Exam Tips

For the AB-900 exam, remember these key points:

  • Insider Risk Management focuses on user behavior, not external attackers.
  • It detects both malicious and accidental risky activities.
  • Policies determine what activities are monitored.
  • Machine learning helps reduce false positives.
  • Alerts can be promoted into investigation cases.
  • Insider Risk Management integrates with DLP, Information Protection, Microsoft Defender, Microsoft Entra ID, and Microsoft 365 audit logs.
  • Risk scores help prioritize investigations.
  • Privacy protections are built into the solution.

10 Practice Exam Questions

Question 1

An employee uploads several confidential engineering documents to a personal cloud storage account shortly before resigning.

Which Microsoft Purview solution is specifically designed to investigate this type of behavior?

A. Microsoft Purview eDiscovery

B. Microsoft Purview Insider Risk Management

C. Microsoft Defender for Cloud Apps

D. Microsoft Intune

Correct Answer: B

Explanation: Insider Risk Management is specifically designed to identify potentially risky insider behavior such as data theft, data leakage, and activities performed by departing employees.


Question 2

Which activity is most likely to increase a user’s insider risk score?

A. Viewing the company homepage

B. Logging into Microsoft Teams during normal working hours

C. Downloading hundreds of confidential files before leaving the company

D. Changing a desktop wallpaper

Correct Answer: C

Explanation: Large-scale downloads of sensitive information—especially by departing employees—are common indicators of insider risk.


Question 3

What is the primary purpose of Insider Risk Management policies?

A. Encrypt all Microsoft 365 data

B. Replace antivirus software

C. Control Microsoft licensing

D. Define which users, activities, and risk indicators should be monitored

Correct Answer: D

Explanation: Policies specify monitored users, monitored activities, thresholds, and investigation settings.


Question 4

Which Microsoft technology helps Insider Risk Management reduce false positives?

A. Static firewall rules

B. Manual investigations only

C. Machine learning and behavioral analytics

D. Network packet inspection

Correct Answer: C

Explanation: Machine learning evaluates user behavior patterns and distinguishes normal activity from potentially risky behavior.


Question 5

What happens after Insider Risk Management determines that user activity exceeds a configured policy threshold?

A. The user account is automatically deleted.

B. The organization’s Microsoft 365 subscription is suspended.

C. All user devices are immediately wiped.

D. An insider risk alert is generated for investigation.

Correct Answer: D

Explanation: Alerts are created when monitored activities exceed policy thresholds and can later be investigated or promoted into cases.


Question 6

Which Microsoft solution provides endpoint signals such as USB usage and local file copying to Insider Risk Management?

A. Microsoft Defender for Endpoint

B. Microsoft Outlook

C. Microsoft Planner

D. Microsoft Bookings

Correct Answer: A

Explanation: Microsoft Defender for Endpoint supplies valuable endpoint telemetry that strengthens insider risk detection.


Question 7

Which statement best describes Microsoft’s approach to employee privacy within Insider Risk Management?

A. Every administrator automatically sees all employee information.

B. Employee privacy protections such as role-based access and pseudonymization are built into the solution.

C. All investigations are anonymous and cannot identify users.

D. Privacy settings cannot be customized.

Correct Answer: B

Explanation: Insider Risk Management incorporates privacy-by-design principles, including role-based access, pseudonymization where supported, and configurable privacy controls.


Question 8

Which scenario is an example of an accidental insider risk?

A. A hacker exploits an internet-facing server.

B. An attacker launches a ransomware attack.

C. An employee mistakenly emails confidential information to the wrong external recipient.

D. A distributed denial-of-service (DDoS) attack targets a website.

Correct Answer: C

Explanation: Insider risks include accidental actions, such as unintentionally sharing sensitive information with unauthorized recipients.


Question 9

What information helps investigators prioritize which alerts should be reviewed first?

A. The user’s mailbox size

B. Microsoft licensing level

C. The user’s department name

D. The insider risk score and alert severity

Correct Answer: D

Explanation: Risk scores and alert severity help investigators focus on the most significant potential threats first.


Question 10

Which Microsoft Purview capability most directly complements Insider Risk Management by identifying and protecting sensitive content through labeling?

A. Microsoft Purview Information Protection

B. Microsoft Exchange Online Protection

C. Microsoft Intune

D. Windows Firewall

Correct Answer: A

Explanation: Microsoft Purview Information Protection classifies and labels sensitive information. Those labels provide valuable context that Insider Risk Management can use when assessing the risk associated with user activities.


Go to the AB-900 Exam Prep Hub main page

Identify sensitive information by using Microsoft Purview Data Explorer (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Identify sensitive information by using Microsoft Purview Data Explorer


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

As organizations increasingly rely on Microsoft 365 and Microsoft 365 Copilot, understanding where sensitive information resides has become a critical governance and security requirement. Sensitive data such as credit card numbers, Social Security numbers, health records, financial information, intellectual property, and confidential business documents can create significant compliance and security risks if not properly managed.

Microsoft Purview Data Explorer helps organizations discover, analyze, and understand sensitive information stored across Microsoft 365 services. It provides visibility into the location, volume, and classification of sensitive data, enabling administrators to make informed decisions about data protection, governance, compliance, and Copilot readiness.

For the AB-900 exam, you should understand the purpose of Data Explorer, how it identifies sensitive information, the types of information it can discover, and how organizations use its insights to reduce compliance and governance risks.


What Is Microsoft Purview Data Explorer?

Microsoft Purview Data Explorer is a reporting and investigation tool within Microsoft Purview that helps administrators visualize and analyze sensitive data across Microsoft 365 environments.

Data Explorer enables organizations to:

  • Discover sensitive information
  • Understand where sensitive data is stored
  • Analyze data classification results
  • Identify compliance risks
  • Support data governance initiatives
  • Validate Microsoft Purview policy effectiveness
  • Improve Microsoft 365 Copilot readiness

Rather than protecting data directly, Data Explorer provides visibility into an organization’s data landscape so administrators can take appropriate actions.


Why Data Discovery Is Important

Organizations often accumulate large amounts of data over time. Without visibility into that data, administrators may not know:

  • What sensitive information exists
  • Where the information is stored
  • Who has access to it
  • Whether it is properly protected
  • Whether regulatory requirements are being met

For example:

  • Customer records may contain personally identifiable information (PII).
  • Financial documents may contain account numbers.
  • Healthcare records may contain protected health information (PHI).
  • Contracts may contain confidential business information.

Data Explorer helps identify these risks before they become security or compliance issues.


How Data Explorer Works

Data Explorer analyzes Microsoft 365 content using classification technologies available in Microsoft Purview.

The system scans content stored in supported locations and identifies:

  • Sensitive information types
  • Sensitivity labels
  • Trainable classifiers
  • Retention labels
  • Data classifications

The results are then presented through visual dashboards and detailed reports.

Administrators can use these reports to understand the organization’s sensitive data footprint.


Data Sources Analyzed by Data Explorer

Data Explorer can analyze content across Microsoft 365 services, including:

SharePoint Online

Examples:

  • Documents
  • Team sites
  • Department sites
  • Project repositories

OneDrive for Business

Examples:

  • Personal work files
  • Shared documents
  • Business records

Exchange Online

Examples:

  • Email messages
  • Attachments
  • Mailbox content

Microsoft Teams

Examples:

  • Shared files
  • Team documents
  • Collaboration content

These locations often contain the information that Microsoft 365 Copilot accesses when generating responses.


Sensitive Information Types (SITs)

One of the primary ways Data Explorer identifies sensitive information is through Sensitive Information Types (SITs).

Sensitive Information Types are predefined patterns that identify specific categories of sensitive data.

Examples include:

  • Social Security Numbers
  • Credit Card Numbers
  • Driver’s License Numbers
  • Passport Numbers
  • Tax Identification Numbers
  • Bank Account Numbers
  • Healthcare Information

Microsoft provides hundreds of built-in sensitive information types.

Organizations can also create custom sensitive information types.


Trainable Classifiers

Data Explorer can also identify information using trainable classifiers.

Unlike pattern matching, trainable classifiers use machine learning to recognize content based on context.

Examples include:

  • Resumes
  • Contracts
  • Invoices
  • Financial documents
  • Source code
  • Intellectual property

This helps organizations classify content that may not contain obvious patterns such as account numbers or IDs.


Sensitivity Labels and Data Explorer

Organizations often use sensitivity labels to classify and protect information.

Examples of labels include:

  • Public
  • General
  • Confidential
  • Highly Confidential

Data Explorer can show:

  • Which files have sensitivity labels
  • Label distribution across the organization
  • Unlabeled sensitive content
  • Areas where additional labeling may be needed

This visibility helps improve data governance and security.


Retention Labels and Data Explorer

Retention labels determine how long content should be retained and when it should be deleted.

Data Explorer can help organizations understand:

  • Which files have retention labels
  • Which files lack retention labels
  • Data that may require retention controls
  • Potential records management gaps

Data Classification Overview

Data classification is the process of identifying and categorizing information according to its sensitivity and business value.

Data Explorer supports classification efforts by helping organizations:

  • Locate sensitive data
  • Understand risk exposure
  • Apply appropriate protections
  • Improve compliance programs

The classification process typically includes:

  1. Discover data
  2. Classify data
  3. Protect data
  4. Monitor data
  5. Govern data

Data Explorer primarily supports the discovery and analysis phases.


Visualizations and Reporting

Data Explorer provides dashboards and reports that help administrators quickly understand sensitive data trends.

Reports can show:

  • Number of sensitive items
  • Sensitive information types detected
  • Label usage
  • Data locations
  • Content trends
  • Classification coverage

These visualizations help administrators identify areas requiring additional protection.


Data Explorer and Microsoft 365 Copilot

Data Explorer plays an important role in Copilot readiness assessments.

Because Microsoft 365 Copilot uses existing permissions and accesses organizational data through Microsoft Graph, organizations should understand what data exists before deploying Copilot broadly.

Data Explorer helps identify:

  • Overexposed sensitive data
  • Unclassified content
  • Excessively shared files
  • Confidential documents lacking protection
  • Data governance gaps

Administrators can use these insights to improve security before expanding Copilot adoption.


Common Governance Risks Identified by Data Explorer

Unlabeled Sensitive Data

Sensitive documents may exist without sensitivity labels.

Risk:

  • Users may accidentally share confidential information.

Recommended Action:

  • Apply sensitivity labels.

Excessive Data Exposure

Sensitive files may be accessible to too many users.

Risk:

  • Unauthorized access.

Recommended Action:

  • Review permissions and sharing settings.

Missing Retention Controls

Important records may lack retention policies.

Risk:

  • Regulatory violations.

Recommended Action:

  • Implement retention labels and policies.

Sensitive Data in Unexpected Locations

Data may be stored outside approved repositories.

Risk:

  • Governance challenges.

Recommended Action:

  • Review storage practices and apply controls.

Relationship with Other Microsoft Purview Solutions

Data Explorer works alongside other Microsoft Purview solutions.

Information Protection

Provides:

  • Sensitivity labels
  • Encryption
  • Classification

Data Explorer shows where protected and unprotected content exists.


Data Loss Prevention (DLP)

Provides:

  • Policy enforcement
  • Data movement restrictions

Data Explorer helps identify data that may require DLP protection.


Insider Risk Management

Provides:

  • Risk detection
  • Insider threat analysis

Data Explorer helps identify sensitive data that could be targeted.


Compliance Manager

Provides:

  • Compliance assessments
  • Risk reduction recommendations

Data Explorer provides visibility into the data that compliance programs are designed to protect.


Benefits of Using Data Explorer

Organizations use Data Explorer to:

  • Discover sensitive information
  • Improve data governance
  • Support regulatory compliance
  • Prepare for Copilot deployment
  • Validate classification strategies
  • Identify protection gaps
  • Reduce organizational risk
  • Improve visibility into data assets

Key Exam Tips

For the AB-900 exam, remember the following:

  • Data Explorer helps organizations discover and analyze sensitive information.
  • It provides visibility into sensitive data locations across Microsoft 365.
  • Sensitive Information Types identify structured sensitive data such as Social Security numbers and credit card numbers.
  • Trainable classifiers identify content based on context and machine learning.
  • Data Explorer supports governance, compliance, and Copilot readiness initiatives.
  • It helps identify unlabeled, unprotected, or overexposed sensitive information.
  • Data Explorer is primarily a discovery and analysis tool, not a protection or enforcement tool.
  • Data Explorer works with sensitivity labels, retention labels, DLP, and other Microsoft Purview solutions.

Practice Exam Questions

Question 1

What is the primary purpose of Microsoft Purview Data Explorer?

A. Generate AI responses for users

B. Discover and analyze sensitive information across Microsoft 365

C. Encrypt all organizational files

D. Replace Microsoft Defender

Answer: B

Explanation: Data Explorer is designed to help organizations discover, analyze, and understand sensitive information stored across Microsoft 365 services.


Question 2

Which Microsoft 365 service can be analyzed by Data Explorer?

A. SharePoint Online

B. Windows Server

C. Hyper-V

D. Microsoft Intune only

Answer: A

Explanation: Data Explorer can analyze content stored in SharePoint Online, OneDrive, Exchange Online, Teams, and other supported Microsoft 365 locations.


Question 3

What is a Sensitive Information Type (SIT)?

A. A method for creating Teams meetings

B. A licensing model for Microsoft Purview

C. A predefined pattern used to identify sensitive information

D. A backup technology

Answer: C

Explanation: Sensitive Information Types are predefined detectors that identify sensitive data such as Social Security numbers and credit card numbers.


Question 4

Which technology helps identify content such as contracts and resumes using context rather than pattern matching?

A. DLP policies

B. Retention labels

C. Sensitivity labels

D. Trainable classifiers

Answer: D

Explanation: Trainable classifiers use machine learning and contextual analysis to identify document types such as contracts, resumes, and invoices.


Question 5

An administrator wants to determine whether confidential files lack sensitivity labels. Which tool should they use?

A. Microsoft Planner

B. Microsoft Lists

C. Microsoft Purview Data Explorer

D. Microsoft Whiteboard

Answer: C

Explanation: Data Explorer can identify sensitive content and show whether appropriate sensitivity labels have been applied.


Question 6

Which statement best describes Data Explorer?

A. It automatically blocks all file sharing.

B. It discovers and reports on sensitive information.

C. It replaces retention policies.

D. It automatically deletes noncompliant content.

Answer: B

Explanation: Data Explorer focuses on visibility and analysis rather than directly enforcing protection actions.


Question 7

Why is Data Explorer valuable before deploying Microsoft 365 Copilot broadly?

A. It upgrades Copilot licenses.

B. It improves Teams meeting quality.

C. It increases mailbox storage.

D. It helps identify sensitive or overexposed data that Copilot could potentially access.

Answer: D

Explanation: Understanding data exposure and classification gaps helps organizations prepare for secure Copilot adoption.


Question 8

Which item would most likely be identified through a built-in Sensitive Information Type?

A. A company strategy presentation

B. A software design diagram

C. A credit card number

D. A project timeline

Answer: C

Explanation: Sensitive Information Types are designed to detect structured data such as credit card numbers, passport numbers, and Social Security numbers.


Question 9

What governance risk might Data Explorer help identify?

A. Unlabeled sensitive documents

B. Printer driver issues

C. Network latency

D. Browser compatibility problems

Answer: A

Explanation: Data Explorer helps identify sensitive content that lacks classification or protection controls.


Question 10

How does Data Explorer support data governance?

A. By replacing all security controls

B. By automatically enforcing compliance regulations

C. By eliminating the need for sensitivity labels

D. By providing visibility into sensitive data and classification coverage

Answer: D

Explanation: Data Explorer supports governance efforts by helping organizations understand where sensitive information exists and whether appropriate classifications and protections are in place.


Exam Summary

Microsoft Purview Data Explorer is a discovery and analysis tool that helps organizations identify sensitive information across Microsoft 365. It uses Sensitive Information Types, trainable classifiers, sensitivity labels, and retention labels to provide visibility into data risks and governance gaps. Data Explorer is particularly important for compliance initiatives and Microsoft 365 Copilot readiness because it helps organizations understand what sensitive information exists, where it is stored, and whether it is properly protected. Understanding how Data Explorer identifies and reports sensitive information is an important objective for the AB-900 certification exam.


Go to the AB-900 Exam Prep Hub main page

Identify compliance risks and recommendations by using Microsoft Purview Compliance Manager (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Identify compliance risks and recommendations by using Microsoft Purview Compliance Manager


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Organizations today face increasing regulatory and compliance requirements related to data privacy, security, records management, and governance. Regulations such as GDPR, HIPAA, ISO 27001, NIST, PCI DSS, and many others require organizations to implement controls that protect sensitive information and demonstrate compliance.

Microsoft Purview Compliance Manager is a solution within Microsoft Purview that helps organizations assess, manage, and improve their compliance posture. It provides a risk-based approach to compliance by measuring how well an organization has implemented controls and by offering actionable recommendations to reduce compliance risks.

For the AB-900 exam, you should understand the purpose of Compliance Manager, how it identifies compliance risks, how compliance scores are calculated, and how organizations can use recommendations to improve their compliance posture.


What Is Microsoft Purview Compliance Manager?

Microsoft Purview Compliance Manager is a compliance management solution that helps organizations:

  • Assess compliance risks
  • Monitor compliance status
  • Track implementation of compliance controls
  • Improve regulatory compliance
  • Generate evidence for audits
  • Prioritize remediation efforts

Compliance Manager translates complex regulatory requirements into manageable improvement actions that administrators can implement within Microsoft 365.

Rather than simply reporting compliance status, Compliance Manager helps organizations actively improve compliance through continuous assessment and risk reduction.


Why Compliance Manager Is Important

Organizations must comply with numerous regulations and standards. Managing compliance manually can be difficult because:

  • Regulations frequently change
  • Multiple frameworks may apply simultaneously
  • Compliance controls span many systems
  • Evidence collection can be time-consuming
  • Auditors require documentation

Compliance Manager helps centralize compliance activities and provides visibility into compliance readiness.

Benefits include:

  • Reduced compliance risk
  • Improved governance
  • Simplified audit preparation
  • Better visibility into regulatory requirements
  • Continuous compliance monitoring
  • Prioritized remediation efforts

Understanding Compliance Risk

Compliance risk refers to the possibility that an organization fails to meet legal, regulatory, or internal policy requirements.

Examples include:

  • Improper handling of personal data
  • Missing security controls
  • Lack of retention policies
  • Inadequate access controls
  • Failure to encrypt sensitive information
  • Insufficient auditing and monitoring

Compliance Manager helps identify these risks by comparing organizational practices against compliance requirements.


Compliance Score

One of the most important concepts in Compliance Manager is the Compliance Score.

The Compliance Score is a measurement that reflects the organization’s progress toward meeting selected compliance requirements.

The score:

  • Is risk-based
  • Measures completed controls
  • Helps prioritize work
  • Changes as actions are completed

A higher score generally indicates that more compliance controls have been implemented.

However, the score does not guarantee compliance with a regulation. It serves as a management tool for tracking progress and reducing risk.


How Compliance Score Is Calculated

Compliance Manager assigns points to improvement actions.

Points are awarded when actions are completed.

Examples of actions include:

  • Enabling multifactor authentication
  • Configuring retention policies
  • Applying sensitivity labels
  • Enabling audit logging
  • Implementing access controls

Higher-risk controls typically receive more points because they contribute more significantly to risk reduction.


Assessments in Compliance Manager

An assessment measures compliance against a specific regulation, standard, or framework.

Examples include:

  • GDPR
  • ISO 27001
  • NIST
  • HIPAA
  • PCI DSS
  • Microsoft Data Protection Baseline

Each assessment contains:

  • Control objectives
  • Improvement actions
  • Testing guidance
  • Documentation requirements
  • Compliance status tracking

Organizations can use multiple assessments simultaneously.


Types of Controls

Compliance Manager evaluates different types of controls.

Microsoft-Managed Controls

These controls are implemented and managed by Microsoft.

Examples include:

  • Physical datacenter security
  • Infrastructure protections
  • Platform-level safeguards

Microsoft provides evidence showing how these controls are implemented.


Customer-Managed Controls

These controls are the responsibility of the organization.

Examples include:

  • MFA configuration
  • Retention policies
  • Access management
  • User training
  • Data classification

Administrators must implement and document these controls.


Shared Controls

Shared controls involve responsibilities divided between Microsoft and the customer.

Examples include:

  • Identity management
  • Security monitoring
  • Data protection configurations

Both parties contribute to compliance.


Improvement Actions

Improvement actions are recommendations that help organizations reduce compliance risk.

An improvement action typically includes:

  • Description of the requirement
  • Implementation guidance
  • Testing procedures
  • Documentation requirements
  • Risk impact

Examples include:

  • Enable multifactor authentication
  • Configure audit logging
  • Apply sensitivity labels
  • Restrict external sharing
  • Implement retention policies
  • Enable Data Loss Prevention policies

Completing improvement actions increases the compliance score.


Recommendations in Compliance Manager

Compliance Manager provides actionable recommendations that help organizations improve compliance.

Recommendations may involve:

Identity Security

Examples:

  • Enable MFA
  • Implement Conditional Access
  • Review privileged accounts
  • Use least-privilege access

Data Protection

Examples:

  • Configure sensitivity labels
  • Encrypt sensitive content
  • Implement DLP policies
  • Protect confidential information

Monitoring and Auditing

Examples:

  • Enable auditing
  • Review activity logs
  • Investigate suspicious behavior
  • Maintain audit records

Information Governance

Examples:

  • Create retention policies
  • Define retention labels
  • Manage records
  • Implement deletion schedules

Testing and Evidence Collection

Compliance Manager supports audit preparation through evidence collection.

Organizations can:

  • Upload documentation
  • Store screenshots
  • Attach policy documents
  • Record test results
  • Maintain audit evidence

This makes audits easier because evidence is stored alongside compliance controls.


Regulatory Templates

Compliance Manager includes built-in templates for many regulations and standards.

Examples include:

  • GDPR
  • HIPAA
  • ISO 27001
  • NIST CSF
  • SOC 2
  • PCI DSS

Templates reduce the effort required to build compliance programs from scratch.


Monitoring Compliance Over Time

Compliance is not a one-time activity.

Compliance Manager supports continuous monitoring by:

  • Tracking score changes
  • Updating assessment status
  • Identifying new risks
  • Monitoring action completion
  • Highlighting outstanding requirements

Organizations can regularly review their compliance posture and address gaps.


Compliance Manager and Microsoft 365 Copilot

As organizations adopt Microsoft 365 Copilot, governance and compliance become increasingly important.

Compliance Manager can help organizations:

  • Evaluate data protection readiness
  • Review access controls
  • Verify sensitivity label deployment
  • Assess retention policies
  • Confirm audit logging is enabled
  • Measure compliance maturity

These controls help ensure Copilot operates within established governance and compliance frameworks.


Key Exam Tips

For the AB-900 exam, remember:

  • Compliance Manager helps assess and improve compliance posture.
  • Compliance Score measures progress toward implementing controls.
  • Improvement actions provide recommendations for reducing risk.
  • Assessments measure compliance against regulations and standards.
  • Controls may be Microsoft-managed, customer-managed, or shared.
  • Compliance Manager supports evidence collection and audit readiness.
  • A higher Compliance Score indicates improved compliance posture but does not guarantee regulatory compliance.
  • Compliance Manager helps organizations identify and prioritize compliance risks.

Practice Exam Questions

Question 1

What is the primary purpose of Microsoft Purview Compliance Manager?

A. Create SharePoint sites automatically

B. Assess and improve an organization’s compliance posture

C. Replace Microsoft Defender

D. Manage Windows updates

Answer: B

Explanation: Compliance Manager helps organizations assess compliance risks, track controls, and improve compliance posture through assessments and recommendations.


Question 2

What does the Compliance Score primarily represent?

A. The number of licensed users

B. The percentage of completed support tickets

C. Progress toward implementing compliance controls

D. The amount of storage consumed

Answer: C

Explanation: Compliance Score measures the organization’s progress in implementing controls that reduce compliance risk.


Question 3

Which type of control is managed entirely by Microsoft?

A. Customer-managed control

B. Shared control

C. Administrative control

D. Microsoft-managed control

Answer: D

Explanation: Microsoft-managed controls are implemented and maintained by Microsoft, such as datacenter security and infrastructure protections.


Question 4

An administrator wants to increase the organization’s Compliance Score. What should they do?

A. Purchase more Microsoft licenses

B. Increase mailbox storage limits

C. Complete improvement actions

D. Delete old assessments

Answer: C

Explanation: Improvement actions contribute points to the Compliance Score and help reduce compliance risk.


Question 5

Which feature helps organizations prepare for audits?

A. Microsoft Forms

B. Evidence collection and documentation storage

C. Viva Engage

D. Power Automate approvals

Answer: B

Explanation: Compliance Manager allows organizations to upload documentation, screenshots, and evidence needed for audits.


Question 6

Which of the following is an example of a customer-managed control?

A. Physical datacenter security

B. Network backbone management

C. Global infrastructure redundancy

D. Configuring multifactor authentication

Answer: D

Explanation: Customers are responsible for implementing controls such as MFA, retention policies, and access controls.


Question 7

What is an assessment in Compliance Manager?

A. A financial audit report

B. A measurement of compliance against a regulation or standard

C. A SharePoint permission review

D. A Microsoft support case

Answer: B

Explanation: Assessments evaluate compliance requirements associated with regulations, standards, or frameworks.


Question 8

Which compliance framework could be evaluated using Compliance Manager?

A. HIPAA

B. DHCP

C. SMTP

D. DNS

Answer: A

Explanation: Compliance Manager includes templates and assessments for frameworks such as HIPAA, GDPR, ISO 27001, and NIST.


Question 9

What is the purpose of improvement actions?

A. To reduce compliance risk and guide remediation efforts

B. To create Teams channels automatically

C. To increase internet bandwidth

D. To manage printer deployments

Answer: A

Explanation: Improvement actions provide guidance for implementing controls that reduce compliance risk and improve compliance posture.


Question 10

Which statement about Compliance Score is correct?

A. A perfect score guarantees regulatory compliance.

B. The score measures storage utilization.

C. The score reflects progress toward implementing compliance controls but does not guarantee compliance.

D. The score only applies to Microsoft-managed controls.

Answer: C

Explanation: Compliance Score is a risk-based measurement of implemented controls and progress, but it does not guarantee compliance with any specific regulation.


Exam Summary

Microsoft Purview Compliance Manager is a risk-based compliance management solution that helps organizations assess regulatory requirements, identify compliance gaps, implement recommended controls, collect audit evidence, and continuously improve compliance posture. Understanding Compliance Score, assessments, improvement actions, and risk reduction recommendations is essential for success on the AB-900 exam and for administering Microsoft 365 and Copilot environments responsibly.


Go to the AB-900 Exam Prep Hub main page

Understand responsible AI principles (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Understand data security implications of Copilot
      --> Understand responsible AI principles


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

As organizations increasingly adopt artificial intelligence (AI) technologies such as Microsoft 365 Copilot and custom AI agents, it is essential that these systems are designed, deployed, and used responsibly. Responsible AI refers to the practice of developing and using AI systems in ways that are ethical, trustworthy, secure, transparent, and beneficial to individuals and society.

Microsoft has established a framework of Responsible AI principles that guide the development and operation of AI solutions, including Microsoft 365 Copilot. These principles help organizations maximize the benefits of AI while minimizing risks such as bias, privacy violations, misinformation, and security threats.

For the AB-900 exam, it is important to understand Microsoft’s Responsible AI principles and how they apply to Microsoft 365 Copilot and AI-powered business solutions.


What Is Responsible AI?

Responsible AI is the practice of designing, building, deploying, and managing AI systems in a way that:

  • Benefits people and organizations
  • Respects privacy and security
  • Promotes fairness
  • Provides transparency
  • Maintains accountability
  • Prevents harm

Responsible AI recognizes that AI systems can significantly influence business decisions, productivity, communication, and access to information. Therefore, safeguards must be implemented to ensure AI is used appropriately.


Why Responsible AI Matters

AI systems can create significant value, but they also introduce potential risks, including:

  • Biased or unfair outcomes
  • Exposure of sensitive information
  • Inaccurate or misleading responses
  • Security vulnerabilities
  • Regulatory compliance issues
  • Lack of transparency regarding AI-generated content

Responsible AI principles help organizations manage these risks while maintaining trust in AI technologies.


Microsoft’s Six Responsible AI Principles

Microsoft’s Responsible AI Standard is built around six core principles:

  1. Fairness
  2. Reliability and Safety
  3. Privacy and Security
  4. Inclusiveness
  5. Transparency
  6. Accountability

These principles guide Microsoft’s development of AI technologies, including Microsoft 365 Copilot.


Principle 1: Fairness

Fairness means AI systems should treat individuals and groups equitably and avoid unjust bias.

AI models may unintentionally learn patterns that reflect historical biases found in training data. Responsible AI practices aim to reduce these biases and ensure fair treatment.

Examples of Fairness

  • Recruiting systems should not favor candidates based on protected characteristics.
  • AI-generated recommendations should not systematically disadvantage specific groups.
  • Business decisions supported by AI should be evaluated for potential bias.

Copilot Example

If Copilot assists with content creation or summarization, organizations should review outputs to ensure they do not contain biased assumptions or discriminatory language.


Principle 2: Reliability and Safety

Reliability and Safety ensure AI systems perform consistently and operate as intended.

AI-generated responses may occasionally contain errors, hallucinations, or incomplete information. Organizations should implement safeguards to reduce risk.

Reliability Considerations

  • AI outputs should be reviewed before critical decisions are made.
  • Systems should be tested under various conditions.
  • Security controls should protect AI services from misuse.

Copilot Example

Users should verify important financial, legal, or regulatory information generated by Copilot before acting on it.


Principle 3: Privacy and Security

Privacy and Security focus on protecting data from unauthorized access and ensuring information is handled appropriately.

AI systems often process large amounts of organizational data. Strong security controls are essential.

Key Protections

  • Authentication and authorization
  • Encryption
  • Access controls
  • Data governance
  • Compliance policies

Copilot Example

Microsoft 365 Copilot respects existing permissions and uses permission trimming to ensure users only access authorized information.


Principle 4: Inclusiveness

Inclusiveness means AI systems should be accessible and useful to people with diverse abilities, backgrounds, and needs.

Inclusive design helps ensure that AI technologies benefit the widest possible range of users.

Examples

  • Accessibility support for individuals with disabilities
  • Multiple language capabilities
  • User experiences that accommodate diverse needs

Copilot Example

Copilot supports users through natural language interactions, helping make technology more accessible to individuals with varying technical skill levels.


Principle 5: Transparency

Transparency means users should understand when AI is being used and how AI-generated content is produced.

Organizations should be able to explain:

  • When content was AI-generated
  • What data sources influenced results
  • The limitations of AI outputs

Transparency in Copilot

Microsoft provides citations and references in many Copilot experiences to help users understand where information originated.

Users should recognize that AI-generated content may require validation and review.


Principle 6: Accountability

Accountability means humans remain responsible for AI systems and their outcomes.

AI should assist decision-making rather than replace human judgment.

Organizations should establish governance processes that define:

  • Who oversees AI usage
  • Who approves deployments
  • How risks are managed
  • How incidents are investigated

Copilot Example

Employees remain responsible for reviewing, validating, and approving content generated by Copilot before sharing or acting on it.


Responsible AI and Microsoft 365 Copilot

Microsoft 365 Copilot incorporates Responsible AI principles throughout its design.

Security and Privacy

Copilot:

  • Uses Microsoft Graph permissions
  • Enforces permission trimming
  • Respects sensitivity labels
  • Honors DLP policies

Transparency

Copilot often provides references and citations to source content.

Accountability

Users remain responsible for reviewing generated outputs.

Reliability

Grounding with Microsoft Graph helps improve response quality and relevance.


Human Oversight and AI

A key Responsible AI concept is human oversight.

Organizations should not blindly trust AI-generated outputs.

Users should:

  • Review AI-generated content
  • Verify factual accuracy
  • Check calculations
  • Confirm compliance requirements
  • Validate business recommendations

This is especially important when AI-generated content affects:

  • Customers
  • Financial decisions
  • Legal matters
  • Regulatory compliance
  • Healthcare outcomes

AI Hallucinations and Responsible Use

An AI hallucination occurs when an AI system generates information that sounds plausible but is inaccurate or fabricated.

Examples include:

  • Invented facts
  • Incorrect citations
  • Misinterpreted data
  • False conclusions

Responsible AI practices encourage users to:

  • Verify information
  • Cross-check important outputs
  • Use trusted source material
  • Apply human judgment

For the AB-900 exam, remember that Copilot can generate incorrect information and should not be considered infallible.


Responsible AI Governance

Organizations should establish governance processes for AI use.

Common governance activities include:

  • Defining AI usage policies
  • Monitoring AI systems
  • Reviewing AI-generated content
  • Managing compliance requirements
  • Auditing AI activities
  • Training users on responsible AI practices

Microsoft Purview and Microsoft Defender help organizations implement governance and security controls around AI usage.


Responsible AI and Compliance

Responsible AI also supports compliance with regulatory requirements and industry standards.

Examples include:

  • Data privacy regulations
  • Industry-specific compliance frameworks
  • Information protection policies
  • Data retention requirements

Microsoft 365 security and compliance tools help organizations align AI usage with these requirements.


Key Exam Tips

For the AB-900 exam, remember:

  • Responsible AI focuses on ethical, trustworthy, and secure AI use.
  • Microsoft’s six Responsible AI principles are:
    • Fairness
    • Reliability and Safety
    • Privacy and Security
    • Inclusiveness
    • Transparency
    • Accountability
  • Copilot incorporates Responsible AI principles into its design.
  • Permission trimming helps support privacy and security.
  • Human oversight remains essential when using AI-generated content.
  • AI-generated outputs can contain errors or hallucinations.
  • Transparency helps users understand AI-generated content.
  • Accountability remains with people and organizations, not the AI system itself.
  • Responsible AI governance helps reduce business and compliance risks.

Practice Exam Questions

Question 1

Which Microsoft Responsible AI principle focuses on ensuring AI systems do not unfairly disadvantage certain individuals or groups?

A. Fairness
B. Transparency
C. Accountability
D. Reliability and Safety

Answer: A

Explanation: Fairness seeks to minimize bias and ensure equitable treatment across individuals and groups.


Question 2

What is the primary goal of the Reliability and Safety principle?

A. Restrict access to Microsoft Graph
B. Ensure AI systems operate consistently and safely
C. Classify documents automatically
D. Eliminate the need for human oversight

Answer: B

Explanation: Reliability and Safety focus on ensuring AI systems function as intended and minimize harmful outcomes.


Question 3

Which Responsible AI principle emphasizes protecting sensitive data and preventing unauthorized access?

A. Inclusiveness
B. Privacy and Security
C. Transparency
D. Accountability

Answer: B

Explanation: Privacy and Security focus on safeguarding data through appropriate protections and controls.


Question 4

Which Responsible AI principle ensures that humans remain responsible for AI outcomes?

A. Fairness
B. Accountability
C. Inclusiveness
D. Reliability and Safety

Answer: B

Explanation: Accountability ensures that people and organizations maintain responsibility for AI system decisions and outcomes.


Question 5

Why is human oversight important when using Microsoft 365 Copilot?

A. Copilot cannot access Microsoft Graph
B. AI-generated content may contain inaccuracies or hallucinations
C. Copilot automatically deletes organizational data
D. Human oversight improves network performance

Answer: B

Explanation: AI systems can generate incorrect information, making human review and validation essential.


Question 6

Which Responsible AI principle focuses on making AI systems accessible to users with diverse backgrounds and abilities?

A. Privacy and Security
B. Transparency
C. Inclusiveness
D. Accountability

Answer: C

Explanation: Inclusiveness promotes accessibility and usability for a broad range of users.


Question 7

What is an AI hallucination?

A. A security breach caused by malware
B. A situation where AI generates inaccurate or fabricated information
C. A failure of multifactor authentication
D. An encrypted response from Microsoft Graph

Answer: B

Explanation: Hallucinations occur when AI generates information that appears plausible but is incorrect or fabricated.


Question 8

Which Responsible AI principle helps users understand how AI-generated content was produced?

A. Accountability
B. Fairness
C. Reliability and Safety
D. Transparency

Answer: D

Explanation: Transparency helps users understand AI processes, limitations, and content origins.


Question 9

How does Microsoft 365 Copilot support the Privacy and Security principle?

A. By bypassing permissions when generating responses
B. By ignoring compliance policies
C. By enforcing permission trimming and existing access controls
D. By storing all prompts publicly

Answer: C

Explanation: Copilot respects existing permissions and security controls, helping protect sensitive information.


Question 10

Which statement best reflects Responsible AI practices?

A. AI should replace all human decision-making.
B. AI-generated outputs should be accepted without review.
C. Accountability belongs entirely to the AI model.
D. Organizations should govern, monitor, and review AI usage.

Answer: D

Explanation: Responsible AI requires governance, oversight, monitoring, and human accountability for AI systems and their outputs.


Go to the AB-900 Exam Prep Hub main page

Understand how Copilot uses permissions and other controls in Microsoft 365, Microsoft Purview, and Microsoft Defender to protect against risks (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Understand data security implications of Copilot
      --> Understand how Copilot uses permissions and other controls in Microsoft 365, Microsoft Purview, and Microsoft Defender to protect against risks


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

One of the most important security concepts for the AB-900 exam is understanding how Microsoft 365 Copilot protects organizational data. Because Copilot can access and summarize information from across Microsoft 365, organizations must ensure that sensitive information remains protected and that users only receive information they are authorized to access.

Microsoft 365 Copilot does not operate independently of an organization’s security framework. Instead, it inherits and respects the security, compliance, governance, and protection controls already configured in Microsoft 365. These controls come primarily from:

  • Microsoft 365 permissions
  • Microsoft Entra ID
  • Microsoft Purview
  • Microsoft Defender
  • SharePoint and OneDrive security
  • Teams security controls

Together, these technologies ensure that Copilot delivers useful responses while minimizing the risk of unauthorized access, data leakage, compliance violations, and insider threats.


The Security Foundation of Copilot

Microsoft 365 Copilot is built on three key principles:

  1. Access only authorized data
  2. Respect existing security controls
  3. Apply compliance and governance policies automatically

Copilot does not create new permissions.

Instead, it uses the permissions already assigned to users and resources throughout Microsoft 365.

This means that if a user cannot access a file directly, they also cannot access that file through Copilot.


Permission Trimming: The Core Security Mechanism

The most important security concept related to Copilot is permission trimming.

Permission trimming ensures that Copilot only retrieves information the user is authorized to access.

When a user submits a prompt:

  1. Microsoft Graph searches organizational data.
  2. Existing permissions are evaluated.
  3. Unauthorized content is excluded.
  4. Only authorized information is sent to the large language model.

For example:

  • HR files are accessible only to HR employees.
  • Finance reports are accessible only to finance personnel.
  • Confidential legal documents remain restricted to legal teams.

If another employee asks Copilot about those documents, the information is not included in the response.


How Microsoft 365 Permissions Protect Data

Microsoft 365 permissions form the first layer of Copilot security.

Permissions are inherited from services such as:

  • SharePoint Online
  • OneDrive for Business
  • Microsoft Teams
  • Exchange Online
  • Microsoft Loop

Examples include:

SharePoint Permissions

Users can only access sites, libraries, folders, and files for which they have permissions.

OneDrive Permissions

Users can access their own files and content explicitly shared with them.

Teams Permissions

Copilot respects team membership and channel access.

Exchange Permissions

Emails and calendar data are only available to authorized users.

Because Copilot uses Microsoft Graph, these permissions are automatically enforced.


Role of Microsoft Entra ID

Microsoft Entra ID provides identity and access management for Microsoft 365.

Copilot relies on Entra ID to verify:

  • User identity
  • Group membership
  • Role assignments
  • Conditional Access policies
  • Authentication status

Entra ID ensures that only authenticated and authorized users can access Microsoft 365 resources.

Examples

A Conditional Access policy may require:

  • Multifactor authentication (MFA)
  • Compliant devices
  • Approved locations

If requirements are not met, users may be blocked from accessing Microsoft 365 resources and Copilot.


How Microsoft Purview Protects Data Used by Copilot

Microsoft Purview provides compliance, governance, and data protection controls.

Because Copilot works with organizational content, Purview protections automatically apply to data used by Copilot.


Sensitivity Labels

Sensitivity labels classify and protect content.

Common labels include:

  • Public
  • General
  • Confidential
  • Highly Confidential

Labels can enforce:

  • Encryption
  • Access restrictions
  • Watermarking
  • Content markings

If a document is protected by a sensitivity label, Copilot respects those protections.


Data Loss Prevention (DLP)

DLP policies help prevent sensitive information from being exposed.

Examples include:

  • Credit card numbers
  • Social Security numbers
  • Healthcare records
  • Financial information

DLP policies can:

  • Detect sensitive data
  • Block sharing
  • Generate alerts
  • Notify administrators

Copilot interactions remain subject to DLP protections.


Data Classification

Microsoft Purview can automatically classify content based on:

  • Sensitive information types
  • Trainable classifiers
  • Custom classifications

This classification helps organizations understand what information exists and where risks may be present.


Retention Policies

Retention policies ensure information is retained or deleted according to organizational requirements.

Copilot only works with content that remains available within Microsoft 365 according to retention settings.


Data Security Posture Management (DSPM) for AI

DSPM for AI helps organizations identify and reduce AI-related risks.

DSPM can:

  • Discover overshared content
  • Identify risky permissions
  • Detect exposure of sensitive data
  • Recommend remediation actions

This is especially important because Copilot may reveal risks that already exist due to improper permissions.


How Microsoft Defender Protects Copilot Environments

Microsoft Defender provides threat detection, prevention, and response capabilities.

Defender helps protect both the data Copilot accesses and the users interacting with Copilot.


Microsoft Defender XDR

Microsoft Defender XDR provides:

  • Cross-domain threat detection
  • Incident correlation
  • Security investigation
  • Automated response

It helps security teams identify attacks that may affect Copilot-accessible data.


Identity Protection

Microsoft Defender and Entra ID can detect:

  • Risky sign-ins
  • Credential theft
  • Impossible travel events
  • Suspicious account activity

Compromised identities can be blocked before attackers access Copilot.


Endpoint Protection

Microsoft Defender for Endpoint protects devices used to access Copilot.

It helps detect:

  • Malware
  • Ransomware
  • Unauthorized access attempts
  • Device compromise

Threat Intelligence

Microsoft Defender uses global threat intelligence to identify:

  • Known malicious actors
  • Emerging threats
  • Attack techniques

This helps reduce the likelihood that attackers gain access to sensitive organizational information.


Oversharing Risks and Copilot

Copilot does not create oversharing problems.

However, it can expose existing oversharing issues more efficiently.

For example:

If a confidential SharePoint folder has accidentally been shared with all employees:

  • Employees may not discover the folder manually.
  • Copilot may locate relevant content and summarize it.

Because of this, organizations should regularly review:

  • File permissions
  • Site permissions
  • Group memberships
  • Sharing settings

DSPM for AI helps identify these risks.


Security Controls Working Together

The protection of Copilot data relies on multiple layers:

Security LayerPurpose
Microsoft Entra IDIdentity verification and access control
Conditional AccessRestrict access based on risk and conditions
Microsoft 365 PermissionsControl resource access
Microsoft GraphApplies permission trimming
Microsoft PurviewGovernance, compliance, and data protection
Microsoft DefenderThreat detection and response
DSPM for AIAI-specific risk identification

These controls work together to create a secure AI environment.


Key Exam Tips

For the AB-900 exam, remember the following:

  • Copilot does not bypass existing permissions.
  • Permission trimming ensures users only see authorized content.
  • Microsoft Graph enforces access controls during data retrieval.
  • Microsoft Entra ID provides identity and access management.
  • Conditional Access can restrict Copilot access based on organizational policies.
  • Microsoft Purview protects data through sensitivity labels, DLP, classification, retention, and DSPM for AI.
  • Microsoft Defender protects identities, endpoints, and organizational resources from threats.
  • Copilot may reveal existing oversharing risks but does not create them.
  • DSPM for AI helps organizations identify and remediate AI-related data exposure risks.

Practice Exam Questions

Question 1

What security mechanism ensures that Copilot only retrieves information a user is authorized to access?

A. Endpoint isolation
B. Data retention
C. Data replication
D. Permission trimming

Answer: D

Explanation: Permission trimming evaluates a user’s permissions and excludes unauthorized content from Copilot responses.


Question 2

A user asks Copilot about a confidential HR document they do not have permission to view. What will happen?

A. Copilot summarizes the document anyway
B. Copilot requests administrator approval automatically
C. The document is excluded from the response due to permission trimming
D. The document is copied into the user’s OneDrive

Answer: C

Explanation: Copilot respects existing permissions and cannot retrieve content users are not authorized to access.


Question 3

Which Microsoft service provides the identity platform that Copilot relies on for authentication and authorization?

A. Microsoft Defender XDR
B. Microsoft Entra ID
C. Microsoft Purview Insider Risk Management
D. Microsoft Intune

Answer: B

Explanation: Microsoft Entra ID manages identities, authentication, authorization, and access controls for Microsoft 365 services.


Question 4

Which Microsoft Purview capability helps prevent sensitive information such as credit card numbers from being improperly shared?

A. Retention policies
B. Conditional Access
C. Privileged Identity Management
D. Data Loss Prevention (DLP)

Answer: D

Explanation: DLP policies detect and protect sensitive information by blocking or monitoring risky sharing activities.


Question 5

What is the primary purpose of sensitivity labels in Microsoft Purview?

A. Manage operating system updates
B. Monitor network performance
C. Classify and protect content based on sensitivity levels
D. Create backup copies of documents

Answer: C

Explanation: Sensitivity labels classify content and can apply protections such as encryption and access restrictions.


Question 6

Which Microsoft Purview solution helps organizations discover overshared content that may present AI-related risks?

A. Data Security Posture Management (DSPM) for AI
B. Microsoft Planner
C. Exchange Online Protection
D. Windows Defender Firewall

Answer: A

Explanation: DSPM for AI identifies sensitive data exposure risks and recommends remediation actions.


Question 7

How does Microsoft Defender help protect environments that use Copilot?

A. By creating user accounts automatically
B. By replacing Microsoft Entra ID permissions
C. By detecting threats, compromised identities, and suspicious activities
D. By bypassing DLP policies

Answer: C

Explanation: Microsoft Defender provides threat detection, investigation, and response capabilities that protect organizational resources.


Question 8

Which statement best describes the relationship between Copilot and oversharing?

A. Copilot automatically fixes overshared content
B. Copilot creates oversharing by default
C. Copilot ignores shared permissions entirely
D. Copilot may reveal existing oversharing issues because it can efficiently locate accessible content

Answer: D

Explanation: Copilot does not create oversharing problems but can make improperly shared content easier to discover.


Question 9

Which security control can require multifactor authentication before a user accesses Microsoft 365 resources and Copilot?

A. SharePoint version history
B. Conditional Access
C. Retention labels
D. Exchange journaling

Answer: B

Explanation: Conditional Access policies can require MFA, compliant devices, or other conditions before granting access.


Question 10

Which statement about Copilot security is correct?

A. Copilot has unrestricted access to all tenant data.
B. Copilot ignores Microsoft Purview protections.
C. Copilot only follows Microsoft Defender policies.
D. Copilot inherits existing Microsoft 365 permissions and compliance controls.

Answer: D

Explanation: Copilot respects permissions, security settings, compliance policies, and governance controls already configured within Microsoft 365.


Go to the AB-900 Exam Prep Hub main page

Understand how Microsoft Graph influences Copilot responses (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Understand data security implications of Copilot
      --> Understand how Microsoft Graph influences Copilot responses


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

One of the most important concepts for the AB-900 exam is understanding how Microsoft 365 Copilot generates responses. Many users assume that Copilot simply searches documents and emails. In reality, Microsoft 365 Copilot relies heavily on Microsoft Graph to provide personalized, context-aware, and permission-trimmed responses.

Understanding the relationship between Microsoft Graph and Copilot is essential because it explains why Copilot can provide relevant answers, summarize organizational information, and generate content based on a user’s work data while maintaining security boundaries.


What Is Microsoft Graph?

Microsoft Graph is Microsoft’s unified API and data layer that connects information across Microsoft 365 services.

It serves as a central gateway to organizational data stored in services such as:

  • Microsoft Outlook
  • Microsoft Teams
  • Microsoft SharePoint
  • Microsoft OneDrive
  • Microsoft Exchange Online
  • Microsoft Planner
  • Microsoft To Do
  • Microsoft Entra ID
  • Microsoft Loop
  • Microsoft Viva

Microsoft Graph not only stores references to data but also understands the relationships between people, files, meetings, emails, chats, and organizational activities.

Think of Microsoft Graph as the intelligence layer that helps Microsoft 365 understand:

  • Who users are
  • What content they can access
  • Which colleagues they work with
  • What meetings they attend
  • Which documents they frequently use
  • How information is connected across the organization

How Microsoft 365 Copilot Uses Microsoft Graph

Microsoft 365 Copilot combines:

  1. Large Language Models (LLMs)
  2. Microsoft Graph
  3. Microsoft 365 applications

When a user submits a prompt, Copilot does not rely solely on the LLM’s pre-trained knowledge.

Instead, Copilot uses Microsoft Graph to retrieve relevant organizational data and then grounds the LLM’s response using that data.

This process helps ensure responses are:

  • Relevant
  • Up-to-date
  • Personalized
  • Context-aware
  • Based on enterprise data

The Copilot Response Process

A simplified workflow looks like this:

Step 1: User Submits a Prompt

Example:

“Summarize the project status for the Contoso migration project.”


Step 2: Copilot Queries Microsoft Graph

Microsoft Graph searches organizational data that the user is permitted to access, including:

  • Project documents
  • Emails
  • Teams conversations
  • Meeting notes
  • SharePoint files

Step 3: Relevant Information Is Retrieved

Graph identifies content related to:

  • The project
  • Team members
  • Recent updates
  • Supporting documents

Step 4: Grounding Occurs

The retrieved business information is provided to the LLM.

This process is known as grounding.

Grounding helps ensure the response is based on actual organizational data rather than relying only on the model’s training data.


Step 5: Copilot Generates a Response

The LLM combines:

  • User prompt
  • Retrieved Graph data
  • Application context

to generate a final response.


What Is Grounding?

Grounding is one of the most important concepts for the AB-900 exam.

Grounding refers to supplying real organizational data from Microsoft Graph to the large language model before it generates a response.

Without grounding:

  • Responses could be generic
  • Information could be outdated
  • Answers would lack organizational context

With grounding:

  • Responses are more accurate
  • Responses are personalized
  • Responses reflect current business information

Why Microsoft Graph Improves Copilot Responses

Microsoft Graph helps Copilot provide responses that are:

Personalized

Different users receive different answers because they have access to different data.

Example:

A manager may receive a project summary containing budget information.

A team member may receive the same summary without budget details if they lack permission.


Context-Aware

Graph understands relationships between:

  • People
  • Teams
  • Projects
  • Meetings
  • Documents

Example:

When a user asks:

“What happened in yesterday’s meeting?”

Copilot can locate:

  • Meeting recordings
  • Meeting transcripts
  • Chat discussions
  • Shared files

and generate a summary.


Current

Unlike the LLM’s training data, Microsoft Graph accesses live Microsoft 365 information.

This allows Copilot to work with:

  • Today’s emails
  • Current documents
  • Recent chats
  • New meeting notes

Relevant

Graph helps prioritize information most closely related to the user’s work activities.

As a result, Copilot can identify content likely to be useful rather than searching randomly across the organization.


Microsoft Graph Connectors

Organizations often store information outside Microsoft 365.

Microsoft Graph Connectors allow external content to be indexed and accessed through Microsoft Graph.

Examples include:

  • ServiceNow
  • Salesforce
  • Confluence
  • Jira
  • File shares
  • Custom business systems

When properly configured, Copilot can use connected external data as part of its grounding process.

This expands the knowledge available to Copilot beyond Microsoft 365 content.


Security and Permission Trimming

A critical exam concept is that Microsoft Graph enforces existing permissions.

Copilot cannot bypass security controls.

This is called permission trimming.

When Graph retrieves data:

  • User permissions are evaluated.
  • Only accessible content is returned.
  • Unauthorized content is excluded.

As a result:

  • Copilot only sees what the user can see.
  • Users cannot retrieve restricted documents through Copilot.
  • Existing Microsoft 365 security controls remain in effect.

Examples of Microsoft Graph Influencing Copilot

Example 1: Meeting Summaries

Prompt:

“Summarize my meetings from this week.”

Graph provides:

  • Calendar events
  • Meeting transcripts
  • Chat messages
  • Shared files

Copilot generates a personalized summary.


Example 2: Document Creation

Prompt:

“Create a proposal using our latest marketing plan.”

Graph retrieves:

  • Marketing documents
  • Recent presentations
  • Strategy files

Copilot uses this information to draft the proposal.


Example 3: Team Updates

Prompt:

“What is the latest status of the migration project?”

Graph gathers:

  • Team conversations
  • Project files
  • Status reports
  • Meeting notes

Copilot generates an informed status summary.


Benefits of Microsoft Graph for Copilot

Microsoft Graph provides several advantages:

Better Accuracy

Responses are grounded in organizational data.

Personalization

Responses reflect the user’s work context.

Real-Time Information

Current business data can be used.

Security

Permission trimming protects sensitive information.

Cross-Application Insights

Information can be gathered from multiple Microsoft 365 services.


Key Exam Tips

For the AB-900 exam, remember:

  • Microsoft Graph is the data and relationship layer of Microsoft 365.
  • Copilot combines LLMs with Microsoft Graph data.
  • Grounding provides organizational data to improve response quality.
  • Microsoft Graph retrieves information from Microsoft 365 services.
  • Copilot respects existing permissions.
  • Permission trimming ensures users only receive data they are authorized to access.
  • Microsoft Graph Connectors can extend Copilot to external systems.
  • Microsoft Graph enables personalized and context-aware responses.

Practice Exam Questions

Question 1

What is the primary role of Microsoft Graph in Microsoft 365 Copilot?

A. Train large language models
B. Store Copilot prompts permanently
C. Provide organizational data and context for responses
D. Replace Microsoft Entra ID authentication

Answer: C

Explanation: Microsoft Graph provides organizational data and relationships that Copilot uses to generate personalized and grounded responses.


Question 2

What process occurs when Copilot uses organizational data to improve the accuracy of a response?

A. Classification
B. Grounding
C. Encryption
D. Federation

Answer: B

Explanation: Grounding is the process of supplying relevant organizational data from Microsoft Graph to the language model before generating a response.


Question 3

Which Microsoft 365 service helps Copilot understand relationships among people, files, meetings, and communications?

A. Microsoft Defender XDR
B. Microsoft Purview
C. Microsoft Intune
D. Microsoft Graph

Answer: D

Explanation: Microsoft Graph provides relationship intelligence across Microsoft 365 services and organizational data.


Question 4

A user asks Copilot to summarize a project. Which source is most likely retrieved through Microsoft Graph?

A. Public internet websites only
B. Operating system registry settings
C. Organizational emails, files, and chats the user can access
D. Device firmware information

Answer: C

Explanation: Microsoft Graph retrieves relevant Microsoft 365 content that the user is authorized to access.


Question 5

Why might two users receive different Copilot responses to the same prompt?

A. Microsoft Graph uses permission-trimmed access to data
B. Copilot randomly changes responses
C. Different users run different operating systems
D. Copilot ignores organizational security controls

Answer: A

Explanation: Responses depend on what data each user is authorized to access through Microsoft Graph.


Question 6

What is the benefit of grounding in Microsoft 365 Copilot?

A. Reduces storage requirements
B. Disables user permissions
C. Makes responses more relevant and based on current business data
D. Eliminates the need for Microsoft Graph

Answer: C

Explanation: Grounding helps ensure responses are accurate, contextual, and based on organizational information.


Question 7

Which statement best describes permission trimming?

A. Copilot grants temporary administrative access to users
B. Copilot can access all organizational content regardless of permissions
C. Permissions are evaluated only after a response is generated
D. Only content a user is authorized to access is available to Copilot

Answer: D

Explanation: Permission trimming ensures that Copilot only retrieves and uses data that the user already has permission to view.


Question 8

What can Microsoft Graph Connectors enable?

A. Replacement of Microsoft Entra ID
B. Access to external business data sources through Microsoft Graph
C. Automatic deletion of all external content
D. Disabling Microsoft 365 search

Answer: B

Explanation: Graph Connectors allow organizations to bring external content sources into Microsoft Graph for search and Copilot experiences.


Question 9

Which Microsoft Graph capability most directly helps Copilot create personalized responses?

A. Relationship awareness across users, documents, meetings, and activities
B. Operating system patch management
C. Network packet inspection
D. Hardware monitoring

Answer: A

Explanation: Microsoft Graph understands relationships among organizational resources and activities, enabling personalized responses.


Question 10

When a user submits a prompt to Microsoft 365 Copilot, what generally happens first?

A. Copilot immediately generates a response without retrieving data
B. The user’s device is scanned for malware
C. Microsoft Graph retrieves relevant authorized organizational information
D. All tenant data is copied into the language model

Answer: C

Explanation: Before generating a response, Copilot typically retrieves relevant data through Microsoft Graph to ground the response in current organizational context.


Go to the AB-900 Exam Prep Hub main page

Understand how Copilot accesses data (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Understand data security implications of Copilot
      --> Understand how Copilot accesses data


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

One of the most important concepts for the AB-900 exam is understanding how Microsoft 365 Copilot accesses and uses organizational data. Many organizations are excited about the productivity benefits of Copilot but also want assurance that sensitive information remains protected.

Microsoft 365 Copilot is designed to work within an organization’s existing Microsoft 365 security, compliance, identity, and permission boundaries. Rather than creating a separate copy of organizational data, Copilot accesses information that users already have permission to access.

Understanding how Copilot retrieves, processes, and presents data is critical for administrators responsible for security, governance, and compliance.


What Is Microsoft 365 Copilot?

Microsoft 365 Copilot is an AI-powered assistant that combines:

  • Large Language Models (LLMs)
  • Microsoft Graph
  • Microsoft 365 applications
  • Organizational data

Copilot helps users:

  • Draft documents
  • Summarize meetings
  • Analyze data
  • Generate presentations
  • Answer questions
  • Perform business tasks more efficiently

The intelligence of Copilot comes from combining AI reasoning with an organization’s business data.


The Three Main Components of Copilot Data Access

Microsoft 365 Copilot relies on three major components:

Large Language Models (LLMs)

LLMs provide:

  • Natural language understanding
  • Reasoning capabilities
  • Content generation
  • Summarization

The LLM interprets the user’s prompt and generates responses.


Microsoft Graph

Microsoft Graph serves as the bridge between Copilot and organizational data.

Microsoft Graph connects to resources such as:

  • Emails
  • Calendars
  • Teams chats
  • Teams meetings
  • SharePoint documents
  • OneDrive files
  • Contacts
  • Tasks

Graph provides context that allows Copilot to generate relevant and personalized responses.


Microsoft 365 Data

Copilot accesses information stored within Microsoft 365 services.

Examples include:

  • Exchange Online mailboxes
  • SharePoint sites
  • OneDrive content
  • Teams conversations
  • Meeting transcripts
  • Microsoft Loop content

This organizational content provides the business context used to answer user requests.


How Copilot Processes a User Request

When a user submits a prompt, several steps occur.

Step 1: User Enters a Prompt

Example:

“Summarize the latest project updates from my team.”


Step 2: Copilot Interprets the Request

The LLM analyzes:

  • User intent
  • Context
  • Required information

Step 3: Microsoft Graph Retrieves Relevant Data

Microsoft Graph searches content the user is authorized to access.

Potential sources include:

  • Emails
  • Documents
  • Teams messages
  • Meeting notes

Step 4: Security Permissions Are Checked

Before data is returned:

  • Existing permissions are evaluated
  • Access controls are enforced
  • Security boundaries remain intact

If a user cannot access content directly, Copilot cannot use it in a response.


Step 5: Response Generation

The LLM combines:

  • User prompt
  • Retrieved business data
  • Organizational context

A response is generated and returned to the user.


Copilot Respects Existing Permissions

One of the most important exam concepts is:

Copilot Does Not Grant Additional Access

Copilot only accesses information a user already has permission to access.

For example:

  • If User A can view a SharePoint document, Copilot may use that document.
  • If User B cannot view the document, Copilot cannot expose it.

Copilot does not bypass:

  • SharePoint permissions
  • OneDrive permissions
  • Teams permissions
  • Microsoft 365 security controls

A common Microsoft phrase is:

“Copilot honors existing permissions.”


Role of Microsoft Graph

Microsoft Graph is central to Copilot’s operation.

Microsoft Graph:

  • Connects Microsoft 365 services
  • Provides contextual information
  • Retrieves relevant content
  • Applies user permissions

Without Microsoft Graph, Copilot would not have access to organizational context.

Think of Microsoft Graph as the intelligence layer that helps Copilot locate relevant business information.


Grounding

A key Copilot concept is grounding.

Grounding means enriching AI responses with organizational data retrieved through Microsoft Graph.

Without grounding:

  • Responses are based primarily on general AI knowledge.

With grounding:

  • Responses include organization-specific information.

Example:

A user asks:

“What decisions were made during yesterday’s budget meeting?”

Copilot can retrieve:

  • Meeting transcripts
  • Notes
  • Shared documents

The response is grounded in actual organizational content.


Data Sources Used by Copilot

Common Microsoft 365 data sources include:

Exchange Online

Provides:

  • Emails
  • Calendars
  • Contacts

SharePoint Online

Provides:

  • Team documents
  • Knowledge repositories
  • Project files

OneDrive

Provides:

  • Personal work files
  • User-owned documents

Microsoft Teams

Provides:

  • Chat messages
  • Meeting transcripts
  • Channel conversations
  • Shared files

Microsoft Loop

Provides:

  • Collaborative workspaces
  • Shared project information

Security Boundaries and Data Access

Copilot operates within existing Microsoft 365 security boundaries.

These include:

  • User permissions
  • Group memberships
  • SharePoint access controls
  • Teams membership
  • Sensitivity labels
  • Conditional Access policies

Security controls continue to function exactly as they would without Copilot.


Copilot and Sensitivity Labels

Sensitivity labels remain effective when Copilot accesses content.

If a document is protected with a sensitivity label:

  • Existing protections remain in place.
  • Access restrictions continue to apply.
  • Users without permission cannot access protected information through Copilot.

This helps maintain compliance and data security.


Copilot and Data Loss Prevention (DLP)

Microsoft Purview DLP policies continue to protect data.

DLP can help:

  • Detect sensitive information
  • Restrict inappropriate sharing
  • Prevent data leakage

Copilot operates within these governance controls.


Copilot and Retention Policies

Retention settings remain active for Copilot-accessed content.

If content:

  • Is retained, Copilot may use it if the user has access.
  • Has been deleted according to retention policies, it generally becomes unavailable for Copilot use.

Organizations should understand that Copilot relies on content already stored in Microsoft 365.


Copilot and Identity Management

Microsoft Entra ID plays a critical role in determining what data Copilot can access.

Entra ID provides:

  • Authentication
  • Authorization
  • User identity verification
  • Access control enforcement

Every Copilot interaction is tied to an authenticated user identity.


Why Permission Management Matters

Because Copilot honors existing permissions, organizations should regularly review:

  • Excessive access rights
  • Oversharing
  • Legacy permissions
  • Inactive accounts
  • SharePoint permissions
  • Teams memberships

Poor permission management can expose information through both traditional access methods and Copilot.

Many organizations conduct permission reviews before deploying Microsoft 365 Copilot.


Data Privacy and Copilot

Microsoft states that organizational prompts, responses, and data used by Microsoft 365 Copilot:

  • Stay within the Microsoft 365 service boundary
  • Are protected by existing Microsoft 365 compliance controls
  • Are not used to train foundation models for other customers

This helps organizations maintain privacy and regulatory compliance.


Common Misconceptions

Misconception 1: Copilot Can See Everything

False.

Copilot only accesses data the current user is authorized to access.


Misconception 2: Copilot Creates New Security Risks by Itself

Not exactly.

Copilot exposes existing permission issues more visibly, but it does not bypass security controls.


Misconception 3: Copilot Stores Separate Copies of All Data

False.

Copilot primarily retrieves information from existing Microsoft 365 sources through Microsoft Graph.


Misconception 4: Copilot Ignores Compliance Controls

False.

Copilot respects:

  • Permissions
  • Sensitivity labels
  • DLP policies
  • Retention policies
  • Identity controls

Key Exam Takeaways

For the AB-900 exam, remember the following:

  • Microsoft 365 Copilot combines LLMs, Microsoft Graph, and Microsoft 365 data.
  • Microsoft Graph retrieves organizational information used to ground responses.
  • Copilot only accesses data a user is authorized to access.
  • Copilot honors existing permissions and access controls.
  • Authentication and authorization are enforced through Microsoft Entra ID.
  • SharePoint, OneDrive, Exchange, Teams, and other Microsoft 365 services provide Copilot’s data sources.
  • Sensitivity labels, DLP policies, and retention policies continue to apply.
  • Copilot does not bypass security boundaries.
  • Permission management is critical for successful Copilot deployments.
  • Grounding improves response quality by incorporating organizational data.

Practice Exam Questions

Question 1

What component connects Microsoft 365 Copilot to organizational data stored across Microsoft 365 services?

A. Microsoft Graph
B. Microsoft Defender XDR
C. Microsoft Intune
D. Azure Virtual Network

Answer: A

Explanation: Microsoft Graph retrieves organizational data and provides context that Copilot uses to generate responses.


Question 2

A user asks Copilot to summarize a document stored in SharePoint. What determines whether Copilot can access the document?

A. The user’s existing permissions to the document
B. Whether the document is larger than 100 MB
C. Whether Microsoft Defender is enabled
D. Whether the document was created in Word

Answer: A

Explanation: Copilot honors existing permissions and can only access content the user is already authorized to view.


Question 3

Which Microsoft 365 service is commonly used as a source of files that Copilot can reference?

A. Active Directory Domain Services
B. Hyper-V
C. SharePoint Online
D. DNS Manager

Answer: C

Explanation: SharePoint Online is a major repository for organizational documents and content accessed by Copilot.


Question 4

What is the purpose of grounding in Microsoft 365 Copilot?

A. Encrypting prompts before submission
B. Backing up user data automatically
C. Monitoring administrator activity
D. Enhancing AI responses with organizational data

Answer: D

Explanation: Grounding enriches AI-generated responses with relevant organizational information retrieved through Microsoft Graph.


Question 5

Which statement best describes how Copilot handles security permissions?

A. It grants temporary access to protected documents.
B. It bypasses SharePoint permissions when necessary.
C. It honors existing Microsoft 365 permissions.
D. It automatically makes all team content available.

Answer: C

Explanation: Copilot respects existing permissions and does not provide access to content users cannot already access.


Question 6

Which Microsoft service provides authentication and authorization for Copilot users?

A. Microsoft Entra ID
B. Microsoft Defender for Endpoint
C. Microsoft Purview Data Map
D. Microsoft Fabric

Answer: A

Explanation: Microsoft Entra ID authenticates users and enforces authorization decisions that determine accessible content.


Question 7

A company applies sensitivity labels to confidential documents. How does Copilot interact with those documents?

A. Copilot removes the labels before processing.
B. Copilot ignores label protections.
C. Copilot can share the documents with any employee.
D. Copilot continues to respect the protections enforced by the labels.

Answer: D

Explanation: Sensitivity labels remain effective and continue governing access to protected content.


Question 8

Which Microsoft 365 workload can provide meeting transcripts that Copilot may use when generating responses?

A. Microsoft Teams
B. Microsoft Project Server
C. Windows Server
D. Microsoft Endpoint Configuration Manager

Answer: A

Explanation: Teams meeting transcripts are one of the organizational data sources that Copilot can use when users have access.


Question 9

What happens when a user asks Copilot about information stored in a file they do not have permission to access?

A. Copilot grants temporary access.
B. Copilot can still summarize the file.
C. Copilot cannot access or expose the file’s contents.
D. Copilot sends an approval request automatically.

Answer: C

Explanation: Copilot enforces existing access controls and cannot retrieve information from content the user is not authorized to access.


Question 10

Why do organizations often review permissions before deploying Microsoft 365 Copilot?

A. Copilot requires every file to be reuploaded.
B. Overshared content may become more discoverable through AI-assisted interactions.
C. Copilot disables SharePoint security.
D. Microsoft Graph cannot function without permission reviews.

Answer: B

Explanation: Because Copilot honors existing permissions, organizations often review and reduce oversharing to ensure users only have access to appropriate information.


Go to the AB-900 Exam Prep Hub main page

Understand retention in Microsoft Purview (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Understand Microsoft Purview
      --> Understand retention


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Data is one of an organization’s most valuable assets. However, organizations must not only protect data but also manage how long it is kept and when it should be deleted. Regulatory requirements, legal obligations, business needs, and security concerns all influence data retention decisions.

Microsoft Purview provides comprehensive retention capabilities that help organizations retain, preserve, review, and dispose of information across Microsoft 365 services. Retention is a key component of information governance and records management.

For the AB-900 exam, it is important to understand the purpose of retention, the difference between retention policies and retention labels, and how Microsoft Purview helps organizations meet compliance and governance requirements.


What Is Retention?

Retention refers to the process of determining:

  • How long information should be kept
  • Whether information must be preserved
  • When information should be deleted
  • How organizations comply with legal, regulatory, and business requirements

Retention ensures that important information remains available when needed while reducing risks associated with keeping unnecessary data indefinitely.

Examples include:

  • Retaining financial records for seven years
  • Preserving employee communications during legal investigations
  • Automatically deleting outdated project documents
  • Maintaining business records for compliance purposes

Why Retention Matters

Organizations use retention solutions to achieve several goals:

Regulatory Compliance

Many industries have laws requiring data to be retained for specific periods.

Examples include:

  • Financial records
  • Healthcare records
  • Tax documentation
  • Legal contracts

Legal Protection

Organizations may need to preserve information for:

  • Litigation
  • Audits
  • Investigations
  • Regulatory reviews

Information Governance

Retention helps organizations:

  • Reduce data sprawl
  • Improve information quality
  • Eliminate outdated content
  • Manage storage costs

Security Improvement

Keeping unnecessary data increases risk.

Proper retention practices help:

  • Minimize exposure to breaches
  • Reduce attack surfaces
  • Remove outdated sensitive information

Retention in Microsoft Purview

Microsoft Purview provides retention solutions that work across Microsoft 365 services such as:

  • Exchange Online
  • SharePoint Online
  • OneDrive
  • Microsoft Teams
  • Microsoft 365 Groups
  • Viva Engage
  • Copilot-related content stored in Microsoft 365

Purview allows organizations to automatically:

  • Retain content
  • Delete content
  • Retain and then delete content

Retention Policies

A retention policy automatically applies retention settings to locations across Microsoft 365.

Administrators create policies that specify:

  • Where the policy applies
  • How long content is retained
  • What happens after the retention period ends

Example

A policy might:

  • Retain all Teams chat messages for 5 years
  • Automatically delete them afterward

Advantages

Retention policies:

  • Apply automatically
  • Require little user involvement
  • Work at scale
  • Provide consistent compliance

Retention Labels

Retention labels provide more granular control than retention policies.

A retention label can be assigned to individual items such as:

  • Documents
  • Emails
  • Files
  • Records

Labels can be applied:

  • Manually by users
  • Automatically by policies
  • Through sensitive information detection
  • Through trainable classifiers

Example

A document labeled “Financial Record” could:

  • Be retained for 7 years
  • Be declared a record
  • Be deleted after the retention period expires

Retention Policies vs. Retention Labels

FeatureRetention PolicyRetention Label
ScopeBroad locationsIndividual items
User involvementUsually noneMay require user action
GranularityLocation levelItem level
FlexibilityModerateHigh
Records managementLimitedStrong

A useful exam tip is:

Retention policies manage locations, while retention labels manage individual content items.


Retain, Delete, or Retain and Delete

Microsoft Purview supports three primary retention actions.

Retain Only

Content remains available throughout the retention period.

Example:

  • Retain employee records for seven years.

Delete Only

Content is automatically removed after a specified period.

Example:

  • Delete temporary files after one year.

Retain and Then Delete

Content is preserved for a retention period and then automatically removed.

Example:

  • Retain project documents for five years and delete afterward.

Records Management

Records management builds on retention by treating important information as official records.

Organizations can:

  • Declare content as records
  • Restrict modifications
  • Track lifecycle events
  • Preserve compliance evidence

Examples of records:

  • Legal contracts
  • Corporate policies
  • Regulatory filings
  • Financial statements

Retention labels are commonly used to manage records.


Retention and Microsoft Teams

Organizations increasingly need to manage communication data.

Purview retention can manage:

  • Teams chat messages
  • Channel messages
  • Meeting content
  • Shared files

Example:

An organization may retain all Teams conversations for three years to satisfy compliance requirements.


Retention and Exchange Online

Retention can be applied to:

  • Emails
  • Mailboxes
  • Calendar items
  • Contacts

Example:

All employee email messages are retained for seven years and deleted afterward.


Retention and SharePoint/OneDrive

Retention supports:

  • Documents
  • Libraries
  • Files
  • Collaboration content

Example:

Project documentation is retained for five years after project completion.


Retention and Microsoft 365 Copilot

Microsoft 365 Copilot uses organizational data stored in Microsoft 365.

Because Copilot accesses existing organizational content:

  • Retention policies continue to govern underlying data.
  • Retention labels remain effective.
  • Information governance policies still apply.
  • Deleted content generally becomes unavailable after retention requirements are fulfilled.

Organizations should ensure retention strategies are aligned with Copilot usage to maintain compliance and data governance.


Adaptive Scopes

Large organizations often need dynamic retention assignments.

Adaptive scopes allow administrators to target retention policies based on attributes such as:

  • Department
  • Geography
  • User type
  • Business unit

This reduces administrative effort and improves policy accuracy.


Retention and eDiscovery

Retention supports eDiscovery by ensuring content remains available during investigations.

Benefits include:

  • Preserving evidence
  • Supporting legal holds
  • Maintaining compliance records
  • Simplifying investigations

Retained content can remain available even if users attempt to delete it.


Retention Best Practices

Organizations should:

  1. Identify regulatory requirements.
  2. Define retention schedules.
  3. Use retention policies for broad coverage.
  4. Use retention labels for specific content.
  5. Regularly review retention settings.
  6. Apply least-privilege administration.
  7. Align retention with records management processes.
  8. Test policies before large-scale deployment.

Key Exam Takeaways

For the AB-900 exam, remember these important concepts:

  • Retention determines how long data is kept and when it is deleted.
  • Microsoft Purview provides retention policies and retention labels.
  • Retention policies apply broadly to locations and workloads.
  • Retention labels apply to individual content items.
  • Organizations can retain content, delete content, or retain and then delete content.
  • Retention supports compliance, governance, security, and legal requirements.
  • Records management relies heavily on retention labels.
  • Retention applies across Exchange Online, SharePoint, OneDrive, Teams, and other Microsoft 365 services.
  • Copilot content governance relies on the retention controls applied to underlying Microsoft 365 data.

Practice Exam Questions

Question 1

An organization wants all Teams chat messages retained for five years and then automatically deleted. Which Microsoft Purview capability should be used?

A. Sensitivity labels
B. Retention policy
C. Conditional Access
D. Insider Risk Management

Answer: B

Explanation: Retention policies can apply retention settings broadly across Microsoft 365 workloads such as Teams chats and automatically delete content after the retention period expires.


Question 2

What is the primary purpose of retention in Microsoft Purview?

A. Encrypt all files in Microsoft 365
B. Prevent users from sharing documents externally
C. Control how long information is preserved and when it is deleted
D. Monitor user productivity

Answer: C

Explanation: Retention helps organizations manage the lifecycle of information by determining how long content is kept and when it should be removed.


Question 3

Which statement best describes a retention label?

A. It applies retention settings to individual items such as emails and documents.
B. It blocks external access to files.
C. It enforces multifactor authentication.
D. It manages network security rules.

Answer: A

Explanation: Retention labels provide item-level retention management and can be applied to specific documents, emails, and records.


Question 4

A company wants users to classify certain documents as official records that cannot be easily altered. Which solution is most appropriate?

A. Adaptive scopes
B. Conditional Access policies
C. Microsoft Defender XDR
D. Retention labels with records management capabilities

Answer: D

Explanation: Retention labels can declare documents as records and enforce records management requirements.


Question 5

Which retention action preserves content during a specified period and then removes it automatically?

A. Retain only
B. Delete only
C. Retain and then delete
D. Archive only

Answer: C

Explanation: Retain and then delete ensures content remains available during the retention period before automatic deletion occurs.


Question 6

What is a key difference between retention policies and retention labels?

A. Retention policies only work with Exchange Online.
B. Retention labels apply to individual content items.
C. Retention labels cannot be automated.
D. Retention policies require user assignment.

Answer: B

Explanation: Retention labels provide item-level control, while retention policies generally apply to locations or workloads.


Question 7

An administrator wants a retention policy to automatically target users based on department membership. Which feature should be used?

A. Data Loss Prevention
B. eDiscovery
C. Sensitivity labeling
D. Adaptive scopes

Answer: D

Explanation: Adaptive scopes dynamically assign retention policies using organizational attributes such as department or location.


Question 8

Why is retention important for eDiscovery investigations?

A. It automatically encrypts evidence.
B. It prevents users from signing in.
C. It helps ensure relevant information remains available for review.
D. It removes all old content immediately.

Answer: C

Explanation: Retention preserves information that may be required for legal or regulatory investigations.


Question 9

Which Microsoft 365 workload can be governed by Microsoft Purview retention policies?

A. Microsoft Teams only
B. SharePoint Online only
C. Exchange Online only
D. Exchange Online, SharePoint Online, OneDrive, and Teams

Answer: D

Explanation: Retention policies support multiple Microsoft 365 workloads, including Exchange, SharePoint, OneDrive, and Teams.


Question 10

How does Microsoft 365 Copilot relate to retention policies?

A. Copilot bypasses all retention settings.
B. Copilot replaces retention labels.
C. Copilot uses underlying Microsoft 365 content that remains governed by retention controls.
D. Copilot automatically creates retention policies.

Answer: C

Explanation: Copilot accesses organizational data stored in Microsoft 365, and existing retention policies and labels continue to govern that content.


Go to the AB-900 Exam Prep Hub main page

Understand data classification in Microsoft Purview (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Understand Microsoft Purview
      --> Understand data classification in Microsoft Purview


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Data is one of an organization’s most valuable assets. However, not all data carries the same level of sensitivity or business value. Some information can be shared publicly, while other information must be protected because it contains financial records, intellectual property, customer data, healthcare information, or confidential business plans.

Microsoft Purview Data Classification helps organizations identify, categorize, and protect sensitive information throughout Microsoft 365. Data classification is a foundational capability that enables organizations to understand their data landscape, apply appropriate protections, meet compliance requirements, and securely adopt AI technologies such as Microsoft 365 Copilot.

For the AB-900 exam, it is important to understand how Microsoft Purview classifies data, the tools involved, and how classification supports security, compliance, governance, and AI readiness.


What Is Data Classification?

Data classification is the process of identifying and categorizing information based on its:

  • Sensitivity
  • Confidentiality
  • Regulatory requirements
  • Business value
  • Risk level

Classification allows organizations to answer questions such as:

  • Which files contain sensitive information?
  • Where is confidential data stored?
  • Who can access regulated data?
  • Which content should be protected or retained?
  • What data can Copilot safely access?

Microsoft Purview automates much of this process through built-in detection technologies.


Why Data Classification Is Important

Without data classification, organizations often struggle to:

  • Identify sensitive information
  • Apply consistent protections
  • Meet compliance requirements
  • Prevent data loss
  • Govern AI access to information

Benefits of data classification include:

  • Improved data visibility
  • Better security controls
  • Regulatory compliance
  • Reduced risk of data breaches
  • More effective data governance
  • Safer use of Microsoft 365 Copilot

Microsoft Purview Data Classification Components

Microsoft Purview uses several components to classify information.

Sensitive Information Types (SITs)

Sensitive Information Types are predefined patterns used to identify sensitive data.

Examples include:

  • Credit card numbers
  • Social Security numbers
  • Passport numbers
  • Driver’s license numbers
  • Bank account numbers
  • Tax identification numbers

Microsoft provides hundreds of built-in SITs covering numerous countries and regions.

Example

A document containing a U.S. Social Security Number may automatically be detected and classified as sensitive content.


Trainable Classifiers

Trainable classifiers use machine learning to identify content based on context rather than exact patterns.

Examples include:

  • Resumes
  • Source code
  • Contracts
  • Financial documents
  • Healthcare records
  • Intellectual property

Unlike SITs, trainable classifiers examine the meaning and context of content.

Example

A contract may be identified even if it does not contain a specific keyword or sensitive number.


Content Explorer

Content Explorer allows administrators to:

  • View classified content
  • See where sensitive data exists
  • Investigate data locations
  • Analyze classification results

This tool helps organizations understand their data environment.


Activity Explorer

Activity Explorer provides visibility into:

  • Labeling activities
  • Classification actions
  • DLP events
  • User interactions with sensitive data

Administrators can investigate how classified information is being used.


Types of Data Classification

Organizations typically classify data into categories such as:

ClassificationDescription
PublicInformation intended for everyone
GeneralEveryday business information
InternalInformation for employees only
ConfidentialSensitive business information
Highly ConfidentialCritical or restricted information

Organizations can customize classifications based on their requirements.


Classification and Sensitivity Labels

Data classification often works together with Sensitivity Labels.

Classification identifies the data.

Sensitivity labels protect the data.

Example

Microsoft Purview detects:

  • Credit card information
  • Customer account numbers

A sensitivity label is then automatically applied:

  • Confidential
  • Highly Confidential

The label can then:

  • Encrypt the file
  • Restrict access
  • Apply watermarks
  • Block unauthorized sharing

Automatic Data Classification

Microsoft Purview can automatically classify information using:

Pattern Matching

Detects predefined sensitive information.

Examples:

  • Credit card numbers
  • Social Security numbers
  • Passport numbers

Machine Learning

Uses trainable classifiers to recognize content types.

Examples:

  • Contracts
  • Legal documents
  • Source code

Keyword Detection

Identifies content based on specific words or phrases.

Examples:

  • Confidential
  • Internal Use Only
  • Proprietary Information

Data Classification and Microsoft 365 Copilot

Data classification is particularly important for Copilot deployments.

Organizations often ask:

What information can Copilot access?

Copilot respects:

  • User permissions
  • Sensitivity labels
  • Compliance controls

Proper data classification helps organizations:

  • Understand their data
  • Identify overshared content
  • Protect confidential information
  • Reduce AI-related risks

Classification improves confidence when deploying AI solutions.


Data Classification and Compliance

Many regulations require organizations to identify and protect sensitive information.

Examples include:

  • GDPR
  • HIPAA
  • PCI DSS
  • SOX
  • Various privacy laws

Microsoft Purview classification helps organizations:

  • Locate regulated data
  • Apply protections
  • Support audits
  • Demonstrate compliance

Data Classification and Data Loss Prevention (DLP)

Data classification works closely with DLP policies.

Process

  1. Purview identifies sensitive content.
  2. Content is classified.
  3. DLP policies evaluate the classification.
  4. Protective actions occur.

Examples:

  • Block file sharing
  • Restrict email transmission
  • Alert administrators
  • Notify users

Without classification, DLP cannot effectively identify sensitive content.


Data Classification and Insider Risk Management

Classified data helps Insider Risk Management identify risky activities involving:

  • Financial records
  • Intellectual property
  • Customer information
  • Confidential business data

This improves risk detection and investigation capabilities.


Common Data Classification Use Cases

Financial Information Protection

Detect:

  • Credit card numbers
  • Banking information
  • Tax records

Apply protection automatically.


Human Resources Data

Identify:

  • Employee records
  • Salary information
  • Performance reviews

Restrict access to authorized personnel.


Healthcare Information

Classify:

  • Patient records
  • Medical identifiers

Support HIPAA compliance.


Legal Documents

Detect:

  • Contracts
  • Legal agreements

Apply confidentiality protections.


Intellectual Property Protection

Identify:

  • Product designs
  • Research data
  • Source code

Prevent unauthorized sharing.


Key Exam Concepts

For the AB-900 exam, remember:

  • Data classification identifies and categorizes information.
  • Sensitive Information Types detect specific data patterns.
  • Trainable classifiers use machine learning and context.
  • Classification supports sensitivity labels and DLP.
  • Content Explorer helps locate classified content.
  • Activity Explorer helps investigate classification activity.
  • Classification is essential for compliance and governance.
  • Microsoft 365 Copilot benefits from proper data classification.
  • Classification enables automated protection policies.
  • Data classification improves organizational visibility into sensitive information.

Practice Exam Questions

Question 1

What is the primary purpose of data classification in Microsoft Purview?

A. To improve internet connectivity
B. To categorize information based on sensitivity and business value
C. To manage Windows updates
D. To configure virtual machines

Answer: B

Explanation: Data classification identifies and categorizes information so organizations can apply appropriate protections and governance controls.


Question 2

Which Microsoft Purview feature identifies information such as Social Security numbers and credit card numbers?

A. Activity Explorer
B. Sensitive Information Types
C. Compliance Manager
D. Insider Risk Management

Answer: B

Explanation: Sensitive Information Types (SITs) are designed to detect structured sensitive data using predefined patterns.


Question 3

Which technology enables Microsoft Purview to recognize contracts and resumes based on context?

A. Firewall policies
B. Sensitivity labels
C. Trainable classifiers
D. Conditional Access

Answer: C

Explanation: Trainable classifiers use machine learning and contextual analysis to identify content types.


Question 4

An administrator wants to see where sensitive information exists across Microsoft 365. Which tool should they use?

A. Microsoft Defender Portal
B. Teams Admin Center
C. Content Explorer
D. Exchange Admin Center

Answer: C

Explanation: Content Explorer provides visibility into classified content and its locations.


Question 5

What is the relationship between data classification and sensitivity labels?

A. They are unrelated technologies
B. Sensitivity labels identify data while classification encrypts it
C. Classification identifies data and labels protect it
D. Classification replaces sensitivity labels

Answer: C

Explanation: Classification discovers and categorizes information, while sensitivity labels apply protection settings.


Question 6

Which statement about Microsoft 365 Copilot is correct?

A. Copilot ignores classified information
B. Copilot respects permissions and protection controls associated with classified data
C. Copilot automatically removes sensitivity labels
D. Copilot bypasses governance policies

Answer: B

Explanation: Copilot honors existing permissions, labels, and compliance controls.


Question 7

Which Microsoft Purview feature allows administrators to investigate labeling and classification events?

A. Activity Explorer
B. Endpoint Manager
C. SharePoint Admin Center
D. Azure Monitor

Answer: A

Explanation: Activity Explorer provides visibility into classification-related activities and events.


Question 8

Which compliance-related benefit does data classification provide?

A. Faster network performance
B. Reduced storage costs only
C. Automatic hardware replacement
D. Easier identification and protection of regulated data

Answer: D

Explanation: Classification helps organizations locate and protect regulated information to support compliance requirements.


Question 9

A Data Loss Prevention (DLP) policy blocks sharing of files containing credit card numbers. What enables the DLP policy to identify those files?

A. Exchange transport rules only
B. Sensitive Information Types and data classification
C. Network firewalls
D. Device encryption

Answer: B

Explanation: DLP relies on classification mechanisms such as Sensitive Information Types to identify protected content.


Question 10

Which statement best describes trainable classifiers?

A. They only detect file names
B. They require manual review of every document
C. They identify information using contextual machine learning models
D. They replace all sensitivity labels

Answer: C

Explanation: Trainable classifiers use machine learning to recognize content such as contracts, source code, and resumes based on context rather than simple pattern matching.


Go to the AB-900 Exam Prep Hub main page

Identify the use cases for sensitivity labels in Microsoft Purview (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Understand Microsoft Purview
      --> Identify the use cases for sensitivity labels in Microsoft Purview


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction to Microsoft Purview Sensitivity Labels

Microsoft Purview Sensitivity Labels are classification and protection mechanisms that help organizations secure sensitive information across Microsoft 365. Labels enable organizations to identify important data and apply protections automatically or manually.

Sensitivity labels are part of Microsoft Purview Information Protection and support the principles of:

  • Data classification
  • Data protection
  • Compliance
  • Governance
  • Secure collaboration
  • AI readiness for Microsoft 365 Copilot

Instead of securing locations only, sensitivity labels secure the data itself, allowing protections to remain with content wherever it travels.


Why Sensitivity Labels Matter

Organizations often handle information with varying levels of confidentiality:

  • Public documents
  • Internal business data
  • Financial records
  • Human resources information
  • Customer data
  • Intellectual property
  • Legal documents

Sensitivity labels provide a consistent method for:

  • Identifying content sensitivity
  • Applying encryption
  • Restricting access
  • Adding visual markings
  • Preventing accidental exposure
  • Supporting compliance requirements

How Sensitivity Labels Work

A sensitivity label can be applied to:

  • Documents
  • Emails
  • Microsoft Teams
  • Microsoft 365 Groups
  • SharePoint sites
  • OneDrive content

Labels can be:

Manually applied

Users choose the appropriate label.

Automatically applied

Microsoft Purview detects sensitive information and assigns labels automatically.

Recommended

Users receive suggestions to apply a label.


Common Label Hierarchies

Organizations frequently create labels such as:

LabelIntended Audience
PublicAnyone
GeneralEmployees
InternalInternal users only
ConfidentialSpecific departments
Highly ConfidentialRestricted users

Labels are customizable and vary by organization.


Core Protection Capabilities

A sensitivity label may configure:

Encryption

Controls who can open content and what actions they can perform.

Examples:

  • View only
  • Edit allowed
  • Print blocked
  • Copy restricted

Content Markings

Visual indicators help users recognize sensitivity.

Examples:

  • Headers
  • Footers
  • Watermarks

Access Restrictions

Limits content access to:

  • Individuals
  • Groups
  • Departments
  • External users

Expiration Settings

Content access can expire after a specified period.


Major Use Cases for Sensitivity Labels

1. Protecting Confidential Documents

Organizations can label:

  • Financial statements
  • Contracts
  • Product designs
  • Strategic plans

Example:

A “Highly Confidential” label encrypts a document and restricts access to executives only.


2. Protecting Email Messages

Labels can secure email communication.

Example:

An HR manager sends salary information using a “Confidential – HR” label that:

  • Encrypts the email
  • Restricts forwarding
  • Prevents printing

3. Supporting Microsoft 365 Copilot

Copilot respects existing permissions and sensitivity labels.

If a document is labeled:

  • Confidential
  • Highly Confidential
  • Executive Only

Copilot only uses content that the user already has permission to access.

Sensitivity labels therefore help organizations prepare data safely for AI experiences.


4. Securing External Collaboration

Organizations can share files externally while maintaining protection.

Example:

A company sends a proposal to a partner:

  • External recipients can read it.
  • Forwarding is blocked.
  • Printing is disabled.

Protection travels with the document.


5. Meeting Regulatory Compliance Requirements

Sensitivity labels help support:

  • GDPR
  • HIPAA
  • Financial regulations
  • Privacy laws
  • Industry-specific requirements

Organizations can demonstrate that sensitive information receives appropriate protection.


6. Preventing Accidental Data Exposure

Users sometimes unintentionally send sensitive information.

Labels provide:

  • Classification awareness
  • Visual reminders
  • Automated protection

Example:

A user sending customer data receives an automatic recommendation to apply a Confidential label.


7. Protecting Intellectual Property

Engineering designs, research documents, and proprietary information can be restricted.

Example:

Only members of the Research department can access files labeled “R&D Confidential.”


8. Applying Visual Classification

Headers, footers, and watermarks immediately show sensitivity.

Examples:

  • INTERNAL USE ONLY
  • CONFIDENTIAL
  • HIGHLY CONFIDENTIAL

These markings help employees recognize handling requirements.


9. Labeling Containers

Sensitivity labels can be applied to:

  • Microsoft Teams
  • Microsoft 365 Groups
  • SharePoint sites

Container labels can control:

  • Guest access
  • Privacy settings
  • External sharing
  • Unmanaged device access

Example:

A Team labeled “Confidential Project” automatically disables guest access.


10. Supporting Data Loss Prevention (DLP)

Sensitivity labels integrate with Microsoft Purview DLP.

Example:

A DLP policy may block external sharing of content labeled “Highly Confidential.”

Labels and DLP together provide layered protection.


Manual vs Automatic Labeling

MethodDescription
Manual labelingUser chooses the label
Recommended labelingSystem suggests labels
Automatic labelingPurview assigns labels automatically

Automatic labeling reduces reliance on users and improves consistency.


Supported Workloads

Sensitivity labels work across:

  • Microsoft Word
  • Excel
  • PowerPoint
  • Outlook
  • Teams
  • SharePoint Online
  • OneDrive
  • Microsoft 365 Groups

Relationship Between Sensitivity Labels and Retention Labels

These labels serve different purposes:

Label TypePurpose
Sensitivity labelProtect and classify data
Retention labelGovern how long data is kept

Sensitivity labels answer:

“Who can access this?”

Retention labels answer:

“How long should we keep this?”


Benefits of Sensitivity Labels

Organizations gain:

  • Stronger data protection
  • Better compliance
  • Secure AI adoption
  • Reduced data leakage
  • Improved collaboration
  • Consistent classification
  • User awareness of sensitive data

AB-900 Exam Tips

Remember these key points:

  • Sensitivity labels protect the content itself, not just the storage location.
  • Labels can apply encryption, markings, and access restrictions.
  • Labels work across Microsoft 365 workloads.
  • Microsoft 365 Copilot honors sensitivity labels and permissions.
  • Labels can be manually or automatically applied.
  • Sensitivity labels and retention labels serve different purposes.
  • Labels integrate with DLP policies for additional protection.

Practice Exam Questions


Question 1

What is the primary purpose of Microsoft Purview sensitivity labels?

A. Monitor network traffic
B. Protect and classify data based on sensitivity
C. Manage software updates
D. Create backups

Answer: B

Explanation: Sensitivity labels classify information and apply protections such as encryption and access restrictions.


Question 2

Which Microsoft 365 service respects sensitivity labels when generating responses?

A. Microsoft DHCP
B. Windows Update
C. Hyper-V
D. Microsoft 365 Copilot

Answer: D

Explanation: Copilot honors both user permissions and sensitivity labels.


Question 3

Which capability can sensitivity labels provide?

A. Device firmware updates
B. Password resets
C. Encryption and access control
D. Network routing

Answer: C

Explanation: Labels can encrypt content and define who can access it.


Question 4

A company wants documents to display “CONFIDENTIAL” across every page. Which sensitivity label feature supports this?

A. Authentication logs
B. Retention policies
C. Device compliance
D. Watermarks and content markings

Answer: D

Explanation: Labels can add headers, footers, and watermarks.


Question 5

What type of information is commonly protected with sensitivity labels?

A. Product designs and financial reports
B. Printer drivers only
C. Operating system files only
D. DNS records

Answer: A

Explanation: Sensitive business information is a common use case.


Question 6

Which statement about automatic labeling is correct?

A. Users must always choose labels manually.
B. Labels only work with Outlook.
C. Purview can automatically apply labels based on detected sensitive information.
D. Automatic labeling disables encryption.

Answer: C

Explanation: Purview can detect sensitive content and assign labels automatically.


Question 7

Which object can receive a sensitivity label?

A. Microsoft Teams
B. Documents
C. Emails
D. All of the above

Answer: D

Explanation: Labels support files, emails, Teams, groups, and SharePoint sites.


Question 8

How do sensitivity labels differ from retention labels?

A. They are identical.
B. Sensitivity labels protect data, while retention labels control how long data is kept.
C. Retention labels encrypt content.
D. Sensitivity labels manage software deployment.

Answer: B

Explanation: Protection and lifecycle management are separate functions.


Question 9

Which Microsoft Purview feature commonly works together with sensitivity labels to prevent data leakage?

A. Windows Firewall
B. Azure Virtual Machines
C. Data Loss Prevention (DLP)
D. Active Directory Sites and Services

Answer: C

Explanation: DLP policies can use sensitivity labels to enforce protection rules.


Question 10

Why are sensitivity labels important for Microsoft 365 Copilot adoption?

A. They increase processor speed.
B. They replace permissions.
C. They eliminate identity management.
D. They help ensure AI accesses data according to existing protections.

Answer: D

Explanation: Copilot follows permissions and sensitivity labels, helping organizations safely enable AI experiences.


Go to the AB-900 Exam Prep Hub main page