Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Your organization has a Microsoft 365 subscription that contains a user named User1. User1 plans to leave your company in two weeks. You need to capture the activity of User1 to identify whether the user is exfiltrating data. Which Microsoft Purview solution should you use?
The correct answer is C. Insider Risk Management. Microsoft documents that Microsoft Purview Insider Risk Management helps organizations detect, investigate, and act on potentially risky internal activities, including data theft and data leakage. Microsoft specifically provides policy templates for departing users, describing scenarios where users who are leaving an organization might download files, print files, or copy data to personal cloud storage or messaging services near their resignation or end date. That matches this question exactly, where User1 is leaving in two weeks and you need to determine whether the user is exfiltrating data.
You use Microsoft 365 Copilot.
You need to schedule a prompt to run at midnight.
What task should you include in your solution?
Your organization has a Microsoft 365 E5 subscription.
You need to ensure that a third-party cloud service can authenticate to Microsoft Entra.
What should you configure?
The correct answer is D. an app registration. Microsoft Learn states that to delegate identity and access management functions to Microsoft Entra ID, an application must be registered with a Microsoft Entra tenant. When you register an application, you create its identity configuration in Microsoft Entra, and a corresponding service principal is created so the application can authenticate and integrate with the tenant. This is the standard Microsoft mechanism for allowing a third-party cloud service or app to authenticate to Microsoft Entra.
Your organization has a Microsoft 365 subscription.
All users are assigned Microsoft 365 Copilot licenses.
Some users report receiving Copilot responses that contain information from a Microsoft SharePoint site named Finance. The users report that the information is commercially sensitive.
You need to prevent Copilot from providing responses that contain information from the Finance site.
What should you do?
The correct answer is D. From the Finance site, configure permissions. Microsoft states that Microsoft 365 Copilot honors existing Microsoft 365 permissions and only grounds responses in content that the signed-in user is already allowed to access. That means if users are getting Finance-site content in Copilot responses, those users likely still have permission to that SharePoint content. The direct fix is to review and correct the site, library, folder, or file permissions on the Finance site so only the intended users retain access.
The other options do not directly solve this requirement. Information Barriers are designed for communication and collaboration segmentation scenarios, not for ordinary site-level oversharing remediation. A Defender data connector is unrelated to SharePoint permission enforcement. Conditional Access controls sign-in and session access conditions, but it does not selectively remove Copilot grounding from one SharePoint site for users who still have site permissions. Because Copilot uses SharePoint and Microsoft Graph permissions as its boundary, the Microsoft-documented corrective action is to fix the Finance site permissions.
Your organization has a Microsoft 365 E5 subscription.
You need to prevent users from sharing corporate financial data to external users. What should you use?
The correct answer is B. data loss prevention (DLP) policies. Microsoft Learn states that Microsoft Purview Data Loss Prevention helps organizations identify, monitor, and automatically protect sensitive information across Microsoft 365 locations such as Exchange, SharePoint, OneDrive, Teams, and devices. Microsoft specifically documents scenarios for preventing sensitive items from being shared with external users in SharePoint and OneDrive, and DLP policies can also block or restrict sharing based on sensitive information types, labels, or policy conditions. This is exactly the control used when the requirement is to stop users from sharing corporate financial data outside the organization.
Option A is incorrect because retention labels manage how long content is kept or deleted, not whether it can be shared externally. Option C is incorrect because role groups are used for permissions and administrative access delegation, not content-sharing prevention. Option D is incorrect because Insider Risk Management is designed to detect and investigate risky user behavior, not to directly block external sharing transactions in the way DLP policies do. For proactive enforcement of external-sharing restrictions on sensitive financial information, Microsoft's documented solution is DLP policies.
75 questions covering all exam domains, starting from $20
Exam domains verified against: Official Microsoft AB-900 exam guide, last checked September 2026.
Learn to identify and configure core Microsoft 365 objects like users, groups, teams, sites, and libraries across Exchange Online, SharePoint, and Teams admin centers. Understand how license types affect feature access and recognize the roles and permissions needed for managing these resources.
Sample question from this domain above: Q5
Master Zero Trust principles, authentication methods, authorization, and threat protection with Microsoft Defender XDR. This foundation supports secure administration of Microsoft 365 environments and protects against modern security threats.
Work with Microsoft Entra, conditional access policies, single sign-on, and Privileged Identity Management. Use audit logs and Identity Secure Score to monitor security posture and troubleshoot common sign-in issues in your organization.
Sample question from this domain above: Q2
Explore Microsoft Purview capabilities including Information Protection, DLP, Insider Risk Management, and Data Lifecycle Management. Understand how Copilot accesses data, uses Microsoft Graph, and respects permissions to protect against data risks while maintaining responsible AI practices.
Sample question from this domain above: Q3
Use Compliance Manager, Data Explorer, Insider Risk Management, and eDiscovery to identify sensitive information and policy violations. Discover and manage AI activity with Data Security Posture Management for AI and troubleshoot oversharing in SharePoint.
Run data access governance reports and use SharePoint Advanced Management to identify and respond to oversharing risks. Learn how restricted site access helps protect sensitive content from unauthorized distribution.
Compare built-in Copilot features and licensing models including monthly and pay-as-you-go options. Learn to assign licenses, monitor usage through Copilot Analytics, manage prompts, create agents, and configure user access using the Microsoft 365 and Power Platform admin centers.
Common questions about the exam itself