Free Microsoft AB-900 Exam Actual Questions & Explanations

Last updated on: Jul 26, 2026
Author: Julia Williams (Microsoft 365 Certification Specialist)

The AB-900 exam validates your foundational knowledge of Microsoft 365 Copilot and Agent Administration Fundamentals. This certification is designed for IT professionals and administrators who manage Microsoft 365 environments and need to understand how to administer Copilot features and agents effectively. This landing page provides a clear study roadmap, covering the core exam topics, question formats, and practical preparation strategies. Whether you're new to Microsoft 365 administration or expanding your certification portfolio, this guide helps you focus your study time on what matters most.

AB-900 Exam Syllabus & Core Topics

Use this topic map to guide your study for Microsoft AB-900 (Microsoft 365 Copilot and Agent Administration Fundamentals) within the Microsoft 365 path.

  • Identify the Core Features and Objects of Microsoft 365 Services: Candidates must recognize the key components of Microsoft 365, including Exchange Online, SharePoint Online, Teams, and OneDrive. You should understand how these services integrate, their primary use cases, and the role of Copilot within each environment. This foundation ensures you can navigate administrative tasks across the platform.
  • Perform Basic Administrative Tasks for Copilot and Agents: This topic covers hands-on administration of Copilot features and agent configurations in Microsoft 365. You'll learn to manage user access, configure agent settings, assign licenses, and monitor agent performance. Real-world examples include enabling Copilot in Teams, setting up agent permissions, and troubleshooting common configuration issues.
  • Understand Data Protection and Governance Tasks for Microsoft 365 and Copilot: Candidates must grasp how data protection policies, retention rules, and compliance frameworks apply to Copilot and agent operations. You should be able to configure data loss prevention (DLP) rules, manage information barriers, and ensure that Copilot respects organizational governance standards. This includes understanding how sensitive data is handled within AI-assisted workflows.

Question Formats & What They Test

The AB-900 exam uses multiple question formats to assess both conceptual knowledge and practical decision-making. Questions progress in difficulty and reflect real-world scenarios you'll encounter as a Microsoft 365 administrator.

  • Multiple Choice: Tests core definitions, feature behavior, service capabilities, and key terminology related to Microsoft 365 and Copilot. These items establish your foundational understanding of platform components.
  • Scenario-Based Items: Presents realistic administrative situations and asks you to select the best course of action. Examples include choosing the correct permission model for an agent, identifying which governance policy applies to a data handling scenario, or determining the appropriate service to use for a business requirement.
  • Configuration and Decision Items: Requires you to evaluate multi-step processes and determine the correct sequence or configuration approach. You may need to think through how to enable a feature, configure access controls, or implement a compliance requirement.

Questions increase in complexity as you progress, moving from recall and recognition to analysis and application of concepts in practical workflows.

Preparation Guidance

An effective study plan breaks the three core topics into manageable weekly goals, combines focused reading with hands-on practice, and includes regular self-assessment. Allocate study time proportionally to topic weight and your confidence level, then reinforce weak areas through targeted review and practice questions.

  • Map the three core topics to weekly study goals: Week 1 focus on Microsoft 365 service features and architecture; Week 2 on Copilot and agent administration tasks; Week 3 on data protection and governance. Track your progress against each objective.
  • Practice with question sets aligned to each topic; review explanations for both correct and incorrect answers to understand the reasoning behind each choice.
  • Connect concepts across administrative workflows: understand how service features enable Copilot deployment, how administrative tasks enforce governance, and how data protection policies constrain agent behavior.
  • Complete a timed mini-mock exam in your final week to build pacing confidence and identify any remaining knowledge gaps under test conditions.
  • Explore hands-on labs in Microsoft Learn to reinforce configuration tasks and gain practical familiarity with the admin centers and tools you'll reference during the exam.

Explore other Microsoft certifications: view all Microsoft exams.

Get the PDF & Practice Test

Strengthen your preparation with up-to-date resources from validexamdumps.com. These materials align to AB-900 and cover practical scenarios with clear explanations.

  • Q&A PDF with Explanations: Topic-mapped questions that clarify why correct options are right and others aren't, helping you build deeper understanding of each concept.
  • Practice Test: Realistic items in timed and untimed modes, with progress tracking and detailed review to pinpoint weak areas.
  • Focused Coverage: Aligned to core features and objects of Microsoft 365 services, basic administrative tasks for Copilot and agents, and data protection and governance tasks so you study what matters most.
  • Regular Updates: Content refreshes that reflect syllabus changes and product updates to Microsoft 365 and Copilot features.

Visit the exam page to download the PDF, Online Practice Test, or get a Bundle Discount offer for both formats: Microsoft 365 Copilot and Agent Administration Fundamentals.

Frequently Asked Questions

What topics carry the most weight on the AB-900 exam?

Data protection and governance tasks typically account for a significant portion of the exam, as they directly impact organizational compliance and risk management. Core features and administrative tasks are also heavily tested. A balanced study approach covering all three domains is recommended, with slightly more emphasis on governance and compliance scenarios.

How do Microsoft 365 service features, Copilot administration, and data governance connect in real workflows?

In practice, you first identify which Microsoft 365 service (Teams, SharePoint, Exchange) fits a business need, then enable and configure Copilot within that service, and finally apply governance policies to ensure data protection. For example, you might enable Copilot in a Teams channel, assign agent permissions, and then configure DLP rules to prevent sensitive data from being processed by the agent. Understanding these connections helps you make sound administrative decisions.

How much hands-on experience helps, and which labs should I prioritize?

Hands-on experience is valuable for building confidence with the admin centers and understanding configuration workflows. Prioritize labs that cover enabling Copilot in Teams, managing agent permissions in the Microsoft 365 admin center, and configuring basic DLP policies. These align directly to exam objectives and common real-world tasks.

What common mistakes lead to lost points on AB-900?

Candidates often confuse service-specific features (e.g., Teams vs. SharePoint Copilot capabilities) or misunderstand which governance policy applies to a given scenario. Another frequent error is overlooking the distinction between user-level and organization-level Copilot settings. Carefully read scenario details and pay attention to the scope of each question (user, team, organization) to avoid these pitfalls.

What pacing and review strategy works best in the final week?

In your final week, shift from learning new content to reinforcing weak areas and building test-taking speed. Complete one full-length practice test under exam conditions, review all incorrect answers, and spend remaining time on targeted review of topics where you scored lowest. Avoid cramming new material; instead, focus on solidifying your understanding and building confidence in your pacing.

Question No. 1

Your organization has a Microsoft 365 subscription.

You need to assign a license to a user.

What should you use?

Show Answer Hide Answer
Correct Answer: B

The correct answer is B. the Microsoft 365 admin center. Microsoft documents that administrators assign product licenses to users from the Microsoft 365 admin center, including on the Active users page where you can open a user account and manage Licenses and apps. Microsoft also documents license assignment workflows there for both direct assignment and group-based licensing scenarios. That makes the Microsoft 365 admin center the standard administrative portal for giving a user access to Microsoft 365 services and features.

The other options are incorrect for this task. The Microsoft Purview portal is used for compliance, governance, data protection, eDiscovery, audit, and related Purview solutions, not for assigning Microsoft 365 product licenses. The Microsoft Teams admin center is used to manage Teams settings, policies, devices, voice, and collaboration features, but it is not the central portal for assigning tenant product licenses to users.


Question No. 2

Your organization has a Microsoft 365 subscription.

All users have Microsoft 365 Copilot licenses.

You need to identify where sensitive content is being used during Copilot interactions, analyze the content usage patterns, and provide recommendations on applying the appropriate protections.

What should you use?

Show Answer Hide Answer
Correct Answer: B

The correct answer is B. the Microsoft Purview DSPM for AI solution. Microsoft documents that Data Security Posture Management for AI (DSPM for AI) in Microsoft Purview provides a central place to secure data for AI apps and proactively monitor AI use, including Copilots and agents. Microsoft also states that DSPM for AI helps organizations identify where sensitive content is used in AI interactions, review Copilot prompts and responses, analyze usage patterns, assess exposure and oversharing risks, and get recommendations for protections such as sensitivity labels and DLP policy coverage.

The other options do not fit this requirement. Microsoft Viva Insights focuses on productivity and work-pattern analytics, not sensitive-data protection in Copilot interactions. Microsoft Security Copilot is a security assistant for analysts, not the Purview governance solution that analyzes sensitive content use in Copilot and recommends data protections. Insider Risk Management is for identifying risky user behavior, not for broad AI interaction posture analysis and protection recommendations. Microsoft specifically positions DSPM for AI as the ''front door'' for discovering, monitoring, and protecting AI-related data usage in Microsoft 365 Copilot.


Question No. 3

Your organization has a Microsoft 365 subscription.

You need to review the impact of a recent phishing incident that targeted email users.

What should you use?

Show Answer Hide Answer
Correct Answer: A

The correct answer is A. the Microsoft Defender portal. Microsoft documents that phishing investigation and analysis for email threats is handled in Microsoft Defender for Office 365 through the Microsoft Defender portal. Microsoft's phishing investigation guidance and email security reporting both point admins to Defender capabilities such as Threat Explorer, campaign views, and phish reports to understand the scope, affected users, and impact of phishing attacks.

The other options are not the primary investigation tool for this scenario. The Microsoft 365 admin center is mainly for tenant administration and usage reporting, not detailed phishing impact investigation. The Microsoft Entra admin center focuses on identity and access management, not email threat analysis. The Exchange admin center manages mail flow and Exchange settings, but Microsoft's current phishing investigation workflows are centered in the Microsoft Defender portal, where security analysts can review detections, remediation actions, and affected recipients.


Question No. 4

Your organization has a Microsoft 365 subscription.

You need to generate a report that shows the permissions and active sharing links of content stored in Microsoft OneDrive accounts.

What should you use?

Show Answer Hide Answer
Correct Answer: A

The correct answer is A. Data access governance in the SharePoint admin center. Microsoft Learn documents Data access governance reports in the SharePoint admin center as the reporting solution used to understand data exposure, including permission structure and sharing link activity. Microsoft specifically states that the site permissions snapshot report provides visibility across SharePoint and OneDrive sites, helping administrators understand current permissions exposure, and that separate reports are created for SharePoint and OneDrive. Microsoft also documents sharing links activity reports as part of Data access governance for monitoring link-sharing activity, and notes that OneDrive support is available through PowerShell for those reports. Together, this is the Microsoft reporting capability aligned with permissions and active sharing links for OneDrive content.

The other options do not fit this requirement. Microsoft 365 admin center reports focus mainly on usage and activity reporting, not detailed permissions and sharing-link governance. Defender Audit is for security investigation activity, and Purview eDiscovery is for legal and investigative content search, not for generating OneDrive permissions and sharing-link governance reports. Therefore, the best Microsoft-documented answer is Data access governance in the SharePoint admin center.


Question No. 5

Your organization has a Microsoft 365 subscription.

All users are assigned Microsoft 365 Copilot licenses.

Some users report receiving Copilot responses that contain information from a Microsoft SharePoint site named Finance. The users report that the information is commercially sensitive.

You need to prevent Copilot from providing responses that contain information from the Finance site.

What should you do?

Show Answer Hide Answer
Correct Answer: D

The correct answer is D. From the Finance site, configure permissions. Microsoft states that Microsoft 365 Copilot honors existing Microsoft 365 permissions and only grounds responses in content that the signed-in user is already allowed to access. That means if users are getting Finance-site content in Copilot responses, those users likely still have permission to that SharePoint content. The direct fix is to review and correct the site, library, folder, or file permissions on the Finance site so only the intended users retain access.

The other options do not directly solve this requirement. Information Barriers are designed for communication and collaboration segmentation scenarios, not for ordinary site-level oversharing remediation. A Defender data connector is unrelated to SharePoint permission enforcement. Conditional Access controls sign-in and session access conditions, but it does not selectively remove Copilot grounding from one SharePoint site for users who still have site permissions. Because Copilot uses SharePoint and Microsoft Graph permissions as its boundary, the Microsoft-documented corrective action is to fix the Finance site permissions.