Microsoft study guide

How to pass Microsoft 365 Certified: Copilot and Agent Administration Fundamentals (AB-900)

17 min read3 domains coveredFree practice, no sign-up

Microsoft 365 Certified: Copilot and Agent Administration Fundamentals (AB-900) tests whether you can describe how Microsoft 365 Copilot and its agents fit into an organisation, and whether you understand the data-protection and administrative controls that keep them safe. It is a Fundamentals exam, so it asks you to recognise services, match a stated need to the right admin centre or Purview capability, and explain how Copilot honours the permissions that already exist. It does not ask you to configure a tenant end to end. It asks you to identify and to choose.

The exam is now generally available. It ran as a beta into early 2026, and a great deal of secondary material still calls it a beta and offers a discount code, but the certification page carries no beta label. Just as important, the skills-measured outline was refreshed on 22 July 2026, with revisions to the core Microsoft 365 objects, the core security features, and the SharePoint oversharing objective. Studying from the beta outline or pre-July material will teach you renamed products and a stale objective split, so anchor everything to the current outline.

It suits people who administer or plan for Microsoft 365 and Copilot: help-desk and junior administrators, IT decision-makers, security and compliance staff, and anyone rolling Copilot out to a workforce. No deep prior administration is required, although an hour spent in the Microsoft 365 admin center, the Microsoft Purview portal, and the Power Platform admin center makes the names concrete far faster than reading alone.

What makes AB-900 pass-or-fail is knowing which tool owns which job. The traps are not obscure edge cases; they are close-sounding capabilities that do different work. Which admin centre performs a task, sensitivity labels versus DLP versus retention, Compliance Manager versus Activity Explorer versus Content search, and above all the single most-tested idea in the exam: Copilot inherits the user's existing permissions, so an oversharing problem is a SharePoint permissions problem, never a Copilot toggle.

AB-900 is a recognition exam built on one governing idea: Copilot only surfaces what a user could already access, so control the data and the permissions and you control Copilot.

Difficulty

Foundational

Best for

Microsoft 365 and Copilot administrators and planners: help-desk and junior administrators, IT decision-makers, and security or compliance staff preparing to deploy and govern Copilot and agents across a workforce.

Prerequisites

None are enforced. A working familiarity with Microsoft 365 helps, and an hour spent in the Microsoft 365 admin center, the Microsoft Purview portal, the Microsoft Entra admin center, and the Power Platform admin center makes the admin-centre split concrete, but nothing is required.

Typically 40 to 60 questions
Questions
45 min
Time allowed
700 / 1000
Pass mark
$99
Exam cost (USD)
295
Practice questions

How this exam thinks

AB-900 frames most questions as a short administrative need and asks you to name the one admin centre, Purview capability, or control built for it. The decision rule is matching, not building: read what the scenario must achieve, then pick the tool whose job fits exactly and reject the close-sounding neighbour that does related but different work. Two rules resolve most items. First, scope: when two tools overlap, ask which object or which stage each one governs, because a capability that detects is wrong when the requirement was to prevent, and vice versa. Second, the permissions model: Copilot has no separate access model, it grounds answers in Microsoft Graph within the permissions the signed-in user already holds, so whenever Copilot surfaces something it should not, the fix lives in the data and its sharing, not in a Copilot setting. Microsoft expects you to favour the current, purpose-built tool named for the task, and to use current product names rather than the retired ones.

What each domain tests and how to study it

The AB-900 blueprint is split across 3 domains. Weights are the official share of the exam; see the official exam guide for the authoritative breakdown.

  1. Identify the core features and objects of Microsoft 365 services

    32% of exam

    What you must be able to do. Match a stated administrative task to the admin centre that performs it, and describe the core Microsoft 365 security principles and features, including Zero Trust, authentication versus authorisation, Microsoft Entra ID, conditional access, and Microsoft Defender XDR.

    In one sentenceThe foundation domain: which admin centre owns which object, and the identity and security building blocks (Entra ID, conditional access, Zero Trust, Defender XDR) that the rest of the exam leans on.

    Recall check: answer these from memory first
    • A stated task involves creating a shared mailbox, a distribution group, a SharePoint site, and a Teams policy. Name the admin centre for each.
    • State the difference between authentication and authorisation in one line, then say which one conditional access evaluates.
    • What is the difference between an App registration and an Enterprise app in Microsoft Entra ID?

    What it tests. The structure of Microsoft 365 and its security foundation. The core objects and the admin centre that configures each, matching a task to the Microsoft 365, Exchange, SharePoint, or Teams admin center, and how licence assignment to users and groups drives feature access; the security principles, including the Zero Trust model, the distinction between authentication and authorisation, authentication methods, and Microsoft Defender XDR; and the core security features, including Microsoft Entra ID, conditional access policies, single sign-on, choosing users or groups as the security object, troubleshooting sign-in failures across MFA, conditional access, and risky sign-ins, reading Identity Secure Score, Privileged Identity Management, and the difference between App registrations and Enterprise apps. This objective set was revised in the 22 July 2026 outline update.

    How to study it. Build the admin-centre map first, because it is the richest source of both correct answers and distractors: mailboxes and distribution groups live in the Exchange admin center, sites and libraries in the SharePoint admin center, teams and channels in the Teams admin center, and tenant-wide settings and licence assignment in the Microsoft 365 admin center. Then fix the identity vocabulary: authentication proves who you are, authorisation decides what you may reach, and conditional access evaluates signals to allow, block, or step up a sign-in, which is not the same as enrolling MFA. Learn to read a described sign-in failure and name the cause, whether it is a conditional access policy, a missing MFA method, or a risky sign-in. Keep current names straight: Azure AD is now Microsoft Entra ID.

    Easy to confuse

    • Conditional access versus multifactor authentication. Conditional access is the policy engine that evaluates signals such as user, device, location, and risk to allow, block, or require extra proof; MFA is one of the controls a conditional access policy can require. A sign-in blocked by policy is a conditional access outcome, not simply MFA being on.
    • App registrations versus Enterprise apps. An App registration defines an application's identity and configuration in your tenant where it was created; an Enterprise app is the local instance (service principal) of an application, including third-party ones, that you assign users and permissions to. One defines the app, the other governs its use in your tenant.
    • Authentication versus authorisation. Authentication verifies identity, confirming you are who you claim to be; authorisation determines what an authenticated identity is permitted to access. A password or MFA prompt is authentication; a role or permission check is authorisation.

    Worked example from the AB-900 bank

    Free sampleIdentify the core features and objects of Microsoft 365 serviceseasy

    An administrator needs to create shared mailboxes, configure mail flow rules, and manage email retention for the organisation. Which admin centre is purpose-built for these mailbox and mail flow tasks?

    • AExchange admin center Correct
    • BMicrosoft 365 admin center
    • CSharePoint admin center
    • DMicrosoft Purview portal
    The Exchange admin center is the console for mailboxes, mail flow rules, and messaging configuration. Mailboxes, shared mailboxes, transport rules, and messaging retention are Exchange Online objects, so they are administered in the Exchange admin center rather than the tenant-wide or content-focused centres.

    Why A is correct: The Exchange admin center is the dedicated console for mailboxes, mail flow rules, and messaging retention, so it is where shared mailboxes and transport rules are configured.

    Why B is wrong: This centre handles tenant-wide users, licences, and billing, and it links out to specialist centres, but shared mailboxes and mail flow rules are configured in the dedicated messaging centre rather than here.

    Why C is wrong: This centre manages sites, storage, and sharing policies for SharePoint, which is tempting because it also touches content, but it does not configure mailboxes or mail flow.

    Why D is wrong: This portal governs compliance, retention labels, and data protection across services, which sounds related to email retention, but it does not create mailboxes or set transport rules.

  2. Understand data protection and governance tasks for Microsoft 365 and Copilot

    38% of exam

    What you must be able to do. Map a stated data-protection or governance requirement to the right Microsoft Purview capability, explain how Copilot accesses data within existing permissions, and identify and monitor SharePoint oversharing before and after Copilot is deployed.

    In one sentenceThe heaviest domain: choosing the correct Purview capability for a requirement, and understanding that Copilot inherits user permissions so oversharing is the risk that must be governed.

    Recall check: answer these from memory first
    • Copilot showed a user a document they should not be able to see. What is the correct fix, and why is it not a Copilot setting?
    • Give the one-line job of sensitivity labels, DLP, and retention so none could be mistaken for another.
    • Which Purview tool assesses your compliance posture and recommends improvement actions, and which one shows what happened to labelled data?

    What it tests. Protecting and governing data across Microsoft 365 and Copilot. Microsoft Purview and the capability that meets a requirement, spanning Information Protection and sensitivity labels, Data Loss Prevention, Insider Risk Management, Communication Compliance, Data Security Posture Management for AI, and Data Lifecycle Management with retention; how Copilot accesses data, how Microsoft Graph and the semantic index shape its responses, how it honours existing permissions and Purview and Defender controls, and responsible AI principles; identifying governance risks with the right tool, choosing between Compliance Manager, Activity Explorer, Content search, DSPM for AI, and DLP alerts; and identifying and monitoring oversharing in SharePoint, including the data access governance report and SharePoint Advanced Management with restricted access control. The Copilot and oversharing objectives were revised in the 22 July 2026 outline update.

    How to study it. Anchor the whole domain to one sentence: Copilot surfaces only what the signed-in user could already open, so a Copilot data-exposure incident is an oversharing and permissions problem, and the fix is a SharePoint data access governance report or restricted access control, never a Copilot switch. Then separate the Purview capabilities by the job each is named for so they cannot be swapped: sensitivity labels classify and protect content, DLP prevents data leaving, retention keeps or deletes, Insider Risk Management watches risky user behaviour, and DSPM for AI discovers and manages AI activity. For the diagnosis tools, learn that each answers a distinct question: Compliance Manager scores your posture and recommends improvement actions, Activity Explorer shows what happened to labelled data, and Content search finds the content itself. Practise reading a requirement and picking prevent versus detect correctly.

    Easy to confuse

    • Sensitivity labels versus DLP versus retention. Sensitivity labels classify and can encrypt or mark content; Data Loss Prevention stops sensitive content from leaving through a channel; retention keeps or deletes content on a schedule. Classify, prevent egress, and keep-or-delete are three different jobs.
    • A Copilot oversharing incident versus a Copilot control. When Copilot surfaces a file a user should not see, the cause is that the user already had access to oversharing content, so the remedy is a SharePoint permissions or restricted access control fix. Copilot never has its own access model to toggle; it inherits the user's permissions.
    • Compliance Manager versus Activity Explorer versus Content search. Compliance Manager assesses posture and recommends improvement actions; Activity Explorer reports what happened to labelled or sensitive data; Content search locates the actual content for review or eDiscovery. Assess, observe, and find are distinct questions.

    Worked example from the AB-900 bank

    Free sampleUnderstand data protection and governance tasks for Microsoft 365 and Copilothard

    A governance lead asks how Microsoft 365 Copilot decides which documents it can use when answering a prompt. Which statement correctly describes the access model Copilot applies?

    • ACopilot uses the signed-in user's existing permissions and can only reference content that the user already has rights to open. Correct
    • BCopilot is granted a dedicated service identity with tenant-wide read access so it can reason over every document in the organisation.
    • CCopilot can read any file whose sensitivity label is lower than the user's clearance level, regardless of sharing permissions.
    • DCopilot indexes content under an administrator identity, then filters results to the user only at display time.
    Copilot inherits the signed-in user's existing permissions and surfaces only content that user could already access. Copilot resolves grounding data through Microsoft Graph in the user's own security context, so permission trimming occurs at query time and Copilot cannot expose files the user lacks rights to open.

    Why A is correct: Correct. Copilot has no access model of its own; it queries content through Microsoft Graph in the user's security context, so it surfaces only what that user could already retrieve.

    Why B is wrong: Tempting because Copilot can seem to 'know everything', but it holds no elevated tenant-wide identity; it always operates within the requesting user's permissions.

    Why C is wrong: Sensitivity labels influence protection and usage rights, but access is decided by the user's file permissions, not by a clearance comparison, so this is wrong.

    Why D is wrong: This sounds plausible given central indexing, but retrieval is trimmed by permission in the user's context during the query, not by a late display-time filter over admin-read data.

  3. Perform basic administrative tasks for Copilot and agents

    30% of exam

    What you must be able to do. Describe the features and licensing of Copilot and agents, and perform the basic administrative tasks for each, including licence assignment, pay-as-you-go billing, usage monitoring, prompt management, and the agent access, approval, and lifecycle across the Microsoft 365 and Power Platform admin centers.

    In one sentenceThe administration domain: the Copilot licensing models, the day-to-day Copilot admin tasks, and the two-admin-centre split that governs agent access, approval, and lifecycle.

    Recall check: answer these from memory first
    • State the difference between the Microsoft 365 Copilot monthly licence and pay-as-you-go billing, and when each applies.
    • List the stages of the agent lifecycle from creation to monitoring, and name the approval step.
    • Which admin centres are involved in administering agents, and what kind of agent task points you to the Power Platform admin center?

    What it tests. Running Copilot and agents day to day. The features and capabilities of Copilot compared with agents, the Microsoft 365 Copilot monthly licence compared with pay-as-you-go billing, which Copilot features can be enabled or disabled, and use cases for Researcher, Analyst, and custom agents; the basic Copilot administrative tasks of assigning licences, managing pay-as-you-go billing policies, monitoring usage and adoption through Copilot Analytics and the Microsoft 365 admin center, and managing prompts by saving, sharing, scheduling, and deleting; and the basic agent tasks of configuring user access, creating an agent, following the agent approval process, and monitoring agent usage and lifecycle across both the Microsoft 365 admin center and the Microsoft Power Platform admin center.

    How to study it. This domain is narrow but precise, so learn the exact boundaries. Fix the two billing models: the Microsoft 365 Copilot licence is a fixed per-user monthly subscription, while pay-as-you-go is metered consumption billed to an Azure subscription and governed by billing policies, and they are not interchangeable. Learn the agent lifecycle as a path from creation through an approval process to monitoring, and note the reliable trap that agent administration is split across the Microsoft 365 admin center and the Microsoft Power Platform admin center, so a question often turns on which centre performs the stated agent task. Match the built-in agents to their use, Researcher for deep multi-step research and Analyst for data analysis, and know that prompt management covers saving, sharing, scheduling, and deleting prompts.

    Easy to confuse

    • Copilot monthly licence versus pay-as-you-go. The Microsoft 365 Copilot licence is a fixed per-user monthly subscription assigned like any other licence; pay-as-you-go is metered usage billed to an Azure subscription through a billing policy. Predictable per-seat cost versus consumption-based billing are different models for different needs.
    • Researcher versus Analyst agent. Researcher is built for deep, multi-step research that reasons over work and web content; Analyst is built for data analysis, working through data to produce insights. One investigates a question broadly, the other crunches data.
    • Microsoft 365 admin center versus Power Platform admin center for agents. Broad Copilot and tenant tasks and some agent oversight sit in the Microsoft 365 admin center, while creating, approving, and managing the lifecycle of custom agents commonly runs through the Microsoft Power Platform admin center. The stated agent task tells you which centre owns it.

    Worked example from the AB-900 bank

    Free samplePerform basic administrative tasks for Copilot and agentsmedium

    An organisation runs a workload where employees only occasionally use a custom agent, and it wants to be charged for the consumption those interactions generate rather than committing to a fixed per-user subscription. Which Microsoft 365 Copilot commercial model matches this requirement?

    • AThe Microsoft 365 Copilot per-user monthly licence, which grants each assigned user unlimited use for a fixed recurring fee
    • BA Microsoft Entra ID P2 subscription, which includes Copilot agent usage as part of its identity governance features
    • CPay-as-you-go billing, which meters agent consumption and charges the organisation for the messages actually used Correct
    • DA Microsoft 365 E5 add-on that converts unused Copilot licences into consumption credits automatically
    Distinguish the fixed per-user Microsoft 365 Copilot licence from consumption-based pay-as-you-go billing for agents. Pay-as-you-go is a metered model that charges for the volume of agent messages consumed, which suits intermittent or unpredictable usage where a fixed per-user licence would be poor value.

    Why A is wrong: This is a real model and is tempting because it is the headline Copilot offer, but it charges a flat fee per assigned user regardless of usage, which is the opposite of paying only for occasional consumption.

    Why B is wrong: Entra ID P2 covers identity protection and governance such as Privileged Identity Management; it does not include or meter Copilot agent consumption, so it cannot fulfil the billing requirement.

    Why C is correct: Pay-as-you-go bills on metered consumption of agent messages, so an organisation with occasional use pays for what it consumes rather than a fixed per-user fee.

    Why D is wrong: This sounds plausible because E5 bundles many add-ons, but no such automatic licence-to-credit conversion add-on exists, making it an invented mechanism.

A study plan that works

  1. Map the current outline and book a date

    Day 1

    Read the three domains and their weights so you know where the marks are. Data protection and governance is the largest block, with core features and objects and Copilot and agent administration close behind. Confirm you are studying the outline refreshed on 22 July 2026, not older beta material, and treat this as a generally available exam rather than a beta. Book a provisional date now, because a fixed date turns vague study into a plan.

  2. Learn the admin-centre map and identity basics

    Week 1

    Start with core features and objects. Drill which admin centre owns which object until Exchange, SharePoint, Teams, and the Microsoft 365 admin center cannot be confused, since this matching skill recurs throughout the exam. Then lock the identity vocabulary: authentication versus authorisation, what conditional access evaluates, and how to read a described sign-in failure. Use current names, especially Microsoft Entra ID rather than Azure AD.

  3. Master the Copilot permissions model

    Week 2

    Spend real time on the single most-tested idea: Copilot grounds answers in Microsoft Graph and the semantic index within the permissions the user already holds, so it never has its own access model. Practise the oversharing scenario until the reflex is automatic: when Copilot surfaces something it should not, the fix is a SharePoint permissions or restricted access control change, never a Copilot toggle. This one idea earns a disproportionate share of the marks.

  4. Separate the Purview capabilities by job

    Weeks 2 to 3

    Work through Microsoft Purview by the job each capability is named for: sensitivity labels classify and protect, DLP prevents egress, retention keeps or deletes, and DSPM for AI discovers AI activity. Then drill the diagnosis tools, Compliance Manager to assess, Activity Explorer to see what happened, and Content search to find content, so you can pick prevent versus detect correctly under time pressure. Keep the renamed products straight, such as Microsoft Purview Information Protection rather than Azure Information Protection.

  5. Cover Copilot and agent administration

    Week 3

    Learn the two billing models, the monthly Copilot licence versus pay-as-you-go, and when each applies. Walk the agent lifecycle from creation through approval to monitoring, and fix the split between the Microsoft 365 admin center and the Power Platform admin center for agent tasks. Match Researcher, Analyst, and custom agents to their use cases, and cover prompt management, including saving, sharing, scheduling, and deleting.

  6. Practise on scenario questions and review the misses

    Week 4

    Move to mixed practice questions across all three domains and read the explanation on every one, including the questions you got right, watching for the close-sounding tool you nearly chose. Use your per-domain accuracy to attack the weakest area rather than re-reading what you already know, and revisit the recall prompts after a few days to space the review.

  7. Sit a timed mock and calibrate

    Week 4

    Take at least one full timed mock under exam conditions to rehearse pacing and the flag-and-return habit. Treat the result as a per-domain readiness signal rather than a single number, and review every missed question, naming the discriminator or admin centre you misread, before you book or sit the real exam.

Know when you're ready

Readiness for AB-900 is a measured score on practice questions you have not seen before, not a feeling that the service names look familiar. Re-reading notes builds recognition, and recognition feels like knowledge, so confidence rises while real recall lags behind. The honest test is whether you can read a fresh one-line need, name the single admin centre, Purview capability, or control that fits, and say why the close-sounding neighbour is wrong, and whether you can explain in your own words why a Copilot oversharing incident is fixed in SharePoint rather than in Copilot. If you can only nod along once the explanation is shown, you are not there yet. Aim to clear every one of the three domains comfortably on unseen questions across more than one sitting, trusting your per-domain accuracy over your gut. When all three domains read comfortably above the bar on questions you have never seen, you are ready to book.

Ready to put this into practice?

Free AB-900 questions, every answer explained. No sign-up.

Practise AB-900 free

Exam-day tips

  • Read the need first, then the options. AB-900 questions are short and usually name the exact job, so identify what is required before you weigh any admin centre or capability.
  • Beat the close-pair traps on scope and stage. When two tools overlap, ask which object each governs and whether the requirement is to prevent or to detect; a detective tool is wrong when the task was to prevent.
  • Treat every Copilot exposure question as an oversharing question. Copilot only surfaces what the user could already access, so the fix is a SharePoint permissions or restricted access control change, not a Copilot setting.
  • Use current product names. Azure AD is Microsoft Entra ID, Azure Information Protection is Microsoft Purview Information Protection, and the Compliance Center is the Microsoft Purview portal; a retired name signals a wrong option.
  • Know which admin centre owns the task, especially for agents. Agent administration is split between the Microsoft 365 admin center and the Power Platform admin center, and many items turn on that split.
  • Watch multiple-response questions. Some items ask you to select more than one correct answer, so read the instruction and pick every option that fits, not just the first good one.
  • Flag and move on. Cover every question once and collect the clear marks first, then return to the few that need thought rather than stalling early and losing easy points.

Frequently asked questions

Is AB-900 still a beta exam?

No. AB-900 is now generally available. It ran as a beta into early 2026, and a lot of secondary material still calls it a beta and offers a discount code, but the certification page carries no beta label. Study it as a live, generally available Fundamentals exam.

Which outline should I study, given the exam changed recently?

Study the skills-measured outline as refreshed on 22 July 2026. That update revised the core Microsoft 365 objects, the core security features, and the SharePoint oversharing objective, so older beta or pre-July material can teach renamed products and a stale objective split. Always work from the current outline.

Do I need Microsoft 365 administration experience before taking AB-900?

No experience is required and there are no enforced prerequisites. It is a Fundamentals exam. That said, an hour spent in the Microsoft 365 admin center, the Microsoft Purview portal, and the Power Platform admin center makes the admin-centre split concrete and sticks far better than reading alone, so it is worth doing.

What is the single most important idea on AB-900?

That Copilot inherits the user's existing permissions and surfaces only what that user could already access. It has no separate access model. This means a Copilot data-exposure incident is really an oversharing problem, and the correct fix lives in SharePoint permissions and governance, never in a Copilot toggle. Expect this to be tested repeatedly.

What kinds of questions does AB-900 ask?

Expect mostly multiple-choice and multiple-response questions framed as short scenarios or definitions. Many give a one-line administrative need and four similar tools, where three are plausible neighbours reached from the wrong admin centre or aimed at the wrong stage, and only one is built for the job, so rejecting the near-miss options is the core skill.

How long should I study for AB-900?

Most people are ready in two to four weeks of steady part-time study, and those already working in Microsoft 365 often need less. The time is best spent on the matching skill, learning to pick the one right admin centre or Purview capability for a stated need, and on the Copilot permissions model, rather than on memorising feature lists.

How should I judge when I am ready to book?

Use a measured score on practice questions you have not seen before, not a feeling of familiarity. When you can clear all three domains comfortably on unseen questions across more than one session, explain the oversharing fix in your own words, and a timed mock feels comfortable on pacing, you are ready; before that, keep drilling the close-pair discriminators and the admin-centre map.

Examworthy is not affiliated with or endorsed by Microsoft. This guide is original study material based on the public exam blueprint. We never reproduce live exam items. AB-900 and related marks belong to their respective owners.