Study guide for Exam AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals

Purpose of this document

This study guide should help you understand what to expect on the exam and includes a summary of the topics the exam might cover and links to additional resources. The information and materials in this document should help you focus your studies as you prepare for the exam.

Useful links Description
How to earn the certification Some certifications only require passing one exam, while others require passing multiple exams.
Certification renewal Microsoft associate, expert, and specialty certifications expire annually. You can renew by passing a free online assessment on Microsoft Learn.
Your Microsoft Learn profile Connecting your certification profile to Microsoft Learn allows you to schedule and renew exams and share and print certificates.
Exam scoring and score reports A score of 700 or greater is required to pass.
Exam sandbox You can explore the exam environment by visiting our exam sandbox.
Request accommodations If you use assistive devices, require extra time, or need modification to any part of the exam experience, you can request an accommodation.

About the exam

Some exams are localized into other languages, and those are updated approximately eight weeks after the English version is updated. If the exam isn't available in your preferred language, you can request an additional 30 minutes to complete the exam.

Note

The bullets that follow each of the skills measured are intended to illustrate how we are assessing that skill. Related topics may be covered in the exam.

Note

Most questions cover features that are general availability (GA). The exam may contain questions on Preview features if those features are commonly used.

Skills measured

Audience profile

As a candidate for this Microsoft Certification, you should be familiar with Microsoft 365, including core services, security, identity and access, data protection, and governance, along with Microsoft 365 Copilot and agents.

Additionally, you should be familiar with the admin centers used to access Microsoft 365 workloads, such as Exchange Online, SharePoint in Microsoft 365, Microsoft Teams, Microsoft Entra, and Microsoft Purview. You need to have experience with AI-driven productivity tools and modern IT management practices.

You must be able to identify the roles of the core features and objects available in Microsoft 365, such as users, groups, teams, sites, and libraries. Plus, you should understand the core security features of Microsoft 365, such as authentication methods, conditional access policies, and single sign-on (SSO).

Skills at a glance

  • Identify the core features and objects of Microsoft 365 services (30–35%)

  • Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)

  • Perform basic administrative tasks for Copilot and agents (25–30%)

Identify the core features and objects of Microsoft 365 services (30–35%)

Identify the core objects of Microsoft 365 services

  • Explain how license types assigned to users and groups affect access to Microsoft 365 features

  • Explore the organization configurations by using the Microsoft 365 admin center (domain names and org settings)

  • Identify the appropriate objects to configure by using the Exchange Online admin center (mailboxes and distribution lists)

  • Identify the appropriate objects to configure by using the SharePoint in Microsoft 365 admin center (sites, libraries, and folders)

  • Identify the appropriate roles and permissions for sites in SharePoint in Microsoft 365

  • Identify the appropriate objects to configure by using the Teams admin center (teams, channels, and policies)

Understand the Microsoft 365 security principles

  • Explain the core Zero Trust principles

  • Understand authorization

  • Understand authentication methods

  • Understand threat protection and intelligence

  • Understand features and capabilities of Microsoft Defender XDR

Identify the core security features of Microsoft 365 services

  • Understand features and capabilities of Microsoft Entra

  • Understand conditional access policies

  • Understand the purpose and benefits of SSO

  • Identify the appropriate security object to use in an organization (users and groups)

  • Identify the appropriate tools to troubleshoot common sign-in issues (multifactor authentication [MFA], conditional access, and risky sign-ins)

  • Interpret Identity Secure Score in Microsoft Entra ID

  • Use the appropriate tools to review audit logs for user and admin activity

  • Identify the role of Privileged Identity Management (PIM) in an organization

  • Understand App registrations and Enterprise apps

Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)

Understand Microsoft Purview

  • Understand features and capabilities of Microsoft Purview Information Protection, Microsoft Purview Data Loss Prevention (DLP), Microsoft Purview Insider Risk Management, Microsoft Purview Communication Compliance, Microsoft Purview Data Security Posture Management (DSPM) for AI, and Microsoft Purview Data Lifecycle Management

  • Identify the use cases for sensitivity labels in Microsoft Purview

  • Understand data classification in Microsoft Purview

  • Understand retention

Understand data security implications of Copilot

  • Understand how Copilot accesses data

  • Understand how Microsoft Graph influences Copilot responses

  • Understand how Copilot uses permissions and other controls in Microsoft 365, Microsoft Purview, and Microsoft Defender to protect against risks

  • Understand responsible AI principles

Identify data protection and governance risks for Microsoft 365 and Copilot

  • Identify compliance risks and recommendations by using Microsoft Purview Compliance Manager

  • Identify sensitive information by using Microsoft Purview Data Explorer

  • Identify risks by using Insider Risk Management

  • Identify and respond to alerts generated by Microsoft Purview DLP

  • Identify policy violations generated by Communication Compliance

  • Identify user activities reported by Microsoft Purview activity explorer

  • Discover and manage AI activity by using DSPM for AI

  • Search for files and emails by using Content search in Microsoft Purview eDiscovery

Identify and monitor oversharing in SharePoint in Microsoft 365

  • Identify the tools to troubleshoot oversharing in an organization

  • Run a data access governance report in SharePoint

  • Understand features and capabilities of SharePoint Advanced Management, including restricted site access

Perform basic administrative tasks for Copilot and agents (25–30%)

Understand features and capabilities of Copilot and agents

  • Compare the built-in capabilities of Copilot and agents

  • Compare Copilot monthly license model to pay-as-you-go, including SharePoint

  • Identify which Copilot features can be enabled or disabled

  • Identify use cases for Researcher

  • Identify use cases for Analyst

  • Identify use cases for custom agents

Perform basic administrative tasks for Copilot

  • Assign Copilot licenses

  • Monitor and manage Copilot pay-as-you-go billing policies

  • Monitor Copilot usage and adoption, including Copilot Analytics and the Microsoft 365 admin center

  • Manage prompts, including saving, sharing, scheduling, and deleting

Perform basic administrative tasks for agents

  • Identify how to configure user access to agents

  • Create an agent

  • Understand approval process for agents

  • Monitor agents, including usage, operational insights, and agent lifecycle, by working with the Microsoft 365 admin center and the Microsoft Power Platform admin center

Study resources

We recommend that you train and get hands-on experience before you take the exam. We offer self-study options and classroom training as well as links to documentation, community sites, and videos.

Study resources Links to learning and documentation
Get trained Choose from self-paced learning paths and modules or take an instructor-led course
Find documentation Microsoft 365 documentation
Microsoft 365 Copilot documentation
Microsoft 365 admin center help
Microsoft Purview documentation
Ask a question Microsoft Q&A | Microsoft Docs
Get community support Microsoft 365 Copilot community hub
Microsoft 365 community hub
Follow Microsoft Learn Microsoft Learn - Microsoft Tech Community
Find a video Exam Readiness Zone
Browse other Microsoft Learn shows