What AB-900 measures in 2026
Exam AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals validates a broad administrative foundation. The name emphasizes Copilot and agents, but the blueprint begins with ordinary Microsoft 365 objects and security. That ordering is practical. A Copilot response can be only as appropriately scoped as the user's identity and effective access. An agent can be only as governable as its owner, audience, knowledge sources, permissions, actions, monitoring, and retirement process.
The official skills measured as of July 22, 2026 contain three domains. Identifying core Microsoft 365 features and objects accounts for 30-35%. Understanding data protection and governance tasks for Microsoft 365 and Copilot is the largest domain at 35-40%. Performing basic Copilot and agent administration accounts for 25-30%. Use these ranges to allocate study time, but do not isolate the domains. Many realistic scenarios deliberately cross them: a licensed pilot user signs in through Microsoft Entra, queries Copilot, receives Microsoft Graph-grounded content from SharePoint, and leaves audit and data-protection evidence in Microsoft Purview.
The audience profile expects familiarity with the Microsoft 365, Exchange, SharePoint, Teams, Microsoft Entra, and Microsoft Purview administration experiences. You do not need to become a specialist in every workload, but you should identify the correct object and control plane. The five-phase PrepKloud AB-900 roadmap turns those relationships into a study sequence.
Start with Microsoft 365 objects, not AI terminology
A strong AB-900 candidate can explain what a license changes. A direct or group-based assignment can enable eligible service plans for a user, but a license is not a permission to every site, mailbox, team, or document. When a group assignment is removed and no other assignment supplies a service, access can be removed after licensing processing. Keep the license question separate from the authorization question.
In Exchange Online, distinguish a user or shared mailbox from a distribution group. A group distributes messages to members. A shared mailbox gives authorized people a common mailbox and sending identity. In SharePoint, a site is a broader collaboration boundary, a document library stores and manages files, and folders optionally organize items. Site roles, group membership, sharing links, inherited permissions, and unique item permissions all contribute to effective access.
Teams adds another relationship. Standard channel files use the SharePoint site connected to the team. Private and shared channels use separate SharePoint sites. That detail becomes important during an oversharing review: correcting the parent team-connected site does not automatically correct every channel site. Teams policies control workload behavior, but they do not replace SharePoint content permissions.
Practice navigating by question. Domains and organization settings belong in the Microsoft 365 admin center. Mailboxes and distribution groups belong in Exchange administration. Sites and access governance belong in SharePoint administration. Teams, channels, meetings, and Teams policies belong in Teams administration. Shortcuts between centers can exist, and visible settings depend on licenses and roles, so learn the responsibility rather than a brittle sequence of clicks.
Build an identity-first security model
Microsoft's Zero Trust principles are verify explicitly, use least privilege access, and assume breach. They provide a reasoning framework for exam scenarios. Verify explicitly means evaluating available identity, device, location, risk, service, and data signals. Least privilege favors narrow permissions, just-in-time administration, and limited duration. Assuming breach means containing blast radius, monitoring behavior, protecting data, and preparing to investigate.
Authentication verifies identity; authorization determines permitted actions. Multifactor authentication strengthens the authentication process. Single sign-on can reduce repeated prompts by allowing an authenticated identity to access connected services under applicable policy. Conditional Access acts as a policy engine: it evaluates assignments and conditions, then applies grant or session controls. Safe deployment includes understanding service dependencies, excluding emergency access accounts appropriately, testing in report-only mode when available, and reviewing results before enforcement.
When a sign-in is blocked, do not infer the cause from the user's description. Microsoft Entra sign-in logs show authentication details, risk, and Conditional Access results. Risky sign-in views and Identity Protection evidence help with risk-based scenarios. Audit logs answer who changed an object or configuration. Identity Secure Score supplies posture recommendations; it is not a guarantee that the tenant is secure.
Privileged Identity Management supports eligible and time-bound role access, approvals, notifications, and reviews where configured. It reduces standing privilege but does not eliminate authentication or oversight. Also distinguish app registrations from enterprise applications. The registration defines an application object, while the enterprise application represents a service principal—an application instance in a tenant used for assignments, consent, and sign-on administration.
Microsoft Defender XDR contributes cross-domain detection and response by correlating supported signals from identities, endpoints, email, applications, and cloud services. Know its role without assuming every tenant has every connected product or automated action. Licensing and onboarding determine the available coverage.
Map Microsoft Purview capabilities to risks
The largest AB-900 domain requires more than recognizing the Purview name. Sensitivity labels classify content and can apply protection such as encryption, visual markings, and container settings where supported. Data classification uses sensitive information types, trainable classifiers, and labels to identify data. Classification informs governance; it does not automatically correct all permissions.
Data Loss Prevention identifies sensitive items and evaluates activities against policy. Depending on mode and configuration, DLP can audit, show a policy tip, require justification, restrict an action, block it, and generate alerts. A careful administrator starts with requirements and evidence, tests with synthetic data, uses simulation where appropriate, tunes false positives, communicates with users, and stages enforcement. A policy that blocks legitimate work without a review or exception path is not mature governance.
Retention answers a different question: how long content must be kept and when it should be deleted or reviewed. Retention policies apply broadly to configured locations, while retention labels can support item-level and records scenarios. Avoid treating retention as backup or DLP. Each capability has a distinct purpose.
Several investigation experiences appear in the blueprint. Compliance Manager organizes assessments, improvement actions, and recommendations against compliance requirements. Data Explorer helps locate classified sensitive data. Activity explorer shows activities involving labels, sensitive information, and protection policies. Audit provides searchable records of user and administrator activity. eDiscovery supports authorized legal workflows across supported content locations, including search, preservation, review, and export depending on configuration.
Insider Risk Management and Communication Compliance also differ. Insider Risk Management correlates configured signals to investigate potentially risky internal behavior with privacy controls. Communication Compliance identifies configured regulatory or conduct violations in supported communications, including eligible AI interactions. Both require role separation, privacy, legal, human-resources, and compliance considerations; neither should become indiscriminate employee surveillance.
Data Security Posture Management for AI acts as a front door for discovering AI activity, assessing data risk, viewing recommendations, and applying Purview protections. It works with classification, DLP, audit, insider risk, communication compliance, eDiscovery, retention, and Compliance Manager. Learn the relationships instead of expecting one dashboard to replace every policy.
How Copilot grounds responses and protects data
A useful simplified flow begins when a user enters a prompt in a Microsoft 365 experience. Copilot preprocesses and grounds that request using relevant context from Microsoft Graph and Microsoft 365 services. The grounded prompt is processed by a model, and a response is returned to the user. Exact flows vary by capability, but the essential administration principle is consistent: data access is scoped to the signed-in user's existing permissions.
Copilot does not grant access to a SharePoint document merely by citing it. If a user receives inappropriate information from a file they can already open, the underlying problem is broad or stale authorization. Microsoft Graph can make useful content easier to find; the same discoverability can reveal access that was technically permitted but no longer justified. The corrective action is to review memberships, links, sharing, unique permissions, site roles, labels, and other source controls.
Copilot also honors applicable Conditional Access and MFA. Microsoft Purview controls can protect and govern source data and AI interactions. Sensitivity labels communicate and enforce supported protection. DLP can detect sensitive content and risky actions. Audit and eDiscovery provide evidence and legal workflows. Retention governs interaction and content lifecycle where supported. Microsoft Defender contributes risk detection and investigation. These are layers, not a single “secure Copilot” switch.
Responsible AI remains relevant. Administrators should account for inaccurate responses, inappropriate content, automation bias, missing context, source quality, and consequential use. A response should be verified against cited evidence and business rules. Administrative policy cannot transfer accountability to the model.
Find and remediate SharePoint oversharing
SharePoint data access governance reports help identify sites and items that might be too broadly exposed. Snapshot reports can reveal organization-wide permission structure, users' site access, and labeled-file locations. Activity reports can identify recent sharing-link creation and sharing with Everyone except external users. A report is a prioritization signal, not an automatic instruction to remove every permission.
A production-shaped remediation begins by validating the content's sensitivity, the access path, the business purpose, and the people affected. Remove stale users and unnecessary direct grants. Replace broad links with appropriate audiences. Ask site owners to review ambiguous access. Correct nested group membership and unique permissions. Record the change and rollback plan, then allow for search and policy propagation.
SharePoint Advanced Management includes restricted access control. This creates an additional boundary using selected Microsoft 365 or Microsoft Entra security groups. Importantly, membership in an allowed group does not grant access by itself. A user needs both underlying site or content permission and membership in the restricted-access control group. Search and Copilot honor the restriction after propagation. Private and shared channel sites are separate and must be handled independently from the parent team-connected site.
Validation should use at least two synthetic personas: an authorized user and a control user. Test direct file access, SharePoint search, organization search where applicable, and approved Copilot prompts before and after remediation. Never use a real confidential file as a canary. The AB-900 portfolio projects include a complete synthetic readiness and oversharing workflow.
Copilot licensing, settings, prompts, and adoption
The blueprint compares a monthly Microsoft Copilot user license with pay-as-you-go. An assigned license enables the capabilities included for that user and prerequisite subscription. Pay-as-you-go meters consumption for eligible services through configured billing policies and can support selected Copilot Chat and SharePoint agent scenarios. These paths are not universally identical. Verify current service descriptions, regions, prerequisites, billing connections, and prices.
In the Microsoft 365 admin center, Copilot settings are organized around user access, data access, actions, and other settings, with shortcuts to specialized admin centers. Visibility changes with tenant licensing and role. The current documentation recommends the AI Administrator role for applicable Copilot changes and Global Reader for viewing; Global Administrator should not be the default for routine work. Settings can control scenarios such as agent access, pay-as-you-go, selected app experiences, image generation, web search policy links, and administrative Copilot availability.
Prompt management has a lifecycle too. Users can save, share, schedule, and delete prompts where supported. A shared prompt should have an owner, intended audience, valid data sources, no secrets, and clear output expectations. A scheduled prompt should be reviewed when a report, schema, permission, or business process changes. Deleting obsolete automation is governance, not lost productivity.
Usage and adoption monitoring should answer whether people can access the capability, whether they use it for intended tasks, where training is needed, and whether assigned licenses remain justified. Copilot Analytics and Microsoft 365 usage views can contribute aggregate evidence. Conversation count does not equal productivity. Pair usage with task outcomes, answer quality, support burden, incidents, user feedback, access findings, and cost. Avoid unnecessary collection or ranking of individual prompt text.
Compare and govern Copilot agents
Standard Copilot supports a broad range of everyday tasks. Researcher is designed for deeper multi-step research that can synthesize authorized work content and web sources into structured, cited reports. Analyst focuses on advanced data analysis, calculations, trends, and visualization from supported data. A custom agent is appropriate when a recurring job benefits from stable instructions, bounded knowledge, a defined audience, or controlled actions.
Creating an agent is only one lifecycle event. Before authoring, define the business purpose, owner, prohibited uses, knowledge authority, answer contract, cost threshold, support process, and retirement date. Use synthetic data in training. Keep the first version read-only and narrow. Test normal, ambiguous, conflicting, unauthorized, and prompt-injection scenarios. Require uncertainty and escalation behavior where the sources do not answer the question.
Approval should review the publisher, instructions, knowledge sources, permissions, actions, connections, data destinations, labels, DLP, audit, retention, licensing, cost, support, and incident plan. Separate maker and approver duties. Tie approval to an exact version, audience, source set, and expiry so that future changes do not inherit trust automatically.
Administrators can manage agent availability and lifecycle through the Microsoft 365 admin center, including supported assignment, deployment, blocking, removal, and submitted-agent workflows. The Power Platform admin center supplies complementary environment, usage, and operational insights for applicable agent types. Product-specific controls change, so focus on the lifecycle verbs and verify the current interface.
After deployment, monitor usage, answer quality, citations, feedback, incidents, source changes, owner status, permissions, cost, and policy events. Exercise blocking before a real incident. When the owner leaves, the source becomes obsolete, the benefit disappears, or risk exceeds tolerance, retire the agent: remove availability, disconnect knowledge and billing, preserve required evidence, and delete disposable content according to policy.
A practical four-to-six-week AB-900 study plan
- Week 1—objects and admin centers: Diagram users, groups, licenses, mailboxes, distribution groups, teams, channels, sites, libraries, folders, roles, and policies. For each scenario, name the controlling admin center.
- Week 2—identity and security: Practice authentication versus authorization, Zero Trust, MFA, SSO, Conditional Access, sign-in troubleshooting, PIM, applications, Secure Score, audit, and Defender XDR.
- Week 3—Purview: Build a table mapping labels, classification, DLP, retention, Compliance Manager, Data Explorer, Activity explorer, Audit, Insider Risk, Communication Compliance, eDiscovery, and DSPM for AI to their primary goals.
- Week 4—Copilot data and oversharing: Trace the grounding flow, inspect synthetic SharePoint permissions, use governance reports, remediate a planted exposure, and repeat persona tests.
- Weeks 5-6—Copilot and agents: Compare licensing models and built-in capabilities, manage sample prompts, create and approve a read-only synthetic agent, review monitoring, run a block exercise, and revisit weak objectives.
Use original AB-900 practice questions for scenario reasoning and AB-900 flashcards for retrieval. Explain why every distractor is wrong. A useful answer identifies the object, control plane, evidence, least-privilege action, validation, and residual risk.
Exam readiness and honest career expectations
Before scheduling, reread the current official study guide and its change log. Microsoft notes that most questions cover generally available features, while commonly used previews can appear. Do not memorize the location of a button without understanding the underlying task because admin portals change frequently.
Use the official exam sandbox, scheduling, accommodation, and scoring information for logistics. Microsoft states that 700 or higher is required to pass, but PrepKloud does not predict your score or specific live questions. Do not seek dumps or share protected exam content after testing.
AB-900 can organize knowledge for junior Microsoft 365, security, compliance, AI operations, service desk, and adoption work. It does not guarantee a role, promotion, interview, or salary. Stronger evidence combines the credential with a permission diagram, a Purview control matrix, a synthetic oversharing remediation, an agent approval record, a measured adoption scorecard, and an honest explanation of limitations.
Official Microsoft references
- Microsoft Learn: Study guide for Exam AB-900
- Microsoft Learn: Microsoft 365 admin center help
- Microsoft Learn: What is Microsoft Entra?
- Microsoft Learn: Zero Trust overview
- Microsoft Learn: Microsoft Defender XDR overview
- Microsoft Learn: Microsoft Purview documentation
- Microsoft Learn: Purview protection for Microsoft 365 Copilot and Copilot Chat
- Microsoft Learn: Microsoft Copilot architecture and data access
- Microsoft Learn: SharePoint data access governance reports
- Microsoft Learn: Restricted access control for SharePoint
- Microsoft Learn: Manage Microsoft Copilot scenarios
- Microsoft Learn: Agents admin guide for Microsoft 365
Continue your AB-900 preparation
- AB-900 five-phase roadmap
- AB-900 practice questions
- AB-900 flashcards
- AB-900 portfolio projects
- Cloud, security, and AI jobs board
- PrepKloud editorial policy
Frequently asked questions
Is AB-900 active in 2026?
Yes. Microsoft Learn publishes the active Exam AB-900 study guide with skills measured as of July 22, 2026. Verify it again before scheduling because objectives can change.
What are the current AB-900 domain weights?
Core Microsoft 365 features and objects are 30-35%, data protection and governance for Microsoft 365 and Copilot are 35-40%, and basic Copilot and agent administration is 25-30%.
Does Copilot get access to all data in a Microsoft 365 tenant?
No. Copilot grounds through Microsoft Graph and Microsoft 365 services within the signed-in user's existing access. Administrators must remediate oversharing because existing broad access can still expose inappropriate content.
Are these AB-900 materials exam dumps?
No. PrepKloud creates original questions, explanations, flashcards, and projects from public objectives and official documentation. It does not use live, recalled, leaked, or proprietary exam content.
Will AB-900 guarantee a Microsoft 365 administrator job?
No. Certification can structure learning and signal knowledge, but hiring depends on experience, judgment, portfolio evidence, location, market conditions, and employer needs.