Microsoft · AB-900
Validates knowledge of Microsoft 365 core services, data protection, governance, and Copilot and agent administration. Covers Microsoft Entra, Microsoft Purview, and the admin centers for Exchange Online, SharePoint, and Teams.
Practice Questions
700
≈ 14 practice exams
Duration
60 minutes
Passing Score
700/1000
Difficulty
FoundationalLast Updated
Mar 2026
Use this AB-900 practice exam to prepare for Microsoft 365 Certified: Copilot and Agent Administration Fundamentals (AB-900) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 700 questions for Microsoft AB-900, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Core Features and Objects of Microsoft 365 Services, Microsoft 365 Security Principles and Zero Trust, Microsoft Entra and Conditional Access, Microsoft Purview Data Protection and Governance, and Data Security Implications of Microsoft 365 Copilot. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Microsoft 365 Certified: Copilot and Agent Administration Fundamentals (AB-900) is a beginner-level certification that validates foundational knowledge of Microsoft 365 core services, security, data protection, governance, and the administration of Microsoft 365 Copilot and AI agents. It demonstrates the ability to support, secure, and protect an AI-enabled Microsoft 365 environment. The exam covers the full breadth of the Microsoft 365 ecosystem, including Exchange Online, SharePoint, Microsoft Teams, Microsoft Entra for identity and access management, and Microsoft Purview for compliance and data protection.
First made available as a beta and reaching general availability on January 27, 2026, AB-900 reflects the growing organizational need to govern AI-powered productivity tools responsibly. It addresses how Microsoft Graph influences Copilot responses, how permissions and sensitivity labels protect data in Copilot interactions, and how administrators can monitor and manage both Copilot licenses and AI agents through the Microsoft 365 admin center, Microsoft Power Platform admin center, and related tooling. It is the entry-level counterpart to more advanced Copilot and Microsoft 365 administration role-based certifications.
This certification is designed for IT administrators, support engineers, and helpdesk professionals who work in or are entering Microsoft 365 environments where Copilot and AI agents are being deployed. It is appropriate for those in roles such as Microsoft 365 administrator, junior cloud administrator, IT generalist, or modern workplace engineer who need to demonstrate foundational competence in managing and securing AI-driven productivity tools.
The certification is also well-suited for business technology professionals, compliance officers, or governance specialists who interact with Microsoft Purview, Microsoft Entra, and Copilot administration. Candidates should have experience with AI-driven productivity tools and modern IT management practices, and a working familiarity with Microsoft 365 admin centers.
There are no formal prerequisites required to sit for the AB-900 exam. However, Microsoft recommends candidates have hands-on familiarity with Microsoft 365 core services and admin centers, including Exchange Online, SharePoint in Microsoft 365, Microsoft Teams, Microsoft Entra, and Microsoft Purview. Candidates should understand core security concepts such as authentication methods, conditional access policies, Zero Trust principles, and single sign-on (SSO).
Practical experience with AI-driven productivity tools and a basic understanding of how Microsoft 365 Copilot accesses organizational data via Microsoft Graph is strongly recommended. Familiarity with licensing models, user and group management, and compliance tooling in Microsoft Purview will also help candidates succeed on the exam.
The AB-900 exam is a proctored assessment with a 45-minute time limit. It may include interactive components in addition to traditional question formats. The exam is delivered in English through Pearson VUE, and students and educators may also schedule through Certiport. A score of 700 out of 1000 is required to pass.
Most questions cover features that are Generally Available (GA), though questions on Preview features may appear if those features are commonly used. Candidates who need the exam in a non-English language may request an additional 30 minutes. If a candidate fails, they may retake the exam after 24 hours; subsequent retake wait times vary per Microsoft's retake policy.
Earning the AB-900 certification positions professionals as credible administrators in organizations adopting Microsoft 365 Copilot and AI agents, a rapidly expanding segment of enterprise IT. It serves as a foundation for more advanced Microsoft 365 certifications, such as the Microsoft 365 Certified: Administrator Expert or role-based associate certifications covering security, compliance, and identity. As organizations accelerate AI tool deployment, the ability to govern, secure, and administer Copilot environments is increasingly listed as a required or preferred qualification in Microsoft 365 administrator job postings.
Because AB-900 is a foundational-level certification, it is particularly valuable for professionals transitioning into cloud administration or seeking to formalize existing knowledge. It complements other Microsoft fundamentals certifications and is recognized in procurement, compliance, and IT operations roles where demonstrable knowledge of AI governance in Microsoft 365 is required. Salary impact varies by region and role, but Microsoft 365 administrators with AI governance skills are increasingly in demand as enterprises scale Copilot deployments.
5 sample questions with answers and explanations. The full bank has 700 questions, enough for 14 full-length practice exams.
Preview — answers shown1. Northwind Traders has a Microsoft 365 E3 subscription and wants to understand which Data Loss Prevention capabilities are available to them versus those requiring an E5 license. Which DLP location is available with their E3 license? (Select one!)
Explanation
Core DLP capabilities for Exchange Online, SharePoint, and OneDrive are included with Microsoft 365 E3. These locations allow organizations to create policies that identify and protect sensitive information in email and document libraries. DLP for Microsoft 365 Copilot and Copilot Chat requires E5 or E5 Compliance add-on. DLP for Teams chat messages also requires E5 or E5 Compliance add-on. Endpoint DLP for Windows and macOS devices similarly requires E5 or E5 Compliance add-on.
2. Contoso is configuring Microsoft Entra ID groups for their organization. The IT administrator needs to create a group that automatically adds and removes members based on the department attribute in user profiles. The organization has Microsoft 365 E3 licenses. Which group configuration should the administrator use? (Select one!)
Explanation
Security groups with dynamic membership rules automatically populate membership based on user attribute rules such as department, location, or job title. Dynamic groups require Entra ID P1 licensing, which is included with Microsoft 365 E3. Microsoft 365 groups with manual membership require administrators to manually add and remove members. Distribution groups do not support dynamic membership and are used only for email distribution. Mail-enabled security groups also do not support dynamic membership rules and would require manual management.
3. Fabrikam's SharePoint administrator discovers that several sites containing employee performance reviews are appearing in Copilot responses for users who have broad read access but should not be discovering this content through AI. The administrator wants to prevent this content from surfacing in Copilot and organization-wide search without changing existing site permissions. Which SharePoint Advanced Management feature should the administrator use? (Select one!)
Explanation
Restricted Content Discovery (RCD) prevents content from specific SharePoint sites from being surfaced in Microsoft 365 Copilot and organization-wide search without changing existing user permissions. This is ideal when users technically have access but the content should not appear through AI-driven discovery. Restricted Access Control (RAC) actively restricts who can access the site and its content by limiting access to a specific security group, which would change effective permissions. Block download policy prevents file downloads but does not affect search or Copilot discovery. Site access review delegates oversharing remediation to site owners but does not immediately prevent content from appearing in Copilot.
4. Northwind Traders has Microsoft 365 E3 licenses and is evaluating the Copilot add-on. The IT manager wants to understand what prerequisites must be met before users can use Copilot. Which combination of requirements must be satisfied? (Select two!)
Multiple correct answersExplanation
Microsoft 365 Copilot requires several prerequisites including having a primary mailbox on Exchange Online (not an archive, group, or shared mailbox), an active OneDrive account, and Microsoft 365 Apps running on either Current Channel or Monthly Enterprise Channel. Semi-Annual Enterprise Channel is explicitly not supported for Copilot. WebSocket connections must be allowed and network endpoints for the Copilot service must be unblocked. Microsoft Entra ID P2 is not a prerequisite for Copilot, though it provides additional identity protection capabilities. Microsoft Defender for Endpoint is also not a requirement for Copilot functionality. Additional prerequisites include having Entra ID accounts and enabling services like Loop and Whiteboard.
5. Contoso is configuring email authentication for their Exchange Online tenant to protect against spoofing and phishing. The IT team needs to implement SPF, DKIM, and DMARC. In what order should they implement these email authentication protocols according to best practices? (Select one!)
Explanation
Microsoft best practice recommends implementing email authentication protocols in the order of SPF first, then DKIM, then DMARC. SPF (Sender Policy Framework) is implemented first as a DNS TXT record listing authorized sending IP addresses, including spf.protection.outlook.com for Exchange Online. DKIM (DomainKeys Identified Mail) is implemented second to add cryptographic digital signatures via DNS CNAME records. DMARC is implemented last because it ties SPF and DKIM together with enforcement policies (none, quarantine, reject). Implementing DMARC before SPF and DKIM are properly configured could cause legitimate emails to be rejected.
Microsoft Certified: Security Operations Analyst Associate (SC-200)
SC-200 · 599 questions
Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-802)
AZ-802 · 600 questions
Microsoft 365 Certified: Administrator Expert (MS-102)
MS-102 · 965 questions
Microsoft 365 Certified: Fundamentals (MS-900)
MS-900 · 1201 questions
Administering Information Security in Microsoft 365 (SC-401)
SC-401 · 939 questions
Administering Windows Server Hybrid Core Infrastructure (AZ-800)
AZ-800 · 898 questions
$17.99
One-time access to this exam