Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Microsoft 365 Copilot and Agent Administration Fundamentals AB-900 Exam Questions

Page: 1 / 8 Total 75 questions

Want more questions? Get Premium Access.

Question 1

Your organization has a Microsoft 365 subscription.

You need to investigate security incidents and alerts raised from the Windows 11 devices in your organization. What should you use?

Correct Answer: C. Microsoft Defender for Endpoint
Explanation:

The correct answer is C. Microsoft Defender for Endpoint. Microsoft documents that Defender for Endpoint is the Microsoft security solution for endpoint devices, including Windows 11, and that it lets security teams investigate incidents, alerts, affected devices, files, processes, and remediation actions in the Microsoft Defender portal. Microsoft's investigation guidance specifically describes using Defender for Endpoint to review alerts and investigate affected devices from the devices list, alerts queue, and incident views.


Question 2

A user named User1 is responsible for quarterly sales reporting.

User1 needs to identify performance trends, generate visual insights, and create a summary of anomalies across multiple files that contain various datasets.

What should you use

Correct Answer: D. the Analyst agent in Microsoft 365 Copilot
Explanation:

The correct answer is D. the Analyst agent in Microsoft 365 Copilot. Microsoft Learn training for Microsoft 365 Copilot specifically distinguishes the Analyst agent as the tool for gathering insights from data and enhancing data presentations. Microsoft's guidance also notes in the Researcher FAQ that when the task is spreadsheet-related, Analyst agent is better suited for Microsoft Excel related tasks. This makes Analyst the best choice for a quarterly sales reporting scenario that involves detecting performance trends, surfacing anomalies, and producing visual insights from multiple datasets.

The other options are less suitable. Researcher is intended for complex multi-step research and source-cited reports across web and work content, not specialized data analysis across files. Microsoft 365 Copilot Search is for finding information, not for deep quantitative analysis and anomaly summarization. Copilot in Excel is powerful for workbook-level analysis, but the question emphasizes broader insight generation across multiple files and asks for the best Copilot experience for trends, visuals, and anomaly summaries. Microsoft positions Analyst as the dedicated agent for that kind of data-analysis workflow.


Question 3

You plan to create an agent in the Microsoft 365 Copilot app to solve a business issue. What are two reasons to create the agent? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Correct Answer: C. You need to use a custom set of instructions that differ from those of the chat experience.; D. You need to reason over a specific website.
Explanation:

The correct answers are C and D. Microsoft Learn explains that agents created with Agent Builder in Microsoft 365 Copilot allow you to define specific instructions that extend Microsoft 365 Copilot for a business scenario. Microsoft also documents that you can add knowledge sources such as specific public websites and SharePoint content so the agent can reason over targeted information instead of relying only on the default chat experience. Those two capabilities directly match the needs in options C and D.

Option A is incorrect because grouping chats is a Copilot notebook scenario, not the reason to build an agent. Option B is incorrect in the context of creating an agent in the Microsoft 365 Copilot app. Agent Builder supports declarative agents with instructions, knowledge, and capabilities, but Microsoft Learn describes custom AI model control as part of custom engine agents built with tools such as Copilot Studio, SDKs, or Foundry, not as a standard Agent Builder feature in the Microsoft 365 Copilot app. Therefore, when the task is specifically to create an agent in the app, the valid reasons are custom instructions and reasoning over a specific website.


Question 4

Your organization has a Microsoft 365 subscription.

You need to assign a license to a user.

What should you use?

Correct Answer: B. the Microsoft 365 admin center
Explanation:

The correct answer is B. the Microsoft 365 admin center. Microsoft documents that administrators assign product licenses to users from the Microsoft 365 admin center, including on the Active users page where you can open a user account and manage Licenses and apps. Microsoft also documents license assignment workflows there for both direct assignment and group-based licensing scenarios. That makes the Microsoft 365 admin center the standard administrative portal for giving a user access to Microsoft 365 services and features.

The other options are incorrect for this task. The Microsoft Purview portal is used for compliance, governance, data protection, eDiscovery, audit, and related Purview solutions, not for assigning Microsoft 365 product licenses. The Microsoft Teams admin center is used to manage Teams settings, policies, devices, voice, and collaboration features, but it is not the central portal for assigning tenant product licenses to users.


Question 5

Your company requires that all Microsoft SharePoint sites have a minimum of two owners.

You need to ensure that sites that have less than two owners are marked as read-only if the sites are NOT remediated.

What should you configure in the SharePoint admin center?

Correct Answer: C. Site lifecycle management
Explanation:

The correct answer is C. Site lifecycle management. In the SharePoint admin center, Microsoft includes a Site ownership policy under Site lifecycle management that can identify sites with too few owners and drive remediation. Microsoft documents that this policy can detect sites with fewer than the required number of owners, notify site owners, and if the issue is not fixed, enforce an action such as making the site read-only. That directly matches the requirement that sites with fewer than two owners be marked as read-only when they are not remediated.

The other options do not fit this scenario. Site-level access restriction is about controlling who can access a site, not enforcing ownership-count governance. Data access governance reports help identify oversharing and permissions exposure, but they do not enforce a minimum-owner remediation policy that makes sites read-only. Block download policy for SharePoint and OneDrive is used to restrict downloading from unmanaged devices or similar access scenarios, not to handle insufficient site ownership. Therefore, the Microsoft-documented feature to configure is Site lifecycle management.


Question 6

Your organization has a Microsoft 365 E5 subscription.

You need to prevent users from sharing corporate financial data to external users. What should you use?

Correct Answer: B. data loss prevention (DLP) policies
Explanation:

The correct answer is B. data loss prevention (DLP) policies. Microsoft Learn states that Microsoft Purview Data Loss Prevention helps organizations identify, monitor, and automatically protect sensitive information across Microsoft 365 locations such as Exchange, SharePoint, OneDrive, Teams, and devices. Microsoft specifically documents scenarios for preventing sensitive items from being shared with external users in SharePoint and OneDrive, and DLP policies can also block or restrict sharing based on sensitive information types, labels, or policy conditions. This is exactly the control used when the requirement is to stop users from sharing corporate financial data outside the organization.

Option A is incorrect because retention labels manage how long content is kept or deleted, not whether it can be shared externally. Option C is incorrect because role groups are used for permissions and administrative access delegation, not content-sharing prevention. Option D is incorrect because Insider Risk Management is designed to detect and investigate risky user behavior, not to directly block external sharing transactions in the way DLP policies do. For proactive enforcement of external-sharing restrictions on sensitive financial information, Microsoft's documented solution is DLP policies.


Question 7

Your organization has a Microsoft 365 subscription.

Which two tasks can you perform by using the Exchange admin center? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Correct Answer: A. Create a mail flow rule.; D. Create a shared mailbox.
Explanation:

The correct answers are A and D because both tasks are supported directly in the Exchange admin center (EAC). Microsoft Learn states that administrators can manage mail flow rules in Exchange Online from the EAC under Mail flow > Rules, which includes creating and managing transport rules for organizational email handling. Microsoft Learn also states that administrators can create shared mailboxes in the EAC under Recipients > Mailboxes, where a shared mailbox can be added and then delegated to users.

Option B is incorrect because adding a custom domain is normally done in the Microsoft 365 admin center, specifically on the Domains page. Although Exchange can later work with accepted domains and related mail flow settings, the act of adding and verifying a custom domain is not an Exchange admin center task. Option C is incorrect because license assignment is handled through Microsoft 365 or Microsoft Entra administrative tools, not the Exchange admin center.


Question 8

Your organization has a Microsoft 365 subscription that contains Microsoft SharePoint sites and Microsoft Teams teams.

You discover that the sites and the teams are shared to users outside your organization.

You need to identify which sites and teams were shared to the external users.

What should you use?

Correct Answer: A. the SharePoint admin center
Explanation:

The correct answer is A. the SharePoint admin center. Microsoft documents that the SharePoint admin center includes Data access governance reports and site-level sharing reports that help administrators identify where content is shared externally. Microsoft also documents that every standard Microsoft Teams team is connected to a SharePoint site for file storage and collaboration. Because Teams files and many sharing scenarios for teams are backed by SharePoint sites, the SharePoint admin center is the correct place to investigate which sites are shared externally, including Teams-connected SharePoint sites.


Question 9

Your organization has a Microsoft 365 subscription.

All users are assigned Microsoft 365 Copilot licenses.

Some users report receiving Copilot responses that contain information from a Microsoft SharePoint site named Finance. The users report that the information is commercially sensitive.

You need to prevent Copilot from providing responses that contain information from the Finance site.

What should you do?

Correct Answer: D. From the Finance site, configure permissions.
Explanation:

The correct answer is D. From the Finance site, configure permissions. Microsoft states that Microsoft 365 Copilot honors existing Microsoft 365 permissions and only grounds responses in content that the signed-in user is already allowed to access. That means if users are getting Finance-site content in Copilot responses, those users likely still have permission to that SharePoint content. The direct fix is to review and correct the site, library, folder, or file permissions on the Finance site so only the intended users retain access.

The other options do not directly solve this requirement. Information Barriers are designed for communication and collaboration segmentation scenarios, not for ordinary site-level oversharing remediation. A Defender data connector is unrelated to SharePoint permission enforcement. Conditional Access controls sign-in and session access conditions, but it does not selectively remove Copilot grounding from one SharePoint site for users who still have site permissions. Because Copilot uses SharePoint and Microsoft Graph permissions as its boundary, the Microsoft-documented corrective action is to fix the Finance site permissions.


Question 10

Your organization has a Microsoft 365 subscription.

You need to generate a report that shows the permissions and active sharing links of content stored in Microsoft OneDrive accounts.

What should you use?

Correct Answer: A. Data access governance in the SharePoint admin center
Explanation:

The correct answer is A. Data access governance in the SharePoint admin center. Microsoft Learn documents Data access governance reports in the SharePoint admin center as the reporting solution used to understand data exposure, including permission structure and sharing link activity. Microsoft specifically states that the site permissions snapshot report provides visibility across SharePoint and OneDrive sites, helping administrators understand current permissions exposure, and that separate reports are created for SharePoint and OneDrive. Microsoft also documents sharing links activity reports as part of Data access governance for monitoring link-sharing activity, and notes that OneDrive support is available through PowerShell for those reports. Together, this is the Microsoft reporting capability aligned with permissions and active sharing links for OneDrive content.

The other options do not fit this requirement. Microsoft 365 admin center reports focus mainly on usage and activity reporting, not detailed permissions and sharing-link governance. Defender Audit is for security investigation activity, and Purview eDiscovery is for legal and investigative content search, not for generating OneDrive permissions and sharing-link governance reports. Therefore, the best Microsoft-documented answer is Data access governance in the SharePoint admin center.