Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft AB-900 Exam Questions

Exam Name: Microsoft 365 Copilot and Agent Administration Fundamentals Exam
Exam Code: AB-900
Related Certification(s): Microsoft 365 Certification
Certification Provider: Microsoft
Number of AB-900 practice questions in our database: 75 (updated: Jul. 29, 2026)
Disscuss Microsoft AB-900 Topics, Questions or Ask Anything Related
0/2000 characters

Amanda Nguyen

1 day ago
Admin roles and role-based access control show up as multiple choice scenarios asking which built-in role grants the minimum privileges to manage Copilot or agent features. Review role capabilities in Azure AD and the Microsoft 365 admin center and memorize least-privilege mappings, I passed the exam after reviewing real role descriptions.
upvoted 0 times
...

Stephanie Rivera

4 days ago
I passed AB-900 after spending time in the admin centers doing the basic tasks rather than only reading. The agent administration items felt straightforward once I knew where settings lived and what each change impacted.
upvoted 0 times
...

George Martinez

1 month ago
Agent onboarding and connector configuration are commonly tested with stepwise troubleshooting items that ask which permission or setting is missing to bring an agent online. Practice the registration flow, service principal permissions, and connector settings, I passed the exam and found Pass4Success useful for targeted practice questions.
upvoted 0 times
...

Christopher Jackson

1 month ago
I managed to pass the Microsoft 365 Copilot and Agent Administration Fundamentals exam by drilling the governance pieces, especially sensitivity labels, retention, and audit basics. A few questions were subtle about what protects data versus what just monitors it, so I practiced sorting those in my notes.
upvoted 0 times
...

Joseph Wright

2 months ago
Sensitivity labels and DLP policies often appear as scenario questions where you must select the correct label and rule to protect a specific document type. Focus on how labels propagate, DLP condition/action pairs, and how Copilot respects labeled content, I took the exam and passed after drilling real policy examples.
upvoted 0 times
...

Tiffany Smith

2 months ago
I passed the AB-900 last week, and the biggest help was mapping Copilot features to the Microsoft 365 services they actually touch instead of memorizing definitions. The exam leaned on practical scenarios, so I reviewed how permissions and connectors affect what Copilot can see.
upvoted 0 times
...

Edward Adams

3 months ago
User and group management is a frequent topic with scenario questions that force you to pick between Microsoft 365 groups, security groups, or guest accounts for specific access requirements. Study license assignment, membership types, and group scopes so you can justify the choice, I passed the exam and thanks Pass4Success for the concise question set that sped my prep.
upvoted 0 times
...

Stephanie Stewart

3 months ago
Noticed that the scenario questions about Copilot data access versus tenant-level compliance controls were the trickiest for me, especially when mapping which admin role or policy to apply. I found drawing a quick table during the test to map roles, objects, and data flows helped.
upvoted 0 times

Rachel White

3 months ago
Actually practicing tenant admin tasks in a sandbox beforehand made it much easier to spot which setting controlled Copilot behavior.
upvoted 0 times

Matthew Cooper

3 months ago
During AB-900 I got tripped up by items that blurred retention policies in Microsoft 365 compliance center and Copilot's own data handling, so keep their scopes distinct.
upvoted 0 times

Kevin Perez

3 months ago
Sometimes the agent administration scenarios focus on role separation and least privilege, so think about specific agent permissions rather than broad admin labels.
upvoted 0 times

Thomas Garcia

3 months ago
Helpful to memorize core objects like Teams, SharePoint sites, and sensitivity labels since many questions ask which object a Copilot policy applies to.
upvoted 0 times
...
...
...
...

Michelle Clark

3 months ago
Also watch for question styles that ask you to choose multiple correct actions in a workflow, because those require sequencing and not just picking one control.
upvoted 0 times
...
...

Free Microsoft AB-900 Exam Actual Questions

Note: Premium Questions for AB-900 were last updated On Jul. 29, 2026 (see below)

Question #1

Your organization has a Microsoft 365 subscription.

You need to assign a license to a user.

What should you use?

Reveal Solution Hide Solution
Correct Answer: B

The correct answer is B. the Microsoft 365 admin center. Microsoft documents that administrators assign product licenses to users from the Microsoft 365 admin center, including on the Active users page where you can open a user account and manage Licenses and apps. Microsoft also documents license assignment workflows there for both direct assignment and group-based licensing scenarios. That makes the Microsoft 365 admin center the standard administrative portal for giving a user access to Microsoft 365 services and features.

The other options are incorrect for this task. The Microsoft Purview portal is used for compliance, governance, data protection, eDiscovery, audit, and related Purview solutions, not for assigning Microsoft 365 product licenses. The Microsoft Teams admin center is used to manage Teams settings, policies, devices, voice, and collaboration features, but it is not the central portal for assigning tenant product licenses to users.


Question #2

Your organization has a Microsoft 365 E5 subscription.

You need to ensure that a third-party cloud service can authenticate to Microsoft Entra.

What should you configure?

Reveal Solution Hide Solution
Correct Answer: D

The correct answer is D. an app registration. Microsoft Learn states that to delegate identity and access management functions to Microsoft Entra ID, an application must be registered with a Microsoft Entra tenant. When you register an application, you create its identity configuration in Microsoft Entra, and a corresponding service principal is created so the application can authenticate and integrate with the tenant. This is the standard Microsoft mechanism for allowing a third-party cloud service or app to authenticate to Microsoft Entra.


Question #3

Your organization has a Microsoft 365 subscription.

You need to evaluate your organization s Identity Secure Score.

Which two factors affect the score? Each correct answer presents a complete the solution.

NOTE: Each correct selection is worth one point.

Reveal Solution Hide Solution
Correct Answer: A, D

The correct answers are A and D because Microsoft Entra Identity Secure Score is based on identity security recommendations, and Microsoft Learn specifically lists recommendations such as ''Designate more than one Global Administrator'' and ''Do not expire passwords.'' That means the number of global administrators in the tenant and whether password expiration is disabled directly influence the Identity Secure Score. Microsoft also notes that the score measures how closely an organization aligns with Microsoft's recommended identity security best practices.

Option B is incorrect because SharePoint site permissions are related to SharePoint and Microsoft 365 workload permissions, not to the Entra identity-focused scoring model. Option C is incorrect because user location may be evaluated in Conditional Access and Zero Trust scenarios, but it is not itself listed as a direct Identity Secure Score factor in the Microsoft Entra recommendations referenced by Microsoft Learn. Identity Secure Score is driven by tracked identity recommendations and security configurations, not by simple geographic placement of users.


Question #4

You need to identify files and emails that contain social security numbers (SSNs) and credit card numbers. What should you use in the Microsoft Purview portal?

Reveal Solution Hide Solution
Correct Answer: B

The correct answer is B. Data explorer. Microsoft Learn states that Data explorer in Microsoft Purview shows a current snapshot of items that have been classified as a sensitive information type in your organization. Microsoft's sensitive information type documentation specifically lists examples such as social security numbers and credit card numbers, which means Data explorer is the appropriate portal feature for identifying files and emails that contain those data types. Data explorer is designed to help administrators see where sensitive data exists across supported Microsoft 365 locations.

The other options are less appropriate for this task. Information Protection reports focus more broadly on label and protection reporting. Information Protection policies are for configuring classification and protection behavior, not for finding existing files and emails containing SSNs or credit card numbers. Activity explorer is primarily used to review user and policy-related activities, such as label changes or DLP events, rather than to provide the direct sensitive-data inventory view requested here. Since the question asks to identify the files and emails containing specific sensitive information types, Microsoft's documented answer is Data explorer.


Question #5

Your organization has a Microsoft 365 E5 subscription.

You need to prevent users from sharing corporate financial data to external users. What should you use?

Reveal Solution Hide Solution
Correct Answer: B

The correct answer is B. data loss prevention (DLP) policies. Microsoft Learn states that Microsoft Purview Data Loss Prevention helps organizations identify, monitor, and automatically protect sensitive information across Microsoft 365 locations such as Exchange, SharePoint, OneDrive, Teams, and devices. Microsoft specifically documents scenarios for preventing sensitive items from being shared with external users in SharePoint and OneDrive, and DLP policies can also block or restrict sharing based on sensitive information types, labels, or policy conditions. This is exactly the control used when the requirement is to stop users from sharing corporate financial data outside the organization.

Option A is incorrect because retention labels manage how long content is kept or deleted, not whether it can be shared externally. Option C is incorrect because role groups are used for permissions and administrative access delegation, not content-sharing prevention. Option D is incorrect because Insider Risk Management is designed to detect and investigate risky user behavior, not to directly block external sharing transactions in the way DLP policies do. For proactive enforcement of external-sharing restrictions on sensitive financial information, Microsoft's documented solution is DLP policies.



Unlock Premium AB-900 Exam Questions with Advanced Practice Test Features:
  • Select Question Types you want
  • Set your Desired Pass Percentage
  • Allocate Time (Hours : Minutes)
  • Create Multiple Practice tests with Limited Questions
  • Customer Support
Get Full Access Now

Save Cancel