AB-900 Exam Guide: Microsoft 365 Copilot and Agent Administration Fundamentals
AB-900 validates foundational ability to identify Microsoft 365 services and objects, protect and govern data used by Microsoft 365 and Copilot, and perform basic administration for Copilot and agents. It is aimed at beginning-level IT professionals and novice administrators, including people without prior hands-on experience. This guide helps you decide whether your background is sufficient, which skill areas need the most study, how to sequence official resources, and when you are ready to schedule the assessment.
What does AB-900 validate?
AB-900 validates whether you can support, secure, and protect an AI-enabled Microsoft 365 environment at a foundational administration level. The assessment connects ordinary Microsoft 365 administration with identity, security, data governance, Copilot, and agent concepts rather than testing software development or advanced solution design.
The official skill outline groups the exam into three domains. Identify the core features and objects of Microsoft 365 services accounts for 30–35% of AB-900. Understand data protection and governance tasks for Microsoft 365 and Copilot accounts for 35–40% of AB-900. Perform basic administrative tasks for Copilot and agents accounts for 25–30% of AB-900.
The middle domain has the largest stated weighting, but the three areas overlap. For example, assigning a Copilot license is an administration task, while controlling access to the underlying data involves identity, permissions, SharePoint, and governance. Prepare to explain how these controls work together instead of memorizing isolated product names.
Who should take this exam?
AB-900 suits beginning-level technical IT professionals and novice administrators who need a working foundation in Microsoft 365, Copilot, and agents. Microsoft states that the related AB-900T00-A course does not require prior hands-on experience, so a candidate can begin with structured learning rather than an established administrator background.
The target profile still includes several areas of familiarity: Microsoft 365 core services, security, identity and access, data protection, governance, AI-driven productivity tools, and modern IT management practices. The profile also names Exchange Online, SharePoint in Microsoft 365, Microsoft Teams, Microsoft Entra, and Microsoft Purview administration centers.
Use the profile as a readiness check. If you know what users, groups, teams, sites, and libraries do but have not administered them, you need foundational practice. If terms such as Conditional Access, sensitivity labels, retention, audit activity, or Copilot data access are unfamiliar, start with the relevant learning content before attempting practice questions.
Which Microsoft 365 objects and centers matter?
The first domain expects you to identify the role of common Microsoft 365 objects and select the appropriate administrative location for a task. Build a map from an administrative requirement to the object and center that manages it; this is more useful than learning a list of portals without knowing what each one controls.
Study users, groups, teams, sites, libraries, mailboxes, distribution groups, folders, channels, policies, roles, and permissions. The study guide specifically connects organization configuration with the Microsoft 365 admin center, mailboxes and distribution groups with the Exchange admin center, sites and libraries with the SharePoint admin center, and teams, channels, and policies with the Teams admin center.
Include licensing in this map. You should be able to explain how license types assigned to users and groups affect access to Microsoft 365 features. A useful exercise is to take a fictional request such as “give a department access to a collaboration feature” and identify the users or group, license decision, service object, and permissions that would need review.
Security fundamentals are part of this domain as well. Review Zero Trust, authentication, authorization, threat protection, Microsoft Defender XDR, Microsoft Entra, Conditional Access, single sign-on, user and group security objects, sign-in troubleshooting, audit logs, Privileged Identity Management, app registrations, and enterprise applications.
How should you study data protection and governance?
Treat data protection and governance as the central preparation priority because Understand data protection and governance tasks for Microsoft 365 and Copilot accounts for 35–40% of AB-900. Your goal is to match a risk or compliance requirement with the appropriate Microsoft Purview capability, control, or investigation tool.
The official outline includes Microsoft Purview Information Protection, data loss prevention, Insider Risk Management, Communication Compliance, Data Security Posture Management for AI, and Data Lifecycle Management. It also covers sensitivity labels, data classification, retention, Copilot’s data security implications, responsible AI, Compliance Manager, Data Explorer, DLP alerts, communication policy violations, Activity Explorer, eDiscovery content searches, and SharePoint oversharing.
Study these topics through scenarios. Ask what an organization is trying to do: classify sensitive information, retain or delete content, detect risky activity, investigate a policy issue, locate files or email, or monitor AI-related activity. Then identify the Purview feature that addresses the requirement and the evidence or alert it produces.
Do not reduce Copilot security to the presence of a license. Review how Copilot accesses data, how Microsoft Graph influences responses, and how permissions and other Microsoft 365, Purview, and Defender controls help protect information. Oversharing in SharePoint deserves specific attention because Copilot can expose information that a user is already permitted to access, making existing access hygiene relevant to AI deployment.
What Copilot and agent administration should you know?
Performing basic administrative tasks for Copilot and agents accounts for 25–30% of AB-900. Prepare to recognize common Copilot capabilities and licensing models, assign licenses, monitor usage and billing, manage prompts, understand Researcher and Analyst use cases, create and monitor agents, and work with the Microsoft 365 and Power Platform admin centers.
Keep the scope practical. AB-900 is not presented as a programming exam, so focus on administrative purpose, prerequisites, governance, monitoring, and the relationship between Copilot and agents. For each feature, write a short answer to four questions: who uses it, what data or service it relies on, which administrator controls it, and what security or compliance issue must be considered.
An agent study session should cover the difference between configuring an agent for a defined purpose and simply using a conversational Copilot feature. Consider its data sources, permissions, intended users, monitoring, and lifecycle. Avoid studying agent names as disconnected product trivia; administration questions are more likely to reward understanding of the control or use case represented by the feature.
Link this domain back to the first two. A Copilot license does not replace identity controls, and an agent does not remove the need for data classification, permissions, retention, or monitoring. Your notes should show these dependencies explicitly.
What is the official exam format and scheduling information?
Microsoft states that AB-900 is a proctored assessment and may include interactive components. The certification page gives candidates 45 minutes to complete it. Use the exam sandbox before scheduling so that the interface and available question interactions are not unfamiliar on assessment day.
The certification page lists Pearson VUE for scheduling and provides a Certiport scheduling route for students or educators. Microsoft recommends registering with a personal Microsoft account rather than an organizational work or school account, because exam records can be lost if the candidate leaves that organization.
The certification page currently lists English as the exam language. Check the official exam page when you schedule because availability and language information can change. The AB-900 study guide states that if the exam is not available in your preferred language, you can request an additional 30 minutes; candidates needing assistive devices, extra time, or another modification should review Microsoft’s accommodation process before booking.
Microsoft states that a score of 700 or greater is required to pass. The exam price is based on the country or region where the exam is proctored, so confirm the current amount during scheduling rather than relying on third-party listings.
How should you use Microsoft Learn resources?
Start with the official AB-900 study guide, then use its skills-at-a-glance and detailed skills-measured sections to create your study checklist. The guide is the controlling reference for scope; training pages and product documentation should explain concepts that you cannot yet describe or apply.
The related AB-900T00-A course, Introduction to Microsoft 365 and AI administration, is a beginner course covering Microsoft 365, Copilot, and AI-powered agents. Microsoft lists it as a one-day course and says it can be approached through instructor-led training or self-paced study. Treat the listed course duration as a course description, not as a promise that one day is enough for exam readiness.
The Microsoft Q&A discussion points learners toward two Microsoft Learn paths: Explore Microsoft 365 administration and Explore Microsoft 365 Copilot and agent administration. Use them selectively against your gap list. A candidate who already understands users, groups, and admin centers should spend more time on Purview, Copilot data access, and agent governance rather than rereading familiar basics.
For difficult topics, consult the Microsoft 365, Microsoft 365 Copilot, Microsoft 365 admin center, and Microsoft Purview documentation linked or recommended from the study resources. Record the reason a control exists and the situation in which it is used; copying definitions without a scenario will make review less effective.
What four-stage study roadmap works for beginners?
A staged plan is more reliable than taking practice questions immediately. First establish the Microsoft 365 object and admin-center map, then study security and identity, then concentrate on Purview and Copilot data governance, and finish with Copilot and agent administration. End each stage with retrieval practice and a written gap list.
Stage 1: build the foundation. Review users, groups, teams, sites, libraries, mailboxes, distribution groups, channels, roles, licenses, and permissions. For every object, write its purpose and the center or workload where it is managed. Add Microsoft Entra, Exchange Online, SharePoint, Teams, and Purview to a one-page navigation map.
Stage 2: connect identity to security. Study authentication, authorization, MFA, Conditional Access, SSO, Zero Trust, security defaults, threat protection, Defender XDR, risky sign-ins, audit logs, PIM, app registrations, and enterprise applications. Use short “which control would you check first?” scenarios instead of trying to memorize portal screens.
Stage 3: focus on data and compliance. Work through sensitivity labels, classification, retention, DLP, Insider Risk Management, Communication Compliance, DSPM for AI, eDiscovery, Compliance Manager, Data Explorer, Activity Explorer, and SharePoint oversharing. For each tool, note its purpose, signal, response, and relationship to Copilot.
Stage 4: finish with Copilot and agents. Review capabilities, license assignment, licensing models, usage and billing monitoring, prompts, Researcher and Analyst use cases, agent creation and monitoring, and the Microsoft 365 and Power Platform admin centers. Then take the official practice assessment and return to the study guide for every uncertain answer.
How can you turn reading into useful practice?
Use a control-to-scenario worksheet rather than passively rereading Microsoft Learn pages. Write a short requirement in one column, the Microsoft 365 object or control in the next, the relevant admin center or workload beside it, and the security or governance consequence in the final column.
Examples of useful prompts include: a group needs access to a licensed feature; an administrator must investigate a risky sign-in; a site contains sensitive information; a retention requirement applies to content; a DLP alert needs a response; an organization wants to monitor AI activity; or an agent should be created for a defined business purpose. The point is to explain the decision, not to reproduce a live question.
If you have access to an appropriate Microsoft 365 environment, use it to locate the admin centers and observe how objects are organized. Hands-on work should reinforce concepts such as license assignment, permissions, audit activity, labels, and policy monitoring. Do not assume that a personal or trial environment exposes every feature named in the blueprint, and do not treat unavailable tenant features as evidence that a topic is out of scope.
Where hands-on access is unavailable, use documentation diagrams, administrative walkthroughs, and your own object map. AB-900 measures foundational understanding, so a clear explanation of what a control does and when to use it is more valuable than clicking through a portal without a defined task.
How should you use the official practice assessment?
Use the AB-900 Practice Assessment as a diagnostic after studying the blueprint, not as a substitute for training or product experience. Microsoft makes Practice Assessments available at no cost and says they can be attempted as many times as desired, which makes them useful for checking whether gaps are closing.
Microsoft says the practice questions are not the same as live exam questions and do not represent the exam’s full length or complexity. The assessment may not expose every question type, case study, or lab-like interaction that could appear in an exam. Never treat repeated exposure to practice wording as a guarantee of success.
Review every uncertain response, including answers you guessed correctly. Classify the cause: unfamiliar object, confused admin center, weak security principle, incorrect Purview use case, misunderstanding of Copilot data access, or failure to distinguish licensing from permissions. Then return to the relevant study-guide bullet and documentation before attempting the assessment again.
Combine practice results with explanation quality. You are closer to readiness when you can justify why the selected control fits the scenario and why the alternatives do not, rather than merely recognizing a familiar answer pattern.
Which mistakes waste the most preparation time?
The most damaging mistake is studying Copilot in isolation. AB-900 connects Copilot and agents to Microsoft 365 identity, permissions, data protection, governance, and administration. A candidate who memorizes Copilot terminology but cannot explain how data access and compliance controls work together will leave a major knowledge gap.
Another mistake is treating the percentage ranges as a question-count forecast. The official blueprint gives domain weightings, not a guaranteed number of questions. Use the ranges to prioritize study time, while still covering all three domains and the related bullets under each one.
Avoid confusing authentication with authorization. Authentication establishes identity; authorization determines permitted access. Conditional Access can evaluate conditions around access, while SSO concerns the sign-in experience across applications. Build simple comparisons in your notes and attach each term to an administrative scenario.
Do not memorize portal names without mapping them to objects. Exchange, SharePoint, Teams, Entra, Purview, Microsoft 365, and Power Platform administration centers serve different purposes, but a question may describe the task without naming the center. Start with the object or control, then identify the administrative location.
Finally, do not rely on dumps, leaked questions, or memorization claims. They are not an ethical or dependable substitute for the official blueprint, training, documentation, and practice assessment, and they cannot prepare you for unfamiliar scenarios or interactive components.
When are you ready to schedule AB-900?
Schedule when you can explain the three domains without notes, identify the relevant Microsoft 365 object or control in a scenario, and describe how identity, permissions, governance, and Copilot administration interact. Readiness should be based on demonstrated understanding and a completed gap review, not on a particular number of practice attempts.
Before booking, verify the current exam page for language, scheduling channel, price, accommodations, and exam policies. Connect the certification profile to a personal Microsoft account, choose the appropriate Pearson VUE or Certiport route, and allow time to review the proctored and interactive exam information.
Launch the exam sandbox before the assessment. Also prepare a final review sheet containing the three domain labels and weightings, admin-center responsibilities, core security distinctions, Purview tool purposes, Copilot data-access principles, license and permission differences, and agent administration concepts.
If you do not pass, Microsoft states that the first retake may be taken 24 hours after the first attempt; later retake intervals vary. Use the score report and your own uncertainty log to target the next study cycle instead of repeating the same material unchanged.
What should you do after passing?
Passing AB-900 establishes a beginner-level foundation; it does not replace operational experience with Microsoft 365 administration, security, compliance, Copilot, or agents. Use the result to choose a practical next skill area, such as identity administration, Purview governance, Microsoft 365 workload management, or Copilot deployment support.
Keep your Microsoft Learn certification profile connected so you can schedule and manage certification activity and share or print certificates. The AB-900 study guide states that Microsoft associate, expert, and specialty certifications expire annually and can be renewed by passing a free online assessment on Microsoft Learn.
The most useful post-exam action is to turn the blueprint into workplace practice. Choose a controlled administrative task, document the object and permissions involved, identify the security or compliance risk, and record how you would monitor the result. That process converts foundational vocabulary into responsible administration habits.
Conclusion
AB-900 preparation should follow the exam’s decision pattern: identify the Microsoft 365 object or service, select the appropriate administrative or security control, consider data protection and governance, and then account for Copilot or agent administration where relevant. Start with the official study guide, prioritize the 35–40% data-protection and governance domain, use the beginner course and learning paths to close gaps, and finish with the official Practice Assessment and exam sandbox. Schedule only after you can explain the reasoning behind your choices, not merely recognize product terms.