CertGrid
Microsoft Certification

AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Practice Exam

Validates foundational skills for supporting, securing and protecting an AI-enabled Microsoft 365 environment - the core features and objects of Microsoft 365 services including licensing, the admin centres and the security model of Microsoft Entra ID, data protection and governance with Microsoft Purview including sensitivity labels, DLP, insider risk, DSPM for AI and SharePoint oversharing, and the basic administration of Copilot and agents covering licences, pay-as-you-go billing, usage monitoring, prompt management and the agent approval and lifecycle process.

Start with a free AB-900 practice test, then work through 647 exam-style questions with full answer explanations, and take timed mock exams that score like the real thing.

647
Practice pool
40-60 qs
Real exam
100 min
Real exam time
Foundational
Level
700 / 1000
Passing score

CertGrid runs a fixed 40-question timed mock, separate from the real exam format above. Microsoft seat time may be longer than exam answering time.

Objective-mapped practice, aligned to current exam objectives · Independent practice platform.

What the AB-900 exam covers

Free AB-900 practice test questions

A sample of 10 questions with answers and explanations. Sign up free to practice all 647.

  1. Question 1Identify the core features and objects of Microsoft 365 services

    A user reports they cannot see Microsoft 365 Copilot in Word although colleagues can. What should the administrator check first?

    • AWhether a Copilot licence has been assigned to that userCorrect
    • BWhether the user has a mailbox in Exchange Online
    • CWhether the user belongs to a Teams channel
    • DWhether the user has a SharePoint site
    ✓ Correct answer: A

    Access to Copilot features is gated by the licence assigned to the individual user or inherited through a group, so a user without one sees no Copilot entry points at all while licensed colleagues do. Confirming the assignment in the Microsoft 365 admin center resolves the majority of these reports immediately.

    Why the other options are wrong
    • BA mailbox in Exchange Online is required for mail rather than for Copilot.
    • CBelonging to a Teams channel does not grant Copilot access.
    • DHaving a SharePoint site is unrelated to Copilot licensing.
  2. Question 2Understand data protection and governance tasks for Microsoft 365 and Copilot

    An organisation is worried that a departing employee may take files. Which capability addresses that scenario?

    • AInsider Risk Management with a departing user policyCorrect
    • BA retention policy on the mailbox
    • CA Conditional Access policy for guest users
    • DA Teams meeting recording policy
    ✓ Correct answer: A

    Insider Risk Management includes policy templates for people who have resigned or been given notice, watching for unusual downloads, copying to removable media and sharing outside the organisation during that period. Matches become cases for review rather than automatic accusations.

    Why the other options are wrong
    • BA retention policy keeps content rather than detecting exfiltration.
    • CConditional Access for guests governs external sign-in.
    • DA meeting recording policy controls Teams recordings.
  3. Question 3Perform basic administrative tasks for Copilot and agents

    A Copilot administrator must explain what a scheduled prompt achieves. What does it do?

    • ARuns a defined prompt at a chosen time without promptingCorrect
    • BAssigns a licence at a chosen time
    • CDeletes content at a chosen time
    • DCreates a Teams meeting at a chosen time
    ✓ Correct answer: A

    Recurring work such as a weekly summary can be set to run on its own, which removes the need for somebody to remember and produces the output consistently. It suits prompts whose value is regular rather than occasional. Reviewing its output occasionally keeps the schedule worthwhile, since a prompt that has stopped being accurate still runs.

    Why the other options are wrong
    • BLicence assignment is an administrative action rather than a prompt.
    • CDeleting content on a schedule is a retention function.
    • DCreating meetings is a calendar and Teams function.
  4. Question 4Identify the core features and objects of Microsoft 365 services

    The IT administrator must decide how to grant a service access to Microsoft 365 data. What is the appropriate mechanism?

    • AAn application identity with narrowly scoped permissionsCorrect
    • BA shared user account with a known password
    • CA global administrator account for the service
    • DA guest account invited from outside
    ✓ Correct answer: A

    Registering the application and granting only the permissions it genuinely needs makes its access attributable, reviewable and revocable, none of which is true of a shared account. It also avoids a password that has to be stored somewhere and rotated by hand.

    Why the other options are wrong
    • BA shared user account removes attribution and needs a stored password.
    • CA global administrator account for a service is a severe exposure.
    • DA guest account is intended for external people rather than services.
  5. Question 5Understand data protection and governance tasks for Microsoft 365 and Copilot

    A workspace administrator must decide how to reduce the volume of DLP alerts nobody acts on. What is the productive approach?

    • ATune the rules so matches reflect genuine riskCorrect
    • BStop routing the alerts to anybody
    • CDelete the policies producing them
    • DIncrease the alert volume to force attention
    ✓ Correct answer: A

    Alerts that reviewers routinely dismiss mean the rule is matching content that is not actually risky, and narrowing the information types, the confidence level or the locations produces a set worth reading. Suppressing them instead leaves the genuine matches unnoticed among the noise.

    Why the other options are wrong
    • BRouting alerts to nobody hides the genuine matches too.
    • CDeleting the policies removes the detection entirely.
    • DIncreasing volume makes the problem substantially worse.
  6. Question 6Perform basic administrative tasks for Copilot and agents

    A Microsoft 365 administrator must decide what to do when users ask for a capability Copilot does not provide. What is the honest response?

    • ASay so and record it as a requirement for considerationCorrect
    • BPromise it will arrive in the next release
    • CSuggest they build an unapproved agent
    • DTell them the request is unreasonable
    ✓ Correct answer: A

    Telling people plainly what the capability does not do preserves credibility, and recording the need means it can be weighed against other work rather than disappearing. Promising a future release the administrator does not control is a commitment nobody can honour.

    Why the other options are wrong
    • BPromising a future release commits to something outside their control.
    • CSuggesting an unapproved agent circumvents the governance process.
    • DTelling them the request is unreasonable dismisses a genuine need.
  7. Question 7Identify the core features and objects of Microsoft 365 services

    An IT administrator must explain why an application's sign-in activity is worth reviewing. What does it reveal?

    • AWhether it is still being used and from whereCorrect
    • BHow much storage its data consumes
    • CHow many Teams its users belong to
    • DHow long its users have been employed
    ✓ Correct answer: A

    An application with broad permissions and no sign-ins for a year is a candidate for removal, while unexpected activity or unexpected locations warrant investigation, so the review answers both questions at once. It is a straightforward way to shrink the estate.

    Why the other options are wrong
    • BStorage consumption is reported separately from sign-in activity.
    • CTeams membership of its users is unrelated to the application.
    • DLength of employment carries no meaning for an application.
  8. Question 8Understand data protection and governance tasks for Microsoft 365 and Copilot

    An operations administrator is asked what makes an insider risk programme acceptable to employees. What matters?

    • ATransparency about what is monitored and whyCorrect
    • BConcealing the programme entirely
    • CMonitoring every message from everybody
    • DPublishing every case to the organisation
    ✓ Correct answer: A

    Programmes that are explained, proportionate and subject to their own controls are generally accepted, whereas covert or unbounded monitoring produces distrust and often falls foul of employment obligations. Transparency also deters some of the behaviour being watched for.

    Why the other options are wrong
    • BConcealing the programme entirely produces distrust when discovered.
    • CMonitoring every message from everybody is disproportionate.
    • DPublishing cases to the organisation breaches privacy severely.
  9. Question 9Understand data protection and governance tasks for Microsoft 365 and Copilot

    A Microsoft 365 administrator must explain what happens when a document is shared with a link that permits editing. What follows?

    • ARecipients can change the content, not only read itCorrect
    • BRecipients receive a copy rather than the original
    • CThe document becomes read-only for its owner
    • DThe document loses its sensitivity label
    ✓ Correct answer: A

    Anybody using the link can modify the document, which is appropriate for collaboration and inappropriate for material meant to be read only, so choosing the link type deliberately matters. Defaulting to edit links is a common and avoidable exposure.

    Why the other options are wrong
    • BRecipients reach the original rather than receiving a copy.
    • CThe owner retains their own permissions.
    • DThe sensitivity label remains on the document.
  10. Question 10Understand data protection and governance tasks for Microsoft 365 and Copilot

    The Copilot admin must decide how to handle a finding that a former employee's account still holds access. What is the priority?

    • AEstablish whether it has been used since they leftCorrect
    • BDelete the account without checking
    • CIncrease its storage quota
    • DAdd it to more groups
    ✓ Correct answer: A

    An active account belonging to somebody who has left is either an oversight or evidence that somebody is using it, and the sign-in records distinguish the two immediately. Deleting it first removes the account and possibly the evidence at the same moment.

    Why the other options are wrong
    • BDeleting it without checking may destroy evidence of misuse.
    • CIncreasing its storage quota is entirely inappropriate.
    • DAdding it to more groups widens a problem.

Who this AB-900 practice exam is for

This practice set is for anyone preparing for the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam at the foundational level - from first-time candidates building a foundation to experienced Microsoft practitioners doing a final review before test day. If you learn best by working through realistic questions and reading why each answer is right or wrong, it is built for you.

How to use this AB-900 practice exam

  1. Start with the free sample questions above to gauge your current baseline.
  2. Read the full explanation on every question, including why each wrong option is wrong.
  3. Track your weak domains and focus your study where you are losing the most marks.
  4. Once you are scoring consistently well, take a timed, full-length mock exam.
  5. Use your readiness score to decide when you are ready to book the real AB-900 exam.

Related Microsoft resources

AB-900 practice exam FAQ

How many questions are in the AB-900 practice exam on CertGrid?

CertGrid has 647 practice questions for AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals, covering 3 exam domains. The real AB-900 exam is 40-60 qs in 100 min. CertGrid's timed mock is a fixed 40 questions.

What is the passing score for AB-900?

Microsoft grades AB-900 on a scaled score of 1 to 1000 with 700 required to pass; the scaled score is not a straight percentage. CertGrid reports your percent-correct on this mock separately as a readiness indicator. You have about 100 min to complete it. CertGrid scores your practice attempts the same way so you know when you are ready.

Are these official AB-900 exam questions?

No. CertGrid is an independent practice platform. We do not provide real or leaked exam questions. Our questions are original and designed to help you practice the concepts, scenarios, and difficulty style of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam.

Is there a free AB-900 practice test?

Yes. You can take a free AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals practice test straight away: a fixed set of 20 practice questions for this exam, retryable as often as you like, with no credit card required. You get readiness scoring and a weak-domain breakdown on those questions. Paid plans unlock the full 647-question bank, timed mock exams and full-bank domain analytics.

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Microsoft. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.