What the AB-900 exam covers
- Identify the core features and objects of Microsoft 365 services214 questions
- Understand data protection and governance tasks for Microsoft 365 and Copilot246 questions
- Perform basic administrative tasks for Copilot and agents187 questions
Free AB-900 practice test questions
A sample of 10 questions with answers and explanations. Sign up free to practice all 647.
-
A user reports they cannot see Microsoft 365 Copilot in Word although colleagues can. What should the administrator check first?
- AWhether a Copilot licence has been assigned to that userCorrect
- BWhether the user has a mailbox in Exchange Online
- CWhether the user belongs to a Teams channel
- DWhether the user has a SharePoint site
✓ Correct answer: AAccess to Copilot features is gated by the licence assigned to the individual user or inherited through a group, so a user without one sees no Copilot entry points at all while licensed colleagues do. Confirming the assignment in the Microsoft 365 admin center resolves the majority of these reports immediately.
Why the other options are wrong- BA mailbox in Exchange Online is required for mail rather than for Copilot.
- CBelonging to a Teams channel does not grant Copilot access.
- DHaving a SharePoint site is unrelated to Copilot licensing.
-
An organisation is worried that a departing employee may take files. Which capability addresses that scenario?
- AInsider Risk Management with a departing user policyCorrect
- BA retention policy on the mailbox
- CA Conditional Access policy for guest users
- DA Teams meeting recording policy
✓ Correct answer: AInsider Risk Management includes policy templates for people who have resigned or been given notice, watching for unusual downloads, copying to removable media and sharing outside the organisation during that period. Matches become cases for review rather than automatic accusations.
Why the other options are wrong- BA retention policy keeps content rather than detecting exfiltration.
- CConditional Access for guests governs external sign-in.
- DA meeting recording policy controls Teams recordings.
-
A Copilot administrator must explain what a scheduled prompt achieves. What does it do?
- ARuns a defined prompt at a chosen time without promptingCorrect
- BAssigns a licence at a chosen time
- CDeletes content at a chosen time
- DCreates a Teams meeting at a chosen time
✓ Correct answer: ARecurring work such as a weekly summary can be set to run on its own, which removes the need for somebody to remember and produces the output consistently. It suits prompts whose value is regular rather than occasional. Reviewing its output occasionally keeps the schedule worthwhile, since a prompt that has stopped being accurate still runs.
Why the other options are wrong- BLicence assignment is an administrative action rather than a prompt.
- CDeleting content on a schedule is a retention function.
- DCreating meetings is a calendar and Teams function.
-
The IT administrator must decide how to grant a service access to Microsoft 365 data. What is the appropriate mechanism?
- AAn application identity with narrowly scoped permissionsCorrect
- BA shared user account with a known password
- CA global administrator account for the service
- DA guest account invited from outside
✓ Correct answer: ARegistering the application and granting only the permissions it genuinely needs makes its access attributable, reviewable and revocable, none of which is true of a shared account. It also avoids a password that has to be stored somewhere and rotated by hand.
Why the other options are wrong- BA shared user account removes attribution and needs a stored password.
- CA global administrator account for a service is a severe exposure.
- DA guest account is intended for external people rather than services.
-
A workspace administrator must decide how to reduce the volume of DLP alerts nobody acts on. What is the productive approach?
- ATune the rules so matches reflect genuine riskCorrect
- BStop routing the alerts to anybody
- CDelete the policies producing them
- DIncrease the alert volume to force attention
✓ Correct answer: AAlerts that reviewers routinely dismiss mean the rule is matching content that is not actually risky, and narrowing the information types, the confidence level or the locations produces a set worth reading. Suppressing them instead leaves the genuine matches unnoticed among the noise.
Why the other options are wrong- BRouting alerts to nobody hides the genuine matches too.
- CDeleting the policies removes the detection entirely.
- DIncreasing volume makes the problem substantially worse.
-
A Microsoft 365 administrator must decide what to do when users ask for a capability Copilot does not provide. What is the honest response?
- ASay so and record it as a requirement for considerationCorrect
- BPromise it will arrive in the next release
- CSuggest they build an unapproved agent
- DTell them the request is unreasonable
✓ Correct answer: ATelling people plainly what the capability does not do preserves credibility, and recording the need means it can be weighed against other work rather than disappearing. Promising a future release the administrator does not control is a commitment nobody can honour.
Why the other options are wrong- BPromising a future release commits to something outside their control.
- CSuggesting an unapproved agent circumvents the governance process.
- DTelling them the request is unreasonable dismisses a genuine need.
-
An IT administrator must explain why an application's sign-in activity is worth reviewing. What does it reveal?
- AWhether it is still being used and from whereCorrect
- BHow much storage its data consumes
- CHow many Teams its users belong to
- DHow long its users have been employed
✓ Correct answer: AAn application with broad permissions and no sign-ins for a year is a candidate for removal, while unexpected activity or unexpected locations warrant investigation, so the review answers both questions at once. It is a straightforward way to shrink the estate.
Why the other options are wrong- BStorage consumption is reported separately from sign-in activity.
- CTeams membership of its users is unrelated to the application.
- DLength of employment carries no meaning for an application.
-
An operations administrator is asked what makes an insider risk programme acceptable to employees. What matters?
- ATransparency about what is monitored and whyCorrect
- BConcealing the programme entirely
- CMonitoring every message from everybody
- DPublishing every case to the organisation
✓ Correct answer: AProgrammes that are explained, proportionate and subject to their own controls are generally accepted, whereas covert or unbounded monitoring produces distrust and often falls foul of employment obligations. Transparency also deters some of the behaviour being watched for.
Why the other options are wrong- BConcealing the programme entirely produces distrust when discovered.
- CMonitoring every message from everybody is disproportionate.
- DPublishing cases to the organisation breaches privacy severely.
-
A Microsoft 365 administrator must explain what happens when a document is shared with a link that permits editing. What follows?
- ARecipients can change the content, not only read itCorrect
- BRecipients receive a copy rather than the original
- CThe document becomes read-only for its owner
- DThe document loses its sensitivity label
✓ Correct answer: AAnybody using the link can modify the document, which is appropriate for collaboration and inappropriate for material meant to be read only, so choosing the link type deliberately matters. Defaulting to edit links is a common and avoidable exposure.
Why the other options are wrong- BRecipients reach the original rather than receiving a copy.
- CThe owner retains their own permissions.
- DThe sensitivity label remains on the document.
-
The Copilot admin must decide how to handle a finding that a former employee's account still holds access. What is the priority?
- AEstablish whether it has been used since they leftCorrect
- BDelete the account without checking
- CIncrease its storage quota
- DAdd it to more groups
✓ Correct answer: AAn active account belonging to somebody who has left is either an oversight or evidence that somebody is using it, and the sign-in records distinguish the two immediately. Deleting it first removes the account and possibly the evidence at the same moment.
Why the other options are wrong- BDeleting it without checking may destroy evidence of misuse.
- CIncreasing its storage quota is entirely inappropriate.
- DAdding it to more groups widens a problem.
Who this AB-900 practice exam is for
This practice set is for anyone preparing for the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam at the foundational level - from first-time candidates building a foundation to experienced Microsoft practitioners doing a final review before test day. If you learn best by working through realistic questions and reading why each answer is right or wrong, it is built for you.
How to use this AB-900 practice exam
- Start with the free sample questions above to gauge your current baseline.
- Read the full explanation on every question, including why each wrong option is wrong.
- Track your weak domains and focus your study where you are losing the most marks.
- Once you are scoring consistently well, take a timed, full-length mock exam.
- Use your readiness score to decide when you are ready to book the real AB-900 exam.
Related Microsoft resources
- Microsoft practice examsAll Microsoft
- Certification pathWhere this fits
- Certification exam guides & tipsBlog
- Plans & pricingFree & paid
- How these questions are written and reviewedMethodology
- Report a problem with a questionCorrections
- AI-103 practice examRelated
- AI-300 practice examRelated
- AI-901 practice examRelated
AB-900 practice exam FAQ
How many questions are in the AB-900 practice exam on CertGrid?
CertGrid has 647 practice questions for AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals, covering 3 exam domains. The real AB-900 exam is 40-60 qs in 100 min. CertGrid's timed mock is a fixed 40 questions.
What is the passing score for AB-900?
Microsoft grades AB-900 on a scaled score of 1 to 1000 with 700 required to pass; the scaled score is not a straight percentage. CertGrid reports your percent-correct on this mock separately as a readiness indicator. You have about 100 min to complete it. CertGrid scores your practice attempts the same way so you know when you are ready.
Are these official AB-900 exam questions?
No. CertGrid is an independent practice platform. We do not provide real or leaked exam questions. Our questions are original and designed to help you practice the concepts, scenarios, and difficulty style of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam.
Is there a free AB-900 practice test?
Yes. You can take a free AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals practice test straight away: a fixed set of 20 practice questions for this exam, retryable as often as you like, with no credit card required. You get readiness scoring and a weak-domain breakdown on those questions. Paid plans unlock the full 647-question bank, timed mock exams and full-bank domain analytics.
What CertGrid is (and is not)
CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.
Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Microsoft. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.