Free AB-900 Exam Flashcards
Memorize 50 essential terms and definitions for the Microsoft 365 Copilot and Agent Administration Fundamentals (AB-900). See the term, recall the definition, then flip to check yourself.
Copilot Administrator role
A Microsoft Entra role scoped to manage Microsoft 365 Copilot settings, usage policies, and configurations without full Global Administrator privileges. Follows least-privilege: use this role instead of Global Admin for day-to-day Copilot administration.
Filter by Topic
Jump to Card
About These AB-900 Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the Microsoft 365 Copilot and Agent Administration Fundamentals (AB-900). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Complete Flashcard Reference
Review every term in this set. Open any term to reveal its definition.
Copilot Administrator role
A Microsoft Entra role scoped to manage Microsoft 365 Copilot settings, usage policies, and configurations without full Global Administrator privileges. Follows least-privilege: use this role instead of Global Admin for day-to-day Copilot administration.
Microsoft 365 Copilot license assignment
Per-user add-on licenses are assigned in the Microsoft 365 admin center under Active users > Licenses and apps. Only licensed users can access Copilot features in Word, Excel, PowerPoint, Outlook, Teams, and other integrated apps.
Copilot Usage Report
An admin-center report showing aggregated Copilot adoption: active users, feature-level usage (chat, email, meetings, documents), and trends across the licensed population. Used to measure ROI and identify departments needing training.
Microsoft Copilot Dashboard (Viva Insights)
Gives organizational leaders visibility into Copilot adoption metrics, feature usage trends, and aggregated employee sentiment about Copilot helpfulness. Adoption analytics tool — not a DLP or forensic audit source.
Web grounding toggle
An org-wide Copilot admin setting that controls whether Copilot can query Bing and public web content to supplement internal data. Regulated industries often disable it to keep responses strictly within governed organizational data.
Microsoft 365 Copilot vs custom agents
Microsoft 365 Copilot is the built-in productivity assistant across M365 apps using the semantic index. Custom agents are organization-built AI assistants created in Copilot Studio with specific topics, knowledge sources, and actions — they require separate governance and approval.
Copilot pay-as-you-go billing
An alternative to per-user monthly Copilot licenses where consumption is metered and billed based on actual usage. Admins manage billing policies in the Microsoft 365 admin center to control cost exposure for variable or pilot deployments.
Microsoft Graph and Copilot data access
Copilot retrieves organizational content through Microsoft Graph permissions — only data the signed-in user can already access. Copilot does not bypass SharePoint, OneDrive, or Exchange permissions; oversharing in source locations directly increases Copilot exposure risk.
Semantic index
Microsoft 365's pre-built index of organizational content that enables Copilot to ground responses in tenant data. Indexing respects existing permissions; admins cannot use the index to expose data users were not already authorized to see.
Responsible AI principles (Microsoft)
Microsoft's framework: fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. AB-900 admins apply these when governing Copilot deployment, prompt policies, and agent approval workflows.
Microsoft Copilot Studio
A low-code platform for building, customizing, and deploying AI agents and copilots. Enables custom topics, knowledge sources, Power Automate actions, and multi-channel deployment (Teams, web, SharePoint) without deep coding expertise.
Topic (Copilot Studio)
A modular conversation flow triggered by specific user intents. Contains trigger phrases that activate it and a sequence of nodes (messages, questions, actions) guiding the agent's response. Building blocks of custom agent logic.
Agent approval process
Organizations can require admin approval before custom agents are published or made available to users. Prevents ungoverned agents from accessing organizational data or performing actions without security review.
Agent lifecycle management
End-to-end governance of custom agents: creation in Copilot Studio, security review, approval, deployment to channels, usage monitoring, and retirement. Monitored through Microsoft 365 admin center and Power Platform admin center.
Power Platform admin center
Administrative hub for managing Copilot Studio agents, Dataverse environments, DLP policies for connectors, and tenant-level Power Platform settings. Critical for agent governance alongside the M365 admin center.
Teams channel deployment (Copilot Studio)
A deployment option that publishes a custom agent as a Teams app, making it available directly within Microsoft Teams channels and chats. Requires appropriate Teams app permission policies.
Knowledge sources (Copilot Studio)
Data connections that ground agent responses: public websites, SharePoint sites, uploaded files, or Dataverse tables. Admins must verify sensitivity of connected sources because agents inherit access patterns of configured knowledge.
Zero Trust (Microsoft 365)
Security model based on 'never trust, always verify.' Core pillars: verify explicitly, use least-privilege access, and assume breach. Applied through Entra ID, Conditional Access, MFA, and continuous monitoring across M365 workloads.
Microsoft Entra ID
Microsoft's cloud identity and access management service (formerly Azure AD). Manages users, groups, app registrations, Conditional Access policies, MFA, SSO, and admin roles across Microsoft 365 and Azure.
Conditional Access
Entra ID policies that enforce access controls based on signals: user, location, device compliance, application, and risk level. Example: require MFA for all admin portal sign-ins or block legacy authentication protocols.
Privileged Identity Management (PIM)
Entra ID service providing just-in-time, time-bound activation of privileged roles (Global Admin, Exchange Admin). Reduces standing admin access — admins must activate roles with justification and optional approval.
Single Sign-On (SSO)
Authentication method allowing users to access multiple applications with one set of credentials. In M365, Entra ID federates with on-premises Active Directory or enables passwordless sign-in across cloud apps.
Identity Secure Score
A percentage score in the Microsoft Entra admin center measuring your tenant's identity security posture against Microsoft best practices. Recommendations include enabling MFA, blocking legacy auth, and reducing global admin count.
SharePoint admin center
Portal for managing SharePoint sites, site collections, sharing policies, storage quotas, and permissions. Critical for Copilot governance because overshared SharePoint content is a primary source of unintended AI data exposure.
Teams admin center
Manages Teams policies: meeting settings, messaging policies, app permission policies, and guest access. Copilot in Teams meetings and chat inherits Teams data governance and retention settings configured here.
Exchange Online admin center
Manages mailboxes, distribution groups, mail flow rules, and mailbox permissions. Copilot in Outlook accesses email content the user can already read — mailbox delegation and shared mailbox permissions affect Copilot exposure.
Microsoft Purview
Unified compliance and data governance platform spanning information protection, data loss prevention, insider risk, eDiscovery, audit, and DSPM for AI. The primary governance toolkit for AB-900's largest exam domain.
Sensitivity labels
Classification tags applied to emails, documents, and Teams messages indicating confidentiality level (e.g., Public, Internal, Confidential). Can enforce encryption, watermarking, and access restrictions. Copilot respects label policies when generating content.
Data Loss Prevention (DLP)
Purview policies that detect and block sharing of sensitive information (SSN, credit cards, health data) across Exchange, SharePoint, OneDrive, Teams, and Copilot interactions. Prevents accidental or intentional data exfiltration.
Insider Risk Management
Purview solution detecting risky insider behaviors: data exfiltration, security policy violations, and intellectual property theft. Uses signals from M365 activity to identify users who may pose data security threats, including risky Copilot usage patterns.
Communication Compliance
Purview feature monitoring communications (email, Teams, Copilot interactions) for policy violations: harassment, threats, regulatory compliance issues. Uses ML classifiers and keyword policies to flag content for reviewer investigation.
DSPM for AI
Data Security Posture Management for AI in Microsoft Purview. Discovers AI activity across the organization, identifies sensitive data accessed by Copilot, and helps maintain security posture as AI adoption scales. Key AB-900 governance concept.
Retention policies
Purview policies defining how long content is kept before deletion or archival. Apply to Exchange, SharePoint, OneDrive, Teams, and Copilot-generated content. Balance compliance retention requirements against data minimization for AI exposure.
Data classification
Process of identifying and labeling data by sensitivity and business impact. In Purview, auto-classification scanners detect sensitive info types in content. Foundation for applying DLP, retention, and sensitivity label policies.
SharePoint oversharing
When SharePoint sites or files have overly permissive sharing links ('Anyone' links) or excessive guest access. A major Copilot risk because Copilot can surface overshared content to users who should not see it. Managed via access governance reports and Advanced Management.
Data Access Governance reports
SharePoint reports showing who has access to sites and files, highlighting overshared content and inactive sharing links. Admins use these to remediate permissions before or after Copilot deployment.
Microsoft Purview Audit
Logs user and admin activity across M365 services including Copilot interactions. Enables forensic investigation of who accessed what data through AI tools. Audit log retention depends on licensing (standard vs premium).
eDiscovery (Purview)
Legal hold and content search across M365 for litigation and investigations. Can include Copilot-generated content and prompts in search scopes when organizations need to preserve or review AI-related communications.
Information Protection (Purview)
Suite of capabilities for classifying and protecting sensitive data: sensitivity labels, label policies, encryption, rights management, and auto-labeling. Ensures Copilot operates within defined data protection boundaries.
Prompt governance
Organizational policies controlling how employees use Copilot prompts: approved use cases, prohibited data types in prompts, and monitoring through Purview. Prevents users from pasting credentials, PII, or trade secrets into Copilot chat.
Multi-Factor Authentication (MFA)
Requires two or more verification methods to sign in (password + phone app, FIDO key). Foundational Zero Trust control enforced via Entra Conditional Access. Should be required for all users, especially admins accessing Copilot governance tools.
Service Health dashboard
Microsoft 365 admin center view showing current service status, active incidents, and planned maintenance for Exchange, SharePoint, Teams, and Copilot services. Not a usage analytics tool — monitors availability, not adoption.
Message Center
Admin notification feed for planned M365 feature changes, deprecations, and updates. Copilot admins should monitor it for new Copilot capabilities, policy changes, and governance feature releases affecting their tenant.
Data residency (Microsoft 365)
Geographic location where Microsoft stores tenant data at rest. Copilot processing occurs within the tenant's data boundary; admins in regulated industries verify residency meets jurisdictional requirements before enabling AI features.
Customer Lockbox
M365 feature requiring admin approval before Microsoft support engineers can access tenant content during a support request. Provides an additional data access control layer relevant to organizations deploying Copilot on sensitive data.
Microsoft 365 E5 vs E3 for Copilot governance
E5 includes advanced Purview capabilities (Insider Risk Management, Communication Compliance, advanced audit) needed for comprehensive Copilot governance. E3 provides basic DLP and sensitivity labels but lacks several AI governance tools tested on AB-900.
Microsoft 365 Copilot prerequisite licenses
Copilot requires a qualifying base license (Microsoft 365 E3/E5, Business Standard/Premium, or Office 365 E3/E5) plus the Copilot add-on. Admins verify both licenses are assigned before users can access Copilot features.
Adoption Score
Microsoft 365 admin center metric measuring overall productivity adoption across all workloads — not Copilot-specific. Distinct from the Copilot Usage Report, which tracks only Copilot feature adoption and active users.
Integrated apps (M365 admin center)
Section managing third-party and custom app integrations with M365, including Copilot plugins and connectors. Admins control which external data sources and actions Copilot and agents can access through approved integrations.
AB-900 annual renewal assessment
Free online assessment on Microsoft Learn required yearly to maintain the Copilot and Agent Administration Fundamentals certification. Unlike older Dynamics fundamentals certs, AB-900 expires annually to keep knowledge current with rapidly evolving AI features.
Frequently Asked Questions
What is the AB-900 exam?
The AB-900 (Microsoft 365 Copilot and Agent Administration Fundamentals) exam validates foundational knowledge for supporting an AI-enabled Microsoft 365 environment. It covers core M365 services and security, data protection with Microsoft Purview, and Copilot and agent administration including licensing, usage monitoring, and lifecycle management.
What score do I need to pass AB-900?
You need a scaled score of 700 out of 1000 (70%) to pass AB-900. The exam contains 40-60 questions in 60 minutes and is delivered through Pearson VUE. The exam fee is $99 USD.
What are the main AB-900 exam domains?
AB-900 has three domains: Data Protection and Governance for Microsoft 365 and Copilot (35-40%), Core Features and Objects of Microsoft 365 Services (30-35%), and Basic Administrative Tasks for Copilot and Agents (25-30%). Purview governance and Copilot data access are the heaviest-weighted areas.
Does AB-900 certification expire?
Yes. AB-900 requires annual renewal through a free online assessment on Microsoft Learn. This keeps your Copilot and agent administration knowledge current as Microsoft 365 AI features evolve rapidly.
How is AB-900 different from MS-900?
MS-900 covers broad Microsoft 365 services, security, and licensing fundamentals. AB-900 focuses specifically on administering Microsoft 365 Copilot and agents, with deeper coverage of Purview governance, Copilot data access via Microsoft Graph, agent lifecycle management, and responsible AI controls.
What is DSPM for AI on the AB-900 exam?
Data Security Posture Management (DSPM) for AI is a Microsoft Purview capability that helps organizations discover AI activity, identify sensitive data accessed by Copilot, and maintain security posture as AI usage scales. It is a key governance tool in the largest AB-900 domain.
Explore More Microsoft Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.