Microsoft 365 Certified: Copilot and Agent Administration Fundamentals (AB-900)
AB-900 Security, Governance, and Responsible AI
In AB-900, secure Copilot and agent use begins with the organization's existing identity, permissions, data-protection, and governance decisions. Read the data risk before choosing a control.
What This AB-900 Module Covers
The current study guide places data protection and governance at the largest published weighting. It includes Microsoft Purview capabilities, classification and sensitivity labels, data loss prevention, retention, Microsoft Graph, data security for Copilot, responsible AI, risk investigation, and SharePoint oversharing. The learner's job is to match the stated risk with the control category, then the appropriate administrative action.
Security Reasoning Starts With Four Boundaries
| Boundary | Question to ask | Examples to recognize |
|---|---|---|
| Identity | Who is signing in, and what role or access is appropriate? | Microsoft Entra ID, authentication, Conditional Access, roles, and least privilege. |
| Data access | What organizational content may the user already reach? | Microsoft Graph, SharePoint and Microsoft 365 permissions, site access, and oversharing review. |
| Data protection | How should sensitive information be classified, protected, retained, or prevented from leaving an approved boundary? | Microsoft Purview Information Protection, sensitivity labels, DLP, retention, and restricted access controls. |
| Governance and evidence | What policy, signal, investigation, or human decision is required? | Activity review, Data Explorer, risk investigation, Compliance Manager, eDiscovery content search, and governance reports. |
Choose the Control Category, Not a Familiar Product
- Protect: use protection reasoning when the requirement is to classify sensitive information or reduce inappropriate sharing or handling.
- Prevent: use DLP reasoning when a scenario calls for stopping or limiting a prohibited sharing or handling action.
- Retain: use lifecycle reasoning when information must be kept or managed for a defined period. Retention does not create access rights.
- Investigate: use audit, activity, search, or risk-investigation reasoning when the question asks what occurred or which content needs review.
- Reduce oversharing: inspect the access model when a user can reach content too broadly. A productivity feature is not the first remedy for an access-boundary problem.
Responsible AI in an Administrative Scenario
Responsible AI is a practical decision lens, not a separate replacement for security controls. When a scenario describes risk, identify whether it needs human oversight, policy and governance, clear information about intended use, privacy and security protection, or monitoring for harmful or unexpected outcomes. Then choose the Microsoft 365 administrative capability that supports that boundary. Do not assume that enabling an AI feature removes accountability for data access or review.
Read
Read the data-protection and governance domain in the official AB-900 study guide, then complete the Microsoft Learn module on protecting and governing Microsoft 365 data. For every capability, write two notes: the risk it addresses and the evidence an administrator could use to confirm or investigate the result.
Scope
Classify each prompt as identity, access, protection, prevention, retention, investigation, oversharing, or responsible-use governance before choosing a solution. For example, a request to find out who accessed sensitive content is an investigation question. A request to stop sensitive content from being shared is a prevention question. This distinction eliminates many plausible but wrong AB-900 answers.
Drill
- A collaborative site contains files that too many users can access. Identify the access and oversharing issue before considering an AI capability.
- A compliance analyst needs to review activity related to a policy concern. Distinguish investigation evidence from a control that would prevent future sharing.
- A department wants to use Copilot with internal information. Explain how the user's existing permissions, Microsoft Graph, and governance controls affect the safe answer.
- A business owner asks for a responsible AI safeguard. State the risk, the role of human oversight or governance, and the administrative control category that supports it.
Prove
You are ready to move on when you can explain the difference between who can access data, how data is protected, how an unwanted action is prevented, and how an event is investigated. In an AB-900 answer, the control must meet the stated data boundary without granting broader access or confusing a report with a remediation.
Official AB-900 Learning Sources
- Microsoft Learn: Study guide for Exam AB-900 - Official objectives for Purview, Copilot data security, Microsoft Graph, responsible AI, risk investigation, and oversharing.
- Microsoft Learn: Protect and govern Microsoft 365 data - Self-paced module covering data protection and governance concepts.
- Microsoft Learn: Explore Microsoft 365 security foundations - Self-paced module for identity and security foundations.
- Microsoft Learn: Explore Microsoft 365 administration - Official learning path that includes governance and data-protection work.