Microsoft Open Module
Log In Create Account
Certification learning module

Security Governance and Responsible AI

Apply authentication, conditional access, data protection, Purview, and responsible AI controls.

Module 5 of 6 About 5 min Microsoft 365 Certified: Copilot and Agent Administration Fundamentals (AB-900)
83%
Course position
Module 5

Security Governance and Responsible AI

Apply authentication, conditional access, data protection, Purview, and responsible AI controls.

Microsoft 365 Certified: Copilot and Agent Administration Fundamentals (AB-900)

AB-900 Security, Governance, and Responsible AI

In AB-900, secure Copilot and agent use begins with the organization's existing identity, permissions, data-protection, and governance decisions. Read the data risk before choosing a control.

What This AB-900 Module Covers

The current study guide places data protection and governance at the largest published weighting. It includes Microsoft Purview capabilities, classification and sensitivity labels, data loss prevention, retention, Microsoft Graph, data security for Copilot, responsible AI, risk investigation, and SharePoint oversharing. The learner's job is to match the stated risk with the control category, then the appropriate administrative action.

Security Reasoning Starts With Four Boundaries

Boundary Question to ask Examples to recognize
Identity Who is signing in, and what role or access is appropriate? Microsoft Entra ID, authentication, Conditional Access, roles, and least privilege.
Data access What organizational content may the user already reach? Microsoft Graph, SharePoint and Microsoft 365 permissions, site access, and oversharing review.
Data protection How should sensitive information be classified, protected, retained, or prevented from leaving an approved boundary? Microsoft Purview Information Protection, sensitivity labels, DLP, retention, and restricted access controls.
Governance and evidence What policy, signal, investigation, or human decision is required? Activity review, Data Explorer, risk investigation, Compliance Manager, eDiscovery content search, and governance reports.

Choose the Control Category, Not a Familiar Product

  • Protect: use protection reasoning when the requirement is to classify sensitive information or reduce inappropriate sharing or handling.
  • Prevent: use DLP reasoning when a scenario calls for stopping or limiting a prohibited sharing or handling action.
  • Retain: use lifecycle reasoning when information must be kept or managed for a defined period. Retention does not create access rights.
  • Investigate: use audit, activity, search, or risk-investigation reasoning when the question asks what occurred or which content needs review.
  • Reduce oversharing: inspect the access model when a user can reach content too broadly. A productivity feature is not the first remedy for an access-boundary problem.

Responsible AI in an Administrative Scenario

Responsible AI is a practical decision lens, not a separate replacement for security controls. When a scenario describes risk, identify whether it needs human oversight, policy and governance, clear information about intended use, privacy and security protection, or monitoring for harmful or unexpected outcomes. Then choose the Microsoft 365 administrative capability that supports that boundary. Do not assume that enabling an AI feature removes accountability for data access or review.

Read

Read the data-protection and governance domain in the official AB-900 study guide, then complete the Microsoft Learn module on protecting and governing Microsoft 365 data. For every capability, write two notes: the risk it addresses and the evidence an administrator could use to confirm or investigate the result.

Scope

Classify each prompt as identity, access, protection, prevention, retention, investigation, oversharing, or responsible-use governance before choosing a solution. For example, a request to find out who accessed sensitive content is an investigation question. A request to stop sensitive content from being shared is a prevention question. This distinction eliminates many plausible but wrong AB-900 answers.

Drill

  1. A collaborative site contains files that too many users can access. Identify the access and oversharing issue before considering an AI capability.
  2. A compliance analyst needs to review activity related to a policy concern. Distinguish investigation evidence from a control that would prevent future sharing.
  3. A department wants to use Copilot with internal information. Explain how the user's existing permissions, Microsoft Graph, and governance controls affect the safe answer.
  4. A business owner asks for a responsible AI safeguard. State the risk, the role of human oversight or governance, and the administrative control category that supports it.

Prove

You are ready to move on when you can explain the difference between who can access data, how data is protected, how an unwanted action is prevented, and how an event is investigated. In an AB-900 answer, the control must meet the stated data boundary without granting broader access or confusing a report with a remediation.

Official AB-900 Learning Sources