The AB-900 exam “Copilot and Agent Administration Fundamentals” is going to be released (General Availability) around the start of the year 2026. It tests the user on their ability to manage Microsoft 365 and Copilot.
The requirements which are needed for this exam are as follows:
Identify the core features and objects of Microsoft 365 services (30–35%)
Identify the core objects of Microsoft 365 services
- Explain how license types assigned to users and groups affect access to Microsoft 365 features
- Explore the organization configurations by using the Microsoft 365 admin center (domain names and org settings)
- Identify the appropriate objects to configure by using the Exchange Online admin center (mailboxes and distribution lists)
- Identify the appropriate objects to configure by using the SharePoint in Microsoft 365 admin center (sites, libraries, and folders)
- Identify the appropriate roles and permissions for sites in SharePoint in Microsoft 365
- Identify the appropriate objects to configure by using the Teams admin center (teams, channels, and policies)
Understand the Microsoft 365 security principles
- Explain the core Zero Trust principles
- Understand authorization
- Understand authentication methods
- Understand threat protection and intelligence
- Understand features and capabilities of Microsoft Defender XDR
- Identify the core security features of Microsoft 365 services
Understand features and capabilities of Microsoft Entra
- Understand conditional access policies
- Understand the purpose and benefits of SSO
- Identify the appropriate security object to use in an organization (users and groups)
- Identify the appropriate tools to troubleshoot common sign-in issues (multifactor authentication [MFA], conditional access, and risky sign-ins)
- Interpret Identity Secure Score in Microsoft Entra ID
- Use the appropriate tools to review audit logs for user and admin activity
- Identify the role of Privileged Identity Management (PIM) in an organization
- Understand App registrations and Enterprise apps
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
Understand Microsoft Purview
- Understand features and capabilities of:
- Microsoft Purview Information Protection,
- Microsoft Purview Data Loss Prevention (DLP),
- Microsoft Purview Insider Risk Management,
- Microsoft Purview Communication Compliance,
- Microsoft Purview Data Security Posture Management (DSPM) for AI, and
- Microsoft Purview Data Lifecycle Management
- Identify the use cases for sensitivity labels in Microsoft Purview
- Understand data classification in Microsoft Purview
- Understand retention
Understand data security implications of Copilot
- Understand how Copilot accesses data
- Understand how Microsoft Graph influences Copilot responses
- Understand how Copilot uses permissions and other controls in Microsoft 365, Microsoft Purview, and Microsoft Defender to protect against risks
- Understand responsible AI principles
Identify data protection and governance risks for Microsoft 365 and Copilot
- Identify compliance risks and recommendations by using Microsoft Purview Compliance Manager
- Identify sensitive information by using Microsoft Purview Data Explorer
- Identify risks by using Insider Risk Management
- Identify and respond to alerts generated by Microsoft Purview DLP
- Identify policy violations generated by Communication Compliance
- Identify user activities reported by Microsoft Purview activity explorer
- Discover and manage AI activity by using DSPM for AI
- Search for files and emails by using Content search in Microsoft Purview eDiscovery
Identify and monitor oversharing in SharePoint in Microsoft 365
- Identify the tools to troubleshoot oversharing in an organization
- Run a data access governance report in SharePoint
- Understand features and capabilities of SharePoint Advanced Management, including restricted site access
Perform basic administrative tasks for Copilot and agents (25–30%)
Understand features and capabilities of Copilot and agents
- Compare the built-in capabilities of Copilot and agents
- Compare Copilot monthly license model to pay-as-you-go, including SharePoint
- Identify which Copilot features can be enabled or disabled
- Identify use cases for Researcher
- Identify use cases for Analyst
- Identify use cases for custom agents
Perform basic administrative tasks for Copilot
- Assign Copilot licenses
- Monitor and manage Copilot pay-as-you-go billing policies
- Monitor Copilot usage and adoption, including Copilot Analytics and the Microsoft 365 admin center
- Manage prompts, including saving, sharing, scheduling, and deleting
Perform basic administrative tasks for agents
- Identify how to configure user access to agents
- Create an agent
- Understand approval process for agents
- Monitor agents, including usage, operational insights, and agent lifecycle, by working with the Microsoft 365 admin center and the Microsoft Power Platform admin center
How can I learn the requirements?
If you want to learn the topics for the AB-900 exam, then please have a look at our AB-900: Copilot and Agent Administration Fundamentals exam preparation course.
Conclusion
We have that the above information will help you to be able to prepare for the AB-900 “Copilot and Agent Administration Fundamentals” exam. For more information about this exam, please read our blog article about the AB-900 exam.