AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals
Fundamentals of administering Microsoft 365 Copilot and agents — M365 admin centers, Entra ID, Purview data governance, DSPM for AI, license + prompt + adoption management. AB-900 exam prep.
View badge details
Exam Preparation Included
Practice with real exam-style questions for the AB-900 certification. AI-powered feedback helps you understand every answer.
About This Course
Learn to administer Microsoft 365 Copilot and agents alongside the Microsoft 365 admin centers, Microsoft Entra ID, and Microsoft Purview. Explore how Zero Trust identity, sensitivity labels, DLP, and DSPM for AI keep Copilot responses safe, then perform the routine tasks license assignment, prompt management, adoption analytics, and custom-agent lifecycle that keep AI-driven productivity flowing. By the end of this course you will be able to describe the core Microsoft 365 admin surface, recognize the data-protection controls that govern Copilot, and complete the fundamentals-level administrative tasks the AB-900 exam measures.
Course Curriculum
15 Lessons
Microsoft 365 service landscape and admin centers
Meet Meridian Grove Consulting through the lens of a brand-new Microsoft 365 admin. In this lesson you will build a mental map of the Microsoft 365 licensing landscape (E3, E5, Business Premium, and the Copilot add-on) and the seven admin surfaces you use daily — the Microsoft 365 admin center, Exchange, SharePoint, Teams, Entra, Purview, and Defender. By the end of the lesson you will be able to identify which admin center owns a given object (mailbox, site, team, user, license) and describe how license assignment flows from purchase to end-user experience.
Explore the Microsoft 365 Admin Center and workload admin centers - Lab Exercises
Tour every Microsoft 365 admin surface you will use in a fundamentals administrator role. You will explore the Microsoft 365 admin center, Exchange admin center, SharePoint admin center, and Teams admin center, then compile a cross-cutting inventory of the tenant configuration you observe. The lab tenant is a bare sandbox with only Microsoft's default configuration — some blades will show small counts or empty lists, and that is a valid observation to record. By the end of this lab you will be able to navigate every workload admin center referenced on the AB-900 exam and describe the tenant-level settings each surface exposes.
Zero Trust, Microsoft Entra ID, and access controls
Learn the identity and access foundations that keep Microsoft 365 Copilot responses safe. You will explore the three Zero Trust principles as Microsoft applies them, the modern authentication methods that replaced passwords, Conditional Access as the runtime policy engine, the difference between app registrations and enterprise apps, Identity Secure Score as an ongoing hygiene signal, and Privileged Identity Management for just-in-time admin access. By the end of this lesson you will be able to describe how Microsoft Entra ID enforces Zero Trust across the Meridian Grove Consulting tenant and recognize the AB-900 exam objectives for security principles and core security features.
Explore Microsoft Entra ID: users, groups, Conditional Access, MFA, PIM - Lab Exercises
Explore Microsoft Entra ID as a Global Reader - the read-only counterpart to Global Administrator. You will walk the Entra admin center to observe users, groups, Conditional Access, authentication methods, Identity Secure Score, and Privileged Identity Management (PIM), and understand how each fits together to keep a Microsoft 365 tenant secure. Because your lab tenant is a bare sandbox with only defaults and your own Global Reader account, some blades will show empty grids or zero policies - that "empty state" is itself informative and mirrors what a Day-1 admin sees on a fresh tenant. By the end of this lab you will be able to identify the appropriate Entra ID objects and controls the AB-900 exam measures, and describe why a real admin would engage each one in a production tenant.
Microsoft Purview foundations for Copilot governance
Learn how Microsoft Purview underpins the data protection story behind Microsoft 365 Copilot. You will explore the Purview solutions catalog, sensitivity labels and Information Protection, data classification and trainable classifiers, Data Loss Prevention (DLP), Communication Compliance, Insider Risk Management, and the Data Lifecycle Management and retention story. By the end of this lesson you will be able to recognize which Purview solution addresses each governance risk that Copilot introduces, and describe how sensitivity labels, DLP, and IRM combine to keep Copilot responses safe.
Explore the Microsoft Purview portal: DLP, sensitivity labels, Compliance Manager - Lab Exercises
Learn how the Microsoft Purview portal frames Copilot governance. You will tour the Purview solutions catalog, explore sensitivity labels + policies, walk the DLP surface, inspect data classification and trainable classifiers, review Compliance Manager, and open Communication Compliance policies. By the end of this lab you will be able to identify each Purview solution the AB-900 exam measures, recognize their role in Copilot data protection, and read the settings pages a Microsoft 365 admin uses every week - all from a read-only Global Reader account with zero risk to the tenant.
Data security implications of Microsoft 365 Copilot
Learn how Microsoft 365 Copilot accesses tenant data through Microsoft Graph, why Copilot only returns content the signed-in user is already permitted to read, and how Microsoft Purview and Microsoft Defender combine to keep responses safe. By the end of this lesson you will be able to describe the Copilot grounding pipeline, recognize oversharing risks, and identify the DSPM-for-AI, DLP, and eDiscovery controls a fundamentals-level admin uses to govern Copilot activity.
Explore DSPM for AI and Insider Risk Management for Copilot - Lab Exercises
Learn to inventory the AI-governance tooling that lives across Microsoft Purview - Data Security Posture Management (DSPM) for AI, Insider Risk Management, and eDiscovery Content Search - so you can describe what each surface tracks about Microsoft 365 Copilot interactions and where a fundamentals-level administrator would start when asked to inventory AI-risk controls. By the end of this lab you will be able to navigate the Purview DSPM for AI dashboard, recognize the recommended AI-risk policy templates, describe the Risky AI Usage Insider Risk template, and locate Copilot interactions through eDiscovery Content Search. The lab tenant is a bare sandbox - dashboards, alerts, and eDiscovery cases will be empty, which is realistic for a fresh Copilot deployment and is itself the finding you record.
Oversharing controls in SharePoint
Learn to recognize and address oversharing risks in SharePoint that let Microsoft 365 Copilot surface content beyond its intended audience. You will explore how default sharing settings, sharing-link types, and legacy migrated sites create exposure, then walk through the SharePoint Advanced Management toolkit — Data Access Governance reports, Restricted Content Discovery, Restricted Access Control, and site sensitivity labels — that mitigates that exposure. By the end of this lesson you will be able to describe the SharePoint oversharing risk pattern and identify the correct governance tool for a given remediation scenario.
Run oversharing reports and explore SharePoint Advanced Management - Lab Exercises
In this hands-on lab you will learn to run the SharePoint oversharing reports and inventory the SharePoint Advanced Management (SAM) controls that keep Microsoft 365 Copilot grounded in only the content it should see. By the end of this lab you will be able to locate the Data Access Governance (DAG) reports in the SharePoint admin center, interpret a Sharing Links report, identify which SAM features are lit up in a tenant, describe how Restricted Content Discovery (RCD) reshapes what Copilot returns, and read a Site Access Review to close the audit loop.
Microsoft 365 Copilot and agents: capabilities, licensing, and prebuilt agents
Learn how Microsoft 365 Copilot and agents differ, when to build declaratively with Agent Builder or the Microsoft 365 Agents Toolkit vs custom engine agents in Copilot Studio, and which prebuilt agents ship pre-pinned to every Microsoft Copilot user's rail. Understand the monthly-license and pay-as-you-go (Copilot Credits) billing models and the tenant-level toggles you use to enable or disable Copilot features. By the end of this lesson you will be able to explain the difference between Copilot and agents, identify the three agent build approaches and the current prebuilt catalog, and choose the right licensing model for a specific business scenario.
Administer Copilot: licenses, PAYG billing, prompt management, adoption analytics - Lab Exercises
Learn how to administer Microsoft 365 Copilot license assignment, Copilot Credits and pay-as-you-go billing, adoption analytics, prompt library governance, and Copilot Control System (CCS) tenant settings. You will sign in from the lab Windows 11 VM using the Global Reader account shown on the Environment tab and walk every control read-only. By the end of this lab you will be able to describe the Microsoft 365 admin surface for Copilot licensing, PAYG billing, adoption reporting, prompt management, and tenant-level Copilot settings — enough depth to speak to the AB-900 fundamentals objectives without any escalation surface on the tenant.
Agent lifecycle: create, approve, and monitor custom agents
Learn how Microsoft 365 Copilot agents move from an idea in Agent Builder to a production tool your organization can safely rely on. You will explore who can use an agent and how access is scoped, walk through the end-to-end authoring flow, understand the approval process that keeps shared agents governable, and see how the Copilot Control System and Power Platform admin center let administrators watch every agent in the tenant. By the end of this lesson you will be able to describe how a Microsoft 365 Copilot agent is created, approved, and monitored across its full lifecycle.
Manage agents in the Microsoft 365 and Power Platform admin centers - Lab Exercises
Learn to inventory, monitor, and govern Microsoft 365 Copilot agents from the two admin surfaces that own the lifecycle: the Copilot Control System inside the Microsoft 365 admin center and the Copilot Studio agents area inside the Power Platform admin center. By the end of this lab you will be able to locate any agent that appears in a tenant, verify who has access to it, walk through the approval-queue shape, and read the operational-health metrics — all read-only, from a Global Reader account.
End-to-end Microsoft 365 Copilot governance review - Lab Exercises
In this capstone review you walk every Microsoft 365 Copilot governance surface — Entra ID, Purview, DSPM for AI, SharePoint, the Microsoft 365 admin center, the Copilot Control System, and the Power Platform admin center — and compile a one-page governance-posture summary. The tenant is a fresh sandbox with sparse dashboards; your job is to describe what you observe AND what a real admin would look at in a production tenant. By the end of this capstone you will be able to describe the state of an M365 Copilot tenant's identity, data-protection, DSPM for AI, oversharing, license-adoption, and agent-governance posture in a single one-page summary.