- 75 Actual Exam Questions
- Compatible with all Devices
- Printable Format
- No Download Limits
- 90 Days Free Updates
Get All Microsoft 365 Copilot and Agent Administration Fundamentals Exam Questions with Validated Answers
| Vendor: | Microsoft |
|---|---|
| Exam Code: | AB-900 |
| Exam Name: | Microsoft 365 Copilot and Agent Administration Fundamentals |
| Exam Questions: | 75 |
| Last Updated: | October 7, 2026 |
| Related Certifications: | Microsoft 365 |
| Exam Tags: | Modern work certifications |
Looking for a hassle-free way to pass the Microsoft 365 Copilot and Agent Administration Fundamentals exam? DumpsProvider provides the most reliable Dumps Questions and Answers, designed by Microsoft certified experts to help you succeed in record time. Available in both PDF and Online Practice Test formats, our study materials cover every major exam topic, making it possible for you to pass potentially within just one day!
DumpsProvider is a leading provider of high-quality exam dumps, trusted by professionals worldwide. Our Microsoft AB-900 exam questions give you the knowledge and confidence needed to succeed on the first attempt.
Train with our Microsoft AB-900 exam practice tests, which simulate the actual exam environment. This real-test experience helps you get familiar with the format and timing of the exam, ensuring you're 100% prepared for exam day.
Your success is our commitment! That's why DumpsProvider offers a 100% money-back guarantee. If you don’t pass the Microsoft AB-900 exam, we’ll refund your payment within 24 hours no questions asked.
Don’t waste time with unreliable exam prep resources. Get started with DumpsProvider’s Microsoft AB-900 exam dumps today and achieve your certification effortlessly!
A user named User1 creates a Microsoft 365 Copilot agent named Agent1 and shares the agent to a user named User2. What occurs if an admin blocks Agent1?
The correct answer is B. Microsoft documents that admins can block agents in the Microsoft 365 admin center, and when administrators block Microsoft agents such as Researcher and Analyst, those agents are made inaccessible to all users in the tenant. Microsoft's agent management guidance also states that admins can manage agent lifecycle and access centrally, including blocking or removing agent availability across the organization.
Your organization has a Microsoft 365 subscription.
All users are assigned a Microsoft 365 Copilot license.
You need to prevent the users from generating images by using Copilot.
What should you use?
The correct answer is C. the Microsoft 365 admin center. Microsoft Learn documents a specific Copilot image generation setting in the Microsoft 365 admin center under Copilot > Settings > Copilot actions > Copilot image generation. Microsoft states that when this scenario is allowed, users can ask Copilot to create, design, and edit images. When it is not allowed, Copilot does not generate images and instead responds with stock or brand images. This directly matches the requirement to prevent users from generating images by using Copilot.
The other options are incorrect because Microsoft does not document this control as being managed from Defender, Purview, or Entra for this scenario. Microsoft also separately notes that organizations can control access to Designer image generation through policy, but the admin experience for managing the Microsoft 365 Copilot scenario itself is explicitly surfaced in the Microsoft 365 admin center. Therefore, for an exam question focused on where an admin should go to disable image generation in Copilot, the best and documented answer is the Microsoft 365 admin center.
Which statement accurately describes authorization in Microsoft 365?
The correct answer is C because Microsoft explains that authorization is the process of determining whether an authenticated identity is allowed to access a resource. Microsoft Learn distinguishes authorization from authentication by stating that authentication proves who you are, while authorization decides what you can access or do after identity has been established. In Microsoft 365 and the Microsoft identity platform, authorization commonly involves permissions, scopes, roles, and consent that control access to data and services such as Microsoft Graph, Exchange, SharePoint, or Teams.
Option A is incorrect because it refers more to external identity validation or federation concepts, not authorization itself. Option B describes authentication, not authorization, since it is about verifying identity claims. Option D describes a control such as multifactor authentication or Conditional Access requirements, which can happen before access is granted, but that still is not the definition of authorization. Authorization begins after identity verification and focuses on whether the identity has the right permissions for the requested resource.
Your company requires that all Microsoft SharePoint sites have a minimum of two owners.
You need to ensure that sites that have less than two owners are marked as read-only if the sites are NOT remediated.
What should you configure in the SharePoint admin center?
The correct answer is C. Site lifecycle management. In the SharePoint admin center, Microsoft includes a Site ownership policy under Site lifecycle management that can identify sites with too few owners and drive remediation. Microsoft documents that this policy can detect sites with fewer than the required number of owners, notify site owners, and if the issue is not fixed, enforce an action such as making the site read-only. That directly matches the requirement that sites with fewer than two owners be marked as read-only when they are not remediated.
The other options do not fit this scenario. Site-level access restriction is about controlling who can access a site, not enforcing ownership-count governance. Data access governance reports help identify oversharing and permissions exposure, but they do not enforce a minimum-owner remediation policy that makes sites read-only. Block download policy for SharePoint and OneDrive is used to restrict downloading from unmanaged devices or similar access scenarios, not to handle insufficient site ownership. Therefore, the Microsoft-documented feature to configure is Site lifecycle management.
Your organization has a Microsoft 365 E5 subscription.
You need to prevent users from sharing corporate financial data to external users. What should you use?
The correct answer is B. data loss prevention (DLP) policies. Microsoft Learn states that Microsoft Purview Data Loss Prevention helps organizations identify, monitor, and automatically protect sensitive information across Microsoft 365 locations such as Exchange, SharePoint, OneDrive, Teams, and devices. Microsoft specifically documents scenarios for preventing sensitive items from being shared with external users in SharePoint and OneDrive, and DLP policies can also block or restrict sharing based on sensitive information types, labels, or policy conditions. This is exactly the control used when the requirement is to stop users from sharing corporate financial data outside the organization.
Option A is incorrect because retention labels manage how long content is kept or deleted, not whether it can be shared externally. Option C is incorrect because role groups are used for permissions and administrative access delegation, not content-sharing prevention. Option D is incorrect because Insider Risk Management is designed to detect and investigate risky user behavior, not to directly block external sharing transactions in the way DLP policies do. For proactive enforcement of external-sharing restrictions on sensitive financial information, Microsoft's documented solution is DLP policies.
Security & Privacy
Satisfied Customers
Committed Service
Money Back Guranteed