CertSafari

    Free Administering Microsoft 365 and AI Services (AB-650) Sample Questions

    35 free sample questions from our bank of 365+, covering every exam domain, with answers and detailed explanations. Updated September 2026.

    Domain 1: Configure and manage Microsoft 365 tenants and workloads

    Subdomain 1.1: Configure and manage a Microsoft 365 tenant

    1.A compliance officer asks an admin to enable ongoing, storage-based protection for the legal department's SharePoint site so that historical versions of documents can be recovered later. Which capability, and configuration model, addresses this?

    1. A.Microsoft 365 Backup, billed under a pay-as-you-go model based on protected data volume
    2. B.Microsoft Purview retention policies, billed per user license assigned
    3. C.Network connectivity insights, billed per office location added
    4. D.Group-based licensing, billed per group membership count
    Show answer & explanation

    Correct answer: AMicrosoft 365 Backup, billed under a pay-as-you-go model based on protected data volume

    • A. Microsoft 365 Backup provides ongoing protection and point-in-time restore for SharePoint sites, and it is billed under a consumption-based pay-as-you-go model tied to the amount of data protected, matching what the compliance officer is asking for.
    • B. Retention policies preserve content for compliance holds rather than providing restorable backup snapshots, and they are not billed per user license, so this does not match the described need.
    • C. Network connectivity insights measures network performance metrics and has no relationship to protecting or restoring document content.
    • D. Group-based licensing assigns product entitlements based on group membership and has no data protection or restore capability.

    Subdomain 1.1: Configure and manage a Microsoft 365 tenant

    2.An admin is reviewing the Security & privacy tab under Org settings for a healthcare tenant. Which of the following controls would the admin expect to configure there? (Select 2)(Select 2)

    1. A.Restrictions on connecting the tenant to third-party storage services
    2. B.Organization-wide external sharing behavior for collaboration
    3. C.The organization's registered postal address on file with Microsoft
    4. D.The default currency used for purchasing new subscriptions
    Show answer & explanation

    Correct answers: A, BRestrictions on connecting the tenant to third-party storage services; Organization-wide external sharing behavior for collaboration

    • A. Controls limiting which third-party storage services can be linked into the tenant are part of the tenant's security and privacy governance, matching the scenario described.
    • B. Organization-wide sharing controls that govern how content can be shared externally are also configured under Security & privacy, since they directly affect data protection posture.
    • C. The organization's registered address is profile information found under Organization profile, not a security or privacy control.
    • D. Default purchasing currency is a billing configuration and is unrelated to the Security & privacy tab.

    Subdomain 1.1: Configure and manage a Microsoft 365 tenant

    3.A domain administrator is planning the DNS records needed after a custom domain is verified in the Microsoft 365 admin center so that mail flow and Teams work correctly. Which record types are typically part of this configuration? (Select 3)(Select 3)

    1. A.MX, for routing inbound mail to Exchange Online
    2. B.CNAME, for pointing service endpoints like Teams to Microsoft 365
    3. C.TXT (SPF), for authorizing Microsoft 365 to send mail on the domain's behalf
    4. D.SRV, exclusively for validating the tenant's billing subscription
    5. E.PTR, required to complete Microsoft 365 domain verification
    Show answer & explanation

    Correct answers: A, B, CMX, for routing inbound mail to Exchange Online; CNAME, for pointing service endpoints like Teams to Microsoft 365; TXT (SPF), for authorizing Microsoft 365 to send mail on the domain's behalf

    • A. An MX record is added after domain verification to route inbound email for the domain to Exchange Online's mail servers.
    • B. CNAME records are used to point specific service endpoints, such as those needed for Teams and other Microsoft 365 services, to the correct Microsoft-hosted addresses.
    • C. A TXT record containing an SPF value authorizes Microsoft 365 servers to send mail on behalf of the domain, helping prevent the domain's mail from being flagged as spoofed.
    • D. SRV records support specific service discovery scenarios, but they are not used to validate a tenant's billing subscription, so this describes an incorrect purpose.
    • E. PTR records are reverse-DNS records used for mail server reputation and are not part of the domain ownership verification process for Microsoft 365.

    Subdomain 1.2: Manage Microsoft 365 workloads

    4.An admin is converting a departing employee's user mailbox into a shared mailbox so the team can keep reading and replying to its content. Which of the following are true about this conversion? (Select all that apply)(Select 3)

    1. A.The mailbox retains its existing email address and message history.
    2. B.The Microsoft 365 license previously assigned to the user can be reassigned to another user.
    3. C.The mailbox can grow beyond 50 GB indefinitely without ever requiring a license.
    4. D.Full Access and Send As permissions must be reassigned to the team members who need access.
    5. E.Converting to a shared mailbox permanently deletes the mailbox's calendar and contacts.
    6. F.The account becomes permanently deleted from Microsoft Entra ID.
    Show answer & explanation

    Correct answers: A, B, DThe mailbox retains its existing email address and message history.; The Microsoft 365 license previously assigned to the user can be reassigned to another user.; Full Access and Send As permissions must be reassigned to the team members who need access.

    • A. Conversion changes the mailbox type but does not change its address or purge its existing mail, so history and address remain intact for the team to reference.
    • B. Because a shared mailbox no longer needs a per-user license under the 50 GB threshold, the license that was assigned to the departing employee can be freed up and reassigned.
    • C. Growth is only unlicensed up to the 50 GB threshold; beyond that the mailbox needs a license assigned to keep growing and receiving mail.
    • D. The former owner's personal delegation does not automatically extend to the rest of the team, so an admin must explicitly grant Full Access and Send As to the people who need to use the mailbox.
    • E. Conversion preserves the mailbox's existing folders, calendar, and contacts rather than deleting them; the team can still see prior appointments and contacts.
    • F. The associated account is disabled for interactive sign-in rather than deleted from Microsoft Entra ID, so the object still exists and the mailbox keeps functioning.

    Subdomain 1.2: Manage Microsoft 365 workloads

    5.A private channel owner wants to remove a member who no longer needs access to that channel's files, without affecting the person's membership in the parent team. What should the owner do?

    1. A.Remove the member from the private channel's member list only.
    2. B.Remove the member from the parent team, which also removes them from the channel.
    3. C.Delete and recreate the private channel without that member.
    4. D.Ask a Global Administrator to remove the member from Microsoft Entra ID.
    Show answer & explanation

    Correct answer: ARemove the member from the private channel's member list only.

    • A. Because a private channel keeps its own separate membership list, removing the person from just that list revokes their channel access while leaving their team membership untouched.
    • B. Removing the person from the parent team would also remove all of their other team access, which is broader than the requirement to only revoke this one channel.
    • C. Deleting and recreating the channel is unnecessary and destructive, losing the channel's existing files and conversation history to accomplish a simple membership change.
    • D. Deleting the person's Microsoft Entra account would remove all of their organizational access, far exceeding the goal of revoking one channel's membership.

    Subdomain 1.2: Manage Microsoft 365 workloads

    6.A compliance reviewer is comparing SharePoint permission levels assigned to different groups on a finance site. Which statements correctly describe the Contribute permission level, as distinct from Read and Full Control? (Select 2-3)(Select 3)

    1. A.Users can add, edit, and delete items in lists and document libraries.
    2. B.Users can view pages and download files but cannot make any changes.
    3. C.Users can change the site's permission levels and manage site collection settings.
    4. D.Users cannot create new lists or document libraries within the site.
    5. E.Users can upload new documents and edit existing ones without managing site-wide settings.
    6. F.Users can delete the entire site.
    Show answer & explanation

    Correct answers: A, D, EUsers can add, edit, and delete items in lists and document libraries.; Users cannot create new lists or document libraries within the site.; Users can upload new documents and edit existing ones without managing site-wide settings.

    • A. Contribute is defined by the ability to add, edit, and delete list items and documents, which is its core content-management capability.
    • B. View-only, no-change access describes Read permission, not Contribute, which explicitly allows content changes.
    • C. Managing site permissions and collection-level settings requires Full Control, not Contribute, which is scoped to content rather than administration.
    • D. Contribute stops short of managing lists, such as creating or deleting entire lists and libraries, which requires the higher Edit permission level.
    • E. Contribute lets users upload and edit documents while leaving site-wide configuration to higher permission levels like Full Control.
    • F. Deleting an entire site is a Full Control-level administrative action, well beyond what Contribute permits.

    Subdomain 1.2: Manage Microsoft 365 workloads

    7.Which statement correctly distinguishes Restricted SharePoint Search (RSS) from Restricted Content Discovery (RCD)?

    1. A.RSS is a temporary allow-list of up to 100 sites and does not change site permissions, while RCD is a per-site setting that hides specific sites from search and Copilot.
    2. B.RSS permanently changes site-level permissions, while RCD only affects the organization-wide search allow list.
    3. C.RSS and RCD both require PowerShell and cannot be configured from any admin center.
    4. D.RSS replaces the need for Microsoft Purview sensitivity labels entirely.
    Show answer & explanation

    Correct answer: ARSS is a temporary allow-list of up to 100 sites and does not change site permissions, while RCD is a per-site setting that hides specific sites from search and Copilot.

    • A. RSS is a temporary, curated allow list capped at roughly 100 sites that leaves permissions untouched, while RCD is applied per site to remove it from Copilot and search visibility without changing access.
    • B. Neither feature permanently changes site-level permissions; RSS is explicitly described as not a security boundary, and it is RCD, not the tenant-wide search allow list, that operates per site.
    • C. RCD is configured per site from the SharePoint admin center's site settings, so it does not require PowerShell the way RSS enablement does.
    • D. RSS is a temporary search visibility measure and is not a substitute for Microsoft Purview sensitivity labels, which apply data classification and protection independently.

    Domain 2: Govern and secure Microsoft 365 tenants and workloads

    Subdomain 2.1: Manage identities in Microsoft Entra

    8.An administrator is preparing to onboard 15 new employees to Microsoft 365 and wants each new account to receive an E3 license and standard collaboration access automatically once the account is created, without manually assigning licenses to each user. Which two actions accomplish this?(Select 3)

    1. A.Set the usage location on each user account
    2. B.Add each user to a group that has group-based licensing configured
    3. C.Assign the E3 license directly during account creation for each user
    4. D.Create a dynamic group membership rule that adds new users automatically
    5. E.Enable self-service password reset for the new accounts
    6. F.Configure a conditional access policy requiring MFA for new users
    Show answer & explanation

    Correct answers: A, B, DSet the usage location on each user account; Add each user to a group that has group-based licensing configured; Create a dynamic group membership rule that adds new users automatically

    • A. Setting the usage location is required before any license can apply to the account, making it a necessary action for the automatic assignment to succeed.
    • B. Group-based licensing applies the E3 license automatically to any member of the configured group, removing the need for manual per-user assignment.
    • C. Assigning the license directly during creation is a manual per-user action, which is exactly what the administrator wants to avoid at this scale.
    • D. A dynamic membership rule adds each new employee to the licensed group automatically based on their attributes, completing the hands-off onboarding flow.
    • E. Self-service password reset helps users manage their own credentials but has no effect on license assignment.
    • F. A conditional access MFA policy secures sign-in but does not assign licenses or collaboration access.

    Subdomain 2.1: Manage identities in Microsoft Entra

    9.Contoso's security team wants to allow B2B collaboration only with two named partner domains and block invitations to every other external domain, while also preventing guests from seeing group memberships beyond their own. Which two settings should the administrator configure in external collaboration settings?(Select 2)

    1. A.Configure collaboration restrictions with an allow list containing the two partner domains
    2. B.Set guest user access to restricted to properties and memberships of their own directory objects
    3. C.Disable guest self-service sign-up via user flows
    4. D.Assign the Guest Inviter role to all employees
    5. E.Set guest invite settings to allow anyone including guests to invite
    6. F.Enable Microsoft Entra ID Protection risk-based policies for guests
    Show answer & explanation

    Correct answers: A, BConfigure collaboration restrictions with an allow list containing the two partner domains; Set guest user access to restricted to properties and memberships of their own directory objects

    • A. An allow list in collaboration restrictions limits B2B invitations to only the two named partner domains and blocks every other domain.
    • B. The most restrictive guest user access setting confines guests to their own profile, satisfying the requirement to prevent them from seeing broader group memberships.
    • C. Self-service sign-up controls whether external users can create their own guest accounts through an app flow, which does not address domain restriction or membership visibility.
    • D. Granting Guest Inviter to every employee widens who can send invitations, which works against tightening external collaboration.
    • E. Allowing anyone including guests to invite widens invitation rights rather than restricting collaboration to two partner domains.
    • F. Risk-based Identity Protection policies address risky sign-ins, not which domains can be invited or what guests can view in the directory.

    Subdomain 2.1: Manage identities in Microsoft Entra

    10.During a review, Contoso finds that several employees hold the Global Administrator role as a permanent active assignment even though they rarely need it. The security team wants to reduce standing access while keeping the ability to escalate quickly when needed. Which two changes align with least-privilege recommendations?(Select 2)

    1. A.Convert the permanent active assignments to eligible assignments requiring activation
    2. B.Require multifactor authentication and justification for activation of the role
    3. C.Leave the assignments as permanent active but add a distribution group for tracking
    4. D.Grant every employee the Global Administrator role so tasks are never blocked
    5. E.Disable audit history for the role to reduce administrative overhead
    6. F.Assign the role to a shared account so no personal activation is required
    Show answer & explanation

    Correct answers: A, BConvert the permanent active assignments to eligible assignments requiring activation; Require multifactor authentication and justification for activation of the role

    • A. Converting the assignments to eligible removes standing access while still letting the employees activate the role quickly whenever it is genuinely needed.
    • B. Requiring MFA and justification at activation adds verification and accountability each time the role is used, reinforcing least privilege without blocking legitimate escalation.
    • C. Leaving the assignments permanent active does not reduce standing access at all; adding a tracking group does not change who holds the privileged role continuously.
    • D. Expanding Global Administrator to every employee massively increases standing privileged access, the opposite of what the security team wants.
    • E. Disabling audit history removes visibility into who used the role and when, which undermines governance rather than supporting least privilege.
    • F. A shared account for a privileged role removes individual accountability and activation controls, which works against least-privilege and auditability goals.

    Subdomain 2.3: Secure Microsoft 365 workloads

    11.Which Defender for Office 365 preset security policy is applied to a user by default if they are not included in the Standard or Strict preset security policies and have no custom Safe Links or Safe Attachments policy assigned?

    1. A.Built-in protection preset security policy
    2. B.Standard preset security policy
    3. C.EOP evaluation policy
    4. D.Default anti-malware policy
    Show answer & explanation

    Correct answer: ABuilt-in protection preset security policy

    • A. Built-in protection gives basic Safe Attachments and Safe Links coverage to every user who isn't excluded, isn't in Standard or Strict, and has no custom Safe Attachments or Safe Links policy, so it applies here.
    • B. Standard protection only applies to users explicitly included in its recipient scope, and this user was described as not being included in it.
    • C. An evaluation policy is a temporary, opt-in tool for comparing Defender for Office 365 detections against an existing solution and is not the fallback policy for uncovered users.
    • D. The default anti-malware policy is a separate baseline that scans for known malware signatures, but it is not what provides link and attachment protection to otherwise-uncovered users.

    Subdomain 2.3: Secure Microsoft 365 workloads

    12.A company wants employees who click a simulated phishing link to see relevant, in-context guidance immediately, rather than waiting for a scheduled training assignment. Which simulation element accomplishes this?

    1. A.The landing page configured in the simulation, shown to users immediately after they interact with the payload.
    2. B.The end-user notification schedule, which sends reminder emails on a recurring basis after simulation launch.
    3. C.The predicted compromise rate, which estimates the click-through percentage before the simulation runs.
    4. D.The payload automation feature, which harvests real phishing messages reported by users into future payloads.
    Show answer & explanation

    Correct answer: AThe landing page configured in the simulation, shown to users immediately after they interact with the payload.

    • A. The landing page is where users go the moment they open the payload, making it the mechanism for showing immediate, in-context feedback rather than a later scheduled message.
    • B. End-user notifications send periodic reminders such as training assignment or reminder emails, which happen on a schedule rather than at the instant of the click.
    • C. The predicted compromise rate is a pre-simulation estimate of likely click-through and has no role in what a user sees after interacting with the payload.
    • D. Payload automation converts reported real-world phishing into future simulation content and does not control what a user sees immediately after clicking during the current simulation.

    Subdomain 2.3: Secure Microsoft 365 workloads

    13.An admin needs a phishing simulation that mimics an attacker sending a link to a file hosted on a well-known file-sharing site; when the recipient opens the linked file, a macro runs on their device. Which social engineering technique should the admin select?

    1. A.Link to Malware, which sends a link to a hosted attachment on a familiar file-sharing site that runs code when opened.
    2. B.Link in Attachment, which sends an attachment containing a link that leads to a credential-harvesting login page.
    3. C.Malware Attachment, which sends the malicious file directly as an email attachment rather than as a hosted link.
    4. D.Drive-by URL, which sends a link to a compromised or cloned website that runs background code on click.
    Show answer & explanation

    Correct answer: ALink to Malware, which sends a link to a hosted attachment on a familiar file-sharing site that runs code when opened.

    • A. Link to Malware sends a link to an attachment hosted on a well-known file-sharing site such as SharePoint or Dropbox, and opening that attachment runs arbitrary code, matching this scenario exactly.
    • B. Link in Attachment is a credential-harvest hybrid where the attachment contains a link to a login page, not a hosted file that runs code on the device.
    • C. Malware Attachment delivers the malicious file directly as the email attachment, rather than as a link to a file hosted on an external sharing site.
    • D. Drive-by URL sends a link straight to a compromised or cloned website, not to a hosted file on a sharing site that runs code when opened.

    Subdomain 2.3: Secure Microsoft 365 workloads

    14.A tenant just turned on the Strict preset security policy for a subset of users for the first time. Which statements about the Strict preset security policy are accurate? (Select all that apply)(Select 3)

    1. A.The rules for the Strict preset security policy are created the first time the policy is turned on in the Defender portal.
    2. B.Admins can directly edit the individual anti-spam, anti-malware, and anti-phishing policies created for Strict using New- and Set- cmdlets.
    3. C.Strict preset security policy settings are evaluated before Standard preset security policy settings for any recipient included in both.
    4. D.Turning off the Strict preset security policy permanently deletes its underlying rules and threat policies.
    5. E.Recipients in the Strict preset security policy also automatically receive impersonation protection from mailbox intelligence.
    Show answer & explanation

    Correct answers: A, C, EThe rules for the Strict preset security policy are created the first time the policy is turned on in the Defender portal.; Strict preset security policy settings are evaluated before Standard preset security policy settings for any recipient included in both.; Recipients in the Strict preset security policy also automatically receive impersonation protection from mailbox intelligence.

    • A. The rules and underlying threat policies for Strict are created the first time an admin turns the policy on in the Microsoft Defender portal, not before.
    • B. Microsoft explicitly states admins should not attempt to create, modify, or remove the individual threat policies tied to preset security policies; the only supported path is turning the preset on in the portal.
    • C. The documented priority order places Strict ahead of Standard, so for any recipient covered by both, the Strict settings are the ones applied.
    • D. Turning off a preset security policy preserves its existing conditions, exceptions, and underlying rules; it does not delete them, so they remain available if the policy is turned back on.
    • E. All recipients in a preset security policy automatically receive impersonation protection from mailbox intelligence as part of the preset configuration.

    Subdomain 2.2: Implement and manage authentication and access in Microsoft Entra

    15.A financial services company must require step-up authentication only when a user is about to access an especially sensitive line-of-business app, while allowing normal sign-in everywhere else. Which Conditional Access concept fits?

    1. A.A policy scoped to that specific cloud app requiring a stronger authentication strength
    2. B.A tenant-wide security defaults baseline applied uniformly across every single application
    3. C.A per-user legacy MFA setting applied broadly to every user of that application
    4. D.A password expiration policy set to 30 days for accounts with access to that app
    Show answer & explanation

    Correct answer: AA policy scoped to that specific cloud app requiring a stronger authentication strength

    • A. Scoping a policy to the specific application and requiring a stronger grant control, such as a phishing-resistant authentication strength, adds the requirement only where it's needed.
    • B. Security defaults apply one uniform baseline across the whole tenant and cannot be scoped to a single sensitive application, so it misses the selective requirement.
    • C. Legacy per-user MFA challenges every sign-in for the user, not just sign-ins to the sensitive app, so it does not achieve app-specific step-up.
    • D. Password expiration changes how often a password must be changed and has no effect on which application triggers additional verification.

    Subdomain 2.2: Implement and manage authentication and access in Microsoft Entra

    16.A hybrid user can authenticate to cloud apps with a password but Windows Hello for Business and Seamless SSO both fail intermittently on their domain-joined device. Which area should the admin investigate first?

    1. A.Whether the device's Kerberos ticket issuance and time sync with the DC are healthy
    2. B.Whether the user's mailbox has already exceeded its currently configured storage quota
    3. C.Whether the tenant's custom banned password list was very recently updated
    4. D.Whether the user belongs to an unusually large number of security groups
    Show answer & explanation

    Correct answer: AWhether the device's Kerberos ticket issuance and time sync with the DC are healthy

    • A. Seamless SSO and Windows Hello for Business both depend on healthy Kerberos ticket issuance and accurate time sync with the domain controller, matching this pattern.
    • B. Mailbox storage quota affects Exchange Online mail flow, not the Kerberos-based mechanisms behind Seamless SSO or Windows Hello for Business.
    • C. A banned password list update affects new password choices, not the ongoing sign-in behavior of an already-set password with SSO mechanisms.
    • D. Group membership count can affect token size, but it does not produce the specific intermittent Kerberos-related SSO failure pattern described.

    Subdomain 2.2: Implement and manage authentication and access in Microsoft Entra

    17.Which of the following are true about the Microsoft Entra Password Protection global banned password list? (Choose 2)(Select 2)

    1. A.It is derived from Microsoft's analysis of real-world Entra security telemetry
    2. B.It is automatically applied to every tenant by default with no configuration required
    3. C.It is published publicly online in full so organizations can audit its exact contents
    4. D.It can be fully disabled per tenant by a Global Administrator role holder
    5. E.It is sourced primarily and exclusively from third-party breached compilations
    6. F.It only applies to accounts synchronized from on-premises Active Directory
    Show answer & explanation

    Correct answers: A, BIt is derived from Microsoft's analysis of real-world Entra security telemetry; It is automatically applied to every tenant by default with no configuration required

    • A. The list is built from Microsoft's own analysis of security telemetry across Entra sign-in and password-change activity, not external sources.
    • B. The global list is on by default for every tenant automatically, with no setting to enable it, and it applies universally to all users.
    • C. Microsoft deliberately does not publish the contents of the global list, since doing so would help attackers work around it.
    • D. The global banned password list cannot be turned off by a tenant admin; only the custom banned list is configurable at all.
    • E. The global list is explicitly not based on third-party breached-password compilations; it comes from Microsoft's own telemetry.
    • F. The global list applies to any user changing or resetting a password in Microsoft Entra ID, not only synchronized accounts.

    Subdomain 2.4: Protect data in Microsoft 365 by using Microsoft Purview

    18.Contoso uses internal project codenames that follow a consistent pattern, such as PRJ-####-XX, and none of the built-in sensitive information types detect them. The compliance team wants DLP policies to be able to match this pattern. What should they create first?

    1. A.A custom sensitive information type that defines the project codename pattern using a regular expression or keyword list.
    2. B.A new sensitivity label named Project Codenames with no protection settings configured.
    3. C.A retention label that automatically applies to any document containing the word project.
    4. D.A DLP policy template for financial data, since it is the closest predefined template available.
    Show answer & explanation

    Correct answer: AA custom sensitive information type that defines the project codename pattern using a regular expression or keyword list.

    • A. Custom sensitive information types let administrators define detection logic, such as a regular expression matching the codename pattern, so that DLP policies and other Purview tools can recognize content that predefined types don't cover.
    • B. A sensitivity label classifies and can protect content once it is applied, but it does not perform pattern-based content detection the way a sensitive information type does, and DLP conditions need a detectable data type.
    • C. A retention label controls retention and deletion behavior; it has no content-matching capability for a codename pattern and cannot be referenced as a DLP detection condition.
    • D. A financial data template is built around financial identifiers like credit card and bank account numbers; it does not detect the organization's custom codename pattern and would need significant unrelated rework.

    Subdomain 2.4: Protect data in Microsoft 365 by using Microsoft Purview

    19.A Microsoft Purview DLP policy rule matches when a user tries to share a sensitive item. Which of the following are protective actions the rule could be configured to take? Select all that apply.(Select 3)

    1. A.Show the user a policy tip and block the sharing action, optionally allowing an override with a documented justification.
    2. B.Move a sensitive item at rest to a secure quarantine location.
    3. C.Block sensitive information from being displayed in a Teams chat message.
    4. D.Permanently delete every mailbox belonging to the user who triggered the match.
    5. E.Automatically revoke all Microsoft 365 licenses assigned to the user.
    Show answer & explanation

    Correct answers: A, B, CShow the user a policy tip and block the sharing action, optionally allowing an override with a documented justification.; Move a sensitive item at rest to a secure quarantine location.; Block sensitive information from being displayed in a Teams chat message.

    • A. A policy tip with a block-and-override option is a standard DLP protective action that warns the user and can require a justification before letting them proceed.
    • B. For data at rest, DLP can lock a sensitive item and move it to a secure quarantine location as a protective action.
    • C. In Teams chat and channel messages, DLP can prevent sensitive information from being displayed to recipients when a rule match occurs.
    • D. Deleting a user's entire mailbox is a destructive administrative action far beyond the scope of DLP protective actions, which target the specific sensitive item or activity, not the whole mailbox.
    • E. Revoking all licenses is an identity and licensing administration task and is not one of the protective actions available within a DLP policy rule.

    Subdomain 2.4: Protect data in Microsoft 365 by using Microsoft Purview

    20.An administrator configures a sensitivity label with encryption enabled. Which of the following does this label configuration allow the administrator to control? Select all that apply.(Select 3)

    1. A.Which specific users or groups can open the content and what actions they're permitted to take.
    2. B.Content marking such as headers, footers, and watermarks displayed in supported Office apps.
    3. C.Whether the content requires the EXTRACT usage right before Copilot can return its content in a response.
    4. D.Automatic translation of the document into other languages when it is opened.
    5. E.Automatic compression of the file to reduce its storage size in OneDrive.
    Show answer & explanation

    Correct answers: A, B, CWhich specific users or groups can open the content and what actions they're permitted to take.; Content marking such as headers, footers, and watermarks displayed in supported Office apps.; Whether the content requires the EXTRACT usage right before Copilot can return its content in a response.

    • A. Encryption-based sensitivity labels let administrators define which users or groups can access the content and restrict actions such as copy, print, or forward.
    • B. A sensitivity label can also apply content marking, including headers, footers, and watermarks, alongside its encryption settings.
    • C. Because the label applies encryption, Copilot and agents check for the EXTRACT usage right before returning the content's data to a user, which is a direct consequence of enabling encryption on the label.
    • D. Sensitivity labels do not provide language translation; that capability is unrelated to classification or encryption settings configured on a label.
    • E. Sensitivity labels do not compress files or manage storage size; their purpose is classification and access protection, not storage optimization.

    Subdomain 2.4: Protect data in Microsoft 365 by using Microsoft Purview

    21.Which of the following are default one-click policies available from Microsoft Purview DSPM for AI to help protect sensitive data used in generative AI? Select all that apply.(Select 3)

    1. A.DSPM for AI - Protect sensitive data from Copilot processing.
    2. B.DSPM for AI - Block sensitive info from AI sites.
    3. C.DSPM for AI - Block elevated risk users from submitting prompts to AI apps in Microsoft Edge.
    4. D.DSPM for AI - Encrypt all Outlook mail sent to external recipients.
    5. E.DSPM for AI - Disable all third-party browser extensions tenant-wide.
    Show answer & explanation

    Correct answers: A, B, CDSPM for AI - Protect sensitive data from Copilot processing.; DSPM for AI - Block sensitive info from AI sites.; DSPM for AI - Block elevated risk users from submitting prompts to AI apps in Microsoft Edge.

    • A. This one-click DLP policy blocks Microsoft 365 Copilot and agents from processing items that carry the sensitivity labels selected in the policy.
    • B. This one-click DLP policy uses Adaptive Protection to give a block-with-override response to risky users pasting or uploading sensitive information to AI apps in the browser.
    • C. This one-click DLP policy uses Adaptive Protection to block elevated, moderate, and minor risk users from submitting prompts to AI apps while using Microsoft Edge.
    • D. Encrypting all external Outlook mail is a broad message encryption configuration unrelated to DSPM for AI's one-click policies, which focus specifically on AI app interactions.
    • E. Disabling browser extensions tenant-wide is a device management action and is not one of the documented DSPM for AI one-click policies.

    Domain 3: Manage and secure AI services in Microsoft 365

    Subdomain 3.1: Enable and manage Microsoft 365 Copilot

    22.A Microsoft 365 admin wants to get AI-assisted help directly while working inside an admin console, such as summarizing a service health incident, rather than opening a separate chat window. What capability provides this?

    1. A.Copilot in admin centers for console tasks
    2. B.Microsoft 365 Copilot Cowork for automation
    3. C.Copilot connectors for people data profiles
    4. D.Self-serve synced connectors for users
    Show answer & explanation

    Correct answer: ACopilot in admin centers for console tasks

    • A. Copilot in admin centers integrates Copilot assistance directly into Microsoft 365 admin consoles, letting admins get AI help with tasks like reviewing service health without leaving the console.
    • B. Copilot Cowork is a usage-based, task-automation experience for end users and does not describe Copilot assistance embedded inside admin center consoles.
    • C. Connectors for people data enrich individual profile information across Microsoft 365 apps; they are unrelated to getting AI help while performing admin console tasks.
    • D. Self-serve synced connectors let individual users index their own external content for search and Copilot; they do not provide in-console admin assistance.

    Subdomain 3.1: Enable and manage Microsoft 365 Copilot

    23.An admin needs to view the Microsoft 365 Copilot Search configuration in the admin center to set up finance-related bookmarks and acronyms, but a help desk technician on the team keeps getting an access denied error when trying to view that page. What is the most likely cause?

    1. A.The technician lacks the global admin, global reader, or AI admin role needed for Search settings
    2. B.Copilot Search settings can only ever be viewed by the tenant's Global Administrator account alone
    3. C.Bookmarks and acronyms require a separate Copilot Search license not yet assigned to the technician
    4. D.Copilot Search admin settings stay unavailable until the organization enables self-service purchases
    Show answer & explanation

    Correct answer: AThe technician lacks the global admin, global reader, or AI admin role needed for Search settings

    • A. Viewing the Copilot Search admin settings requires the global admin, global reader, or AI admin role, so a technician without one of those roles would correctly be denied access.
    • B. Access is not restricted to only the Global Administrator; global reader and AI admin roles can also view these settings, which are lower-privilege alternatives.
    • C. Bookmarks and acronyms configuration in Copilot Search does not require its own separate license; existing Microsoft Search configuration for bookmarks and acronyms already carries over.
    • D. Self-service purchases control whether users can buy Copilot licenses themselves and have no relationship to whether an admin can view Copilot Search configuration pages.

    Subdomain 3.1: Enable and manage Microsoft 365 Copilot

    24.A finance team using Copilot Cowork is unexpectedly close to its monthly cost cap. The admin reviews the Microsoft 365 admin center to understand what drove the consumption. Which of the following is most likely to have contributed to the usage-based charges?

    1. A.The team generated several images and ran automated browser tasks
    2. B.The team simply had more Copilot licenses assigned than the prior month
    3. C.The team enabled the AI disclaimer setting for Word and Excel documents
    4. D.The team increased the number of synced connectors indexed into Graph
    Show answer & explanation

    Correct answer: AThe team generated several images and ran automated browser tasks

    • A. Activities such as model responses, tool and skill calls, image generation, and browser tasks all count toward Cowork's usage-based consumption, so heavier use of those features plausibly drove the team toward its cost cap.
    • B. Having more Copilot licenses assigned does not by itself generate Cowork usage-based charges; charges come from actual consumption activities, not license counts.
    • C. The AI disclaimer is a display setting in supported apps and does not consume Cowork's usage-based billing; it has no cost impact.
    • D. Indexing additional synced connectors affects what content is searchable, but it is not one of the consumption activities that drives Cowork's usage-based billing.

    Subdomain 3.1: Enable and manage Microsoft 365 Copilot

    25.A company builds a Copilot Studio-based IT help desk agent. They want the agent to both answer questions from the internal knowledge base and take action to reset a user's password. Which two capabilities, used together, make this possible?

    1. A.A Copilot connector for domain knowledge, extended with a Power Platform connector or plugin for the action
    2. B.A synced tenant connector by itself, since connectors can both answer questions and reset passwords natively
    3. C.The AI disclaimer setting by itself, since it authorizes agents to perform account actions directly
    4. D.The web search setting by itself, since public search results can be used to reset a password
    Show answer & explanation

    Correct answer: AA Copilot connector for domain knowledge, extended with a Power Platform connector or plugin for the action

    • A. Connectors supply agents with domain-specific knowledge to answer questions, and extending the agent with a Power Platform connector or API plugin adds the action-taking capability needed to perform a task like resetting a password.
    • B. Connectors are read-only knowledge sources by default; they surface indexed content but cannot perform actions like resetting a password without an additional action-taking extension.
    • C. The AI disclaimer setting only controls a transparency message shown to users about AI-generated content; it does not grant or relate to any ability for an agent to perform account actions.
    • D. Public web search results are informational and are not a mechanism for performing a privileged action such as resetting a user's password.

    Subdomain 3.2: Implement and manage agents in Microsoft 365 and Agent 365

    26.The security team notices an agent identity making an unusually high number of sign-in attempts against unfamiliar resources overnight. Which Microsoft Entra capability is designed to automatically detect and respond to this kind of risky agent behavior?

    1. A.Microsoft Entra ID Protection for agents, which watches for anomalous sign-in and access patterns.
    2. B.Microsoft Purview Data Security Posture Management for AI, which watches oversharing across AI activity.
    3. C.The agent registry's Risks column, which aggregates findings that other platforms already detected.
    4. D.Agent management rules for ownerless agents, which close ownership gaps rather than score sign-in risk.
    Show answer & explanation

    Correct answer: AMicrosoft Entra ID Protection for agents, which watches for anomalous sign-in and access patterns.

    • A. Microsoft Entra ID Protection for agents automatically detects and responds to risky agent identity behavior, such as unfamiliar resource access or a spike in sign-in attempts.
    • B. DSPM for AI focuses on monitoring AI data activity and oversharing detection in Purview, not identity-level sign-in risk scoring for agents.
    • C. The Risks column surfaces already-detected high-severity findings from platforms like Entra, Defender, and Purview; it doesn't itself perform the behavioral detection.
    • D. Agent management rules for ownerless agents address governance gaps in ownership, not real-time detection of anomalous sign-in behavior.

    Subdomain 3.2: Implement and manage agents in Microsoft 365 and Agent 365

    27.An admin wants Microsoft's own first-party agents to be proactively available to every employee without manually installing each one individually. Which agent management rule accomplishes this in bulk?

    1. A.The Install Microsoft agents rule, which finds Microsoft-published agents and installs them for all users at once.
    2. B.The Reassign ownerless agents rule, which hands orphaned agents to the previous owner's manager instead.
    3. C.The Apply template rule, which pushes preset security policies onto agents that are already published.
    4. D.The Reject old publish requests rule, which clears out stale pending submissions instead of installing any agents at all.
    Show answer & explanation

    Correct answer: AThe Install Microsoft agents rule, which finds Microsoft-published agents and installs them for all users at once.

    • A. The Install Microsoft agents rule identifies Microsoft-published agents in the tenant and installs selected ones for all users through a single bulk action, addressing the proactive installation gap.
    • B. The reassignment rule transfers ownership of agents whose creators left the organization; it doesn't install agents for the broader user base.
    • C. Applying a template pushes security policies onto existing agent instances at scale, but it doesn't install any agent for users who don't already have it.
    • D. This rule clears out aging publish requests that haven't been acted on; it has no effect on which agents are installed for users.

    Subdomain 3.2: Implement and manage agents in Microsoft 365 and Agent 365

    28.The AI admin team is overwhelmed by a backlog of custom agent publish requests that have sat pending review for over 60 days with no action. Which agent management rule can clear this backlog in bulk instead of rejecting each request manually?

    1. A.Reject agent publish requests older than a specified number of days, clearing the stale backlog at once.
    2. B.Block ownerless agents without usage, which targets already-published agents rather than pending submissions.
    3. C.Reassign ownerless agents created with Agent Builder to a manager, which doesn't touch pending requests.
    4. D.Apply a template to agent instances matching defined criteria, which configures policy rather than requests.
    Show answer & explanation

    Correct answer: AReject agent publish requests older than a specified number of days, clearing the stale backlog at once.

    • A. This rule lets admins define an age threshold and reject every matching stale publish request in one bulk operation, directly addressing an aging backlog.
    • B. This rule targets agents that are already published but lack an owner and see no usage; it doesn't act on pending publish submissions.
    • C. This rule transfers ownership of ownerless Agent Builder agents to a manager and has no bearing on unreviewed publish requests.
    • D. Applying a template pushes security policy configuration onto existing agent instances and doesn't reject or otherwise act on pending submissions.

    Subdomain 3.3: Secure and govern agents by using Agent 365

    29.A Defender analyst wants to visualize how a compromised agent identity could be chained to reach a critical business asset, before an incident occurs. Which capability supports this analysis?

    1. A.Agent security posture management in Microsoft Defender, visualizing attack paths to critical assets.
    2. B.Insider Risk Management, which pseudonymizes usernames before analysts review any flagged agent activity.
    3. C.Data classification in Purview, tagging files with built-in or custom sensitive information types.
    4. D.The Agent 365 registry, listing the publisher categories for agents made available in the tenant.
    Show answer & explanation

    Correct answer: AAgent security posture management in Microsoft Defender, visualizing attack paths to critical assets.

    • A. Correct — agent security posture management in Defender is the capability built to visualize attack paths from an agent identity to critical assets before an incident happens.
    • B. Insider Risk Management focuses on detecting risky behavior with privacy protections, not visualizing attack paths to assets.
    • C. Data classification tags sensitive content types; it does not model or visualize identity-to-asset attack paths.
    • D. The agent registry tracks where an agent came from and how it was published, not potential attack paths to critical assets.

    Subdomain 3.3: Secure and govern agents by using Agent 365

    30.Which activities does the AI observability page highlight as top risky activities for agents? (Choose 3)(Select 3)

    1. A.Oversharing
    2. B.Exfiltration
    3. C.Unethical behavior
    4. D.Excessive licensing cost
    5. E.Slow response latency
    Show answer & explanation

    Correct answers: A, B, COversharing; Exfiltration; Unethical behavior

    • A. Correct — oversharing is one of the top risky activities the AI observability page analyzes for agents.
    • B. Correct — exfiltration is one of the top risky activities the AI observability page analyzes for agents.
    • C. Correct — unethical behavior is one of the top risky activities the AI observability page analyzes for agents.
    • D. Licensing cost is a financial metric, not one of the risky activity categories the page analyzes.
    • E. Response latency is a performance metric, not one of the risky activity categories the page analyzes.

    Subdomain 3.3: Secure and govern agents by using Agent 365

    31.Which statements about Compliance Manager assessments for Agent 365 are correct? (Choose 2)(Select 2)

    1. A.Every new agent instance is included automatically in the built-in AI regulation templates.
    2. B.Compliance Manager tracks a compliance score that reflects implemented controls over time.
    3. C.Administrators must manually add each agent instance to an assessment before it gets scored at all.
    4. D.Compliance Manager assessments apply only to agents that Microsoft itself builds and ships.
    5. E.Assessment templates only cover agents deployed inside Microsoft Copilot Studio.
    Show answer & explanation

    Correct answers: A, BEvery new agent instance is included automatically in the built-in AI regulation templates.; Compliance Manager tracks a compliance score that reflects implemented controls over time.

    • A. Correct — an agent instance is automatically included in the built-in AI regulation assessments as soon as it is created, with no manual step required.
    • B. Correct — Compliance Manager tracks a compliance score that moves as controls are implemented, giving a measurable view of progress.
    • C. No manual enrollment step is required; inclusion in the assessment happens automatically when the agent instance is created.
    • D. Assessment templates are not restricted to Microsoft-built agents; they apply broadly to agent instances regardless of who built them.
    • E. Assessment coverage is not limited to Copilot Studio; it applies to Agent 365 agent instances generally.

    Subdomain 3.4: Monitor AI services in Microsoft 365

    32.By default, usernames and display names are hidden in Copilot usage reports for privacy. An admin investigating a specific compliance concern needs to temporarily reveal that identifying detail for one review. What must the admin do?

    1. A.Enable the setting to show user, group, or site details in usage reports
    2. B.Request that the user's manager re-license Copilot with identity tracking enabled
    3. C.Switch the report timeframe to 180 days so identities become visible automatically
    4. D.Export the report to CSV, which always includes usernames regardless of settings
    Show answer & explanation

    Correct answer: AEnable the setting to show user, group, or site details in usage reports

    • A. Microsoft 365 admin center usage reports have a dedicated setting to show user, group, or site details, which is exactly what reveals hidden identifying information.
    • B. Copilot licensing has no separate identity-tracking configuration; user identity visibility in reports is controlled by the report privacy setting instead.
    • C. Changing the timeframe filter only changes the reporting window and has no effect on whether user identities are displayed.
    • D. CSV exports still respect the tenant's privacy setting, so identities remain hidden in the export unless the display setting is enabled first.

    Subdomain 3.4: Monitor AI services in Microsoft 365

    33.Which of the following metrics appear in the summary view of the Microsoft Copilot usage report's Usage tab? (Select all that apply.)(Select 3)

    1. A.Enabled Users
    2. B.Active Users
    3. C.Total prompts submitted
    4. D.Total licenses purchased tenant-wide
    5. E.Cost per Copilot seat
    6. F.Average revenue per active user
    Show answer & explanation

    Correct answers: A, B, CEnabled Users; Active Users; Total prompts submitted

    • A. Enabled Users is one of the headline summary numbers shown on the Usage tab, representing licensed users in the timeframe.
    • B. Active Users is a headline summary metric on the Usage tab, representing licensed users who took a qualifying Copilot action.
    • C. Total prompts submitted is shown as a summary figure representing prompt volume sent to Copilot Chat during the timeframe.
    • D. The report does not display a separate 'total licenses purchased' figure distinct from Enabled Users; this is not a report metric.
    • E. Cost per seat is not a metric the Copilot usage report tracks; it focuses on adoption and engagement, not per-seat pricing.
    • F. Average revenue per active user is a business metric unrelated to Copilot usage reporting and does not appear in this report.

    Subdomain 3.4: Monitor AI services in Microsoft 365

    34.Which columns can appear in the user-level activity table of the Microsoft Copilot usage report? (Select all that apply.)(Select 3)

    1. A.Prompts submitted (any app)
    2. B.Active Days
    3. C.Last activity date (UTC)
    4. D.Department cost center
    5. E.Manager approval status
    6. F.Azure subscription ID
    Show answer & explanation

    Correct answers: A, B, CPrompts submitted (any app); Active Days; Last activity date (UTC)

    • A. Prompts submitted (any app) is a documented column showing the total prompts a user submitted across all in-scope host applications.
    • B. Active Days is a documented column showing the number of days within the timeframe the user submitted at least one prompt.
    • C. Last activity date (UTC) is a documented column showing the most recent date the user sent a message to Copilot Chat.
    • D. Department cost center is not a column in the Copilot usage report's user-level activity table.
    • E. Manager approval status is not a column in the Copilot usage report's user-level activity table.
    • F. Azure subscription ID is not a column in the Copilot usage report's user-level activity table; this report is scoped to Microsoft 365, not Azure subscriptions.

    Subdomain 3.4: Monitor AI services in Microsoft 365

    35.Which of the following actions can an admin perform directly from the Microsoft Copilot usage report page? (Select all that apply.)(Select 3)

    1. A.Filter results by a 7, 28, 90, or 180-day timeframe
    2. B.Export the underlying report data to a .csv file
    3. C.Add or remove columns using Choose columns
    4. D.Approve or reject pending agent registry submissions
    5. E.Configure Conditional Access policies for agents
    6. F.Adjust Copilot license SKUs assigned to users
    Show answer & explanation

    Correct answers: A, B, CFilter results by a 7, 28, 90, or 180-day timeframe; Export the underlying report data to a .csv file; Add or remove columns using Choose columns

    • A. The report page offers a timeframe filter with 7, 28, 90, and 180-day options at the top of the view.
    • B. The report page includes an Export option that saves the underlying usage data as a .csv file for further analysis.
    • C. The user-level activity table includes a Choose columns control that lets the admin add or remove displayed columns.
    • D. Approving or rejecting agent registry submissions is done in the agent registry admin experience, not on the usage report page.
    • E. Conditional Access policy configuration is done in Microsoft Entra, not on the Copilot usage report page.
    • F. License SKU assignment is managed in the billing or user management areas of the admin center, not on the usage report page itself.

    Want the full experience?

    These are just samples. Practice the full Administering Microsoft 365 and AI Services (AB-650) question bank in quiz mode — free, no signup, with domain practice and exam simulation.