Examinotion
Study Guides

AB-900 Data Protection and Governance: Microsoft Purview, Copilot Oversharing and DSPM for AI Explained (2026)

Data protection and governance is the largest AB-900 domain at 35-40% of the exam, and the one Microsoft Learn covers least. This 2026 guide explains Microsoft Purview, how Copilot respects permissions, DSPM for AI and SharePoint oversharing remediation, sourced entirely from Microsoft documentation

ET

Examinotion Team

24 min read27 July 2026Updated: 27 July 2026
 Layered vault and shield structures representing AB-900 Copilot data protection and governance

AB-900 Data Protection and Governance: Microsoft Purview, Copilot Oversharing and DSPM for AI Explained (2026)

Last updated: July 2026. Written and fact-checked by the Examinotion editorial team against the official Microsoft Learn study guide for AB-900 (skills measured as of 22 July 2026) and Microsoft Purview product documentation.

TL;DR Data protection and governance is the largest domain on AB-900 at 35-40% of the exam. It covers Microsoft Purview capabilities, how Copilot respects existing permissions, DSPM for AI, and identifying oversharing in SharePoint. Only one of the six official Learn modules covers it, so most candidates under-prepare this domain.

Exam AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals has a weighting problem that catches candidates out. Its heaviest domain is not the Copilot administration content most people revise, it is data protection and governance, worth 35-40% of the scored questions [1]. That single domain is bigger than either of the other two, and it is the one where Microsoft's own free training gives you the least support.

This guide covers that domain end to end: what Microsoft Purview actually does, how Microsoft 365 Copilot decides what a user is allowed to see, why generative AI amplifies oversharing rather than merely exposing it, and how Data Security Posture Management (DSPM) for AI fits in. Every claim here is sourced from Microsoft Learn or Microsoft product documentation, with the source list at the end.

What the AB-900 data protection domain actually asks you to know

The official study guide for AB-900 lists three domains with these weightings [1]:

Domain Weighting
Identify the core features and objects of Microsoft 365 services 30-35%
Understand data protection and governance tasks for Microsoft 365 and Copilot 35-40%
Perform basic administrative tasks for Copilot and agents 25-30%

The middle domain breaks into four skill groups, and it is worth reading them as Microsoft phrases them rather than as a topic summary, because the exam questions track the verbs [1]:

  • Understand Microsoft Purview. Features and capabilities of Purview Information Protection, Data Loss Prevention (DLP), Insider Risk Management, Communication Compliance, Data Security Posture Management (DSPM) for AI, and Data Lifecycle Management. Plus use cases for sensitivity labels, data classification, and retention.
  • Understand data security implications of Copilot. How Copilot accesses data, how Microsoft Graph influences Copilot responses, how Copilot uses permissions and other controls across Microsoft 365, Purview and Defender, and responsible AI principles.
  • Identify data protection and governance risks. Using Compliance Manager, Data explorer, Insider Risk Management, DLP alerts, Communication Compliance policy violations, Activity explorer, DSPM for AI, and Content search in eDiscovery.
  • Identify and monitor oversharing in SharePoint. The tools for troubleshooting oversharing, running a data access governance report, and the features of SharePoint Advanced Management including restricted access control.

Notice the pattern. The first two groups are conceptual, "understand what this is". The second two are diagnostic, "given a symptom, name the tool". That distinction matters more than any single product fact, and we return to it at the end of this guide.

What the 22 July 2026 refresh changed

Microsoft refreshed the AB-900 skills outline on 22 July 2026 [1][2]. If you have been revising against an older printout, the good news is that almost nothing moved. The study guide's own change log marks the data protection and governance domain heading as No change, and the only sub-area inside it flagged as touched at all is "Identify and monitor oversharing in SharePoint in Microsoft 365", marked Minor [1].

Minor, in Microsoft's change-log vocabulary, means wording rather than substance. No weighting moved, and no new skill area was added to this domain. Treat any source telling you the July 2026 refresh added new content to AB-900 with scepticism, and check the change-log table on the study guide yourself.

How Microsoft 365 Copilot accesses data

This is the single most common anxiety question about Copilot, and the exam tests it directly through the bullet "Understand how Copilot accesses data".

Copilot cannot show a user content that user cannot already access. Microsoft's wording is unambiguous: AI apps that Microsoft Purview supports "use existing controls to ensure that data stored in your tenant is never returned to the user or used by a large language model (LLM) if the user doesn't have access to that data" [3].

The mechanism is the existing Microsoft 365 permission model, surfaced through Microsoft Graph. When a user prompts Copilot, the grounding layer retrieves organisational content the user already has permission to open, exactly as a manual search would, then passes that content to the model as context. Microsoft's current documentation names this grounding and personalisation layer Work IQ: "Microsoft 365 Copilot uses Work IQ to enhance responses to user prompts using data that the user already has permission to access. When your organization's data is well governed, current, and appropriately shared, Copilot can deliver accurate, relevant, and secure responses" [4].

That last sentence contains the exam's real point. Copilot does not break permissions. It faithfully executes permissions that were already wrong.

Sensitivity labels as a second gate

Permissions are the first gate. Encryption applied by a sensitivity label is the second. When a sensitivity label applies encryption, "users must have the EXTRACT usage right, as well as VIEW, for the AI apps to return the data" [3].

This is a favourite exam distinction, because VIEW alone is not enough. A user who can open a document in Word may still find that Copilot will not summarise it, because summarising requires extracting content, and the label's usage rights do not grant EXTRACT.

Two hard exclusions are worth memorising verbatim. Microsoft states that "S/MIME protected emails won't be returned by Copilot, and Copilot isn't available in Outlook when an S/MIME protected email is open", and that "password-protected documents can't be accessed by AI apps unless they're already opened by the user in the same app (data in use)" [3].

There is also a prerequisite that quietly breaks label enforcement if you skip it. Sensitivity labels must be enabled for SharePoint and OneDrive specifically. Microsoft warns that "when sensitivity labels aren't enabled for these services, the encrypted files that Copilot and agents can access are limited to data in use from Office apps on Windows" [3].

Microsoft Purview at a glance: the capabilities AB-900 names

Microsoft Purview is not one product. It is a family of data security, governance and compliance capabilities, and AB-900 names a specific subset. You do not need to configure any of them for a Fundamentals exam, but you do need to say what each one is for in a single sentence, and pick the right one from a scenario.

Capability What it does Typical AB-900 scenario
Sensitivity labels (Information Protection) Classifies and protects content with a persistent label that can apply encryption, content markings and access control, and that follows the item wherever it travels [5] Protecting a document so Copilot will not summarise it for users without EXTRACT rights
Data classification Identifies and tags sensitive data using built-in or custom sensitive information types and trainable classifiers [3] Finding where credit-card numbers live before a Copilot rollout
Data Loss Prevention (DLP) Detects sensitive items and enforces policies to prevent leakage, including a dedicated Microsoft 365 Copilot policy location that can stop Copilot processing content carrying particular labels [6] Blocking Copilot from using "Highly Confidential" files as grounding data
Data Lifecycle Management (retention) Retains or deletes content, including Copilot prompts and responses, to meet business, legal and regulatory requirements [7] Setting how long Copilot interactions are kept
Communication Compliance Detects regulatory and business-conduct violations across communication channels, explicitly including AI prompts and responses [8] Flagging a user who repeatedly prompts Copilot with harassing language
Insider Risk Management Uses machine-learning signals to detect and investigate internal risks such as IP theft and data leakage, with a "Risky AI usage" policy template [9] Detecting prompt-injection attempts by an employee
eDiscovery and Content search Identifies, holds and exports electronic content for legal cases, and can filter for "Copilot activity" as a content type [10] Producing a departing employee's Copilot interactions for a legal hold
Audit Logs Copilot and AI user interactions and admin activities, including which resources were accessed and whether they were labelled [11] Proving which files a Copilot answer drew on
Compliance Manager Assesses and manages compliance posture across a multicloud estate, with regulatory templates for generative AI [12] Measuring readiness against an AI regulation
Data explorer and Activity explorer Data explorer natively displays the content of items flagged by classification; Activity explorer shows activities such as label changes, downgrades and AI interactions [13] Confirming what a classifier actually matched, versus who did what
DSPM for AI Discovers and governs AI activity and the sensitive data exposed through it, across Copilot, agents and third-party AI apps [14] Reporting on sensitive data referenced in Copilot interactions

The Data explorer trap

The AB-900 outline says Data explorer, and that is a specific tool, not a generic phrase. Microsoft Purview has three explorers under Information Protection, and candidates routinely conflate them [13]:

  • Data explorer natively displays the actual content of items that classification has flagged. Access is deliberately restricted, requiring roles such as Compliance Administrator, Security Administrator, Compliance Data Administrator or Global Administrator, plus the separate Data Explorer List viewer and Data Explorer Content viewer Purview roles [13].
  • Content explorer shows the volume and type of sensitive data across locations, without showing you item content in the same way.
  • Activity explorer shows activities rather than content: label applications and downgrades, external sharing, and AI interactions.

If a question describes an admin who needs to see what a classifier matched inside a document, that is Data explorer. If it describes an admin who needs to see who downgraded a label last week, that is Activity explorer.

Sensitivity labels, classification and retention

Three of the domain's bullets sit together as the "how do we tag and keep things" cluster, and each has a Copilot-specific wrinkle.

Sensitivity labels classify and protect. The Copilot-specific behaviour candidates most often miss is inheritance. If you use Copilot in Word, PowerPoint or Outlook to create new content based on a labelled item, "the sensitivity label from the source file is automatically inherited, with the label's protection settings" [3]. Microsoft's own worked example: a user selects "Draft with Copilot" in Word and references a file labelled "Confidential\Anyone (unrestricted)" that carries a "Confidential" footer. The new Copilot-drafted content is labelled the same way and picks up the same footer. Where multiple source files are referenced, the highest-priority label wins, and a user can override an inherited label unless mandatory labelling is enforced [3].

Copilot Chat also surfaces labels in its answers. Microsoft 365 Copilot Chat "displays the sensitivity label for items listed in the response and citations", showing the highest-priority label from the data used in that chat [3].

Data classification is the discovery layer beneath labelling. It uses sensitive information types and trainable classifiers to work out what data you hold, which is what makes reporting on sensitive data in AI prompts and responses possible in the first place [3].

Retention is Data Lifecycle Management's job, and Copilot interactions are in scope. Prompts and responses can be retained or deleted through a dedicated retention location for Copilot experiences [7]. For the exam, the takeaway is simply that Copilot interactions are organisational records like any other, not ephemeral chat.

Oversharing: why generative AI amplifies it

Oversharing is the domain's fourth skill group and, in practice, the reason the whole domain exists. Most organisations have SharePoint sites shared far more widely than anyone intended: legacy "Everyone except external users" permissions, broken inheritance, anonymous sharing links, and sites whose owners left years ago.

Before Copilot, that content was technically accessible but practically invisible. Nobody was going to find the 2019 salary spreadsheet buried in a departed manager's site through SharePoint search. Copilot changes the economics of finding it.

Microsoft states the mechanism plainly: "Because of the power and speed AI can proactively surface content that might be obsolete, over-permissioned, or lack governance controls, generative AI amplifies the problem of oversharing data" [15].

Read that carefully, because the exam framing follows from it. Copilot does not create the oversharing. It removes the obscurity that was doing the security work.

The tools for troubleshooting oversharing

The outline asks you to "identify the tools to troubleshoot oversharing in an organization" and to "run a data access governance report in SharePoint". Both point at SharePoint Advanced Management (SAM), which bundles the oversharing toolkit [16]:

  • Data Access Governance (DAG) reports, including permission-state reports, per-user site-permission reports, a sensitivity-label snapshot report, sharing-links activity reports, and "Everyone except external users" (EEEU) insights. This is the report the exam bullet names directly.
  • Restricted Access Control (RAC), which restricts access to a SharePoint or OneDrive site to specific groups [17].
  • Restricted Content Discovery (RCD), which prevents high-risk sites and files from surfacing in Microsoft 365 Copilot and agentic experiences [18].
  • Site access reviews, which delegate the review of DAG report findings to the site owners of overshared sites [16].
  • Inactive site management and site ownership policies, which detect dormant sites and chase down ownership gaps [16].

Distinguish RAC from RCD, because the names are close and the functions are not. RAC controls who can access the site at all. RCD controls whether the site's content can surface in Copilot, leaving direct access untouched. RCD is the interim measure you apply while you fix permissions properly; RAC is part of the fix.

Remediating oversharing: the foundational deployment blueprint

Microsoft publishes a named, three-step remediation path called the Foundational deployment blueprint [4]. Knowing its shape is useful for scenario questions that ask what to do first.

Step 1: Remediate oversharing. Identify and prioritise high-risk sites and content, apply interim protections (Restricted Content Discovery, and Purview DLP policies for Copilot), then fix the underlying access: apply site sensitivity labels, remove excessive and anonymous access, initiate site access reviews, correct broken permission inheritance, and confirm site ownership [4].

Step 2: Set up guardrails. Establish secure defaults so the problem does not return: enforce Restricted Access Control by default at site provisioning, disable or restrict company-wide sharing and "Anyone" links, and require sensitivity labels at provisioning. Then add secure guardrails: auto-labelling, DLP for Copilot policies that restrict processing of labelled or sensitive content, and Insider Risk Management policies for risky Copilot usage with Adaptive Protection [4].

Step 3: Meet regulations. Assess regulatory gaps in Compliance Manager, define audit-log and Copilot-interaction retention policy, use eDiscovery for Copilot content, and improve ongoing data hygiene through inactive-site and inactive-file cleanup, Microsoft 365 Archive, and retention policies [4].

The sequencing is the exam-relevant part. Remediate first, then prevent recurrence, then prove compliance. A question that offers "roll out Copilot to a pilot group and monitor" as an alternative to remediating known oversharing is testing whether you understand that order.

DSPM for AI: the terminology trap

Data Security Posture Management (DSPM) for AI is where the AB-900 outline and the live Microsoft Purview portal have drifted apart, and it is the single most likely place for a well-prepared candidate to second-guess a correct answer.

The capability has carried three names:

  1. Microsoft Purview AI Hub, the original preview name. It survives today only as a policy-name prefix, Microsoft AI Hub -, on policies created during the preview [19].
  2. DSPM for AI, the general-availability name, and the exact term the AB-900 skills outline uses [1]. Microsoft's documentation now labels this version "DSPM for AI (classic)".
  3. Data Security Posture Management (DSPM), the current unified experience, which supersedes both DSPM for AI (classic) and DSPM (classic) and extends coverage beyond AI apps to Microsoft 365, Azure, Fabric and integrated third-party platforms [14].

Microsoft's own banner on the current documentation says most new features "will be added to this version only", while the previous versions and their documentation remain accessible [14].

For the exam, answer to the outline. AB-900 as of 22 July 2026 names "Microsoft Purview Data Security Posture Management (DSPM) for AI", so that is the term the questions use. In a live tenant you will see the newer, broader DSPM. Learn the concept under both names and you cannot be caught either way.

What DSPM actually does

The current DSPM organises itself around four questions, quoted directly: "What data do we have? Where is it stored? Who can access it? How is it protected?" [14]. Admins select data security objectives such as "Prevent data exposure in Microsoft 365 Copilot and Microsoft Copilot interactions", "Prevent oversharing of sensitive data", "Prevent exfiltration to risky locations", and "Discover sensitive data in your organization" [14].

Two concrete mechanics are worth carrying into the exam. First, coverage: the AI activities view spans Microsoft 365 Copilot, Microsoft 365 Copilot Chat, Copilot Studio agents, Security Copilot, Copilot in Fabric, and, with the right integrations, third-party generative AI sites accessed through the browser [14]. Second, the default assessment cadence: "A default data risk assessment automatically runs weekly for the top 100 SharePoint sites based on usage in your organization" [15].

Prerequisites for monitoring Copilot and agents through DSPM for AI are modest but specific: Purview auditing enabled (it is on by default), and a Microsoft 365 Copilot licence assigned to the users being monitored [19]. Broader coverage costs more. Copilot in Fabric and Security Copilot need the enterprise version of Purview data governance; monitoring third-party AI sites needs devices onboarded to Purview plus the Purview browser extension; and AI apps other than Microsoft 365 Copilot and Microsoft Facilitator require pay-as-you-go billing [19].

Identifying risk: matching the symptom to the tool

The domain's third skill group is a decision table in disguise. Every bullet pairs a diagnostic need with exactly one Purview tool. Learn it as a table and the scenario questions become mechanical.

The scenario says The answer is
Assess compliance posture against a regulation, get improvement actions Compliance Manager [12]
See the actual sensitive content inside items that classification flagged Data explorer [13]
Detect an employee exfiltrating IP, or making risky AI use Insider Risk Management [9]
An alert fired because sensitive data was about to leave, review and respond Data Loss Prevention alerts [6]
A message breached a business-conduct or regulatory policy Communication Compliance [8]
See what users did: label changes, downgrades, external sharing, AI interactions Activity explorer [13]
Discover which AI apps are in use and what sensitive data they touch DSPM for AI [14]
Find specific files and emails for a legal matter Content search in eDiscovery [10]

The trap in this group is over-thinking. Several tools can technically surface overlapping information, and candidates talk themselves out of the obvious answer. The exam is testing the tool's stated primary purpose, not the cleverest possible route to the data.

Licensing: foundational versus optimized

AB-900 does not ask you to price a deployment, but licensing tiers shape which controls exist, and the Copilot Control System documentation gives you a clean two-tier model to memorise [20]:

Foundational: controls for security and governance in the Microsoft 365 admin center, SharePoint Advanced Management, and Microsoft Purview with an A3/E3/G3 license. Optimized: controls in Microsoft Purview and Microsoft Defender for Cloud Apps with an A5/E5/G5 license.

Tier Representative controls
Foundational (A3/E3/G3) DAG reports, Restricted Access Control, Restricted Content Discovery, manual sensitivity labelling prompts, DLP oversharing notifications, label-based encryption, DSPM for AI reports only, eDiscovery search and export of Copilot prompts and responses, label inheritance for Copilot-created content, audit access, retention policies for Copilot interactions [20]
Optimized (A5/E5/G5) DSPM for AI targeted data-risk assessments and one-click policy remediation, automatic sensitivity labelling, Insider Risk Management with Adaptive Protection, DLP that blocks Copilot from processing specific labelled content, Communication Compliance alerts for AI violations, Compliance Manager regulatory tracking [20]

Two further points sit slightly apart from that table and are easy to state imprecisely. SharePoint Advanced Management is "included with Copilot licenses", so SAM access rides on the Microsoft 365 Copilot add-on rather than on the base plan [4]. And the Copilot add-on itself is exactly that, an add-on: it requires a qualifying base plan such as Microsoft 365 E3 or E5, Office 365 E3 or E5, or one of the Business and Frontline plans, rather than being sold standalone [21].

How this domain is examined, and how to prepare for it

AB-900 is a 45-minute Fundamentals exam with a pass mark of 700 out of 1,000 [2]. Two format facts matter for this domain in particular.

You cannot use Microsoft Learn during AB-900. Microsoft's exam-experience policy is explicit: "You can access Microsoft Learn as you complete your associate or expert exam. NOTE that access to Learn is NOT available on Fundamentals exams or GitHub exams... This resource is only available on role-based exams, not fundamentals or Microsoft Office Specialist (MOS) exams" [22]. AB-900 is a Fundamentals certification, so plan to recall the Purview capability list from memory. This is the opposite of the advice that circulates about associate-level exams such as AI-103, and applying that advice here will cost you.

The free training under-serves this domain. Course AB-900T00-A maps to two learning paths totalling six modules [23]. Exactly one of them, "Protect and govern Microsoft 365 data", covers the data protection and governance domain [24]. One module out of six, for 35-40% of the exam. That imbalance is the honest reason candidates find this domain hard: it is not conceptually difficult, it is simply under-resourced in the official free curriculum, so you have to supplement it with the product documentation.

A workable revision approach for this domain specifically:

  1. Read the outline as your checklist, not a textbook chapter. Every bullet is a question topic.
  2. Build the capability table. Ten Purview capabilities, one sentence each. If you can write the table from memory you have covered the "Understand Microsoft Purview" group.
  3. Learn the symptom-to-tool mapping in the section above. It converts the largest sub-group into recall.
  4. Memorise the three-step blueprint order: remediate, guardrail, meet regulations.
  5. Nail three distinctions: RAC versus RCD, Data explorer versus Activity explorer, and foundational versus optimized licensing.
  6. Practise under time pressure. 45 minutes is not generous, and this domain rewards fast recognition over deliberation.

Is this domain hard? It is not conceptually difficult, but it is broad, and it is the part of AB-900 where candidates most often run out of preparation time. Underestimating it is the common failure mode, not the material itself.

If you want structured practice on this domain alongside the rest of the syllabus, our AB-900 exam preparation course covers all three domains with worked explanations, and the AB-900 study guide maps each skills-outline bullet to its content. For the wider picture on why AB-900 is tougher than its Fundamentals label suggests, see our AB-900 exam guide and how to pass the AB-900 exam.

Frequently Asked Questions

Can Microsoft 365 Copilot show me files I do not have permission to access?

No. Microsoft's documentation states that AI apps Purview supports use existing controls to ensure tenant data is never returned to a user, or used by a large language model, if that user does not have access to it. Copilot enforces your existing Microsoft 365 permissions exactly as they apply to search [3].

What is DSPM for AI, and is it the same as DSPM?

DSPM for AI is Microsoft Purview's capability for discovering and governing AI usage, including Copilot and agents. It launched in preview as Microsoft Purview AI Hub, reached general availability as DSPM for AI, and is now labelled "(classic)" because a broader unified Data Security Posture Management has superseded it. AB-900 still says DSPM for AI [1][14].

Is Microsoft Learn available during the AB-900 exam?

No. Microsoft's official exam-experience policy states that Learn access is not available on Fundamentals exams, and that the resource is only offered on role-based exams. AB-900 is a Fundamentals certification, so you cannot consult Microsoft Learn during your 45-minute exam [22].

Do sensitivity labels carry over into content Copilot generates?

Yes, in Copilot for Word, PowerPoint and Outlook. When new content is drafted from a labelled source file, the source's sensitivity label and its protection settings are inherited automatically. If several source files are referenced, the highest-priority label applies. Users can override an inherited label unless mandatory labelling is enforced [3].

What is the difference between Restricted Access Control and Restricted Content Discovery?

Restricted Access Control limits who can access a SharePoint or OneDrive site at all, by scoping it to specific groups. Restricted Content Discovery leaves direct access alone but prevents a high-risk site's content from surfacing in Microsoft 365 Copilot and agentic experiences. RCD is typically an interim protection while permissions are fixed [17][18].

Why does generative AI make oversharing worse rather than just revealing it?

Microsoft's explanation is that the power and speed of AI proactively surfaces content that may be obsolete, over-permissioned or lacking governance controls, which amplifies the oversharing problem. Files that were technically accessible but practically undiscoverable can now appear instantly inside a natural-language answer [15].

What licence do I need for SharePoint Advanced Management?

SharePoint Advanced Management is included with Microsoft 365 Copilot licences, layered on a qualifying Microsoft 365 or Office 365 base plan. Depth of automation still varies by tier: DAG reports and Restricted Access Control are foundational A3/E3/G3 controls, while DSPM for AI's targeted assessments and policy remediation are optimized A5/E5/G5 capabilities [4][20].

How much of AB-900 is data protection and governance?

Between 35% and 40% of the scored content, making it the largest of the exam's three domains. The other two are core Microsoft 365 features and objects at 30-35%, and basic administrative tasks for Copilot and agents at 25-30%. Those weightings were unchanged by the 22 July 2026 skills-outline refresh [1].

Conclusion

The data protection and governance domain is where AB-900 stops being a product tour and starts testing whether you understand the security model underneath Microsoft 365 Copilot. The concepts are not hard, but the domain is wide, the official free training covers only a fraction of it, and the terminology is actively drifting as Microsoft restructures DSPM.

Anchor your revision on three things and the domain becomes manageable: the Purview capability list, the symptom-to-tool mapping, and the remediate-guardrail-regulate order of the oversharing blueprint. Then verify your recall under time pressure, because 45 minutes leaves no room to reason your way from first principles.

Ready to test yourself on this domain? Start practising for AB-900 with Examinotion's AB-900 practice tests, or browse all Microsoft AI exam preparation courses to plan your wider certification path. If you are weighing AB-900 against the business-focused route, our AB-730 preparation and Microsoft Copilot agents business guide are useful next reads.

Sources

  1. Study guide for Exam AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals - Microsoft Learn, skills measured as of 22 July 2026, accessed 2026-07-27
  2. Microsoft 365 Certified: Copilot and Agent Administration Fundamentals - Microsoft Learn, last updated 22 July 2026, accessed 2026-07-27
  3. Use Microsoft Purview to manage data security and compliance for Microsoft 365 Copilot - Microsoft Learn, updated 25 June 2026, accessed 2026-07-27
  4. Configure a secure and governed foundation for Microsoft 365 Copilot - Microsoft Learn, updated 6 May 2026, accessed 2026-07-27
  5. Learn about sensitivity labels - Microsoft Learn, updated 25 June 2026, accessed 2026-07-27
  6. Learn about data loss prevention and DLP for Microsoft 365 Copilot - Microsoft Learn, accessed 2026-07-27
  7. Microsoft Purview Data Lifecycle Management and retention policies for Copilot - Microsoft Learn, accessed 2026-07-27
  8. Learn about communication compliance - Microsoft Learn, accessed 2026-07-27
  9. Learn about insider risk management - Microsoft Learn, accessed 2026-07-27
  10. Microsoft Purview eDiscovery solutions - Microsoft Learn, accessed 2026-07-27
  11. Audit logs for Copilot and AI applications - Microsoft Learn, updated 17 July 2026, accessed 2026-07-27
  12. Microsoft Purview Compliance Manager - Microsoft Learn, accessed 2026-07-27
  13. Get started with data explorer - Microsoft Learn, updated 15 June 2026, accessed 2026-07-27
  14. Learn about Microsoft Purview Data Security Posture Management - Microsoft Learn, updated 25 June 2026, accessed 2026-07-27
  15. Prevent oversharing with data risk assessments from Microsoft Purview DSPM - Microsoft Learn, updated 25 June 2026, accessed 2026-07-27
  16. SharePoint Advanced Management overview - Microsoft Learn, updated 1 July 2026, accessed 2026-07-27
  17. Restricted access control for SharePoint sites - Microsoft Learn, accessed 2026-07-27
  18. Restricted content discovery - Microsoft Learn, accessed 2026-07-27
  19. Considerations for deploying Microsoft Purview DSPM for AI - Microsoft Learn, updated 25 June 2026, accessed 2026-07-27
  20. Copilot Control System: security and governance - Microsoft Learn, updated 15 July 2026, accessed 2026-07-27
  21. License options for Microsoft 365 Copilot - Microsoft Learn, updated 18 June 2026, accessed 2026-07-27
  22. Exam duration and exam experience - Microsoft Learn, updated 4 June 2026, accessed 2026-07-27
  23. Course AB-900T00-A: Introduction to Microsoft 365 and AI administration - Microsoft Learn, accessed 2026-07-27
  24. Protect and govern Microsoft 365 data - Microsoft Learn training module, accessed 2026-07-27

Preparing for a Microsoft AI Certification?

Try 5 free practice questions with detailed explanations, no credit card required.

Lifetime access280+ questions per exam7-day money-back guarantee
Start Practising Today

Ready to Pass Your Exam?

Don't leave your certification to chance. Prepare with realistic practice questions, case studies, and detailed explanations for every answer.

No credit card required • Instant access

Can we do better?