Microsoft Certification Study Guide
AB-650 Microsoft 365 and AI Services Administrator Associate certification badge

AB-650 Study Guide

Microsoft 365 and AI Services Administrator Associate

Free study notes for every skill Microsoft measures on the AB-650 beta exam, plus the resources I recommend.

The AB-650 Study Guide helps you prepare for Administering Microsoft 365 and AI Services, the exam behind the new Microsoft 365 and AI Services Administrator Associate certification. It is written for administrators who configure, secure and govern Microsoft 365 tenants, workloads and AI services like Microsoft 365 Copilot and agents. AB-650 is in beta right now, and Microsoft expects it to reach general availability around October 2026, so treat the skills measured as provisional until then.

Everything here lines up with the skills Microsoft measures: free Microsoft Learn paths and my own study notes for self-study, plus the practice test I recommend when you want more. No exam dumps, ever.

Because the exam is new and still in beta, there is no dedicated book, video course or instructor-led course yet. I will add those here as soon as good ones exist.

Exam length
100 min
Passing score
700 / 1000
Skills measured
3 domains, 58 skills
Guide reviewed
September 2026

Resources by the way you like to study

3 hand-picked, free and paid

Practice Tests

1 resource

These are practice exams, not dumps. Dumps ruin the value of a certification for everyone. Practice tests are a great way to check you are ready once you have studied everything in this guide.

Udemy

AB-650: Administering Microsoft 365 and AI Services

Five full-length practice exams with detailed answer explanations, aligned to the AB-650 skills measured. A solid way to check your readiness once you have worked through this guide, and to find weak spots while the exam is still in beta.

Take the practice test (opens in a new tab)

Microsoft Learn Modules

1 resource

Microsoft Learn is a great free way to learn the AB-650 content. It is mostly text-based articles, with small quizzes at the end of every module.

The course syllabus below is Microsoft's own list of the learning paths and modules that cover the exam. When you want one topic rather than the whole curriculum, every skill in my study notes links the exact Microsoft Learn page for it.

Microsoft

Course AB-650T00-A: Administer Microsoft 365 and AI services

Free

Microsoft's official AB-650 course page. The syllabus lists every Microsoft Learn path and module the course teaches, and all of them are free to work through at your own pace.

Start on Microsoft Learn (opens in a new tab)

Live Training

1 resource

This is the Microsoft Official Course, which you can schedule at a Microsoft learning partner. The classes are presented by Microsoft Certified Trainers. It is the best way to learn any topic, since you can ask a live instructor questions, and also the most expensive one.

Microsoft

Course AB-650T00-A: Administer Microsoft 365 and AI services

Instructor-led

The official Microsoft instructor-led course for AB-650, delivered by a Microsoft Certified Trainer at a learning partner. It works through the tenant, workload and AI service administration the exam measures, with an instructor to ask.

Find a class (opens in a new tab)

Some links on this page are affiliate links. If you use them, I may earn a commission at no extra cost to you.

Skills measured and study notes

58 skills, free to study here
0 of 58 studied

Before you start, one important note: AB-650 is a beta exam. Microsoft has released it in beta and expects it to reach general availability around October 2026. While the exam is in beta, the skills measured can still shift, so Microsoft may change the domains, the weightings, or the individual tasks before it goes GA. I wrote these notes to the skills measured Microsoft published for the AB-650 beta and last checked them on September 22, 2026 (the Microsoft study guide page was last updated July 27, 2026, and shows a single version with no change log). I will update them once the exam is finalized, so treat everything below as current for the beta and worth a quick recheck against the official skills measured before you book.

These notes are organized exactly the way Microsoft groups the AB-650 skills measured: three domains, each broken into skill groups, with every single skill explained below along with the key facts the exam can ask and a Microsoft Learn link. After years of helping IT pros prepare for Microsoft exams, I can tell you the most reliable way to study is to walk the skills measured one at a time, which is how these notes are laid out. Here is how the three domains break down by weight:

Tip: The two heaviest domains are governance and security at 40-45% and AI services at 35-40%. If your study time is limited, make identity, Defender for Office 365, Purview, and the Copilot and agent administration sections your priority, because together they are most of the exam.

Domain 1 Configure and Manage Microsoft 365 Tenants and Workloads 20-25% of the exam 0 / 13 studied

This domain covers the day-to-day administration of a Microsoft 365 tenant and its core workloads. Expect questions on tenant-wide settings, licensing (including the AI licenses), Microsoft 365 Backup, service monitoring, and the management of Exchange, Teams, and SharePoint, with an eye on how each workload is prepared for Copilot.

Configure and manage a Microsoft 365 tenant

01

Configure branding in a Microsoft 365 tenant, including logo, company URL, themes, and backgrounds

Organizational branding lets you replace the default Microsoft look with your own logo, colors, and sign-in background so users can trust that they are signing in to the right place. In Microsoft 365 the theme is set in the admin center, while the sign-in page branding lives in Microsoft Entra.

What you need to know

  • The Microsoft 365 theme is configured in the Microsoft 365 admin center under Settings, then Org settings, then Organization profile, then Custom themes
  • Company branding for the sign-in experience (background image, banner logo, sign-in text) is set in the Microsoft Entra admin center under Company branding
  • You can set a default brand plus language-specific variations, and Entra ID P1 or P2 is required for custom sign-in branding
  • Theme elements include the logo, the navigation bar color, the accent color, and whether the user's photo or a custom image appears

Microsoft Learn resource: Customize the Microsoft 365 theme for your organization (opens in a new tab)

02

Implement and manage domains

A custom domain (for example, contoso.com) replaces the default onmicrosoft.com address on email and sign-in names. Adding one means proving you own it and pointing the right DNS records at Microsoft 365.

What you need to know

  • You add and verify a domain in the Microsoft 365 admin center under Settings, then Domains, by publishing a TXT (or MX) record at your DNS host
  • After verification you add the service records: MX for mail, CNAME records for Autodiscover and Teams, and TXT records for SPF
  • Every tenant keeps its original onmicrosoft.com domain, which cannot be removed
  • You can set a default domain for new users, and you must move users and groups off a domain before you can remove it

Microsoft Learn resource: Add a domain to Microsoft 365 (opens in a new tab)

Exam tip: You cannot delete a custom domain while any user, group, or mailbox still uses it as an address, so reassign those first.

03

Configure and manage organizational settings, including security and privacy settings and the organization profile

Org settings are the tenant-wide switches that control how services, security, and privacy behave for everyone. They live in one place so you can turn features on or off across the organization.

What you need to know

  • Org settings live in the Microsoft 365 admin center under Settings, then Org settings, split into Services, Security & privacy, and Organization profile tabs
  • Security & privacy covers items such as self-service password reset, sharing, and privacy profile settings
  • The Organization profile holds the organization name, address, technical contact, and release preferences
  • Many settings here are tenant-wide defaults that individual workload admin centers can then refine

Microsoft Learn resource: Overview of the Microsoft 365 admin center (opens in a new tab)

04

Manage and monitor Microsoft 365 licenses, including group-based licensing and pay-as-you-go

Licenses control which services a user can use, and at scale you want to assign them by group rather than one user at a time. Some newer services bill by consumption instead of per-user seats.

What you need to know

  • Licenses can be assigned directly to a user or, at scale, through group-based licensing in Microsoft Entra, where every member of a group inherits the assigned licenses
  • Group-based licensing requires Microsoft Entra ID P1 for the users being licensed, and it automatically assigns and removes licenses as membership changes
  • Pay-as-you-go services (such as Microsoft 365 Backup and Microsoft 365 Archive) bill against a linked Azure subscription based on what you consume, with no seat to assign
  • You monitor assignment and usage from the admin center under Billing, then Licenses, and from the Reports area

Microsoft Learn resource: Assign licenses to users by using group-based licensing (opens in a new tab)

05

Manage and monitor licenses for AI services, including Microsoft 365 Copilot, Microsoft Agent 365, and Microsoft Copilot Studio

The AI services carry their own licensing, and the exam expects you to know how each one is licensed and where you assign or monitor it.

What you need to know

  • Microsoft 365 Copilot is a per-user add-on that requires an eligible base Microsoft 365 license, and it is assigned like any other license in the admin center
  • Microsoft Agent 365 is included with Microsoft 365 E7 and is available as an add-on to Microsoft 365 E5, A5, or Business Premium (or the Defender and Purview suites)
  • Copilot Studio can be licensed per-user or consumed with pay-as-you-go metered billing (message packs or a linked Azure subscription)
  • You track AI license assignment and demand from the Copilot page in the admin center, including the self-service purchase and usage signals

Microsoft Learn resource: Understand licensing for Microsoft 365 Copilot (opens in a new tab)

06

Configure and use Microsoft 365 Backup, including setup, restore, and monitor

Microsoft 365 Backup protects SharePoint sites, OneDrive accounts, and Exchange mailboxes inside the Microsoft trust boundary, with fast restore for scenarios like ransomware recovery. It is a pay-as-you-go service, not a per-user license.

What you need to know

  • Microsoft 365 Backup is set up in the Microsoft 365 admin center and requires a SharePoint Administrator or Global Administrator, plus a linked Azure subscription for pay-as-you-go billing
  • It protects three workloads independently: SharePoint, OneDrive, and Exchange, and you scope protection with backup policies
  • Billing is consumption-based on the volume of protected content (list price around 0.15 US dollars per GB per month), charged through Azure with no extra Azure storage fees
  • Restores are fast because data stays in the Microsoft 365 substrate; express restore points let you recover a site or mailbox to a point in time

Microsoft Learn resource: Overview of Microsoft 365 Backup (opens in a new tab)

Exam tip: Microsoft 365 Backup is pay-as-you-go and needs an Azure subscription, so there is no seat to assign; contrast that with a per-user add-on like Copilot.

07

Configure and review network connectivity insights

Network connectivity insights measure how well each office location reaches Microsoft 365 and flag problems like backhauling traffic through a distant proxy. Good connectivity matters a lot for real-time workloads such as Teams.

What you need to know

  • Network connectivity is found in the Microsoft 365 admin center under Health, then Network connectivity
  • It gives each location a network connectivity score and compares your egress against Microsoft's connectivity principles (for example, egress traffic locally, avoid unnecessary proxying)
  • You can add locations and run assessments, and the onboarding tool collects measurements from a user's location
  • Insights call out issues like high latency, distant Microsoft 365 service front doors, and traffic that is not broken out locally

Microsoft Learn resource: Microsoft 365 network connectivity overview (opens in a new tab)

08

Monitor the health of Microsoft 365 services by using Service health, including notification configuration

Service health tells you whether a problem is Microsoft's or yours, and it is the first place to look when users report an outage. You can also have it notify you when incidents are posted.

What you need to know

  • Service health lives in the Microsoft 365 admin center under Health, then Service health, and shows current incidents and advisories per service
  • Each issue has a status, an impact description, and a history of updates, plus a linked message in the message center where relevant
  • You configure email notifications for service health so admins are alerted when new incidents or advisories are posted for chosen services
  • Viewing service health requires a role such as Global Reader, Service Support Administrator, or an admin role that includes it

Microsoft Learn resource: How to check Microsoft 365 service health (opens in a new tab)

Manage Microsoft 365 workloads

09

Create and manage mailboxes, including shared mailboxes

Exchange Online mailboxes come in several types, and knowing which type needs a license and which does not is a classic exam point. Shared mailboxes let a team work from a common address like info@contoso.com.

What you need to know

Exchange Online recipient types differ mainly in whether they need a license and who signs in:

Mailbox type Who uses it License needed
User mailbox One person's email, calendar, contacts Yes
Shared mailbox A team, from a common address No, unless over 50 GB or needing archive/hold
Resource mailbox A room or piece of equipment for booking No
  • Shared mailboxes are managed in the Microsoft 365 admin center or the Exchange admin center, and members are granted Full Access and Send As permissions
  • A shared mailbox has a disabled sign-in account, so users open it through their own credentials rather than signing in directly
  • You can convert a user mailbox to a shared mailbox to preserve its contents without keeping a paid license

Microsoft Learn resource: Create and manage shared mailboxes (opens in a new tab)

Exam tip: A shared mailbox under 50 GB needs no license, but it does need a license once you apply an archive or a litigation hold, or if it exceeds 50 GB.

10

Create and manage teams in Microsoft Teams, including channels, owners, and members

A team in Microsoft Teams is backed by a Microsoft 365 Group, and creating one provisions a SharePoint site, a group mailbox, and channels. Owners manage the team, while members use it.

What you need to know

  • Teams are created and managed from the Teams admin center (Teams, then Manage teams) or by users in the Teams client, subject to your policies
  • Every team has at least one owner; owners add and remove members, manage channels, and control settings, and Microsoft recommends at least two owners per team
  • Standard channels are open to all members and share the team's SharePoint site, while private and shared channels each get their own SharePoint site and membership
  • You govern team creation, naming, and expiration through Microsoft 365 Groups settings, naming policies, and group expiration policies

Microsoft Learn resource: Manage teams in the Microsoft Teams admin center (opens in a new tab)

11

Configure settings for Copilot in Teams meetings, including transcription

Copilot in Teams meetings can summarize discussions and answer questions about what was said, but it depends on the meeting being transcribed or recorded. Admins control that behavior with meeting policies.

What you need to know

  • Copilot in meetings is governed by a Teams meeting policy setting that can be set to run only with transcription on, or to work during the meeting without saving the transcript
  • Transcription and recording are themselves controlled by meeting policies in the Teams admin center under Meetings, then Meeting policies
  • If transcription is turned off and the Copilot setting requires it, users cannot use Copilot in that meeting
  • Meeting Copilot requires an eligible Microsoft 365 Copilot license for the user invoking it

Microsoft Learn resource: Manage Copilot in Microsoft Teams meetings and events (opens in a new tab)

12

Create and manage SharePoint sites, including permissions

SharePoint sites store the files behind Teams, OneDrive, and much of Microsoft 365, so managing sites and their permissions is central to keeping content secure and Copilot-ready.

What you need to know

  • Sites are created and managed in the SharePoint admin center under Sites, then Active sites, where you can create, delete, and change site settings and ownership
  • Communication sites have no Microsoft 365 Group, while team sites are group-connected and inherit the group's owners and members
  • Site permissions flow through SharePoint groups (Owners, Members, Visitors) mapped to Full Control, Edit, and Read; avoid breaking inheritance except where you must
  • Sharing settings at the organization and site level control whether content can be shared with guests or anonymously

Microsoft Learn resource: Manage sites in the SharePoint admin center (opens in a new tab)

13

Configure SharePoint and OneDrive for Copilot, including SharePoint Advanced Management, Microsoft Search in SharePoint, and site exclusions

Copilot returns whatever a user already has permission to see, so oversharing in SharePoint becomes a Copilot problem. SharePoint Advanced Management (SAM) gives you the controls to find and contain that risk.

What you need to know

  • SharePoint Advanced Management provides data access governance reports, Restricted Content Discovery, Restricted Access Control, and site lifecycle policies to reduce oversharing before Copilot can surface it
  • Restricted Content Discovery can exclude a site's content from Copilot and organization-wide search while still letting people who have direct access open it
  • Microsoft Search in SharePoint underpins how Copilot finds tenant content, so search configuration and content quality affect Copilot results
  • SAM is included with Microsoft 365 Copilot and is also available as a standalone add-on

Microsoft Learn resource: Get started with SharePoint Advanced Management (opens in a new tab)

Exam tip: To keep a sensitive site out of Copilot answers without changing who can open it directly, reach for Restricted Content Discovery in SharePoint Advanced Management.

Domain 2 Govern and Secure Microsoft 365 Tenants and Workloads 40-45% of the exam 0 / 21 studied

This is the largest domain and it spans identity, authentication, threat protection, and data protection. Expect heavy coverage of Microsoft Entra (users, groups, roles, PIM, authentication methods, Conditional Access), Microsoft Defender for Office 365, and Microsoft Purview information protection, data lifecycle, and DLP, including how these protect AI activity.

Manage identities in Microsoft Entra

14

Create and manage Microsoft 365 users

User accounts in Microsoft Entra ID are the identities behind every Microsoft 365 sign-in. You create them, license them, and manage their lifecycle from the admin center or with Microsoft Graph PowerShell.

What you need to know

  • Users are created in the Microsoft 365 admin center under Users, then Active users, or in the Microsoft Entra admin center
  • Each cloud user has a user principal name (UPN) based on a verified domain, plus properties like usage location, which is required before you can assign some licenses
  • Deleting a user moves it to a recycle bin where it can be restored for 30 days before permanent deletion
  • Blocking sign-in and resetting passwords are common lifecycle actions you can do individually or in bulk

Microsoft Learn resource: Create, invite, and delete users (opens in a new tab)

15

Manage guest users and external access settings

Guest access lets people outside your tenant collaborate in Teams, SharePoint, and groups without you creating full accounts for them. External access settings decide how far that collaboration can go.

What you need to know

  • Guests are added through Microsoft Entra B2B collaboration and appear as guest user objects in your directory
  • External collaboration settings control who can invite guests, whether guests can invite others, and which domains are allowed or blocked
  • Cross-tenant access settings give granular control over inbound and outbound B2B collaboration and trust of MFA and device claims from other tenants
  • Access reviews can periodically confirm that guests still need their access, and remove them when they do not

Microsoft Learn resource: B2B collaboration overview (opens in a new tab)

16

Create and manage groups, including Microsoft 365 groups

Groups drive licensing, access, and collaboration. Knowing the group types and their membership options is essential because they behave differently.

What you need to know

Microsoft Entra groups differ by type and by how membership is set:

Group type Main use Membership options
Microsoft 365 group Collaboration (Teams, SharePoint, shared mailbox) Assigned or dynamic
Security group Access to resources and license assignment Assigned or dynamic
Mail-enabled security group Access plus email distribution Assigned only
  • Microsoft 365 groups provide a shared identity for Teams, a SharePoint site, a group mailbox, and a calendar
  • Dynamic membership uses rules based on user attributes and requires Microsoft Entra ID P1
  • Group owners can manage membership, and expiration policies can automatically retire unused Microsoft 365 groups

Microsoft Learn resource: Manage Microsoft Entra groups and group membership (opens in a new tab)

17

Manage roles for Microsoft 365, including Microsoft Entra Privileged Identity Management (PIM)

Admin roles grant elevated permissions, and the goal is to give the fewest, for the shortest time. PIM makes powerful roles just-in-time instead of always-on.

What you need to know

  • Microsoft Entra has built-in roles (Global Administrator, User Administrator, and least-privilege roles such as AI Administrator) that you assign in the admin center
  • PIM makes a user eligible for a role rather than permanently active; the user activates the role when needed, with MFA, a justification, and optionally approval
  • Activations are time-bound and fully audited, which shrinks the window a privileged role is usable
  • PIM requires Microsoft Entra ID P2, and access reviews can confirm that eligible assignments are still needed

Microsoft Learn resource: What is Microsoft Entra Privileged Identity Management? (opens in a new tab)

Exam tip: The AI Administrator role is the least-privilege way to manage Copilot and AI features, so prefer it over Global Administrator for Copilot tasks.

18

Create and manage administrative units

Administrative units (AUs) scope an admin's power to a slice of the directory, such as one region or department, so a helpdesk admin can only act on their own users.

What you need to know

  • An administrative unit contains users, groups, or devices, and a role assignment scoped to an AU applies only to those members
  • AUs let you delegate roles like User Administrator or Helpdesk Administrator without giving tenant-wide power
  • Membership can be assigned manually or, with Microsoft Entra ID P1, set dynamically by rule
  • Restricted management administrative units can protect their members from modification by admins outside the AU

Microsoft Learn resource: Administrative units in Microsoft Entra ID (opens in a new tab)

19

Create and manage contacts

Mail contacts are directory entries for external people (for example, a vendor) so they appear in the address book without having a mailbox in your tenant.

What you need to know

  • Mail contacts have an external email address and show up in the global address list, but they have no mailbox and cannot sign in
  • You create and manage them in the Exchange admin center under Recipients, then Contacts, or in the Microsoft 365 admin center
  • Mail users are similar but have a sign-in identity in your directory, while mail contacts do not
  • Contacts can be added to distribution groups so external partners receive group mail

Microsoft Learn resource: Manage mail contacts in Exchange Online (opens in a new tab)

20

Perform bulk management, including Microsoft Graph PowerShell

At scale you do not click through users one by one. Bulk operations and Microsoft Graph PowerShell let you create, update, and license identities in one pass.

What you need to know

  • The admin centers support bulk operations such as bulk create, invite, delete, and license users from a CSV file
  • Microsoft Graph PowerShell is the current, supported module for scripting Microsoft 365 identity and service tasks; the older MSOnline and AzureAD modules are deprecated
  • You connect with Connect-MgGraph and consent to scopes, then use cmdlets such as New-MgUser and Get-MgUser
  • Bulk changes benefit from testing against a few objects first and from running with least-privilege scopes

Microsoft Learn resource: Bulk operations for users in the Microsoft Entra admin center (opens in a new tab)

Implement and manage authentication and access in Microsoft Entra

21

Configure and manage authentication methods

Authentication methods are the ways users prove who they are, from passwords to phishing-resistant passkeys. Modern policy lets you control which methods are available and to whom.

What you need to know

  • The Authentication methods policy in Microsoft Entra controls which methods (Microsoft Authenticator, FIDO2 security keys, passkeys, Windows Hello, SMS, and others) are enabled and for which groups
  • Microsoft Authenticator supports push approval and phishing-resistant passwordless sign-in, and passkeys and FIDO2 are the phishing-resistant options
  • The Authentication methods activity report shows registration and usage so you can plan a move away from weaker methods
  • Microsoft has moved method management out of the legacy MFA and SSPR portals into the unified Authentication methods policy

Microsoft Learn resource: What authentication and verification methods are available in Microsoft Entra ID? (opens in a new tab)

22

Implement and manage Microsoft Entra Password Protection

Password Protection blocks weak and easily guessed passwords by rejecting banned words and their variations, both in the cloud and, optionally, in on-premises Active Directory.

What you need to know

  • Microsoft maintains a global banned password list that applies automatically to every tenant
  • You can add a custom banned password list of terms specific to your organization (brand names, local sports teams) in the Authentication methods, then Password protection settings
  • Smart lockout protects against brute-force attacks by locking sign-ins after repeated failures while distinguishing the real user from an attacker
  • Deploying Password Protection to on-premises Active Directory uses a proxy and DC agents and requires Microsoft Entra ID P1

Microsoft Learn resource: Eliminate bad passwords with Microsoft Entra Password Protection (opens in a new tab)

23

Configure self-service password reset (SSPR)

SSPR lets users reset or unlock their own accounts without calling the helpdesk, using registered authentication methods to prove identity first.

What you need to know

  • SSPR is enabled in Microsoft Entra for none, selected (a group), or all users, and requires users to register enough authentication methods
  • You set how many methods are required to reset (one or two) and which methods qualify (mobile app, email, phone, security questions)
  • Password writeback lets a cloud-driven reset flow back to on-premises Active Directory in a hybrid environment
  • Combined registration lets users register for MFA and SSPR at the same time

Microsoft Learn resource: How self-service password reset works in Microsoft Entra ID (opens in a new tab)

24

Investigate and resolve authentication issues

When a user cannot sign in, the sign-in logs tell you why, from a blocking Conditional Access policy to a wrong password or a risky sign-in.

What you need to know

  • Sign-in logs in Microsoft Entra show each attempt with a status, a failure reason, and the Conditional Access policies that applied
  • The sign-in diagnostic walks you through a specific failed sign-in and suggests the cause and fix
  • Common causes include Conditional Access blocks, MFA challenges, disabled accounts, and expired or wrong passwords
  • Log retention depends on license (longer with Microsoft Entra ID P1 or P2), and you can export logs to Log Analytics for deeper analysis

Microsoft Learn resource: What are Microsoft Entra sign-in logs? (opens in a new tab)

25

Implement and manage Microsoft Entra Conditional Access policies, including Microsoft Entra ID Protection and multifactor authentication

Conditional Access is the policy engine at the heart of Zero Trust. It evaluates each sign-in and decides, based on conditions you set, whether to allow, block, or require extra proof.

What you need to know

Conditional Access policies follow an if-then structure:

  • If (assignments): which users, which apps or actions, and under which conditions (sign-in risk, device platform, location, client app)

  • Then (access controls): block, grant with MFA, require a compliant or hybrid-joined device, or apply session controls

  • Conditional Access requires Microsoft Entra ID P1, and risk-based conditions (sign-in risk, user risk) require Microsoft Entra ID P2 through ID Protection

  • ID Protection detects risky sign-ins and risky users and feeds that risk into Conditional Access for automatic response

  • Report-only mode lets you see the impact of a policy before you enforce it, and security defaults are a simpler alternative that is mutually exclusive with Conditional Access

Microsoft Learn resource: What is Conditional Access in Microsoft Entra ID? (opens in a new tab)

Exam tip: Security defaults and Conditional Access cannot both be on; turn off security defaults before you enforce Conditional Access policies.

Secure Microsoft 365 workloads

26

Manage alerts in Microsoft Defender for Office 365

Defender for Office 365 protects email and collaboration from phishing, malware, and malicious links, and it raises alerts you triage in the Defender portal.

What you need to know

  • Alerts surface in the Microsoft Defender portal under Incidents & alerts, where related alerts are correlated into incidents
  • Alert policies define what triggers an alert, its severity, and who is notified, and many come preconfigured
  • You can filter, assign, and resolve alerts, and drill from an alert into the underlying email or activity
  • Defender for Office 365 comes in Plan 1 (protection) and Plan 2 (adds investigation and automation such as Automated Investigation and Response)

Microsoft Learn resource: Microsoft Defender for Office 365 overview (opens in a new tab)

27

Configure threat policies and rules in Defender for Office 365

Threat policies decide how mail is filtered for spam, malware, phishing, and malicious links and attachments. Preset policies give you a Microsoft-recommended baseline fast.

What you need to know

  • Threat policies include anti-malware, anti-phishing, anti-spam, Safe Attachments, and Safe Links, configured in the Defender portal under Email & collaboration, then Policies & rules
  • Preset security policies (Standard and Strict) apply Microsoft's recommended settings and are easier to maintain than many custom policies
  • Safe Attachments detonates attachments in a sandbox; Safe Links rewrites and checks URLs at time of click
  • Policy precedence matters: preset policies and custom policy priority determine which policy applies when several match

Microsoft Learn resource: Preset security policies in Microsoft Defender for Office 365 (opens in a new tab)

28

Investigate and respond to email and collaboration threats by using Defender for Office 365

When a threat lands, Threat Explorer and remediation actions let you find affected messages and pull them back or clean them up.

What you need to know

  • Threat Explorer (or real-time detections) shows detected malware, phish, and campaigns across email, Teams, SharePoint, and OneDrive
  • You can take manual remediation actions such as soft delete, move to junk, or move to deleted items on affected messages
  • Automated Investigation and Response (AIR, in Plan 2) investigates alerts and recommends or takes remediation
  • Zero-hour Auto Purge (ZAP) retroactively removes messages found malicious after delivery

Microsoft Learn resource: About Threat Explorer and Real-time detections in Microsoft Defender for Office 365 (opens in a new tab)

29

Configure and manage attack simulations, including training campaigns

Attack simulation training runs safe, realistic phishing campaigns against your own users so you can measure risk and assign targeted training.

What you need to know

  • Attack simulation training is in the Defender portal under Email & collaboration, then Attack simulation training, and requires Defender for Office 365 Plan 2
  • You choose a social engineering technique (for example, credential harvest), a payload, a target audience, and a schedule
  • Results report who was compromised, and you can automatically assign training to those users
  • Simulation automations and payload automations let you run recurring campaigns without building each one by hand

Microsoft Learn resource: Get started using attack simulation training (opens in a new tab)

Protect data in Microsoft 365 by using Microsoft Purview

30

Identify requirements for Microsoft Purview Data Loss Prevention (DLP) policies, including those for Exchange, SharePoint, OneDrive, Teams, endpoints, and Copilot

DLP stops sensitive information from leaving where it should not, by detecting content and enforcing actions across many locations, now including Copilot.

What you need to know

DLP policies apply to a set of locations, each with its own considerations:

  • Exchange email, SharePoint, OneDrive, and Teams chat and channel messages are the classic locations
  • Endpoint DLP covers actions on Windows and macOS devices, such as copy to USB or upload to a browser
  • The Microsoft 365 Copilot location lets a DLP policy keep labeled content from being summarized or used by Copilot
  • A policy detects content by sensitive information types, trainable classifiers, or sensitivity labels, then applies actions such as block, block with override, or notify

Microsoft Learn resource: Learn about data loss prevention (opens in a new tab)

Exam tip: To stop Copilot from using content that carries a given sensitivity label, use a DLP policy scoped to the Microsoft 365 Copilot location.

31

Identify requirements for information protection, including sensitive information types, sensitivity labels, and sensitivity label policies

Information protection classifies and protects content itself, so a labeled file stays protected wherever it travels. Sensitivity labels are the core tool.

What you need to know

  • Sensitive information types (SITs) detect patterns such as credit card or national ID numbers and are the building blocks of classification
  • Sensitivity labels can mark content (headers, footers, watermarks) and enforce protection (encryption, access rights) that travels with the file
  • Label policies publish labels to users and groups and can set a default label and require justification for downgrades
  • Auto-labeling can apply labels automatically based on content, in the service or on the client

Microsoft Learn resource: Learn about sensitivity labels (opens in a new tab)

32

Identify requirements for data lifecycle management, including retention labels, retention label policies, and retention policies

Data lifecycle management keeps what you must and deletes what you should not keep, using retention policies and retention labels. The difference between the two is a favorite exam point.

What you need to know

Retention comes in two shapes that work together:

Tool Scope How it is applied
Retention policy A whole location (all of Exchange, all SharePoint, and so on) Automatically, tenant or location wide
Retention label An individual item or folder By users, by default, or automatically by rule
  • Both can retain, retain then delete, or just delete after a set period based on when content was created, last modified, or labeled
  • Retention labels can also mark content as a record, which restricts edits and deletion
  • The principles of retention decide the outcome when multiple settings apply (retention wins over deletion, longest retention wins)

Microsoft Learn resource: Learn about retention policies and retention labels (opens in a new tab)

33

Review and respond to DLP alerts for Microsoft 365 and AI services

DLP does not just block; it reports. The DLP alerts dashboard is where you see policy matches, including those involving AI, and decide what to do.

What you need to know

  • The DLP alerts dashboard in the Microsoft Purview portal shows policy matches, severity, and the user and location involved
  • You can drill into an alert to see the matched content, the rule that fired, and any user override and justification
  • Alerts feed activity explorer and can be part of a broader data security investigation
  • DLP for the Copilot location and AI activity means some alerts reflect attempts to use sensitive content with AI

Microsoft Learn resource: Get started with the data loss prevention alerts dashboard (opens in a new tab)

34

Monitor and secure AI activity by using Microsoft Purview Data Security Posture Management (DSPM)

DSPM for AI gives you one place to see how much sensitive data your AI apps touch and what to do about it, covering Microsoft 365 Copilot, other Copilots, and third-party AI.

What you need to know

  • DSPM for AI lives in the Microsoft Purview portal and gives reports on AI interactions, sensitive data referenced in prompts and responses, and risky AI usage
  • It offers one-click policies to help discover and protect AI data, such as detecting sensitive info in prompts and applying DLP or labels
  • It covers Microsoft 365 Copilot, Copilot Studio agents, Microsoft Foundry apps, and third-party AI apps
  • Activity explorer and audit surface the underlying AI interaction events for investigation

Microsoft Learn resource: Learn about Microsoft Purview Data Security Posture Management for AI (opens in a new tab)

Domain 3 Manage and Secure AI Services in Microsoft 365 35-40% of the exam 0 / 24 studied

This domain is what sets AB-650 apart from earlier Microsoft 365 admin exams. It covers enabling and governing Microsoft 365 Copilot, managing agents through Microsoft 365 and Microsoft Agent 365, securing agents with Microsoft Entra Agent ID and Purview, and monitoring the cost, adoption, and health of AI services. Because these features are new and moving quickly, expect the exact portal locations and names to keep evolving through the beta.

Enable and manage Microsoft 365 Copilot

35

Assess tenant readiness for Copilot, including in-app experiences

Before you assign Copilot licenses, you check that the tenant and its apps are ready, from update channels to how much people already use the apps Copilot plugs into.

What you need to know

  • The Copilot readiness report in the Microsoft 365 admin center (Reports, then Usage, then Microsoft Copilot) shows license eligibility, app readiness, and technical requirements
  • Copilot works best when users are on current Microsoft 365 Apps and signed in with a work account, and the report flags gaps
  • In-app Copilot experiences (Word, Excel, PowerPoint, Outlook, Teams) depend on those apps being deployed and up to date
  • Readiness data can take up to 72 hours to appear and to refresh

Microsoft Learn resource: Microsoft Copilot readiness report (opens in a new tab)

36

Identify and resolve data readiness issues for Copilot, including data leaks, data oversharing, and data compliance

Copilot inherits each user's existing permissions, so it will happily surface anything they can already reach. Data readiness is about closing oversharing before Copilot exposes it.

What you need to know

  • Oversharing is the top data readiness risk: content shared too broadly (org-wide links, open sites) becomes reachable by Copilot for anyone who can see it
  • SharePoint Advanced Management reports (data access governance) and Restricted Content Discovery help find and contain overshared sites
  • Purview sensitivity labels and DLP for the Copilot location protect content that must not be summarized or reused
  • The secure and governed data foundation guidance lays out a remediate-then-guardrail approach before broad rollout

Microsoft Learn resource: Configure a secure and governed foundation for Microsoft Copilot (opens in a new tab)

Exam tip: Copilot never bypasses permissions; if it returns something it should not, the fix is the underlying sharing, not Copilot itself.

37

Manage web search for Copilot and Microsoft 365 Copilot Chat

Web search lets Copilot ground answers on public web content, which improves quality but sends the query to the web. Admins decide whether to allow it.

What you need to know

  • The Allow web search in Copilot policy controls web grounding for both Microsoft 365 Copilot and Microsoft 365 Copilot Chat
  • The setting is reached from the Copilot page in the Microsoft 365 admin center, which links you to create a cloud policy in the Microsoft 365 Apps admin center
  • When web search is off, Copilot grounds only on tenant data and its model, not on live web content
  • The policy can target specific groups through the cloud policy service

Microsoft Learn resource: Manage web search for Microsoft 365 Copilot and Microsoft 365 Copilot Chat (opens in a new tab)

39

Configure Copilot settings for a tenant, including self-service purchases, Copilot in admin centers, release preferences, AI disclaimer, and video and image generation

The Copilot page in the admin center is where you turn tenant-wide Copilot behaviors on or off, from who can buy licenses to whether users can generate images.

What you need to know

  • Self-service purchases (Copilot, then Settings, then User access) can be set to Allow, Allow trials only, or Do not allow so users cannot buy Copilot on their own
  • Copilot in admin centers controls whether admins get Copilot help inside the Microsoft 365, Exchange, SharePoint, and Teams admin centers
  • Image generation in Copilot Chat and other in-app AI actions are toggled through Copilot controls
  • Release preferences and AI disclaimers are configured in org settings and the Copilot settings, so users see the right experience and any required notice

Microsoft Learn resource: Manage Microsoft Copilot scenarios in the Microsoft 365 admin center (opens in a new tab)

40

Manage Copilot user experiences

Beyond the tenant switches, you shape how the Copilot app itself looks and behaves for users, such as whether Copilot Chat is pinned and which agents appear.

What you need to know

  • The Copilot app settings (managed with the Office Apps admin role through cloud policy) control pinning Copilot Chat, the Search module, and agent availability
  • Pinning policies decide whether Copilot Chat appears in the Microsoft 365 app and other surfaces, based on license
  • You can allow or block agents from showing in the Copilot app through Integrated apps
  • User enablement (prompt gallery, training) drives whether the experience is actually adopted

Microsoft Learn resource: Microsoft Copilot app features that admins can control (opens in a new tab)

41

Manage Microsoft 365 Copilot Cowork

Copilot Cowork lets users delegate complex, multi-step work that Copilot carries out across Microsoft 365 apps, checking in for review. It is consumption-based, so admins manage its billing.

What you need to know

  • Cowork takes an outcome you describe, then gathers information, coordinates tasks across apps, and produces deliverables while keeping you in control through review and approval
  • For work or school accounts Cowork is generally available; the personal-account preview runs through the Microsoft Copilot Frontier program
  • Because Cowork is metered, you configure billing policies and spending controls (Copilot credits and usage-based billing) rather than assigning a seat
  • You monitor consumption so costs stay within your spending policies

Microsoft Learn resource: Get started with Microsoft 365 Copilot Cowork (opens in a new tab)

42

Manage third-party AI providers

Copilot can be extended to use non-Microsoft large language models, and admins decide whether to allow that. This is the AI providers setting.

What you need to know

  • The AI providers for other large language models setting is under Copilot, then Settings, then Data access in the Microsoft 365 admin center
  • It controls whether users can use non-Microsoft models (for example, Anthropic Claude models) within Copilot Chat and Copilot Studio
  • Allowing a third-party provider means user prompts can be processed by that provider, so treat it as a data governance decision
  • It is off or on at the tenant level, and it works alongside your Purview and DLP controls

Microsoft Learn resource: Connect to AI models from other providers (opens in a new tab)

43

Configure Copilot connectors

Copilot connectors (formerly Microsoft Graph connectors) bring content from outside Microsoft 365, such as a wiki or a ticketing system, into the search index so Copilot can ground on it.

What you need to know

  • Copilot connectors index external content into the Microsoft 365 semantic and search index so Copilot and Copilot Search can use it as grounding data
  • There are over 100 prebuilt connectors in the gallery from Microsoft and independent vendors, plus a custom connector option through the API
  • Connectors are managed in the Microsoft 365 admin center (Search & intelligence, then Data sources) and you control which content and which users see it
  • Indexed items count toward connector quotas and respect the access permissions you configure

Microsoft Learn resource: Microsoft 365 Copilot connectors overview (opens in a new tab)

Implement and manage agents in Microsoft 365 and Agent 365

44

Manage the lifecycle workflows for agent identities by using Microsoft Entra Agent ID

Agents are non-human actors that need identities of their own. Microsoft Entra Agent ID gives each agent a first-class identity you can govern like a user.

What you need to know

  • Microsoft Entra Agent ID gives agents their own identities in Microsoft Entra, separate from the users they work for, so their actions are attributable
  • Identity governance for agents provides sponsors and owners, access packages, and lifecycle workflows so access is intentional, auditable, and time-bound
  • Lifecycle workflows help ensure agents do not accumulate stale permissions and are retired when no longer needed
  • Microsoft Entra Agent ID is in preview and extends existing Entra governance to agents

Microsoft Learn resource: What is Microsoft Entra Agent ID? (opens in a new tab)

45

Secure agent access, including access packages and conditional access

The same access controls you use for people apply to agents: Conditional Access to gate sign-in, and entitlement management access packages to grant time-bound resource access.

What you need to know

  • Conditional Access for agents evaluates agent identity and risk before granting access, with Microsoft-managed policies providing a secure baseline that blocks high-risk agents
  • Access packages (entitlement management) grant an agent access to specific resources for a limited time, with review, so access is intentional and expires
  • Custom security attributes let you apply Conditional Access to many agents at scale while still allowing fine-grained control
  • Governing agent access this way requires Microsoft Agent 365 with the appropriate Entra licensing

Microsoft Learn resource: Conditional Access for agent identities (opens in a new tab)

46

Manage agent owners

Every agent needs a responsible human. Ownership makes someone accountable for an agent's lifecycle, compliance, and cleanup, and ownerless agents are a governance gap.

What you need to know

  • Each agent should have a designated owner (and often a sponsor) responsible for its lifecycle and compliance
  • The agent overview in the Microsoft 365 admin center surfaces agents without owners so you can assign one
  • Assigning ownership is a governance action that requires the AI Administrator or Global Administrator role
  • Ownerless or orphaned agents are flagged because they create risk and cost with no one accountable

Microsoft Learn resource: Agent management in the Microsoft 365 admin center (opens in a new tab)

47

Configure agent settings, including allowed agent types, sharing, templates, and user access

Agent settings decide who can use and build agents, which agent types are allowed, and how they can be shared, so experimentation stays within guardrails.

What you need to know

  • Agent settings are configured under Copilot, then Settings, then Data access, then Agents, and through Integrated apps in the Microsoft 365 admin center
  • You control who can access agents and which agent types users can install or create
  • Sharing controls determine whether users can share agents they build, and templates provide approved starting points
  • Built-in agents are on by default, and you can allow or block specific agents from appearing in the Copilot app

Microsoft Learn resource: Manage agents for Microsoft Copilot in Integrated apps (opens in a new tab)

48

Discover and manage Microsoft and third-party agents in the agent registry

The agent registry is the single inventory of every agent in your tenant, whether built on Microsoft platforms or acquired elsewhere. It is where governance starts.

What you need to know

  • The agent registry in the Microsoft 365 admin center is a centralized inventory giving a unified view of agent adoption, activity, and health
  • It includes agents from Microsoft platforms (Copilot Studio, SharePoint, Agent Builder, AI Foundry) and detected non-Microsoft agents
  • From the registry you can filter agents by risk, owner, or status and take action
  • The registry is part of the observe pillar of Microsoft Agent 365

Microsoft Learn resource: Manage agents with the agent registry (opens in a new tab)

49

Review requests and publish or reject agents in the agent registry

New agents come under control through one approval flow. Admins review pending requests and either publish an agent for use or reject it.

What you need to know

  • Users submit agents for approval, and pending requests appear in the agent overview and the registry's Requests view
  • Reviewing and approving or rejecting agent requests requires the AI Administrator or Global Administrator role
  • Onboarding agents through this IT-controlled flow applies policy templates for governance and compliance from day one
  • The overview surfaces top actions such as pending requests, agents at risk, and agents with exceptions

Microsoft Learn resource: Agent governance and top actions in the Microsoft 365 admin center (opens in a new tab)

50

Install, block, or control access to agents in the agent registry, including uploading custom agents

Beyond approving requests, you decide which agents users can install, block risky ones, and bring your own custom agents under management.

What you need to know

  • Through Integrated apps and the registry you can deploy an agent to users, block it, or control who can access it
  • Custom agents can be uploaded and brought under the same governance and policy templates as built-in ones
  • Least-privilege access controls limit which users, data, and tools an agent can reach
  • Rules-based management can automatically block risky agents or flag ownerless ones

Microsoft Learn resource: Manage agents for Microsoft Copilot in Integrated apps (opens in a new tab)

51

Manage tools in Agent 365

Agents act through tools, such as connectors to Outlook, Teams, or SharePoint. Managing those tools controls what an agent can actually do.

What you need to know

  • Tools are the capabilities an agent uses to take action, including Model Context Protocol (MCP) connected services such as Outlook, Teams, SharePoint, and OneDrive
  • Agent 365 lets you manage which tools an agent can use as part of least-privilege access
  • Restricting tools limits an agent to only the resources it needs to do its job
  • Tool usage is captured in agent activity for audit and investigation

Microsoft Learn resource: Overview of Microsoft Agent 365 (opens in a new tab)

Secure and govern agents by using Agent 365

52

Monitor agent activity by using Agent 365

Observability is the first pillar of Agent 365. It gives you real-time visibility into what agents are doing so you can spot risk before it becomes a problem.

What you need to know

  • Agent 365 gives real-time visibility into agent usage, performance, and risk signals through the registry and the agent overview
  • Agent activity, including prompts, tool usage, and outcomes, is captured and correlated across Microsoft Entra, Microsoft Defender, and Microsoft Purview
  • The agent overview shows a rolling snapshot of activity, usage trends, and governance gaps
  • Role-specific views give IT, security, and business stakeholders the insights they each need

Microsoft Learn resource: Overview of Microsoft Agent 365 (opens in a new tab)

53

Protect sensitive data by using Agent 365

Agents touch documents, mail, and other content, so the same Purview protections that guard users must extend to agents.

What you need to know

  • Agent 365 integrates with Microsoft Purview to apply data protection policies to agent activity and to audit what agents access
  • DLP, sensitivity labels, and information protection extend to agents so sensitive content is not mishandled
  • Agent interactions are recorded so compliance teams can investigate data usage
  • Purview coverage for agents is part of the secure pillar of Agent 365

Microsoft Learn resource: Microsoft Purview data security and compliance protections for agents (opens in a new tab)

54

Evaluate compliance gaps by using Agent 365

Governance means proving agents operate within policy. Agent 365 helps you find where they do not, so you can close the gap before an auditor does.

What you need to know

  • Agent 365 surfaces compliance gaps and agents at risk by aggregating high-severity signals across Microsoft Entra, Defender, and Purview
  • Built-in auditing, data classification, and retention help you detect sensitive data usage and keep records for investigation
  • The agent overview flags agents with exceptions, agents at risk, and ownerless agents as governance tasks to resolve
  • Securing agents at scale uses baseline controls across Entra, Defender, and Purview

Microsoft Learn resource: Secure AI agents at scale with Microsoft Agent 365 (opens in a new tab)

Monitor AI services in Microsoft 365

55

Manage and monitor costs for AI services in Microsoft 365

Several AI services bill by consumption rather than per seat, so cost management means watching credits and metered usage, not just counting licenses.

What you need to know

  • Consumption-based AI services (Copilot Cowork, Copilot Studio pay-as-you-go, agent usage) draw on Copilot credits and usage-based billing tied to an Azure subscription
  • You set billing policies and spending controls in the Microsoft admin center to cap or segment consumption
  • Monitoring usage-based billing shows where credits are going so you can forecast and control spend
  • Per-user Copilot licenses are a separate, predictable cost you track under Billing

Microsoft Learn resource: Usage-based billing and cost management for Copilot credits (opens in a new tab)

56

Monitor usage reports for Copilot in the Microsoft 365 admin center, including workload-level adoption details

The Copilot usage report tells you whether your investment is being used, broken down by app so you can target enablement where adoption is low.

What you need to know

  • The Microsoft Copilot usage report (Reports, then Usage, then Microsoft Copilot) summarizes how users adopt, retain, and engage with Copilot
  • It breaks adoption down by Microsoft 365 app (Word, Excel, Teams, Outlook, and others) so you see workload-level detail
  • It also surfaces the most used agents
  • Usage data typically appears within about 48 hours, and viewing reports needs a role such as AI Administrator or Reports Reader

Microsoft Learn resource: Microsoft Copilot usage report (opens in a new tab)

57

Monitor usage and adoption for AI services in Microsoft 365 by using the Copilot Control System

The Copilot Control System is Microsoft's framework for managing, measuring, and securing Copilot. For adoption you use its measurement tools, chiefly the reports and the Copilot dashboard.

What you need to know

  • The Copilot Control System brings together management controls, measurement (usage and readiness reports, the Copilot dashboard in Viva Insights), and security and governance for Copilot
  • The Copilot dashboard classifies users by engagement (for example, power, habitual, and novice users) over a rolling window so you can see real adoption
  • Admin center reports and the dashboard together answer both who is licensed and who is actually getting value
  • These measurement tools help you decide where to focus enablement and license assignment

Microsoft Learn resource: Microsoft Copilot reporting options for admins (opens in a new tab)

58

Monitor service health by using the Copilot Control System

When Copilot itself has a problem, service health tells you whether it is Microsoft's incident or your configuration, the same way it does for other Microsoft 365 services.

What you need to know

  • Service health in the Microsoft 365 admin center reports incidents and advisories for Copilot and its underlying services
  • It is the authoritative place to confirm whether a Copilot problem is a known service issue
  • You can configure notifications so admins hear about Copilot-related incidents as they are posted
  • Health signals sit alongside the Copilot Control System's management and measurement views for a full operational picture

Microsoft Learn resource: How to check Microsoft 365 service health (opens in a new tab)

Quick reference: where to go for what

Task Where to go
Set the Microsoft 365 theme Microsoft 365 admin center > Settings > Org settings > Organization profile
Add and verify a domain Microsoft 365 admin center > Settings > Domains
Assign licenses by group Microsoft Entra admin center > Groups > (group) > Licenses
Set up Microsoft 365 Backup Microsoft 365 admin center > Settings > Backup (with an Azure subscription)
Check service health Microsoft 365 admin center > Health > Service health
Review network connectivity Microsoft 365 admin center > Health > Network connectivity
Create a shared mailbox Microsoft 365 admin center > Teams & groups, or Exchange admin center > Recipients > Mailboxes
Manage a team Microsoft Teams admin center > Teams > Manage teams
Reduce Copilot oversharing SharePoint admin center > Reports and SharePoint Advanced Management
Manage users in bulk Microsoft 365 admin center > Users, or Microsoft Graph PowerShell
Configure Conditional Access Microsoft Entra admin center > Protection > Conditional Access
Set up PIM Microsoft Entra admin center > ID Governance > Privileged Identity Management
Manage authentication methods Microsoft Entra admin center > Protection > Authentication methods
Configure threat policies Microsoft Defender portal > Email & collaboration > Policies & rules
Run attack simulation training Microsoft Defender portal > Email & collaboration > Attack simulation training
Create a DLP policy Microsoft Purview portal > Data Loss Prevention > Policies
Publish sensitivity labels Microsoft Purview portal > Information Protection
Configure retention Microsoft Purview portal > Data Lifecycle Management
Monitor AI activity Microsoft Purview portal > DSPM for AI
Configure Copilot settings Microsoft 365 admin center > Copilot > Settings
Configure Copilot Search Microsoft 365 admin center > Copilot > Search
Manage agents and requests Microsoft 365 admin center > Copilot > Agents, then the agent registry
Govern agent identities Microsoft Entra admin center > Agent ID and ID Governance
Track Copilot adoption Microsoft 365 admin center > Reports > Usage > Microsoft Copilot

Additional tips

The best thing you can do after reading this guide is to start a free Microsoft 365 trial and play with the features. Follow the tutorials in the Learn paths inside your own tenant and the exam questions will feel familiar.

Before exam day, explore the exam interface in the Microsoft exam sandbox (opens in a new tab), so the question types and the navigation hold no surprises.

Microsoft

Microsoft 365 developer sandbox

Free

A Microsoft 365 E5 developer sandbox with sample users and data, so you can try every admin task in this guide without touching production. The sandbox is free, though setup now requires a billing account for verification.

Start on Microsoft Learn (opens in a new tab)

Frequently asked questions

Is the AB-650 exam still in beta?

Yes. AB-650 is currently a beta exam, and Microsoft expects it to reach general availability around October 2026. While it is in beta the skills measured can still change, so check the official AB-650 study guide before you book. Beta exams also are not scored right away, because Microsoft first gathers data on the questions, so expect your result to arrive after the beta period closes.

How long should I study for the AB-650?

AB-650 is an associate-level exam that assumes real experience with Microsoft 365, Microsoft Entra ID, Defender XDR, and Microsoft Graph PowerShell, so plan around 6 to 8 weeks of focused study if you already administer Microsoft 365. If you are newer to the platform, or new to the Copilot and agent administration topics, give yourself more time and start with the free Microsoft Learn paths in this guide. The AI services domain is the newest material for most admins, so budget extra time there.

Do I need hands-on experience to pass the AB-650?

Yes, hands-on experience helps a lot, because this exam is written for practicing administrators rather than beginners. You should be comfortable in the Microsoft 365 admin center, the Microsoft Entra admin center, the Microsoft Defender portal, and the Microsoft Purview portal, and increasingly in the Copilot and agent management experiences. If you do not have a production tenant to practice in, set up a free Microsoft 365 developer sandbox and work through the tasks in this guide there.

How does the AB-650 relate to the retiring MS-102 exam?

Microsoft is retiring MS-102: Microsoft 365 Administrator on November 30, 2026, and AB-650 is the new associate certification for administering Microsoft 365 together with its AI services. If you were planning to take MS-102, AB-650 is the path to look at going forward, since it carries the modern tenant, identity, security, and Purview content plus the new Copilot and agent administration skills. Microsoft has not published a formal one-to-one replacement mapping between the two, so treat AB-650 as the current direction rather than a direct swap.

What experience does Microsoft recommend before taking the AB-650?

Microsoft's audience profile expects you to configure, manage, secure, and govern Microsoft 365 tenants, workloads, and AI services, including Microsoft 365 Copilot and agents. You should have experience with Microsoft 365 workloads and Microsoft Entra ID, an understanding of Microsoft Defender XDR capabilities, and familiarity with Microsoft Graph PowerShell. In practice this is a role for someone who already administers Microsoft 365 day to day and is now taking on the AI services that run on top of it.

Maintained by Vlad Catrinescu, reviewed September 2026 · All study guides