Microsoft 365 and AI Services Administrator Associate
Free study notes for every skill Microsoft measures on the AB-650 beta exam, plus the resources I recommend.
By Vlad CatrinescuMicrosoft MVP and MCT · Pluralsight Author
The AB-650 Study Guide helps you prepare for Administering Microsoft 365 and AI Services, the exam behind the new Microsoft 365 and AI Services Administrator Associate certification. It is written for administrators who configure, secure and govern Microsoft 365 tenants, workloads and AI services like Microsoft 365 Copilot and agents. AB-650 is in beta right now, and Microsoft expects it to reach general availability around October 2026, so treat the skills measured as provisional until then.
Everything here lines up with the skills Microsoft measures: free Microsoft Learn paths and my own study notes for self-study, plus the practice test I recommend when you want more. No exam dumps, ever.
Because the exam is new and still in beta, there is no dedicated book, video course or instructor-led course yet. I will add those here as soon as good ones exist.
Exam length
100 min
Passing score
700 / 1000
Skills measured
3 domains, 58 skills
Guide reviewed
September 2026
Resources by the way you like to study
3 hand-picked, free and paid
Practice Tests
1 resource
These are practice exams, not dumps. Dumps ruin the value of a certification for everyone. Practice tests are a great way to check you are ready once you have studied everything in this guide.
AB-650: Administering Microsoft 365 and AI Services
Five full-length practice exams with detailed answer explanations, aligned to the AB-650 skills measured. A solid way to check your readiness once you have worked through this guide, and to find weak spots while the exam is still in beta.
Microsoft Learn is a great free way to learn the AB-650 content. It is mostly text-based articles, with small quizzes at the end of every module.
The course syllabus below is Microsoft's own list of the learning paths and modules that cover the exam. When you want one topic rather than the whole curriculum, every skill in my study notes links the exact Microsoft Learn page for it.
Course AB-650T00-A: Administer Microsoft 365 and AI services
Free
Microsoft's official AB-650 course page. The syllabus lists every Microsoft Learn path and module the course teaches, and all of them are free to work through at your own pace.
This is the Microsoft Official Course, which you can schedule at a Microsoft learning partner. The classes are presented by Microsoft Certified Trainers. It is the best way to learn any topic, since you can ask a live instructor questions, and also the most expensive one.
Course AB-650T00-A: Administer Microsoft 365 and AI services
Instructor-led
The official Microsoft instructor-led course for AB-650, delivered by a Microsoft Certified Trainer at a learning partner. It works through the tenant, workload and AI service administration the exam measures, with an instructor to ask.
Some links on this page are affiliate links. If you use them, I may earn a commission at no extra cost to you.
Skills measured and study notes
58 skills, free to study here
0 of 58 studied
Before you start, one important note: AB-650 is a beta exam. Microsoft has released it in beta and expects it to reach general availability around October 2026. While the exam is in beta, the skills measured can still shift, so Microsoft may change the domains, the weightings, or the individual tasks before it goes GA. I wrote these notes to the skills measured Microsoft published for the AB-650 beta and last checked them on September 22, 2026 (the Microsoft study guide page was last updated July 27, 2026, and shows a single version with no change log). I will update them once the exam is finalized, so treat everything below as current for the beta and worth a quick recheck against the official skills measured before you book.
These notes are organized exactly the way Microsoft groups the AB-650 skills measured: three domains, each broken into skill groups, with every single skill explained below along with the key facts the exam can ask and a Microsoft Learn link. After years of helping IT pros prepare for Microsoft exams, I can tell you the most reliable way to study is to walk the skills measured one at a time, which is how these notes are laid out. Here is how the three domains break down by weight:
Tip: The two heaviest domains are governance and security at 40-45% and AI services at 35-40%. If your study time is limited, make identity, Defender for Office 365, Purview, and the Copilot and agent administration sections your priority, because together they are most of the exam.
Domain 1Configure and Manage Microsoft 365 Tenants and Workloads20-25% of the exam0 / 13 studied
This domain covers the day-to-day administration of a Microsoft 365 tenant and its core workloads. Expect questions on tenant-wide settings, licensing (including the AI licenses), Microsoft 365 Backup, service monitoring, and the management of Exchange, Teams, and SharePoint, with an eye on how each workload is prepared for Copilot.
Configure and manage a Microsoft 365 tenant
01
Configure branding in a Microsoft 365 tenant, including logo, company URL, themes, and backgrounds
Studied
Organizational branding lets you replace the default Microsoft look with your own logo, colors, and sign-in background so users can trust that they are signing in to the right place. In Microsoft 365 the theme is set in the admin center, while the sign-in page branding lives in Microsoft Entra.
What you need to know
The Microsoft 365 theme is configured in the Microsoft 365 admin center under Settings, then Org settings, then Organization profile, then Custom themes
Company branding for the sign-in experience (background image, banner logo, sign-in text) is set in the Microsoft Entra admin center under Company branding
You can set a default brand plus language-specific variations, and Entra ID P1 or P2 is required for custom sign-in branding
Theme elements include the logo, the navigation bar color, the accent color, and whether the user's photo or a custom image appears
A custom domain (for example, contoso.com) replaces the default onmicrosoft.com address on email and sign-in names. Adding one means proving you own it and pointing the right DNS records at Microsoft 365.
What you need to know
You add and verify a domain in the Microsoft 365 admin center under Settings, then Domains, by publishing a TXT (or MX) record at your DNS host
After verification you add the service records: MX for mail, CNAME records for Autodiscover and Teams, and TXT records for SPF
Every tenant keeps its original onmicrosoft.com domain, which cannot be removed
You can set a default domain for new users, and you must move users and groups off a domain before you can remove it
Exam tip: You cannot delete a custom domain while any user, group, or mailbox still uses it as an address, so reassign those first.
03
Configure and manage organizational settings, including security and privacy settings and the organization profile
Studied
Org settings are the tenant-wide switches that control how services, security, and privacy behave for everyone. They live in one place so you can turn features on or off across the organization.
What you need to know
Org settings live in the Microsoft 365 admin center under Settings, then Org settings, split into Services, Security & privacy, and Organization profile tabs
Security & privacy covers items such as self-service password reset, sharing, and privacy profile settings
The Organization profile holds the organization name, address, technical contact, and release preferences
Many settings here are tenant-wide defaults that individual workload admin centers can then refine
Manage and monitor Microsoft 365 licenses, including group-based licensing and pay-as-you-go
Studied
Licenses control which services a user can use, and at scale you want to assign them by group rather than one user at a time. Some newer services bill by consumption instead of per-user seats.
What you need to know
Licenses can be assigned directly to a user or, at scale, through group-based licensing in Microsoft Entra, where every member of a group inherits the assigned licenses
Group-based licensing requires Microsoft Entra ID P1 for the users being licensed, and it automatically assigns and removes licenses as membership changes
Pay-as-you-go services (such as Microsoft 365 Backup and Microsoft 365 Archive) bill against a linked Azure subscription based on what you consume, with no seat to assign
You monitor assignment and usage from the admin center under Billing, then Licenses, and from the Reports area
Manage and monitor licenses for AI services, including Microsoft 365 Copilot, Microsoft Agent 365, and Microsoft Copilot Studio
Studied
The AI services carry their own licensing, and the exam expects you to know how each one is licensed and where you assign or monitor it.
What you need to know
Microsoft 365 Copilot is a per-user add-on that requires an eligible base Microsoft 365 license, and it is assigned like any other license in the admin center
Microsoft Agent 365 is included with Microsoft 365 E7 and is available as an add-on to Microsoft 365 E5, A5, or Business Premium (or the Defender and Purview suites)
Copilot Studio can be licensed per-user or consumed with pay-as-you-go metered billing (message packs or a linked Azure subscription)
You track AI license assignment and demand from the Copilot page in the admin center, including the self-service purchase and usage signals
Configure and use Microsoft 365 Backup, including setup, restore, and monitor
Studied
Microsoft 365 Backup protects SharePoint sites, OneDrive accounts, and Exchange mailboxes inside the Microsoft trust boundary, with fast restore for scenarios like ransomware recovery. It is a pay-as-you-go service, not a per-user license.
What you need to know
Microsoft 365 Backup is set up in the Microsoft 365 admin center and requires a SharePoint Administrator or Global Administrator, plus a linked Azure subscription for pay-as-you-go billing
It protects three workloads independently: SharePoint, OneDrive, and Exchange, and you scope protection with backup policies
Billing is consumption-based on the volume of protected content (list price around 0.15 US dollars per GB per month), charged through Azure with no extra Azure storage fees
Restores are fast because data stays in the Microsoft 365 substrate; express restore points let you recover a site or mailbox to a point in time
Exam tip: Microsoft 365 Backup is pay-as-you-go and needs an Azure subscription, so there is no seat to assign; contrast that with a per-user add-on like Copilot.
07
Configure and review network connectivity insights
Studied
Network connectivity insights measure how well each office location reaches Microsoft 365 and flag problems like backhauling traffic through a distant proxy. Good connectivity matters a lot for real-time workloads such as Teams.
What you need to know
Network connectivity is found in the Microsoft 365 admin center under Health, then Network connectivity
It gives each location a network connectivity score and compares your egress against Microsoft's connectivity principles (for example, egress traffic locally, avoid unnecessary proxying)
You can add locations and run assessments, and the onboarding tool collects measurements from a user's location
Insights call out issues like high latency, distant Microsoft 365 service front doors, and traffic that is not broken out locally
Monitor the health of Microsoft 365 services by using Service health, including notification configuration
Studied
Service health tells you whether a problem is Microsoft's or yours, and it is the first place to look when users report an outage. You can also have it notify you when incidents are posted.
What you need to know
Service health lives in the Microsoft 365 admin center under Health, then Service health, and shows current incidents and advisories per service
Each issue has a status, an impact description, and a history of updates, plus a linked message in the message center where relevant
You configure email notifications for service health so admins are alerted when new incidents or advisories are posted for chosen services
Viewing service health requires a role such as Global Reader, Service Support Administrator, or an admin role that includes it
Create and manage mailboxes, including shared mailboxes
Studied
Exchange Online mailboxes come in several types, and knowing which type needs a license and which does not is a classic exam point. Shared mailboxes let a team work from a common address like info@contoso.com.
What you need to know
Exchange Online recipient types differ mainly in whether they need a license and who signs in:
Mailbox type
Who uses it
License needed
User mailbox
One person's email, calendar, contacts
Yes
Shared mailbox
A team, from a common address
No, unless over 50 GB or needing archive/hold
Resource mailbox
A room or piece of equipment for booking
No
Shared mailboxes are managed in the Microsoft 365 admin center or the Exchange admin center, and members are granted Full Access and Send As permissions
A shared mailbox has a disabled sign-in account, so users open it through their own credentials rather than signing in directly
You can convert a user mailbox to a shared mailbox to preserve its contents without keeping a paid license
Exam tip: A shared mailbox under 50 GB needs no license, but it does need a license once you apply an archive or a litigation hold, or if it exceeds 50 GB.
10
Create and manage teams in Microsoft Teams, including channels, owners, and members
Studied
A team in Microsoft Teams is backed by a Microsoft 365 Group, and creating one provisions a SharePoint site, a group mailbox, and channels. Owners manage the team, while members use it.
What you need to know
Teams are created and managed from the Teams admin center (Teams, then Manage teams) or by users in the Teams client, subject to your policies
Every team has at least one owner; owners add and remove members, manage channels, and control settings, and Microsoft recommends at least two owners per team
Standard channels are open to all members and share the team's SharePoint site, while private and shared channels each get their own SharePoint site and membership
You govern team creation, naming, and expiration through Microsoft 365 Groups settings, naming policies, and group expiration policies
Configure settings for Copilot in Teams meetings, including transcription
Studied
Copilot in Teams meetings can summarize discussions and answer questions about what was said, but it depends on the meeting being transcribed or recorded. Admins control that behavior with meeting policies.
What you need to know
Copilot in meetings is governed by a Teams meeting policy setting that can be set to run only with transcription on, or to work during the meeting without saving the transcript
Transcription and recording are themselves controlled by meeting policies in the Teams admin center under Meetings, then Meeting policies
If transcription is turned off and the Copilot setting requires it, users cannot use Copilot in that meeting
Meeting Copilot requires an eligible Microsoft 365 Copilot license for the user invoking it
Create and manage SharePoint sites, including permissions
Studied
SharePoint sites store the files behind Teams, OneDrive, and much of Microsoft 365, so managing sites and their permissions is central to keeping content secure and Copilot-ready.
What you need to know
Sites are created and managed in the SharePoint admin center under Sites, then Active sites, where you can create, delete, and change site settings and ownership
Communication sites have no Microsoft 365 Group, while team sites are group-connected and inherit the group's owners and members
Site permissions flow through SharePoint groups (Owners, Members, Visitors) mapped to Full Control, Edit, and Read; avoid breaking inheritance except where you must
Sharing settings at the organization and site level control whether content can be shared with guests or anonymously
Configure SharePoint and OneDrive for Copilot, including SharePoint Advanced Management, Microsoft Search in SharePoint, and site exclusions
Studied
Copilot returns whatever a user already has permission to see, so oversharing in SharePoint becomes a Copilot problem. SharePoint Advanced Management (SAM) gives you the controls to find and contain that risk.
What you need to know
SharePoint Advanced Management provides data access governance reports, Restricted Content Discovery, Restricted Access Control, and site lifecycle policies to reduce oversharing before Copilot can surface it
Restricted Content Discovery can exclude a site's content from Copilot and organization-wide search while still letting people who have direct access open it
Microsoft Search in SharePoint underpins how Copilot finds tenant content, so search configuration and content quality affect Copilot results
SAM is included with Microsoft 365 Copilot and is also available as a standalone add-on
Exam tip: To keep a sensitive site out of Copilot answers without changing who can open it directly, reach for Restricted Content Discovery in SharePoint Advanced Management.
Domain 2Govern and Secure Microsoft 365 Tenants and Workloads40-45% of the exam0 / 21 studied
This is the largest domain and it spans identity, authentication, threat protection, and data protection. Expect heavy coverage of Microsoft Entra (users, groups, roles, PIM, authentication methods, Conditional Access), Microsoft Defender for Office 365, and Microsoft Purview information protection, data lifecycle, and DLP, including how these protect AI activity.
Manage identities in Microsoft Entra
14
Create and manage Microsoft 365 users
Studied
User accounts in Microsoft Entra ID are the identities behind every Microsoft 365 sign-in. You create them, license them, and manage their lifecycle from the admin center or with Microsoft Graph PowerShell.
What you need to know
Users are created in the Microsoft 365 admin center under Users, then Active users, or in the Microsoft Entra admin center
Each cloud user has a user principal name (UPN) based on a verified domain, plus properties like usage location, which is required before you can assign some licenses
Deleting a user moves it to a recycle bin where it can be restored for 30 days before permanent deletion
Blocking sign-in and resetting passwords are common lifecycle actions you can do individually or in bulk
Guest access lets people outside your tenant collaborate in Teams, SharePoint, and groups without you creating full accounts for them. External access settings decide how far that collaboration can go.
What you need to know
Guests are added through Microsoft Entra B2B collaboration and appear as guest user objects in your directory
External collaboration settings control who can invite guests, whether guests can invite others, and which domains are allowed or blocked
Cross-tenant access settings give granular control over inbound and outbound B2B collaboration and trust of MFA and device claims from other tenants
Access reviews can periodically confirm that guests still need their access, and remove them when they do not
Manage roles for Microsoft 365, including Microsoft Entra Privileged Identity Management (PIM)
Studied
Admin roles grant elevated permissions, and the goal is to give the fewest, for the shortest time. PIM makes powerful roles just-in-time instead of always-on.
What you need to know
Microsoft Entra has built-in roles (Global Administrator, User Administrator, and least-privilege roles such as AI Administrator) that you assign in the admin center
PIM makes a user eligible for a role rather than permanently active; the user activates the role when needed, with MFA, a justification, and optionally approval
Activations are time-bound and fully audited, which shrinks the window a privileged role is usable
PIM requires Microsoft Entra ID P2, and access reviews can confirm that eligible assignments are still needed
Exam tip: The AI Administrator role is the least-privilege way to manage Copilot and AI features, so prefer it over Global Administrator for Copilot tasks.
18
Create and manage administrative units
Studied
Administrative units (AUs) scope an admin's power to a slice of the directory, such as one region or department, so a helpdesk admin can only act on their own users.
What you need to know
An administrative unit contains users, groups, or devices, and a role assignment scoped to an AU applies only to those members
AUs let you delegate roles like User Administrator or Helpdesk Administrator without giving tenant-wide power
Membership can be assigned manually or, with Microsoft Entra ID P1, set dynamically by rule
Restricted management administrative units can protect their members from modification by admins outside the AU
Mail contacts are directory entries for external people (for example, a vendor) so they appear in the address book without having a mailbox in your tenant.
What you need to know
Mail contacts have an external email address and show up in the global address list, but they have no mailbox and cannot sign in
You create and manage them in the Exchange admin center under Recipients, then Contacts, or in the Microsoft 365 admin center
Mail users are similar but have a sign-in identity in your directory, while mail contacts do not
Contacts can be added to distribution groups so external partners receive group mail
Perform bulk management, including Microsoft Graph PowerShell
Studied
At scale you do not click through users one by one. Bulk operations and Microsoft Graph PowerShell let you create, update, and license identities in one pass.
What you need to know
The admin centers support bulk operations such as bulk create, invite, delete, and license users from a CSV file
Microsoft Graph PowerShell is the current, supported module for scripting Microsoft 365 identity and service tasks; the older MSOnline and AzureAD modules are deprecated
You connect with Connect-MgGraph and consent to scopes, then use cmdlets such as New-MgUser and Get-MgUser
Bulk changes benefit from testing against a few objects first and from running with least-privilege scopes
Implement and manage authentication and access in Microsoft Entra
21
Configure and manage authentication methods
Studied
Authentication methods are the ways users prove who they are, from passwords to phishing-resistant passkeys. Modern policy lets you control which methods are available and to whom.
What you need to know
The Authentication methods policy in Microsoft Entra controls which methods (Microsoft Authenticator, FIDO2 security keys, passkeys, Windows Hello, SMS, and others) are enabled and for which groups
Microsoft Authenticator supports push approval and phishing-resistant passwordless sign-in, and passkeys and FIDO2 are the phishing-resistant options
The Authentication methods activity report shows registration and usage so you can plan a move away from weaker methods
Microsoft has moved method management out of the legacy MFA and SSPR portals into the unified Authentication methods policy
Implement and manage Microsoft Entra Password Protection
Studied
Password Protection blocks weak and easily guessed passwords by rejecting banned words and their variations, both in the cloud and, optionally, in on-premises Active Directory.
What you need to know
Microsoft maintains a global banned password list that applies automatically to every tenant
You can add a custom banned password list of terms specific to your organization (brand names, local sports teams) in the Authentication methods, then Password protection settings
Smart lockout protects against brute-force attacks by locking sign-ins after repeated failures while distinguishing the real user from an attacker
Deploying Password Protection to on-premises Active Directory uses a proxy and DC agents and requires Microsoft Entra ID P1
Implement and manage Microsoft Entra Conditional Access policies, including Microsoft Entra ID Protection and multifactor authentication
Studied
Conditional Access is the policy engine at the heart of Zero Trust. It evaluates each sign-in and decides, based on conditions you set, whether to allow, block, or require extra proof.
What you need to know
Conditional Access policies follow an if-then structure:
If (assignments): which users, which apps or actions, and under which conditions (sign-in risk, device platform, location, client app)
Then (access controls): block, grant with MFA, require a compliant or hybrid-joined device, or apply session controls
Conditional Access requires Microsoft Entra ID P1, and risk-based conditions (sign-in risk, user risk) require Microsoft Entra ID P2 through ID Protection
ID Protection detects risky sign-ins and risky users and feeds that risk into Conditional Access for automatic response
Report-only mode lets you see the impact of a policy before you enforce it, and security defaults are a simpler alternative that is mutually exclusive with Conditional Access
Exam tip: Security defaults and Conditional Access cannot both be on; turn off security defaults before you enforce Conditional Access policies.
Secure Microsoft 365 workloads
26
Manage alerts in Microsoft Defender for Office 365
Studied
Defender for Office 365 protects email and collaboration from phishing, malware, and malicious links, and it raises alerts you triage in the Defender portal.
What you need to know
Alerts surface in the Microsoft Defender portal under Incidents & alerts, where related alerts are correlated into incidents
Alert policies define what triggers an alert, its severity, and who is notified, and many come preconfigured
You can filter, assign, and resolve alerts, and drill from an alert into the underlying email or activity
Defender for Office 365 comes in Plan 1 (protection) and Plan 2 (adds investigation and automation such as Automated Investigation and Response)
Configure threat policies and rules in Defender for Office 365
Studied
Threat policies decide how mail is filtered for spam, malware, phishing, and malicious links and attachments. Preset policies give you a Microsoft-recommended baseline fast.
What you need to know
Threat policies include anti-malware, anti-phishing, anti-spam, Safe Attachments, and Safe Links, configured in the Defender portal under Email & collaboration, then Policies & rules
Preset security policies (Standard and Strict) apply Microsoft's recommended settings and are easier to maintain than many custom policies
Safe Attachments detonates attachments in a sandbox; Safe Links rewrites and checks URLs at time of click
Policy precedence matters: preset policies and custom policy priority determine which policy applies when several match
Configure and manage attack simulations, including training campaigns
Studied
Attack simulation training runs safe, realistic phishing campaigns against your own users so you can measure risk and assign targeted training.
What you need to know
Attack simulation training is in the Defender portal under Email & collaboration, then Attack simulation training, and requires Defender for Office 365 Plan 2
You choose a social engineering technique (for example, credential harvest), a payload, a target audience, and a schedule
Results report who was compromised, and you can automatically assign training to those users
Simulation automations and payload automations let you run recurring campaigns without building each one by hand
Protect data in Microsoft 365 by using Microsoft Purview
30
Identify requirements for Microsoft Purview Data Loss Prevention (DLP) policies, including those for Exchange, SharePoint, OneDrive, Teams, endpoints, and Copilot
Studied
DLP stops sensitive information from leaving where it should not, by detecting content and enforcing actions across many locations, now including Copilot.
What you need to know
DLP policies apply to a set of locations, each with its own considerations:
Exchange email, SharePoint, OneDrive, and Teams chat and channel messages are the classic locations
Endpoint DLP covers actions on Windows and macOS devices, such as copy to USB or upload to a browser
The Microsoft 365 Copilot location lets a DLP policy keep labeled content from being summarized or used by Copilot
A policy detects content by sensitive information types, trainable classifiers, or sensitivity labels, then applies actions such as block, block with override, or notify
Exam tip: To stop Copilot from using content that carries a given sensitivity label, use a DLP policy scoped to the Microsoft 365 Copilot location.
31
Identify requirements for information protection, including sensitive information types, sensitivity labels, and sensitivity label policies
Studied
Information protection classifies and protects content itself, so a labeled file stays protected wherever it travels. Sensitivity labels are the core tool.
What you need to know
Sensitive information types (SITs) detect patterns such as credit card or national ID numbers and are the building blocks of classification
Sensitivity labels can mark content (headers, footers, watermarks) and enforce protection (encryption, access rights) that travels with the file
Label policies publish labels to users and groups and can set a default label and require justification for downgrades
Auto-labeling can apply labels automatically based on content, in the service or on the client
Identify requirements for data lifecycle management, including retention labels, retention label policies, and retention policies
Studied
Data lifecycle management keeps what you must and deletes what you should not keep, using retention policies and retention labels. The difference between the two is a favorite exam point.
What you need to know
Retention comes in two shapes that work together:
Tool
Scope
How it is applied
Retention policy
A whole location (all of Exchange, all SharePoint, and so on)
Automatically, tenant or location wide
Retention label
An individual item or folder
By users, by default, or automatically by rule
Both can retain, retain then delete, or just delete after a set period based on when content was created, last modified, or labeled
Retention labels can also mark content as a record, which restricts edits and deletion
The principles of retention decide the outcome when multiple settings apply (retention wins over deletion, longest retention wins)
Monitor and secure AI activity by using Microsoft Purview Data Security Posture Management (DSPM)
Studied
DSPM for AI gives you one place to see how much sensitive data your AI apps touch and what to do about it, covering Microsoft 365 Copilot, other Copilots, and third-party AI.
What you need to know
DSPM for AI lives in the Microsoft Purview portal and gives reports on AI interactions, sensitive data referenced in prompts and responses, and risky AI usage
It offers one-click policies to help discover and protect AI data, such as detecting sensitive info in prompts and applying DLP or labels
It covers Microsoft 365 Copilot, Copilot Studio agents, Microsoft Foundry apps, and third-party AI apps
Activity explorer and audit surface the underlying AI interaction events for investigation
Domain 3Manage and Secure AI Services in Microsoft 36535-40% of the exam0 / 24 studied
This domain is what sets AB-650 apart from earlier Microsoft 365 admin exams. It covers enabling and governing Microsoft 365 Copilot, managing agents through Microsoft 365 and Microsoft Agent 365, securing agents with Microsoft Entra Agent ID and Purview, and monitoring the cost, adoption, and health of AI services. Because these features are new and moving quickly, expect the exact portal locations and names to keep evolving through the beta.
Enable and manage Microsoft 365 Copilot
35
Assess tenant readiness for Copilot, including in-app experiences
Studied
Before you assign Copilot licenses, you check that the tenant and its apps are ready, from update channels to how much people already use the apps Copilot plugs into.
What you need to know
The Copilot readiness report in the Microsoft 365 admin center (Reports, then Usage, then Microsoft Copilot) shows license eligibility, app readiness, and technical requirements
Copilot works best when users are on current Microsoft 365 Apps and signed in with a work account, and the report flags gaps
In-app Copilot experiences (Word, Excel, PowerPoint, Outlook, Teams) depend on those apps being deployed and up to date
Readiness data can take up to 72 hours to appear and to refresh
Identify and resolve data readiness issues for Copilot, including data leaks, data oversharing, and data compliance
Studied
Copilot inherits each user's existing permissions, so it will happily surface anything they can already reach. Data readiness is about closing oversharing before Copilot exposes it.
What you need to know
Oversharing is the top data readiness risk: content shared too broadly (org-wide links, open sites) becomes reachable by Copilot for anyone who can see it
SharePoint Advanced Management reports (data access governance) and Restricted Content Discovery help find and contain overshared sites
Purview sensitivity labels and DLP for the Copilot location protect content that must not be summarized or reused
The secure and governed data foundation guidance lays out a remediate-then-guardrail approach before broad rollout
Exam tip: Copilot never bypasses permissions; if it returns something it should not, the fix is the underlying sharing, not Copilot itself.
37
Manage web search for Copilot and Microsoft 365 Copilot Chat
Studied
Web search lets Copilot ground answers on public web content, which improves quality but sends the query to the web. Admins decide whether to allow it.
What you need to know
The Allow web search in Copilot policy controls web grounding for both Microsoft 365 Copilot and Microsoft 365 Copilot Chat
The setting is reached from the Copilot page in the Microsoft 365 admin center, which links you to create a cloud policy in the Microsoft 365 Apps admin center
When web search is off, Copilot grounds only on tenant data and its model, not on live web content
The policy can target specific groups through the cloud policy service
Copilot Search is the AI-powered search experience in the Copilot app. It works out of the box for licensed users, and you shape its results with the same tools you use for Microsoft Search.
What you need to know
No setup is required: users with an eligible Copilot license get Copilot Search in the Search module of the Copilot app, while unlicensed users get Microsoft Search
You customize it in the admin center under Copilot, then Search, by managing connectors, bookmarks, and acronyms, and by tuning results and filters
Bookmarks and acronyms you already curated for Microsoft Search carry over automatically
Acronyms can be Published, Draft, or Excluded to control whether they appear in results
Configure Copilot settings for a tenant, including self-service purchases, Copilot in admin centers, release preferences, AI disclaimer, and video and image generation
Studied
The Copilot page in the admin center is where you turn tenant-wide Copilot behaviors on or off, from who can buy licenses to whether users can generate images.
What you need to know
Self-service purchases (Copilot, then Settings, then User access) can be set to Allow, Allow trials only, or Do not allow so users cannot buy Copilot on their own
Copilot in admin centers controls whether admins get Copilot help inside the Microsoft 365, Exchange, SharePoint, and Teams admin centers
Image generation in Copilot Chat and other in-app AI actions are toggled through Copilot controls
Release preferences and AI disclaimers are configured in org settings and the Copilot settings, so users see the right experience and any required notice
Beyond the tenant switches, you shape how the Copilot app itself looks and behaves for users, such as whether Copilot Chat is pinned and which agents appear.
What you need to know
The Copilot app settings (managed with the Office Apps admin role through cloud policy) control pinning Copilot Chat, the Search module, and agent availability
Pinning policies decide whether Copilot Chat appears in the Microsoft 365 app and other surfaces, based on license
You can allow or block agents from showing in the Copilot app through Integrated apps
User enablement (prompt gallery, training) drives whether the experience is actually adopted
Copilot Cowork lets users delegate complex, multi-step work that Copilot carries out across Microsoft 365 apps, checking in for review. It is consumption-based, so admins manage its billing.
What you need to know
Cowork takes an outcome you describe, then gathers information, coordinates tasks across apps, and produces deliverables while keeping you in control through review and approval
For work or school accounts Cowork is generally available; the personal-account preview runs through the Microsoft Copilot Frontier program
Because Cowork is metered, you configure billing policies and spending controls (Copilot credits and usage-based billing) rather than assigning a seat
You monitor consumption so costs stay within your spending policies
Copilot connectors (formerly Microsoft Graph connectors) bring content from outside Microsoft 365, such as a wiki or a ticketing system, into the search index so Copilot can ground on it.
What you need to know
Copilot connectors index external content into the Microsoft 365 semantic and search index so Copilot and Copilot Search can use it as grounding data
There are over 100 prebuilt connectors in the gallery from Microsoft and independent vendors, plus a custom connector option through the API
Connectors are managed in the Microsoft 365 admin center (Search & intelligence, then Data sources) and you control which content and which users see it
Indexed items count toward connector quotas and respect the access permissions you configure
Implement and manage agents in Microsoft 365 and Agent 365
44
Manage the lifecycle workflows for agent identities by using Microsoft Entra Agent ID
Studied
Agents are non-human actors that need identities of their own. Microsoft Entra Agent ID gives each agent a first-class identity you can govern like a user.
What you need to know
Microsoft Entra Agent ID gives agents their own identities in Microsoft Entra, separate from the users they work for, so their actions are attributable
Identity governance for agents provides sponsors and owners, access packages, and lifecycle workflows so access is intentional, auditable, and time-bound
Lifecycle workflows help ensure agents do not accumulate stale permissions and are retired when no longer needed
Microsoft Entra Agent ID is in preview and extends existing Entra governance to agents
Secure agent access, including access packages and conditional access
Studied
The same access controls you use for people apply to agents: Conditional Access to gate sign-in, and entitlement management access packages to grant time-bound resource access.
What you need to know
Conditional Access for agents evaluates agent identity and risk before granting access, with Microsoft-managed policies providing a secure baseline that blocks high-risk agents
Access packages (entitlement management) grant an agent access to specific resources for a limited time, with review, so access is intentional and expires
Custom security attributes let you apply Conditional Access to many agents at scale while still allowing fine-grained control
Governing agent access this way requires Microsoft Agent 365 with the appropriate Entra licensing
Every agent needs a responsible human. Ownership makes someone accountable for an agent's lifecycle, compliance, and cleanup, and ownerless agents are a governance gap.
What you need to know
Each agent should have a designated owner (and often a sponsor) responsible for its lifecycle and compliance
The agent overview in the Microsoft 365 admin center surfaces agents without owners so you can assign one
Assigning ownership is a governance action that requires the AI Administrator or Global Administrator role
Ownerless or orphaned agents are flagged because they create risk and cost with no one accountable
Configure agent settings, including allowed agent types, sharing, templates, and user access
Studied
Agent settings decide who can use and build agents, which agent types are allowed, and how they can be shared, so experimentation stays within guardrails.
What you need to know
Agent settings are configured under Copilot, then Settings, then Data access, then Agents, and through Integrated apps in the Microsoft 365 admin center
You control who can access agents and which agent types users can install or create
Sharing controls determine whether users can share agents they build, and templates provide approved starting points
Built-in agents are on by default, and you can allow or block specific agents from appearing in the Copilot app
Discover and manage Microsoft and third-party agents in the agent registry
Studied
The agent registry is the single inventory of every agent in your tenant, whether built on Microsoft platforms or acquired elsewhere. It is where governance starts.
What you need to know
The agent registry in the Microsoft 365 admin center is a centralized inventory giving a unified view of agent adoption, activity, and health
It includes agents from Microsoft platforms (Copilot Studio, SharePoint, Agent Builder, AI Foundry) and detected non-Microsoft agents
From the registry you can filter agents by risk, owner, or status and take action
The registry is part of the observe pillar of Microsoft Agent 365
Agents act through tools, such as connectors to Outlook, Teams, or SharePoint. Managing those tools controls what an agent can actually do.
What you need to know
Tools are the capabilities an agent uses to take action, including Model Context Protocol (MCP) connected services such as Outlook, Teams, SharePoint, and OneDrive
Agent 365 lets you manage which tools an agent can use as part of least-privilege access
Restricting tools limits an agent to only the resources it needs to do its job
Tool usage is captured in agent activity for audit and investigation
Observability is the first pillar of Agent 365. It gives you real-time visibility into what agents are doing so you can spot risk before it becomes a problem.
What you need to know
Agent 365 gives real-time visibility into agent usage, performance, and risk signals through the registry and the agent overview
Agent activity, including prompts, tool usage, and outcomes, is captured and correlated across Microsoft Entra, Microsoft Defender, and Microsoft Purview
The agent overview shows a rolling snapshot of activity, usage trends, and governance gaps
Role-specific views give IT, security, and business stakeholders the insights they each need
Manage and monitor costs for AI services in Microsoft 365
Studied
Several AI services bill by consumption rather than per seat, so cost management means watching credits and metered usage, not just counting licenses.
What you need to know
Consumption-based AI services (Copilot Cowork, Copilot Studio pay-as-you-go, agent usage) draw on Copilot credits and usage-based billing tied to an Azure subscription
You set billing policies and spending controls in the Microsoft admin center to cap or segment consumption
Monitoring usage-based billing shows where credits are going so you can forecast and control spend
Per-user Copilot licenses are a separate, predictable cost you track under Billing
Monitor usage and adoption for AI services in Microsoft 365 by using the Copilot Control System
Studied
The Copilot Control System is Microsoft's framework for managing, measuring, and securing Copilot. For adoption you use its measurement tools, chiefly the reports and the Copilot dashboard.
What you need to know
The Copilot Control System brings together management controls, measurement (usage and readiness reports, the Copilot dashboard in Viva Insights), and security and governance for Copilot
The Copilot dashboard classifies users by engagement (for example, power, habitual, and novice users) over a rolling window so you can see real adoption
Admin center reports and the dashboard together answer both who is licensed and who is actually getting value
These measurement tools help you decide where to focus enablement and license assignment
Monitor service health by using the Copilot Control System
Studied
When Copilot itself has a problem, service health tells you whether it is Microsoft's incident or your configuration, the same way it does for other Microsoft 365 services.
What you need to know
Service health in the Microsoft 365 admin center reports incidents and advisories for Copilot and its underlying services
It is the authoritative place to confirm whether a Copilot problem is a known service issue
You can configure notifications so admins hear about Copilot-related incidents as they are posted
Health signals sit alongside the Copilot Control System's management and measurement views for a full operational picture
Microsoft Defender portal > Email & collaboration > Attack simulation training
Create a DLP policy
Microsoft Purview portal > Data Loss Prevention > Policies
Publish sensitivity labels
Microsoft Purview portal > Information Protection
Configure retention
Microsoft Purview portal > Data Lifecycle Management
Monitor AI activity
Microsoft Purview portal > DSPM for AI
Configure Copilot settings
Microsoft 365 admin center > Copilot > Settings
Configure Copilot Search
Microsoft 365 admin center > Copilot > Search
Manage agents and requests
Microsoft 365 admin center > Copilot > Agents, then the agent registry
Govern agent identities
Microsoft Entra admin center > Agent ID and ID Governance
Track Copilot adoption
Microsoft 365 admin center > Reports > Usage > Microsoft Copilot
Additional tips
The best thing you can do after reading this guide is to start a free Microsoft 365 trial and play with the features. Follow the tutorials in the Learn paths inside your own tenant and the exam questions will feel familiar.
A Microsoft 365 E5 developer sandbox with sample users and data, so you can try every admin task in this guide without touching production. The sandbox is free, though setup now requires a billing account for verification.
Yes. AB-650 is currently a beta exam, and Microsoft expects it to reach general availability around October 2026. While it is in beta the skills measured can still change, so check the official AB-650 study guide before you book. Beta exams also are not scored right away, because Microsoft first gathers data on the questions, so expect your result to arrive after the beta period closes.
How long should I study for the AB-650?
AB-650 is an associate-level exam that assumes real experience with Microsoft 365, Microsoft Entra ID, Defender XDR, and Microsoft Graph PowerShell, so plan around 6 to 8 weeks of focused study if you already administer Microsoft 365. If you are newer to the platform, or new to the Copilot and agent administration topics, give yourself more time and start with the free Microsoft Learn paths in this guide. The AI services domain is the newest material for most admins, so budget extra time there.
Do I need hands-on experience to pass the AB-650?
Yes, hands-on experience helps a lot, because this exam is written for practicing administrators rather than beginners. You should be comfortable in the Microsoft 365 admin center, the Microsoft Entra admin center, the Microsoft Defender portal, and the Microsoft Purview portal, and increasingly in the Copilot and agent management experiences. If you do not have a production tenant to practice in, set up a free Microsoft 365 developer sandbox and work through the tasks in this guide there.
How does the AB-650 relate to the retiring MS-102 exam?
Microsoft is retiring MS-102: Microsoft 365 Administrator on November 30, 2026, and AB-650 is the new associate certification for administering Microsoft 365 together with its AI services. If you were planning to take MS-102, AB-650 is the path to look at going forward, since it carries the modern tenant, identity, security, and Purview content plus the new Copilot and agent administration skills. Microsoft has not published a formal one-to-one replacement mapping between the two, so treat AB-650 as the current direction rather than a direct swap.
What experience does Microsoft recommend before taking the AB-650?
Microsoft's audience profile expects you to configure, manage, secure, and govern Microsoft 365 tenants, workloads, and AI services, including Microsoft 365 Copilot and agents. You should have experience with Microsoft 365 workloads and Microsoft Entra ID, an understanding of Microsoft Defender XDR capabilities, and familiarity with Microsoft Graph PowerShell. In practice this is a role for someone who already administers Microsoft 365 day to day and is now taking on the AI services that run on top of it.
Maintained by Vlad Catrinescu, reviewed September 2026 · All study guides
Subscribe to the Vlad Talks Tech Newsletter
Don't miss out on the latest Microsoft and certification news, conference and
certification discounts, tutorials featuring some of your favorite
Microsoft MVPs, and much more!
Not sure yet? Subscribe and find out why THOUSANDS around the globe subscribe.