Microsoft AB-900: A Hands-On Study Plan

AB-900 is a fundamentals exam, but “fundamentals” does not mean that the best preparation is a glossary. The credential sits at the intersection of Microsoft 365 administration, identity, data protection, Copilot, and agents. Those topics make more sense when you can see how a tenant is organized and how an administrator changes access, policy, or configuration.

The current AB-900 exam covers core Microsoft 365 services and objects, data protection and governance for Microsoft 365 and Copilot, and basic administrative tasks for Copilot and agents. Microsoft has also announced an English-language skills update for October 14, 2026, so candidates preparing around that date should compare their scheduled exam with the current study guide rather than relying on an older course outline.

A useful plan is therefore hands-on but restrained. You do not need to become an MS-102-level administrator. You do need enough tenant experience to understand what users, groups, sites, teams, permissions, policies, and agent controls mean when they appear in a scenario.

Week one: map the Microsoft 365 tenant as a set of connected objects

Begin with users, groups, teams, SharePoint sites, mailboxes, licenses, roles, and the administrative portals that manage them. Create a simple diagram showing which objects represent identities, collaboration spaces, content locations, and administrative authority. The purpose is to remove the “everything is Microsoft 365” blur.

Then use a sandbox, training tenant, or guided lab to locate the corresponding objects in the Microsoft 365 admin center. Observe which changes are tenant-wide and which are scoped to a user, group, or service. If you cannot access a tenant, use Microsoft’s interactive material and documentation to rehearse the same navigation conceptually.

The internal guide to the Microsoft 365 admin center is a good companion because it reinforces the idea that administration begins with understanding where service and identity responsibilities meet.

Week two: make identity and access concrete

AB-900 candidates should be able to recognize authentication, single sign-on, multifactor authentication, Conditional Access, and the role of Microsoft Entra ID. Instead of memorizing definitions, build short scenarios: a new employee needs access, a contractor should have limited rights, a risky sign-in requires stronger authentication, or an admin role must be delegated without giving broader privileges.

For each scenario, identify the identity, the resource, the condition, and the control. That prevents a common error: choosing a security feature because it sounds strong rather than because it addresses the actual access requirement.

A deeper explanation of Microsoft Entra ID can help connect tenant identities to the broader concepts of authentication, authorization, roles, and policy that AB-900 expects candidates to recognize.

Week three: learn why data location matters to Copilot governance

Copilot can surface information from Microsoft 365, which means permissions and data governance become part of AI administration. If a user can access a document, AI-assisted experiences may be able to use that accessible information in ways that make oversharing more visible. The administrator therefore needs to understand the existing permission model before thinking about Copilot as a separate layer.

Take a simple set of documents and classify which users should have access. Then ask what would happen if permissions are too broad, a site contains stale sensitive content, or a group membership grants more reach than intended. The lesson is that AI governance starts with ordinary information governance.

Microsoft Purview concepts are important here because retention, sensitivity, information protection, and compliance controls can affect how data should be handled. The SC-400 information-protection perspective goes beyond AB-900, but it shows the practical purpose behind the governance vocabulary.

Week four: practice Copilot administration as a lifecycle

Do not study Copilot administration as one toggle. Think about readiness, licensing, user enablement, permissions, policy, adoption, monitoring, and support. An organization may technically enable a feature but still be unprepared if data access is uncontrolled or administrators cannot explain who is entitled to use it.

Create a fictional rollout for three groups: a pilot team, a broader user population, and an excluded group. Decide how you would assign access, what prerequisites you would check, what user guidance is needed, and what signs would tell you the rollout is working or creating risk.

The Microsoft 365 Copilot and Agent Administration Fundamentals path is the best internal anchor for this stage because it keeps the lab focused on the administrator role rather than on end-user prompting techniques.

Week five: understand agents as managed objects, not just AI conversations

Agents introduce another layer of scope, data access, actions, and governance. For AB-900, the important question is not how to build a sophisticated autonomous system. It is how an administrator recognizes the objects, permissions, lifecycle, and control points involved when agents are introduced into Microsoft 365.

Use a simple scenario: an agent helps employees answer questions from approved business content. Identify where the content lives, who can access it, who can use the agent, what the agent is allowed to do, and what should happen if the source data contains sensitive material. This creates a governance map that is much easier to remember than a list of features.

The broader discussion of agentic systems can provide context, but keep AB-900 preparation at the fundamentals level: administration, permissions, data, and responsible enablement.

Week six: connect Teams and SharePoint to the information boundary

Microsoft 365 collaboration services are not separate from Copilot administration because they contain the content people create and share. A Team can be connected to groups, SharePoint sites, files, conversations, and membership. If you understand that relationship, scenarios about information exposure become much easier to reason through.

Practice tracing a document from storage to access. Who owns the site? Which group grants membership? Can a guest reach it? What happens when a user leaves? If a user asks Copilot about the document, should that user already have permission to see the source?

This is also a good place to remember that basic Microsoft 365 administration still matters. The MS-102 administrator perspective is more advanced, but it illustrates why identity, collaboration, security, and governance must be managed as one environment.

Use policy scenarios to practice “least necessary access”

Fundamentals exams often present broad controls and ask for the most appropriate one. Create scenarios where access is required only for a department, where an administrator needs a limited role, where sensitive content must be labeled, or where a user needs stronger authentication only under certain conditions.

For each, select the narrowest control that meets the requirement. This builds an instinct for least privilege and scoped administration. It also prevents overreaction: disabling a service for the whole tenant is rarely the best answer when the requirement only affects one group or one type of data.

The Entra identity and access model is especially useful for understanding why identity policy should be targeted rather than treated as a single tenant-wide switch.

Practice licensing and role assignment as governance decisions

Fundamentals questions can include licensing or administrative-role context because access to a feature is not the same as authority to manage it. In your fictional tenant, decide which users need a Copilot entitlement, which administrators need a role, and which tasks should remain outside a help-desk or service-owner boundary. This turns abstract “who can do what” questions into a simple responsibility map.

Use the Microsoft certifications to keep role depth in context. AB-900 validates foundational administration awareness; it does not expect the same breadth as a Microsoft 365 Administrator Expert. Knowing that boundary helps you study the controls you must recognize without drifting into every advanced service configuration.

Prepare explicitly for the October 14, 2026 skills update

Microsoft’s study guide states that the English-language exam skills are updated on October 14, 2026. The change log characterizes some areas as minor changes rather than a completely new exam, but candidates near the date should still check the version that applies to their scheduled sitting.

Do not solve this by studying two separate exams. Compare the before-and-after objectives, highlight the changed bullets, and add a short review session for those deltas. The foundational tenant model—users, groups, services, security, governance, Copilot, and agent administration—remains the organizing structure.

The broader Microsoft 365 certifications can also help position AB-900 correctly: it is an administration fundamentals credential, not a replacement for role-based expert administration.

Finish with one end-to-end administration story

For final review, invent a small organization adopting Microsoft 365 Copilot. Create users and groups, define collaboration spaces, identify sensitive content, assign administrative roles, plan a pilot, decide how identity controls apply, and explain how an agent would access approved information. Then add one problem, such as an over-permissioned site or an external user who should no longer have access.

Walk through the response as an administrator. Which object do you inspect first? Which portal or service owns the control? Is the issue identity, permission, information governance, or Copilot configuration? What is the narrowest corrective action?

AB-900 becomes much easier when Microsoft 365 stops looking like a collection of product names and starts looking like a governed tenant. Hands-on practice gives you that mental model, which is exactly what scenario questions need.

img