Sample questions

AB-650 practice questions, with full explanations

75 sample AB-650 (Administering Microsoft 365 and AI Services) questions, each with the correct answer, a breakdown of why every other option is wrong, a memory hook, and the Microsoft Learn reference. Work the questions by topic; each topic names the book behind it.

Exam AB-650 is in beta.

Work the 75 questions, one topic at a time

Each topic opens to its questions with the full explanation, the memory hook and the Microsoft Learn page behind it.

Cover of Microsoft 365 Tenant Administration Field Guide
Topic 1 of 7

Microsoft 365 Tenant Administration (11 questions)

Go deeper in Microsoft 365 Tenant Administration Field Guide. Get it on Amazon · Companion page

Show the 11 questions and explanations

An Exchange Online incident has affected Tailspin Toys users for three hours. In Service health, the incident's status just changed from Restoring service to Extended recovery. The CIO wants to tell all staff that email is fully fixed and close the internal incident ticket. What should the administrator advise?

Correct answer: C. Hold the announcement, because Extended recovery means corrective action hasn't yet reached every affected system

Learn's service health status definitions say Extended recovery means corrective action is in progress to restore service to most users but will take some time to reach all affected systems, or that a temporary fix is reducing impact while Microsoft waits to apply a permanent fix. The all-clear is Service restored, when Microsoft confirms corrective action has resolved the underlying problem, so the internal ticket should stay open until then.

Why the other options are wrong:

  • A. Send the announcement, because Extended recovery is the status Microsoft posts once it confirms the service is back to a healthy state Extended recovery sounds like the final step, but the healthy-state confirmation is Service restored, which follows once corrective action has resolved the underlying problem.
  • B. Send the announcement, because Extended recovery means Microsoft found no service impact and traced the cause outside the service Some incidents do end with no service impact, but that outcome is False positive, where Microsoft confirms the service is healthy or the cause originated outside the service.
  • D. Hold the announcement and collect logs, because Extended recovery means Microsoft needs data from the organization to continue Both statuses mean work is still open, but a request for customer data is Investigation suspended, not Extended recovery.

Memory hook: Extended recovery means most users, not all; wait for Service restored.

Microsoft Learn: View service health

Fabrikam is retiring fabrikam.net. Every user, shared and resource mailbox, contact, group and distribution list now uses fabrikam.com except the administrator's own account, which signs in as admin@fabrikam.net, and fabrikam.net is still the default domain. A second Global Administrator signs in on fabrikam.com. Which sequence lets the domain removal succeed?

Correct answer: C. Set fabrikam.com as the default domain, change your own username to fabrikam.com and sign in again with it, then remove fabrikam.net

Learn's Remove a domain page lists the prerequisites: the domain isn't the default domain; no users, shared or resource mailboxes, contacts, groups, distribution lists or teams use it; and no admin account signs in with it. Two blockers remain here, the default flag and the administrator's own username. Learn has you change your own username, then sign out and back in on the new domain, which is safe because another Global Administrator exists on a different domain. Domain changes take the Domain Name Administrator role.

Why the other options are wrong:

  • A. Remove fabrikam.net right away, because a default domain can be removed once no mailboxes or groups still use it Clearing mailboxes and groups feels like the whole job, but Learn's first prerequisite is that the domain isn't the default domain, and the administrator's own sign-in still uses it.
  • B. Delete the MX, SPF and verification records for fabrikam.net at the DNS host, then wait for the domain to drop off the Domains page Removing DNS records seems like cutting the domain loose, but a domain leaves the tenant only when an administrator removes it after every reference is gone. Deleting its records at the DNS host doesn't take it off the Domains page.
  • D. Make a new onmicrosoft.com domain the fallback domain, then remove fabrikam.net while still signed in as admin@fabrikam.net The fallback domain sounds related, but changing which onmicrosoft.com domain is the fallback clears neither the default-domain flag on fabrikam.net nor the admin account that signs in with it.

Memory hook: Before removing a domain: move the default flag, move every name including your own, then remove it.

Microsoft Learn: Remove a domain

An administrator at Fabrikam runs Get-MgUser -Filter "endsWith(userPrincipalName,'@fabrikam.com')" -All to list the users in one domain. Microsoft Graph returns a Request_UnsupportedQuery error saying the endsWith operator isn't supported because required parameters might be missing. What should the administrator change?

Correct answer: D. Add -ConsistencyLevel eventual and -CountVariable to the Get-MgUser command

A filter using endsWith on userPrincipalName is an advanced query. The Learn article on advanced query capabilities for directory objects says such requests need the ConsistencyLevel header set to eventual and the $count query parameter; without either, the request returns an error. In Graph PowerShell that pair is -ConsistencyLevel eventual with -CountVariable, and the error text itself suggests adding exactly those two.

Why the other options are wrong:

  • A. Reconnect with Connect-MgGraph -Scopes 'Directory.Read.All' before rerunning it A missing permission produces an authorization error; this error is about query support, and a broader scope doesn't add the advanced query parameters.
  • B. Run the same filter with Get-MgBetaUser so the beta endpoint evaluates it The beta endpoint has the same requirement; the Learn article's own example of this error comes from a beta request.
  • C. Replace -All with -Top 999 so the query returns a single page of results Paging options such as -Top and -All don't change which filter operators Graph accepts, so the same error returns.

Memory hook: ne, not, endsWith, or $count in a filter: add -ConsistencyLevel eventual and -CountVariable.

Microsoft Learn: Aad advanced queries

Woodgrove Bank synchronizes 3,000 employees from on-premises Active Directory with password hash synchronization and also has 60 cloud-only contractor accounts. Auditors require contractor passwords to expire every 90 days. A User Administrator sets the password expiration policy to 90 days under Settings, then Org settings, then Security and privacy. What is the result?

Correct answer: C. Only the 60 cloud-only contractor accounts expire every 90 days; the synced employees aren't covered by this policy

Learn's Set the password expiration policy page scopes the setting to cloud-only users and says it doesn't apply to hybrid identities that use password hash sync, pass-through authentication or on-premises federation such as AD FS. Passwords never expire by default; a User Administrator can set 14 to 730 days, and the admin center and Microsoft 365 apps no longer send expiration notifications.

Why the other options are wrong:

  • A. Only accounts created after the policy is saved expire every 90 days, so the existing contractor accounts must be recreated Some settings apply only to new objects, but this policy is set per managed domain and covers the existing cloud-only users on it.
  • B. The contractor accounts expire every 90 days, and each contractor receives an expiration notice from the admin center beforehand A warning before expiry sounds natural, but Learn states the admin center and Microsoft 365 productivity apps no longer support password expiration notifications.
  • D. All 3,060 accounts expire every 90 days, because password hash synchronization applies the cloud policy to synced users as well Hash sync does copy password hashes to the cloud, which makes this plausible, but Learn excludes password hash sync, pass-through and federated users from this policy, so the 3,000 synced employees aren't affected.

Memory hook: The admin center expiration policy covers cloud-only accounts; hybrid identities are outside its scope.

Microsoft Learn: Set password expiration policy

Litware's privacy office approved showing real names in usage reports. A compliance analyst with the Reports Reader role still sees hashed user and site names in the Microsoft 365 admin center usage reports, the Teams admin center usage reports and the Microsoft 365 usage analytics app in Power BI. What single change shows the names on all three, and who can make it?

Correct answer: B. A Global Administrator clears Conceal user, group, and site names in all reports under Org settings, then Services, then Reports

Learn's Microsoft 365 admin center usage reports overview says reports hide user, group and site details by default and that Global Administrators can change this on the Reports page under the Services tab of Org settings. The same setting applies to the usage reports in Microsoft Graph, Power BI and the Teams admin center, so one change covers all three surfaces, and showing identifiable information is logged in the Microsoft Purview audit log.

Why the other options are wrong:

  • A. The analyst, as a Reports Reader, clears Conceal user, group, and site names in all reports under Org settings, then Services, then Reports The analyst can already open the reports, which makes self-service tempting, but Reports Reader can't change the concealment setting, which Learn reserves for Global Administrators.
  • C. A Teams Administrator turns off name concealment in the Teams admin center, and the other two reports then follow that setting The Teams admin center shows the same hashed names, so it looks like a place to fix them, but its usage reports follow the Reports setting in the Microsoft 365 admin center rather than holding a switch the others inherit.
  • D. A Privileged Role Administrator gives the analyst the Global Reader role, which shows real names whatever the concealment setting A broader read role seems like it should reveal more, but concealment is a tenant-wide setting rather than a permission, so a Global Reader sees the same hashed names.

Memory hook: Hashed names in every report: one Org settings checkbox, and only a Global Administrator can clear it.

Microsoft Learn: Activity reports

At Fabrikam, a service desk lead must assign and remove product licenses for individual users, set the usage location on accounts that have none, and reprocess failed group license assignments. The lead must not create users, change group membership, or buy subscriptions. Which Microsoft Entra role should the lead receive to follow least privilege?

Correct answer: B. License Administrator

The Microsoft Entra built-in roles reference describes License Administrator as able to read, add, remove, and update license assignments on users and groups, reprocess license assignments, and update users' usage location. It can't purchase or manage subscriptions, create or manage groups, or manage users beyond usage location. That covers every task the lead needs and nothing the stem forbids, which is what least privilege asks for.

Why the other options are wrong:

  • A. User Administrator User Administrator can assign licenses, but it also creates and deletes users and manages groups, which the stem rules out. It's the broader fallback, not the least-privileged fit.
  • C. Billing Administrator Billing Administrator makes purchases and manages subscriptions, which the stem forbids, and it holds no permission to assign licenses.
  • D. Groups Administrator Groups Administrator can assign and reprocess licenses on groups, but it can't license individual users directly or change usage location, and it manages the group membership the lead must not touch.

Memory hook: Assigns seats and sets usage location but buys nothing: License Administrator.

Microsoft Learn: Permissions reference

Contoso pays for Microsoft 365 Backup through a pay-as-you-go billing policy under Billing, then Pay-as-you-go, in the Microsoft 365 admin center. Finance wants an email to its mail-enabled finance group when monthly spending reaches 80 percent of $3,000, and wants backup charges to stop automatically once spending hits $3,000. What should the administrator configure and tell Finance?

Correct answer: A. Set a $3,000 monthly budget with an 80 percent alert, and explain that charges stop only if Backup is disconnected from the policy.

The pay-as-you-go setup page for the Billing node lets a billing policy carry a budget that resets monthly, quarterly, or yearly, alerts at 100 percent by default, and accepts up to four more thresholds from 1 to 99 percent, sent to email-enabled groups. The same page is explicit that reaching 100 percent doesn't stop the service or billing. Only disconnecting stops charges, so Finance can have the 80 percent email but not an automatic cutoff.

Why the other options are wrong:

  • B. Set a $3,000 monthly budget on the policy, which disconnects Backup at 100 percent and pauses billing until the budget resets. Reaching 100 percent of a budget doesn't stop the service or billing. A budget never disconnects Backup or pauses charges on its own.
  • C. Set budgets on the individual protected sites and mailboxes that add up to $3,000, so no single one can push spending past the limit. Budgets exist only at the billing policy level, not for individual users, agents, or sites, so per-site budgets can't be created.
  • D. Set a $36,000 yearly budget instead, because pay-as-you-go budgets can't reset monthly or send any alert below 100 percent. Budgets can reset on the first day of each month, quarter, or year, and a policy can alert at up to four extra thresholds between 1 and 99 percent, so the yearly workaround fixes a limit that doesn't exist.

Memory hook: A pay-as-you-go budget is a smoke alarm, not a circuit breaker.

Microsoft Learn: Pay as you go setup billing node

Contoso wants Microsoft 365 Backup to protect its SharePoint sites and executive mailboxes. A SharePoint Administrator opens Settings, then Microsoft 365 Backup, in the Microsoft 365 admin center for the first time. What must be in place before any backup policy can protect content?

Correct answer: B. A pay-as-you-go billing policy linked to an Azure subscription and a resource group in that subscription.

The Set up Microsoft 365 Backup page puts pay-as-you-go billing first: a valid Azure subscription, a resource group, a region, and Owner or Contributor rights on the subscription. Only then are backup policies created under Settings, then Microsoft 365 Backup. The service bills $0.15 per GB per month of protected data with free restores rather than per user, and it keeps backups inside the Microsoft 365 data trust boundary.

Why the other options are wrong:

  • A. A Recovery Services vault in Azure Backup, created in the same Azure region as the Microsoft 365 tenant. A Recovery Services vault belongs to Azure Backup, a different product. Microsoft 365 Backup keeps backups inside the Microsoft 365 data trust boundary and needs only the billing link to Azure.
  • C. A Microsoft 365 Backup license assigned to each user whose mailbox or OneDrive account will be protected. Microsoft 365 Backup has no per-user license. It's a pay-as-you-go offering billed on the amount of protected data, with restores free.
  • D. A Microsoft Purview retention policy on the same sites and mailboxes, which Backup reads as its recovery window. Purview retention and deletion policies don't affect the backup recovery window, which each backup policy sets for itself at 3 months, 6 months, 1 year, or 2 years.

Memory hook: No billing policy, no backup: link pay-as-you-go to Azure before the first policy.

Microsoft Learn: Backup setup

An employee left Woodgrove Bank, and the administrator removed the employee's Microsoft 365 E3 license that day. The manager now wants the employee's mailbox, 12 GB with no archive or hold, kept as a shared mailbox for the team. On the user's Mail tab in the Microsoft 365 admin center, Convert to shared mailbox doesn't appear. What should the administrator do?

Correct answer: D. Reassign the license, convert the mailbox to shared, then remove the license

The Convert a user mailbox to a shared mailbox page is explicit: the user mailbox needs a license assigned before conversion, otherwise the convert option isn't shown, and a removed license must be added back first. After conversion the license can be removed, because a shared mailbox under 50 GB with no archive or hold needs none. The user account stays, since it anchors the shared mailbox.

Why the other options are wrong:

  • A. Delete the user account first, because the shared mailbox won't need it after conversion The account anchors the shared mailbox, so Learn says not to delete it; a deleted user's mailbox has to be restored and relicensed before it can be converted.
  • B. Assign an Exchange Online Plan 2 license and keep it, since converted mailboxes need one A converted mailbox doesn't have to keep its license: this one is 12 GB with no archive or hold, under the 50 GB free limit, so keeping a Plan 2 license only adds cost.
  • C. Reset the user's password and block sign-in, then convert the mailbox Blocking sign-in is good practice for a leaver, but it doesn't make the convert option appear; the missing license is what hides it.

Memory hook: License on to convert, license off after: under 50 GB a shared mailbox runs free on its old account.

Microsoft Learn: Convert user mailbox to shared mailbox

Fabrikam's IT operations manager reviews Service health every morning. It never lists the Exchange Online planned maintenance that Microsoft schedules, and she wants one place to follow planned maintenance and upcoming changes her team may need to prepare for. Where should she look?

Correct answer: B. Message center in the Microsoft 365 admin center, filtered to Exchange Online posts

Learn's How to check Microsoft 365 service health page states that planned maintenance events aren't shown in Service health and points admins to Message center to track them, including when a change happens, its effect and how to prepare. Message center, under Health in the admin center, is also where Microsoft tries to give at least 30 days' notice of changes that need admin action.

Why the other options are wrong:

  • A. The Issue history tab in Service health, filtered to Exchange Online Issue history is Service health's look back, but it lists resolved incidents and advisories from the last 7 or 30 days, and planned maintenance never appears in Service health.
  • C. Service health email notifications for Exchange Online, with advisories included Advisories cover limited-impact problems, which can sound like maintenance, but these emails cover only incidents and advisories, and planned maintenance isn't shown in Service health.
  • D. The Microsoft AI at Work Roadmap, formerly the Microsoft 365 Roadmap, filtered to Exchange Online The public roadmap does announce upcoming features, but it isn't specific to a tenant, and Learn directs planned maintenance tracking to Message center.

Memory hook: Outages live in Service health; planned maintenance and changes live in Message center.

Microsoft Learn: View service health

Tailspin Toys' accounts payable staff need the vendor address billing@fabrikam.com listed in the global address list so they can pick it in Outlook and add it to a distribution group. The vendor must not be able to sign in to any Tailspin Toys resource. Which object should an Exchange administrator create?

Correct answer: D. A mail contact in the Exchange admin center, under Recipients then Contacts

The Learn article on managing mail contacts in Exchange Online describes mail contacts as mail-enabled objects for people outside the organization, each with an external email address, created in the Exchange admin center under Recipients, then Contacts, with Add a mail contact. Contacts appear in the shared address book and can be members of distribution groups, and they carry no sign-in credentials, which fits a vendor who must not be able to sign in.

Why the other options are wrong:

  • A. A mail user in the Exchange admin center, with a user ID, domain, and password A mail user also has an external address, but it adds sign-in credentials in your organization, which the vendor must not have.
  • B. A shared mailbox that forwards all incoming mail to billing@fabrikam.com A shared mailbox is an internal mailbox with its own Tailspin Toys address, so the address book would list that address instead of the vendor's.
  • C. A B2B guest user invited from the Microsoft Entra admin center at that address A guest account exists so an outsider can sign in to shared resources, and guest objects aren't shown in the global address list by default.

Memory hook: Address book entry, no sign-in: mail contact. Address book entry plus credentials in your tenant: mail user.

Microsoft Learn: Manage mail contacts

Cover of Authentication and Conditional Access with Microsoft Entra ID
Topic 2 of 7

Authentication and Conditional Access (6 questions)

Go deeper in Authentication and Conditional Access with Microsoft Entra ID. Get it on Amazon · Companion page

Show the 6 questions and explanations

Contoso has a Conditional Access policy for all users and all resources with Block access as its grant control. Its Client apps condition is configured with only Exchange ActiveSync clients selected. The sign-in logs show IMAP4 and POP3 sign-in attempts for which this policy's result is Not applied. What should the administrator change so that the policy also covers those attempts without affecting modern authentication clients?

Correct answer: B. Select Other clients in the Client apps condition, alongside Exchange ActiveSync clients.

Legacy authentication maps to two Client apps choices: Exchange ActiveSync clients and Other clients. Other clients covers basic authentication over mail protocols such as IMAP, POP, SMTP and MAPI, plus older Office apps without modern authentication. Learn's block legacy authentication policy checks both boxes with Block access, so adding Other clients brings the IMAP4 and POP3 attempts into scope while modern clients stay unaffected.

Why the other options are wrong:

  • A. Set Configure under Client apps to No so that the policy applies to every client app type. With Configure set to No, the policy applies to all client apps, modern ones included, so Block access would stop every sign-in in the organization.
  • C. Select Mobile apps and desktop clients in the Client apps condition, alongside Exchange ActiveSync clients. Mobile apps and desktop clients is a modern authentication choice; with Block access it would cut off current Office apps and still leave IMAP and POP out of scope.
  • D. Change the grant control from Block access to Require multifactor authentication. The grant control doesn't change who is in scope; the client apps condition still leaves IMAP and POP out, so the policy still isn't applied to them.

Memory hook: Blocking legacy authentication takes both boxes: Exchange ActiveSync clients and Other clients.

Microsoft Learn: Policy block legacy authentication

Litware uses pass-through authentication and has Microsoft Entra ID P1. In AD DS, the account lockout threshold is 10 invalid attempts and the account lockout duration is 15 minutes. A password spray against cloud sign-ins is locking user accounts in AD DS. Which smart lockout values should the administrator set on the Password protection page in the Microsoft Entra admin center?

Correct answer: B. Lockout threshold of 5 and lockout duration of 1,200 seconds

The smart lockout page gives two rules for pass-through authentication: the Microsoft Entra lockout threshold must be less than the AD DS threshold, with AD DS at least two or three times higher, and the Microsoft Entra lockout duration must be longer than the AD DS lockout duration. Microsoft Entra sets duration in seconds and AD DS in minutes. A threshold of 5 against 10, and 1,200 seconds (20 minutes) against 15 minutes, lets cloud lockout stop the spray before AD DS locks the accounts.

Why the other options are wrong:

  • A. Keep the defaults, because bad password hash tracking stops repeated guesses Hash tracking isn't available with pass-through authentication, and the default threshold of 10 equals the AD DS threshold instead of sitting below it.
  • C. Lockout threshold of 5 and lockout duration of 600 seconds 600 seconds is 10 minutes, shorter than the 15-minute AD DS duration; the Microsoft Entra duration has to be the longer one.
  • D. Lockout threshold of 20 and lockout duration of 1,200 seconds A threshold of 20 sits above the AD DS threshold of 10, so AD DS locks the accounts before smart lockout acts.

Memory hook: With PTA, Entra locks sooner and longer: lower threshold, longer duration, and mind seconds versus minutes.

Microsoft Learn: Password smart lockout

A Tailspin Toys user sees error AADSTS53003 when opening a line-of-business web app. The help desk finds the failed event in the Microsoft Entra sign-in logs. Where should they look first to identify the policy that stopped the sign-in?

Correct answer: D. The Conditional Access tab of the event, which lists the policies that applied and each result

AADSTS53003 is BlockedByConditionalAccess: a Conditional Access policy didn't allow token issuance. Learn's troubleshooting steps are to find the event in the sign-in logs, narrowing by correlation ID or user if needed, and open its Conditional Access tab, which shows the specific policy or policies that interrupted the sign-in. Selecting a policy name there opens that policy's configuration for review.

Why the other options are wrong:

  • A. The audit logs filtered to the Conditional Access service, which list recent changes to policies Audit logs record who changed a policy and when; they don't evaluate an individual sign-in, so they can't name the policy that blocked this one.
  • B. The Authentication Details tab of the event, which lists each method the user tried and its result Authentication Details shows how the user authenticated, not which Conditional Access policy refused the token.
  • C. The Report-only tab of the event, which lists policies evaluated in report-only mode for this sign-in Report-only policies are evaluated but never enforced, so none of them can cause a block like AADSTS53003.

Memory hook: 53003 means blocked by Conditional Access: open the event's Conditional Access tab.

Microsoft Learn: Troubleshoot conditional access

Contoso enabled SMS in the Authentication methods policy for a single group of 40 retail staff. Office workers outside that group still receive SMS verification codes at sign-in. The legacy multifactor authentication service settings still have Text message to phone selected, and Manage migration is set to Migration in Progress. What should the administrator do so that only the retail staff can use SMS?

Correct answer: D. Set Manage migration to Migration Complete so that Microsoft Entra ID ignores the legacy method settings

Until migration is complete, Microsoft Entra ID honors every method policy at once: a user enabled for a method in any policy can register and use it, so Text message to phone in the legacy MFA settings keeps SMS open to everyone. The Manage authentication methods page describes Migration in Progress as respecting legacy settings, while Migration Complete uses only the Authentication methods policy for sign-in and SSPR and ignores the legacy settings. Completing the migration leaves the retail group's SMS targeting as the only rule.

Why the other options are wrong:

  • A. Set system-preferred authentication to Enabled so that users are offered a stronger registered method first System-preferred authentication changes which registered method is offered first, and users can still choose SMS. It doesn't remove SMS from the methods a user is allowed to use.
  • B. Add the office workers as an excluded group on the SMS method in the Authentication methods policy An exclusion changes only the Authentication methods policy. The legacy MFA setting still enables SMS for every user, and a method must be disabled in all policies before users lose it.
  • C. Set Manage migration to Pre-migration so that the Authentication methods policy takes priority over legacy settings Pre-migration still respects the legacy settings and uses the Authentication methods policy only for authentication, so the legacy SMS setting keeps applying. A tenant that started in Migration in Progress also can't move back to Pre-migration.

Memory hook: Until Migration Complete, allowed methods are the union of every policy; Migration Complete leaves only the Authentication methods policy.

Microsoft Learn: Concept authentication methods manage

For a year, Fabrikam's SSPR policy required one method, and many users registered only one method, a mobile phone number. Today an administrator changes Number of methods required to reset to 2. Tomorrow, a user who registered only that mobile phone number forgets their password and opens the SSPR portal. What happens?

Correct answer: C. The user can't reset, sees an error page, and needs an administrator to reset the password

The SSPR how-it-works page covers this exact change: a user with one registered method is unable to reset or unlock once two methods are required. SSPR checks that the user has data for at least as many enabled methods as the policy requires; if not, the user sees an error and must ask an administrator for a reset. Raising the count safely means getting users to register a second method before the change.

Why the other options are wrong:

  • A. The user registers a second method inside the reset flow and then finishes the reset The reset flow doesn't register methods. A user without enough registered methods is sent to an administrator instead.
  • B. The user resets with the mobile phone, because the change applies only to new registrations The new count applies to every reset attempt from the moment it's saved, not only to users who register later.
  • D. The user resets with the mobile phone until the reconfirmation period ends, then adds a method The reconfirmation interval only controls when users are asked to review their registered information. It doesn't delay the new method count.

Memory hook: Raise SSPR from one method to two only after users have two registered, or they land on an error page.

Microsoft Learn: Concept SSPR howitworks

Litware put a policy that requires multifactor authentication for all users into Report-only. An accountant signed in to Outlook on the web with only a password, and the Report-only tab of that sign-in event lists the policy with the result Report-only: User action required. What does this result tell the administrator?

Correct answer: A. The conditions matched, and meeting the policy needs an interactive MFA prompt, which report-only mode doesn't send.

Report-only evaluates a policy without enforcing it. User action required means every configured condition matched, but the grant control can be met only by something the user must do, such as an MFA challenge or accepting terms of use, and report-only mode doesn't prompt the user for it. The result isn't a failure: with the policy On, this accountant would be asked for MFA rather than blocked.

Why the other options are wrong:

  • B. An MFA claim already in the accountant's token met the requirement, so no prompt will appear once the policy is On. An MFA claim that already satisfies the policy produces Report-only: Success.
  • C. The accountant failed an MFA challenge that report-only mode sent, so the policy would block the sign-in once it's On. Report-only mode never sends an MFA challenge; unmet non-interactive controls, such as a block or a failed device check, show as Report-only: Failure.
  • D. The policy's conditions didn't all match, so the accountant must be added to the included users before it's turned On. Conditions that don't all match produce Report-only: Not applied, not User action required.

Memory hook: Report-only: User action required means the policy would prompt, not that it would block.

Microsoft Learn: Concept conditional access report only

Cover of Microsoft Defender XDR Field Guide
Topic 3 of 7

Microsoft Defender XDR (7 questions)

Go deeper in Microsoft Defender XDR Field Guide. Get it on Amazon · Companion page

Show the 7 questions and explanations

At Contoso, Ana is covered by the Strict preset security policy, Ben by the Standard preset security policy, and Carl only by the default anti-spam policy. No anti-spam setting has been changed from its default. A newsletter reaches all three with a bulk complaint level (BCL) of 6 and no spam, phishing, or malware verdict. Where does each copy end up?

Correct answer: D. Ana: quarantine; Ben: Junk Email folder; Carl: Inbox

A message is treated as bulk when its BCL meets or exceeds the policy's bulk email threshold. The BCL article lists thresholds of 5 for Strict, 6 for Standard, and 7 for the default policy, with Strict quarantining bulk and Standard and the default policy moving it to Junk Email. BCL 6 meets Strict's 5 and Standard's 6 but not the default 7, so Ana's copy is quarantined, Ben's goes to Junk Email, and Carl's reaches the Inbox.

Why the other options are wrong:

  • A. Ana: quarantine; Ben: Junk Email folder; Carl: Junk Email folder The default anti-spam policy's bulk threshold is 7, not 6, so a BCL 6 message isn't treated as bulk for Carl and isn't moved to Junk Email.
  • B. Ana: quarantine; Ben: Inbox; Carl: Inbox This reads the threshold as crossed only when BCL is higher than it. The bulk action applies when BCL meets or exceeds the threshold, and BCL 6 meets Standard's threshold of 6.
  • C. Ana: Junk Email folder; Ben: Junk Email folder; Carl: Inbox It's easy to assume both presets treat bulk the same way, but Standard moves bulk mail to Junk Email while Strict quarantines it.

Memory hook: Bulk thresholds 5, 6, 7 for Strict, Standard, default; at or above the line counts, and only Strict quarantines.

Microsoft Learn: Anti spam bulk complaint level bcl about

Fabrikam's quarantine policies let users request the release of their quarantined messages. The service desk team, rather than the administrators who get these emails today, must receive the notification emails that user release requests generate. What should the administrator change?

Correct answer: A. The email recipients of the User requested to release a quarantined message alert policy

User release requests trigger the default alert policy named User requested to release a quarantined message, an Informational alert that notifies administrators by default. The quarantine policies article says admins can customize that policy's email notification recipients, and default alert policies let you change the recipient list and daily notification limit even though their other settings are locked. Adding the service desk team there sends the request emails to them.

Why the other options are wrong:

  • B. The frequency setting in the global quarantine notification settings The name suggests quarantine emails, but the global settings control how often recipients hear about their own quarantined messages; they don't route release requests to any team.
  • C. An alert tuning rule for the alerts that user release requests create Alert tuning works on the same alerts, but it resolves matching alerts to cut noise; it adds no notification recipients and would bury the requests instead.
  • D. Quarantine notifications in the quarantine policy that grants the request release permission Quarantine notifications do mention release, but they go to the message recipients about their own quarantined mail, not to the people who approve release requests.

Memory hook: Release request emails come from an alert policy: change its recipients, not the quarantine policy.

Microsoft Learn: Quarantine policies

At Litware, Nora holds the Attack Payload Author role and builds tenant payloads for the awareness program. She now also has to create payload automations and schedule simulation automations, but she must not get permissions to manage threat policies or other Defender for Office 365 settings. Which role should replace Attack Payload Author for her?

Correct answer: D. Attack Simulation Administrator

The get started article describes Attack Simulation Administrator as creating and managing all aspects of attack simulation campaigns, and it lists what Attack Payload Author can't do: create or edit simulations, training campaigns, simulation automations, or payload automations. Attack simulation training permissions come from Microsoft Entra roles, and this one is scoped to attack simulations, unlike Security Administrator, which also manages threat policies.

Why the other options are wrong:

  • A. Global Reader Global Reader is the read-only version of Global Administrator, so it can't create automations or payloads.
  • B. Security Operator Security Operator can view all aspects of attack simulation campaigns but can't create or edit simulations, training campaigns, or automations.
  • C. Security Administrator Security Administrator can run Attack simulation training, but it also manages threat policies and other security settings, which breaks the requirement.

Memory hook: Payload Author only builds payloads; Attack Simulation Administrator runs the rest of Attack simulation training.

Microsoft Learn: Attack simulation training

Contoso built a simulation automation with three social engineering techniques and eight payloads, a Randomized schedule with a maximum of one simulation, Unique payloads on, and Target all selected users in every simulation run selected. After it ran, all 600 targeted users had received the same payload. What explains the result?

Correct answer: C. The automation made one run, and a run uses one payload for all its users

The simulation automations article says each run gets one social engineering technique and one payload, and every user assigned to that run receives it. Multiple payloads form a pool for different runs, not a mix inside one run, and Unique payloads only avoids reuse across runs. With a randomized maximum of one, the automation can create at most one run, so all 600 users saw the same payload.

Why the other options are wrong:

  • A. Randomize send times was off, so no delivery batches got their own payloads Delivery batches from randomized send times only stagger when messages go out; the article says they don't create runs or select payloads.
  • B. Unique payloads assigns a different payload per user only on a Fixed schedule Unique payloads avoids reusing a payload across runs on either schedule type; it never gives each recipient in one run a different payload.
  • D. Region aware delivery was off, so every user landed in one payload group Region aware delivery schedules messages by each user's time zone in Outlook on the web; it doesn't create more runs or select more payloads.

Memory hook: One run means one technique and one payload for everyone in it; variety needs more runs.

Microsoft Learn: Attack simulation training simulation automations

Contoso runs Attack simulation training. User reported messages go to Microsoft and to an Exchange Online reporting mailbox that its normal Safe Links and Safe Attachments policies cover. Employees who correctly reported a simulated phishing message with the built-in Report button were later assigned training as if they had clicked the payload. The SOC must keep receiving every report in that mailbox. What should the administrator configure?

Correct answer: A. Add the reporting mailbox as a SecOps mailbox in the advanced delivery policy

The user reported settings article says to identify the reporting mailbox as a SecOps mailbox in the advanced delivery policy, and warns that without it a user reported message might trigger a training assignment by the phishing simulation product. The Attack simulation training FAQ gives the cause: Safe Links or Safe Attachments can detonate the reported messages, and detonations result in training assignments. For SecOps mailboxes, the advanced delivery policy keeps Safe Links and Safe Attachments from detonating them.

Why the other options are wrong:

  • B. Exclude the reporting mailbox from the organization's DLP policies Excluding the reporting mailbox from DLP is the other listed prerequisite, which makes it tempting, but DLP doesn't detonate links or attachments, so it isn't what assigns the training.
  • C. Add the simulation domains on the Phishing simulation tab of the advanced delivery policy The Phishing simulation tab identifies non-Microsoft simulation vendors by domain and sending IP; it doesn't exempt the reporting mailbox, and Attack simulation training doesn't send from a static list of IP addresses.
  • D. Turn off Track user clicks in the Safe Links policy that covers the reporting mailbox Attack simulation training tracks clicks through Safe Links even when Track user clicks is off, so turning the setting off doesn't prevent the recorded clicks.

Memory hook: Make the reporting mailbox a SecOps mailbox, or detonated reports will look like your reporters clicked.

Microsoft Learn: Submissions user reported messages custom mailbox

Fabrikam licenses Microsoft 365 E3, which includes Defender for Office 365 Plan 1 as of July 1, 2026. A phishing message reached 60 Inboxes. In Real-time detections, the Take action wizard offers the administrator only Submit to Microsoft for review and Tenant Allow/Block List entries, but she needs to soft delete the delivered copies from that wizard. What does Fabrikam need?

Correct answer: B. Defender for Office 365 Plan 2, which adds Threat Explorer and Move or delete

The threat hunting article's Take action table lists Move or delete as a Defender for Office 365 Plan 2 action. With Plan 1, which the service description says Microsoft 365 E3 includes from July 1, 2026, Real-time detections offers only Submit to Microsoft for review and Tenant Allow/Block List entries. Soft deleting delivered mail from the wizard therefore needs Plan 2 and its Threat Explorer. Permissions such as Search and Purge matter only once the action exists.

Why the other options are wrong:

  • A. Unified RBAC activated, with Email & collaboration advanced actions (manage) Email & collaboration advanced actions (manage) is the unified RBAC permission for remediating email, but unified RBAC for Defender for Office 365 is available for Plan 2 only, and a permission can't add a Plan 2 action.
  • C. The Show all response actions toggle turned on in the Take action wizard Show all response actions makes available the actions that are grayed out because of a message's latest delivery location, but the toggle exists only in Threat Explorer and adds no Plan 2 actions.
  • D. The Search and Purge role, assigned by adding her to the Data Investigator role group Move or delete does require the Search and Purge role, so the role looks like the missing piece, but the action exists only in Plan 2 and no role adds it to Real-time detections.

Memory hook: Real-time detections can report and block; only Plan 2's Threat Explorer can move or delete.

Microsoft Learn: Threat explorer threat hunting

On June 2, Tailspin Toys ran a training campaign that assigned a phishing awareness module to every employee. A new campaign on August 18 assigned the same module, but employees who finished it in June weren't assigned it, and those who never finished show Training Previously Assigned. For next week's campaign, management wants the module assigned to every targeted employee regardless of earlier assignments. What should the administrator change?

Correct answer: D. Set the training threshold on the Settings tab to 0

The training threshold, 90 days by default and counted from when a module is assigned, keeps a module from being reassigned to users who completed it or were assigned it during that period, and the Training Previously Assigned status shows that effect. June 2 to August 18 falls inside 90 days. The training campaigns article says that setting the threshold to 0 on the Settings tab removes it, so training is always assigned.

Why the other options are wrong:

  • A. Select Include all users in my organization on the Target users page The employees are already targeted; the training threshold filters the module out after targeting, so a wider target list doesn't change who gets it.
  • B. Clear Send training with an end date on the Schedule page Clearing the end date only stops reminder notifications after the first assignment notice; the threshold would still block the reassignment.
  • C. Raise the repeat offender threshold on the Settings tab The repeat offender threshold sets how many consecutive simulations with given-up credentials make someone a repeat offender; it has nothing to do with reassigning training.

Memory hook: Module skipped or marked Training Previously Assigned? That's the 90-day training threshold; 0 turns it off.

Microsoft Learn: Attack simulation training campaigns

Cover of Microsoft Entra ID Fundamentals Field Guide
Topic 4 of 7

Entra ID Fundamentals (7 questions)

Go deeper in Microsoft Entra ID Fundamentals Field Guide. Get it on Amazon · Companion page

Show the 7 questions and explanations

Woodgrove Bank synchronizes accounts from on-premises Active Directory with Microsoft Entra Connect Sync. Mei, a synchronized user, transfers to the London office. Her job title must change, and her usage location must become GB so the right services can be licensed. A User Administrator is handling both changes. Where should each change be made?

Correct answer: C. Job title in on-premises Active Directory, then wait for sync; usage location directly in the Microsoft Entra admin center.

The Learn article on adding or updating a user's profile information says that for users whose source of authority is Windows Server Active Directory, identity, contact info, and job info must be changed in Active Directory and show up after the next sync cycle. The same note says Microsoft Entra ID attributes such as Usage Location can be updated directly in the Microsoft Entra admin center. Job title is job info; usage location is a cloud attribute.

Why the other options are wrong:

  • A. Both changes in the Microsoft Entra admin center, because a User Administrator can edit every property of a non-admin user. User Administrator rights don't override the source of authority: job information on a synchronized account is mastered in Active Directory, not in the cloud.
  • B. Job title in the Microsoft Entra admin center; usage location in on-premises Active Directory, then wait for sync. This reverses the split. Job title belongs to Active Directory for a synchronized user, while usage location is a Microsoft Entra ID attribute set in the cloud.
  • D. Job title in the Microsoft 365 admin center, which writes it back to Active Directory; usage location in the Entra admin center. Job title on a synchronized account can't be edited in the cloud, and sync carries these attributes from Active Directory to the cloud, not back.

Memory hook: Synced user: identity, contact, and job info change on-premises; usage location and licenses change in the cloud.

Microsoft Learn: Manage user profile info

Contoso has Microsoft Entra ID P1 and a Conditional Access policy that requires MFA for guests. Guests from Fabrikam, another Microsoft Entra organization, complete MFA at home and then again in Contoso. MFA must stay required, but MFA done in Fabrikam's tenant should satisfy it, while guests from every other partner still complete MFA in Contoso. What should you configure?

Correct answer: A. In cross-tenant access settings, add Fabrikam under Organizational settings and trust MFA on its inbound Trust settings tab.

Inbound trust settings let Contoso's Conditional Access policies accept MFA claims from another Microsoft Entra organization: the MFA policy still applies, but a guest who already completed MFA at home isn't challenged again. Set on Fabrikam's entry under Organizational settings, the trust covers Fabrikam only, because organizational settings take precedence over the defaults that every other partner keeps. Trust settings require Microsoft Entra ID P1.

Why the other options are wrong:

  • B. In cross-tenant access settings, edit the inbound defaults and trust MFA from Microsoft Entra tenants on the Trust settings tab. Trusting MFA in the default settings applies to every external Microsoft Entra organization without custom settings, not only Fabrikam.
  • C. In cross-tenant access settings, add Fabrikam under Organizational settings and turn on automatic redemption for its inbound access. Automatic redemption suppresses the consent prompt on first access; it doesn't make Contoso trust anyone's MFA claims.
  • D. In Conditional Access, exclude guests from Fabrikam's tenant from the policy that requires MFA for guests. Excluding Fabrikam's guests removes the MFA requirement for them altogether, which breaks the rule that MFA must stay required.

Memory hook: Trust one partner's MFA: Organizational settings, inbound Trust settings. Trust it in defaults and every partner gets it.

Microsoft Learn: Cross tenant access settings B2B collaboration

Woodgrove Bank put the CFO's account, which holds no admin roles, in the restricted management administrative unit Exec-Protect. Two support staff hold Helpdesk Administrator scoped to Exec-Protect, and both are unavailable tonight when the CFO needs a password reset. Lena, a Global Administrator at tenant scope, must reset it without taking the account out of the unit, even briefly. What should she do?

Correct answer: A. Assign herself the Helpdesk Administrator role scoped to Exec-Protect, and then reset the CFO's password

In a restricted management administrative unit, only administrators assigned at that unit's scope can change the Microsoft Entra properties of its members, so Lena's tenant-scope Global Administrator role can't reset the password. The restricted management article lets Global Administrators and Privileged Role Administrators assign roles scoped to the unit, including to themselves, and records the assignment in the audit logs. A unit-scoped Helpdesk Administrator can reset passwords for non-administrators in the unit.

Why the other options are wrong:

  • B. Remove the CFO's account from Exec-Protect, reset the password, and then add the account back to the unit Removing the account takes it out of the unit's protection, which the stem rules out.
  • C. Activate her eligible Privileged Authentication Administrator role at tenant scope in PIM, then reset it A stronger role seems like the answer, but any role assigned at tenant scope, built-in or custom, is blocked from modifying objects in a restricted management unit.
  • D. Set the restricted management setting of Exec-Protect to No, reset the password, then set it back to Yes The restricted management setting is chosen when the unit is created and can't be changed afterward.

Memory hook: Restricted management unit: even Global Administrators must assign themselves at the unit's scope to change members.

Microsoft Learn: Admin units restricted management

Litware's tenant was created with the United States as its country. An administrator creates 40 accounts for a new office in Brazil with a script that sets display name, UPN, password, and the Country or region property to Brazil, but never sets usage location. The accounts are added to a security group that has Microsoft 365 E3 assigned through group-based licensing. What happens?

Correct answer: C. The licenses are applied, and each account takes the tenant's location, the United States.

The Microsoft 365 admin center article on group-based licensing notes that a license can't be assigned directly to a user until the user's location is set, and that for group-based licensing any user without a specific location inherits the tenant's location. Country or region is a separate profile property from usage location, so these Brazil staff are licensed as if they were in the United States. Set usage location when accounts are created.

Why the other options are wrong:

  • A. The licenses are applied, and each account takes Brazil from its Country or region property. Country or region is a profile detail, not the usage location that licensing reads, so it doesn't place the accounts in Brazil for licensing.
  • B. The licenses stay unapplied until a License Administrator selects Reprocess for the group. Reprocess retries assignments that ended in errors; nothing errors here, because the missing location is inherited from the tenant.
  • D. The assignment fails for each account until an administrator sets a usage location on it. Blocking until a location is set describes a direct license assignment; group-based licensing fills the gap with the tenant's location instead.

Memory hook: No usage location: a direct assignment is refused, a group assignment borrows the tenant's country. Country or region never counts.

Microsoft Learn: Manage group licenses

A Privileged Role Administrator at Fabrikam must give the eight members of the existing Service-Desk security group the Helpdesk Administrator role through a group assignment. Service-Desk was created last year with assigned membership, and it doesn't appear in the picker when she adds an assignment to the role. What should she do?

Correct answer: B. Create a new role-assignable security group, add the eight users to it, and assign the role to that group

Only groups created with isAssignableToRole set to true, shown in the admin center as Microsoft Entra roles can be assigned to the group, can hold a role. The role-assignable groups article says the property can be set only on new groups, is immutable, and can't be applied to an existing group. Creating one takes at least Privileged Role Administrator, its membership must be Assigned, and nesting isn't supported, so a new group with the eight users as direct members is the path.

Why the other options are wrong:

  • A. In the Service-Desk properties, set Microsoft Entra roles can be assigned to the group to Yes, then assign the role The option is offered only while a group is being created; an existing group can't be turned into a role-assignable group afterward.
  • C. Switch Service-Desk to dynamic membership on the department attribute, then assign the role to the group Role-assignable groups must use Assigned membership, and changing the membership type doesn't make an existing group eligible for a role.
  • D. Add Service-Desk as a member of an existing role-assignable group that already holds Helpdesk Administrator Nesting feels like a shortcut, but role-assignable groups don't support it: a group can't be added as a member of one.

Memory hook: Role-assignable is set at birth: new group, Assigned members, no nesting.

Microsoft Learn: Groups concept

Contoso assigns its Windows Autopilot deployment profile to a Microsoft Entra group. Every Autopilot device registered in the tenant, including devices registered next month, must get the profile without anyone maintaining a member list. Which group should the administrator create for the profile assignment?

Correct answer: A. A security group with Dynamic Device membership and a rule on device.devicePhysicalIds

Microsoft 365 groups can include only users, and a dynamic rule targets users or devices but never both, so a self-maintaining device group has to be a security group with the Dynamic Device membership type. The dynamic membership rules article lists devicePhysicalIds, the attribute Windows Autopilot uses, as a device rule property, with an example that matches all Autopilot devices, and names Autopilot profile assignment as a use for dynamic groups. Devices need no license to be members.

Why the other options are wrong:

  • B. A Microsoft 365 group with dynamic membership and a rule on device.devicePhysicalIds It looks right because Microsoft 365 groups support dynamic membership, but they can include only users, so a device rule can't populate one.
  • C. A dynamic distribution group in the Exchange admin center with a recipient filter The word dynamic tempts here, but a dynamic distribution group calculates mail-enabled recipients for message delivery and can't hold device objects or take an Autopilot profile.
  • D. A security group with Dynamic User membership and a rule on the device owners' attributes Using a user rule to reach devices is the trap: device membership rules can reference only device attributes, and a Dynamic User group holds users, not their devices.

Memory hook: Devices in a dynamic group means a security group: Microsoft 365 groups hold users only.

Microsoft Learn: Groups dynamic membership

Litware set its guest invite settings to Only users assigned to specific admin roles can invite guest users. A project coordinator must now invite vendor staff as B2B guests for a new project and should hold no other administrative permissions. Which role should you assign to the coordinator?

Correct answer: A. Guest Inviter

The external collaboration settings article says that with Only users assigned to specific admin roles selected, only users with User Administrator or Guest Inviter can invite guests, and that Guest Inviter lets individuals invite guests without a higher privileged administrator role. The Least privileged roles by task reference also lists Guest Inviter as the least privileged role for creating guest users.

Why the other options are wrong:

  • B. Helpdesk Administrator Helpdesk Administrator is the least privileged role for resetting a guest's redemption status, not for sending new invitations.
  • C. External Identity Provider Administrator External Identity Provider Administrator configures federation with outside identity providers; it isn't one of the roles allowed to invite under this setting.
  • D. User Administrator User Administrator can invite under this setting, but it also creates, edits, and deletes accounts, far more than the coordinator needs.

Memory hook: Invites locked to admin roles: Guest Inviter is the smallest role that can still send them.

Microsoft Learn: External collaboration settings configure

Cover of Data Loss Prevention with Microsoft Purview
Topic 5 of 7

Data Loss Prevention (4 questions)

Go deeper in Data Loss Prevention with Microsoft Purview. Get it on Amazon · Companion page

Show the 4 questions and explanations

Litware has 3,000 Windows 11 devices that are already onboarded to Microsoft Defender for Endpoint through Intune. The compliance team wants Endpoint DLP policies to apply to these devices with the least administrative effort. What should the admin do?

Correct answer: A. Turn on device onboarding in the Purview portal and use the devices that are already listed there.

Learn's onboarding overview says device onboarding is shared across Microsoft 365 and Defender for Endpoint: devices already onboarded to Defender for Endpoint appear in the managed devices list, and no further steps are needed to onboard them. The admin goes to Settings, then Device onboarding, then Devices, turns on device onboarding (usually about 60 seconds, up to 30 minutes), and then scopes Endpoint DLP policies to those devices.

Why the other options are wrong:

  • B. Download the onboarding package from the Purview portal and deploy it to every device with Intune. A package is how you onboard devices that aren't onboarded yet. These devices already are, so a second deployment adds work without adding coverage.
  • C. Offboard the devices from Defender for Endpoint, then onboard them again from the Purview portal. Offboarding strips Defender for Endpoint protection and gains nothing, because onboarding from either portal lands the device in the same shared list.
  • D. Install the Microsoft Purview Information Protection client on each device to serve as the DLP agent. Endpoint DLP is built into Windows 10 and 11 and needs no additional agent, so installing a client isn't part of making these policies apply.

Memory hook: Onboarded to Defender for Endpoint means ready for Endpoint DLP: turn on device onboarding, don't redeploy.

Microsoft Learn: Device onboarding overview

Woodgrove Bank has Microsoft 365 E3 with no add-ons. An Exchange DLP rule is set to send an alert every time an activity matches. Within 10 minutes, four different users each send a message that matches the rule, yet the DLP Alerts dashboard shows a single alert that holds all four events. The security operations lead asks why. What explains the single alert?

Correct answer: C. Single-event alerts from one rule are grouped within a fixed 15-minute window on E3 that admins can't change.

Learn's Get started with DLP alerts page says single-event alerts from the same rule are aggregated when the events fall within a set window of each other: 60 seconds on E5 and 15 minutes on E3, and the admin can't configure either window. Four matches in 10 minutes on an E3 tenant land in one window, so one alert carrying four events is expected behavior, not a fault. Separate alerts per sender would need the tenant-level user and rule based aggregation, which is in preview.

Why the other options are wrong:

  • A. The rule was edited less than three hours ago, so the new matches were attached to an older alert. The delay of up to three hours after you configure or modify alert settings holds new alerts back. It doesn't merge new matches into an existing alert.
  • B. Alert emails and incident reports go out only once per document, so the later matches joined the first alert. The once-per-document rule covers the same document triggering again, such as a file shared twice. These are four separate messages from four senders.
  • D. The rule uses a threshold-based aggregate alert that waits for four matches before raising one alert. Threshold-based aggregate alerts need A5, E5, G5 or a qualifying add-on, and this rule alerts on every match in an E3 tenant with no add-ons.

Memory hook: One rule, one window: 60 seconds on E5, 15 minutes on E3, and nobody can change it.

Microsoft Learn: DLP alerts

Contoso has Microsoft 365 E3 with no compliance or security add-ons. The DLP admin turns on single-event alerts in the Exchange, SharePoint, and OneDrive policies, and the security team asks where its analysts should triage those alerts. Where should the admin point them?

Correct answer: B. The DLP Alerts dashboard in the Microsoft Purview portal, under Data loss prevention, then Alerts.

Learn's page on investigating DLP alerts with Microsoft Defender XDR lists the licenses needed to investigate DLP incidents in the Defender portal: Office 365 E5 or A5, Microsoft 365 E5 or A5, and the E5 or A5 Compliance and Information Protection and Governance offers. Any DLP subscription, E3 included, can raise single-event alerts, and the Purview DLP Alerts dashboard is where they are viewed, triaged, and given a status.

Why the other options are wrong:

  • A. The Alert policy page in the Microsoft Defender portal, under Email & collaboration, then Policies & rules. The Alert policy page manages Microsoft 365 alert policies. DLP alerts are configured in the DLP rules and reviewed in the DLP Alerts dashboard.
  • C. The Incidents queue in the Microsoft Defender portal, filtered to Microsoft Data Loss Prevention. Microsoft recommends the Defender queue for DLP alerts when you're licensed for it, but investigating DLP incidents there needs an E5-class license this tenant doesn't have.
  • D. Content explorer in the Microsoft Purview portal, filtered to the policies' sensitive info types. Content explorer shows where classified items are stored, not the alerts a policy raises, so analysts can't triage alerts there.

Memory hook: E3 DLP alerts live in the Purview dashboard. The Defender incident view needs E5-class licensing.

Microsoft Learn: DLP investigate alerts Defender

Tailspin Toys runs shared Windows 11 kiosks in its warehouses. An Endpoint DLP policy blocks printing of files with customer data, and it must apply to anyone who signs in to a kiosk, including daily temporary workers who aren't in any group. The admin scoped users to the Kiosk-Operators group and devices to the kiosk device group. Temporary workers still print those files. What should the admin change?

Correct answer: C. Set the user scope to All users and groups, and keep the kiosk device group as the device scope.

The device scoping section of Learn's DLP policy reference says a Devices policy is enforced only when both the user and the device are in scope. Temporary workers aren't in Kiosk-Operators, so the policy never applies when they sign in. Learn's own pattern for kiosks used by many people is All users and groups for the user scope plus specific devices and device groups for the device scope, which covers every user on the kiosks without touching other laptops.

Why the other options are wrong:

  • A. Set the device scope to All devices and device groups, and keep Kiosk-Operators as the user scope. A wider device scope still requires membership in Kiosk-Operators, so temporary workers stay out of scope while operators pick up the block on every device.
  • B. Move the kiosk policy above the default DLP policy for devices in the policy priority order. Endpoint DLP applies the most restrictive action across matching policies, so priority isn't the obstacle. The policy never matches these users at all.
  • D. Onboard the kiosks again through Intune so they download the updated policy scope. The kiosks already have the policy. Onboarding them again doesn't change the fact that the signed-in temporary worker is outside the user scope.

Memory hook: Endpoint scope is an AND: the user must be in scope and so must the device.

Microsoft Learn: DLP policy reference

Cover of AB-650 Administering Microsoft 365 and AI Services Complete Exam Guide
Topic 6 of 7

Copilot, agents and AI services (30 questions)

Go deeper in AB-650 Administering Microsoft 365 and AI Services Complete Exam Guide. Get it on Amazon

Show the 30 questions and explanations

Fabrikam licenses Microsoft Agent 365. On one day, a single analyst is the only user of an Agent Builder agent. She chats with it from 9:00 to 9:10 AM, returns at 9:25 AM and chats until 9:30 AM, then returns at 10:15 AM for one more exchange. With the agent's Activity tab date range set to that day, what does the tab report?

Correct answer: B. One active user and two sessions, because only a gap of over 30 minutes starts a session

The Activity tab counts a user as active after a single interaction in the date range, however often she returns, so the analyst is one active user. A session is a back-and-forth conversation, and a new one starts after 30 minutes of inactivity. The 15-minute gap before 9:25 AM keeps her in the first session, and the 45-minute gap before 10:15 AM starts a second. The tab needs E7 or Agent 365 and currently covers Agent Builder, SharePoint, and Microsoft 365 Agents Toolkit agents.

Why the other options are wrong:

  • A. Three active users and three sessions, because every session adds one more active user Active users are unique people who interacted at least once in the date range, so one analyst counts once no matter how many sessions she has.
  • C. One active user and three sessions, because each return to the agent starts a new session Returning alone doesn't start a session. The 15-minute gap before 9:25 AM is under the 30-minute inactivity threshold, so that chat continues the first session.
  • D. One active user and one session, because a session covers a user's whole day with the agent Sessions aren't daily buckets. A new session starts after 30 minutes of inactivity, so the 45-minute gap before 10:15 AM splits her day into two.

Memory hook: Active user: one person, counted once. New session: 30 minutes of silence.

Microsoft Learn: Agent details

Contoso's tenant is in the EU. Last year its admin opted in to Anthropic models under Anthropic's own commercial terms. Claude has since disappeared from Researcher and the Copilot model picker, and the AI providers operating as Microsoft subprocessors page shows Anthropic set to No users. Only the Research security group should get Claude. What should the AI Administrator do?

Correct answer: A. Opt in to Anthropic again on the subprocessors page and assign the Research security group.

Anthropic now operates as a Microsoft subprocessor, and in the EU, EFTA, and the UK its setting defaults to No users. The older independent processor setting was decommissioned on May 1, 2026, so organizations that opted in under Anthropic's own terms must opt in again on the AI providers operating as Microsoft subprocessors page. Access is assigned per provider to users or security groups, so assigning Research returns Claude to that group across Copilot experiences.

Why the other options are wrong:

  • B. Turn on the Anthropic model family on the Features page of a Research environment in Power Platform. The Power Platform setting governs external models only in Copilot Studio and Power Platform, and it can't be turned on until the provider is enabled in the Microsoft 365 admin center.
  • C. Opt in to Anthropic models with Data Retention and choose the Research security group for them. Models with Data Retention are a separate, off-by-default category in which Anthropic acts as an independent processor under its own terms. Opting in doesn't restore the standard Claude models.
  • D. Turn on the Copilot in Microsoft 365 apps with Anthropic models setting for the whole tenant. That EU, EFTA, and UK setting lets Copilot in Word, Excel, and PowerPoint use Anthropic models. It doesn't affect Researcher or the model picker in other Copilot features.

Memory hook: EU, EFTA, and UK start Anthropic at No users, and old opt-ins must opt in again.

Microsoft Learn: Connect to AI subprocessor

Fabrikam's Cowork spending policy draws on prepaid capacity packs and on an Azure subscription that carries a Copilot Credit pre-purchase plan (P3). Pay-as-you-go is enabled on the same subscription, and both prepaid sources still hold credits this month. In what order does Cowork usage draw on these sources?

Correct answer: A. Prepaid capacity packs first, then P3 commit units, then pay-as-you-go billing

The managing usage-based billing page states that when a policy uses both prepaid capacity packs and a subscription with a Copilot Credit pre-purchase plan, billing follows a fixed order to keep spending predictable: prepaid capacity packs, then the P3 plan, then pay-as-you-go. Pay-as-you-go only picks up what the prepaid sources can't cover, and with no prepaid credits left and pay-as-you-go off, requests are blocked.

Why the other options are wrong:

  • B. Prepaid capacity packs first, then pay-as-you-go, with P3 applied at renewal P3 commit units are consumed before any pay-as-you-go overage. They aren't a true-up at renewal.
  • C. Whichever source the billing method lists first, then the others in listed order The order is fixed by the service, not by how an admin arranges the billing method.
  • D. P3 commit units first, then prepaid capacity packs, then pay-as-you-go billing P3 is discounted, which tempts candidates to spend it first, but Learn puts capacity packs ahead of P3.

Memory hook: Credits draw down packs, then P3, then pay-as-you-go.

Microsoft Learn: Usage based billing manage Copilot credits

Woodgrove Bank is preparing for an ISO certification audit of the management system that governs how it develops and uses AI, including agents run under Agent 365. The compliance manager wants a Compliance Manager assessment whose controls match that standard. Which regulatory template should the assessment use?

Correct answer: D. ISO/IEC 42001:2023

ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system, and Compliance Manager offers a premium template for it. The Compliance Manager assessments page lists it among the four AI regulation templates under Premium AI templates, with the EU Artificial Intelligence Act, ISO/IEC 23894:2023, and NIST AI RMF 1.0. Among the choices, only 42001 is an ISO standard for AI, so its template matches the audit.

Why the other options are wrong:

  • A. ISO/IEC 27001:2022 ISO/IEC 27001:2022 specifies an information security management system. It's a premium template under Premium templates, not a standard for managing AI.
  • B. ISO/IEC 27701:2019 ISO/IEC 27701:2019 specifies a privacy information management system that extends ISO/IEC 27001, so it governs personal data handling, not AI.
  • C. NIST AI Risk Management Framework (RMF) 1.0 NIST AI RMF 1.0 is one of the AI templates, but it's a NIST framework, not an ISO standard, so it doesn't match an ISO certification audit.

Memory hook: ISO/IEC 42001 manages AI; 27001 manages security; 27701 manages privacy.

Microsoft Learn: Offering iso 42001

Contoso has Microsoft 365 E7. On the All agents page, an agent's Risks column shows 4, and its Risk details pane lists Microsoft Purview among the platforms contributing signals. A Global Administrator selects the Microsoft Purview link to review the Insider Risk Management alerts but can't view them. What should the administrator do?

Correct answer: A. Assign themselves the IRM Analyst or IRM Investigator role, which that Purview link requires.

Each platform named in the Risk details pane is a deep link, and what opens depends on the viewer's roles. The agent registry page's table accepts Global Administrator, Global Reader, Security Reader, Security Administrator, or AI Administrator for the Entra and Defender links, but only IRM Analyst or IRM Investigator for Purview IRM alerts, and says Global Administrator alone is insufficient. In Purview those are the Insider Risk Management Analysts and Investigators role groups, which a Global Administrator can add themselves to.

Why the other options are wrong:

  • B. Wait up to an hour, since Purview can trail the admin center before it shows a counted signal. The documented lag runs the other way: the admin center's counts can trail the security portals by up to an hour. The alert already exists; the viewer lacks the role.
  • C. Assign themselves Security Reader, the role the Risk details pane checks for every source link. Security Reader does open the Entra and Defender links, which is why it tempts, but it isn't one of the roles the Purview IRM alerts link accepts.
  • D. Assign an Agent 365 license to their own account, since risk details are licensed per viewer. The Risks column needs an E7 or Agent 365 license in the tenant, which Contoso has since the counts show. A license doesn't grant access to Purview IRM alerts.

Memory hook: Purview IRM deep links want IRM Analyst or IRM Investigator, even from a Global Administrator.

Microsoft Learn: Agent registry

Litware's records team wants members of the Research group to stop creating new Copilot Pages and Copilot Notebooks in the Microsoft Copilot app. Loop workspaces must keep working for everyone, and nobody outside Research should be affected. What should the Office Apps admin do?

Correct answer: D. In Cloud Policy, disable Create and view Copilot Pages and Copilot Notebooks in a configuration for Research.

Creation of Copilot Pages and Copilot Notebooks is governed by the Create and view Copilot Pages and Copilot Notebooks setting in Cloud Policy, which is enabled by default and can be scoped to a group. Disabling it for Research stops new Pages and Notebooks, hides the Notebooks module in the Copilot app, and deletes nothing that already exists. Pages and Notebooks are independent of Loop, so Loop workspaces keep working.

Why the other options are wrong:

  • A. In Cloud Policy, disable Enable code previews for AI-generated content in a configuration scoped to Research. Code previews only control whether AI-generated code runs as a preview in Copilot Chat and Pages. Creation of Pages and Notebooks stays on.
  • B. On the Copilot settings page, restrict Advanced package uploads to users outside the Research group. Advanced package uploads govern who can upload agent and plugin packages that use actions or MCP servers. They don't touch Pages or Notebooks.
  • C. In Cloud Policy, disable Create Loop workspaces in Loop in a policy configuration scoped to Research. Loop and Copilot Pages share a storage container, which makes this tempting, but the Loop policy blocks the workspaces that must keep working and leaves Pages and Notebooks creation on.

Memory hook: Pages and Notebooks share one Cloud Policy switch, and it's separate from Loop.

Microsoft Learn: Cpcn admin configuration

Fabrikam's security team wants to stop administrators from using Copilot inside the Microsoft 365, Exchange, SharePoint, and Teams admin centers, while Copilot for licensed end users stays exactly as it is. Several of the administrators hold no Copilot license, yet they already use Copilot in those admin centers. What should the AI Administrator do?

Correct answer: C. Turn off Microsoft Copilot in admin centers on the User access tab of Copilot settings.

Microsoft Copilot in admin centers, on the User access tab under Copilot then Settings, decides whether users with an admin role can use Copilot in the Microsoft 365, Exchange, SharePoint, and Teams admin centers. It is allowed for all admins by default, which is why unlicensed admins already use it. Turning it off removes Copilot from those admin centers and leaves end-user Copilot alone. The admin experience needs no extra Copilot license, so licenses aren't the lever.

Why the other options are wrong:

  • A. Remove the Microsoft Copilot licenses from every account that holds an administrator role. Licenses feel like the obvious switch, but the admin-center experience needs no extra Copilot license, as the unlicensed admins show, and stripping licenses would also change Copilot for admins who use it as end users.
  • B. Set Copilot Frontier to No access so preview Copilot features stay off for every administrator. Frontier only governs early access to preview features and already defaults to No access. Copilot in the admin centers is a generally available setting with its own control.
  • D. Turn off Pin Microsoft Copilot Chat on the User access tab of Copilot settings. Pinning decides whether Copilot Chat is pinned in Teams, Outlook, and the Copilot app. It would change the end-user experience and leaves Copilot in the admin centers untouched.

Memory hook: Copilot in the admin centers is on for every admin by default. The off switch sits on the User access tab.

Microsoft Learn: Microsoft 365 Copilot page

Woodgrove Bank has a Conditional Access policy, set to On, that blocks every agent identity derived from its trading blueprint from All resources. Later, the hosting service uses the blueprint to call Microsoft Graph and create two new agent identities, and an existing trading agent calls a partner pricing service with a static API key that isn't registered in Microsoft Entra ID. What happens?

Correct answer: B. Both succeed; the blueprint's creation token and API-key calls are outside Conditional Access.

The Conditional Access for agents page lists its boundaries: policies don't apply when an agent identity blueprint acquires a Microsoft Graph token to create an agent identity or an agent's user account, and Conditional Access protects only resources secured by Microsoft Entra ID, so a call made with an API key bypasses token issuance entirely. The block still applies once the new agent identities request tokens for Entra-protected resources.

Why the other options are wrong:

  • A. The creation is blocked, but the API-key call succeeds because the service isn't in Entra ID. Blueprint token acquisition for creating agent identities is a documented exception, so the creation isn't blocked.
  • C. Both are blocked, because a blueprint-scoped policy covers every token the blueprint requests. A blueprint-scoped policy covers the agent identities derived from the blueprint, not the blueprint's own Graph token for creating them.
  • D. The creation succeeds, but the API-key call is blocked because the policy targets All resources. All resources means resources protected by Microsoft Entra ID; a service reached with an API key never asks Entra for a token, so the policy never evaluates it.

Memory hook: Blueprint creation tokens and API keys sit outside Conditional Access.

Microsoft Learn: Agent ID

At Tailspin Toys, six platform engineers in an assigned-membership security group must be able to edit an agent identity blueprint's settings and manage its credentials. Adding the group as an owner of the blueprint fails, and the team won't accept any tenant-wide admin role. What should the administrator do?

Correct answer: B. Add each of the six engineers individually as an owner of the blueprint.

The owners, sponsors, and managers page says individual users, including guests, and service principals can be owners, while groups aren't supported as owners. Owners hold administrative rights scoped to their blueprint or agent identity: they edit settings, manage credentials, change configurations, and add more owners. Adding each engineer as an owner meets the need with no directory role, and multiple owners also give backup coverage.

Why the other options are wrong:

  • A. Add the security group as a sponsor of the blueprint instead of an owner. Assigned-membership security groups are rejected as sponsors, and sponsorship wouldn't grant technical access even for an allowed group type.
  • C. Convert the group to a role-assignable group, then add it as an owner. No group type can be an owner, and role-assignable groups are excluded from sponsorship as well.
  • D. Add each of the six engineers individually as a sponsor of the blueprint. Sponsors carry business accountability with nondestructive lifecycle rights only; they can't modify application settings or credentials.

Memory hook: Owners are people or service principals, never groups.

Microsoft Learn: Agent owners sponsors managers

Fabrikam bills Copilot Studio agents through a Power Platform billing plan and Cowork through its default spending policy, both on one Azure subscription. In Azure Cost Management, finance sees all of it under a single Microsoft Copilot Studio service and wants Cowork charges separated from next month on. What should the admin do?

Correct answer: C. Bill the Cowork policy to its own Azure subscription or resource group.

The article comparing admin center views with the Azure bill says Cowork, Copilot Studio, and Work IQ API consumption is billed through one Copilot Credits service labeled Microsoft Copilot Studio, and that attributing cost to one service means separating it by Azure subscription or resource group. A Global or Billing Administrator can change an existing spending policy's billing method without recreating the policy.

Why the other options are wrong:

  • A. Filter Azure Cost Management on a Microsoft Copilot Cowork service name. Azure has no separate Cowork service today. Cowork consumption posts under Microsoft Copilot Studio.
  • B. Use the Consumption tab export in Copilot Cost Management as the cost record. The admin center counts Copilot Credits, not currency, and Microsoft says to reconcile against the monthly billing record rather than the dashboards.
  • D. Turn off Auto-apply new services so Cowork charges post as their own service. Auto-apply new services only decides whether newly supported services join a policy. It doesn't change how Azure labels charges.

Memory hook: One Copilot Studio line in Azure: split cost by subscription or resource group.

Microsoft Learn: Usage based billing compare dashboard views

Tailspin Toys' insider risk team wants Insider Risk Management to detect prompt injection attacks and access to protected materials when employees interact with agents managed by Agent 365. Which policy template should the team create its policy from?

Correct answer: D. The Risky AI usage template

The Purview page for Agent 365 points Insider Risk Management to the Risky AI usage policy template to detect risky usage that includes prompt injection attacks and access to protected materials. The policy templates page adds that this template scores user prompts and AI responses containing sensitive information in Microsoft 365 Copilot, Microsoft Copilot, and agents, and that its detections feed user risk scoring in Adaptive Protection. The other three templates score file, departure, and device signals rather than AI interactions.

Why the other options are wrong:

  • A. The Data theft by departing users template Data theft by departing users scores exfiltration near resignation or end dates from an HR connector or account deletion, so it never evaluates prompt injection in agent interactions.
  • B. The Data leaks template Data leaks sounds right for protected materials, but it scores SharePoint downloads, file sharing, printing, copying to personal cloud services, and high-severity DLP alerts, not risky prompts to agents.
  • C. The Security policy violations template Security policy violations scores Microsoft Defender for Endpoint alerts about defense evasion and unwanted software on devices, not AI interactions.

Memory hook: Prompt injection or protected materials in agent chats: Risky AI usage.

Microsoft Learn: AI agent 365

Tailspin Toys wants makers who build agents with Microsoft Copilot Agent Builder to stop sharing them with the whole organization. Makers must still be able to share an agent directly with individual colleagues, and no group of makers should keep broad sharing rights. Which configuration under Agents then Settings meets these requirements?

Correct answer: C. Set Sharing to No users, and leave User access at its default of All users.

Sharing on the Agent settings page offers All users, No users, and Specific users. No users turns off sharing at the organization level while still letting users share directly with specific individuals, which matches Tailspin's requirement exactly. Specific users restricts broad sharing to designated groups, so a group would keep it. The page also notes that the Sharing control applies only to agents built with Microsoft Copilot Agent Builder, the maker population in this scenario.

Why the other options are wrong:

  • A. Set Sharing to Specific users, and select a small group of trusted makers. Specific users feels like the cautious middle ground, but it keeps broad sharing rights for the selected group, and the stem says no group should keep them.
  • B. Set User access to Specific users/groups, and select only the makers. User access gates who can use agents, not how makers share them, and it would also stop every other employee from using agents.
  • D. Under Allowed agent types, turn off Allow apps and agents built by your organization. This toggle keeps org-built agents out of the Agent store for users. It doesn't govern sharing and would take the organization's agents away from everyone.

Memory hook: Sharing set to No users: no org-wide shares, direct shares with named people still work, Agent Builder only.

Microsoft Learn: Agent settings

Woodgrove Bank has 35 assigned Microsoft Copilot licenses and no Viva Insights licenses. Executives who open the Copilot Dashboard want to compare adoption with similar companies, but no benchmarks appear. What has to change before benchmarks are available?

Correct answer: D. Reach at least 50 Copilot licenses or 50 Viva Insights licenses.

The Copilot Dashboard is the strategic report in the measurement and reporting pillar of Copilot controls, and its license table decides which features a tenant gets. Tenants with 1 to 49 Copilot licenses get the Readiness page and adoption and impact metrics, but not benchmarks, agent insights, intelligent summaries, or delegation. Those arrive with at least 50 Copilot licenses or at least 50 Viva Insights licenses.

Why the other options are wrong:

  • A. Have an executive delegate dashboard access to the other leaders. Delegation is itself one of the features a tenant under 50 licenses doesn't get, and it wouldn't add benchmarks.
  • B. Upload an organizational data file with the Organization attribute. Organizational data adds filters such as Organization. It doesn't change which features the license count allows.
  • C. Lower the dashboard's minimum group size from 10 down to 5. Minimum group size decides which groups show metrics. It doesn't unlock benchmarks, and it can't go below 5.

Memory hook: Benchmarks, agent insights, and delegation need 50 Copilot or 50 Viva Insights licenses.

Microsoft Learn: Copilot dashboard

Litware's search administrator is bulk importing 40 acronyms into Copilot Search from a CSV file. Legal must approve each definition before users can see it in search results, and the review will take several days. How should the administrator set up the import?

Correct answer: D. Set State to Draft for each row, then move each acronym to Published after approval.

The Copilot Search admin experience article gives acronyms three states: Published, which users see in Copilot Search; Draft, which stays out of search results until an admin moves it to Published; and Excluded, which prevents an acronym from appearing. State is a mandatory column in the acronym import file, so importing each row as Draft and publishing after Legal signs off matches the review requirement.

Why the other options are wrong:

  • A. Set State to Excluded for each row, then remove the exclusion after Legal approves it. Excluded actively suppresses an acronym, and undoing it means deleting the excluded entry and adding the acronym again, which isn't a review workflow.
  • B. Leave the State column empty so the acronyms stay hidden until an admin publishes them. State is a mandatory column in the acronym import file, so leaving it empty isn't an option.
  • C. Set State to Scheduled with a publish date after Legal's review is expected to end. Scheduled is a bookmark state; acronym rows accept only Published, Draft, or Excluded.

Memory hook: Acronyms awaiting review go in as Draft; Excluded suppresses, and Scheduled is for bookmarks.

Microsoft Learn: Microsoft 365 Copilot search admin experience

Litware's sales team relies on a shared Agent Builder agent that a single employee owns. That owner moves to a new role in two months. The team lead wants a colleague to have full edit rights starting now, while the current owner keeps full access until the move. What should the AI Administrator do in the Microsoft 365 admin center?

Correct answer: A. Open the agent's Owners pane and use Add owner to add the colleague.

The governance and lifecycle actions page says Agent Builder agents support multiple owners, and all owners have the same rights to edit, share, manage, and maintain the agent, with no primary or secondary roles. Add owner leaves the current owner in place, so both keep full access during the transition. The departing owner can be removed later, since only the last remaining owner can't be removed.

Why the other options are wrong:

  • B. Add the colleague as a specific user under Agents, then Settings, then Sharing. The Sharing setting controls who can share Agent Builder agents in the organization; it grants no one edit rights on a specific agent.
  • C. Use Assign new owner on the agent and select the colleague as owner. Assign new owner gives the colleague full rights but removes all of the previous owner's access, including read, which breaks the transition requirement.
  • D. Run the Reassign ownerless agents created with Agent Builder to manager rule. That rule acts only on ownerless agents and hands them to the previous owner's manager; this agent still has an owner.

Memory hook: Add owner keeps both people in; Assign new owner locks the old owner out.

Microsoft Learn: Agent actions

Litware turned on Restricted SharePoint Search in March 2026 with 60 reviewed sites on its allowed list. The Budget Planning site isn't on the list and isn't associated with any hub site, yet a planner who edited two files there last week gets Copilot answers that quote them. What explains this?

Correct answer: B. Restricted SharePoint Search still surfaces files a user recently viewed, edited, or created.

The Restricted SharePoint Search page says the feature isn't a security boundary and doesn't guarantee that only allowed sites appear. Results and Copilot responses still draw on files a user viewed, edited, or created, files shared directly with them, and their frequently visited sites, up to the last 2,000 such entities. The planner edited the files last week, so Copilot can use them. The feature is retiring, and new enablement has been blocked since July 31, 2026.

Why the other options are wrong:

  • A. Allowed-list changes can take more than a week to reach Copilot for sites that hold many items. No list change happened here, and the week-plus delay for sites over 500,000 items belongs to Restricted Content Discovery; Restricted SharePoint Search goes into effect within an hour of being enabled.
  • C. The allowed list governs org-wide search only, and Copilot answers don't honor it. As a temporary measure, the allowed list applies to Copilot Chat and agentic experiences as well as org-wide search.
  • D. Budget Planning is included because it rides along with a hub site on the allowed list. Associated sites of an allowed hub site are included without counting toward the 100-site limit, but Budget Planning belongs to no hub.

Memory hook: Restricted SharePoint Search is an allowed list, not a wall: recent and shared files still surface.

Microsoft Learn: Restricted SharePoint search

Contoso licenses Microsoft 365 E5 for every user and has bought no add-ons. An administrator goes to Agents, then All agents, in the Microsoft 365 admin center and selects an agent on the Registry list. The agent's Security tab shows no details, and the list has no Risks column. What should Contoso buy so both appear?

Correct answer: B. Microsoft Agent 365 licenses, sold per user as an add-on for eligible plans that include E5

The agent details page in the Microsoft 365 admin center says a Microsoft E7 or Agent 365 license is needed to see the Risks column in the Agent Registry and the details on an agent's Security tab, and Contoso's E5 tenant has neither. The Entra licensing page adds that Agent 365 is included in Microsoft 365 E7 and is otherwise sold as an add-on for Microsoft E5, A5, or Business Premium, licensed per user, so buying Agent 365 licenses turns on both views.

Why the other options are wrong:

  • A. Microsoft 365 Copilot licenses, the AI assistant component that Microsoft 365 E7 adds on top of E5 Copilot is part of the E7 bundle, which makes it tempting, but the Risks column and the Security tab check for E7 or Agent 365, and a Copilot license is neither.
  • C. Microsoft Purview Suite licenses, since each Security tab action opens a Microsoft Purview solution The Security tab does hand off to Purview, but the license it checks is E7 or Agent 365. The Purview Suite, paired with the Defender Suite, is only one eligible base for buying Agent 365.
  • D. Microsoft Entra Suite licenses, the identity component that Microsoft 365 E7 adds on top of E5 Entra Suite also ships in E7, yet it doesn't unlock the registry's Risks column or the Security tab. Microsoft Entra Agent ID itself is available to every Microsoft Entra customer.

Memory hook: Risks column and Security tab: no E7 or Agent 365, no data.

Microsoft Learn: Agent details

Woodgrove Bank labels Finance workbooks in Excel for Windows with a label that encrypts them and grants the Finance group the Editor permission level, then saves them to a SharePoint site. Copilot in Excel for Windows summarizes an open workbook, but Copilot Chat never finds or cites these files, SharePoint search can't find words inside them, and Excel for the web can't open them. What should you do?

Correct answer: B. Run Set-SPOTenant -EnableAIPIntegration $true, then have the existing labeled files edited or uploaded again.

Until sensitivity labels for Office files in SharePoint and OneDrive are enabled, those services can't process encrypted files, so search, Office for the web, and similar features fail, and Copilot reaches such files only as data in use in Office apps on Windows. Turn it on with Set-SPOTenant -EnableAIPIntegration $true or Turn on now in the Purview portal. Files labeled earlier don't change until they're edited or uploaded again.

Why the other options are wrong:

  • A. Run Set-SPOTenant -EnableSensitivityLabelforPDF $true so SharePoint and OneDrive can process the workbooks. That parameter adds PDF support for sensitivity labels in SharePoint and OneDrive; it isn't the setting that lets the services process encrypted Excel files.
  • C. Grant the Finance group Full Control on the SharePoint site so Copilot can read the encrypted workbooks. Finance users can already open the files, and site permissions don't let SharePoint process content that a label encrypted.
  • D. Change the label so the Finance group gets the Owner permission level, which adds the EXTRACT usage right. The Editor level already includes Copy, the EXTRACT usage right, which is why Copilot in Excel for Windows can summarize an open workbook.

Memory hook: Encrypted files invisible to search and Copilot Chat: enable labels for SharePoint and OneDrive, then re-save the files.

Microsoft Learn: Sensitivity labels SharePoint OneDrive files

In Microsoft Purview Data Security Posture Management, the weekly default data risk assessment flags Fabrikam's Deals site: many files contain sensitive information types but carry no sensitivity label. The deal team still needs Copilot to use the site's other content, and the flagged files must end up protected by labels. Which remediation from the site's Protect tab fits this finding?

Correct answer: D. Create an auto-labeling policy, which applies a sensitivity label to files with sensitive data.

The data risk assessments page lists four Protect tab actions: restrict access by label, restrict all items, create an auto-labeling policy, and create retention policies. The auto-labeling action is the one for sensitive information found in unlabeled files: Information Protection applies a sensitivity label automatically, so the files gain protection while the rest of the site stays available to Copilot.

Why the other options are wrong:

  • A. Restrict access by label, which creates a DLP policy that stops Copilot using labeled files. The DLP policy behind restrict access by label matches selected sensitivity labels, and these files have no label, so it wouldn't act on them.
  • B. Restrict all items, which uses Restricted Content Discovery to exempt the site from Copilot. Restrict all items applies Restricted Content Discovery to the whole site, so Copilot loses the other content the deal team still needs.
  • C. Create retention policies, which delete site content that hasn't been accessed for three years. Retention policies from this action delete stale content; they don't label sensitive files that are still in use.

Memory hook: Sensitive but unlabeled in a data risk assessment: answer with an auto-labeling policy.

Microsoft Learn: Data security posture management oversharing

Two days ago, Tailspin Toys' AI Administrator added the executive team's Microsoft Entra ID group under Manage access settings for Microsoft Copilot Dashboard. The executives can open the dashboard in the Viva Insights web app, but the AI Administrator still can't. What should the admin do?

Correct answer: C. Add their own account in the same access settings and allow up to 24 hours.

The article on managing Copilot Dashboard settings notes that the AI Administrator doesn't have automatic access to the Viva Insights web app and must add themselves through the same Manage access settings page. Changes to that access list take effect within 24 hours. The executives got in because their group was added, and the admin's own account wasn't part of it.

Why the other options are wrong:

  • A. Ask a Global Administrator for the Reports Reader role, which opens the dashboard. Reports Reader opens the admin center usage reports. It isn't one of the ways a user gains Copilot Dashboard access.
  • B. Assign themselves a Microsoft Copilot license, which dashboard viewers must hold. Neither a paid Viva Insights license nor a Copilot license is required to view the Copilot Dashboard.
  • D. Turn the old Copilot Dashboard feature access control back on with PowerShell. The earlier Copilot Dashboard controls in the admin center and PowerShell are no longer available. Access now runs through the Viva Insights web app.

Memory hook: The AI Administrator isn't auto-enabled: add your own account to see the Copilot Dashboard.

Microsoft Learn: Manage settings Copilot dashboard

Fabrikam runs customer-facing Copilot Studio agents on its public website and forecasts about 1.5 million Copilot Credits over the next 12 months, most of it in two seasonal peaks. Finance wants a discount for committing up front, wants credits unused in a quiet month to stay usable later in the year, and wants the agents to keep answering if demand beats the forecast. Which purchasing approach meets all three goals?

Correct answer: C. Buy a Copilot Credit pre-purchase plan sized to the forecast, and keep a pay-as-you-go billing policy linked to cover usage beyond it.

The usage-based billing comparison page describes Copilot Credit pre-purchase plans as discounted commit units that cover eligible usage across a one-year term or until the units run out, so a quiet month's credits stay available for the peaks. The same page says usage draws down the pre-purchase balance first and can then bill through pay-as-you-go when it's enabled, which keeps the agents answering past the forecast.

Why the other options are wrong:

  • A. Link the environments to an Azure subscription through a pay-as-you-go billing policy only, and count the metered rate as the discount. Pay-as-you-go has no upfront commitment and bills usage at the applicable rate. It keeps the agents running but gives Finance no commitment discount.
  • B. Buy prepaid Copilot Credit capacity packs sized to one twelfth of the forecast each month, and let quiet-month credits carry into the peaks. Copilot Studio enforces purchased capacity monthly, and unused Copilot Credits don't carry over to the next month, so quiet-month credits are lost rather than saved for the peaks.
  • D. Assign Microsoft 365 Copilot licenses to the customer-service staff, so the agents' conversations with website visitors are zero-rated. The no-charge inclusion covers employee-facing use by people licensed for Microsoft 365 Copilot. Website visitors aren't licensed users in Fabrikam's tenant, so their conversations still consume credits.

Memory hook: Pre-purchase plan: a discounted year-long pool. Capacity packs: use them each month or lose them. Pay-as-you-go: the overflow.

Microsoft Learn: Usage based billing compare dashboard views

Fabrikam's Confidential label encrypts files and assigns the Co-Author permission level to Add all users and groups in your organization. Labels are enabled for Office files in SharePoint and OneDrive, and the files are explicitly shared with an Agent 365 agent instance (preview). The agent instance summarizes unlabeled files but returns nothing from Confidential ones. What should the administrator change?

Correct answer: C. Add the agent instance to the label's encryption settings by name, with at least VIEW and EXTRACT

Agent instances, agents with their own identity, are available through the Frontier preview program. The Purview page for Agent 365 sets two conditions for an agent instance to use labeled files: the files must be explicitly shared with it, and label encryption must explicitly grant the agent instance the VIEW and EXTRACT usage rights. It adds that a label configured for Add all users and groups in your organization or Add any authenticated users isn't sufficient. Sharing and label enablement are already in place, so the explicit grant is the missing piece.

Why the other options are wrong:

  • A. Grant the agent instance the Files.Read.All Microsoft Graph permission on its Permissions tab An API permission doesn't satisfy a label's encryption. The encryption itself has to grant the agent instance the VIEW and EXTRACT usage rights.
  • B. Change the label's assignment to Add any authenticated users, so accounts beyond the org list qualify The same page names Add any authenticated users as insufficient, just like Add all users and groups in your organization, so the agent instance still gets no usage rights.
  • D. Share the Confidential files with the agent instance a second time, this time with edit permission The files are already explicitly shared, which meets the sharing condition. Sharing them again changes nothing about the rights that the label's encryption grants.

Memory hook: Encrypted file and an agent instance: share it, and name the agent in the label with VIEW and EXTRACT.

Microsoft Learn: AI agent 365

Woodgrove Bank already licenses Microsoft 365 E5 for every user. A 25-person automation team builds and owns about 400 agents across Copilot Studio and Microsoft Foundry, and the bank wants the generally available Microsoft Agent 365 to observe, govern, and secure them. Which licensing action enables Agent 365 and covers those agents?

Correct answer: A. Assign Agent 365 licenses to the 25 team members, since agents that a licensed user owns or manages need no license of their own.

The Agent 365 overview says the product has been generally available for the Commercial segment since May 1, 2026, is licensed per user, and needs at least one user with a qualifying Agent 365 license before it can be enabled. The Frontier program FAQ adds that under general availability every agent managed or owned by a licensed user is covered by that user's Agent 365 or Microsoft 365 E7 license. Licensing the 25 owners covers the 400 agents.

Why the other options are wrong:

  • B. Assign Microsoft 365 Copilot licenses to the 25 team members, since the Copilot add-on includes Agent 365 for agents its users build. Agent 365 is its own subscription, included in Microsoft 365 E7 but not in the Copilot add-on, so Copilot licenses don't enable it.
  • C. Buy about 400 Agent 365 licenses and assign one to each agent instance before those agents can be governed. Per-instance licensing is how the Frontier preview works. Under general availability Agent 365 is licensed per user, and agents don't require their own Agent 365 license.
  • D. Enroll the tenant in the Frontier program, since Frontier turns on Agent 365 for Microsoft 365 E5 tenants without separate licenses. Frontier previews Agent 365 features and requires at least one E7 license in the tenant. It isn't a route to the generally available product for an E5 tenant without Agent 365 licenses.

Memory hook: Agent 365 licenses people, not agents: license the owners and their agents are covered.

Microsoft Learn: Microsoft agent 365: Frontier

Contoso's Copilot program lead holds the AI Administrator role. In Copilot, then Cost Management, she can change the limits and alerts on the existing spending policy, but she can't create the new Cowork spending policy for the Legal group. Which role should she also be given so she can create it?

Correct answer: C. Billing Administrator

The usage-based billing role requirements separate editing from creating. AI Administrator and License Administrator can edit spending policies and manage limits and alerts, but they can't create spending policies. Global Administrator and Billing Administrator are the roles that run the initial setup, which activates the default spending policy, and that set billing methods in policies, so Billing Administrator lets her add the Legal policy without Global Administrator.

Why the other options are wrong:

  • A. License Administrator License Administrator sounds like it should govern consumption, but it has the same boundary as AI Administrator here: it can edit spending policies and limits, not create them.
  • B. Global Reader Global Reader is a reader-based role that can view consumption dashboards and reports. It can't create or change spending policies.
  • D. Office Apps Administrator Office Apps Administrator creates Cloud Policy configurations for the Microsoft Copilot app. It isn't one of the roles that manage spending policies.

Memory hook: Spending policies: AI and License admins edit, Global and Billing admins create.

Microsoft Learn: Usage based billing manage Copilot credits

Fabrikam runs production agents in Amazon Bedrock and Google Vertex AI. The AI administrator wants those agents listed in the agent registry in the Microsoft 365 admin center for central visibility and governance, without asking the agent teams to do any development work. What should the administrator do?

Correct answer: B. From the All agents page, open Connected platforms, connect each environment with its credentials, then select Sync agents.

Connected platforms is the registry's route for agents that live on external AI platforms, and Amazon Bedrock and Google Vertex AI are both supported. From its web part on the All agents page, the administrator selects Manage, adds a connection per environment with its platform, region, and credentials, validates and saves it, and then selects Sync agents to pull those agents into the registry. Nothing changes in the agents' code, so the teams do no development work.

Why the other options are wrong:

  • A. Integrate each agent with the Agent 365 SDK so that it gets a Microsoft Entra agent identity and shows up in the registry. The Agent 365 SDK is a real way to bring outside agents under the control plane, but it's development work for every agent team, which the stem rules out.
  • C. Export each agent as a .zip package from its platform, then upload the packages with Add agent on the All agents page. Add agent uploads the .zip agent package that Copilot Studio and Agent Builder export; Connected platforms is the documented route for Bedrock and Vertex AI agents.
  • D. Register each agent's endpoint as a bring-your-own MCP server with the Agent 365 CLI, then approve it on the Tools Requests tab. A bring-your-own MCP server registers a tool that agents call, so the Bedrock and Vertex AI agents themselves still wouldn't appear in the registry.

Memory hook: Agents running in another cloud: connect the platform, then Sync agents.

Microsoft Learn: Connected platforms

At Woodgrove Bank, User access under Agents then Settings is set to Specific users/groups with only the AI-Pilot group selected. A loan officer who isn't in AI-Pilot can't use an agent whose Available to setting is All users in the organization. The bank wants this officer to use agents without opening agents to every employee. What should the administrator do?

Correct answer: D. Add the loan officer, or a security group that contains the officer, to the User access setting.

User access under Agents then Settings is the tenant-wide gate on using agents. With Specific users/groups selected, the Agent settings page says only the users or groups picked there can use agents, even if they have permission to install and use agents from the registry. Available to is already All users, so the officer's block comes from User access; adding the officer, or a group containing the officer, fixes it for that person without opening agents to everyone.

Why the other options are wrong:

  • A. Change the agent's Available to option to Specific users or groups, and select the loan officer. Available to already includes the officer as All users, and narrowing it doesn't lift the tenant-wide User access gate.
  • B. Set Sharing under Agents then Settings to All users so the maker can share the agent with the officer. Sharing controls how Agent Builder makers share their agents. It grants nobody the right to use agents that User access leaves out.
  • C. Set the agent's Installed for option to include the loan officer so that it's preinstalled for them. Preinstalling looks like a way to hand the officer the agent, but Installed for only controls who gets it preinstalled, and User access still refuses use.

Memory hook: Available to scopes one agent; User access is the tenant-wide gate on using any agent.

Microsoft Learn: Agent settings

Litware's on-call team wants Service health email only when a Copilot problem makes the service or a major function unavailable. It doesn't want mail about problems that affect some users and usually come with a workaround. What should the admin configure?

Correct answer: B. Customize, then Email in Service health, with incidents selected and advisories cleared

The service health article defines an incident as a critical issue in which the service or a major function is unavailable, and an advisory as a problem affecting some users while the service stays available, often with a workaround. Under Customize, then Email, each admin chooses incidents or advisories, the services to cover, and up to two addresses, so incidents only for Copilot matches the on-call rule.

Why the other options are wrong:

  • A. Customize, then Email in Service health, with advisories selected and incidents cleared This is the reverse. Advisories are the limited-impact problems with workarounds that the team wants to skip.
  • C. Customize, then Custom view in Service health, with only Copilot selected Custom view only filters which services the dashboard shows. It sends no email.
  • D. Message center preferences that email a weekly digest of Copilot posts A weekly digest summarizes Message center announcements once a week. It can't alert the team when the service or a major function goes down.

Memory hook: Incident: down. Advisory: degraded, often with a workaround. Choose under Customize, then Email.

Microsoft Learn: View service health

Fabrikam creates new claims-processing agent identities from one agent identity blueprint every week. Security wants a single Conditional Access policy that blocks every claims agent, current and future, from a finance API registered in Microsoft Entra ID. No step may be required per new agent, and agents built from other blueprints must stay out of scope. How should the policy's agent assignment be set?

Correct answer: C. Include the claims blueprint so every agent identity derived from it is covered.

The Conditional Access for agents page says a policy applied at the agent identity blueprint level automatically covers all agent identities derived from it, including new ones added in the future. In the policy builder, the blueprint is picked on the Agent blueprint principals tab of the agent selection. That meets both constraints: no action per new agent, and agents from other blueprints are never in scope.

Why the other options are wrong:

  • A. Include agents by a custom security attribute that is set on each new claims agent. As written, this needs the attribute set on every new claims agent, which is the per-agent step the requirement forbids; targeting the blueprint covers new agents with no extra step.
  • B. Include each existing claims agent identity, then add new ones every week. Picking identities one by one never covers agents created after the policy is saved, so every new agent needs a manual edit.
  • D. Include All agent identities so every current and future agent is covered. All agent identities also blocks agents built from every other blueprint, which the requirement rules out.

Memory hook: Target the blueprint to cover today's agents and tomorrow's from the same template.

Microsoft Learn: Agent ID

Woodgrove Bank's change board wants most users to receive deferred-capable Copilot updates later so it can validate them first. A 40-member IT pilot security group must get the same updates as soon as they reach general availability. The admin opens Copilot release preferences: General Availability in Copilot settings. What should she configure?

Correct answer: A. Select Deferred Release, then add the IT pilot group as an exception so it stays on Standard Release.

Copilot release preferences offer Standard Release, the default, and Deferred Release, which holds major deferred-capable updates for 30 days after the Standard rollout begins. You choose the option most users should get, then add up to 100 exceptions to the other one, and each member of an excepted group counts toward that limit. Deferred Release with the 40-member pilot group excepted to Standard gives the pilot general availability timing while everyone else waits.

Why the other options are wrong:

  • B. Select Deferred Release, then set Copilot Frontier to specific user groups and add the IT pilot group. Frontier gives early access to preview features before they're generally available. It doesn't place the pilot group on the Standard Release timing for GA updates.
  • C. Select Standard Release, then add the IT pilot group as an exception so it moves to Deferred Release. This mirrors the right design but inverts it: everyone stays on Standard Release and only the IT pilot group is delayed, the opposite of what the change board asked for.
  • D. Select Standard Release, then give the IT pilot group targeted release under Organization profile. Leaving the tenant on Standard Release delays nobody, and targeted release under Organization profile belongs to the older model that doesn't govern deferred-capable Copilot updates.

Memory hook: Pick the ring most users ride, then except the rest: up to 100 users, each group member counted.

Microsoft Learn: Configure release options

A Reports Reader at Litware exports the Copilot usage report and finds anonymized values where user names should be. The privacy office approves showing names so managers can follow up with inactive users. What change reveals the names?

Correct answer: B. Have a Global Administrator clear the concealment option in Org settings, then Services, then Reports.

The usage reports overview says all reports hide usernames, display names, groups, and sites by default, and Global administrators can reveal them by clearing Conceal user, group, and site names in all reports under Settings, then Org Settings, then Services, then Reports. The setting is tenant-wide: it also governs the Microsoft Graph reports API, Power BI, and the Teams admin center reports, and showing identifiable user information is a logged event in the Purview audit log.

Why the other options are wrong:

  • A. Have an AI Administrator turn off name concealment under Copilot, then Settings, then Data access. Concealment isn't a Copilot setting. It's one org-wide setting under Org settings that Global administrators change.
  • C. In the Copilot usage report, open Choose columns and add the User name and Display name columns. Choose columns adds or removes columns, but the names in them stay concealed while the org setting is on.
  • D. Pull the same data from the Microsoft Graph reports API, which the admin center setting doesn't cover. The same setting also applies to the Microsoft 365 usage reports in Microsoft Graph and Power BI, so the API returns concealed values too.

Memory hook: Names are hidden in every report by default, and one Global Admin setting in Org settings reveals them everywhere.

Microsoft Learn: Activity reports

Topic 7 of 7

Mixed objectives (10 questions)

Questions from Teams, Channels, and Apps · Sensitivity Labels and Data Classification · Teams Meetings and Phone · SharePoint Governance and Compliance · Data Lifecycle and Records Management · SharePoint Permissions and Sharing · Identity Governance · SharePoint Content, Metadata, and Search.

Show the 10 questions and explanations

Contoso's Merger team finished its project. Members must still be able to read every conversation and file for the next two years, but no one may post new messages and members may not edit files. The team might need to be reactivated if the deal reopens. What should the Teams administrator do?

Correct answer: A. Archive the team and make its SharePoint site read-only for team members

Archiving stops all activity in a team while members keep read access to conversations and files in standard and private channels, and an archived team can be reactivated at any time. The Archive or delete a team page adds an option to make the SharePoint site read-only for team members, which stops their file edits; owners can still edit. Deletion is the wrong tool, because a deleted team comes back only by restoring its group within 30 days.

Why the other options are wrong:

  • B. Turn on moderation in every channel so that only the team owners can post Moderation exists only in standard channels, can still allow member replies, and leaves files editable, so it doesn't make the team read-only.
  • C. Delete the team, and restore its Microsoft 365 group if the deal reopens A deleted team can't be restored directly; its Microsoft 365 group is kept for only 30 days, far short of the two years required.
  • D. Change the team to private and remove the members from its SharePoint site Removing members from the site takes away the read access they must keep, and changing privacy has no effect on who can post.

Memory hook: Finished but maybe needed again: archive, which is reversible and read-only; delete only when a 30-day undo is enough.

Microsoft Learn: Archive or delete a team

Contoso has two sensitivity label policies. All Users, order number 1, applies to everyone and sets General as the default label for documents. Legal, order number 0, is published to the Legal group and sets Confidential as the default label for documents. Both policies were published two weeks ago, yet Legal users still get General on new documents. What should the administrator do?

Correct answer: B. Move the Legal policy down the list so that it has a higher order number than All Users

The sensitivity labels overview explains that a user assigned several label policies gets all of their labels, but when settings conflict, the setting from the policy with the highest order number, shown at the bottom of the Label policies list, is applied. Legal sits at order 0, the lowest priority, so the General default from All Users wins for Legal users. Moving the Legal policy down until it has the higher order number makes its Confidential default the one that applies.

Why the other options are wrong:

  • A. Wait up to 24 hours for the label policy settings to replicate to the users' Office apps Allowing 24 hours is the right first check for a new policy, but these have been live for two weeks. The result is the documented conflict rule, not a replication delay.
  • C. Move the Confidential label below General in the labels list so that it has the higher label priority Label order sets label priority, which matters for justification prompts and auto-labeling, but it doesn't decide which policy's default label setting wins. That conflict is settled by policy order.
  • D. Turn on mandatory labeling in the Legal policy so that its users must choose a label for every document Mandatory labeling only forces a choice when content is unlabeled, and a default label takes priority over it. The General default from the winning policy still applies.

Memory hook: Label policy conflict: the policy at the bottom of the list, with the highest order number, wins each setting.

Microsoft Learn: Sensitivity labels

Contoso's CISO wants Copilot kept out of meetings organized by the Acquisitions team. An admin set the Copilot setting in the Acquisitions team's meeting policy to Off. Three weeks later, licensed attendees used Copilot throughout a meeting organized by an Acquisitions analyst. What explains this?

Correct answer: B. Off sets only the default in meeting options, and the analyst turned Copilot back on for that meeting.

Set to Off (Disabled), the Copilot policy value only makes Off the starting value in each new meeting's options. The Manage Teams meeting transcription page states that organizers with this policy can change it to Only during the meeting or During and after the meeting, meeting by meeting. None of the four Copilot values locks the option at Off; the one enforced value, On with saved transcript required, locks it at During and after the meeting.

Why the other options are wrong:

  • A. The policy change hasn't reached the analyst's Teams client yet, so the previous value still applies. Three weeks is far past any policy propagation delay. The policy is in effect; Off just isn't enforced.
  • C. The analyst's Microsoft Copilot license takes precedence over a meeting policy that is set to Off. The license is a prerequisite for using Copilot, not an override; it doesn't decide what the organizer's meeting option allows.
  • D. Transcription is still allowed in the policy, and an allowed transcript overrides the Copilot setting. Transcription doesn't override the organizer's Copilot option. When that option is Off, no one can use Copilot, and recording and transcription are off for the meeting too.

Memory hook: Policy Off is a default, not a block: organizers can turn Copilot back on per meeting.

Microsoft Learn: Copilot Teams transcription

Contoso has assigned Microsoft Copilot licenses and is preparing SharePoint for a wider rollout. The Workplace Investigations site must stop surfacing in organization-wide search results and Copilot responses while its owners review permissions. No one's access to the site may change, and members must still be able to search within the site. What should you do?

Correct answer: B. Turn on Restricted Content Discovery for the site in the SharePoint admin center.

Restricted Content Discovery is the per-site discoverability control. In the SharePoint admin center, open Active sites, select the site, and on the Settings tab turn on Restrict content from Microsoft Copilot, or run Set-SPOSite with -RestrictContentOrgWideSearch $true. Content stops surfacing in organization-wide search and Copilot responses, permissions don't change, and searches that start from the site itself keep working, which is the combination required here.

Why the other options are wrong:

  • A. Enable Restricted SharePoint Search and leave the site off the allowed list. Restricted SharePoint Search is retiring, and new enablement has been blocked since July 31, 2026. It was also a tenant-wide allow list that narrowed search for every site not on the list.
  • C. Apply restricted site access to the site with a security group of its current members. Restricted site access is an access control: anyone outside the group loses access even through earlier links, and members still see the content in Copilot.
  • D. Set "Allow this site to appear in Search results" to No in the site's search settings. Setting it to No blocks the site's content from organization-wide search and from site-specific search, so members lose search inside the site.

Memory hook: Hide from Copilot, keep access and in-site search: Restricted Content Discovery.

Microsoft Learn: Restricted content discovery

Litware's legal team stores signed contracts in a SharePoint site. They want contract owners to declare individual contracts as records so they can't be edited or deleted, and they want a named reviewer to approve deletion when each contract reaches 10 years. Which approach meets both requirements?

Correct answer: B. A retention label that marks items as records, with disposition review, published to the site in a label policy

The comparison table in the retention overview shows that declaring an item as a record and disposition review are retention label capabilities, not retention policy capabilities. A label works at the item level, so owners can apply it to individual contracts, and a retention label policy publishes it to the SharePoint site. At the end of the 10 years, disposition review sends each contract to the named reviewer before anything is deleted.

Why the other options are wrong:

  • A. An eDiscovery hold on the contracts site that the named reviewer releases as each contract reaches 10 years An eDiscovery hold preserves content for a case, but it doesn't declare records or trigger a review at a set age. Tracking release dates by hand isn't a retention control.
  • C. A retention policy for the SharePoint site that retains content for 10 years and then deletes it automatically A retention policy applies one setting to a whole location and can retain and then delete, but it can't declare records or send items to disposition review. Users also can't apply it to individual contracts.
  • D. A sensitivity label that encrypts the contracts and grants users the Viewer permission level so they can't edit them Encryption controls who can open or change content, not how long it's kept. It offers no records declaration and no reviewer step before deletion.

Memory hook: Records or disposition review in the requirement: that's a retention label, never a retention policy.

Microsoft Learn: Purview: Retention

Tailspin Toys' records manager turns on an auto-apply retention label policy that applies Contract 10 Years to SharePoint documents matching the keyword query "master services agreement". Simulation reported 1,200 matches. Ten days later, 800 documents carry the new label, and the other 400 still carry General 2 Years, which users applied manually last year. What should the records manager do so the policy labels the 400 documents?

Correct answer: A. Remove General 2 Years from those documents so they become eligible for the auto-apply policy

The auto-apply article states that an auto-apply retention label policy never replaces a retention label already applied to content, and that relabeling with your conditions means manually removing the current label first. Simulation counts every matching item, but once the policy is on, only content that isn't already labeled is eligible. That's why 400 of the 1,200 matches kept General 2 Years, and why removing that label is the step that lets the policy apply Contract 10 Years.

Why the other options are wrong:

  • B. Edit the policy to turn on the option that replaces a manually applied label with lower priority Replacing a lower-priority manually applied label is an option in sensitivity label auto-labeling policies. Retention auto-apply policies have no such setting and never replace an existing retention label.
  • C. Move Contract 10 Years above General 2 Years in the retention labels priority order Retention labels have no priority order, unlike sensitivity labels. An item holds one retention label at a time, and no ordering makes a new label win.
  • D. Restart the policy's simulation so that it reevaluates the 400 documents against the query Simulation already counted those 400 documents. Once the policy is on, labeled items stay ineligible, so another simulation changes nothing.

Memory hook: Auto-apply retention never overwrites a retention label: remove the old one first.

Microsoft Learn: Apply retention labels automatically

Fabrikam's Marketing site is connected to a public Microsoft 365 group, so Everyone except external users has Edit through the site's Members group. Last year the site owner also added Everyone except external users to a custom SharePoint group, Marketing Readers, which has Read. Today the owner changes the group's privacy to Private. What access does Everyone except external users have on the site afterward?

Correct answer: D. Read, because the change removes the claim from the default Members group only.

By design, the Everyone except external users claim sits in the Members group of a public group-connected site and is removed when the group is changed to Private. The SharePoint troubleshooting article on this behavior notes that the removal touches only the default Members group, which is why its workaround is a separate SharePoint group. Marketing Readers keeps the claim, so everyone in the organization still has Read on the site.

Why the other options are wrong:

  • A. Edit and Read, because a privacy change affects who can join the group, not site permissions. The privacy change does touch site permissions: it removes the claim from the Members group, so the Edit grant is gone.
  • B. Edit, because the claim stays in the Members group until an admin removes it by hand. No admin action is needed; the claim is removed from the Members group automatically when the group becomes Private.
  • C. None, because the change to Private removes the claim from every SharePoint group on the site. The conversion removes the claim only from the default Members group. A copy in a custom SharePoint group survives, which is the trap in assuming the site is now closed.

Memory hook: Public to Private strips Everyone except external users from Members only; check custom groups for leftovers.

Microsoft Learn: Everyone except external user removed

At Contoso, Nadia will assign Microsoft Entra roles to other administrators and edit Privileged Identity Management role settings such as the activation maximum duration and approval requirements. Contoso follows least privilege. Which built-in role is the least privileged role that covers both tasks?

Correct answer: D. Privileged Role Administrator

The PIM role settings article requires at least the Privileged Role Administrator role to manage role settings, and the PIM overview says only Privileged Role Administrators or Global Administrators can manage Microsoft Entra role assignments for other administrators. The least privileged roles by task reference also lists Privileged Role Administrator for adding a user to a directory role, so it covers both tasks without Global Administrator's tenant-wide reach.

Why the other options are wrong:

  • A. Security Administrator Security Administrator can view Microsoft Entra role assignments in PIM, but managing assignments for other administrators is limited to Privileged Role Administrator and Global Administrator.
  • B. Privileged Authentication Administrator The similar name is the trap: Privileged Authentication Administrator manages authentication methods and passwords for any user, but it can't manage role assignments or PIM role settings.
  • C. Global Administrator Global Administrator can do both tasks but grants far more than they need, so it fails the least-privilege requirement.

Memory hook: Assigning roles and setting PIM policy: Privileged Role Administrator, not Global Administrator.

Microsoft Learn: PIM configure

Litware requires approval to activate the Exchange Administrator role in Privileged Identity Management, and the role settings name no approvers. Tomas, who is eligible for the role, submits an activation request with a justification. Who can approve the request?

Correct answer: D. Anyone who holds Privileged Role Administrator or Global Administrator as an active assignment

The PIM role settings article says that when approval is required and no specific approvers are selected, active Privileged Role Administrators and Global Administrators become the default approvers. Eligible holders don't count until they activate, which is why the same article warns of a tenant lockout when every holder of those roles is eligible, none is active, and no approvers are named. Naming specific approvers (Learn recommends at least two) and keeping emergency access accounts active avoids it.

Why the other options are wrong:

  • A. Anyone who holds the Exchange Administrator role as an active assignment Holding the same role gives no approval right; without named approvers, the defaults are active Privileged Role Administrators and Global Administrators.
  • B. Anyone eligible for Privileged Role Administrator or Global Administrator, even without activating Learn's line that an approver needs no role applies to approvers you name; default approvers must hold one of those two roles actively.
  • C. Tomas's manager, as recorded in the manager attribute of his user profile Manager approval is an option in entitlement management access package policies, not a PIM default for Microsoft Entra role activation.

Memory hook: No approvers named? Active Privileged Role Administrators and Global Administrators approve by default.

Microsoft Learn: PIM change default settings

Litware's intranet team created a promoted result for the query "benefits enrollment" in classic search settings in the SharePoint admin center. Users who search from the SharePoint start page don't see it on the All tab. The tenant supports bookmarks in Microsoft Search. What should the search admin do so the answer appears for organization-wide searches?

Correct answer: C. Create a bookmark for the benefits page in the Microsoft 365 admin center.

Microsoft Search, the modern experience on the SharePoint start page, uses bookmarks where classic search uses promoted results. The page comparing classic and modern search states that in clouds that support bookmarks, only bookmarks show at the organization level on the All tab. Classic search is managed in the SharePoint admin center, while Microsoft Search answers such as bookmarks are managed in the Microsoft 365 admin center.

Why the other options are wrong:

  • A. Request a full re-index of the site that hosts the benefits page. Re-indexing refreshes content in the index both experiences share; it doesn't turn a classic promoted result into an organization-level answer.
  • B. Create a tenant-level custom result source that boosts the benefits page. When Microsoft Search is fully deployed, custom result sources at the site collection or tenant level don't affect its results.
  • D. Set the page's managed properties to Sortable and Refinable in the search schema. Microsoft Search doesn't support sorting or refiners, so the Sortable and Refinable settings don't affect it, and they never create an answer anyway.

Memory hook: Classic search promotes results; Microsoft Search uses bookmarks, managed in the Microsoft 365 admin center.

Microsoft Learn: Differences classic modern search