What active Exam AB-650 measures
Exam AB-650: Administering Microsoft 365 and AI Services reflects a major evolution of Microsoft 365 administration. The role still requires tenant, identity, Exchange, Teams, SharePoint, OneDrive, security, compliance, resilience, and health skills. It now explicitly includes Microsoft 365 Copilot, agents, connected AI capabilities, Microsoft Entra Agent ID, Agent Registry, Agent 365, data security for AI, AI service cost, adoption, and service health.
The official audience profile describes an administrator who configures, manages, secures, and governs Microsoft 365 tenants, workloads, and AI services at enterprise scale. Candidates should have experience with Microsoft 365 workloads and Microsoft Entra ID, understand Defender XDR capabilities, and be familiar with Microsoft Graph PowerShell. The role collaborates with architects and administrators across identity, endpoints, infrastructure, security, compliance, and applications. This is not an isolated “Copilot admin” exam.
The largest domain is governance and security, but it cannot be separated from tenant operations or AI administration. A Conditional Access policy depends on identity and method readiness. A DLP policy depends on classification, scope, workload behavior, investigation, and user communication. Copilot safety depends on existing permissions and data lifecycle. Agent governance depends on identity, tools, ownership, monitoring, and the ability to revoke access. Use the five-phase AB-650 roadmap to study those relationships.
Domain 1: configure and manage Microsoft 365 tenants and workloads
Operate the tenant as a service
Tenant setup includes organization branding, the company profile, security and privacy settings, domains, licensing, Backup, network insights, and Service health. Adding a custom domain requires ownership verification and appropriate DNS records. Setting a verified domain as default affects newly created users; it does not silently rename existing identities. Operational judgment means knowing the requested outcome and the propagation, dependency, support, and rollback implications.
Licensing deserves more than manual assignment. Group-based licensing can attach product licenses to eligible group members and expose processing errors for remediation. It does not grant directory roles, SharePoint permissions, team membership, mailbox delegation, or access to every file. Administrators need to distinguish product entitlement from workload authorization. AB-650 also expects administration and monitoring of licenses for Microsoft 365 Copilot, Microsoft Agent 365, and Microsoft Copilot Studio, including applicable pay-as-you-go models and consumption signals.
Microsoft 365 Backup introduces protection policy, restore-point, restore execution, and monitoring tasks. Backup is not retention. Backup supports recovery from loss or damage; retention supports lifecycle, records, preservation, and deletion requirements. A mature administrator can restore selected supported content, validate the result with the owner, communicate status, and preserve evidence without assuming that a successful job automatically meets the business recovery objective.
Service health shows tenant-relevant incidents and advisories. Network Connectivity Insights provides evidence about connectivity paths and protocol conditions. When one office reports intermittent access, the administrator should correlate user timing, affected workloads, Service health, local network changes, DNS, HTTPS, WebSocket, proxy, interception, and endpoint evidence instead of treating every symptom as a Microsoft outage.
Manage Exchange, Teams, SharePoint, and OneDrive
Exchange tasks include creating and managing user and shared mailboxes. A shared mailbox gives authorized members a common inbox and sending identity; it differs from a distribution group, which distributes messages. Delegation, licensing, size, archive, and compliance behavior should be verified for the exact scenario.
Teams administration includes teams, channels, owners, members, guest and external access, and meeting settings such as transcription and Copilot behavior. SharePoint and OneDrive administration includes sites, ownership, permissions, sharing, search, and Copilot readiness. These workloads form much of the organizational content boundary that Copilot and agents can use, so stale ownership and permissive sharing are both collaboration and AI-readiness problems.
SharePoint Advanced Management, Microsoft Search controls, data access governance, restricted content discovery, and site exclusions can reduce risk in supported scenarios. They should not become permanent substitutes for fixing source authorization. Temporary controls need owners, a reason, a review date, success criteria, and an exit plan.
Domain 2: govern and secure Microsoft 365 tenants and workloads
Identity, delegation, and privileged roles
Create and manage users, contacts, guests, security groups, and Microsoft 365 groups with clear ownership and lifecycle. Administrative units can scope supported role assignments to a subset of directory objects, such as one region. That supports least privilege better than making every regional help-desk operator a tenant-wide administrator. Bulk management through Microsoft Graph PowerShell still requires permission review, error handling, auditability, and validation of the affected objects.
Guest access should be justified, time-aware, reviewable, and removable. End-of-project cleanup includes group memberships, Teams, SharePoint, applications, access packages, sponsorship, and the guest identity itself. Disabling audit or converting a stale guest into an administrator is never remediation.
Microsoft Entra Privileged Identity Management reduces standing privilege through eligible assignments and controlled activation. Depending on policy, activation can require multifactor authentication, authentication context, justification, approval, and a bounded duration. PIM also supports notifications, audit history, and access reviews. Keep role scope narrow: Exchange administration does not automatically require Global Administrator.
Authentication, Password Protection, SSPR, and Conditional Access
Authentication methods should align with risk. For privileged users, prioritize phishing-resistant authentication such as supported passkeys or FIDO2 security keys through authentication strengths. Microsoft Entra Password Protection blocks known weak and organization-specific banned passwords. Self-service password reset lets registered users recover access under configured policy. These capabilities complement rather than replace multifactor authentication and Conditional Access.
Conditional Access is Microsoft's Zero Trust policy engine. It combines identity, group or agent, application, location, device, risk, and other signals, then blocks access or imposes grant controls such as multifactor authentication, authentication strength, a compliant device, approved client, app protection, password change, or terms of use. Policies apply after first-factor authentication and are not a denial-of-service defense.
Safe rollout is exam-critical: define target users and resources, preserve monitored emergency access, verify method readiness, use report-only mode, run What If, inspect sign-in logs, communicate effects, then enforce in stages. Risk-based policies rely on Microsoft Entra ID Protection licensing and signals. A policy that looks correct in a diagram can still produce unexpected interactions with another policy or an unsupported client.
Defender for Office 365
Microsoft Defender for Office 365 protects email and collaboration through cumulative layers. Built-in Exchange Online Protection handles broad known threats. Defender for Office 365 Plan 1 adds capabilities such as enhanced anti-phishing, Safe Links, Safe Attachments, alerts, and real-time detections. Plan 2 adds features such as Explorer, advanced investigation, automation, hunting, and attack simulation training. Verify current licensing rather than memorizing a plan table without context.
Policy strategy can use Standard or Strict preset security policies and justified custom policies. Understand anti-phishing, impersonation, anti-spam, anti-malware, Safe Links, Safe Attachments, quarantine, user reporting, submissions, and the Tenant Allow/Block List. An allow entry is not harmless; it changes protection and needs evidence, owner, expiration, and review.
Investigation connects alerts, incidents, messages, URLs, attachments, users, campaigns, Explorer evidence, entity pages, and remediation. Automated investigation and response can gather evidence and recommend or perform actions depending on capability and configuration. Administrators must validate scope and follow approved response procedures. Attack simulation training uses controlled simulations and safe payloads to measure behavior and assign learning; it must be authorized, privacy-aware, supported, and never designed to capture real credentials.
Microsoft Purview information protection, DLP, and retention
Sensitivity labels, DLP, and retention are related but not interchangeable. A sensitivity label classifies content and can apply visual markings, encryption, or container settings. A DLP policy detects sensitive content and risky activity, then audits, warns, permits justified override, restricts, or blocks according to its rule. Retention controls keep or delete content according to lifecycle and records requirements.
DLP planning starts with stakeholders, sensitive data categories, business processes, supported locations, policy intent, exceptions, user behavior, and investigation. Locations can include Exchange, SharePoint, OneDrive, Teams, endpoints, applications, and supported Copilot or AI surfaces. Design conditions and actions, deploy in simulation, inspect Activity explorer and alerts, tune false positives and business impact, communicate, then enforce gradually. A technically valid block can still be an operational failure if no one reviewed the business process.
When an alert appears, review policy, rule, user, activity, data classification, location, surrounding events, and source permission. Determine whether the activity is authorized, malicious, accidental, or a policy-quality issue. Preserve evidence proportionally and avoid unnecessary exposure of sensitive matched content. Defender correlation can help connect DLP events to wider incidents.
Domain 3: manage and secure AI services in Microsoft 365
Readiness before license assignment
A Microsoft 365 Copilot rollout begins with workload and data readiness, not license assignment. Assess user scenarios, applications, network connectivity, Service health, support, authentication, devices, source ownership, sharing, classification, lifecycle, and compliance requirements. Define a limited pilot with baseline measures and explicit expansion, pause, and stop gates.
Copilot operates within the signed-in user's authorized Microsoft 365 context. It does not create a SharePoint permission simply because a user asks a question. The risk is that existing overshared content can become easier to discover and summarize. Remediate overly broad groups, anonymous or external links, stale sites, obsolete files, missing owners, and inappropriate direct permissions at the source. Then test direct access, search, Copilot Search, Copilot, and agents with controlled personas.
Microsoft Purview Data Security Posture Management provides views and recommendations for AI activity, data risk, oversharing, sensitive-data use, apps, and agents. Current documentation distinguishes newer DSPM capabilities from the classic DSPM for AI experience, so use current product guidance. DSPM is a posture and observability entry point; labels, DLP, retention, audit, source permissions, and workload controls perform much of the enforcement and remediation.
Copilot settings, search, providers, and connectors
AB-650 includes web search, Microsoft 365 Copilot Search, tenant settings, in-app experiences, release preferences, self-service purchases, AI disclaimers, image and video generation, Copilot in admin centers, Copilot Cowork, third-party AI providers, and Copilot connectors. Product availability can change, so study intent and governance rather than memorizing one menu.
Web search and organizational search have different data sources and risks. Web search can supply current public information when enabled. Microsoft 365 Copilot Search focuses on permission-trimmed organizational content across Microsoft 365 and configured connectors. Neither should bypass authentication, authorization, tenant policy, or source permissions.
A Copilot connector expands the organizational knowledge surface. Review the source owner, indexed entities and fields, crawl scope, access-control mapping, connector identity, data flow, privacy, contracts, compliance, cost, error handling, monitoring, stale content, and removal. Test with multiple personas before broad enablement. A connector that cannot preserve source authorization is not ready.
Microsoft Entra Agent ID and Agent Registry
Agents need identity and accountability. Microsoft Entra Agent ID supports agent identity, authentication, authorization, ownership, lifecycle, risk, Conditional Access scenarios, sign-ins, and audit. Interactive agents may act on behalf of a user; autonomous agents can act through their own identities. The exact design depends on capability, but a shared human administrator password is never an acceptable agent identity.
Assign a responsible sponsor or owner, narrow permissions to the required resources, use access packages or other governed entitlements where applicable, apply Conditional Access where supported, and create lifecycle workflows and access reviews. Test expiration and revocation before production. An agent should not persist after its owner, purpose, or business need disappears.
Agent Registry governance includes discovering Microsoft and third-party agents, reviewing requests, publishing or rejecting, installing, blocking, controlling user access, and uploading approved custom agents. Review publisher, owner, purpose, exact version, instructions, knowledge, connections, permissions, actions, tools, sharing, templates, audience, data movement, support, monitoring, cost, expiry, and rollback. Registry presence is inventory, not proof of approval.
Agent 365 tools, protection, monitoring, and compliance
Tools define what an agent can do. Separate read-only retrieval from consequential actions. Scope identities, resources, inputs, destinations, network access, and data. Validate tool arguments outside the model. Require meaningful human approval for high-impact actions and bind approval to the exact proposed operation. The model can propose, but deterministic controls authorize and execute.
Ongoing Agent 365 administration should monitor activity, tool invocations, sign-ins, access, sensitive-data use, owners, policy coverage, incidents, and compliance gaps. Correlate Agent 365 evidence with Entra sign-in and audit logs, Defender incidents, Purview DLP alerts, DSPM posture, and source activity. Practice block, access revocation, ownership transfer, containment, and retirement. A monitoring dashboard without an operator or response path is decorative.
Cost, adoption, outcomes, and service health
AI service operations include license utilization, pay-as-you-go or Copilot Credit consumption, cost anomalies, workload-level adoption, user support, and Service health. Copilot Control System and Microsoft 365 reporting experiences can contribute cost, adoption, and health evidence. Current names and views may evolve; the decision model remains stable.
Assigned licenses and prompt counts are not business outcomes. Measure active and repeat use, task completion, quality, time, human correction, user confidence, support demand, security and compliance incidents, unit cost, and workload-level outcomes against a baseline. Distinguish adoption from effectiveness. A heavily used feature may create rework; a specialized feature may create value for a small audience.
Expansion should be gated. Review readiness, identity, permissions, data security, agent governance, tool controls, incidents, cost, adoption, outcomes, support, and health. Choose expand, revise, pause, stop, or retire. Retirement must revoke agent and connector access, remove tools and licenses, stop consumption, remove identities and entitlements, and preserve required evidence according to retention.
Two projects that cover the blueprint
The first AB-650 project hardens a synthetic Microsoft 365 tenant. It inventories the estate, standardizes licensing, scopes administrators, reduces standing privilege through PIM, stages Conditional Access, secures Exchange, Teams, SharePoint, and OneDrive, configures Defender, implements Purview labels, DLP, and retention, exercises Microsoft 365 Backup, and closes with health, incident, and cleanup evidence.
The second project designs a governed Microsoft 365 Copilot and Agent 365 rollout. It assesses data readiness, remediates oversharing, applies Conditional Access and PIM, configures Defender, labels, DLP, retention, and DSPM, governs Copilot settings and connectors, creates owner-backed Agent ID lifecycle, reviews Agent Registry requests, controls Agent 365 tools, monitors activity, cost, adoption, and health, and exercises expansion and retirement gates.
Both projects use synthetic content and test identities. They are evidence exercises, not claims of production compliance. Before using a real tenant, verify licensing, roles, regional availability, preview support, data boundaries, organizational policy, legal requirements, and change approval.
An eight-to-ten-week AB-650 study plan
- Week 1: Read the current study guide. Map every objective to an admin center, control purpose, dependency, evidence source, failure mode, and rollback.
- Week 2: Practice domains, licensing, group-based assignment, Backup, Service health, network insights, Exchange recipients, Teams, SharePoint, and OneDrive.
- Week 3: Practice users, guests, groups, contacts, administrative units, Microsoft Graph PowerShell, directory roles, PIM, and access reviews.
- Week 4: Practice methods, authentication strengths, Password Protection, SSPR, Conditional Access, report-only, What If, ID Protection, and sign-in investigation.
- Week 5: Study Defender for Office 365 threat policies, Safe Links, Safe Attachments, anti-phishing, alerts, incidents, Explorer, remediation, and attack simulation.
- Week 6: Study sensitive information types, labels, label policies, DLP design and simulation, alerts, Activity explorer, retention, audit, and Defender correlation.
- Week 7: Assess Copilot readiness, oversharing, SharePoint controls, web search, Copilot Search, tenant settings, user experience, providers, and connectors.
- Week 8: Study Entra Agent ID, lifecycle, access packages, Conditional Access for agents, owners, Agent Registry, installation, blocking, user scope, and custom agents.
- Week 9: Study Agent 365 tools, activity monitoring, data protection, compliance gaps, cost, Copilot Credits, workload adoption, support, and service health.
- Week 10: Complete both projects, answer original AB-650 scenarios, review AB-650 flashcards, revisit weak objectives, and rehearse incident, rollback, and retirement decisions.
Common AB-650 preparation mistakes
- Memorizing portals instead of outcomes. Interfaces change; control purpose, dependencies, evidence, and risk remain more durable.
- Confusing license and authorization. Service plans, directory roles, groups, workload permissions, sharing, and data policy are distinct.
- Deploying Conditional Access without report-only. Untested scope and method gaps can cause lockout.
- Using permanent Global Administrator for routine work. Prefer narrow roles, PIM eligibility, bounded activation, and review.
- Blocking DLP immediately. Design intent, use simulation, inspect business impact, tune, communicate, and enforce gradually.
- Assuming Copilot fixes permissions. It can surface content users already have access to; repair oversharing at the source.
- Approving an agent without an owner. Registry review must include identity, data, tools, audience, monitoring, support, expiry, and rollback.
- Putting agent authority in instructions. Identity, authorization, validation, approval, and audit belong in trusted controls.
- Counting prompts as value. Measure outcomes, quality, corrections, support, incidents, cost, adoption, and health together.
- Ignoring retirement. AI access, identities, connectors, tools, licenses, and consumption must be removable.
Certification and career expectations
AB-650 can structure practical knowledge for Microsoft 365 administration in an AI-enabled workplace. It cannot guarantee an exam result, job, promotion, salary, compliance outcome, security outcome, adoption target, or return on investment. Strong evidence includes a tenant baseline, license and role model, Conditional Access rollout, PIM activation tests, Defender investigation, DLP simulation and alert response, retention design, restore exercise, Copilot readiness report, agent review standard, identity and tool matrix, adoption and cost scorecard, service-health runbook, and tested retirement plan.
Use the PrepKloud jobs explorer to compare that evidence with Microsoft 365 administrator, identity administrator, security administrator, compliance administrator, collaboration engineer, and AI service administrator roles. Label synthetic work honestly. Continue through the PrepKloud blog for Zero Trust, AI security, data governance, platform operations, and career guidance.
Official Microsoft references
- Study guide for Exam AB-650: Administering Microsoft 365 and AI Services
- Microsoft 365 admin center documentation
- Microsoft 365 for enterprise documentation
- Microsoft Entra documentation
- Microsoft Entra Conditional Access overview
- Microsoft Entra Privileged Identity Management
- Microsoft Entra Agent ID documentation
- Microsoft Defender for Office 365 documentation
- Microsoft Purview documentation
- Microsoft Purview Data Loss Prevention
- Microsoft Purview Data Security Posture Management
- Microsoft 365 Copilot documentation
- Microsoft Agent 365 service description
Continue your AB-650 preparation
- AB-650 five-phase roadmap
- AB-650 original practice questions
- AB-650 flashcards
- AB-650 hands-on projects
- Cloud, security, compliance, and AI administration jobs
- PrepKloud editorial policy
Frequently asked questions
Is AB-650 active in 2026?
Yes. Microsoft publishes the study guide for Exam AB-650: Administering Microsoft 365 and AI Services. The guide was last updated July 28, 2026. Verify it before scheduling.
What are the current AB-650 weights?
Configure and manage Microsoft 365 tenants and workloads is 20–25%; govern and secure Microsoft 365 tenants and workloads is 40–45%; manage and secure AI services in Microsoft 365 is 35–40%.
What experience does AB-650 expect?
Candidates should have Microsoft 365 workload and Microsoft Entra experience, understand Defender XDR capabilities, and be familiar with Microsoft Graph PowerShell. The role collaborates across identity, security, compliance, endpoints, infrastructure, and applications.
Does Copilot bypass Microsoft 365 permissions?
No. Copilot uses the signed-in user's authorized Microsoft 365 context. Existing oversharing can become easier to discover, so administrators must remediate source permissions and validate access with controlled personas.
Are PrepKloud AB-650 materials dumps or guarantees?
No. They are original educational materials based on public objectives and official Microsoft documentation. They contain no live, recalled, leaked, or proprietary exam content and provide no pass, compliance, job, salary, or business-outcome guarantee.