HomeRoadmaps › AB-650
Active Microsoft associate exam

AB-650 Microsoft 365 and AI Services Administrator Roadmap

Configure, secure, govern, and operate Microsoft 365 workloads, identity, data, Microsoft 365 Copilot, and Agent 365 through five evidence-driven phases.

Exam code: AB-6503 official domainsSuggested pace: 8–10 weeksPublished: August 19, 2026
Use the current study guide as the exam source of truth. Microsoft services, licensing, portal navigation, preview status, Agent 365 capabilities, data boundaries, and objectives can change. Recheck the official AB-650 study guide and linked Microsoft documentation before scheduling or implementing a production control.

What active Exam AB-650 measures

AB-650 targets administrators who configure, manage, secure, govern, monitor, and continuously optimize Microsoft 365 tenants, workloads, Microsoft 365 Copilot, agents, and connected AI services. The audience is expected to collaborate across identity, security, compliance, endpoints, infrastructure, applications, and workload administration and to understand Microsoft Graph PowerShell.

Configure and manage Microsoft 365 tenants and workloads20–25%
Govern and secure Microsoft 365 tenants and workloads40–45%
Manage and secure AI services in Microsoft 36535–40%
1

Tenant, licensing, workloads, resilience, and health

Weeks 1–2

Build a reliable Microsoft 365 administration baseline before layering security or AI services.

  • Configure branding, organization profile, privacy and security settings, verified domains, DNS, and the default domain
  • Manage users, groups, contacts, licenses, group-based licensing, processing errors, pay-as-you-go, and AI service licenses
  • Monitor Microsoft 365 Copilot, Agent 365, and Copilot Studio entitlement and utilization
  • Create shared mailboxes and manage Exchange recipients and delegated access
  • Create teams, channels, owners, members, guests, external access, and meeting transcription or Copilot settings
  • Create SharePoint sites and manage owners, permissions, sharing, OneDrive, Microsoft Search, and site exclusions
  • Configure Microsoft 365 Backup protection, restore content, validate recovery, and monitor operations
  • Use Service health, notifications, Network Connectivity Insights, and documented escalation paths
2

Identity, authentication, privileged access, and Zero Trust

Weeks 3–4

Verify explicitly, use least privilege, and assume breach across users, guests, administrators, and supported agent identities.

  • Create and manage users, guest users, contacts, groups, Microsoft 365 groups, administrative units, and scoped roles
  • Use bulk operations and Microsoft Graph PowerShell with least-privilege permissions and auditable output
  • Review external access, guest sponsorship, memberships, entitlement, inactivity, and removal
  • Replace standing privileged roles with eligible PIM assignments where appropriate
  • Configure role activation duration, MFA or authentication context, justification, approval, notification, and access review
  • Configure authentication methods, phishing-resistant strengths, Password Protection, and SSPR
  • Investigate sign-in, registration, password-reset, and authentication-method issues from logs and diagnostics
  • Plan Conditional Access scope, emergency access, report-only testing, What If, staged enforcement, and rollback
  • Use ID Protection risk signals and require risk-appropriate remediation where licensing supports it
3

Defender, Purview, and workload governance

Weeks 5–6

Protect collaboration and sensitive information through layered prevention, detection, investigation, response, and lifecycle controls.

  • Review the Defender for Office 365 protection stack, Standard and Strict presets, and justified custom policies
  • Configure anti-phishing, anti-spam, anti-malware, Safe Links, Safe Attachments, reporting, quarantine, and Tenant Allow/Block List governance
  • Investigate email and collaboration alerts through incidents, Explorer, entity pages, submissions, and automated investigation evidence
  • Plan authorized attack simulation training with safe payloads, target groups, training, notifications, privacy, and support
  • Define sensitive information types, sensitivity labels, label policies, encryption, markings, and auto-labeling where supported
  • Design DLP intent, locations, scope, conditions, actions, policy tips, override, alerts, simulation, tuning, and enforcement
  • Create retention labels, retention-label policies, and retention policies for keep, delete, records, and Copilot interaction requirements
  • Use Activity explorer, audit, DLP alerts, and Defender correlation to investigate data events
  • Apply administrative scoping and separation of duties to security and compliance administration
4

Microsoft 365 Copilot readiness, settings, search, and data security

Weeks 7–8

Enable Copilot only after identity, workload, permission, content, policy, cost, support, and network readiness are measurable.

  • Assess licenses, in-app experiences, network, Service health, organizational settings, support, and pilot personas
  • Find and remediate SharePoint and OneDrive oversharing, broad groups, anonymous links, stale sites, missing owners, and obsolete content
  • Use SharePoint Advanced Management, data access governance, DSPM data-risk assessments, search restrictions, or site exclusions appropriately
  • Validate direct access, Microsoft Search, Copilot Search, and Copilot responses with controlled authorized and unauthorized personas
  • Configure web search, Microsoft 365 Copilot Search, release preferences, self-service purchase, AI disclaimer, and generation settings
  • Manage Copilot user experiences, Copilot Cowork, third-party AI providers, and current tenant capabilities according to policy
  • Review Copilot connectors for source ownership, indexed data, ACL mapping, crawl scope, data flow, cost, monitoring, and retirement
  • Use labels, DLP, retention, audit, DSPM, and Defender evidence to protect and investigate AI activity
  • Teach users to validate output, handle sensitive data, report issues, and understand that Copilot honors existing access rather than repairing it
5

Agent 365 governance, cost, adoption, health, and readiness

Weeks 9–10

Operate agents as accountable identities and governed applications with bounded tools, data, access, monitoring, cost, and lifecycle.

  • Use Microsoft Entra Agent ID to manage agent owners, sponsors, authentication, authorization, lifecycle workflows, risk, sign-ins, and audit
  • Secure agent access with dedicated identities, access packages, narrow permissions, Conditional Access where supported, reviews, and expiration
  • Configure allowed agent types, sharing, templates, user access, and ownership expectations
  • Discover Microsoft and third-party agents in Agent Registry and review pending requests
  • Publish, reject, install, block, upload, scope, version, re-review, or retire agents according to documented criteria
  • Limit Agent 365 tools by purpose, identity, resource, input, destination, and human approval for consequential actions
  • Monitor Agent 365 activity, sensitive-data access, DLP, DSPM, Defender, audit, compliance gaps, owner status, and lifecycle
  • Monitor Copilot and AI cost, Copilot Credits, license utilization, workload-level adoption, task outcomes, support, and incidents
  • Use Copilot Control System and Microsoft 365 Service health to monitor adoption and reliability
  • Complete both projects, review every domain, explain distractors, and rehearse expansion, containment, rollback, and retirement

PrepKloud AB-650 study surfaces

Official Microsoft sources

AB-650 study guide

Confirm the current audience, skills, weights, updates, and study resources.

Open Microsoft Learn
Microsoft 365 administration

Review tenant setup, workloads, licensing, Backup, service health, and network connectivity.

Open Microsoft 365 admin docs
Microsoft Entra

Review users, groups, roles, PIM, authentication, Conditional Access, risk, governance, and Agent ID.

Open Entra documentation
Microsoft Defender for Office 365

Review threat policies, alerts, investigation, response, and attack simulation.

Open Defender documentation
Microsoft Purview

Review information protection, DLP, retention, audit, DSPM, and AI data security.

Open Purview documentation
Microsoft 365 Copilot and Agent 365

Review Copilot deployment and governance plus current Agent 365 capabilities and administration.

Open Microsoft 365 Copilot documentation

Frequently asked questions

Is AB-650 an active Microsoft exam?

Yes. Microsoft publishes the current study guide for Exam AB-650: Administering Microsoft 365 and AI Services. The guide was last updated July 28, 2026. Verify it before scheduling.

What are the AB-650 domain weights?

Configure and manage Microsoft 365 tenants and workloads is 20–25%; govern and secure Microsoft 365 tenants and workloads is 40–45%; manage and secure AI services in Microsoft 365 is 35–40%.

Does AB-650 cover both users and AI agents?

Yes. It covers conventional tenant identities and workloads plus Microsoft 365 Copilot, Entra Agent ID, Agent Registry, Agent 365 access and tools, data protection, cost, adoption, and service health.

What should be completed before a broad Copilot rollout?

Review licensing, network and workload readiness, source permissions, oversharing, labels, DLP, retention, identity, Conditional Access, privileged roles, support, cost, and pilot evidence before expanding.

Are PrepKloud AB-650 materials exam dumps or guarantees?

No. They are original educational materials grounded in public objectives and official Microsoft documentation. They contain no live, recalled, leaked, or proprietary exam content and cannot guarantee a passing result.

Integrity, independence, and implementation caution: PrepKloud is independent and is not Microsoft. This roadmap contains original educational material based on public official sources. It contains no exam dumps, marketplace copying, guaranteed predictions, compliance assurance, salary promise, or employment guarantee. Use synthetic data and governed nonproduction environments for practice. Verify current objectives, licensing, plans, roles, product names, regions, previews, data boundaries, retention, security controls, propagation, and pricing before implementation.

Practice operating one governed Microsoft 365 and AI estate

Use original questions, focused flashcards, and two evidence-driven projects spanning conventional workloads and the agentic workplace.