Microsoft 365 AI Services Administrator Associate practice questions
Microsoft · AB-650 · 300 questions
Original practice questions for Microsoft 365 AI Services Administrator Associate.
This course contains the use of artificial intelligence.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
configure-manage-microsoft-365-tenants-workloads · 66 questions
- Contoso Ltd. wants to display their company logo and a custom background image on the Microsoft 365 sign-in page so employees see a branded login experience. The IT admin needs to configure this. Where in the Microsoft admin portals should the admin go to configure the sign-in page logo and background image?
- Adventure Works has purchased a new domain 'adventureworks.com' and wants to add it to their Microsoft 365 tenant so employees can use it for email. After adding the domain in the Microsoft 365 admin center, the admin needs to verify ownership of the domain. What is the MOST common method used to verify domain ownership in Microsoft 365?
- Tailspin Toys has 500 employees who all need Microsoft 365 E3 licenses. The IT admin wants to ensure that when new employees are added to the 'Sales Department' Azure AD security group, they automatically and immediately receive a Microsoft 365 E3 license — without any manual intervention. What feature should the admin configure to achieve this?
- Fabrikam Inc. recently enabled Microsoft 365 Backup for their tenant. A user reports that they accidentally deleted important project files from their OneDrive three weeks ago and needs them restored. The admin has confirmed the files are not in the user's OneDrive recycle bin. Which Microsoft admin portal section should the admin use to initiate a point-in-time restore of the user's OneDrive?
- Northwind Traders has purchased 200 Microsoft 365 Copilot licenses and wants to assign them to specific users in the Sales and Marketing departments. The admin also needs to monitor which users have active Copilot licenses and track license utilization over time. Where in the Microsoft 365 admin center can the admin assign Microsoft 365 Copilot licenses AND view a report on active usage?
- Lamna Healthcare has been experiencing slow Microsoft 365 performance for employees at their branch office in Austin, TX. The IT manager wants to identify whether the network path to Microsoft 365 services is causing the issue and get specific recommendations to improve connectivity. Which Microsoft 365 admin center feature should the admin use to diagnose and review connectivity issues for the Austin branch?
- Wide World Importers wants to proactively receive email notifications whenever there is an incident or advisory affecting Microsoft Teams or Exchange Online in their tenant. The admin wants the IT helpdesk team to be automatically notified without having to check the admin center manually. Where should the admin configure these service health email notifications?
- Contoso's customer support team needs a shared email address — [email protected] — that five support agents can send and receive email from without requiring each agent to have a separate additional mailbox license. The admin needs to create this mailbox in the most license-efficient way possible. Which mailbox type should the admin create, and what is the license requirement?
- Alpine Ski House is setting up Microsoft Teams for their operations department. The admin has created a team called 'Operations' and needs to ensure that only department managers (team owners) can create new channels and add external guests. Regular team members should be able to post messages but not modify team structure. What is the correct way to enforce this configuration?
- Bellows College wants to enable Microsoft 365 Copilot features in Teams meetings so that Copilot can summarize meeting discussions, answer questions during the call, and generate action items after the meeting. The admin has assigned Copilot licenses to all users but notices that Copilot is not functioning in meetings. What specific prerequisite must be configured BEFORE Copilot can function in Teams meetings?
- Fourth Coffee has deployed Microsoft 365 Copilot to 300 users. The legal team is concerned that Copilot might surface confidential merger documents stored in a restricted SharePoint site called 'Legal-M&A' in its responses to regular employees. The admin needs to prevent Copilot from using content from this specific SharePoint site without deleting the site or changing existing user permissions. What is the BEST approach?
- Northgate Financial Services is rolling out a new brand identity. The IT admin has been asked to upload a custom banner logo that will appear on the sign-in page and apply a custom navigation bar color across the Microsoft 365 experience. The admin opens the Microsoft 365 admin center but is unsure which section controls these specific sign-in and navigation branding settings. Which location should the admin use to configure the banner logo and navigation bar color?
- Crestwood Legal Group has acquired a new subdomain, mail.crestwoodlegal.com, that they want to add to their Microsoft 365 tenant to support a new email routing strategy. As part of the domain addition process, Microsoft 365 requires Crestwood to prove they own the domain before it can be used. The IT admin checks the setup wizard and sees that Microsoft 365 will provide a verification value that must be added to the domain's DNS. What type of DNS record does Microsoft 365 use by default to verify domain ownership?
- Redwood Diagnostics Inc. has a strict data privacy policy. The CISO has directed the IT admin team to minimize the amount of diagnostic and telemetry data that Microsoft 365 desktop applications send back to Microsoft from employee devices. The admin needs to find the setting that controls this behavior and configure it to the lowest acceptable level — sending only the data Microsoft requires to keep the service secure and up to date. Which setting and location in the Microsoft 365 admin center should the admin configure?
- Pinnacle Healthcare Systems wants to automatically assign Microsoft 365 E3 licenses to all employees whose Department attribute in Microsoft Entra ID is set to 'Nursing', without requiring any manual license assignment each time a new Nursing employee is onboarded or transferred. The solution must work continuously and without admin intervention after initial setup. What is the correct approach to achieve this?
- Vantage Retail Solutions has purchased 50 Microsoft Copilot Studio licenses. The IT admin opens the Microsoft 365 admin center and notices two similar license SKUs listed under Billing > Licenses: 'Copilot Studio' and 'Power Virtual Agents'. The admin needs to assign the correct license to allow users to build and publish custom AI copilots in Microsoft Copilot Studio. Which action should the admin take?
- A Microsoft Teams site for a critical project at Lakeside Property Management was accidentally deleted by a team owner 97 days ago. The SharePoint admin has Microsoft 365 Backup configured for the tenant. What is the correct method for restoring the deleted SharePoint site associated with that team?
- Users at Coastal Engineering Associates' Denver branch office are experiencing degraded Microsoft Teams call quality and slow SharePoint page loads. The IT admin suspects the network path from the Denver office to Microsoft 365 service endpoints may be suboptimal. Which tool in the Microsoft 365 admin center provides per-office network connectivity assessment scores and actionable recommendations for improving Microsoft 365 network performance?
- The IT director at Summit Insurance Group wants the helpdesk team to automatically receive email alerts whenever Microsoft Exchange Online or Microsoft Teams experiences a service incident or advisory — without requiring the helpdesk team to manually check the admin center. What must the Microsoft 365 admin configure to enable this automated notification behavior?
- The IT team at Harborview Medical Center created a shared mailbox called '[email protected]' and added five staff members as delegates with Full Access permissions. Three of the five users report that the shared mailbox appeared automatically in their Outlook desktop client, but two users say it did not appear. All five users have verified their Full Access permissions are correctly assigned. What is the most likely reason two users do not see the shared mailbox auto-mapped in Outlook?
- Meridian Consulting Partners wants to enable Microsoft 365 Copilot in Teams meetings so that meeting participants can ask Copilot questions during and after meetings. However, they want to ensure that Copilot can function even in meetings where a recording is not started. Which Teams meeting policy setting must be configured, and what value allows Copilot to work without requiring a recording?
- Blackwood Pharmaceutical Research has highly sensitive pre-clinical research data stored in a SharePoint site called 'R&D Confidential'. When employees use Microsoft 365 Copilot to search across the organization, results from the R&D Confidential site are appearing in Copilot responses for users who have access. The compliance officer wants to prevent the R&D Confidential site from being included in Copilot responses organization-wide, even for users who have SharePoint permissions to the site. What is the correct method to exclude this site from Microsoft 365 Copilot results?
- Humongous Insurance rebranded with a new corporate purple. Employees should see that color on the Microsoft 365 navigation bar after they sign in. Sign-in page branding is already correct. Where does the admin set the navigation bar theme color?
- Wingtip Toys verified wingtiptoys.com in Microsoft 365 and now wants Exchange Online to receive mail for that domain. Which DNS records must be configured for mail delivery and anti-spoofing readiness?
- Fabrikam wants certain AI capacity consumption billed only when used, and needs visibility of pay-as-you-go AI charges for Microsoft 365 AI services. Where should the admin primarily manage this?
- A project SharePoint site at Contoso was corrupted by a mass file overwrite yesterday. Microsoft 365 Backup is enabled. Where should the admin initiate a point-in-time restore?
- Lucerne Publishing needs power users to build custom agents in Microsoft Copilot Studio. Microsoft 365 Copilot licenses alone are not enough for Studio authoring. What should the admin assign?
- Southridge Video's Seattle branch has poor Teams quality. The admin wants Microsoft 365 network connectivity insights and recommendations for that location. Where?
- VanArsdel's NOC must receive email when Exchange Online or Teams has an active incident. What should the admin configure?
- Fourth Coffee needs [email protected] used by six staff without assigning a separate paid mailbox license to the shared object (within standard limits). What should they create?
- Alpine Ski House wants a private channel in Operations where only managers post files and guests cannot be added by members. Which approach is most appropriate?
- Bellows College assigned Copilot licenses, but Copilot in Teams meetings still fails. Meeting transcription prerequisites are not enabled in policy. What must be configured?
- Proseware's Legal-Privileged SharePoint site must stay accessible to lawyers with permissions, but Copilot and Microsoft Search must not surface it org-wide. Best admin control?
- Microsoft needs a technical contact for the tenant for service communications. Where is the organization technical contact maintained?
- After adding custom domain fabrikam-engineering.com, what is the most common default verification method Microsoft 365 requests?
- All members of Entra security group 'Sales-Cloud' must automatically receive Microsoft 365 E5 and Copilot licenses. What feature?
- A user purged important OneDrive files past recycle bin retention. Microsoft 365 Backup is on. What restores them?
- IT must track Microsoft Agent 365 and Copilot Studio license assignment counts versus purchased seats. Where?
- Network connectivity insights flag that a branch proxies Microsoft 365 traffic inefficiently. What should IT do?
- After a Teams outage, leadership wants historical incident details for a postmortem. Where is the official incident history?
- Support agents must send email that appears from [email protected] (Send As), not merely on behalf. What permission is required?
- A company-wide Teams channel should allow only communications team to post; others read only. What approach?
- Users with Copilot licenses still cannot get meeting recap content they did not attend. Why might that be expected?
- Before enabling Copilot broadly, admins should reduce sites shared with Everyone. Which SharePoint governance area helps manage oversharing at scale?
- Adventure Works wants their logo in the Microsoft 365 header after sign-in, not on the authentication page. Which setting area?
- Contoso uses contoso.com for email and wants a second accepted domain partners.contoso.com for a partner-facing mail namespace. After adding/verifying the domain, what else is typically required for mail?
- IT purchased 500 Copilot seats but only 310 appear active. Where to confirm assignment vs usage signals?
- After enabling Microsoft 365 Backup, ops must confirm protection status and restore points exist for critical sites. What should they review?
- A business unit wants flexible AI capacity billed on consumption for certain scenarios, while core users keep prepaid Copilot seats. What should the admin understand?
- Connectivity insights recommend fixing DNS recursion/egress for Microsoft 365 endpoints at a branch. Impact if ignored?
- During an Exchange Online incident, helpdesk needs accurate public Microsoft status notes for customer updates. Best source?
- Five agents need to open a shared mailbox in Outlook desktop. Besides licensing model, what permission is typically required?
- A project team wants external guests in Teams channels, but guests must not create channels. What should be configured?
- Only the Executives group should have Copilot-friendly meeting transcription policies; others remain off. How is this typically achieved?
- A SharePoint project site should have three owners and members with edit, but visitors read-only. Where are classic membership groups managed?
- Admin must review tenant-level security and privacy related organization settings for Microsoft 365. Where primarily?
- New users should get UPN suffix @tailspintoys.com by default after the custom domain is verified. What should admin set?
- Group-based licensing shows errors for some users due to conflicting service plans. What should admin do?
- A mailbox was maliciously wiped. Microsoft 365 Backup protects Exchange. Goal is restore to a point before wipe. Action?
- Copilot Studio makers hit capacity limits. Where should admins monitor Studio/AI capacity consumption signals?
- Connectivity insights show a poor score for the Chicago egress. What is the admin's operational response?
- Beyond email, admins may integrate service health into operations tooling. What remains the authoritative incident source?
- A shared mailbox approaches capacity limits for unlicensed shared mailboxes. What are valid responses?
- Security review finds 40 owners on a sensitive team. Best practice?
- Meeting transcripts used by Copilot may be subject to retention/compliance. What should admins align?
- Microsoft Search configuration can influence what users discover, which affects Copilot grounding inputs. Admin focus?
govern-secure-microsoft-365-tenants-workloads · 132 questions
- Contoso is onboarding 500 employees from a recently acquired company. The IT admin has a CSV file containing user attributes including Department, Job Title, and Manager, and needs to create all accounts with proper Microsoft 365 license assignments as quickly as possible. Which approach should the admin use?
- Fabrikam's compliance team requires that Global Administrator access only be granted when operationally necessary. The policy mandates that users must provide a business justification, receive manager approval before activation, and have access automatically revoked after 8 hours. What should the admin configure?
- Northwind Traders has regional IT teams in North America, Europe, and Asia-Pacific. Each regional team needs to reset passwords and manage licenses only for users in their own region. No regional admin should be able to affect users in another region. What should the admin configure?
- Adventure Works wants to allow B2B collaboration so partner users can be invited as guests to Teams and SharePoint. However, they need to ensure guest users cannot enumerate other directory members or see other guest accounts in the directory. What should the admin configure?
- Contoso wants all users whose Department attribute is set to 'Sales' in Microsoft Entra ID to be automatically added to a group called 'Sales Team'. The group should include a shared mailbox and a Microsoft Teams workspace, and membership should update automatically when the Department attribute changes. What should the admin create?
- Woodgrove Bank wants to allow employees to reset their own passwords without calling the IT helpdesk. The bank's security policy requires that users verify their identity using two separate authentication methods before a password reset is permitted. The admin wants to enable mobile app notification and email OTP as the available methods. What should the admin configure?
- Alpine Ski House requires MFA for all users when accessing Microsoft 365 services from outside the corporate network. Users connecting from within the office should have a seamless experience without MFA prompts. What should the admin configure?
- Contoso's IT team discovers that many users are setting passwords containing company-specific terms like 'Contoso', 'Corp', and 'HQ2024'. These passwords pass the standard complexity requirements but are weak against targeted attacks. The admin wants to automatically block these terms and common variants. What should the admin configure?
- A user at Fourth Coffee reports that they are unable to sign in to Microsoft 365 and receive an error message. The user's account appears active in the Microsoft 365 admin center. The admin needs to quickly identify the exact failure reason, error code, and which Conditional Access policy (if any) is blocking access. What should the admin do?
- Trey Research wants high-risk user accounts (flagged by Microsoft Entra ID Protection due to leaked credentials or anomalous sign-in behavior) to be automatically remediated by forcing an immediate password change. The security team should not need to manually intervene for each incident. What should the admin configure?
- Contoso's security team requires that all Global Administrators use phishing-resistant authentication methods only. The company has decided to deploy FIDO2 hardware security keys for these accounts. What must the admin configure to enable FIDO2 authentication in Microsoft Entra ID?
- Tailwind Traders has been targeted by spear-phishing attacks where external senders impersonate the company's CEO and CFO to trick employees into taking fraudulent actions. The admin needs to configure Defender for Office 365 to detect and quarantine emails that impersonate these specific executives. What should the admin configure?
- The security operations team at Fabrikam wants to receive an email notification when Microsoft Defender for Office 365 detects that more than 10 users in the organization have received malware-containing emails within a one-hour window, indicating a potential malware campaign. What should the admin configure?
- Multiple users at Woodgrove Bank report receiving phishing emails that appear to have been delivered to their inboxes despite having anti-phishing policies in place. The security admin needs to investigate the delivery action, determine where the emails were delivered, identify how many users received them, and check whether any users clicked links in the emails. What tool should the admin use?
- Contoso needs to ensure that all email attachments are scanned in a sandbox environment before users can open them. However, users must still be able to read the email body immediately — they should not wait for attachment scanning to complete before the message is delivered to their inbox. Which Safe Attachments action should the admin configure?
- The security team at Alpine Ski House wants to test employee susceptibility to credential harvesting phishing attacks. Employees who submit their credentials on the simulated phishing page should automatically be enrolled in a security awareness training course without any manual admin effort. What should the admin configure?
- A user at Northwind Traders clicked a URL in an email and was redirected to a malicious website. The admin suspects Safe Links should have blocked the URL. The admin needs to determine why Safe Links did not block the URL and check whether other users in the organization also clicked the same link. What should the admin do?
- Fabrikam's compliance team needs to prevent credit card numbers from being shared in Microsoft Teams chats and channel messages, including in Microsoft 365 Copilot interactions within Teams. A policy must block users from sending this information and notify them of the policy violation in real time. What should the admin create?
- Contoso is running a confidential merger and acquisition project. Project documents stored in a dedicated SharePoint site must be encrypted so only designated M&A team members can open them — even if a document is accidentally shared externally or downloaded to a personal device. The protection must travel with the document. What should the admin configure?
- A financial services company must comply with regulations requiring all email communications to be retained for a minimum of 7 years and to remain immutable during that period. The requirement applies to all current and future Exchange Online mailboxes. What should the admin configure?
- A DLP alert fires in Microsoft Purview indicating that a Finance department user shared a SharePoint document containing Social Security Numbers with an external email address. Before taking action, the security admin needs to review the matched content, understand which DLP policy was triggered, and determine whether the sharing was potentially authorized. What is the correct first action?
- Woodgrove Bank has deployed Microsoft 365 Copilot to 1,000 users. The compliance team is concerned that users might be accessing sensitive customer financial data through Copilot prompts and that this exposure is not visible to administrators. The team needs a solution to monitor AI interactions involving sensitive data and receive recommendations for improving AI data security posture. What should the admin enable?
- Fabrikam is onboarding 500 new employees simultaneously across three departments. The IT administrator has a CSV file containing each employee's display name, user principal name, department, and job title. The admin wants to create all 500 accounts in Microsoft Entra ID using Microsoft Graph PowerShell. Which approach correctly accomplishes this?
- Woodgrove Bank operates three regional offices: East, West, and Central. Each region has its own IT support team that needs to manage password resets, group memberships, and user account properties — but only for users in their own region. The global IT team wants to ensure that the East IT team cannot accidentally modify a Central region user account. What should the Microsoft Entra administrator configure?
- Alpine Ski House regularly works with external contractors from partner companies. The IT team wants these contractors to access specific Teams channels and SharePoint project sites via B2B collaboration. However, the security team has flagged a concern: they do not want guest users to be able to invite additional external users on their own. The global admin needs to configure this restriction. Which setting should be adjusted?
- Tailwind Toys' security team is hardening their Microsoft 365 environment. They want the Exchange Administrator role to follow a zero-standing-access model: no one should have the role active at all times. When someone needs it, they must submit a business justification and get approved by the security team lead before the role activates. Which configuration in Microsoft Entra Privileged Identity Management (PIM) achieves this?
- Northwind Traders has accumulated over 8,000 Microsoft 365 groups over the past three years. Many are tied to completed projects and appear to be abandoned — no owner activity, no content updates. The IT governance team wants groups to automatically expire and be soft-deleted after 180 days of inactivity, with group owners receiving email notifications at 30, 15, and 1 day before expiration so they can renew active groups. What should the administrator configure?
- Fourth Coffee's IT team has noticed that employees frequently set passwords like 'FourthCoffee2024!' and '4thCoffee#1' — variations of the company name that technically pass complexity rules but are easily guessable. The security team wants to proactively block these company-specific password patterns for all users. What should the admin configure to address this?
- Adventure Works' security team wants to use Microsoft Entra ID Protection's sign-in risk signals to automate their response to risky sign-ins. Their policy is: sign-ins flagged as 'High' risk should be completely blocked, while sign-ins flagged as 'Medium' risk should be allowed if the user completes MFA. What is the correct way to implement this in Microsoft Entra?
- A user at Proseware calls the helpdesk reporting they cannot sign in to Microsoft 365. The error message displayed is 'Your account has been locked.' The admin needs to quickly determine whether the lockout is caused by Microsoft Entra Smart Lockout triggering due to too many failed attempts, or whether an administrator has explicitly disabled the user's account. Where should the admin look first to get this information?
- Bellows College wants to configure Microsoft 365 access so that students signing in from on-campus (a set of known IP ranges) are not prompted for MFA, but students accessing from off-campus must complete MFA. The IT admin needs to implement this without disrupting the growing population of remote learners. What is the correct approach?
- Litware Inc wants to protect email users from malicious attachments without introducing delays in reading emails. Employees must be able to open and read the email body immediately upon arrival, while any attached files are still being scanned in the background. The security team has asked the Microsoft 365 administrator to configure the appropriate Safe Attachments policy action. Which action should the administrator select?
- Trey Research's CEO, Megan Bowen ([email protected]), has been impersonated in phishing emails sent to employees from external addresses. Multiple employees received emails appearing to be from Megan with requests to wire transfer funds. The Microsoft 365 administrator needs to ensure that future emails attempting to impersonate the CEO are automatically quarantined before reaching any employee inbox. What is the most effective configuration?
- Wide World Importers' security operations center received an alert that multiple users clicked a malicious URL embedded in a phishing email. The security administrator needs to identify every user who received this email, determine which users actually clicked the URL, and assess whether any downstream actions occurred. The administrator wants to use a built-in Microsoft Defender for Office 365 tool to investigate. Which tool should be used?
- VanArsdel Ltd's compliance officer wants to give end users limited control over their quarantined emails. Specifically, users should be able to release their own emails quarantined by spam filtering without admin involvement. However, emails quarantined because of phishing or malware detections must require admin approval before any release — end users should only be able to request a release, not perform it themselves. How should the Microsoft 365 administrator configure this?
- Adatum Corp's security team wants to test the phishing awareness of employees in the Finance department only. The simulation should use a credential harvesting technique — presenting a fake login page when the user clicks a link — and any employee who clicks the link should automatically be enrolled in a security awareness training course without any manual intervention by the security team. What is the correct way to set up this simulation in Microsoft 365?
- Fabrikam's security operations team is receiving a high volume of 'Email messages containing malicious URL removed after delivery' alerts triggered by a known-safe internal newsletter sent from [email protected]. The alerts are flooding the security queue and causing alert fatigue, making it harder to identify real threats. The administrator needs to stop false positive alerts from this specific safe sender while ensuring the overall alert policy remains active for all other senders. What should the administrator do?
- Humongous Insurance has deployed Microsoft 365 Copilot across their organization. The compliance team is concerned that employees may enter credit card numbers or Social Security Numbers (SSNs) directly into Copilot prompts, which would violate PCI-DSS and privacy regulations. The compliance administrator needs to prevent this from happening. What is the correct DLP configuration?
- Lucerne Publishing wants all documents uploaded to their 'Legal Contracts' SharePoint site to be automatically labeled with the 'Highly Confidential - Legal' sensitivity label — without requiring any action from users — when those documents contain words like 'CONFIDENTIAL' or 'ATTORNEY-CLIENT'. What should the compliance administrator configure to achieve this?
- Munson's Pickles and Preserves has two retention requirements for Exchange email: (1) ALL Exchange email must be retained for a minimum of 7 years for regulatory compliance, and (2) individual employees must be able to mark specific customer complaint emails to be retained for 10 years. Which combination should the compliance administrator deploy?
- Tailspin Toys' compliance team receives a DLP alert in Microsoft Purview showing that an employee emailed a file containing 15 credit card numbers to an external recipient. The alert status is 'Active.' What are the correct next steps for the compliance officer managing this alert in Microsoft Purview?
- Southridge Video has deployed Microsoft 365 Copilot organization-wide. The CISO wants visibility into what sensitive data Copilot is accessing and summarizing on behalf of users, including which sensitive information types appear in Copilot interactions. The administrator needs to set up a monitoring solution. What should they configure?
- Graphic Design Institute uses an internal employee ID format: the prefix 'GDI-' followed by exactly 6 digits (for example, 'GDI-482931'). The compliance team wants DLP policies to be able to detect these employee IDs when they appear in documents or emails. What is the FIRST step the administrator must complete before the DLP policies can detect this pattern?
- Adventure Works is onboarding 300 hires from a CSV (UPN, displayName, department, jobTitle). Which approach best creates accounts at scale?
- Tailwind Traders requires Exchange Administrator to be eligible only, with manager approval and 4-hour max activation. What should be configured?
- Woodgrove Bank helpdesks in EMEA and APAC must reset passwords only for users in their region. What Entra feature scopes those roles?
- Relecloud allows B2B guests for projects but guests must not invite more guests. What should be restricted?
- Northwind wants all users with department=Finance automatically in a Microsoft 365 group used for Teams and SharePoint. Membership must update when department changes. What should be used?
- Graphic Design Institute enables SSPR and requires two verification methods before reset. Mobile app notification and email are allowed. What configuration meets this?
- Contoso requires MFA when users access Microsoft 365 from outside corporate IP ranges, but not from trusted office IPs. How should this be implemented?
- Users keep choosing passwords containing 'Contoso' and 'HQ2026'. Complexity is on, but terms are guessable. What blocks org-specific terms?
- A user cannot sign in; the account looks enabled. The admin needs the failure reason, error code, and any Conditional Access that blocked the attempt. Where first?
- Trey Research wants high user risk (e.g., leaked credentials) to force password change automatically. What should be configured?
- Global Administrators must use phishing-resistant authentication with FIDO2 security keys. What must the admin enable/configure?
- CEO and CFO display-name impersonation phishing is rising. Which Defender for Office 365 control targets user impersonation?
- SOC wants email when more than 10 users receive malware in one hour. What should be configured?
- Multiple users clicked a malicious URL in email. The analyst must find all recipients and clickers. Which tool?
- Attachments must be detonated in a sandbox, but users must read the email body immediately. Which Safe Attachments action?
- Finance users should get a credential-harvest simulation; clickers auto-enroll in training. What feature?
- A legitimate partner URL is rewritten/blocked by Safe Links. After confirming safety, what should the admin do?
- Block Social Security Numbers in Teams chat/channel messages with a policy tip. What is required?
- M&A documents must remain encrypted so only the M&A group can open them even if emailed externally. What control?
- All Exchange Online mail must be retained 7 years immutably for regulation. What is the broad control?
- A DLP alert shows a finance user shared a file with many credit card numbers externally. What is the correct first admin action in Purview?
- Compliance needs visibility into sensitive data exposure via Copilot interactions and AI data security recommendations. Which capability?
- An admin must create a single cloud user with department and usage location via automation-friendly tooling. Which is preferred on modern tenants?
- PIM role settings should require MFA on activation for Security Administrator. Where is this enforced?
- A school district wants campus IT to manage groups only for users in their campus administrative unit. What is required?
- Partners should lose guest access if no longer needed. Which governance feature periodically re-certifies guest access?
- Unused Microsoft 365 groups should expire after 180 days of inactivity with owner renewal notices. What configures this?
- IT wants to enable Microsoft Authenticator passwordless phone sign-in for users. Which admin plane primarily governs authentication methods availability?
- Baseline: all users must perform MFA when accessing Microsoft 365 cloud apps. Best control?
- Hybrid identity: custom banned passwords should apply to on-prem AD password changes too. What component extends Entra Password Protection on-premises?
- Analysts want to find legacy authentication attempts. Where?
- Medium sign-in risk should require MFA; high sign-in risk should block. How?
- A CA policy must require phishing-resistant MFA for access to a sensitive app. What concept is used?
- Attackers spoof lookalike domains similar to contoso.com. Which policy feature helps?
- Admin wants recommended baseline threat policies for anti-spam, anti-malware, Safe Links, Safe Attachments quickly. What approach is common?
- Analyst confirms a phishing message already delivered. They need to purge it from mailboxes. Which investigation experience supports soft delete/purge actions?
- Users may release their own spam-quarantined messages, but phishing/malware quarantine requires admin release. What configures this?
- Security wants recurring phishing simulations with automatic training for failures across the whole company. What product area?
- A file hash is repeatedly flagged as malware incorrectly for an internal LOB installer. After validation, what can suppress false positives for that file?
- DLP must cover Exchange, SharePoint, OneDrive, Teams, and devices. Which product family provides this unified policy approach?
- Contracts site should auto-apply Highly Confidential when documents match keywords. What is needed?
- All mail retained 7 years; specific complaint emails retained 10 years by user-applied label. What combination?
- After confirming a DLP alert is a false positive, what should the analyst do in the alert workflow?
- DSPM for AI shows recommendations to fix risky AI data exposure. What should admins do next?
- Org employee IDs look like 'ACME-######'. DLP must detect them. First step?
- After bulk-creating users, admin must assign Microsoft 365 E3 via automation. Which approach fits modern practice?
- Privileged role assignments should be re-certified quarterly. Which feature?
- Administrative unit membership for 'EU-Users' should auto-include users with usageLocation=EU. What helps?
- B2B guests should only come from partnera.com and partnerb.com. What configuration direction?
- Dynamic security group for department=Engineering should drive E5 licenses. What two pieces?
- Many users never registered SSPR methods. How can admin drive registration?
- Org must block legacy authentication protocols for Microsoft 365. Best control?
- Admin enables custom banned passwords in audit mode first. Purpose?
- A CA policy did not apply to a sign-in as expected. Where to see 'not applied' reasons?
- For high user risk, access should be blocked until admin remediates. Policy type?
- Besides FIDO2, which method class is commonly treated as phishing-resistant for privileged access scenarios?
- Anti-phishing policy can use mailbox intelligence to better detect impersonation. What is the value?
- SOC wants alerts when phishing messages are removed after delivery (ZAP-style events) at high volume. What configures notifications?
- Analyst needs to pivot from one bad subject line to all related messages in a campaign. Best tool?
- For a high-security business unit, attachments detected as malicious must never be delivered. Which Safe Attachments action fits best?
- Simulation should target only the Finance Entra group. How?
- Safe Links should rewrite URLs in email and Teams. What must be true?
- DLP must prevent credit card numbers in Exchange email and SharePoint/OneDrive files, and Teams chat. How many products?
- Label 'Confidential' should prevent external users from opening encrypted docs. What label setting area?
- Users must manually apply a 'Regulatory-10Y' retention label in Outlook. What is required after creating the label?
- Compliance officers should receive email when high-severity DLP alerts fire. Where is this commonly configured?
- DSPM for AI highlights sites contributing most to AI oversharing risk. Admin next step?
- External partner SMTP addresses should appear in the shared address book without full guest user objects. What object type is commonly used?
- Security wants email when someone activates Global Administrator via PIM. What provides this?
- Helpdesk needs password reset without user admin for all properties tenant-wide. Best role design?
- Guest accounts inactive for 90 days should be reviewed/removed. Which capabilities help?
- All Microsoft 365 groups must be prefixed with 'GRP-'. What configures this?
- New hires need a time-limited bootstrap credential to register passwordless methods. Which method?
- Access to Microsoft 365 from iOS/Android must require approved app protection / compliant devices per policy design. What engine enforces?
- User locked due to repeated bad passwords. Where to confirm Smart Lockout vs admin disable?
- Before enforcing a new sign-in risk CA policy, admin should evaluate impact. How?
- Windows Hello for Business can contribute to phishing-resistant auth postures for Windows users. How does it fit admin strategy?
- Spoof intelligence shows a partner domain spoofing that is actually legitimate bulk mail. Admin action?
- SOC wants a high-level view of email threat campaigns affecting the tenant. Where?
- A message was clean at delivery then later classified malicious. What technology can remove it retroactively?
- User requests release of a quarantined phishing message. Policy forbids end-user release. Who releases if business-justified?
- After a simulation, CISO wants compromise rate and training completion. Where?
- A malicious URL should be blocked tenant-wide even if not yet in global intel. Action?
- DLP should educate users with policy tips rather than hard block for first rollout of a new rule. What action type?
- Sensitivity labels should be visible only to Legal and Finance first. How?
- Retention should apply only to users in the HR department dynamically. What helps target?
- Endpoint DLP locations are selected but devices show no activity. What prerequisite is commonly missing?
- Executives want a posture-oriented view of AI data security risk trends over time. Which solution area?
- DLP must detect a list of internal project codenames. What SIT approach?
manage-secure-ai-services-microsoft-365 · 101 questions
- An organization discovers dozens of unused Copilot agents with broad Graph permissions. What is the most appropriate lifecycle action?
- Contoso Ltd. is planning to deploy Microsoft 365 Copilot to 500 users. Before purchasing licenses, the IT administrator wants to evaluate whether the tenant is ready for Copilot. Which tool in the Microsoft 365 admin center should the administrator use first to assess tenant readiness?
- Fabrikam Inc. has enabled Microsoft 365 Copilot and discovered that Copilot is surfacing confidential HR documents to general employees in its responses. The security administrator suspects data oversharing is occurring through SharePoint. What is the BEST approach to identify and resolve this data readiness issue?
- Northwind Traders is a financial services company with strict data handling policies. The compliance team has determined that Microsoft 365 Copilot must not use web search when generating responses, to prevent any risk of data leakage to external services. Where should the administrator configure this setting?
- Adventure Works has deployed Microsoft 365 Copilot company-wide. The legal team requires that every Copilot-generated response displayed to users includes a visible disclaimer stating that AI-generated content should be verified before use. Additionally, the IT department wants to prevent users from purchasing Copilot add-ons independently through self-service. Which admin center is the CORRECT location to configure BOTH of these settings?
- Tailspin Toys wants Microsoft 365 Copilot to be able to search and retrieve information from their on-premises ServiceNow knowledge base when responding to user queries. The administrator needs to make this data available to Copilot without migrating the data to Microsoft 365. What should the administrator configure?
- Woodgrove Bank has developed several AI agents using Microsoft Copilot Studio that interact with Microsoft 365 services. The security team wants to ensure each agent has a distinct, auditable identity that can be managed and monitored independently. The administrator needs to manage the full lifecycle of these agent identities, including creation, permissions assignment, and decommissioning. Which identity platform should be used to manage agent identities?
- Contoso Healthcare has deployed AI agents in Microsoft 365 that access sensitive patient data stored in SharePoint. The security team wants to ensure these agents can only access resources when running from trusted, compliant execution environments. Which control should the administrator implement to enforce this requirement?
- A developer at Lucerne Publishing has submitted a custom AI agent built with Microsoft Copilot Studio to the organization's agent registry for company-wide deployment. As the Microsoft 365 administrator, you receive a request to review and approve this agent. Where should you go to review the agent submission and publish or reject it for organizational use?
- Fourth Coffee's IT administrator needs to configure the organization's agent deployment policy so that only IT-approved agents of the 'Declarative Agent' type are allowed, users cannot share agents externally, and a specific team of business analysts has access to a restricted set of agent templates. Which section in Microsoft 365 is used to configure these agent deployment settings?
- The security team at Adatum Corporation has discovered that a third-party AI agent available in the Microsoft 365 agent registry is connecting to an unauthorized external API endpoint. The administrator needs to immediately prevent any user in the organization from accessing or installing this agent. What action should the administrator take in Agent 365?
- The compliance team at Proseware Inc. suspects that one of their deployed AI agents is performing actions outside its intended scope — specifically, accessing SharePoint libraries that it should not need for its function. The administrator needs to review what actions the agent has been taking and which resources it has accessed. Where should the administrator look to investigate agent activity?
- Bellows College has deployed multiple AI agents that assist faculty with administrative tasks. The data protection officer has raised concerns that agents may be processing or transmitting student PII (Personally Identifiable Information) in ways that violate FERPA requirements. The administrator needs to configure protections to prevent agents from processing labeled sensitive data without authorization. Which Agent 365 capability should the administrator use?
- City Power & Light is undergoing an ISO 27001 audit. The compliance officer needs to demonstrate that their AI agents in Microsoft 365 meet specific data handling and access control requirements. The administrator must identify which agents have compliance gaps — such as missing data handling policies, excessive permissions, or unreviewed access to sensitive resources. Which Agent 365 feature should the administrator use?
- Coho Winery has deployed Microsoft 365 Copilot to 200 users across sales, marketing, and finance departments. The CFO wants a monthly report showing how much is being spent on Copilot by department, and the IT administrator wants to set up alerts if monthly AI service costs exceed a defined budget threshold. Where should the administrator go to manage and monitor these AI service costs?
- Wide World Importers deployed Microsoft 365 Copilot six months ago. The VP of IT wants to present to the executive team showing how many users are actively using Copilot in Teams, Word, and Outlook specifically, along with trend data over the past 90 days. Where should the administrator find these workload-level adoption details?
- The Copilot adoption team at Relecloud wants to measure not just raw usage statistics but also how their Copilot deployment compares to similar organizations in their industry, and to track whether users are actually changing their work habits as a result of Copilot. The administrator is looking for a tool that provides adoption benchmarking, sentiment data, and structured adoption recommendations. Which tool should be used?
- Users at Graphic Design Institute are reporting that Microsoft 365 Copilot is responding slowly and occasionally returning errors in Teams and Outlook. The administrator needs to determine whether this is a service-side issue with Copilot infrastructure, check for any active service incidents, and review historical availability data to include in an incident report. Which tool in the Microsoft 365 ecosystem provides this AI-specific service health information?
- Redstone Financial is planning to roll out Microsoft 365 Copilot to 2,000 employees. Before enabling licenses, the CIO asks the Microsoft 365 admin to verify that the tenant is technically ready and that users will have a quality Copilot experience. Which action provides the most comprehensive readiness view across all Microsoft 365 workloads?
- Lakewood Legal Group has deployed Microsoft 365 Copilot for its attorneys. Within two weeks, attorneys report that Copilot is surfacing confidential settlement documents from other case teams in its responses. The Microsoft 365 admin suspects widespread data oversharing in SharePoint. Which tool should the admin use first to identify and report on sites and files that are accessible to more users than intended?
- Nordic Biotech's compliance team has determined that employees must not use AI tools that reference external internet sources when working with proprietary research data. The Microsoft 365 admin needs to ensure that Microsoft 365 Copilot Chat does not use web content to generate responses for any user in the tenant. What is the correct configuration step?
- Apex Insurance Group's IT governance policy requires that all Microsoft 365 license acquisitions go through a formal procurement process approved by the CFO. The IT admin discovers that some business unit managers have been independently purchasing Microsoft 365 Copilot licenses through Microsoft's self-service portal. How should the admin prevent future self-service Copilot license purchases?
- Cascade Logistics has a large ServiceNow instance containing IT incident history, knowledge base articles, and change records. The IT operations team wants Microsoft 365 Copilot to be able to answer questions like 'What's the resolution for incident INC0012345?' by pulling from ServiceNow data. What must the administrator configure to make this possible?
- BlueStar Technology has begun deploying AI agents across multiple business units. The security team requires that every AI agent have a traceable, auditable identity that can be managed through the same lifecycle processes used for human users and service accounts. Which feature in Microsoft Entra should the administrator use to register and manage agent identities?
- Quantum Analytics has deployed an internal AI agent that processes sensitive financial forecasts. The security team wants to ensure that this agent can only be accessed by users who are connecting from compliant, Intune-managed devices. Non-compliant device access attempts should be blocked. What should the administrator configure to enforce this requirement?
- SunPath Insurance has built a custom AI agent using Microsoft Copilot Studio that helps claims adjusters look up policy coverage. A developer has submitted this agent for organizational deployment. Before users can access it from Microsoft Teams and Microsoft 365 Copilot Chat, what step must the Microsoft 365 administrator complete?
- Crestview University's IT governance board has mandated that only IT-approved AI agents may be used within the organization. Users must not be able to create personal agents or use agents from outside the approved list. As the Microsoft 365 administrator, which configuration satisfies this requirement?
- Ironclad Manufacturing's CISO wants a weekly report showing which AI agents are being used across the organization, how many sessions each agent handled, and which data sources each agent accessed. The security team specifically wants to identify any agents that accessed sensitive production data stores. Which Microsoft 365 feature provides this agent activity visibility?
- Vertex Law Firm has deployed an internal AI agent that helps paralegals draft case summaries. The data governance team discovers through Agent 365 monitoring that the agent is including content from privileged attorney-client communications — documents labeled 'Highly Confidential / Privileged' — in its responses without restriction. What should the administrator do in Agent 365 to prevent this?
- Redwood Community Bank is subject to strict FFIEC and SOX compliance requirements. Their compliance officer wants to evaluate whether the bank's deployed AI agents create any regulatory gaps — specifically, whether agents are operating without proper data retention policies, audit logging, or approved data handling procedures. Which capability in Agent 365 should the administrator use to surface these gaps?
- Pinnacle Staffing Solutions has hired 50 contract workers for a 90-day software development project. These contractors need access to a specialized AI coding agent within Microsoft 365 for the duration of the project only. After 90 days, their access should automatically expire without manual intervention. Which approach should the administrator use?
- Skyline Media Group has deployed Microsoft 365 Copilot across three business units: Editorial, Marketing, and Sales. The CFO needs a monthly breakdown of Copilot license costs and AI service consumption allocated by business unit to support internal cost chargebacks. How should the Microsoft 365 administrator provide this visibility?
- Harborview Health System has deployed Microsoft 365 Copilot to 500 clinical and administrative staff. Three months in, the IT director wants to know which Microsoft 365 workloads (Teams, Outlook, Word, etc.) are seeing the highest Copilot adoption, and which workloads are being underutilized despite license assignment. Where should the administrator go to find this workload-level Copilot adoption data?
- Pacific Ventures Capital has deployed Microsoft 365 Copilot to 300 investment analysts. Six months in, the CTO asks for a centralized view showing overall Copilot adoption trends, a breakdown of which users are active versus licensed-but-inactive, and the ability to drill into specific teams to understand their Copilot usage patterns. Which tool provides this centralized AI adoption intelligence?
- Multiple users at Meridian Consulting are reporting that Microsoft 365 Copilot in Teams stopped generating responses approximately 45 minutes ago. The Microsoft 365 administrator needs to quickly determine whether this is an organization-wide service degradation, a configuration issue, or a subset of affected users, before escalating to Microsoft Support. What is the best first step?
- Before buying 800 Copilot licenses, IT must assess tenant readiness (prereqs, user eligibility). What should they run first?
- Copilot surfaces HR files to broad audiences. Permissions appear overshared. What is the best remediation approach?
- A regulated firm forbids Copilot from using web search grounding. Where is the control?
- Managers buy Copilot seats via self-service, bypassing procurement. How does IT stop future self-service purchases?
- Copilot must answer from on-prem Confluence without migrating spaces to SharePoint. What should be configured?
- Each custom AI agent needs a distinct auditable non-human identity with lifecycle management. Which platform feature?
- Users may invoke a finance agent only from Intune-compliant devices. What enforces this?
- A developer submitted a Copilot Studio agent for org-wide use. Where does the M365 admin approve/publish or reject it?
- IT policy allows only approved agent types; users must not freely create/share unrestricted agents. Where are allowed agent types and sharing controls configured?
- A third-party agent in the registry calls an unauthorized external API. How do you immediately stop org use?
- Compliance suspects an agent accessed SharePoint libraries outside scope. Where to review agent actions and resource access?
- Agents must not process content labeled Highly Confidential without authorization. Which Agent 365 focus area applies?
- An ISO audit needs identification of agents missing proper controls (excessive permissions, missing policies). What feature helps surface gaps?
- Contractors need a specialized agent for 90 days then auto-lose access. Best approach?
- CFO wants AI spend monitoring and alerts when monthly Copilot/AI costs exceed a threshold. Where?
- Leadership wants active Copilot usage broken down by Word, Teams, and Outlook over 90 days. Where?
- The adoption team wants Copilot adoption insights and a place to check Copilot-specific service health signals. Which hub is designed for this?
- Data readiness for Copilot includes oversharing, labeling gaps, and compliance issues. Which mindset is correct?
- Admins need to configure Microsoft 365 Copilot Search experiences and related search intelligence data sources. Where are search/data source admin controls generally managed?
- Legal wants an AI disclaimer on Copilot experiences; IT wants controlled release preferences. Where are these tenant Copilot settings?
- IT must control which in-app Copilot experiences are available to users as Microsoft exposes admin controls. What is the administrative approach?
- Sales wants Copilot grounded in Salesforce opportunity data. Best integration path?
- Each production agent must have a responsible owner for operations and review. Where is owner management for agents handled?
- Only approved templates should be available when users create agents. What settings area?
- Security wants an inventory of Microsoft and third-party agents present in the tenant registry. Where?
- IT built a custom agent package that must be made available under admin control. What registry action applies?
- Admins must manage tools available to agents in Agent 365 (what capabilities agents may call). What is the focus?
- CISO wants weekly metrics: agent sessions, heavy users, unusual spikes. Where?
- A legal agent must not ground on privileged labeled matter. What should admins emphasize?
- Agent 365 flags an agent with excessive permissions and missing audit configuration. Next step?
- Finance needs Copilot costs allocated by department for chargeback. What admin capability supports this?
- Leadership wants adoption trends and guidance beyond raw active-user counts for Copilot. Which system is purpose-built?
- Users report Copilot errors in Outlook. Admin wants AI-focused service health context quickly. Best first pane?
- Readiness shows some users lack eligible base licenses for in-app Copilot. What should admin do before assigning Copilot?
- Users paste secrets into Copilot prompts. Which controls help reduce this risk?
- Web search must be off for Copilot Chat enterprise grounding policy. Admin action?
- Legal requires AI disclaimer text; security wants to restrict AI image/video generation features if available in tenant settings. Where?
- Org must manage third-party AI providers connected to Microsoft 365 AI experiences per admin controls. What is the admin goal?
- After deploying a Graph connector, users see only external items they are allowed to see. Why?
- A retired agent must no longer authenticate or access Microsoft 365. What lifecycle step?
- Users must request a premium research agent with manager approval. Best governance tool?
- Only the Data Science security group may use a class of agents. Where to constrain user access?
- Submitted agent requests excessive Graph permissions. Admin decision?
- Users must not install agents that are not approved. Which control family?
- Overnight an agent tripled SharePoint read volume. Where to investigate?
- HR agent must not exfiltrate employee PII to unauthorized channels. Controls?
- Auditors request evidence of agent compliance gap reviews. What should admins retain/export?
- AI costs spiked 40% month-over-month. First admin check?
- Many users have Copilot licenses but zero activity for 60 days. What should IT consider?
- Copilot fails for a subset of users while CCS and Service health show healthy. Likely next checks?
- Copilot readiness is green for licenses but users complain of slow responses at one site. Parallel check?
- Many links are 'People in organization.' Why is this still a Copilot risk?
- Security policy: Copilot Chat may use work content but not the public web. Configuration?
- Self-service purchase is disabled globally, but a pilot team needs an exception process. Best governance approach?
- An agent only needs read access to one SharePoint site. How should its Entra Agent ID be permissioned?
- Conditional Access should target agent workload identities differently from humans. What design approach is appropriate?
- Agent owner leaves the company. What operational step is required?
- Policy forbids sharing agents externally. Where to enforce?
- IT wants to see first-party Microsoft agents available versus third-party. Where?
- A published custom agent later fails security review. Immediate action?
- An agent has tools enabling write actions it does not need. What should admin do?
- SOC wants agent activity in the SIEM. What should be ensured?
- Documents labeled Highly Confidential should not be usable by a general productivity agent. Controls?
- Compliance wants continuous evaluation of agents, not one annual review. Approach?
- Finance wants proactive budget alerts before AI spend exceeds quarterly forecast. Capability?
- CIO wants a single pane for Copilot adoption health and service health narrative for a board update. Best primary hub?
govern-secure-medium-microsoft-365-tenants-workloads · 1 question
These questions are original practice material and are NOT actual exam questions or brain-dump content. Vendor marks are trademarks of their owners. This site is not affiliated with the exam vendor.