manage-secure-ai-services-microsoft-365
Microsoft 365 AI Services Administrator Associate · 101 questions
- An organization discovers dozens of unused Copilot agents with broad Graph permissions. What is the most appropriate lifecycle action?
- Contoso Ltd. is planning to deploy Microsoft 365 Copilot to 500 users. Before purchasing licenses, the IT administrator wants to evaluate whether the tenant is ready for Copilot. Which tool in the Microsoft 365 admin center should the administrator use first to assess tenant readiness?
- Fabrikam Inc. has enabled Microsoft 365 Copilot and discovered that Copilot is surfacing confidential HR documents to general employees in its responses. The security administrator suspects data oversharing is occurring through SharePoint. What is the BEST approach to identify and resolve this data readiness issue?
- Northwind Traders is a financial services company with strict data handling policies. The compliance team has determined that Microsoft 365 Copilot must not use web search when generating responses, to prevent any risk of data leakage to external services. Where should the administrator configure this setting?
- Adventure Works has deployed Microsoft 365 Copilot company-wide. The legal team requires that every Copilot-generated response displayed to users includes a visible disclaimer stating that AI-generated content should be verified before use. Additionally, the IT department wants to prevent users from purchasing Copilot add-ons independently through self-service. Which admin center is the CORRECT location to configure BOTH of these settings?
- Tailspin Toys wants Microsoft 365 Copilot to be able to search and retrieve information from their on-premises ServiceNow knowledge base when responding to user queries. The administrator needs to make this data available to Copilot without migrating the data to Microsoft 365. What should the administrator configure?
- Woodgrove Bank has developed several AI agents using Microsoft Copilot Studio that interact with Microsoft 365 services. The security team wants to ensure each agent has a distinct, auditable identity that can be managed and monitored independently. The administrator needs to manage the full lifecycle of these agent identities, including creation, permissions assignment, and decommissioning. Which identity platform should be used to manage agent identities?
- Contoso Healthcare has deployed AI agents in Microsoft 365 that access sensitive patient data stored in SharePoint. The security team wants to ensure these agents can only access resources when running from trusted, compliant execution environments. Which control should the administrator implement to enforce this requirement?
- A developer at Lucerne Publishing has submitted a custom AI agent built with Microsoft Copilot Studio to the organization's agent registry for company-wide deployment. As the Microsoft 365 administrator, you receive a request to review and approve this agent. Where should you go to review the agent submission and publish or reject it for organizational use?
- Fourth Coffee's IT administrator needs to configure the organization's agent deployment policy so that only IT-approved agents of the 'Declarative Agent' type are allowed, users cannot share agents externally, and a specific team of business analysts has access to a restricted set of agent templates. Which section in Microsoft 365 is used to configure these agent deployment settings?
- The security team at Adatum Corporation has discovered that a third-party AI agent available in the Microsoft 365 agent registry is connecting to an unauthorized external API endpoint. The administrator needs to immediately prevent any user in the organization from accessing or installing this agent. What action should the administrator take in Agent 365?
- The compliance team at Proseware Inc. suspects that one of their deployed AI agents is performing actions outside its intended scope — specifically, accessing SharePoint libraries that it should not need for its function. The administrator needs to review what actions the agent has been taking and which resources it has accessed. Where should the administrator look to investigate agent activity?
- Bellows College has deployed multiple AI agents that assist faculty with administrative tasks. The data protection officer has raised concerns that agents may be processing or transmitting student PII (Personally Identifiable Information) in ways that violate FERPA requirements. The administrator needs to configure protections to prevent agents from processing labeled sensitive data without authorization. Which Agent 365 capability should the administrator use?
- City Power & Light is undergoing an ISO 27001 audit. The compliance officer needs to demonstrate that their AI agents in Microsoft 365 meet specific data handling and access control requirements. The administrator must identify which agents have compliance gaps — such as missing data handling policies, excessive permissions, or unreviewed access to sensitive resources. Which Agent 365 feature should the administrator use?
- Coho Winery has deployed Microsoft 365 Copilot to 200 users across sales, marketing, and finance departments. The CFO wants a monthly report showing how much is being spent on Copilot by department, and the IT administrator wants to set up alerts if monthly AI service costs exceed a defined budget threshold. Where should the administrator go to manage and monitor these AI service costs?
- Wide World Importers deployed Microsoft 365 Copilot six months ago. The VP of IT wants to present to the executive team showing how many users are actively using Copilot in Teams, Word, and Outlook specifically, along with trend data over the past 90 days. Where should the administrator find these workload-level adoption details?
- The Copilot adoption team at Relecloud wants to measure not just raw usage statistics but also how their Copilot deployment compares to similar organizations in their industry, and to track whether users are actually changing their work habits as a result of Copilot. The administrator is looking for a tool that provides adoption benchmarking, sentiment data, and structured adoption recommendations. Which tool should be used?
- Users at Graphic Design Institute are reporting that Microsoft 365 Copilot is responding slowly and occasionally returning errors in Teams and Outlook. The administrator needs to determine whether this is a service-side issue with Copilot infrastructure, check for any active service incidents, and review historical availability data to include in an incident report. Which tool in the Microsoft 365 ecosystem provides this AI-specific service health information?
- Redstone Financial is planning to roll out Microsoft 365 Copilot to 2,000 employees. Before enabling licenses, the CIO asks the Microsoft 365 admin to verify that the tenant is technically ready and that users will have a quality Copilot experience. Which action provides the most comprehensive readiness view across all Microsoft 365 workloads?
- Lakewood Legal Group has deployed Microsoft 365 Copilot for its attorneys. Within two weeks, attorneys report that Copilot is surfacing confidential settlement documents from other case teams in its responses. The Microsoft 365 admin suspects widespread data oversharing in SharePoint. Which tool should the admin use first to identify and report on sites and files that are accessible to more users than intended?
- Nordic Biotech's compliance team has determined that employees must not use AI tools that reference external internet sources when working with proprietary research data. The Microsoft 365 admin needs to ensure that Microsoft 365 Copilot Chat does not use web content to generate responses for any user in the tenant. What is the correct configuration step?
- Apex Insurance Group's IT governance policy requires that all Microsoft 365 license acquisitions go through a formal procurement process approved by the CFO. The IT admin discovers that some business unit managers have been independently purchasing Microsoft 365 Copilot licenses through Microsoft's self-service portal. How should the admin prevent future self-service Copilot license purchases?
- Cascade Logistics has a large ServiceNow instance containing IT incident history, knowledge base articles, and change records. The IT operations team wants Microsoft 365 Copilot to be able to answer questions like 'What's the resolution for incident INC0012345?' by pulling from ServiceNow data. What must the administrator configure to make this possible?
- BlueStar Technology has begun deploying AI agents across multiple business units. The security team requires that every AI agent have a traceable, auditable identity that can be managed through the same lifecycle processes used for human users and service accounts. Which feature in Microsoft Entra should the administrator use to register and manage agent identities?
- Quantum Analytics has deployed an internal AI agent that processes sensitive financial forecasts. The security team wants to ensure that this agent can only be accessed by users who are connecting from compliant, Intune-managed devices. Non-compliant device access attempts should be blocked. What should the administrator configure to enforce this requirement?
- SunPath Insurance has built a custom AI agent using Microsoft Copilot Studio that helps claims adjusters look up policy coverage. A developer has submitted this agent for organizational deployment. Before users can access it from Microsoft Teams and Microsoft 365 Copilot Chat, what step must the Microsoft 365 administrator complete?
- Crestview University's IT governance board has mandated that only IT-approved AI agents may be used within the organization. Users must not be able to create personal agents or use agents from outside the approved list. As the Microsoft 365 administrator, which configuration satisfies this requirement?
- Ironclad Manufacturing's CISO wants a weekly report showing which AI agents are being used across the organization, how many sessions each agent handled, and which data sources each agent accessed. The security team specifically wants to identify any agents that accessed sensitive production data stores. Which Microsoft 365 feature provides this agent activity visibility?
- Vertex Law Firm has deployed an internal AI agent that helps paralegals draft case summaries. The data governance team discovers through Agent 365 monitoring that the agent is including content from privileged attorney-client communications — documents labeled 'Highly Confidential / Privileged' — in its responses without restriction. What should the administrator do in Agent 365 to prevent this?
- Redwood Community Bank is subject to strict FFIEC and SOX compliance requirements. Their compliance officer wants to evaluate whether the bank's deployed AI agents create any regulatory gaps — specifically, whether agents are operating without proper data retention policies, audit logging, or approved data handling procedures. Which capability in Agent 365 should the administrator use to surface these gaps?
- Pinnacle Staffing Solutions has hired 50 contract workers for a 90-day software development project. These contractors need access to a specialized AI coding agent within Microsoft 365 for the duration of the project only. After 90 days, their access should automatically expire without manual intervention. Which approach should the administrator use?
- Skyline Media Group has deployed Microsoft 365 Copilot across three business units: Editorial, Marketing, and Sales. The CFO needs a monthly breakdown of Copilot license costs and AI service consumption allocated by business unit to support internal cost chargebacks. How should the Microsoft 365 administrator provide this visibility?
- Harborview Health System has deployed Microsoft 365 Copilot to 500 clinical and administrative staff. Three months in, the IT director wants to know which Microsoft 365 workloads (Teams, Outlook, Word, etc.) are seeing the highest Copilot adoption, and which workloads are being underutilized despite license assignment. Where should the administrator go to find this workload-level Copilot adoption data?
- Pacific Ventures Capital has deployed Microsoft 365 Copilot to 300 investment analysts. Six months in, the CTO asks for a centralized view showing overall Copilot adoption trends, a breakdown of which users are active versus licensed-but-inactive, and the ability to drill into specific teams to understand their Copilot usage patterns. Which tool provides this centralized AI adoption intelligence?
- Multiple users at Meridian Consulting are reporting that Microsoft 365 Copilot in Teams stopped generating responses approximately 45 minutes ago. The Microsoft 365 administrator needs to quickly determine whether this is an organization-wide service degradation, a configuration issue, or a subset of affected users, before escalating to Microsoft Support. What is the best first step?
- Before buying 800 Copilot licenses, IT must assess tenant readiness (prereqs, user eligibility). What should they run first?
- Copilot surfaces HR files to broad audiences. Permissions appear overshared. What is the best remediation approach?
- A regulated firm forbids Copilot from using web search grounding. Where is the control?
- Managers buy Copilot seats via self-service, bypassing procurement. How does IT stop future self-service purchases?
- Copilot must answer from on-prem Confluence without migrating spaces to SharePoint. What should be configured?
- Each custom AI agent needs a distinct auditable non-human identity with lifecycle management. Which platform feature?
- Users may invoke a finance agent only from Intune-compliant devices. What enforces this?
- A developer submitted a Copilot Studio agent for org-wide use. Where does the M365 admin approve/publish or reject it?
- IT policy allows only approved agent types; users must not freely create/share unrestricted agents. Where are allowed agent types and sharing controls configured?
- A third-party agent in the registry calls an unauthorized external API. How do you immediately stop org use?
- Compliance suspects an agent accessed SharePoint libraries outside scope. Where to review agent actions and resource access?
- Agents must not process content labeled Highly Confidential without authorization. Which Agent 365 focus area applies?
- An ISO audit needs identification of agents missing proper controls (excessive permissions, missing policies). What feature helps surface gaps?
- Contractors need a specialized agent for 90 days then auto-lose access. Best approach?
- CFO wants AI spend monitoring and alerts when monthly Copilot/AI costs exceed a threshold. Where?
- Leadership wants active Copilot usage broken down by Word, Teams, and Outlook over 90 days. Where?
- The adoption team wants Copilot adoption insights and a place to check Copilot-specific service health signals. Which hub is designed for this?
- Data readiness for Copilot includes oversharing, labeling gaps, and compliance issues. Which mindset is correct?
- Admins need to configure Microsoft 365 Copilot Search experiences and related search intelligence data sources. Where are search/data source admin controls generally managed?
- Legal wants an AI disclaimer on Copilot experiences; IT wants controlled release preferences. Where are these tenant Copilot settings?
- IT must control which in-app Copilot experiences are available to users as Microsoft exposes admin controls. What is the administrative approach?
- Sales wants Copilot grounded in Salesforce opportunity data. Best integration path?
- Each production agent must have a responsible owner for operations and review. Where is owner management for agents handled?
- Only approved templates should be available when users create agents. What settings area?
- Security wants an inventory of Microsoft and third-party agents present in the tenant registry. Where?
- IT built a custom agent package that must be made available under admin control. What registry action applies?
- Admins must manage tools available to agents in Agent 365 (what capabilities agents may call). What is the focus?
- CISO wants weekly metrics: agent sessions, heavy users, unusual spikes. Where?
- A legal agent must not ground on privileged labeled matter. What should admins emphasize?
- Agent 365 flags an agent with excessive permissions and missing audit configuration. Next step?
- Finance needs Copilot costs allocated by department for chargeback. What admin capability supports this?
- Leadership wants adoption trends and guidance beyond raw active-user counts for Copilot. Which system is purpose-built?
- Users report Copilot errors in Outlook. Admin wants AI-focused service health context quickly. Best first pane?
- Readiness shows some users lack eligible base licenses for in-app Copilot. What should admin do before assigning Copilot?
- Users paste secrets into Copilot prompts. Which controls help reduce this risk?
- Web search must be off for Copilot Chat enterprise grounding policy. Admin action?
- Legal requires AI disclaimer text; security wants to restrict AI image/video generation features if available in tenant settings. Where?
- Org must manage third-party AI providers connected to Microsoft 365 AI experiences per admin controls. What is the admin goal?
- After deploying a Graph connector, users see only external items they are allowed to see. Why?
- A retired agent must no longer authenticate or access Microsoft 365. What lifecycle step?
- Users must request a premium research agent with manager approval. Best governance tool?
- Only the Data Science security group may use a class of agents. Where to constrain user access?
- Submitted agent requests excessive Graph permissions. Admin decision?
- Users must not install agents that are not approved. Which control family?
- Overnight an agent tripled SharePoint read volume. Where to investigate?
- HR agent must not exfiltrate employee PII to unauthorized channels. Controls?
- Auditors request evidence of agent compliance gap reviews. What should admins retain/export?
- AI costs spiked 40% month-over-month. First admin check?
- Many users have Copilot licenses but zero activity for 60 days. What should IT consider?
- Copilot fails for a subset of users while CCS and Service health show healthy. Likely next checks?
- Copilot readiness is green for licenses but users complain of slow responses at one site. Parallel check?
- Many links are 'People in organization.' Why is this still a Copilot risk?
- Security policy: Copilot Chat may use work content but not the public web. Configuration?
- Self-service purchase is disabled globally, but a pilot team needs an exception process. Best governance approach?
- An agent only needs read access to one SharePoint site. How should its Entra Agent ID be permissioned?
- Conditional Access should target agent workload identities differently from humans. What design approach is appropriate?
- Agent owner leaves the company. What operational step is required?
- Policy forbids sharing agents externally. Where to enforce?
- IT wants to see first-party Microsoft agents available versus third-party. Where?
- A published custom agent later fails security review. Immediate action?
- An agent has tools enabling write actions it does not need. What should admin do?
- SOC wants agent activity in the SIEM. What should be ensured?
- Documents labeled Highly Confidential should not be usable by a general productivity agent. Controls?
- Compliance wants continuous evaluation of agents, not one annual review. Approach?
- Finance wants proactive budget alerts before AI spend exceeds quarterly forecast. Capability?
- CIO wants a single pane for Copilot adoption health and service health narrative for a board update. Best primary hub?