What active Exam AB-650 measures
AB-650 targets administrators who configure, manage, secure, govern, monitor, and continuously optimize Microsoft 365 tenants, workloads, Microsoft 365 Copilot, agents, and connected AI services. The audience is expected to collaborate across identity, security, compliance, endpoints, infrastructure, applications, and workload administration and to understand Microsoft Graph PowerShell.
Tenant, licensing, workloads, resilience, and health
Weeks 1–2Build a reliable Microsoft 365 administration baseline before layering security or AI services.
- Configure branding, organization profile, privacy and security settings, verified domains, DNS, and the default domain
- Manage users, groups, contacts, licenses, group-based licensing, processing errors, pay-as-you-go, and AI service licenses
- Monitor Microsoft 365 Copilot, Agent 365, and Copilot Studio entitlement and utilization
- Create shared mailboxes and manage Exchange recipients and delegated access
- Create teams, channels, owners, members, guests, external access, and meeting transcription or Copilot settings
- Create SharePoint sites and manage owners, permissions, sharing, OneDrive, Microsoft Search, and site exclusions
- Configure Microsoft 365 Backup protection, restore content, validate recovery, and monitor operations
- Use Service health, notifications, Network Connectivity Insights, and documented escalation paths
Identity, authentication, privileged access, and Zero Trust
Weeks 3–4Verify explicitly, use least privilege, and assume breach across users, guests, administrators, and supported agent identities.
- Create and manage users, guest users, contacts, groups, Microsoft 365 groups, administrative units, and scoped roles
- Use bulk operations and Microsoft Graph PowerShell with least-privilege permissions and auditable output
- Review external access, guest sponsorship, memberships, entitlement, inactivity, and removal
- Replace standing privileged roles with eligible PIM assignments where appropriate
- Configure role activation duration, MFA or authentication context, justification, approval, notification, and access review
- Configure authentication methods, phishing-resistant strengths, Password Protection, and SSPR
- Investigate sign-in, registration, password-reset, and authentication-method issues from logs and diagnostics
- Plan Conditional Access scope, emergency access, report-only testing, What If, staged enforcement, and rollback
- Use ID Protection risk signals and require risk-appropriate remediation where licensing supports it
Defender, Purview, and workload governance
Weeks 5–6Protect collaboration and sensitive information through layered prevention, detection, investigation, response, and lifecycle controls.
- Review the Defender for Office 365 protection stack, Standard and Strict presets, and justified custom policies
- Configure anti-phishing, anti-spam, anti-malware, Safe Links, Safe Attachments, reporting, quarantine, and Tenant Allow/Block List governance
- Investigate email and collaboration alerts through incidents, Explorer, entity pages, submissions, and automated investigation evidence
- Plan authorized attack simulation training with safe payloads, target groups, training, notifications, privacy, and support
- Define sensitive information types, sensitivity labels, label policies, encryption, markings, and auto-labeling where supported
- Design DLP intent, locations, scope, conditions, actions, policy tips, override, alerts, simulation, tuning, and enforcement
- Create retention labels, retention-label policies, and retention policies for keep, delete, records, and Copilot interaction requirements
- Use Activity explorer, audit, DLP alerts, and Defender correlation to investigate data events
- Apply administrative scoping and separation of duties to security and compliance administration
Microsoft 365 Copilot readiness, settings, search, and data security
Weeks 7–8Enable Copilot only after identity, workload, permission, content, policy, cost, support, and network readiness are measurable.
- Assess licenses, in-app experiences, network, Service health, organizational settings, support, and pilot personas
- Find and remediate SharePoint and OneDrive oversharing, broad groups, anonymous links, stale sites, missing owners, and obsolete content
- Use SharePoint Advanced Management, data access governance, DSPM data-risk assessments, search restrictions, or site exclusions appropriately
- Validate direct access, Microsoft Search, Copilot Search, and Copilot responses with controlled authorized and unauthorized personas
- Configure web search, Microsoft 365 Copilot Search, release preferences, self-service purchase, AI disclaimer, and generation settings
- Manage Copilot user experiences, Copilot Cowork, third-party AI providers, and current tenant capabilities according to policy
- Review Copilot connectors for source ownership, indexed data, ACL mapping, crawl scope, data flow, cost, monitoring, and retirement
- Use labels, DLP, retention, audit, DSPM, and Defender evidence to protect and investigate AI activity
- Teach users to validate output, handle sensitive data, report issues, and understand that Copilot honors existing access rather than repairing it
Agent 365 governance, cost, adoption, health, and readiness
Weeks 9–10Operate agents as accountable identities and governed applications with bounded tools, data, access, monitoring, cost, and lifecycle.
- Use Microsoft Entra Agent ID to manage agent owners, sponsors, authentication, authorization, lifecycle workflows, risk, sign-ins, and audit
- Secure agent access with dedicated identities, access packages, narrow permissions, Conditional Access where supported, reviews, and expiration
- Configure allowed agent types, sharing, templates, user access, and ownership expectations
- Discover Microsoft and third-party agents in Agent Registry and review pending requests
- Publish, reject, install, block, upload, scope, version, re-review, or retire agents according to documented criteria
- Limit Agent 365 tools by purpose, identity, resource, input, destination, and human approval for consequential actions
- Monitor Agent 365 activity, sensitive-data access, DLP, DSPM, Defender, audit, compliance gaps, owner status, and lifecycle
- Monitor Copilot and AI cost, Copilot Credits, license utilization, workload-level adoption, task outcomes, support, and incidents
- Use Copilot Control System and Microsoft 365 Service health to monitor adoption and reliability
- Complete both projects, review every domain, explain distractors, and rehearse expansion, containment, rollback, and retirement
PrepKloud AB-650 study surfaces
Twenty-five varied questions balanced across the current 24%, 40%, and 36% domain mix.AB-650 flashcards
Review tenant, identity, Defender, Purview, Copilot, Agent 365, cost, adoption, and health concepts.Two administration projects
Harden a synthetic Microsoft 365 tenant and design a governed Copilot and Agent 365 rollout.Complete AB-650 guide
Read the blueprint strategy, control relationships, project path, and study plan.Explore relevant jobs
Compare portfolio evidence with Microsoft 365, identity, security, compliance, and AI administration roles.PrepKloud blog
Continue with Zero Trust, AI security, Copilot governance, and career guidance.
Official Microsoft sources
Confirm the current audience, skills, weights, updates, and study resources.
Open Microsoft LearnReview tenant setup, workloads, licensing, Backup, service health, and network connectivity.
Open Microsoft 365 admin docsReview users, groups, roles, PIM, authentication, Conditional Access, risk, governance, and Agent ID.
Open Entra documentationReview threat policies, alerts, investigation, response, and attack simulation.
Open Defender documentationReview information protection, DLP, retention, audit, DSPM, and AI data security.
Open Purview documentationReview Copilot deployment and governance plus current Agent 365 capabilities and administration.
Open Microsoft 365 Copilot documentationFrequently asked questions
Is AB-650 an active Microsoft exam?
Yes. Microsoft publishes the current study guide for Exam AB-650: Administering Microsoft 365 and AI Services. The guide was last updated July 28, 2026. Verify it before scheduling.
What are the AB-650 domain weights?
Configure and manage Microsoft 365 tenants and workloads is 20–25%; govern and secure Microsoft 365 tenants and workloads is 40–45%; manage and secure AI services in Microsoft 365 is 35–40%.
Does AB-650 cover both users and AI agents?
Yes. It covers conventional tenant identities and workloads plus Microsoft 365 Copilot, Entra Agent ID, Agent Registry, Agent 365 access and tools, data protection, cost, adoption, and service health.
What should be completed before a broad Copilot rollout?
Review licensing, network and workload readiness, source permissions, oversharing, labels, DLP, retention, identity, Conditional Access, privileged roles, support, cost, and pilot evidence before expanding.
Are PrepKloud AB-650 materials exam dumps or guarantees?
No. They are original educational materials grounded in public objectives and official Microsoft documentation. They contain no live, recalled, leaked, or proprietary exam content and cannot guarantee a passing result.
Practice operating one governed Microsoft 365 and AI estate
Use original questions, focused flashcards, and two evidence-driven projects spanning conventional workloads and the agentic workplace.