I’ve just started preparing for the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals exam, and I’ve decided to document the journey here as I go. Partly to keep myself accountable, and partly because writing about what I learn is the best way I know to actually retain it. If you’re thinking about this certification yourself, I hope these posts give you a realistic picture of what the course covers.
The exam prep course I’m following is Microsoft’s official Introduction to Microsoft 365 and AI administration, which is split into two learning paths — one on Microsoft 365 administration and one on Copilot and agent administration. That’s roughly six and a half hours of content across six modules, and I’m working through it alongside a full-time job, so expect these posts to arrive at a very human pace.
Starting with security (not Copilot)
Here’s the first thing that surprised me: a course about Copilot administration doesn’t open with Copilot at all. It opens with security foundations. And honestly, the more I got into the first module, the more that made sense. Before you let an AI assistant loose across your organisation’s emails, documents, and chats, you’d better be confident about who can access what.
The module is built around the Zero Trust security model, and the core idea is refreshingly simple: stop assuming that anything inside your network is automatically safe. Every access request gets verified — every user, every device, every time. Coming from a world where “inside the office network = trusted” was the default, this is a real mindset shift. But with hybrid and remote work now the norm, the old castle-and-moat approach just doesn’t hold up. There is no moat anymore.
What I found genuinely useful is how Microsoft 365 applies Zero Trust across six areas: identities, endpoints, data, applications, infrastructure, and networks. It’s not one product or one setting — it’s a philosophy baked into the whole platform.
The practical tools
The module then gets hands-on with two features that most of us have already experienced as end users, probably without knowing the admin side:
Multifactor authentication (MFA) — that prompt on your phone when you sign in. Mildly annoying as a user, absolutely essential as an admin. Even if someone steals a password, they hit a second wall.
Conditional Access — this one was new to me in depth, and it’s clever. Instead of blanket rules, access decisions adapt to context: where the sign-in is coming from, what device is being used, how risky the attempt looks. A login from a managed laptop in the office might sail through, while the same account signing in from an unknown device overseas gets challenged or blocked.
The bigger picture: Defender, Intune and Purview
The last part of the module introduces the trio that keeps a Microsoft 365 environment monitored and governed: Microsoft Defender for threat protection, Intune for managing devices and endpoints, and Purview for data governance and compliance. I’ll admit these were mostly just product names to me before this week. Now I at least understand where each one sits — and I suspect they’ll keep coming up as the course moves toward Copilot, because AI administration is really just data governance wearing a new hat.
Where I’m up to
I’ve finished the introduction and the Zero Trust unit, with the rest of the security foundations module ahead of me — identity and authentication, access and permissions, Microsoft Entra, and a module assessment at the end. I’ll share how that goes in the next post.
If you’re studying for AB-900 too, or thinking about it, I’d love to hear how you’re finding it. See you in Part 2.






































