AB-900 data protection and governance
Understand data protection and governance tasks for Microsoft 365 and Copilot is worth 35–40% of AB-900, the largest share of the exam. It covers four things: the Microsoft Purview solutions, how Copilot accesses data, the tools that surface data risks, and oversharing in SharePoint. The skill being tested is matching a problem to the right tool — and there are many tools that sound alike.
The Purview solutions
| Solution | Answers the question |
|---|---|
| Information Protection | How do we classify and protect this content, wherever it goes? |
| Data Loss Prevention (DLP) | How do we stop sensitive content leaving where it should stay? |
| Data Lifecycle Management | How long do we keep this, and when do we delete it? |
| Insider Risk Management | Is someone inside behaving in a way that puts data at risk? |
| Communication Compliance | Are messages breaking our conduct or regulatory policies? |
| DSPM for AI | What are people doing with AI, and what sensitive data is involved? |
Sensitivity labels
A sensitivity label classifies content and can protect it: encryption, content marking such as headers and watermarks, and settings for containers such as sites, groups and teams. Because encryption travels with the file, protection holds after the file is downloaded or emailed. Labels matter for Copilot too: Copilot respects the usage rights encryption grants, and content it creates from labelled sources can inherit the label.
Typical use cases: marking confidential documents, restricting a board pack to named people, preventing external sharing of a site.
Classification
Purview identifies sensitive content with sensitive information types (patterns such as credit card or passport numbers), trainable classifiers (content categories learned from examples, such as contracts or CVs) and exact data match. Classification feeds labels, DLP and the explorers.
DLP
A DLP policy watches a location — Exchange, SharePoint, OneDrive, Teams, devices, and Microsoft 365 Copilot — for content that matches conditions, then warns, blocks or audits. Users see policy tips; admins receive alerts they can investigate and resolve. A DLP policy for Copilot can stop it processing content with specific sensitivity labels.
Retention
Retention keeps content for a set period, deletes it afterwards, or both. A retention policy applies broadly to locations; a retention label applies to individual items and can be applied manually or automatically. When a user deletes an item that must be retained, it is preserved out of sight until the period ends.
Insider risk versus communication compliance
Easy to mix up. Insider Risk Management analyses activity — mass downloads, copying to USB, sharing before resignation — to find risky users. Communication Compliance reviews message content in email, Teams and Copilot interactions for harassment, sensitive information or regulatory breaches. Both are designed with privacy controls, such as pseudonymised user names.
How Copilot accesses data
- Copilot grounds its answers in organisational content through Microsoft Graph: emails, files, chats, meetings and calendars.
- It only retrieves what the signed-in user already has permission to access. It does not bypass permissions, labels or DLP.
- Prompts, responses and data accessed through Graph are not used to train the foundation models.
- Protections in Microsoft 365, Purview and Defender — permissions, labels, DLP, audit — apply to Copilot as they do to users.
The consequence is the central idea of this domain: Copilot does not create oversharing, it reveals it. A file shared with everyone years ago was always accessible; Copilot simply makes it easy to find.
Microsoft’s responsible AI principles also appear here: fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability.
Tools that surface risk
| You need to | Use |
|---|---|
| Measure compliance against a regulation and get improvement actions | Compliance Manager |
| See where sensitive items are stored | Data Explorer |
| See what users did with labelled or sensitive content | Activity explorer |
| Investigate risky user behaviour | Insider Risk Management |
| Triage an alert from a blocked share | DLP alerts |
| Review messages that broke a conduct policy | Communication Compliance |
| Discover AI use and sensitive data in prompts | DSPM for AI |
| Find emails and files for a legal request | eDiscovery Content search |
Oversharing in SharePoint
SharePoint is where most oversharing lives, so it gets its own objective group.
- Data access governance reports in the SharePoint admin center list sites with many sharing links, sites shared with “everyone except external users”, and sites with sensitive labelled content.
- SharePoint Advanced Management adds governance features, including restricted access control, which limits a site to members of a specified group even if content inside was shared more widely, plus site access reviews and inactive site policies.
- DSPM for AI and Purview reports show where Copilot interactions touch sensitive data.
The usual sequence is discover (reports), then contain (restricted access, labels), then fix at the source (owners remove broad links and permissions).
Sample questions
Question 1. Before rolling out Copilot, a company wants to find SharePoint sites that are shared with 'everyone except external users', so owners can tighten access. What should the admin run?
- A. A data access governance report in SharePoint
- B. A Compliance Manager assessment
- C. A retention policy for all SharePoint sites
- D. A Communication Compliance policy
Show answer
Answer: A
A data access governance report in the SharePoint admin center lists sites shared with broad groups such as everyone except external users, which is exactly the oversharing check needed before Copilot. Compliance Manager scores regulatory posture. A retention policy keeps or deletes content. Communication Compliance reviews messages, not site permissions.
Want more questions like this? Full AB-900 practice tests →
Question 2. Legal must keep all email from the finance department for seven years and then delete it. Users must not be able to remove it permanently before then. What should you configure?
- A. A sensitivity label with encryption
- B. A DLP policy for Exchange
- C. An Insider Risk Management policy
- D. A retention policy set to retain for seven years and then delete
Show answer
Answer: D
A retention policy on the finance mailboxes with a keep-then-delete setting preserves the email for seven years, even if users delete it, and removes it afterwards. A sensitivity label protects content but does not control how long it is kept. DLP stops sharing. Insider Risk Management detects risky behaviour.
Want more questions like this? Full AB-900 practice tests →
Question 3. The CISO wants to know which AI apps employees use, and whether prompts sent to them contain sensitive information. Which Purview capability is designed for this?
- A. Activity explorer
- B. DSPM for AI
- C. eDiscovery Content search
- D. Compliance Manager
Show answer
Answer: B
Data Security Posture Management for AI discovers AI activity across Copilot and other AI apps and reports on sensitive data in prompts and responses. Activity explorer shows label and DLP activity, not an AI-focused view. Content search finds items for investigations. Compliance Manager assesses regulatory controls.
Want more questions like this? Full AB-900 practice tests →
What to practise
Write each tool in the “tools that surface risk” table on a card, and each problem on another, and match them until it is automatic. Then create one sensitivity label, one DLP policy and one retention policy in a test tenant and watch how each behaves on the same document. Most wrong answers in this domain are a right tool for a different problem.