AB-900 Microsoft 365 core features explained

Updated September 28, 2026

Identify the core features and objects of Microsoft 365 services is worth 30–35% of AB-900. It has three parts: the objects each admin center manages, the security principles behind Microsoft 365, and the identity features that enforce them in Microsoft Entra ID. The skill being tested is knowing where things live and which tool answers a given question — not configuring them in depth.

Which admin center owns what

Many questions describe a task and ask where to do it.

Admin centerObjects you configure there
Microsoft 365 admin centerUsers, groups, licences, domain names, org settings, usage reports, Copilot settings
Exchange admin centerMailboxes (user, shared, resource), distribution groups, mail-enabled security groups, mail flow
SharePoint admin centerSites, sharing settings, storage, site admins; libraries and folders live inside sites
Teams admin centerTeams, channels, meeting, messaging and app policies
Microsoft Entra admin centerIdentities, conditional access, authentication methods, app registrations, PIM
Microsoft Purview portalLabels, DLP, retention, audit, eDiscovery, insider risk

Licences and access

A licence decides which services a user can reach. A user without an Exchange Online plan has no mailbox; a user without a Copilot licence does not get Microsoft 365 Copilot in their apps. Licences can be assigned to individual users or to groups. Group-based licensing assigns a licence to every member of a security group or Microsoft 365 group, so access follows membership. Distribution groups cannot carry licences.

SharePoint roles

Every site has three default permission groups:

GroupDefault permission
OwnersFull control, including managing members and settings
MembersEdit: add, change and delete content
VisitorsRead only

Sharing a single file with a link does not add anyone to these groups, which is why links are a common source of oversharing. Folders inherit permissions from their library, and libraries from their site, unless inheritance is broken.

Teams objects

A team is backed by a Microsoft 365 group and a SharePoint site. Standard channels are open to everyone in the team, private channels to a subset, and shared channels to people in other teams or organisations. Policies in the Teams admin center — meetings, messaging, app setup and permissions — are assigned to users or groups, not to teams.

Security principles

Zero Trust

Three principles, which the exam expects you to recognise in scenarios:

  • Verify explicitly — authenticate and authorise every request using all available signals.
  • Use least-privilege access — give just enough access, just in time.
  • Assume breach — segment access, encrypt, and monitor as if an attacker is already inside.

Authentication and authorisation

Authentication proves who you are: passwords, MFA, Microsoft Authenticator, passkeys, Windows Hello for Business. Authorisation decides what you may do once identified: roles, group membership, permissions. Questions often hinge on which of the two is failing.

Threat protection

Microsoft Defender XDR correlates signals from endpoints, identities, email and collaboration, and cloud apps into single incidents, so an analyst sees one attack rather than scattered alerts. Threat intelligence feeds it with knowledge of current attacker techniques.

Core security features in Entra ID

FeatureWhat it does
Conditional accessIf-then policies: given signals such as user, location, device and risk, block access or require MFA or a compliant device
Single sign-onOne identity for many apps; fewer passwords, central control and revocation
Identity Secure ScoreA percentage measuring identity posture against recommended actions, with improvement steps
Sign-in logsEach sign-in attempt, including MFA and which conditional access policies applied
Risky sign-insSign-ins flagged as possibly not by the account owner
Audit logsChanges to users, groups, roles and apps; Purview Audit covers activity across Microsoft 365
Privileged Identity ManagementJust-in-time, time-limited and approval-based activation of admin roles
App registrationsThe definition of an application you build or own
Enterprise applicationsAn application’s presence in your tenant, where you assign users and configure SSO

The last two are commonly confused. An app registration is where developers define an app and its permissions. An enterprise application is the local instance in a tenant — including third-party SaaS apps from the gallery — and it is where an admin controls who can use the app.

Sample questions

Question 1. Several IT staff hold the Global Administrator role permanently. The security team wants them to hold it only when needed, for a limited time, with a justification recorded. What should you use?

  • A. A conditional access policy requiring MFA
  • B. Identity Secure Score recommendations
  • C. Microsoft Entra Privileged Identity Management
  • D. An app registration for each administrator
Show answer

Answer: C

Privileged Identity Management makes roles eligible rather than permanently active, so admins activate them just in time for a set duration, with justification and optionally approval. Conditional access controls how users sign in, not role duration. Identity Secure Score only recommends improvements. An app registration defines an application, not admin access.

Want more questions like this? Full AB-900 practice tests →

Question 2. A project team needs a shared inbox that several people can read and send from, without buying an extra licence. Where and what should the admin create?

  • A. A shared mailbox in the Exchange admin center
  • B. A distribution group in the Exchange admin center
  • C. A document library in the SharePoint admin center
  • D. A messaging policy in the Teams admin center
Show answer

Answer: A

A shared mailbox, created in the Exchange admin center, lets several users read and send as one address and does not need its own licence under normal size limits. A distribution group only forwards mail to members and has no inbox. A SharePoint library stores files, not mail. A Teams messaging policy governs chat features.

Want more questions like this? Full AB-900 practice tests →

Question 3. A company has bought a third-party SaaS application from the Microsoft Entra gallery. The admin must configure single sign-on and control which users can open it. Where is this done?

  • A. App registrations in Microsoft Entra ID
  • B. Enterprise applications in Microsoft Entra ID
  • C. Privileged Identity Management
  • D. The SharePoint admin center
Show answer

Answer: B

Gallery SaaS apps appear under Enterprise applications, which represent the app in your tenant; that is where you configure SSO and assign users and groups. App registrations are for defining applications your organisation develops. PIM manages privileged roles. The SharePoint admin center has no role in app sign-in.

Want more questions like this? Full AB-900 practice tests →

What to practise

Walk through each admin center once with a list of objects in hand, and note where each lives. Then open the Entra sign-in logs, find a failed sign-in and read which conditional access policy applied. Compare an app registration with its enterprise application in your test tenant. By then, most questions in this domain are recognition rather than recall.