AB-650 currently has no official Microsoft practice assessment — Microsoft's own AB-650 exam page confirms one isn't available yet for this beta exam. That makes independently grounded practice questions more useful for AB-650 than for most Microsoft certifications, since there is no official baseline to lean on instead. The 12 questions below are scenario-based, matching the reasoning style of the real exam, and grouped by the three domains from Microsoft's official AB-650 study guide.
Want the full domain breakdown and a study plan before you start? Read the AB-650 study guide first. Prefer a dense reference table for your final review? Jump to the AB-650 cheat sheet.
How These Practice Questions Work
Answer each question before reading its rationale box. Every rationale explains why the correct choice is right andwhy each of the three distractors is wrong — the distractors are built to mirror real Microsoft 365 admin mistakes, not random wrong answers.
Domain 1 Questions: Configure & Manage Tenants and Workloads
Questions 1–3
A 400-person marketing department needs Microsoft 365 Copilot licenses. New hires join the department weekly, and the admin does not want to manually assign a Copilot license to each new account.
Which licensing approach should the admin configure?
Answer: B. Group-based licensing assigns and removes the Copilot license automatically as membership in the security group changes, which is exactly what a department with regular new hires needs. A is what the admin is trying to avoid. C describes a billing model, not a license-assignment mechanism, and doesn't exist as a way to skip assignment. D confuses access control (Conditional Access) with license assignment — Conditional Access can restrict how a license is used, but it doesn't assign the license itself.
A ransomware attack encrypts and deletes files across a SharePoint site. The organization needs to restore the site's content to its state from three days earlier, before the attack began.
Which Microsoft 365 capability is designed for this scenario?
Answer: B. Microsoft 365 Backup exists specifically to set up, restore, and monitor point-in-time recovery of Exchange, SharePoint, and OneDrive content. A is a compliance/lifecycle tool for keeping or deleting content on schedule, not a restore mechanism for an attack. C controls whether a site is included in Copilot indexing — unrelated to data recovery. D is an identity access control, not a data protection or restore feature.
A SharePoint site under active legal hold must remain accessible to the legal team exactly as it is today, but its content should never appear in Microsoft 365 Copilot's generated answers for any user, including the legal team.
What should the admin configure?
Answer: B. Site exclusions in SharePoint Advanced Management remove a site from Copilot's grounding sources without touching the underlying SharePoint permissions. A breaks the requirement that the legal team keep normal access. C would destroy content under legal hold, which is the opposite of what's needed. D blocks SharePoint entirely, far broader than the Copilot-only restriction requested.
Keep going in the real quiz interface
Try 40 Free AB-650 Questions With Instant Scoring
Practice mode with explanations for every answer. No credit card required.
Start Free Practice →Domain 2 Questions: Govern & Secure Tenants and Workloads
Questions 4–8
A helpdesk technician needs Global Administrator rights for exactly 4 hours to complete a tenant migration task, and should not retain that access afterward without re-justifying it.
How should the admin grant this access?
Answer: B. PIM eligible assignments let a user activate a privileged role for a defined window and require re-activation afterward — exactly the temporary, re-justified access described. A grants standing access with no time limit, the opposite of the requirement. C administrative units scope management of users/groups within an org, not role duration. D introduces an unnecessary guest identity and still doesn't time-bound the role.
Security wants MFA required automatically whenever Microsoft Entra ID Protection flags a sign-in as risky, but does not want every user prompted for MFA on every routine sign-in.
What should the admin configure?
Answer: B. A Conditional Access policy that evaluates ID Protection's sign-in risk signal and applies MFA only when risk is detected matches the requirement precisely. A prompts everyone every time, which the scenario explicitly rules out. C SSPR handles forgotten passwords, not risk-based authentication. D Password Protection blocks weak passwords at set time, but does nothing about risky sign-in behavior after the fact.
Defender for Office 365 is already filtering most phishing email, but employees keep clicking the small percentage that gets through. Security wants a way to measure which employees are still vulnerable and train them.
Which capability should the admin use?
Answer: B. Attack simulation training sends realistic simulated phishing to measure who clicks and automatically assigns follow-up training — it addresses the human layer the filtering already missed. A is more mail filtering, which the scenario says is already in place and still being bypassed. C DLP prevents sensitive data leaving the org; it doesn't train users to recognize phishing. D blocking all external email is disproportionate and would break legitimate business email.
Compliance is concerned that Microsoft 365 Copilot could include unmasked national ID numbers from source documents in its generated answers to end users.
What should the admin configure to prevent this?
Answer: B. Purview DLP policies can be scoped specifically to the Copilot location, and a sensitive information type detects the ID number pattern automatically across all matching content — no manual labeling required. A doesn't scale and misses any document an admin forgets to label. C disables the feature entirely rather than protecting the specific data type, over-correcting for the actual requirement. D restricting Copilot to one team doesn't stop that team from seeing the unmasked data — it narrows who has the problem, not the exposure itself.
Legal wants Microsoft Teams chat messages automatically deleted after 3 years, except for any chats currently under an active legal hold, which must be preserved regardless of age.
Which Purview capability satisfies both requirements together?
Answer: B. Retention policies are Purview's data lifecycle management tool for automatic deletion on a schedule, and legal hold takes precedence over a retention policy's delete action — exactly the combination requested. A DLP stops data leaving the org; it doesn't delete data on a timer. C sensitivity labels classify and protect content but don't schedule deletion. D DSPM for AI monitors AI activity and risk, unrelated to chat retention.
Domain 3 Questions: Manage & Secure AI Services
Questions 9–12
An onboarding automation agent needs read access to the HR SharePoint site for exactly 14 days while a new-hire workflow runs, and access should expire automatically afterward without manual cleanup.
How should the admin grant this?
Answer: B. Access packages issued through Entra Agent ID support time-bound assignment for agent identities, which expires access automatically at the end of the window — no manual cleanup step needed. A is permanent, the opposite of the requirement. C a sensitivity label controls usage rights on content the agent already has access to; it doesn't grant site membership or expire automatically. D works but relies on someone remembering to do it manually, which the scenario explicitly wants to avoid.
An employee submits a third-party AI agent for tenant-wide use. The agent has not yet been reviewed for data handling or permissions.
What should happen before the agent becomes installable tenant-wide?
Answer: B. The agent registry is where admins discover, review, and publish or reject both Microsoft and third-party agent submissions before they can be installed broadly. A skips governance entirely, the opposite of what an unreviewed agent needs. C applying Conditional Access after the fact doesn't address whether the agent should have been allowed at all. D a DLP exception is unrelated to whether an agent is vetted for tenant-wide install.
During a Microsoft 365 Copilot pilot, several employees discover Copilot can summarize files they technically have SharePoint permission to open but were never meant to see, because those permissions were set too broadly years ago.
What should the admin address before expanding the Copilot rollout?
Answer: B. Copilot only summarizes what the requesting user already has permission to access — the real problem is over-permissioned content, and data readiness assessment exists specifically to surface and remediate oversharing before wider rollout. A disabling the feature avoids the symptom instead of fixing the permissions issue underneath it. C connectors bring in new data sources; they don't fix existing SharePoint permission sprawl. D a disclaimer addresses trust in the answer, not unauthorized data exposure.
Leadership wants a single view showing Copilot adoption rates broken down by department, alongside overall AI service cost trends for the quarter.
Where should the admin find this?
Answer: B. The Copilot Control System is where AI service costs, workload-level Copilot adoption, and service health are monitored together. A the agent registry manages agent discovery and installation, not adoption reporting. C Purview covers data governance and compliance, not usage or cost trends. D Conditional Access reports show policy evaluation results, not Copilot adoption or spend.
Distractor Patterns to Watch For
Across these 12 questions, the wrong answers fall into four recurring patterns. Recognizing the pattern is often faster than recalling the exact feature name under exam pressure.
| Pattern | What it looks like | Example from above |
|---|---|---|
| Right domain, wrong tool | A Purview or Entra feature that sounds close but solves a different problem (DLP vs. retention, Conditional Access vs. licensing). | Q1 (Conditional Access instead of group licensing), Q8 (DLP instead of retention) |
| Fixes the symptom, not the cause | Disabling a feature entirely instead of remediating the underlying configuration. | Q7 (disabling Copilot Search vs. scoped DLP), Q11 (disabling Copilot vs. fixing permissions) |
| Manual process where automation is required | A correct-sounding manual workaround when the scenario specifically asks for something that scales or expires on its own. | Q1 (manual license assignment), Q9 (manual removal after 14 days) |
| Human-identity assumption applied to agents | A control or grant that works for human users assumed to apply automatically to agent identities. | Q9 (permanent human-style group membership for an agent) |
12 down. 488 to go.
MSCertQuiz maintains a 500-question AB-650 bank, 40 of them free with no signup. Take the timed readiness quiz to see your score broken down by domain.
Frequently Asked Questions
Are these questions harder than the real AB-650 exam?
They're written to match the real exam's scenario-based reasoning style rather than testing simple recall. Since AB-650 has no official practice assessment yet, there's no Microsoft benchmark to calibrate difficulty against directly — these are grounded in the official skills-measured list instead.
Why do these questions include Copilot and Agent 365 material?
Because Domain 3 (Manage and secure AI services in Microsoft 365) makes up 35–40% of AB-650 — nearly two out of every five questions on the real exam touch Copilot, agents, or Agent 365 governance.
Do I need hands-on Microsoft 365 admin experience to answer these?
It helps but isn't required. Each rationale explains the underlying concept, not just the answer letter, so you can learn from a question even without prior hands-on time in the admin center.
How many questions are on the real AB-650 exam?
Microsoft's AB-650 exam page doesn't publish an exact count for this beta exam. Microsoft's general guidance is that most certification exams run 40–60 questions within a 100-minute Associate-level time limit.
What if I get several Domain 2 questions wrong?
Domain 2 (Govern and secure Microsoft 365 tenants and workloads) is the largest at 40–45% of the exam. Missing multiple Domain 2 questions is a strong signal to revisit Entra Conditional Access, PIM, and Purview DLP/retention before your exam date.
About This Practice Set
These questions were written by the MSCertQuiz team, who also maintain the paid 500-question AB-650 practice bank linked above. Every scenario is grounded in Microsoft's official AB-650 study guide (skills measured checked August 2026) rather than adapted from another certification's question set.