Instiq
Chapter 3 · Basic administration for Copilot and agents·v1.3.0·Updated 8/1/2026·~12 min

What's changed: (1) Fixed out-of-area distractors in nine mini-quizzes: NSG, TDE and Azure Key Vault are outside the official scope and were replaced with real features from the same Copilot/agent administration area (license assignment, PAYG billing policies, Copilot Analytics, prompt management, user access configuration, approval process, agent creation and monitoring), matching the fix applied to questions ab900-059/062/065/066/067/068/069/070/071. (2) Removed paragraph p-intune from section 2: Microsoft Intune appears in neither the skills measured nor the audience profile (inherited from the predecessor MS-900) and is unrelated to the subject of this section, Copilot administration. Question ab900-081, which carried the same inheritance, was likewise replaced with an official topic (creating an agent). / Section 2 now describes billing policies concretely, per Microsoft Learn (pay-as-you-go/setup): the Azure subscription and resource group charged, the users/groups in scope, a budget that notifies rather than caps, activation by connecting the policy to a pay-as-you-go service, the roles required to create one, and the 50-per-tenant limit. Mini-quiz q2 was rebuilt to match the corrected ab900-064 (distractors are now real features in the same Copilot administration area). Added per-section figures (cert-figure-retrofit). New AB-900 Chapter 3 (Domain 3 "Copilot and agent administration": capabilities = Copilot vs agents/monthly-PAYG/enable-disable/Researcher-Analyst-custom agents; Copilot admin = license assignment/PAYG billing policies/Copilot Analytics usage-adoption/prompt management; agent admin = user access config/creation/approval process/monitoring via M365 and Power Platform admin centers)

3.3Basic administrative tasks for agents

Key points

Understand configuring user access to agents, creating an agent, the agent approval process, and monitoring agents (usage, operational insights, lifecycle) using the Microsoft 365 admin center and the Microsoft Power Platform admin center.

Agents are powerful, so governing who can use them, whether they are approved, and whether they run safely is essential. Admins manage the whole lifecycle: access configuration, creation, approval, and monitoring.

3.3.1Access configuration, creation, and approval

First, configure user access to control which users/groups can use which agents (least privilege). Create agents tailored to org knowledge and processes. Before distributing across the org, run them through an approval process so unapproved agents are not used ungoverned—ensuring safety and governance.

3.3.2Monitoring agents and lifecycle

After deployment, monitor agents’ usage, operational insights, and lifecycle (create → publish → update → retire). Use the Microsoft 365 admin center and the Microsoft Power Platform admin center to govern agents built in tools like Copilot Studio. Remember the flow: "create → approve → monitor → retire."

TaskWhatWhere
Configure accessWho can use which agentControl with least privilege
CreateSpecialized to org knowledge/processesCopilot Studio, etc.
ApproveApproval process before distributionPrevent ungoverned use
MonitorUsage/operational insights/lifecycleM365 admin center / Power Platform admin center
Warning

Watch the mix-ups: (1) distribute agents only after an approval process (prevent ungoverned use). (2) Monitor using both the Microsoft 365 admin center and the Power Platform admin center. (3) Configure access with least privilege.

Exam point

Common: requirement → admin task. E.g., "control who can use an agent" = configure user access; "review before org-wide distribution" = approval process; "monitor agent usage/lifecycle" = M365 admin center / Power Platform admin center; "provide an org-specific agent" = create an agent.

Diagram of the agent administration lifecycle: create, test, publish, approve/govern, monitor.
Agent administration lifecycle

3.3.3Section summary

  • Agent lifecycle: configure access (least privilege) → create → approve → monitor
  • Run an approval process before distribution to prevent ungoverned use
  • Monitor using both the M365 admin center and the Power Platform admin center

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Before distributing agents org-wide, what should they go through to prevent ungoverned use of unapproved ones?

Q2. Which admin task controls which users/groups can use which agents?

Q3. Which admin centers are used to monitor agent usage, operational insights, and lifecycle?

Q4. Which admin task provides an agent specialized to org-specific knowledge or processes?

Q5. Which best represents the general agent management lifecycle?

Q6. Which principle best applies when configuring access to agents?

Check your understandingPractice questions for Chapter 3: Basic administration for Copilot and agents

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.