GregLab | Exam Prep

Understand data protection and governance tasks for Microsoft 365 and Copilot

Copilot Data Access, Graph, and Responsible AI

Core

Understand how identity, Microsoft Graph, source permissions, Purview, Defender, and responsible AI combine to govern Copilot without creating a new permission boundary.

Aligned to the current AB-900 guide, verified July 22, 2026.

Why this matters

AB-900 expects you to explain how Copilot grounds responses in permitted Microsoft 365 data and why administrators must fix oversharing at the source.

Must Know

  • Microsoft 365 Copilot combines the user prompt, orchestration, Microsoft Graph grounding, and large language models to produce a response.
  • Microsoft Graph retrieves relevant work context in the signed-in user’s context; it does not grant new permission.
  • Permission trimming enforces existing access during retrieval. It does not decide whether the underlying access is appropriate.
  • Fix oversharing by correcting source ownership, memberships, sharing links, and permissions—not by changing the prompt or blaming Copilot.
  • Entra controls identity and access signals; Purview protects and governs data; Defender supplies threat detections and investigation signals.
  • Responsible AI principles are fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability.
  • Important Copilot output still requires validation and human accountability.

Compare and Distinguish

  • Graph grounding vs permission grant: retrieve relevant permitted context vs change who may access a resource.
  • Copilot permission trimming vs source permission remediation: enforce existing access during retrieval vs correct the access model itself.
  • Entra access vs Purview protection: identity/policy decision vs data classification, protection, lifecycle, and compliance controls.
  • Purview vs Defender: data security/compliance controls and evidence vs threat protection and security signals.
  • Responsible AI vs technical permission: principles and accountable use vs an enforceable resource-access decision.

Scenario examples

  • Scenario: Copilot cites a file a user should not need, and the user can open it manually. Think: Investigate SharePoint permissions and oversharing first.
  • Scenario: A user cannot open a cited-looking source. Think: Verify the citation, current access, identity, and source status; Copilot does not bypass a denied permission.
  • Scenario: Confidential content must remain encrypted in Copilot-enabled workflows. Think: Use a sensitivity label and correct source permission; Graph is not the protection policy.
  • Scenario: A manager wants to act on an unverified generated conclusion. Think: Apply transparency, validation, and accountable human review.

Exam traps

  • Copilot does not create a separate access-control list or fix source oversharing.
  • Microsoft Graph is not a license, a sensitivity label, or a permission-remediation tool.
  • Purview and Defender complement identity/source permission; neither makes those layers unnecessary.
  • Responsible AI principles guide safe and accountable use but do not replace technical controls or human validation.

Key takeaways

  • Identity + source permission define the boundary; Graph supplies relevant permitted grounding.
  • Fix oversharing at the source; add Purview and Defender as complementary layers.
  • Generated output assists people—important decisions remain accountable and verified.
How it works
  • The user authenticates, Copilot interprets the prompt, Microsoft Graph retrieves relevant permitted context, the orchestration layer constructs a grounded request, and the model generates a response with citations or source links where supported.
  • Permission trimming prevents retrieval of content the user cannot access, but any overly broad direct, inherited, group-derived, or link-based access remains valid from the service’s perspective.
  • Purview and Defender operate as layers: labels and DLP govern data, audit records activity, DSPM surfaces posture, and Defender contributes security signals. Human review remains responsible for consequential decisions and factual validation.
Objects and administrative surfaces
  • Users, groups, authentication, Conditional Access, and app access — Microsoft Entra admin center.
  • Sites, mailboxes, teams, files, sharing links, and source permissions — their workload admin centers and resource experiences.
  • Labels, DLP, retention, audit, eDiscovery, and DSPM — Microsoft Purview portal; incidents and security signals — Microsoft Defender portal.
  • Copilot settings, licensing, access, reports, and agent governance — Microsoft 365 admin center.
When to use it
  • Fix source permissions when Copilot surfaces content a user should not need, especially when the user can open the source directly.
  • Use Purview when the requirement is classification, protection, risky-data-use control, lifecycle, investigation evidence, or posture.
  • Use Defender when the question concerns malicious activity, correlated incidents, or security investigation, and apply responsible AI review to important output.
Security and governance implications
  • Prepare sources before rollout: identify owners, remove broad links and memberships, classify sensitive data, and establish review cycles.
  • Use least privilege for identities, applications, connectors, agents, and administrative roles; audit high-impact changes and interactions.
  • Teach users to inspect citations, distinguish generated output from authoritative records, and escalate harmful or suspicious output.
Troubleshooting signals
  • Ask first whether the user can open the source directly. Then trace identity, direct/inherited/group/link permission, item sensitivity, DLP/Conditional Access, and service health.
  • If grounding is missing, check source access, indexing/availability, content support, prompt specificity, and relevant admin settings rather than granting broad access.
  • If a security concern exists, preserve relevant audit/Defender evidence and investigate the source permission and activity together.
More detail
  • Microsoft 365 Copilot combines the user’s prompt, Microsoft Graph grounding, orchestration, and large language models to generate a response. Work grounding can include files, mail, meetings, chats, people, and relationships the signed-in user is authorized to access.
  • Microsoft Graph is the data and API layer that represents Microsoft 365 resources and relationships. Copilot queries it in the user’s context and trims results according to permissions. Graph increases relevance; it does not independently grant access.
  • Identity and access begin in Microsoft Entra ID: the signed-in identity, authentication, Conditional Access, application access, and group membership affect the request. Workload/source permissions remain the boundary for the underlying mailbox, site, file, team, or other resource.
  • Purview adds classification, sensitivity labels, DLP, retention, audit, eDiscovery, risk, and DSPM capabilities. These controls can protect content and monitor interactions, but they do not make bad SharePoint membership correct.
  • Defender products provide security detections and signals about identities, endpoints, email, applications, and cloud activity. Those signals support prevention and investigation around Copilot use; Defender is not a content-permission store.
  • Oversharing is especially important because Copilot can make already-accessible information easier to discover and synthesize. The fix is to right-size source ownership, membership, sharing links, and permissions, then use governance controls as defense in depth.
  • Microsoft’s responsible AI principles include fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. Administrators and users should validate important output, protect data, provide human oversight, and keep accountable decisions with people.

Ready for the quiz?

  • Why does Graph grounding not grant access?
  • How does permission trimming differ from fixing source permissions?
  • What distinct roles do Entra, Purview, and Defender play around Copilot?
  • Why does responsible AI still require human oversight?

Related objectives

  • D2.2.a — Understand how Copilot accesses data
  • D2.2.b — Understand how Microsoft Graph influences Copilot responses
  • D2.2.c — Understand how Copilot uses permissions and other controls in Microsoft 365, Microsoft Purview, and Microsoft Defender to protect against risks
  • D2.2.d — Understand responsible AI principles

Learn more

Free Microsoft 365 Copilot and Agent Administration Fundamentals prep

Build focused AB-900 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not identify the specific item types that will appear on an individual exam before delivery. This lane counts multiple-choice and multiple-response items as exam-style practice. Ordering and matching are supplemental learning exercises and do not count toward exam-style accuracy. Difficulty labels are calibrated to AB-900 Fundamentals, not a Microsoft-published question rating.

Reference

AB-900 topics and reference map

Study links

AB-900 resources