AB-100
Agentic AI Business Solutions Architect
A free, card-by-card guide to the AB-100 exam. The exam’s centre of gravity is everything after the demo — responsible AI, security, governance, lifecycle and monitoring — and the cards are weighted to match. Re-checked against Microsoft Learn weekly; last verified 23 August 2026.
44 cards · 44 written up so far · free, no sign-up · leads to Microsoft Certified: Agentic AI Business Solutions Architect (Expert)
Foundations
Card 01What an agent actually is — and what it is not
The four things question stems confuse — flow, chatbot, copilot, agent — where agents genuinely earn their place, and the three situations where reaching for one is marked wrong.
Card 02The Microsoft agentic stack — picking the surface
What each surface is actually for, the four questions that resolve almost every surface scenario, and why "right idea, wrong product" is the distractor pattern to watch for.
Card 03The vocabulary that runs through every question
Grounding, tools and orchestration in plain terms, the difference between MCP and A2A that the exam deliberately blurs, and the words in a stem that decide the answer on their own.
Domain 1 · Plan
Card 04Requirements — deciding where an agent genuinely helps
The four-step assessment, the three lenses the outline names, how to organise data so other systems can use it, and why the baseline has to exist before you build.
Card 05Data readiness — the five grounding dimensions
Each dimension learned by its failure mode, why a smaller curated corpus beats a comprehensive one, and the reason availability means permissions rather than uptime.
Card 06AI adoption, and the Center of Excellence
The six Cloud Adoption Framework phases and why guardrails come before the first build, the three jobs of a CoE, and why the strongest governance answer makes the compliant path the easiest one.
Card 07Extend, configure, or build custom
The list you work down until something fits, the good and bad reasons for a custom model, and the ladder that ends with fine-tuning teaching form rather than facts.
Card 08Designing a multi-agent solution
The three legitimate reasons to split — surface, owner, risk — when splitting is dodging a design problem, and the generative-at-the-edges pattern worth preferring.
Card 09Prompts as an organisational asset
Why a prompt library exists, the guidelines worth publishing, where small models earn their place, and the rule that a prompt is guidance rather than enforcement.
Card 10Model choice and the model router
The ladder climbed in order, what a router must have before it is safe to use, and why choosing small against large follows the shape of the task rather than the ambition.
Card 11The money — ROI, TCO, and build versus buy
The four parts of total cost, how to build an ROI case that survives a finance conversation, and why the omitted operate line always flatters a custom build.
Domain 2 · Design
Card 12The three agent shapes
Prompt-and-response, task and autonomous, how to read the shape out of a scenario, and the four controls every autonomous agent needs without exception.
Card 13Copilot Studio — orchestration, topics and fallback
The three orchestration modes and when each is right, the honest trade between classic and generative, and why the fallback log is the best monitoring you can buy.
Card 14Agent flows and prompt actions
The two ways to make an agent do something, where each belongs, and the pattern that answers most scenario questions: reason at the edges, execute through a flow.
Card 15Copilot in Dynamics 365 — customer experience and service
The four design tasks the outline names, why business terms stop answers being generically right and locally wrong, and the three situations that justify a custom agent alongside.
Card 16Dynamics 365 finance and supply chain — AI features and knowledge
Starting from the process rather than the feature, preferring what ships, and why adding a knowledge source is a governed change rather than a configuration tweak.
Card 17Power Platform AI — hub, canvas apps and generative pages
The building blocks and where each fits, inserting AI where judgement repeats rather than where exactness is needed, and why a clever feature that changes no decision has improved nothing.
Card 18The Well-Architected Framework for intelligent workloads
Each pillar turned into a question you can ask about a real design, what good looks like against each, and why these questions reward the boring option over the capable one.
Card 19Extensibility — custom models, MCP and Computer Use
The three extension routes and the order to prefer them, when to extend Microsoft 365 Copilot rather than build separately, and why Computer Use is the over-engineering distractor.
Card 20Agent behaviours, and agents inside Microsoft 365
Reasoning and voice as trades rather than upgrades, why over-refusal is also a failure, and what changes when an agent is grounded on a SharePoint site.
Card 21Orchestrating prebuilt agents and Microsoft 365 apps
Find, configure, extend, then build — and why most exam answers land on step two. Plus what to check before proposing Copilot for Sales or Service.
Domain 3 · Deploy
Card 22Monitoring vs evaluation — the distinction behind many questions
Why a green dashboard is fully compatible with an agent that is systematically wrong, what to instrument, and why the fallback log is the best single investment you can make.
Card 23The metrics — and the dangerous one
What each metric actually tells you, why containment rises both when the agent is good and when users give up, and how to tell a content problem from a retrieval one.
Card 24Tuning — the four causes, and the order to work in
Diagnosing before changing anything, the tuning order from cheapest to most expensive, and why misreading a retrieval failure as a content gap makes the problem worse.
Card 25Testing agents — why the usual approach breaks
Why conventional test practice fails on non-deterministic output, the four ways to judge quality, and why an agent that refuses too much has failed rather than played safe.
Card 26The evaluation set — the durable asset
What makes a set worth having, why every production failure becomes a test case, and why the set outlives the agent, the model and the platform it was built for.
Card 27ALM — the minimum viable setup
The seven things a defensible lifecycle contains, the four parts that actually make up an agent, and why promoting the definition alone reproduces the look but not the behaviour.
Card 28ALM per platform — what differs
How each platform versions and promotes, the catch that comes with each, why a kill switch is not a rollback, and where to look first when dev works and production does not.
Card 29Responsible AI in practice
What each of the six principles demands of an architect, the question to ask of every control, and why fairness measured in aggregate has not been measured at all.
Card 30Security — an agent is an access amplifier
Acting identity as the highest-value control, the three residency questions rather than one, and why data can sit perfectly still and still leave the boundary.
Card 31Adversarial AI — prompt manipulation and containment
Why models cannot separate instruction from data, the defences ranked by what actually works, and the one question that turns an unbounded worry into an answerable one.
Card 32Governance — the three-way split
Who may create, use and share agents — three questions controlled in different places, the blunt toggle that couples two of them, and why sharing is an allow-list with no per-user deny.
Master cards
Card 33The decision tables — everything condensed
Picking the surface, the agent shapes, orchestration, grounding, the model ladder and the money — all of it in the tables you would want the morning of the exam.
Card 34The Deploy half — condensed
The largest domain in one card: monitoring against evaluation, the four tuning causes, testing, lifecycle, security and adversarial — and the enforced-or-intended test.
Card 35How the questions are built, and how to read them
The five judgements the exam rewards, the five distractor patterns to spot, and the order to read a question in so the constraint eliminates two options before you start.
Added after the August 2026 sweep
Card 36AI maturity, and Success by Design
Domain 1. Two frameworks with two different scopes, the four AI adoption maturity levels, and why selling a level ahead of where an organisation sits is how these programmes fail.
Card 37What things actually cost — credits, not tokens
Domain 1. Copilot Studio bills per action at rates that vary a hundredfold, the biggest lever is a licensing decision, and running out of capacity disables agents rather than slowing them.
Card 38The named Dynamics 365 agents, app by app
Domain 2. Two platform families and what each inherits, then every named agent — Sales seven, Customer Service seven, Project Operations three, and why Commerce has none.
Card 39The grounding pipeline — whose pipeline is it?
Domain 2. Microsoft owns the index for Microsoft 365 grounding, so chunking is not a customer surface — and the six stages for when the pipeline genuinely is yours.
Card 40Voice — two agent types, not one setting
Domain 2. Basic against real-time voice agents and how the requirement picks between them, what both need to exist at all, and why reasoning bills twice.
Card 41Validation metrics — match the family to the model
Domain 3. Precision, recall and F1 for classification, mAP for detection, Foundry evaluators for anything generative — and what makes a criterion real rather than a wish.
Card 42The four security control planes
Domain 3. Entra Agent ID, Agent 365, Purview and Defender — each learned by the question it answers, why agent identity stopped being optional in July 2026, and the two things Customer Lockbox quietly does not cover.
Card 43The three harnesses — the choice you cannot undo
Domain 2. Copilot Studio has been restructured around harnesses. What each one is for, why topics are scoped rather than gone, and why an agent can never move between them.
Card 44What shipped in 2026, and where it lands
The currency check. What went generally available during 2026 and what is still preview, mapped to the card it belongs to — plus the three changes that alter an answer rather than just your vocabulary.