Responsible AI, Security, Governance, Risk and Compliance
This topic covers agent security, governance, model security, vulnerability analysis, prompt manipulation, responsible AI review, data residency, movement compliance, access controls on grounding data and model tuning, and audit trails.
How to study for Microsoft AB-100
Treat each item as an architecture decision: identify the business process, select the Microsoft AI pattern, then add ALM, telemetry, security, responsible AI, and governance controls.
Core concepts
Concept 1
Secure AI-powered business solutions need agent security, model security, access controls, protected grounding data, secure tuning workflows, and audit trails.
Exam cue: Use prompt manipulation defenses when user input can override agent instructions or actions.
Concept 2
Responsible AI review should assess solution behavior against fairness, reliability, safety, privacy, security, inclusiveness, transparency, and accountability.
Exam cue: Use data residency checks when grounding data or model workflows cross geographic or tenant boundaries.
Concept 3
Compliance checks should validate data residency, data movement, model changes, tuning access, prompt manipulation defenses, and governance evidence.
Exam cue: Use audit trails when changes to models, prompts, grounding data, and access need accountability.
Risk pitfalls and guardrails
Giving agents broad access to grounding data without least privilege.
Guardrail: Avoid defaulting to custom agents, skipping grounding-data checks, or treating prompts and connectors as outside the release process.
Treating responsible AI as a launch checklist instead of ongoing governance.
Guardrail: Avoid defaulting to custom agents, skipping grounding-data checks, or treating prompts and connectors as outside the release process.
Skipping audit trails for prompt, model, and data changes.
Guardrail: Avoid defaulting to custom agents, skipping grounding-data checks, or treating prompts and connectors as outside the release process.
Memory anchors
Agent Security
Agent security protects identities, actions, data access, channels, and tool permissions.
Model Security
Model security protects model access, tuning workflows, outputs, and deployment configuration.
Prompt Manipulation
Prompt manipulation attempts to override, bypass, or misuse agent instructions and safeguards.
Data Residency
Data residency controls where data is stored, processed, and moved.
Grounding Access Control
Grounding access control limits source data access based on user and solution permissions.
Tuning Access
Tuning access controls who can modify model behavior and what data may be used.
Audit Trail
An audit trail records changes and actions for accountability and investigation.
Responsible AI Review
A responsible AI review evaluates the solution against responsible AI principles and risk controls.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A Copilot Studio agent uses a service account with access to every Dataverse table, although it reads only customer cases. What should the architect change?
An internal agent is configured with no authentication and linked to restricted knowledge. What is the correct design response?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
