Microsoft Information Security Administrator (SC-401)¶
Data protection in Microsoft 365 and Purview: classify it, label it, stop it leaving, detect the insider, and prove what happened.
SC-401 replaced SC-400. The rename to Information Security Administrator came with a shift toward data security operations and the addition of AI-era material: DSPM for AI, DLP for Copilot, and auditing of AI interactions.
Exam Details¶
- Exam Code: SC-401
- Level: Associate
- Duration: 100 minutes
- Questions: Typically 40-60
- Passing Score: 700/1000
- Cost: USD 165, varies by region
- Prerequisites: None formal
- Validity: 1 year, free online renewal
Full detail in the fact sheet.
Domains¶
| Domain | Weight | Notes |
|---|---|---|
| Implement information protection | 30-35% | 01 |
| Implement data loss prevention | 30-35% | 02 |
| Manage risks, alerts, and activities | 30-35% | 03 |
Three near-equal domains, which is unusual and useful: there is no domain you can afford to skip, and no domain worth over-weighting.
The distinction the whole exam turns on¶
Sensitivity labels classify and protect the content itself. The protection travels with the file. If a labeled and encrypted document is emailed to a personal address, downloaded to a home machine, or posted to a competitor's site, the encryption still applies and the recipient still needs an authorized identity to open it.
DLP policies prevent an action at a boundary. The file itself is unchanged. DLP inspects activity and blocks, warns, or audits when content matching a condition crosses a defined boundary.
Most real designs need both, and most exam distractors offer one when the requirement needs the other. When you read a question, ask: does the requirement describe protection that must persist, or an action that must be prevented?
Study sequence¶
- Classification first. Sensitive information types, trainable classifiers, EDM. Everything else consumes these.
- Sensitivity labels and label policies. Including auto-labeling and the client-side versus service-side distinction.
- DLP. Policy anatomy, then location-specific behavior, then endpoint DLP.
- Insider risk, Adaptive Protection, and the investigation tools.
- Retention, records, audit, and eDiscovery.
Schedule in the practice plan.
Hands-on¶
A Microsoft 365 E5 trial gives you everything here. Build:
- A custom sensitive information type and test it with a sample document
- A sensitivity label with encryption, published through a label policy
- An auto-labeling policy in simulation mode, then read the simulation results
- A DLP policy in test mode with policy tips, then review the alerts
- An insider risk policy from a template, and inspect the indicators it enables
- A retention label with disposition review
Simulation and test modes exist because these controls break user workflows when misconfigured. The exam expects you to use them.
Study resources¶
- π SC-401 study guide - authoritative outline
- π Microsoft Purview documentation - primary reference
- π Microsoft Learn SC-401 path - free official modules
- Practice questions - question bank in this repo