SC-401 Study Guide
A curated learning path for the SC-401 exam: the best documentation, videos, blog posts and tutorials for every exam objective.A curated learning path for the SC-401 exam: the best documentation, videos, blog posts and tutorials for every exam objective, in the order worth studying them.
Microsoft Certified: Information Security Administrator Associate
Exam at a Glance
SC-401 measures whether you can protect an organization's sensitive data in Microsoft 365 with Microsoft Purview: classifying and labeling content, stopping leaks with data loss prevention, retaining and recovering what the business needs, managing insider risk, investigating alerts and audit activity, and extending all of it to data used by AI services like Copilot.
| SC-401 | Administering Information Security in Microsoft 365 |
|---|---|
| Certification | Microsoft Certified: Information Security Administrator Associate |
| Level | Intermediate (associate role-based exam) |
| Exam length | 100 minutes |
| Questions | Typically 40 to 60; the number and format mix can vary |
| Passing score | 700 out of 1000 |
| Question formats | Multiple choice, multiple select, drag and drop, build list, hot area, case studies |
| Microsoft Learn access | Available within the exam; browsing is restricted and the timer continues |
| Skills measured version | July 28, 2026 |
| Renewal | Certification expires annually; renew with a free online assessment on Microsoft Learn |
| Cost | Depends on your country or region; shown when you schedule |
What the Exam Covers
The exam has three equally weighted domains. That split matters: alert investigation and insider risk carry exactly as much weight as the labeling and DLP topics most candidates focus on.
Implement information protection — 30-35%
Data classification (built-in and custom sensitive info types, document fingerprinting, exact data match, trainable classifiers, OCR, Data explorer and Content explorer), sensitivity labels end to end (roles, label design for items and containers, protection settings, publishing and auto-labeling policies, labels for Teams/Groups/Power BI/SharePoint, labeling via Defender for Cloud Apps), the Purview Information Protection client and scanner, and Purview Message Encryption including Advanced Message Encryption.
Implement data loss prevention and retention — 30-35%
DLP policy design, roles, and management; Adaptive Protection integration; policy and rule precedence; Defender for Cloud Apps file policies from DLP; Endpoint DLP (device requirements, advanced rules, settings, just-in-time protection, monitoring); and retention (retention labels and label policies, auto-apply, adaptive policy scopes, policy precedence and Policy lookup, retention policies, recovering retained content).
Manage risks, alerts, and activities — 30-35%
Insider Risk Management (roles, connectors, Defender for Endpoint integration, settings, indicators, policy templates, forensic evidence, risk levels for Adaptive Protection, alerts, cases, workflow), information security alerts (Purview Audit licensing and investigation, audit retention policies, Activity explorer, DLP alert response, Defender XDR integration, eDiscovery searches), and protecting data used by AI services (Purview and M365 controls for AI, DSPM for AI prerequisites, roles, policies, and monitoring).
The full bullet-level list lives in the official study guide. Treat it as your checklist:
The Official SC-401 Study Guide
How This Maps to CertiAce Practice Modules
The CertiAce question bank is organized by the same topic areas the exam measures, so you can drill each area in isolation:
| CertiAce practice module | What you will drill there |
|---|---|
| Implement Microsoft Purview Information Protection | Sensitive info types, EDM, trainable classifiers, sensitivity labels, auto-labeling, message encryption |
| Implement and manage Microsoft Purview Data Loss Prevention | DLP policy design and precedence, Endpoint DLP, just-in-time protection, Adaptive Protection, alerts |
| Implement and manage Microsoft 365 retention and recovery | Retention labels vs policies, adaptive scopes, precedence, preservation, recovering content |
| Implement and manage Microsoft Purview Insider Risk Management | Policy templates, indicators, connectors, forensic evidence, adaptive protection, cases |
| Audit and search activity in Microsoft Purview | Audit Standard vs Premium, audit log investigation, retention policies, Activity explorer, eDiscovery |
| Secure AI interactions and environments with Microsoft Purview | DSPM for AI, Copilot data protection, AI-app controls in Purview and M365 |
Where SC-401 Fits
| Certification | What it validates | When to take it |
|---|---|---|
| SC-900: Security, Compliance, and Identity Fundamentals | Foundational knowledge of Microsoft security, compliance, and identity solutions | Optional first step if you are new to the Microsoft security stack |
| SC-401: Information Security Administrator Associate (this exam) | Protecting sensitive data with Microsoft Purview: information protection, DLP, retention, insider risk, AI data security | You are here |
| SC-100: Cybersecurity Architect Expert | Designing an organization-wide cybersecurity strategy on Zero Trust principles | A later architecture goal. SC-401 does not satisfy its certification prerequisite; you also need a qualifying associate certification. |
To become a Microsoft Certified: Cybersecurity Architect Expert you must hold at least one of three associate certifications in addition to passing SC-100: Identity and Access Administrator Associate (exam SC-300), Security Operations Analyst Associate (exam SC-200), or Cloud and AI Security Engineer Associate (exam SC-500). Information Security Administrator Associate (exam SC-401) is not one of them, so plan a second associate exam if SC-100 is your goal.
SC-401 has no official prerequisites, but it assumes you know your way around Microsoft 365 administration. If Purview and the compliance portal are completely new to you, SC-900 first builds the vocabulary; if you already work in the Purview or Defender portals, go straight to SC-401.
Before You Start
The exam assumes practical Microsoft 365 experience. Check yourself against this table. Anything unfamiliar is where your preparation should start:
| Area | You should be comfortable with |
|---|---|
| Microsoft 365 services | Exchange Online, SharePoint, OneDrive, and Teams from an admin's point of view. That is where the protected data lives |
| Microsoft Purview portal | Navigating the portal and knowing which solution solves which problem |
| Microsoft Entra | Users, groups, and roles. Purview permissions build on them |
| Defender portal awareness | What Defender XDR and Defender for Cloud Apps are. Several alert workflows land there |
| PowerShell | Reading and running basic Exchange Online / Security & Compliance PowerShell |
Step-by-Step Study Plan
How long you need depends on where you start. Treat these estimates as planning guidance and adjust them to your starting knowledge and weekly study hours:
| Your starting point | Suggested prep time |
|---|---|
| Working with Purview (labels, DLP, retention) weekly | 2 to 4 weeks |
| Experienced M365 admin, newer to Purview depth | 4 to 8 weeks |
Step 1: Read the Official Study Guide
Skim the full skills-measured list once, and mark every bullet you could not explain to a colleague. That marked-up list is your personal syllabus: everything else in this plan exists to clear it. Pay particular attention to the "Protect data used by AI services" section: it is the newest material, and older compliance-era study resources do not cover it at all.
Step 2: Schedule Your Exam
Choose a realistic target date after reviewing the skills list and your available study time. A date on the calendar turns studying into a countdown, so pick one using the prep-time table above and plan backwards from it.
Certification and Exam Details Page
Step 3: Work Through the Official Course Material
Complete the SC-401 course modules on Microsoft Learn. Take notes on every concept you cannot explain in one sentence, and flag anything that needs hands-on practice. You will come back to those in Step 4.
Official Course Page (SC-401T00)
Step 4: Get Hands-On Practice
SC-401 is an implementation exam, and Purview behavior is much easier to remember once you have configured it yourself. A Microsoft 365 E5 trial (or the Purview solutions trial) supports many of the core exercises. The AI and Copilot exercises have their own prerequisites (licensing, permissions, and available activity data), so check them before you start. Aim for hands-on time with:
- A custom sensitive info type and a trainable classifier, checked in Content explorer
- A sensitivity label with encryption, published and then auto-applied
- A DLP policy in test mode with policy tips, then an Endpoint DLP rule
- A retention label and an adaptive scope, then Policy lookup to see precedence
- An Insider Risk Management policy from a template, reviewing a triggered alert
- DSPM for AI reports for Copilot interactions
Watch how each control surfaces in Activity explorer and the audit log. The investigation domain is about a third of the exam.
Step 5: Benchmark Your Knowledge
Use CertiAce to benchmark your readiness module by module. The practice modules map to the exam domains as shown above, so use the module mapping and the topics behind your missed questions to identify the skills-measured areas to revisit. Microsoft also offers a free official practice assessment. Aim for consistent performance across every module, not one lucky high score.
Free Official Practice Assessment
Step 6: Take the Exam
The day before, review only your weak topics: no brand-new material. On exam day, read each question for what it is truly asking (SC-401 scenarios often hinge on which Purview solution owns the requirement, or which policy wins under precedence) and eliminate options from the wrong solution first.
Worth knowing before you sit down:
- Microsoft Learn is available during the exam in a split screen. Use it to check details you genuinely need: the timer keeps running, and the exam is deliberately too long to look up every answer. Browsing is limited to Microsoft Learn itself (no Q&A, practice assessments, or profile), and personal notes and other websites are unavailable.
- You can take unscheduled breaks, but the clock keeps running and you cannot return to questions you already saw.
- Watch the naming: the exam uses current product names such as Microsoft Purview solutions, Microsoft Defender XDR, Microsoft Entra ID, so cross-check older compliance-center-era product names and objectives against the current study guide.
- Try the exam sandbox beforehand so the question formats and interface hold no surprises: Exam Sandbox
Additional Learning Resources
SC-401 is a young exam, so community prep content is still thin. The official material below is the reliable core, and more community resources will appear over time:
| Resource | Type | Why it is useful |
|---|---|---|
| Free Official Practice Assessment | Practice | Microsoft's own question-style preview, free |
| Official SC-401 Exam Prep Videos | Video series | Microsoft's exam-prep series for SC-401, straight from the certification team |
| Microsoft Purview documentation | Docs hub | The entire exam lives in this doc set: information protection, DLP, retention, insider risk, audit, DSPM |
| Learn about data loss prevention | Docs | The DLP domain's anchor page: policy model, locations, precedence |
| Data Security Posture Management for AI | Docs | The AI-security domain's source of truth |
| Security, compliance, and identity community hub | Community | Microsoft's official SCI community: announcements and discussions |
Realistic SC-401 exam-style questions with instant feedback and detailed explanations.
Practice SC-401 now