SC-401STUDY GUIDEFree
Guides

SC-401 Study Guide

A curated learning path for the SC-401 exam: the best documentation, videos, blog posts and tutorials for every exam objective.

Microsoft Certified: Information Security Administrator Associate


Exam at a Glance

SC-401 measures whether you can protect an organization's sensitive data in Microsoft 365 with Microsoft Purview: classifying and labeling content, stopping leaks with data loss prevention, retaining and recovering what the business needs, managing insider risk, investigating alerts and audit activity, and extending all of it to data used by AI services like Copilot.

SC-401Administering Information Security in Microsoft 365
CertificationMicrosoft Certified: Information Security Administrator Associate
LevelIntermediate (associate role-based exam)
Exam length100 minutes
QuestionsTypically 40 to 60; the number and format mix can vary
Passing score700 out of 1000
Question formatsMultiple choice, multiple select, drag and drop, build list, hot area, case studies
Microsoft Learn accessAvailable within the exam; browsing is restricted and the timer continues
Skills measured versionJuly 28, 2026
RenewalCertification expires annually; renew with a free online assessment on Microsoft Learn
CostDepends on your country or region; shown when you schedule

 

What the Exam Covers

The exam has three equally weighted domains. That split matters: alert investigation and insider risk carry exactly as much weight as the labeling and DLP topics most candidates focus on.

 

Implement information protection — 30-35%

Data classification (built-in and custom sensitive info types, document fingerprinting, exact data match, trainable classifiers, OCR, Data explorer and Content explorer), sensitivity labels end to end (roles, label design for items and containers, protection settings, publishing and auto-labeling policies, labels for Teams/Groups/Power BI/SharePoint, labeling via Defender for Cloud Apps), the Purview Information Protection client and scanner, and Purview Message Encryption including Advanced Message Encryption.

 

Implement data loss prevention and retention — 30-35%

DLP policy design, roles, and management; Adaptive Protection integration; policy and rule precedence; Defender for Cloud Apps file policies from DLP; Endpoint DLP (device requirements, advanced rules, settings, just-in-time protection, monitoring); and retention (retention labels and label policies, auto-apply, adaptive policy scopes, policy precedence and Policy lookup, retention policies, recovering retained content).

 

Manage risks, alerts, and activities — 30-35%

Insider Risk Management (roles, connectors, Defender for Endpoint integration, settings, indicators, policy templates, forensic evidence, risk levels for Adaptive Protection, alerts, cases, workflow), information security alerts (Purview Audit licensing and investigation, audit retention policies, Activity explorer, DLP alert response, Defender XDR integration, eDiscovery searches), and protecting data used by AI services (Purview and M365 controls for AI, DSPM for AI prerequisites, roles, policies, and monitoring).

 

The full bullet-level list lives in the official study guide. Treat it as your checklist:

The Official SC-401 Study Guide

 

How This Maps to CertiAce Practice Modules

The CertiAce question bank is organized by the same topic areas the exam measures, so you can drill each area in isolation:

CertiAce practice moduleWhat you will drill there
Implement Microsoft Purview Information ProtectionSensitive info types, EDM, trainable classifiers, sensitivity labels, auto-labeling, message encryption
Implement and manage Microsoft Purview Data Loss PreventionDLP policy design and precedence, Endpoint DLP, just-in-time protection, Adaptive Protection, alerts
Implement and manage Microsoft 365 retention and recoveryRetention labels vs policies, adaptive scopes, precedence, preservation, recovering content
Implement and manage Microsoft Purview Insider Risk ManagementPolicy templates, indicators, connectors, forensic evidence, adaptive protection, cases
Audit and search activity in Microsoft PurviewAudit Standard vs Premium, audit log investigation, retention policies, Activity explorer, eDiscovery
Secure AI interactions and environments with Microsoft PurviewDSPM for AI, Copilot data protection, AI-app controls in Purview and M365

 

Where SC-401 Fits

CertificationWhat it validatesWhen to take it
SC-900: Security, Compliance, and Identity FundamentalsFoundational knowledge of Microsoft security, compliance, and identity solutionsOptional first step if you are new to the Microsoft security stack
SC-401: Information Security Administrator Associate (this exam)Protecting sensitive data with Microsoft Purview: information protection, DLP, retention, insider risk, AI data securityYou are here
SC-100: Cybersecurity Architect ExpertDesigning an organization-wide cybersecurity strategy on Zero Trust principlesA later architecture goal. SC-401 does not satisfy its certification prerequisite; you also need a qualifying associate certification.

To become a Microsoft Certified: Cybersecurity Architect Expert you must hold at least one of three associate certifications in addition to passing SC-100: Identity and Access Administrator Associate (exam SC-300), Security Operations Analyst Associate (exam SC-200), or Cloud and AI Security Engineer Associate (exam SC-500). Information Security Administrator Associate (exam SC-401) is not one of them, so plan a second associate exam if SC-100 is your goal.

SC-401 has no official prerequisites, but it assumes you know your way around Microsoft 365 administration. If Purview and the compliance portal are completely new to you, SC-900 first builds the vocabulary; if you already work in the Purview or Defender portals, go straight to SC-401.

 

Before You Start

The exam assumes practical Microsoft 365 experience. Check yourself against this table. Anything unfamiliar is where your preparation should start:

AreaYou should be comfortable with
Microsoft 365 servicesExchange Online, SharePoint, OneDrive, and Teams from an admin's point of view. That is where the protected data lives
Microsoft Purview portalNavigating the portal and knowing which solution solves which problem
Microsoft EntraUsers, groups, and roles. Purview permissions build on them
Defender portal awarenessWhat Defender XDR and Defender for Cloud Apps are. Several alert workflows land there
PowerShellReading and running basic Exchange Online / Security & Compliance PowerShell

 


Step-by-Step Study Plan

How long you need depends on where you start. Treat these estimates as planning guidance and adjust them to your starting knowledge and weekly study hours:

Your starting pointSuggested prep time
Working with Purview (labels, DLP, retention) weekly2 to 4 weeks
Experienced M365 admin, newer to Purview depth4 to 8 weeks

 

Step 1: Read the Official Study Guide

Skim the full skills-measured list once, and mark every bullet you could not explain to a colleague. That marked-up list is your personal syllabus: everything else in this plan exists to clear it. Pay particular attention to the "Protect data used by AI services" section: it is the newest material, and older compliance-era study resources do not cover it at all.

The Official Study Guide

 

Step 2: Schedule Your Exam

Choose a realistic target date after reviewing the skills list and your available study time. A date on the calendar turns studying into a countdown, so pick one using the prep-time table above and plan backwards from it.

Certification and Exam Details Page

 

Step 3: Work Through the Official Course Material

Complete the SC-401 course modules on Microsoft Learn. Take notes on every concept you cannot explain in one sentence, and flag anything that needs hands-on practice. You will come back to those in Step 4.

Official Course Page (SC-401T00)

 

Step 4: Get Hands-On Practice

SC-401 is an implementation exam, and Purview behavior is much easier to remember once you have configured it yourself. A Microsoft 365 E5 trial (or the Purview solutions trial) supports many of the core exercises. The AI and Copilot exercises have their own prerequisites (licensing, permissions, and available activity data), so check them before you start. Aim for hands-on time with:

  • A custom sensitive info type and a trainable classifier, checked in Content explorer
  • A sensitivity label with encryption, published and then auto-applied
  • A DLP policy in test mode with policy tips, then an Endpoint DLP rule
  • A retention label and an adaptive scope, then Policy lookup to see precedence
  • An Insider Risk Management policy from a template, reviewing a triggered alert
  • DSPM for AI reports for Copilot interactions

Watch how each control surfaces in Activity explorer and the audit log. The investigation domain is about a third of the exam.

 

Step 5: Benchmark Your Knowledge

Use CertiAce to benchmark your readiness module by module. The practice modules map to the exam domains as shown above, so use the module mapping and the topics behind your missed questions to identify the skills-measured areas to revisit. Microsoft also offers a free official practice assessment. Aim for consistent performance across every module, not one lucky high score.

CertiAce SC-401 Exam Practice

Free Official Practice Assessment

 

Step 6: Take the Exam

The day before, review only your weak topics: no brand-new material. On exam day, read each question for what it is truly asking (SC-401 scenarios often hinge on which Purview solution owns the requirement, or which policy wins under precedence) and eliminate options from the wrong solution first.

Worth knowing before you sit down:

  • Microsoft Learn is available during the exam in a split screen. Use it to check details you genuinely need: the timer keeps running, and the exam is deliberately too long to look up every answer. Browsing is limited to Microsoft Learn itself (no Q&A, practice assessments, or profile), and personal notes and other websites are unavailable.
  • You can take unscheduled breaks, but the clock keeps running and you cannot return to questions you already saw.
  • Watch the naming: the exam uses current product names such as Microsoft Purview solutions, Microsoft Defender XDR, Microsoft Entra ID, so cross-check older compliance-center-era product names and objectives against the current study guide.
  • Try the exam sandbox beforehand so the question formats and interface hold no surprises: Exam Sandbox

 


Additional Learning Resources

SC-401 is a young exam, so community prep content is still thin. The official material below is the reliable core, and more community resources will appear over time:

ResourceTypeWhy it is useful
Free Official Practice AssessmentPracticeMicrosoft's own question-style preview, free
Official SC-401 Exam Prep VideosVideo seriesMicrosoft's exam-prep series for SC-401, straight from the certification team
Microsoft Purview documentationDocs hubThe entire exam lives in this doc set: information protection, DLP, retention, insider risk, audit, DSPM
Learn about data loss preventionDocsThe DLP domain's anchor page: policy model, locations, precedence
Data Security Posture Management for AIDocsThe AI-security domain's source of truth
Security, compliance, and identity community hubCommunityMicrosoft's official SCI community: announcements and discussions
READY TO TEST YOURSELF?
Practice what you just studied

Realistic SC-401 exam-style questions with instant feedback and detailed explanations.

Practice SC-401 now