Microsoft • SC-401
Plan and implement information security of sensitive data using Microsoft Purview and related services. Covers information protection, data loss prevention, retention, and managing risks and alerts.
Questions
939
Duration
100 minutes
Passing Score
700/1000
Difficulty
AssociateLast Updated
Jan 2026
The SC-401 exam, Administering Information Security in Microsoft 365, validates a candidate's ability to plan and implement information security for sensitive data using Microsoft Purview and related Microsoft services. The exam covers a broad set of data security disciplines including information protection, data loss prevention (DLP), data lifecycle retention, and insider risk management—all within the Microsoft 365 ecosystem. It also addresses the increasingly critical domain of protecting data used by AI services, reflecting Microsoft's focus on securing AI-driven workloads through tools like Data Security Posture Management (DSPM) for AI.
Passing SC-401 earns the Microsoft Certified: Information Security Administrator Associate certification, which replaced the retired SC-400 (Information Protection and Compliance Administrator) certification as of May 31, 2025. The exam encompasses deep technical skills across Microsoft Purview's sensitivity labels, exact data match classifiers, trainable classifiers, endpoint DLP, adaptive scopes, insider risk policies, and audit capabilities—as well as integration points with Microsoft Defender for Cloud Apps, Microsoft Defender XDR, and Microsoft Entra. Candidates must demonstrate proficiency not only in configuring these tools but also in interpreting policy precedence, managing alerts and cases, and responding to security incidents.
This certification is designed for information security administrators and compliance professionals who work primarily within Microsoft 365 environments. Ideal candidates hold roles such as Information Security Administrator, Compliance Specialist, Security Analyst, Microsoft 365 Security Engineer, or Governance and Risk Consultant. These professionals are responsible for designing and enforcing data protection policies, responding to DLP and insider risk alerts, and collaborating with workload administrators, business application owners, and governance stakeholders to implement organization-wide security controls.
The certification is particularly well-suited for mid-career professionals who already have hands-on experience with Microsoft 365 services and are looking to formalize and advance their expertise in the data security and compliance space. It also serves as a stepping stone toward the expert-level Microsoft Certified: Cybersecurity Architect Expert credential.
Microsoft does not enforce formal prerequisites for SC-401, but strong familiarity with the Microsoft 365 platform is essential for success. Candidates should have working knowledge of Microsoft Purview services (including sensitivity labels, DLP policies, retention policies, and insider risk management), Microsoft Entra (formerly Azure AD), the Microsoft Defender portal, and Microsoft Defender for Cloud Apps. Comfort with PowerShell for administrative scripting is also expected, as some exam topics involve command-line management of Purview components.
In terms of experience, Microsoft recommends that candidates have practical, hands-on experience administering information security within a Microsoft 365 tenant. Familiarity with data governance concepts such as data classification, information barriers, records management, and regulatory compliance frameworks will provide important context. Candidates who previously held the SC-400 certification (now retired) will find much of the foundational content familiar, though SC-401 expands coverage into AI data security and updated Purview features.
SC-401 is a proctored exam administered through Pearson VUE and can be taken online or at a testing center. Candidates are given 100 minutes to complete the assessment. The exam contains approximately 65 questions, including a case study with approximately 4 questions and a set of yes/no (binary choice) questions. No performance-based lab (PBT) questions are included. Question types typically include multiple choice, multiple select, drag-and-drop scenario questions, and case study-based items.
The exam is scored on a scale of 1–1000, and a passing score of 700 is required. Scores are reported immediately upon completion. Candidates who fail may retake the exam after 24 hours; subsequent retakes have a variable waiting period per Microsoft's retake policy. The exam is available in English, Portuguese (Brazil), French, German, Japanese, Chinese (Simplified), and Spanish. Non-English speakers may request an additional 30 minutes if taking the exam in a non-native language.
Earning the Microsoft Certified: Information Security Administrator Associate through SC-401 positions professionals for high-demand roles at the intersection of cybersecurity, compliance, and data governance. Certified individuals typically qualify for titles such as Information Security Administrator, Compliance Specialist, Security Analyst, Microsoft 365 Security Engineer, and Governance and Risk Consultant. According to industry salary data for 2025, certified information security administrators in Microsoft environments can expect annual compensation ranging from approximately $90,000 to $120,000 depending on experience, geography, and organization size—with senior and consulting roles commanding higher figures.
The certification carries strong market recognition because it validates expertise in Microsoft Purview, one of the most widely deployed enterprise compliance platforms globally. It directly replaces the retired SC-400 certification, meaning organizations that previously required SC-400 are now looking for SC-401 holders. The credential also integrates well into broader Microsoft security career paths: it builds on the SC-900 foundations and aligns with the SC-100 (Cybersecurity Architect Expert) expert-level certification for those pursuing advanced roles. Microsoft certifications renew annually via a free online assessment on Microsoft Learn, keeping the credential current without requiring a full re-examination.
1. You are investigating an insider risk case and want to ensure the investigation is coordinated across your security team. You have identified that the case requires input from HR, Legal, and IT Security. What action should you take to facilitate collaboration?
2. Contoso's compliance team wants to create a custom trainable classifier to detect confidential vendor contracts. The team has gathered 75 sample vendor contracts that represent the type of content to classify, and 200 non-contract documents from various business processes. The organization has Microsoft 365 E3 licenses. What should the team verify before proceeding with classifier creation?
3. Litware Inc. is investigating a concerning alert where a senior research scientist downloaded multiple files labeled Confidential from the research team's SharePoint site. The files contain proprietary drug formulas worth millions. Using Microsoft Purview Insider Risk Management investigation tools, the security team needs to determine if this is a genuine threat or a legitimate business need. Which combination of investigation tools should they use to build a complete picture? (Choose two!)
Select all that apply4. Your organization has onboarded Windows 10 devices to Microsoft Purview endpoint DLP. You need to configure a policy to monitor and control sensitive data activities involving USB devices and external drives. Which activity type should you configure in the endpoint DLP policy?
5. Solution: Fabrikam wants to ensure that only users with specific investigative responsibilities can create cases from Insider Risk Management alerts and escalate them for eDiscovery investigation. Fabrikam assigns the Insider Risk Management Analysts role to these users. Does this solution meet the goal?
All exams included • Cancel anytime