SC-401

SC-401 Study Guide: A Domain-by-Domain Path Through the Information Security Administrator Exam

Objectives as of July 28, 2026•18 min read

Quick answer

SC-401 (Administering Information Security in Microsoft 365) tests three domains — information protection, data loss prevention and retention, and risk/alert management — each weighted 30–35%. It requires a 700/1000 passing score, has no enforced prerequisites, and is currently listed as a beta exam by Microsoft with no retirement date. There is no separate "fundamentals" version; candidates go straight into scenario-based questions on Microsoft Purview.

Microsoft Certified: Information Security Administrator Associate is earned by passing SC-401. Unlike a survey-style fundamentals exam, this one assumes you can actually operate Microsoft Purview — building sensitivity labels, tuning DLP rules, and reading insider risk alerts — not just describe what those features do. This guide walks the three domains in the order Microsoft groups them on the official study guide, with the specific traps candidates report inside each one.

What Is SC-401, and Who Is It For?

Exam Code

SC-401

Certification Earned

Information Security Administrator Associate

Passing Score

700 / 1000

Typical Price

$165 USD (region-dependent)

Exam Time / Seat Time

100 min / 120 min*

Languages

English only

Status

Beta, no retirement date listed

Prerequisites

None enforced

*Microsoft has not published SC-401-specific timing. This is the standard allocation for Associate/Expert role-based exams without labs, per Microsoft's exam duration policy (checked September 7, 2026).

Who is SC-401 built for?

Per Microsoft's official certification page, the Information Security Administrator plans and implements information security for sensitive data using Microsoft Purview — protecting content inside Microsoft 365 collaboration tools from internal and external threats, and protecting data used by AI services. That last clause is not filler: it is its own exam objective, and it is the newest, least-documented part of the exam.

Domain 1: Implement Information Protection

30–35%

This domain is where most candidates spend the bulk of their study time, and Microsoft's own study guide breaks it into three sub-areas: data classification, sensitivity labels, and information protection for Windows, file shares, and Exchange.

Data classification — the part people underrate

Sensitive information types (SITs), exact data match (EDM), document fingerprinting, and trainable classifiers all sound like variations on the same idea, but the exam treats them as distinct tools for distinct problems. EDM is for matching a known, structured dataset (an actual list of customer IDs or account numbers) with near-zero false positives. A trainable classifier is for unstructured content that follows a pattern rather than a fixed value — resumes, contracts, source code. Document fingerprinting matches a specific template, like a company's tax form. If a scenario says "we have the exact list of values to match," the answer is EDM, not a custom SIT.

Sensitivity labels — permissions before policy

Before you can publish a label, you need the right administrative role assigned — a detail the exam tests directly rather than assuming. Know the difference between publishing a label (making it available to users) and auto-labeling (applying it automatically based on content or a trainable classifier). Auto-labeling can run in simulation mode first; candidates who forget that option tend to pick the more aggressive, policy-enforcing answer when a lower-risk option exists.

Windows, file shares, and Exchange

The Microsoft Purview Information Protection scanner handles bulk classification of on-premises file shares — it is the answer whenever a scenario mentions on-premises data that was never touched by cloud services. Separately, know that Microsoft Purview Message Encryption and Advanced Message Encryption are two different tiers: Advanced adds revocation, expiration, and custom branding on top of the base encryption capability.

Test what you just read

Try 40 Free SC-401 Practice Questions

Scenario-based questions with explanations, built to Domain 1's actual objectives. No credit card required.

Start Free Practice →

Domain 2: Implement Data Loss Prevention and Retention

30–35%

DLP policy design and precedence

Interpreting policy and rule precedence is called out as its own exam skill, not an implied detail — expect a question where two DLP policies could both apply to the same content, and you have to determine which rule fires. The general order: policies are evaluated by priority order (lowest number first), and within a policy, rules are evaluated top to bottom, with the first matching rule's actions applied unless the rule is configured to keep evaluating lower-priority rules.

Endpoint DLP and Adaptive Protection

Endpoint DLP extends policies to devices — think copying a labeled file to USB, or printing a document with sensitive content. Just-in-time protection is the specific Endpoint DLP feature that grants access to a monitored file for a limited time when a policy would otherwise block it outright. Adaptive Protection changes DLP enforcement dynamically based on a user's calculated insider risk level, which is the exam's way of connecting this domain back to Domain 3.

Retention: labels vs. policies vs. precedence

Retention labels apply to individual items and can be assigned manually or automatically; retention policies apply broadly across a workload or location. When both a label and a policy could govern the same content, Microsoft's precedence rules generally favor the setting that retains content longest or the one with an explicit deletion — Policy Lookup is the named tool for confirming which setting will actually win before you rely on your own memory of the precedence order during the exam.

Domain 3: Manage Risks, Alerts, and Activities

30–35%

Insider Risk Management policy templates

Microsoft ships named policy templates (data theft by departing employees, data leaks, security policy violations, and others) rather than making you build detection logic from scratch. Choosing the right template for a described scenario — not building a custom one — is what most Domain 3 questions are actually testing. Forensic evidence capture (optional screen-capture on flagged activity) has its own permission and configuration path separate from the policy itself.

Working alerts across three surfaces

The exam expects you to know which portal handles which alert type: DLP alerts and insider risk cases live in the Microsoft Purview portal; some of those same signals also surface in Microsoft Defender XDR; and Defender for Cloud Apps generates its own file-policy alerts. A scenario describing "a single pane for security and compliance signals together" is pointing at Defender XDR, not Purview alone.

Protecting data used by AI services

This is the objective that did not exist on SC-401's Purview-administration predecessor exams, and it is folded into Domain 3 rather than given its own domain. It covers implementing Purview controls for AI services and Microsoft 365 Copilot specifically, plus Data Security Posture Management (DSPM) for AI — its prerequisites, role and permission setup, policy configuration, and activity monitoring. Because DSPM for AI is newer than the rest of the objectives list, it has the thinnest third-party study coverage of anything on the exam.

Where to Put Your Study Hours

Since all three domains carry near-identical exam weight, time allocation should follow how much ground each one covers on Microsoft's own study guide and training catalog, not the weighting percentages alone. This breakdown is based on the sub-objective count in each domain and the module count in Microsoft's own Purview learning paths — a genuinely different signal than the 30–35%/30–35%/30–35% split most guides stop at.

DomainSub-objective groupsSuggested study hours
1. Implement information protection3 (classification, labels, Windows/file/Exchange)14–16 hrs
2. Implement DLP and retention3 (DLP policy, Endpoint DLP, retention)12–14 hrs
3. Manage risks, alerts, and activities3 (insider risk, alerts/activities, AI data protection)14–16 hrs

Total: roughly 40–46 hours for a candidate already comfortable navigating the Microsoft Purview portal. Add 8–10 hours if Purview is new to you, concentrated in Domain 1 before moving on.

Why SC-401 Is Currently a Beta Exam — and What That Means for You

Microsoft's official exam catalog lists SC-401 as "Administering Information Security in Microsoft 365 (beta)" with a retirement date of "none" and English as the only available language (checked September 7, 2026). Beta status is a normal, temporary phase for a new Microsoft exam — it means Microsoft is still collecting statistical data on how real candidates perform on each question before the exam is fully scored on the spot.

Practical effect:if you sit SC-401 while it is still in beta, you will not see a pass/fail result immediately after finishing. Microsoft typically releases beta exam results in batches once enough data has been gathered — check the current timeline on Microsoft's beta exam policy page before you schedule, since this detail changes as Microsoft moves the exam toward general availability.

Frequently Asked Questions

Is SC-401 a beta exam?

Yes. As of Microsoft's official exam catalog (checked September 7, 2026), SC-401 is listed as beta with no retirement date, meaning scoring is delayed while Microsoft evaluates question performance data.

What is the passing score for SC-401?

700 out of 1000, Microsoft's standard threshold for role-based exams. During the beta period, that score is calculated after the exam window rather than reported the same day.

How long is the SC-401 exam?

Microsoft has not published SC-401-specific timing. Associate/Expert role-based exams without labs generally get 100 minutes of exam time and 120 minutes of seat time under Microsoft's general exam policy.

What are the prerequisites for SC-401?

None are enforced at registration. Microsoft recommends familiarity with Microsoft 365 services, PowerShell, Microsoft Entra, the Defender portal, and Defender for Cloud Apps.

What is the difference between SC-401 and SC-400?

They cover overlapping Purview material but are separate, independently scheduled exams that lead to different certifications. Passing SC-400 does not exempt you from any SC-401 objective.

How much does SC-401 cost?

Microsoft prices exams by region and doesn't list a flat figure on the SC-401 scheduling page itself; its general exam FAQ states Associate/Expert exams typically run US$165 before local pricing and tax adjustments.

About This Guide

MSCertQuiz sells a 500-question SC-401 practice bank (40 questions free) alongside this guide, written by the same team that maintains the question bank. Every domain, weighting, and figure above traces to Microsoft's own SC-401 study guide and exam page, checked September 7, 2026 — no figure here was estimated or carried over from another certification.