sc-401Associate
Administering Information Security in Microsoft 365
Microsoft Certified: Information Security Administrator Associate
SC-401 is Purview with a data-security lens rather than the older records-management one. The path follows the exam's shape — protect (labels, encryption), prevent loss (DLP), manage lifecycle (retention), then insider risk and the AI-era controls around Copilot.
For: Purview administrators: sensitivity labels, DLP, retention, insider risk, and the data-security side of Copilot. Replaced SC-400.
21 guides in 4sections. The sections are this site's grouping, written to follow the shape of the published skills outline; weightings and the current outline live on the exam page above and change between exam versions.
01Information protection
- 1What is Microsoft Purview?What Microsoft Purview is: labels, DLP, retention, eDiscovery, insider risk, and the data-governance catalogue — how the two halves differ and where to start.
- 2Microsoft Purview sensitivity labels — a deep diveHow Purview sensitivity labels classify and protect content, how to design a taxonomy that survives contact with users, and the rollout order that works.
- 3Purview auto-labelling policiesHow auto-labelling applies sensitivity and retention labels automatically based on content match — and the operational realities.
- 4How to publish sensitivity labels in Microsoft PurviewHow-toHow to publish sensitivity labels in Microsoft Purview: create the label set, configure encryption and marking, publish a label policy, set defaults, pilot.
- 5Sensitivity labels for Teams meetingsHow sensitivity labels apply to Teams meetings — controlling who can join, what's allowed, and how the meeting is protected.
- 6Office 365 Message Encryption deep diveHow OME works under the hood — encryption flow, branding, custom templates, and the recipient experience.
- 7Customer Key for Microsoft 365How Customer Key lets you bring your own encryption keys for Microsoft 365 service encryption — and when to use it.
02Data loss prevention
- 8Microsoft Purview Data Loss Prevention — a deep diveDLP policies detect and prevent sensitive data from leaving Microsoft 365. Here's the architecture and how to roll them out.
- 9How to create a DLP policy in Microsoft PurviewHow-toHow to create a DLP policy in Microsoft Purview for card and personal data: locations, sensitive info types, rules and actions, simulation mode, enforcement.
- 10Power Platform DLP policiesHow Power Platform DLP policies govern which connectors apps and flows can combine — for data protection at the platform layer.
03Retention and lifecycle
- 11Purview retention policies explainedHow Microsoft Purview retention policies keep and delete content across Microsoft 365 — the model and the gotchas.
- 12How to create a retention policy in Microsoft PurviewHow-toHow to create a retention policy in Microsoft Purview: static or adaptive scope, locations, retain-then-delete settings, and rolling it out without surprises.
- 13Microsoft Purview records managementRecords management is retention with teeth — declaring content as a record locks it for legal/regulatory compliance.
- 14Microsoft Purview audit retentionHow long Microsoft 365 retains audit logs by default, what Audit (Premium) adds, and how to think about retention.
- 15How to search the audit log in Microsoft PurviewHow-toHow to search the Microsoft 365 unified audit log in Purview: check it's on, search by activity, user, and date, export, and Search-UnifiedAuditLog at scale.
04Insider risk and AI data security
- 16Purview Insider Risk ManagementInsider Risk Management detects risky internal behaviour — data theft, IP leakage, policy violations — with built-in privacy controls.
- 17Purview Communication ComplianceCommunication Compliance reviews emails, Teams chats, and Viva Engage messages against policy. Here's the model.
- 18Purview Information BarriersInformation Barriers prevent specific groups of users from communicating or collaborating — for regulatory, ethical, or legal reasons.
- 19Microsoft 365 Copilot data security and privacyHow Microsoft 365 Copilot handles your tenant's data — what's sent to the model, what's retained, and what compliance covers.
- 20Restricted Content Discovery for CopilotHow SharePoint Restricted Content Discovery hides sensitive sites from Microsoft 365 Copilot without breaking access, how it works with labels, and its limits.
- 21Microsoft Purview Data MapThe Data Map is the data governance side of Purview — discovering, classifying, and cataloguing data across the enterprise.
Independent site, not affiliated with Microsoft. Found a gap in this path? Send it through the contact form.