Active Microsoft associate certification
SC-401 Microsoft Information Security Administrator Roadmap
Classify and protect sensitive data, prevent inappropriate use, govern retention, investigate risk and alerts, support eDiscovery, and protect data used by AI services through accountable Microsoft Purview operations.
Exact balanced 50-question allocation
Microsoft publishes a 30-35% range for each of the three domains. PrepKloud's independent bank stays inside those ranges with 17 information-protection items, 17 DLP-and-retention items, and 16 risk-alert-and-activity items.
Classification, SITs, EDM, fingerprints, classifiers, OCR, labels, scanner, encryption.
DLP design, Adaptive Protection, Endpoint DLP, JIT, scopes, labels, policies, recovery.
Insider Risk, Audit, Activity Explorer, alerts, eDiscovery, DSPM for AI, Copilot data.
Phase 1 — Data classification and information protection
Translate business descriptions into defensible classifiers. Use built-in sensitive information types where they fit, custom types for structured patterns, Exact Data Match when authoritative membership matters, document fingerprinting for forms, and trainable classifiers for semantic categories.
- Define confidence, proximity, supporting evidence, positives, negatives, and boundary tests.
- Monitor aggregate classification in Data Explorer and use least-privilege Content Explorer for item review.
- Configure OCR for supported image content and document unsupported coverage.
- Design sensitivity labels for items and containers; understand that container labels do not automatically label every file.
- Publish labels to a pilot, configure defaults and downgrade justification, and validate protection.
- Run service-side auto-labeling in simulation before staged activation.
Phase 2 — Windows, file share, and Exchange protection
Extend the label program beyond Office document authoring. Evaluate the Microsoft Purview Information Protection client for supported Windows experiences and the scanner for authorized on-premises repositories.
- Deploy the scanner with a protected identity, explicit repositories, discovery-first content jobs, and rollback.
- Test bulk labeling against synthetic shares and measure both detection and access impact.
- Apply supported labels to connected cloud-app files through Defender for Cloud Apps where appropriate.
- Design Microsoft Purview Message Encryption for internal and external recipients.
- Evaluate Advanced Message Encryption for supported branding, expiration, and revocation scenarios.
- Document that revocation cannot erase content a recipient was legitimately able to export outside the controlled experience.
Phase 3 — DLP, Endpoint DLP, and Adaptive Protection
DLP is an activity control, not a synonym for classification or retention. Begin from the data, action, actor, location, audience, and business exception. Then design conditions, rule order, restrictions, notifications, overrides, alerts, and tuning.
- Assign narrow DLP roles and run Microsoft 365 DLP policies in simulation.
- Interpret policy and rule priority, exceptions, and stop-processing behavior from evidence.
- Use Adaptive Protection to connect governed insider risk levels to supported DLP conditions.
- Configure Defender for Cloud Apps file policies for supported connected-app governance.
- Validate Endpoint DLP licensing, OS, onboarding, connectivity, browser, extension, and policy prerequisites.
- Configure device, printer, removable-media, network-share, browser, service-domain, restricted-app, and just-in-time protection controls where supported.
Phase 4 — Retention, records, disposition, and recovery
Lifecycle begins with a defensible schedule. Broad retention policies cover configured locations; labels add item-level lifecycle, record behavior, event triggers, auto-application, and disposition review.
- Choose static or adaptive policy scopes from membership requirements.
- Create, publish, and auto-apply retention labels through separate policy types.
- Use event-based retention when the business clock starts from a contract, employment, or other event.
- Configure retention policies for supported Exchange, SharePoint, OneDrive, Teams, and Microsoft 365 locations.
- Apply documented retention precedence principles and use Policy lookup to inspect scope.
- Prove recovery from supported preserved locations rather than assuming retention is backup.
Phase 5 — Insider risk, investigations, alerts, eDiscovery, and AI data security
Risk scores and alerts prioritize review; they do not prove intent. Build privacy, minimization, anonymization, role separation, authorized context, evidence retention, and legal or HR escalation into the workflow.
- Configure Insider Risk role groups, HR and Defender connectors, settings, indicators, templates, risk levels, alerts, cases, notices, and optional forensic evidence governance.
- Search Audit, create Audit Premium retention policy where needed, and analyze classification activity in Activity Explorer.
- Investigate DLP, insider risk, Purview, Defender XDR, and Defender for Cloud Apps alerts through evidence-led response.
- Run authorized Microsoft Purview eDiscovery cases with bounded custodians, queries, review, preservation, and export.
- Configure DSPM for AI prerequisites, roles, policies, recommendations, and activity monitoring.
- Protect Microsoft 365 Copilot data by correcting source permissions, classification, DLP, retention, and risk controls—never by treating a prompt as authorization.
Official Microsoft source set
All SC-401 learning surfaces
Frequently asked questions
Is SC-401 active in 2026?
Yes. Microsoft Learn lists the Information Security Administrator Associate certification and a study guide with skills measured from July 28, 2026. Verify again before scheduling.
How long is SC-401?
Microsoft lists 100 minutes. Verify current language, accommodation, scheduling, and delivery details on the official exam page.
What are the current domain weights?
Information protection, DLP and retention, and risks, alerts, and activities are each 30-35%.
How are the 50 practice questions allocated?
17 information protection, 17 DLP and retention, and 16 risks, alerts, and activities. This is an independent study allocation, not a live-form prediction.
Should I enforce DLP immediately?
No. Start from requirements, scope narrowly, simulate, inspect matches and false positives, communicate, stage enforcement, monitor alerts, and preserve rollback.
Does an insider risk score prove misconduct?
No. It prioritizes authorized review. Investigators must validate evidence and context, preserve privacy, document uncertainty, and follow legal, HR, and organizational procedures.
Are these materials exam dumps or a pass guarantee?
No. All materials are original education grounded in public Microsoft sources. They contain no live or recalled questions and cannot guarantee a score, job, promotion, or salary.
Build defensible data-security operations
Read the guide · Start questions · Review cards · Build projects