Microsoft Information Security Administrator Associate

Microsoft · SC-401 · Associate

Microsoft · Microsoft Azure + M365

Microsoft Information Security Administrator Associate

SC-401● activeAssociate
Official Microsoft source · learn.microsoft.com ↗

Microsoft Information Security Administrator (SC-401)

SC-401 · ● Active · Associate · Microsoft

Exam facts

FieldDetails
Exam CodeSC-401
Full NameAdministering Information Security in Microsoft 365
Cost$165 USD (pricing may vary by region)
Duration120 minutes (1 hour 40 minutes)
Number of Questions65 questions total (1 case study with 4 questions, 6 Yes-or-No questions)
Passing Score700 out of 1000
DeliveryPearson VUE (online via OnVUE and in-person test centers)
LanguagesEnglish and additional languages (varies by region)
Credential Validity1 year from certification date
Renewal MethodPass free online renewal assessment on Microsoft Learn before expiry (180-day renewal window)
PrerequisitesNone (formal prerequisites not required, but hands-on experience recommended)
Performance-Based LabsNot included in this exam

Vendor source — Microsoft Certified: Information Security Administrator Associate

Official study guide — Study guide for Exam SC-401: Administering Information Security in Microsoft 365

Official exam blueprint — Exam SC-401: Administering Information Security in Microsoft 365

Official training course — SC-401T00-A: Protect sensitive information with Microsoft Purview in the AI era

About

SC-401 is the successor to SC-400 (Information Protection Administrator Associate), which was retired on May 31, 2025. Microsoft introduced SC-401 in response to feedback that the two distinct roles—data security/information protection and compliance—should have separate credentials.

As an Information Security Administrator, you plan and implement information security of sensitive data using Microsoft Purview and related services. You're responsible for:

  • Mitigating risks by protecting data inside Microsoft 365 collaboration environments from internal and external threats
  • Protecting data used by AI services (including DSPM for AI data classification)
  • Implementing information protection, data loss prevention (DLP), retention policies, and insider risk management
  • Managing information security alerts and activities
  • Administering sensitivity labels, encryption, and rights management policies

Key difference from SC-400: SC-401 expands the scope to include AI-data protection and DSPM (Data Security Posture Management) for AI, reflecting the evolving security landscape with generative AI tools like Microsoft Copilot in Microsoft 365 environments.

Domain context — Security / Microsoft 365 Compliance & Data Protection

SC-401 validates expertise in securing sensitive information and managing compliance-related security across Microsoft 365 cloud environments. It bridges the gap between pure compliance administration (SC-400) and security operations, with stronger emphasis on threat mitigation and data protection.

Topics covered

The SC-401 exam is structured around three primary skill domains, each weighted approximately 30–35%:

Domain 1: Implement Information Protection (~30–35%)

  • Configure and manage sensitivity labels (automatic and manual application)
  • Implement encryption with Azure Information Protection (AIP)
  • Configure rights management and content encryption
  • Deploy classifiers for automatic data discovery
  • Manage label policies and sublabels
  • Implement DSPM (Data Security Posture Management) for AI data classification
  • Configure encryption options for SharePoint, Teams, and Exchange

Domain 2: Implement Data Loss Prevention (DLP) (~30–35%)

  • Design and deploy DLP policies across Microsoft 365 workloads
  • Configure endpoint DLP (protect data on local devices)
  • Integrate Microsoft Defender for Cloud Apps (formerly MCAS) with DLP
  • Monitor and respond to policy matches and false positives
  • Implement AI-driven DLP for Copilot data protection
  • Configure exceptions and policy refinement
  • Test and validate DLP policies in simulation mode

Domain 3: Manage Risks, Alerts, and Activities (~30–35%)

  • Implement Insider Risk Management (IRM) policies
  • Configure Adaptive Protection based on user risk levels
  • Review and analyze audit logs and activity monitoring
  • Manage content search and data investigation
  • Respond to security alerts and incidents
  • Monitor AI activity and data usage patterns
  • Configure alerts and reporting for compliance activities

Common job-ready skills

Upon earning the SC-401 certification, professionals typically possess these job-ready skills:

  • Data Classification & Sensitivity Labels — Automatically classify sensitive data and apply protective labels across Microsoft 365
  • Encryption & Rights Management — Configure encryption policies and control document access using AIP/Rights Management
  • DLP Policy Design & Deployment — Create and enforce data loss prevention rules to prevent unauthorized data exfiltration
  • Insider Risk Management — Detect and respond to risky user behavior and internal data threats
  • Audit & Compliance Monitoring — Monitor user activities and maintain compliance audit trails using unified audit logs
  • Endpoint Protection — Extend data protection to local machines and devices using endpoint DLP
  • Cloud Apps Monitoring — Monitor and control data movement via Microsoft Defender for Cloud Apps
  • AI Data Governance — Manage and protect data used by AI services and generative AI tools in Microsoft 365
  • Incident Response — Investigate security incidents and execute remediation actions based on alerts
  • Cross-workload Security — Secure data across SharePoint, Teams, OneDrive, Exchange, and Copilot environments

Recommended courses

CourseProviderFormatDetails
Protect sensitive information with Microsoft Purview in the AI era (SC-401T00-A)Microsoft LearnSelf-paced / Instructor-ledOfficial Microsoft training course covering all exam objectives
Implement Microsoft Purview Information ProtectionMicrosoft LearnSelf-paced learning pathFree comprehensive training modules on sensitivity labels and encryption
Implement Data Loss Prevention with Microsoft PurviewMicrosoft LearnSelf-paced learning pathFree modules on DLP policy design and deployment
Manage insider risk in Microsoft PurviewMicrosoft LearnSelf-paced learning pathFree training on Insider Risk Management policies and alerts
SC-401: Microsoft Information Security Administrator 2026UdemySelf-paced videoThird-party comprehensive video course with practice exams
Microsoft SC-401 Exam Practice Questions (300+ Q&A)UdemySelf-paced practiceThird-party practice question course with detailed explanations

Practice exams

ResourceFormatQuestionsCostNotes
MeasureUp — Microsoft SC-401 Practice TestOnline interactiveMultiple full-length testsPaidOfficial Microsoft exam simulator, closest to real exam format
ExamTopics — SC-401Web-based Q&A600+ crowdsourced questionsFreemiumCommunity-driven; free access with limited features
OpenExamPrep — Free SC-401 Practice QuestionsWeb-based100+ practice questionsFreeFree practice questions with explanations
CertLibrary — SC-401 Exam QuestionsOnlineFull-length testsPaidPaid practice exams with detailed answer explanations
Microsoft Learn Sandbox EnvironmentInteractive labsHands-on scenariosFreeOfficial Microsoft sandbox for practical experience with Purview

Books

TitleAuthorFormatYearNotes
Study guide for Exam SC-401Microsoft LearnDigital/PDF2025Official Microsoft exam guide; free resource
SC-401 Study Guide: Administering Information Security In Microsoft 365Charbel Nemnom (MVP)Digital2025Comprehensive guide from Microsoft MVP and MCT
Exam Ref SC-401 (if available)Microsoft PressPrint/Digital2025Official Microsoft exam reference series

Note: SC-401 is very recent (May 2025 release). Traditional textbooks may be limited compared to SC-400. Rely on official Microsoft Learn resources, official study guides, and community blogs from Microsoft MVPs.

Job titles

Professionals with SC-401 certification typically fill these roles:

  • Information Security Administrator (primary role)
  • Microsoft 365 Security Administrator
  • Data Protection Administrator
  • Purview Information Protection Administrator
  • Security Operations Administrator
  • Compliance & Security Administrator
  • Cloud Security Administrator (Microsoft)
  • DLP (Data Loss Prevention) Administrator
  • Insider Risk Management Administrator
  • Information Governance Administrator
  • Microsoft Purview Administrator
  • Sensitivity & Encryption Administrator

Salary (USD / GBP / EUR / AUD / ZAR)

RegionCurrencySalary RangeNotes
United StatesUSD$85,000–$125,000 / yearAverage ~$97,112 for MS 365 Security Admin (2026)
United KingdomGBP£45,000–£60,000 / yearMedian £45,000 for Office 365 Admin (March 2026)
European UnionEUR€50,000–€70,000 / yearApproximate range; varies by country
AustraliaAUDAUD $90,000–$130,000 / yearApproximate based on regional salary data
South AfricaZARZAR 1,530,000–2,250,000 / yearRough equivalent (USD × ~18)

Salary ranges vary based on experience, certifications, employer size, location, and cost of living. Information Security Administrators with SC-401 and additional certifications (SC-300, SC-900, CISSP) typically earn at the higher end of these ranges.

Skills validated

SC-401 validates the following competencies as assessed by Microsoft:

✓ Implement information protection using sensitivity labels and encryption
✓ Configure and manage Azure Information Protection (AIP) policies
✓ Design and deploy Data Loss Prevention (DLP) policies
✓ Implement Insider Risk Management to detect risky behavior
✓ Monitor and respond to security alerts and compliance activities
✓ Manage audit logs and user activity monitoring
✓ Protect data in Microsoft 365 workloads (Teams, SharePoint, Exchange, OneDrive)
✓ Integrate Microsoft Defender for Cloud Apps with security policies
✓ Implement DSPM for AI data governance and protection
✓ Conduct content search and forensic investigation
✓ Manage endpoint DLP for local device protection
✓ Configure Adaptive Protection based on user risk scoring
✓ Respond to and remediate insider risk incidents
✓ Maintain compliance with regulatory requirements

Related certifications

SC-401 certification path and relationships:

Cert CodeTitleLevelRelationship
SC-900Microsoft Security, Compliance, and Identity FundamentalsFundamentalsPrerequisite foundation; covers basic security/compliance concepts
SC-300Microsoft Entra ID (Identity & Access Administrator)AssociateComplementary; focuses on identity/access; often combined with SC-401 for comprehensive security roles
SC-200Security Operations AnalystAssociateSibling certification; focuses on threat detection vs. data protection
SC-100Cybersecurity Architect ExpertExpertAdvanced pathway; builds on associate-level certs like SC-401
SC-400 (Retired)Information Protection AdministratorAssociatePredecessor—retired May 31, 2025; SC-401 is the replacement
PL-900Power Platform FundamentalsFundamentalsOptional complementary cert for broader M365 governance
MS-101Microsoft 365 Enterprise Administrator ExpertExpertAdvanced M365 administration pathway

Recommended progression:

For aspiring information security administrators:

  1. Start with SC-900 (Fundamentals) if new to Microsoft security
  2. Pursue SC-401 (Associate-level data protection specialist)
  3. Optionally add SC-300 for identity/access expertise
  4. Progress to SC-100 (Expert Cybersecurity Architect) for strategic roles

Note on SC-400 retirement: Microsoft retired SC-400 on May 31, 2025, because the role was becoming too broad. Organizations now prefer specialized certifications: SC-401 for information protection/data security and a separate compliance path for regulatory compliance administrators. SC-401 absorbs much of SC-400's content with added AI/DSPM coverage.

Sources


Verification date: May 2, 2026
Status as of 2026: SC-401 is an active, current certification with regular updates to include emerging Microsoft 365 security features and AI-related governance requirements.

Rate this cert
…
Was this helpful?
Comments (—)
0/2000