SC-401 Exam Guide 2026: What to Study for the July Blueprint
Accuracy check: August 7, 2026. Microsoft's current SC-401 study guide says the skills measured are effective July 28, 2026. Microsoft can change exam objectives and delivery details, so open the official pages again before scheduling.
SC-401: Administering Information Security in Microsoft 365 is the exam for the Microsoft Certified: Information Security Administrator Associate credential. It focuses on protecting sensitive information with Microsoft Purview and related services, including data used by AI services.
This guide separates published Microsoft facts from practical study advice. It does not promise a fixed question count, percentage-correct conversion, salary outcome, or guaranteed pass.
SC-401 Exam at a Glance
| Item | Current official information |
|---|---|
| Credential | Microsoft Certified: Information Security Administrator Associate |
| Level | Intermediate |
| Exam time | 100 minutes |
| Passing score | 700 or higher on Microsoft's scaled score |
| Skills outline | Effective July 28, 2026 |
| Domain weights | Three domains, each 30–35% |
| Question count | Not fixed for SC-401; Microsoft says most certification exams typically have 40–60 questions, but the number can vary |
| Delivery | Proctored through Pearson VUE; Microsoft says interactive components may appear |
| Price | Based on the country or region where the exam is proctored; confirm the live price during scheduling |
| Languages | English, Portuguese (Brazil), French, German, Japanese, Chinese (Simplified), and Spanish |
| Renewal | Annual; free online assessment during the six months before expiration |
These details come from the official SC-401 certification page and Microsoft's exam-duration and experience policy. The certification page strongly recommends registering with a personal Microsoft account because records tied only to a work or school account can be lost when you leave that organization.
Do not plan around a fixed number of questions
Microsoft deliberately does not identify an exact SC-401 question count or guaranteed item mix. Its general policy says most certification exams typically contain 40–60 questions, while the number can change. The SC-401 page says only that the exam is proctored and may have interactive components. Use the official Exam Sandbox to learn the interface, not to predict which formats will appear on your attempt.
Do not convert 700 into a percentage
A score of 700 is a scaled score, not a promise that 70% or 75% correct will pass. Microsoft's exam-scoring policy explains that a scaled score may not equal 70% of the points; Microsoft does not publish an SC-401 raw-score conversion. Treat every objective as testable and use practice results to locate weak topics, not to estimate an exact live-exam score.
What Changed on July 28, 2026?
Microsoft's change log describes minor updates inside two parts of Domain 3: managing information security alerts and activities, and protecting data used by AI services. The audience profile and the three top-level domains did not change.
The practical consequence is important: an older guide can look broadly correct while still omitting current tasks. Your checklist should now explicitly include:
- Optical character recognition support for sensitive information types
- Microsoft Purview Information Protection client and scanner
- Microsoft Purview Message Encryption and Advanced Message Encryption
- Defender for Cloud Apps file policies that use DLP
- Endpoint DLP device requirements, file extensions, advanced rules, settings, monitoring, and just-in-time protection
- Retention Policy Lookup and recovery of retained Microsoft 365 content
- Purview alert response in Microsoft Defender XDR
- Controls for AI services and Microsoft 365 productivity workloads
- DSPM for AI prerequisites, permissions, policies, and monitoring
Older SC-401 outlines may emphasize Communication Compliance, Information Barriers, file plans, or detailed records-management workflows. Those products may still matter at work, but they are not named in the July 28, 2026 skills outline. Prioritize the current published objectives first.
Domain 1: Implement Information Protection — 30–35%
Domain 1 has three connected jobs: classify information, apply sensitivity-based protection, and extend protection to Windows, file shares, and Exchange.
1. Implement and manage data classification
Know how to translate a business requirement into the right classifier:
- Built-in or custom sensitive information type: detects structured patterns using primary elements, supporting evidence, confidence, and proximity.
- Document fingerprinting: recognizes content based on a standard form or document template.
- Exact data match (EDM): securely matches values from an organization's data source with greater specificity than a broad pattern.
- Trainable classifier: identifies content by learned characteristics rather than one deterministic pattern.
- OCR support: lets Purview inspect supported image content for sensitive information.
The blueprint names both Data Explorer and Content Explorer for monitoring classification and label usage. They show classified and labeled items, with tightly controlled list and content-viewer permissions. Activity Explorer, also relevant later in the outline, provides a historical view of activities involving labeled content. Practice choosing the view that answers the question rather than treating the explorers as interchangeable.
Hands-on drill: create a custom sensitive information type in an authorized lab, test it with both matching and nonmatching samples, then inspect where detections and label activity appear. Repeat the reasoning for a document fingerprint, EDM classifier, and trainable classifier even if your lab cannot license every feature.
2. Implement and manage sensitivity labels
The current outline covers roles and permissions; labels for items and containers; protection settings; content marking; publishing; auto-labeling; Teams, Microsoft 365 Groups, Power BI, and SharePoint; and Defender for Cloud Apps.
Keep these distinctions exact:
- A sensitivity label classifies an item or container and can apply protection such as encryption or content marking.
- A label policy publishes labels and can define user-facing behavior such as defaults or justification requirements.
- An auto-labeling policy evaluates content and can apply labels at scale in supported locations.
- A label for a file or email is not the same configuration as a label for a Teams, Microsoft 365 Group, or SharePoint container.
Label priority is easy to reverse. In the Purview label list, labels lower in the list have higher priority; administrators should order more restrictive labels below less restrictive ones. Microsoft's auto-labeling documentation says an automatically applied label can replace a lower-priority automatic label, but not a higher-priority one; manual labels are not replaced by default.
Hands-on drill: publish two labels to a test user, configure a default or mandatory-label setting, apply content marking and encryption, then observe what happens when a user manually labels content before an auto-labeling policy evaluates it.
3. Protect Windows, file shares, and Exchange
Do not stop at cloud labels. The blueprint names the Microsoft Purview Information Protection client, management of files through that client, bulk classification of on-premises data with the scanner, Message Encryption, and Advanced Message Encryption.
For scenario questions, identify the workload first:
- Desktop file classification points toward the Information Protection client.
- Large on-premises repositories point toward the scanner and its prerequisites.
- Protected external email points toward Message Encryption capabilities and policy design.
Use Microsoft's linked documentation from the current study guide for configuration details because supported clients, licensing, and portal workflows can change.
Domain 2: Implement Data Loss Prevention and Retention — 30–35%
This domain joins controls that reduce inappropriate data movement with controls that retain or delete content according to policy. They use some shared signals, but they solve different problems.
1. Create and configure DLP policies
A good DLP design starts with the business requirement, locations, users or groups, sensitive conditions, actions, exceptions, user notifications, incident reporting, and testing mode. The outline also calls out roles and permissions, Adaptive Protection, policy and rule precedence, and Defender for Cloud Apps file policies that use DLP.
For a scenario, work in this order:
- Identify the sensitive data and confidence needed.
- Identify the workload or endpoint activity.
- Decide who and what should be in scope.
- Choose audit, warn, allow with override, or block behavior that meets the requirement.
- Decide how incidents and alerts should be investigated.
- Check policy and rule priority when more than one rule can match.
Avoid the vague shortcut that DLP simply "blocks data from leaving." DLP can audit, notify, allow an override, restrict an activity, or generate incidents depending on the policy.
2. Configure Endpoint DLP
The July outline explicitly names device requirements and extensions, advanced DLP rules for devices, Endpoint DLP settings, just-in-time protection, and monitoring. A complete lab should therefore include more than creating a generic Microsoft 365 DLP policy.
Endpoint drill: document the device-onboarding prerequisite, select device locations and restricted activities, test an advanced rule with a safe sample file, inspect the user experience, and find the event in Activity Explorer or the relevant alert workflow. Then explain when just-in-time protection is appropriate.
3. Implement retention and recovery
A retention policy applies settings at locations such as a site or mailbox. A retention label applies item-level settings and can remain with content as it moves inside the Microsoft 365 tenant. The current exam also names adaptive policy scopes, label publication and auto-application, Policy Lookup, retention policies, and recovery of retained content.
Do not memorize a false single-line hierarchy. For ordinary retention settings, when priority cleanup is not in use, Microsoft's retention principles resolve conflicts in stages:
- Retaining content takes precedence over deleting it.
- When multiple retention settings apply, the longest retention period wins.
- For competing deletion actions, an explicit retention label takes precedence over policy deletion; a scoped policy takes precedence over an organization-wide policy; the shortest deletion period wins if conflicts remain.
Current Microsoft documentation identifies priority cleanup as an exception that can override retention and eDiscovery holds in supported scenarios; it is not supported for items marked as records or regulatory records. Priority cleanup is not named in the July 28 SC-401 skills outline, so prioritize the published objectives unless Microsoft changes the outline.
Your practice should include using Policy Lookup to identify which retention settings affect a user, site, or group and tracing how retained content can be recovered.
Adaptive scopes are not Adaptive Protection
These names describe different mechanisms:
- Adaptive policy scopes use attribute-based queries to update membership dynamically. In the current SC-401 outline, they appear under retention.
- Adaptive Protection connects Insider Risk Management risk levels to DLP so enforcement can adapt to a user's risk level.
If a question asks who belongs in a retention policy, think scope membership. If it asks how DLP restrictions should change with insider-risk level, think Adaptive Protection.
Domain 3: Manage Risks, Alerts, and Activities — 30–35%
Domain 3 combines Insider Risk Management, investigation across Purview and Defender, and data protection for AI environments.
1. Implement and manage Insider Risk Management
Study roles and permissions, connectors, integration with Microsoft Defender for Endpoint, global settings, policy indicators, templates, policy creation, forensic evidence, Adaptive Protection risk levels, alerts, cases, and notice templates.
Do not assume one policy template has a guaranteed number of questions. Microsoft does not publish per-objective item counts. Instead, practice the complete workflow:
- Translate the risk scenario into indicators and users in scope.
- Select and configure a suitable template.
- Explain prerequisites and privacy controls.
- Triage an alert and decide whether to create or update a case.
- Document an appropriate response, including a notice when required.
2. Manage information security alerts and activities
The outline expects you to understand Microsoft Purview Audit (Premium) licensing, audit searches and retention policies, Activity Explorer, DLP alerts in the Purview portal, insider-risk investigations, Purview alerts in Microsoft Defender XDR, Defender for Cloud Apps file-policy alerts, and searches using eDiscovery.
Build a simple alert-response map:
| Signal or task | Primary place to begin |
|---|---|
| Label or DLP activity trend | Activity Explorer |
| Audit event investigation | Microsoft Purview Audit |
| DLP incident | DLP alerts in the Purview portal |
| Insider-risk signal | Insider Risk Management alert and case workflow |
| Purview alert correlated with security incidents | Microsoft Defender XDR |
| Cloud-app file-policy event | Defender for Cloud Apps |
| Case content search | eDiscovery search |
The objective is not to memorize a single portal path forever. It is to know which solution owns the signal, which permissions and licensing it needs, and how evidence moves into investigation and response.
3. Protect data used by AI services
The current blueprint explicitly tests controls in Microsoft Purview and Microsoft 365 productivity workloads for environments using AI services. It also names four DSPM for AI tasks: prerequisites, roles and permissions, policies, and monitoring.
A useful lab narrative is: discover sensitive data exposed to AI, reduce oversharing, configure the appropriate policy, monitor activities, and investigate an alert. Avoid assuming that a sensitivity label alone is a complete AI-data-security program; the scenario can involve permissions, sharing, DLP, insider risk, audit, or DSPM for AI.
SC-400 Is Retired: What That Means
Microsoft retired the SC-400 exam, the Information Protection and Compliance Administrator Associate certification, and its renewal assessments on May 31, 2025. Existing credentials remain on the holder's transcript, but Microsoft says renewal is no longer available after retirement.
SC-401 is the current exam for the Information Security Administrator Associate credential, but it is not a one-for-one copy of SC-400. Do not rely on an old SC-400 guide alone. Start with the current SC-401 outline and add only older study material that maps directly to a current objective. See Microsoft's retirement announcement.
Use Official Resources in This Order
- Current SC-401 study guide: your source of truth for objectives and change log.
- SC-401 certification page: current duration, languages, scheduling, practice assessment, sandbox, and live regional price.
- SC-401T00 course page: Microsoft's four-day instructor-led course and linked self-directed learning paths.
- Microsoft Learn documentation linked under each objective: use it to resolve configuration details and product changes.
- Practice and review: take the official Practice Assessment, use the Exam Sandbox, and use our free SC-401 practice questions to expose weak reasoning. Never use recalled live questions or exam dumps; Microsoft's exam security policy prohibits sharing or using protected exam content.
Choose a lawful hands-on environment
Use an employer-authorized lab tenant, an authorized training environment, or a developer sandbox only when you qualify and your use follows its terms. Microsoft's Developer Program guidance limits sandbox access to qualifying members and development use. It is not a universal, permanent, free E5 tenant for exam study.
If you cannot access a licensed feature, document the prerequisites, walk through official screenshots or demonstrations, and rehearse the decision logic. Never enable a policy in a production tenant without authorization and a rollback plan.
An Eight-Week Objective-Driven Study Plan
There is no official required study-hour total. Adjust the pace to your Microsoft 365 and Purview experience; keep the sequence because later topics reuse earlier classification and policy concepts.
Week 1: Blueprint, baseline, and environment
- Save or print the July 28 skills outline.
- Take a baseline Practice Assessment without searching for answers.
- Create an objective tracker with three states: explain, configure, troubleshoot.
- Confirm your authorized lab access and roles.
Week 2: Classification
- Compare built-in and custom sensitive information types, document fingerprinting, EDM, and trainable classifiers.
- Include OCR support in your notes.
- Practice Content Explorer versus Activity Explorer decisions.
Week 3: Sensitivity and messaging protection
- Create, publish, and test sensitivity labels for items and containers.
- Verify label priority and auto-label behavior.
- Study the Information Protection client, scanner, Message Encryption, and Advanced Message Encryption.
Week 4: DLP and Endpoint DLP
- Build a policy from requirements instead of copying a template blindly.
- Test policy and rule priority, notifications, overrides, and alerts.
- Cover device requirements, extensions, advanced endpoint rules, settings, just-in-time protection, and monitoring.
Week 5: Retention
- Contrast policies, labels, and adaptive policy scopes.
- Work through conflict principles.
- Use Policy Lookup and trace a retained-content recovery scenario.
Week 6: Insider risk
- Map roles, connectors, Defender for Endpoint, indicators, templates, forensic evidence, alerts, cases, and notices.
- Contrast adaptive scopes with Adaptive Protection.
- Practice turning an alert into a documented case decision.
Week 7: Audit, alerts, eDiscovery, and AI
- Run an audit-search scenario and interpret Activity Explorer.
- Route DLP, insider-risk, Defender XDR, and Defender for Cloud Apps alerts to the right workflow.
- Practice an eDiscovery search.
- Cover all four DSPM for AI objective groups.
Week 8: Timed integration and repair
- Retake a current assessment under a 100-minute limit.
- For every miss, cite the current objective and an official page that resolves it.
- Repeat hands-on tasks you cannot explain from memory.
- Use the Exam Sandbox and verify current scheduling, identification, and system requirements.
Exam-Day Strategy Based on Published Rules
SC-401 is an associate role-based exam, so Microsoft Learn is available inside the exam interface. The timer keeps running, no extra time is added, and access excludes Q&A, Practice Assessments, and your profile. External websites are blocked. Use Learn for a targeted lookup, not as a substitute for preparation.
Microsoft does not announce the exact item formats for a particular live exam. The sandbox demonstrates possible interfaces, but your attempt can differ. Read the opening instructions because they explain the sections, navigation, and whether a lab is present.
If you do not pass, Microsoft's current retake policy requires a 24-hour wait after the first failed attempt and a 14-day wait after subsequent attempts. A candidate may take the same exam at most five times in a 12-month period starting with the first attempt, and applicable retake fees must be paid.
Renewal: The Deadline Is Before Expiration
The Information Security Administrator Associate credential follows Microsoft's annual renewal policy. The renewal assessment is free, online, open book, and unproctored. Eligibility opens six months before expiration, and passing extends the credential one year from its existing expiration date.
There is no six-month grace period after expiration. If the credential expires, Microsoft's renewal FAQ says you must earn it again by passing the required exam. Renewal attempts are unlimited while eligible; after two failed renewal attempts, later attempts require at least a 24-hour wait. Microsoft estimates about 45 minutes for a renewal assessment.
Does SC-401 Lead to Microsoft 365 Administrator Expert?
As of this accuracy check, SC-401 is one of the associate certifications that can satisfy the prerequisite for Microsoft 365 Certified: Administrator Expert, together with MS-102. Microsoft's credential-retirement page lists October 31, 2026 as the Administrator Expert retirement date, and its scheduled exam retirement table gives MS-102 the same date.
If that path matters to you, complete and verify every requirement before October 31, 2026. Retirement information can change, so recheck both official tables before scheduling; do not assume MS-102 will remain a long-term next step.
Final Readiness Checklist
You are ready to schedule when you can do all of the following without relying on remembered answer patterns:
- Explain every July 28 objective in one or two sentences.
- Choose among sensitive information types, document fingerprints, EDM, trainable classifiers, and OCR for a stated requirement.
- Predict label priority and distinguish item labels from container settings.
- Design a DLP rule, explain Endpoint DLP prerequisites, and route its alert.
- Resolve a retention conflict and use Policy Lookup.
- Distinguish adaptive policy scopes from Adaptive Protection.
- Move an insider-risk alert through triage and case response.
- Choose among Audit, Activity Explorer, Defender XDR, Defender for Cloud Apps, and eDiscovery for a task.
- Describe DSPM for AI prerequisites, permissions, policies, and monitoring.
- Complete current practice scenarios while explaining why each alternative is wrong.


