Microsoft SC-401 Information Security Administrator exam guide covering the three Purview domains and AI data security

SC-401 Exam: What Replaced the Information Protection Administrator

SC-401 is not SC-400 with a new number on it. The credential changed name, from Information Protection Administrator to Information Security Administrator, and the exam changed with it. The clearest evidence sits in the objectives: a whole group of them now covers protecting data used by AI services, including Data Security Posture Management for AI, which did not exist as examinable content on the previous paper.

Most of the Purview skills carry over. Sensitivity labels, data loss prevention, retention and insider risk are all still there, and someone who studied for SC-400 has done most of the work. What has moved is the framing. Microsoft now describes the role as planning and implementing information security for sensitive data across Purview and related services, and the official training course for it is titled around protecting sensitive information in the AI era. This guide covers all three domains, the exam mechanics including one duration figure that is widely misreported, and what the AI objectives actually require.

What Does the SC-401 Exam Cover?

SC-401 covers three domains, each weighted 30 to 35 percent: implement information protection, implement data loss prevention and retention, and manage risks, alerts and activities. Passing awards the Microsoft Certified Information Security Administrator Associate credential. The whole exam sits inside Microsoft Purview and the related services that feed it.

The three SC-401 domains weighted 30 to 35 percent each: protect, prevent and monitor
DomainWeightWhat it covers
Implement information protection30-35%Data classification, sensitive info types, trainable classifiers, sensitivity labels, and protection for Windows, file shares and Exchange
Implement data loss prevention and retention30-35%DLP policy design and precedence, Endpoint DLP, Adaptive Protection, retention labels and policies, and content recovery
Manage risks, alerts, and activities30-35%Insider Risk Management, Purview Audit and activity explorer, eDiscovery, alert response, and protecting data used by AI services

Microsoft positions the credential at intermediate level, under the Microsoft 365 Security Center product, for the administrator role, with the subject given as information protection and governance. That combination describes the reader well: someone who already administers a tenant and now owns the data side of it.

The one thing the domain names hide is where the newest material lives. AI data security sits inside the third domain rather than standing on its own, so an objective list read at heading level makes the exam look unchanged.

What Are the SC-401 Exam Details?

SC-401 gives you 100 minutes to complete the assessment, carries 40 to 60 questions, and is passed at 700 on a 1000 point scale. It costs 165 US dollars, is booked through Pearson VUE, is proctored, and may include interactive components rather than only multiple choice items.

FieldValue
Exam nameAdministering Information Security in Microsoft 365
Exam codeSC-401
CredentialMicrosoft Certified Information Security Administrator Associate
Questions40 to 60
Duration100 minutes
Passing score700 out of 1000
Price$165
LevelIntermediate
DeliveryPearson VUE, proctored
LanguagesSeven, including English, French, German, Japanese, Spanish, Portuguese and Simplified Chinese

The duration is worth pausing on, because 120 minutes is quoted for this exam in a lot of places. Microsoft’s own SC-401 exam page states 100 minutes to complete the assessment. The 120 comes from Microsoft’s general duration policy, which allows 100 minutes for associate and expert role-based exams without labs and 120 minutes for those that may contain labs. SC-401 sits in the first group. Microsoft deliberately publishes no list of which exams carry labs, because a lab can be withdrawn at any time, so the exam page is the figure to trust.

The 700 pass mark is a scaled score rather than a percentage, so there is no fixed number of questions you can afford to lose. With a variable item count of 40 to 60, that is the only sensible way to score it. A failed first attempt can be retaken after 24 hours; later retakes carry longer waits. Working through SC-401 practice material before booking is the cheapest way to find out which of the three domains is thin.

Is SC-401 Just SC-400 With a New Number?

No. SC-401 replaces SC-400 and inherits most of its Purview content, but the credential name changed from Information Protection Administrator to Information Security Administrator and the objectives were extended into AI data security. Sensitivity labels, DLP, retention and insider risk carry over; the AI material and the surrounding governance framing are new.

For anyone part way through SC-400 preparation, that is good news. The classification work, the label lifecycle, the policy precedence rules and the retention model are the same product behaviours, and time spent on them is not wasted.

What actually changed

Three things. The role description now spans information security for sensitive data rather than information protection specifically. The third domain absorbed AI data security, including Data Security Posture Management for AI. And Adaptive Protection appears in the DLP objectives, tying policy strength to insider risk levels rather than treating the two as separate systems.

What that means for study material

Material written for SC-400 remains useful for roughly the first two domains and misses a meaningful part of the third. Anyone working from an older guide should treat the AI objectives as a separate reading exercise rather than assuming coverage. The CertificationBox SC-400 exam guide is still a reasonable orientation to the shared Purview ground.

What Does Implement Information Protection Ask For?

The information protection domain covers data classification, sensitivity labels and protection for content outside the cloud, at 30 to 35 percent of the exam. It runs from identifying an organisation’s sensitive information requirements through to applying labels automatically across Teams, SharePoint, Microsoft 365 Groups and Power BI.

Classification is the harder half. The objectives name custom sensitive information types, document fingerprinting, exact data match, trainable classifiers and optical character recognition support, which are five distinct mechanisms for finding sensitive content and each suits a different problem. Knowing which to reach for is a more realistic exam question than knowing how to configure one.

  • Built in and custom sensitive info types for structured patterns such as identifiers and card numbers.
  • Document fingerprinting for content that follows a known form or template.
  • Exact data match for values checked against a known list rather than a pattern.
  • Trainable classifiers for categories that cannot be expressed as a rule at all.

The labels half then covers roles and permissions, label creation for items and containers, protection settings and content marking, publishing policies, and auto-labelling. The domain closes outside the cloud entirely, with the Purview Information Protection client and scanner for on-premises data, and message encryption for mail. Microsoft’s own Purview documentation is the reference for all of it.

How Much of SC-401 Is Data Loss Prevention?

Data loss prevention shares its domain with retention, and the two together carry 30 to 35 percent of SC-401. DLP itself covers policy design, roles and permissions, policy and rule precedence, Adaptive Protection, Endpoint DLP and file policies in Defender for Cloud Apps. Retention covers labels, adaptive policy scopes, policy precedence and recovering retained content.

Precedence appears in both halves and is the concept most likely to decide a question. When several policies could apply to the same item, the outcome is determined by rules the exam expects you to be able to trace, and Microsoft provides Policy lookup precisely because the answer is not obvious. The underlying discipline is not Microsoft specific, and a general grounding in how data loss prevention works helps make sense of why the product behaves as it does.

Endpoint DLP is its own topic

The objectives for Endpoint DLP are specific: device requirements including file extensions, advanced rules for devices, endpoint settings, just in time protection and activity monitoring. Someone who has only configured DLP for Exchange and SharePoint should treat this as unfamiliar ground rather than an extension of what they know.

Adaptive Protection links the domains

Configuring DLP policies for Adaptive Protection means policy strength varies with a user’s insider risk level, which is calculated in the third domain. It is the clearest example of the exam expecting the three domains to be understood as one system rather than three product areas.

What Does the Exam Expect About AI Data Security?

SC-401 examines protecting data used by AI services as a named objective group inside the third domain. It covers implementing controls in Purview and in Microsoft 365 productivity workloads to protect content in an environment using AI services, the prerequisites for Data Security Posture Management for AI, the roles and permissions for it, configuring DSPM for AI policies, and monitoring activity in it.

The four SC-401 AI data security objectives in sequence: controls, prerequisites, roles and monitoring

The scope is narrower than the phrase suggests, and that should reassure anyone without a machine learning background. Nothing here asks about model training, prompt engineering or AI architecture. The question the objectives ask is a data governance one: when an assistant can read everything a user can read, what stops sensitive content leaving through it.

That reframing is what makes the material examinable at administrator level. Labels and DLP policies already control what leaves through mail and endpoints. AI services are simply another egress path, and DSPM for AI is the visibility layer over it. The broader discipline is moving quickly, and the Cloud Security Alliance AI research is a useful independent view of the risks the objectives are responding to.

The practical consequence for study is that this material is genuinely new. There is no SC-400 equivalent to fall back on, and it needs hands on time in a tenant rather than reading.

Why Are All Three Domains Weighted the Same?

All three SC-401 domains sit at 30 to 35 percent, which is the flattest weighting on any exam of this kind. There is no dominant domain to prioritise and no light domain to skim. Microsoft is signalling that the three areas are one job rather than three specialities, and that a candidate strong in two of them is not ready.

The ranges overlap completely, so the actual split varies between forms of the paper. Any of the three could be the largest on the day you sit it. Planning study time in equal thirds is the only defensible reading of that.

It also has a practical consequence for revision order. On an exam with a 30 percent domain, you start there. Here, the better sequence follows the product rather than the marks: classify content first, then control where it goes, then watch what happens to it. That order matches how the objectives reference each other, with Adaptive Protection in the second domain depending on insider risk levels from the third.

How Should You Prepare for the SC-401 Exam?

Preparation works best in product order rather than domain order, because the three domains are evenly weighted and reference each other. Classification has to be understood before labels make sense, labels before DLP policies, and insider risk before Adaptive Protection. Working the objectives in that dependency order removes most of the confusion candidates report.

  1. Start with data classification and learn where each mechanism fits, separating custom sensitive info types, document fingerprinting, exact data match and trainable classifiers by the kind of content each is designed to find.
  2. Move to sensitivity labels, covering creation for items and containers, protection settings, publishing policies and auto-labelling, since everything downstream depends on content being labelled correctly.
  3. Cover the on-premises and mail side of information protection, including the Purview Information Protection client and scanner and message encryption, which candidates working only in the cloud tend to skip.
  4. Work data loss prevention next, paying particular attention to policy and rule precedence and to Endpoint DLP, which behaves differently from DLP in Exchange and SharePoint.
  5. Add retention labels and policies, and practise interpreting precedence with Policy lookup rather than reasoning it out from memory.
  6. Study Insider Risk Management properly, including connectors, policy indicators, templates and risk levels, because Adaptive Protection in the DLP domain depends on it.
  7. Finish with the AI data security objectives, setting up Data Security Posture Management for AI in a tenant rather than reading about it, since there is no equivalent material on the previous exam to fall back on.
  8. Take Microsoft’s free practice assessment and the exam sandbox before booking, then sit timed practice questions to confirm the pace across 40 to 60 items in 100 minutes.

Keeping the Credential Current

Microsoft role-based certifications expire unless they are renewed, and SC-401 is one of them. Renewal is free and is done by passing an online assessment on Microsoft Learn rather than by sitting the full exam again. The assessment is unproctored, taken at your own desk, and can be retried.

That model suits a product that changes as often as Purview does. A credential awarded once and never revisited would say progressively less about whether someone can administer the current feature set, and the renewal assessment is deliberately weighted towards what has changed.

One small piece of practical advice from Microsoft’s own booking guidance is worth repeating: register with a personal Microsoft account rather than a work or school account. Certifications tied to an organisational account become awkward to reach when you change employer. If you are mapping the wider Microsoft security track, the SC-200 certification guide covers the operations analyst route that sits alongside this one.

Frequently Asked Questions

How long is the SC-401 exam?

Microsoft states 100 minutes to complete the assessment. The 120 minute figure comes from Microsoft’s general duration policy, which allows 100 minutes for associate and expert role-based exams without labs and 120 for those that may contain labs. SC-401 is in the first group.

How many questions are on SC-401?

Between 40 and 60, and the exam may include interactive components rather than only multiple choice items. The variable count is why the result is reported as a scaled score.

What is the passing score for SC-401?

700 on a scale of 1000. Because it is scaled rather than a raw percentage, there is no fixed number of questions you can afford to get wrong.

Does SC-401 replace SC-400?

Yes. The credential moved from Information Protection Administrator to Information Security Administrator, keeping most of the Purview content and adding AI data security objectives that SC-400 did not examine.

How much does SC-401 cost?

165 US dollars, booked through Pearson VUE. Microsoft also publishes a free practice assessment and an exam sandbox on the credential page.

Which domain is worth the most marks?

None of them. All three are weighted 30 to 35 percent, and the ranges overlap completely, so any of the three could be the largest on the form you sit.

Do I need machine learning knowledge for the AI objectives?

No. The AI objectives are data governance ones: controls in Purview and Microsoft 365 workloads, and setting up and monitoring Data Security Posture Management for AI. No model building is examined.

Does the SC-401 certification expire?

Yes. Microsoft role-based certifications expire unless renewed, and renewal is free through an unproctored online assessment on Microsoft Learn rather than a full re-sit.

What languages is SC-401 available in?

Seven: English, Portuguese for Brazil, French, German, Japanese, Simplified Chinese and Spanish.

Can I retake SC-401 straight away if I fail?

Not immediately. A first retake can be booked 24 hours after the initial attempt, and the waiting period increases for subsequent attempts.

Conclusion

SC-401 rewards someone who treats Purview as one system. The three domains are weighted identically because classification, control and monitoring are three views of the same job, and the objectives reference each other often enough that studying them in isolation leaves gaps.

Two things are worth fixing in your plan before anything else. The exam is 100 minutes, not 120, so rehearse at the real pace. And the AI data security objectives have no SC-400 equivalent, which makes them the one part of the syllabus where older material will quietly let you down. Build them in a tenant, then use practice questions in the exam’s own format to find whatever is left.

Rating: 0 / 5 (0 votes)