Domain 1: Implement Information Protection
- Sensitive information types (SITs) are pattern-matching detectors using primary patterns, supporting elements, character proximity, and confidence levels; Microsoft ships hundreds of built-in SITs (credit card with Luhn check, U.S. SSN) and you can create custom SITs for organization-specific patterns.
- Exact Data Match (EDM) matches against a hashed, uploaded reference table of your own sensitive records, giving high precision and far fewer false positives than generic SITs; document fingerprinting detects standard forms by converting a template into a SIT.
- Trainable classifiers use machine learning to categorize content by example rather than by pattern (resumes, source code, contracts); pre-trained classifiers are ready to use, while custom classifiers require seed and test data, and optical character recognition (OCR) can extract text from images for classification.
- Content explorer shows a current snapshot of labeled and sensitive items and where they live, while Activity explorer shows the actions performed on that content over time; both support classification tuning and investigation.
- Sensitivity labels are the core Purview classification mechanism; a label can apply visual content marking (header, footer, watermark), encryption with usage rights, and other protection, and that protection travels with the file even after it leaves the tenant.
- Label encryption binds usage rights such as View, Edit, Copy, Print, and Reply to specified users or groups, so an unauthorized user who obtains the file still cannot open it; external users and guests can be granted access by address, domain, or an authenticated-users option.
- A label policy publishes labels to users and groups and sets behaviors like a default label, mandatory labeling, justification for lowering a label, and label order; auto-labeling policies apply labels to data automatically without user action.
- Auto-labeling exists in two forms: client-side auto-labeling in Office apps (which can recommend or apply as users work) and service-side auto-labeling that applies to data at rest in Exchange, SharePoint, and OneDrive without opening the file; always run auto-labeling in simulation mode first.
- Container labels extend sensitivity labels to Microsoft Teams, Microsoft 365 Groups, SharePoint sites, and Power BI, controlling privacy, guest access, external sharing, and unmanaged-device access at the container level rather than the individual file.
- Information protection for endpoints, file shares, and on-premises repositories uses the Microsoft Purview Information Protection client (for manual and recommended labeling in File Explorer and Office) and the Information Protection scanner (to discover, classify, and label files at rest on Windows file shares and SharePoint Server).
- Microsoft Purview Message Encryption protects email so only intended recipients can read it, including external recipients who authenticate; Advanced Message Encryption adds custom branded templates, expiration of encrypted mail, and revocation of access to sent messages.
- Built-in labeling is native in Microsoft 365 Apps (Word, Excel, PowerPoint, Outlook) and is the recommended path; use adaptive scopes and targeted high-risk sites for auto-labeling, and reserve encryption for labels that truly need it so you do not break co-authoring or collaboration.
Domain 2: Implement Data Loss Prevention and Retention
- DLP policies detect sensitive content and prevent its unauthorized disclosure; actions include restricting or blocking sharing, showing a policy tip, generating admin alerts, allowing user override with justification, and encrypting; locations span Exchange, SharePoint, OneDrive, Teams, endpoints, on-premises repositories, and Microsoft Defender for Cloud Apps.
- Always deploy a new DLP policy in simulation (test) mode first so it logs matches without blocking or notifying; review the results in Activity explorer, assess business impact, then tune instance count and confidence level to cut false positives before enforcing.
- Assign DLP work with least privilege using Purview role groups (for example Compliance Administrator, Compliance Data Administrator, Information Protection); within a policy the first matching rule with the most restrictive action wins, and policy precedence is set by priority order.
- Adaptive Protection integrates Insider Risk Management signals with DLP so users whose risk level is elevated automatically receive more restrictive DLP enforcement, and the restrictions relax as their risk level falls, without an administrator editing policies for each user.
- Endpoint DLP protects Windows and macOS devices that are onboarded (through Intune or the onboarding package); it can restrict copy to USB or network share, printing, pasting to a browser, and uploading to unsanctioned cloud apps, and just-in-time protection evaluates an action at the moment it occurs before allowing or blocking it.
- Advanced DLP rules combine conditions (a SIT at or above an instance-count threshold, a sensitivity label, shared externally), exceptions, and actions; raising the instance-count threshold and requiring high-confidence matches makes rules fire only on meaningful volumes.
- DLP in Microsoft Defender for Cloud Apps extends policy enforcement to third-party and non-Microsoft SaaS apps, letting you detect and control sensitive content in connected cloud apps and apply session controls to labeled data.
- Retention labels apply to individual items, folders, and libraries and can trigger record declaration and disposition, while retention policies apply broadly to locations (mailboxes, sites, Teams, Viva Engage) without user action; labels can be published for manual use or auto-applied by SIT, keyword, query, or trainable classifier.
- Retention principles of precedence resolve conflicts: retention wins over deletion, the longest retention period wins, explicit labels beat policies, and the shortest deletion applies only after all retention obligations are satisfied.
- Adaptive scopes target retention dynamically using an attribute query (Department, country, or site URL), so membership updates automatically as users and sites change, unlike static scopes that an administrator maintains by hand.
- Data lifecycle management and disposition control what happens at the end of retention: retain only, retain then delete, or delete only; disposition review inserts a manual approval step so designated reviewers approve deletion, relabeling, or extension and produce an audit trail, and is best reserved for high-value records.
- Content that a user deletes while under retention is preserved in a hidden location (Recoverable Items for mailboxes, the Preservation Hold library for SharePoint and OneDrive) and remains recoverable through the retention period.
Domain 3: Manage Risks, Alerts, and Activities
- Microsoft Purview Insider Risk Management correlates signals to detect risky user activity such as data theft by departing employees, leaks of sensitive data, and security policy violations; it uses connectors (for example the HR connector for resignation and termination dates) and integrates with Microsoft Defender for Endpoint for device signals.
- Insider Risk policies are built from templates (data theft by departing users, data leaks, security policy violations, risky browser usage) and use indicators such as bulk downloads, external forwarding, copying to USB, and printing; you tune indicators and thresholds so meaningful signals surface and low-value noise is suppressed.
- Forensic evidence captures visual activity (clips of user actions on a device) for high-severity insider-risk cases, subject to opt-in, capturing rules, and privacy controls; Adaptive Protection uses insider-risk levels to dynamically apply stronger DLP and Conditional Access controls.
- Insider Risk work is organized into alerts and cases with a triage-to-resolution workflow; analysts review alerts, escalate to a case, add notes and evidence, and can send a user notice, escalate for investigation, or resolve the case, all under role-based access that supports pseudonymization for privacy.
- Microsoft Purview Audit (Premium) extends default audit-log retention to one year (up to ten years with an add-on), surfaces high-value crucial events (such as MailItemsAccessed), and provides higher bandwidth; Audit (Standard) retains most events for 180 days, and audit ingestion must be enabled before events are captured.
- Activity explorer provides a filterable history of activities on labeled and sensitive content across Microsoft 365 (labels applied or changed, files copied or shared, DLP matches), supporting both investigation and DLP or label tuning.
- DLP alerts are triaged in the Purview DLP alerts dashboard and in Microsoft Defender XDR, where DLP incidents are correlated with other signals; configure alert severity and aggregation so high-severity, high-volume events surface first.
- eDiscovery searches for, preserves, and exports content across Exchange, SharePoint, OneDrive, and Teams for legal and investigative matters; a hold preserves relevant content from deletion, and eDiscovery (Premium) adds custodian management, legal-hold notifications, review sets, and analytics.
- Respond to alerts in Microsoft Defender XDR and Microsoft Defender for Cloud Apps by investigating correlated incidents, taking response actions (such as suspending a user or quarantining files), and following the alert through to resolution across the unified portal.
- Data Security Posture Management (DSPM) for AI gives a central place to discover, monitor, and protect data used by AI services, including Microsoft 365 Copilot and other generative-AI apps; it surfaces sensitive-data interactions, risky prompts, and unlabeled content that AI could expose.
- Protecting Microsoft 365 Copilot data with DSPM for AI relies on prerequisites such as onboarded endpoints, sensitivity labels and DLP in place, and audit enabled; Copilot honors sensitivity-label permissions so it will not surface content a user is not authorized to open.
- DSPM for AI ships recommended one-click policies (for example detecting risky AI interactions and applying DLP to block sensitive data in prompts) and provides monitoring reports and Activity explorer views so administrators can measure AI data exposure and tune protection over time.
SC-401 exam tips
- Always run new DLP, auto-labeling, and retention auto-apply policies in simulation or test mode first, review Activity explorer, and tune instance count and confidence before enforcing; expect several questions framed around reducing false positives without disabling protection.
- Memorize the retention precedence rules cold: retention wins over deletion, longest retention wins, explicit labels beat policies, and deletion applies only after all retention is satisfied.
- Distinguish overlapping features by their unique purpose: SIT vs trainable classifier vs EDM vs document fingerprinting; sensitivity label vs retention label; DLP simulation vs enforce; Audit Standard vs Premium; adaptive vs static scopes; eDiscovery Standard vs Premium.
- Understand how Adaptive Protection ties Insider Risk Management levels to automatic DLP and Conditional Access enforcement, and know the Insider Risk workflow from indicators and templates through alerts, cases, forensic evidence, and resolution.
- Know DSPM for AI well: what it discovers and monitors, its prerequisites (onboarded endpoints, labels, DLP, audit), how it protects Microsoft 365 Copilot data, and that Copilot respects existing sensitivity-label permissions.
- When a scenario stresses scale or noise, prefer adaptive scopes, targeted locations and groups, high-confidence SITs, container labels for collaboration surfaces, and disposition review only for high-value records rather than broad tenant-wide enforcement.
Study guide FAQ
What is the passing score for SC-401 and how is the exam structured?
The passing score is 700 on a scale of 100 to 1000. SC-401 runs about 100 minutes and has roughly 50 questions organized into three equally weighted domains, each carrying 30 to 35 percent: implement information protection, implement data loss prevention and retention, and manage risks, alerts, and activities.
Did SC-401 replace SC-400?
Yes. SC-401 (Administering Information Security in Microsoft 365, for the Information Security Administrator role) replaced the retired SC-400 in 2026. It keeps the Microsoft Purview information protection, DLP, and retention foundations but consolidates the scope into three domains and adds coverage of insider risk, security alert investigation, and protecting data used by AI services.
What is DSPM for AI and why is it on the exam?
Data Security Posture Management (DSPM) for AI is a Microsoft Purview capability that discovers, monitors, and protects the data that AI services use, including Microsoft 365 Copilot and other generative-AI apps. It surfaces sensitive-data interactions and risky prompts, ships one-click policies, and relies on sensitivity labels and DLP. It is tested because protecting AI-accessed data is now a core responsibility of the Information Security Administrator.
What is the difference between a sensitivity label and a retention label?
A sensitivity label classifies and protects content by applying encryption, usage rights, and visual content marking that travels with the file. A retention label governs the data lifecycle, defining how long an item is kept and whether it is deleted, reviewed, or declared a record at the end of the period. An item can carry both a sensitivity label and a retention label at the same time.
When should I use Exact Data Match (EDM) instead of a built-in sensitive information type?
Use EDM when you need to protect specific, known records such as your customer or employee database with high precision. EDM matches against a hashed, uploaded reference table of your own data, dramatically reducing false positives compared with generic SITs that match any value fitting a pattern. Choose a trainable classifier instead when the content has no fixed pattern, such as contracts or source code.