NEW SC-401 Administering Information Security in M365 Certification

Microsoft has just announced exam SC-401 Administering Information Security in Microsoft 365 which gives you the Microsoft Certified: Information Security Administrator Associate certification! In this video, we’ll take a first look at this exam!

Links

Video Summary

  • New Certification: Microsoft announced the SC-401 exam, “Administering Information Security in Microsoft 365,” which replaces the SC-400 exam. This new certification focuses solely on information protection.
  • Role and Responsibilities: As an Information Security Administrator, you’ll handle sensitive data security using Microsoft Purview, mitigate risks, protect data in collaboration environments, and manage security alerts and activities.
  • Exam Focus Areas: The SC-401 exam covers three main skills: implementing information protection, data loss prevention and retention, and managing risks, alerts, and activities. Each area is equally weighted.
  • Key Study Areas: To pass the exam, focus on insider risk management, data security posture management (DSPM), data loss prevention (DLP), and auditing and monitoring. New topics include OCR support for sensitive information and AI data security.
  • Availability and Beta: The SC-401 exam will be available in beta on February 11, 2025. Early beta exam takers might get up to 75% off, so keep an eye on the Microsoft Learn blog for updates.

For more information, read the transcript blog below, or watch the video above!

Video Transcript

Microsoft just announced a brand new security certification that is a must-have if you are serious about protecting your data in Microsoft 365. Its exam number is SC-401, with the exam name Administering Information Security in Microsoft 365. Passing this exam grants you the Microsoft Certified Information Security Administrator certification.

In this video, we’ll talk about why this certification was created, when it will be available, and what’s covered inside. Let’s get started!

Let me start by answering the question: where does this certification come from? If you missed my earlier video, the SC-400 exam is getting retired because Microsoft received feedback that having a certification targeting both information protection administrators and compliance administrators was too much. In companies, no one really does both roles. So, they created exam SC-401, which is dedicated specifically to information protection. Meanwhile, compliance administrators will not receive a dedicated certification but will instead use the Applied Skills credentials.

Okay, enough about the SC-400. If you want to learn more, check out the dedicated video. For now, let’s focus on the SC-401 exam: Administering Information Security in Microsoft 365.

First, let’s talk about what Microsoft shared about who should get this certification. As an Information Security Administrator, you plan and implement the information security of sensitive data by using Microsoft Purview and related services. You are responsible for mitigating risks by protecting data inside collaboration environments managed by Microsoft 365 from internal and external threats. You are also responsible for protecting data used by AI services. Additionally, you implement information protection, data loss prevention, retention, insider risk management, and manage information security alerts and activities.

You work with other roles responsible for governance, data, and security to evaluate and develop policies that address an organization’s information security and risk reduction goals. You collaborate with workload administrators, business application owners, and governance stakeholders to implement technology solutions that support the necessary policies and controls. This role also participates in responding to information security incidents.

As an exam taker, you should be familiar with all Microsoft 365 services, PowerShell, Microsoft Entra, the Microsoft Defender portal, and Microsoft Defender for Cloud Apps. So far, this makes perfect sense.

Now, let’s take a look at what you need to know to pass this exam. This is the first time I’ve seen an exam structured this way—SC-401 has three main skills measured, and they are all weighted equally. This means you will get an equal number of questions (or close to it) from all three areas. The three measured skills are:

  • Implement information protection
  • Implement data loss prevention and retention
  • Manage risks, alerts, and activities

Now, I won’t go through the entire list of objectives because you’ll find the link in the description below, but let me cover some highlights. To pass the SC-401 exam, you need to focus on several key areas:

  • Insider Risk Management is critical. You’ll need to understand how to configure and manage adaptive protection policies, insider risk policies, forensic evidence collection, and alert workflows.
  • Data Security Posture Management (DSPM) is another major area, covering how to classify and protect AI-generated data, enforce security policies, and monitor compliance risks.
  • Data Loss Prevention (DLP) has really expanded, requiring you to know how to apply DLP policies across cloud apps, endpoints, and AI tools while integrating Microsoft Defender to detect and prevent data leaks.
  • Auditing and Monitoring includes real-time activity tracking, so you’ll need to understand how to implement audit retention policies and configure alerts for security incidents.

Now, you might wonder: if you are studying for or have already passed the SC-400 exam, do you still need to study for the SC-401?

If you’ve already passed or studied for the SC-400, you’re in a great spot because many of the core concepts carry over to SC-401. However, there are a few new areas you’ll need to focus on.

First, the SC-401 puts a strong emphasis on enhanced data classification and information protection, including configuring OCR support for sensitive information types. This means you’ll need to classify data within images and scanned documents.

The exam also dives deeper into endpoint protection, requiring you to plan, deploy, and manage the Microsoft Purview Information Protection client for Windows file shares and Exchange.

Additionally, a significant new topic is protecting data in AI environments through Data Security Posture Management (DSPM) for AI. Here, you’ll learn how to implement controls, manage policies, and monitor activities in scenarios involving AI services, which, let’s be honest, almost every company now uses.

In summary, while the SC-400 covered both protection and compliance, the SC-401 focuses solely on information protection. This means you’ll only study one big topic, but it goes much deeper—with OCR, endpoint-specific protection, and AI data security. You’ll need to study those areas to be fully prepared.

Now, when can you take the exam?

The SC-401 exam will be available in beta on February 11, 2025, so in about a week from today. And let me give you a hint—while not a guarantee, Microsoft usually offers up to 75% off for the first people who take beta exams. Make sure you check the Microsoft Learn blog on the Tech Community or come back to this video around February 11. If the offer is available, I’ll post a link in the description below.

If you’re an MCT (Microsoft Certified Trainer), check out the MCT Lounge, where you can get more information about the MCT beta exam rebate.

That’s it for this video on the brand-new SC-401 Microsoft certification exam!

Now, my question for you is: will you take it? Do you think it holds as much value as the SC-400, given that it covered both compliance and information protection?

Let me know in the comments below! And if you take the beta, let me know how you found it—of course, without breaking NDA.

If you found this video valuable, check out some of the other videos appearing on your screen right now, and make sure you like this video and subscribe to the channel for the latest certification news!

Blogs and Videos