
SC-401: Administering Information Security in Microsoft 365
People are viewing this right now
Course Detail
-
Module: Implement Information Protection (30–35%)
- Identify organizational sensitive information needs; translate into built-in or custom sensitive info types
- Create/manage custom sensitive info types, document fingerprinting, EDM classifiers, trainable classifiers
- Monitor classification and label usage via Data Explorer and Content Explorer
- Configure OCR support for sensitive info types
- Manage sensitivity labels (creation, policies, auto-labeling) for containers (Teams, SharePoint, Power BI)
- Apply labels via Defender for Cloud Apps
- Deploy Purview Information Protection client, bulk classify on-premises, message encryption
-
Module: Implement Data Loss Prevention & Retention (30–35%)
- Design and deploy DLP policies, configure Adaptive Protection, understand rule precedence
- Create DLP file policies via Defender for Cloud Apps
- Onboard devices for Endpoint DLP; configure settings, advanced rules, just-in-time protection, and monitor
- Plan retention and disposition with labels; create retention labels, adaptive scopes, auto-apply labels
- Manage retention policies and content recovery
-
Module: Manage Risks, Alerts, and Activities (30–35%)
- Configure Insider Risk Management: roles, connectors, Defender for Endpoint integration, policy indicators, templates, forensic evidence, adaptive protection, alerts & cases, workflows
- Manage information security alerts and auditing: assign Audit Premium licenses, investigate via Purview Audit, configure retention, analyze via Activity Explorer
- Respond to DLP and risk alerts in Purview and Defender XDR; perform content searches
- Implement protections for AI services: configure DSPM for AI, roles, policies, and monitoring

SC-401: Administering Information Security in Microsoft 365