SC-401 Administering Information Security in Microsoft 365

Duration: 4 days Dates: 27 October 2026 14 December 2026

SC-401 is the successor to SC-400 and centres on protecting information in Microsoft 365: classifying data and applying sensitivity labels, preventing data exfiltration with DLP and Endpoint DLP, governing retention, detecting insider risks – and, new, securing data processed by AI services such as Microsoft Copilot. The course prepares you for the SC-401 exam (certification «Microsoft Certified: Information Security Administrator Associate»).

Information protection

  • Data classification: determine protection needs and translate them into built-in or custom sensitive information types
  • Custom types, document fingerprinting, exact data match (EDM), trainable classifiers, OCR support
  • Track the use of classification and labels via the data and content explorers
  • Sensitivity labels in Microsoft Purview: roles and permissions, labels for items and containers, protection settings and content marking, publishing and auto-labelling policies
  • Labels for Teams, Microsoft 365 groups, Power BI and SharePoint; applying them via Defender for Cloud Apps
  • Information Protection client and scanner for Windows, file shares and on-premises data; Message Encryption and Advanced Message Encryption

Data loss prevention and retention

  • Design and manage DLP policies, roles and permissions, understand policy and rule precedence
  • DLP for Adaptive Protection, file policies in Defender for Cloud Apps
  • Endpoint DLP: device requirements, advanced rules, settings, just-in-time protection, monitoring endpoint activity
  • Retention: retention labels and policies, adaptive policy scopes, auto-apply, checking precedence with Policy Lookup, recovering retained content

Risks, alerts and activities

  • Insider Risk Management: roles, connectors, integration with Defender for Endpoint, policy indicators and templates, forensic evidence, risk levels for Adaptive Protection, working with alerts and cases
  • Microsoft Purview Audit: licensing, investigations, retention policies; analysis in Activity Explorer
  • Responding to DLP and Purview alerts, including in Defender XDR; searching with eDiscovery
  • Protect data in AI services: controls in Purview and in the Microsoft 365 workloads, prerequisites and policies for Data Security Posture Management for AI, monitoring activity
Learning Solution

Blended Learning, Firmenseminar, Individualcoaching, Klassenraumtraining, Online Live Webinar, Prüfungsvorbereitung

Language

Deutsch, Englisch, Französisch, Italienisch

Dates

2026/08/31, 2026/10/27, 2026/12/14, flexibel, auf Anfrage

Location

Brüttisellen, Lausanne, flexibel, auf Anfrage

People responsible for information security, compliance and data protection in Microsoft 365 environments, as well as administrators who operate Purview.

Knowledge of Microsoft 365 services and a basic understanding of compliance requirements are required. If you were familiar with SC-400: that exam has been retired, and SC-401 is its successor.

After the course you will be able to:

  • determine protection needs and translate them into classification and sensitivity labels
  • have labels applied automatically, including on Teams, SharePoint and Power BI
  • build DLP and Endpoint DLP policies that are effective without blocking operations
  • govern retention and deletion in a traceable way
  • detect insider risks and protect data processed by Copilot and other AI services

Price range: CHF2'720 through CHF12'500 excl. VAT

Clear

SIGN UP

Newsletter

Receive news about new courses, offers and promotions by email.

← Back

Thank you for your response. ✨

Email Subscription
Amazon
VMware and Virtualisation