Information Security Administrator (SC-401)
Your sensitive information needs consistent protection rules in Microsoft 365. Connect classification, access and security controls to structure its administration. Strengthen your ability to coordinate configurations and data protection requirements.
- Duration
- 4 days 28 hours
- Code
- SC-401T00-A Code
- Certification
- Microsoft Certified : Information Security Administrator Associate Certification
Accredited training for the Microsoft Certified : Information Security Administrator Associate certification.
Presentation
As business data spreads across cloud services and devices, protecting it and meeting regulatory requirements such as GDPR has become a major strategic challenge. This course on administering information protection with Microsoft Purview develops the technical skills to address that challenge by building and managing an end-to-end data governance strategy.
The 4-day program is highly practical, alternating theoretical concepts and immersive workshops. First, you will learn to classify sensitive information accurately. You will then apply effective protection measures, including encryption and access restrictions, using sensitivity labels. You will also deploy data loss prevention policies (DLP) to secure your entire Microsoft 365 environment.
The course also prepares you to take the SC-401 examination, included in our offering, to validate your skills and earn the Microsoft Certified: Information Security Administrator Associate certification (see the Certification tab for details).
Objectives
By the end of the Microsoft SC-401 course, you will be able to:
- classify data to identify and locate sensitive information using built-in, custom and machine-learning-based classifiers;
- implement and manage sensitivity labels to apply encryption, access restrictions and visual markings to documents, emails and service containers such as Teams and SharePoint;
- design and configure data loss prevention (DLP) policies to prevent unauthorised sharing of sensitive information across cloud services and workstations;
- manage the data lifecycle by deploying retention policies and labels to retain or delete content according to business requirements;
- deploy and manage insider risk management to detect, investigate and act on potentially risky user activities;
- audit activities and respond to security and compliance alerts using Microsoft Purview investigation tools;
- protect data in environments using artificial intelligence services by applying appropriate security controls;
- pass the SC-401 examination and earn Microsoft Certified: Information Security Administrator Associate certification.
Program
Module 1: identifying and classifying sensitive data
- Identifying sensitive information requirements for organisational data.
- Mapping sensitive information requirements to built-in or custom sensitive information types.
- Creating and managing custom sensitive information types.
- Implementing document fingerprinting.
- Creating and managing exact data match (EDM) classifiers.
- Creating and managing trainable classifiers.
- Monitoring data classification and label use with data explorer and content explorer.
- Configuring optical character recognition (OCR) support for sensitive information types.
Module 2: applying protection through sensitivity labels
- Implementing roles and permissions for sensitivity label administration.
- Defining and creating sensitivity labels for items and containers.
- Configuring protection settings and content markings for sensitivity labels.
- Configuring and managing sensitivity label publishing policies.
- Configuring and managing sensitivity auto-labelling policies.
- Applying sensitivity labels to containers: Microsoft Teams, Microsoft 365 Groups, Power BI and SharePoint.
- Applying sensitivity labels using Microsoft Defender for Cloud Apps.
Module 3: protecting on-premises data and endpoints
- Planning and implementing the Microsoft Purview Information Protection client.
- Managing files with the Microsoft Purview Information Protection client.
- Bulk-classifying on-premises data using the Microsoft Purview Information Protection scanner.
- Designing and implementing Microsoft Purview Message Encryption.
- Designing and implementing Microsoft Purview Advanced Message Encryption.
Module 4: data loss prevention strategies
- Designing data loss prevention policies based on organisational requirements.
- Implementing roles and permissions for data loss prevention.
- Creating and managing data loss prevention policies.
- Configuring DLP policies for adaptive protection.
- Interpreting DLP policy and rule priority.
- Creating file policies in Microsoft Defender for Cloud Apps using a DLP policy.
Module 5: controlling endpoint activities
- Specifying device requirements for Endpoint DLP, including extensions.
- Configuring advanced device DLP rules within DLP policies.
- Configuring endpoint DLP settings.
- Configuring just-in-time protection.
- Monitoring endpoint activities.
Module 6: data lifecycle governance
- Planning information retention and deletion using retention labels.
- Creating, configuring and managing adaptive scopes.
- Creating retention labels for data lifecycle management.
- Configuring a retention label policy to publish labels.
- Configuring a retention label policy to apply labels automatically.
- Interpreting policy priority outcomes, including through policy lookup.
- Creating and configuring retention policies.
- Recovering retained content in Microsoft 365.
Module 7: detecting and investigating insider risks
- Implementing roles and permissions for insider risk management.
- Planning and implementing insider risk management connectors.
- Planning and implementing integration with Microsoft Defender for Endpoint.
- Configuring and managing insider risk management settings.
- Configuring policy indicators.
- Selecting an appropriate policy template.
- Creating and managing insider risk management policies.
- Managing forensic evidence settings.
- Enabling and configuring insider risk levels for adaptive protection.
- Managing insider risk alerts and cases.
- Managing the insider risk management workflow, including notice templates.
Module 8: auditing, investigation and alert response
- Assigning Microsoft Purview Audit (Premium) user licences.
- Investigating activities with Microsoft Purview Audit.
- Configuring audit retention policies.
- Analysing Purview activities with activity explorer.
- Responding to DLP alerts in the Microsoft Purview portal.
- Investigating insider risk activities through the Microsoft Purview portal.
- Responding to Purview alerts in Microsoft Defender XDR.
- Responding to Defender for Cloud Apps file policy alerts.
- Performing searches using content search.
Module 9: data security for artificial intelligence (DSPM)
- Implementing Microsoft Purview controls to protect content in environments using AI services.
- Implementing controls in Microsoft 365 productivity workloads to protect content in environments using AI services.
- Implementing prerequisites for Data Security Posture Management (DSPM) for AI.
- Managing DSPM for AI roles and permissions.
- Configuring DSPM for AI policies.
- Monitoring activities in DSPM for AI.
Module 10: preparing for the SC-401 examination
- Review of key course concepts.
- Examination advice and tips.
- Analysis of sample examination questions.
- Additional preparation resources.
Audience
This course is intended for:
- Information protection administrators directly responsible for deploying and managing data classification, labelling and protection solutions.
- Security administrators seeking to master information protection tools and strengthen overall organisational security.
- Compliance and risk managers wishing to use Microsoft Purview technologies to implement governance and insider risk management policies.
- Microsoft 365 administrators who configure and maintain security and compliance features within their environments.
Prerequisites
This Microsoft course requires:
- Practical experience with Microsoft 365 services, particularly Exchange Online, SharePoint Online and Microsoft Teams.
- Knowledge of fundamental Microsoft product security and compliance concepts.
- Knowledge of cloud computing and identity management concepts, particularly Active Directory and Microsoft Entra ID.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Course highlights
- An expert Microsoft-certified instructor: learn from a Microsoft Purview specialist with expertise in information protection and compliance administration.
- A practical approach based on real scenarios: apply your knowledge through official labs and case studies based on real data protection, DLP and risk management challenges.
- Comprehensive SC-401 preparation: prepare effectively for the certification examination, with voucher included and review sessions to maximise your chances of success.
- Certification guarantee: this course includes Microsoft Exam Replay, allowing a free retake if you do not pass on your first attempt.
- Master information governance: learn to translate business compliance requirements into effective technical rules and manage the full sensitive information lifecycle.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
Microsoft®, Microsoft 365®, Microsoft Purview®, Microsoft Defender® and Microsoft Azure® are registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries.
fr
en