Microsoft Certified Information Protection and Compliance Administrator Associate (SC 400)

Master Information Protection, Data Governance, and Compliance in Microsoft 365.

 

ABOUT THE PROGRAM

The Microsoft SC-400 certification validates your ability to safeguard an organisation’s information by designing and implementing effective information protection and compliance solutions in Microsoft 365. This course provides a solid foundation in data lifecycle management, information governance, insider risk, and endpoint data loss prevention, empowering professionals to meet modern regulatory and security needs with confidence.

 

Microsoft Certified Information Protection and Compliance Administrator Associate (SC-400) Enquiry

 

Enquire Now


----- OR -------

PREREQUISITES

  • Basic knowledge of Microsoft 365 services and architecture

  • Understanding of security, compliance, or information governance concepts

  • Prior experience with Microsoft 365 workloads is beneficial but not required

TARGET AUDIENCE

This course is ideal for:

  • Information Protection Administrators

  • Compliance Administrators & Managers

  • Security Analysts & Engineers

  • IT Professionals managing Microsoft 365 environments

  • Data Governance & Risk Officers

  • Anyone preparing for the SC-400 certification exam

WHAT WILL YOU LEARN?

  • Implement and manage information protection policies

  • Configure and monitor data loss prevention across devices and cloud apps

  • Apply and manage sensitivity and retention labels

  • Use Microsoft Purview for data classification and governance

  • Manage insider risks and communication compliance

  • Perform eDiscovery investigations and analyse audit logs

  • Evaluate and improve compliance posture using Compliance Manager

  • Support organisational regulatory and data protection requirements

PROGRAM OVERVIEW

The SC-400 Information Protection and Compliance Administrator course equips learners with the knowledge and hands-on skills necessary to plan and execute data protection strategies using Microsoft Purview and Microsoft 365 compliance solutions. Participants will explore data classification, sensitivity labels, retention policies, eDiscovery workflows, insider risk management, and auditing capabilities. Through real-world scenarios and guided labs, learners will gain the capabilities to help organisations safeguard sensitive information and maintain regulatory compliance across cloud and hybrid environments.


PROGRAM CONTENT

SC-400 Course Outline with Hands-on Labs

Module 1: Introduction to Microsoft Information Protection & Compliance

Topics

  • Overview of Microsoft Purview
  • Understanding data protection and compliance in Microsoft 365
  • Core components of information governance
  • Compliance centre navigation and reporting

Lab 1: Explore the Microsoft Purview Compliance Portal

  • Navigate the compliance portal
  • Review compliance score and improvement actions
  • Explore information protection and governance capabilities

Module 2: Implementing Information Protection

Topics

  • Data classification and content explorer
  • Configuring sensitivity labels
  • Auto-labelling for documents and emails
  • Understanding policy scopes and publishing labels
  • Monitoring label activity

Lab 2: Configure and Apply Sensitivity Labels

  • Create and publish a sensitivity label
  • Define encryption and content marking settings
  • Apply labels manually in Office apps
  • Test and validate auto-labeling policies

Module 3: Data Loss Prevention (DLP)

Topics

  • Overview of DLP in Microsoft 365
  • Endpoint DLP and device policy configuration
  • DLP for cloud apps using Microsoft Defender for Cloud Apps (MDCA)
  • Creating DLP rules and policy conditions
  • Reviewing alerts and reports

Lab 3: Create and Test a DLP Policy

  • Create DLP policies for sensitive data types
  • Configure endpoint DLP for device protection
  • Trigger and validate DLP alerts
  • Monitor policy performance in compliance reports

Module 4: Information Governance & Records Management

Topics

  • Retention labels and retention policies
  • Automating data lifecycle and retention
  • Records management for regulatory requirements
  • File plan management
  • Disposition review and data retention reports

Lab 4: Implement Retention Policies and Records Management

  • Create and publish retention labels
  • Configure auto-apply rules
  • Set up a file plan and review record disposition
  • Monitor content subject to retention

Module 5: Insider Risk Management

Topics

  • Insider risk analytics and indicators
  • Understanding triggers and thresholds
  • Communication compliance configuration
  • Policy tuning and alert governance

Lab 5: Configure Insider Risk Policies

  • Create insider risk management policies
  • Review activity indicators and alerts
  • Configure communication compliance policy
  • Investigate a simulated insider threat incident

Module 6: eDiscovery & Audit

Topics

  • Content search fundamentals
  • eDiscovery Standard: Case creation and exports
  • eDiscovery Premium: Collections, holds, and review sets
  • Advanced auditing features
  • Reporting & case analytics

Lab 6: Perform an eDiscovery Investigation

  • Create an eDiscovery case
  • Place content on legal hold
  • Create a search query and export results
  • Review audit logs and analyse user activity

Module 7: Manage Compliance Requirements

Topics

  • Compliance Manager overview
  • Risk assessments and improvement plans
  • Implementing regulatory controls
  • Reporting compliance posture
  • Integrating security and compliance operations

Lab 7: Improve Compliance Score

  • Run an assessment using Compliance Manager
  • Implement improvement actions
  • Review risk scores and compliance posture
  • Generate compliance reports