Stay ahead by continuously learning and advancing your career. Learn More

Microsoft Information Protection Administrator (SC-400) Exam

Practice Exam
Take Free Test

Microsoft Information Protection Administrator (SC-400) Exam



The Microsoft SC-400 certification is designed for information protection and compliance administrators who are involved in planning and executing risk and compliance controls within the Microsoft Purview compliance portal.

In this, candidates are tasked with translating the risk and compliance requirements of an organization into technical implementations. Their responsibilities include the implementation and management of solutions for content classification, data loss prevention (DLP), information protection, data lifecycle management, records management, privacy, risk, and compliance.

They collaborate with other roles responsible for governance, data, and security to assess and formulate policies aimed at addressing the risk reduction and compliance objectives of an organization. Additionally, they provide assistance to workload administrators, business application owners, human resources departments, and legal stakeholders in implementing technology solutions that align with the required policies and controls.


Who should take the exam?

The exam is best suitable for those having experience with Microsoft 365 services, including:

  • Microsoft 365 Apps
  • Microsoft Exchange Online
  • Microsoft SharePoint
  • Microsoft OneDrive
  • Microsoft Teams

And, candidates should also be familiar with PowerShell.



SC-400 Exam Course Outline 

The Microsoft SC-400 Exam covers the given topics  - 
  • Domain 1: Learn about implementing information protection (25–30%)
  • Domain 2: Understand about implementing DLP (15–20%)
  • Domain 3: Implementing data lifecycle and records management (10–15%)
  • Domain 4: Understand Monitoring and investigating data and activities by using Microsoft Purview (15–20%)
  • Domain 5: Managing insider and privacy risk in Microsoft 365 (15–20%)

Microsoft Information Protection Administrator (SC-400) Exam FAQs

If you fail a certification exam, you can retake it. There is a waiting period between retakes in order to maintain the integrity of the exam. When you fail for the first time, you must wait 24 hours between retakes. 

No. Microsoft does not offer refunds for exams you do not pass or exam appointments you miss.

For exams taken with PSI, your score report was sent to the contact email listed on your certification profile and cannot be accessed through your certification dashboard. Score reports are available online for exams taken with Pearson VUE.

The Microsoft SC-400 exam covers the following topics - 

  • Implement information protection (35-40%)
  • Implement data loss prevention (30-35%)
  • Implement information governance (25-30%)

The Microsoft Information Protection Administrator (SC-400) measures your ability to accomplish the following technical tasks: implement information protection; implement data loss prevention, and implement information governance.


Microsoft Certification exams are available in several languages. However, candidates who must take the exam in English rather than in their native language can request accommodation for additional time. Approval for extra time is provided on a case-by-case basis and needs to be requested in advance of the exam.

As Microsoft Information Protection Administrator you will be required to plan and implement controls that meet organizational compliance needs. Also, you will be responsible for translating requirements and compliance controls into technical implementation. You will be required to assist organizational control owners to become and stay compliant.

If you have a concern about the technical accuracy of a particular item, please submit an online request. An Item Challenge form will be sent to you. However, a re-evaluation of your score is unlikely to change your pass/fail status. Because Microsoft must ensure that candidates who pass exams and earn our certifications have demonstrated the required proficiency level(s) across the skill domain(s), the final result of an exam is rarely changed based on a re-evaluation of your exam results. 

  • You will be required to work with information technology (IT) personnel, business application owners, human resources, and legal stakeholders to implement technology that supports policies and controls necessary to sufficiently address regulatory requirements for their organization.
  • You will be required to work with the compliance and security leadership such as a Chief Compliance Officer and Security Officer to evaluate the full breadth of associated enterprise risk and partner to develop those policies.
  • You will be required to define application requirements and tests IT processes and operations against those policies and controls.
  • You will be responsible for creating policies and rules for content classification, data loss prevention, governance, and protection.