SC-401 : Protect sensitive information with Microsoft Purview in the AI era
- Administrators
- Data Protection Administrators
- Security Operators
Training Overview
This course will provide you with the essential skills to plan and deploy information security on sensitive data using Microsoft Purview and its related services. You’ll learn how to secure data in Microsoft 365 collaborative environments, protecting against internal and external threats.
You will be proficient in security alert management and incident response, investigating suspicious activity, dealing with DLP alerts, and managing risky situations related to internal users. You’ll also learn how to protect the data used by artificial intelligence services in Microsoft environments, while also putting controls in place to secure your content.

Learning Objectives
Trainees will be able to:
- Implement Microsoft Purview Information Protection
- Implement and manage Microsoft Purview Data Loss Prevention
- Implement and manage Microsoft Purview Insider Risk Management
- Protect data in AI environments with Microsoft Purview
- Implement and manage Microsoft 365 retention and recovery
- Use auditing and research activity in Microsoft Purview
Protecting sensitive data in a digital world
- Describe the challenges of protecting sensitive data in cloud and AI environments.
- Explain how Microsoft Purview enables data classification, labeling, and protection.
- Identify how data loss prevention (DLP) prevents unauthorized data sharing.
- Learn how Insider Risk Management helps detect potential threats.
- Explore security monitoring tools to detect and respond to data risks.
Classify data for protection and governance purposes
- Explain the importance of data classification for protection and governance.
- Describe how sensitive information types (SITs) classify structured data.
- Explain how trainable classifiers identify unstructured data.
- Create a custom trained classifier to detect organization-specific content.
Review and analyze data classification and protection
- Interpret information protection reports to assess classification and protection trends.
- Review tagged content using Data Explorer and Content Explorer to identify classification patterns.
- Analyze user activity in Activity Explorer for policy violations and potential security risks.
- Use Microsoft Purview tools to improve data security, maintain compliance, and fine-tune protection policies.
Create and manage sensitive information types
- Differentiate between built-in and custom sensitivity labels.
- Configure sensitive information types with classification based on exact data matching.
- Implement fingerprinting.
- Create custom keyword dictionaries.
Create and configure sensitivity labels with Microsoft Purview
- Understand the basics of Microsoft Purview sensitivity labels in Microsoft 365.
- Create and publish sensitivity labels to classify and protect data.
- Configure encryption settings with sensitivity labels to improve data security.
- Implement automatic labeling for consistent data classification and protection.
- Use the Microsoft Purview Data Classification Dashboard to monitor sensitivity label usage.
Apply sensitivity labels for data protection
- Understand the basics of sensitivity label integration in Microsoft 365.
- Manage sensitivity label usage in Office apps for security compliance.
- Secure Outlook and Teams meetings with sensitivity labels.
- Apply labels to Microsoft 365, SharePoint, and OneDrive groups for data protection.
Classify and protect on-premises data with Microsoft Purview
- Prepare your environment to support the Microsoft Purview Information Protection scanner.
- Configure scanner settings, authentication, and deployment prerequisites.
- Run scans in discovery or application mode.
- Apply sensitivity labels and protection to local files.
- Use data loss prevention (DLP) rules to restrict access or quarantined files based on the policy.
Understanding Microsoft 365 encryption
- Explain how encryption mitigates the risk of unauthorized data disclosure.
- Describe Microsoft’s data-at-rest and data-in-transit encryption solutions.
- Explain how Microsoft 365 implements service encryption to protect customer data at the application layer.
- Understand the differences between Microsoft-managed keys and customer-managed keys for using service encryption.
Protect email with Microsoft Purview message encryption
- Enable Microsoft Purview Message Encryption using Azure Rights Management.
- Automatically enforce encryption by using mail flow rules.
- Customize branding for encrypted messages and the encryption portal.
- Use Advanced Message Encryption to control message expiration and revocation.
Prevent data loss in Microsoft Purview
- Understand the purpose and benefits of Microsoft Purview DLP.
- Plan, design, simulate, and deploy DLP policies.
- Apply adaptive protection for dynamic risk-based data controls.
- Use DLP analytics to improve policy effectiveness.
- Monitor, review, and refine policies using alerts and activity tracking.
Implement endpoint data loss prevention (DLP) with Microsoft Purview
- Understand the benefits of endpoint DLP
- Onboard devices for endpoint data loss prevention
- Configure endpoint DLP settings
- Create and manage endpoint DLP policies
Configure DLP policies for Microsoft Defender for Cloud Apps and Power Platform
- Describe the integration of DLP with Microsoft Defender for Cloud Apps.
- Configure policies in Microsoft Defender for Cloud Apps.
Review and respond to Microsoft Purview data loss prevention alerts
- Review DLP alerts in Microsoft Purview and Microsoft Defender XDR
- Review alert details, associated user activities, and matched events
- Apply remediation actions and update alert or incident statuses
- Assign ownership, document decisions, and take responsibility
- Recognize when DLP policies may need adjustments based on investigation findings
Understand insider risk management in Microsoft Purview
- Define insider risks and their effects on organizations.
- Understand the purpose of insider risk management as part of Microsoft Purview.
- Identify key features such as policies, signals, analytics, dashboards, and investigation tools.
- Recognize how these tools detect and resolve potential risks.
- Explore scenarios that illustrate effective risk management strategies.
Prepare for Microsoft Purview Insider Risk Management
- Collaborate with stakeholders to prepare for insider risk management.
- Understand what is required to meet the implementation requirements.
- Configure settings to align with compliance and privacy needs.
- Connecting tools and data sources improves risk management.
Create and manage Insider Risk Management policies
- Explain the purpose of the strategy templates.
- Identify when to use quick or custom policies.
- Create quick policies for common scenarios.
- Generate and configure custom policies for specific risks.
- Update and manage policies based on the needs of the organization.
Review internal risk alerts and related activity
- Learn how alerts are generated and prioritized in insider risk management.
- Set policies and thresholds to effectively manage the volume of alerts.
- Use the alerts dashboard and alert details to triage and respond to risky activity.
- Examine behavior using tabs such as all risk factors, Activity Explorer, and User Activity.
- Integrate with Microsoft Defender XDR for broader threat investigation.
- Create, manage, and resolve insider risk management cases.
Implement adaptive protection in insider risk management
- Describe adaptive protection and its role in dynamic risk mitigation.
- Configure risk level settings and customize risk levels based on your organization’s needs.
- Configure adaptive protection with a quick or custom configuration.
- Manage adaptive protection to review policy metrics, track users across the scope, and assess risk levels.
Discover AI interactions with Microsoft Purview
- Explain how Microsoft Purview DSPM for AI and auditing helps identify data risks due to AI.
- Configure DSPM for AI to detect activity from AI tools such as Microsoft 365 Copilot and other enterprise tools.
- Use Microsoft Purview Audit to find and investigate Copilot interactions.
- Analyze AI activity and risks using built-in reports and insights.
Protecting sensitive data from AI risks
- Use sensitivity labels to control how AI tools access and manage content.
- Configure endpoint DLP to restrict risky actions in browsers.
- Apply DSPM for AI recommendations to protect sensitive data in Microsoft Purview solutions.
Govern the use of AI with Microsoft Purview
- Apply retention policies to manage the lifecycle of Copilot and other AI-generated content using data lifecycle management.
- Review and delete Copilot interaction history using eDiscovery (Premium).
- Create policies to evaluate Copilot messages and other AI-related communications using communication compliance.
Assess and mitigate AI risks with Microsoft Purview
- Detect the generative use of AI with insider risk management.
- Use risk scoring to identify users who are higher risk.
- Apply dynamic protections with adaptive protection based on user behavior.
- Use data assessments to identify oversharing risks in AI interactions.
Understanding retention in Microsoft Purview
- Identify common use cases for enforcing retention.
- Explain how retention supports data protection alongside tools such as data loss prevention.
- Apply retention settings to specific users, sites, or content types.
- Recognize what retention controls and what it does not.
Implement and manage Microsoft 365 retention and recovery
- Plan conservation and disposition using conservation labels.
- Automatically create, publish, and apply retention labels.
- Use adaptive scopes to dynamically target users, groups, or sites.
- Configure retention policies for Microsoft 365 workloads.
- Interpret the result when multiple retention settings apply.
- Restore deleted items and previous versions of content to SharePoint, OneDrive, and Teams.
Research and investigate with Microsoft Purview Audit
- Identify the differences between Microsoft Purview Audit (Standard) and Audit (Premium).
- Configure Microsoft Purview Audit to optimize log management.
- Conduct audits to assess compliance and security measures.
- Analyze irregular access patterns using advanced tools in Purview Audit (Premium) and PowerShell.
- Verify regulatory compliance through strategic data management.
Search for content with Microsoft Purview eDiscovery
- Assign roles and permissions to access Microsoft Purview eDiscovery
- Create and manage cases that are used to run eDiscovery searches
- Define search scope and generate queries using Copilot-generated conditions, keywords, and prompts
- Perform research and validate results using statistics or random examples
Updated on 03/04/2026
In this training, we mix theory with technical workshops to quickly make you operational. Additionally, each participant receives course materials at the end of the training.
One of our consultant trainers conducts the training. With solid field experience, they make the learning process both interactive and enriching.
For assessment, the trainer regularly asks questions and uses various methods to continuously measure your progress. This approach promotes a dynamic and engaging learning experience.
After the training, we ask you to complete a satisfaction questionnaire. Your feedback helps us to maintain and constantly improve the quality of our training.
Finally, we offer the flexibility to deliver this training both in-person and remotely, and it can be customized to meet your company’s specific needs upon request.
This training prepares you for the Microsoft certification exam “SC-401: Microsoft Information Protection Administrator.” We recommend scheduling your exam approximately one month after completing the training. The course materials and labs provided during the training will help you review effectively for your certification.
You can register for certification on the Microsoft site. If you would like to buy a certification voucher from us, or if you would like us to support you in this process, please contact us
You can register for one of our training courses up to two business days before it starts, if there are still available places and you signed quote.
If you have specific needs related to a disability, please do not hesitate to make a request; we are happy to adjust our services according to the type of disability.