SC-400 Retired: Historical Blueprint and Next Steps

SC-400

Retired exam

SC-400 was retired on May 30, 2025

Microsoft retired SC-400; the exam URL redirects to the Information Protection and Compliance Administrator Associate certification page, which prints 'Retirement Date 05/30/2025' and 'This certification and the renewal assessment are retired.' No successor is named.

No direct replacement is named in the reviewed official sources.

Historical SC-400 Scope

Administering Information Protection and Compliance in Microsoft 365 was a professional Microsoft certification exam. It covered areas including content classification, data loss prevention, and organizational risk management. This exam officially retired, and Microsoft has not named a successor for this specific certification. Candidates should consult the official Microsoft Learn portal for credential paths and requirements regarding information protection and compliance roles in the enterprise environment.

Who SC-400 Was For

This exam targeted information protection and compliance administrators. Candidates required experience with Microsoft 365 services, including Exchange Online, SharePoint, OneDrive, and Teams, alongside familiarity with PowerShell to translate organizational risk requirements into technical implementations for their respective business environments.

Skills You Should Be Ready to Demonstrate

How to Reuse Your Preparation

Since this exam is retired and has no successor, you should not prepare to sit for it. If you are seeking current certifications, review the latest Microsoft Learn documentation to identify active exams that align with your professional goals. Focus on mastering Microsoft Purview compliance tools and data governance principles, as these remain relevant to the information protection and compliance administrator role in the cloud-based security landscape.

Historical Domain Guide

Implement information protection: Historical Scope

This domain covers the technical application of data classification and protection controls within the Microsoft 365 environment, focusing on the creation of sensitive info types, sensitivity labels, and the design of encryption for email messages.

Implement DLP: Historical Scope

This domain focuses on the configuration and monitoring of policies to prevent unauthorized data sharing and loss, specifically requiring candidates to demonstrate proficiency in creating DLP policies and managing Endpoint DLP within the organization.

Implement data lifecycle and records management: Historical Scope

This domain addresses the retention, deletion, and lifecycle management of organizational data using labels and policies, ensuring that administrators can effectively manage data deletion and retention requirements through the use of retention labels.

Monitor and investigate data and activities by using Microsoft Purview: Historical Scope

This domain involves using Microsoft Purview to manage regulatory compliance, eDiscovery, and audit logging, requiring skills in managing Compliance Manager, planning eDiscovery and Content search, and analyzing audit logs and reports within the platform.

Manage insider and privacy risk in Microsoft 365: Historical Scope

This domain covers the implementation of tools to identify and mitigate internal risks and privacy concerns, focusing on the management of Communication Compliance, Insider Risk Management, and the implementation of Information Barriers within Microsoft 365.

Frequently asked questions

How many questions were on the exam?

The exam consisted of 40 questions in total. These questions were designed to test the candidate's knowledge across various domains of information protection and compliance within the Microsoft 365 ecosystem.

What was the passing score?

A passing score of 700 was required to successfully pass the exam. This score was calculated on a scale of 1-1000, reflecting the depth of knowledge required for the certification.

How long was the exam?

The exam had a total duration of 100 minutes. Candidates were expected to manage their time effectively across the various question types and case studies presented during the testing session.

What was the cost of the exam?

The exam price was set at 165 dollars. This fee covered the registration for the certification exam at authorized testing centers or through online proctored delivery methods before the retirement date.

Sources and Verification

Verified 2026-08-30

How this page was made

This editorial was constructed by synthesizing official Microsoft exam documentation, including study guides and skill measurement tables, to provide a factual summary of the retired SC-400 exam for reference purposes.

Historical SC-400 Domains

Implement information protection Implement information protection 25%
  • Create and manage sensitive info typesCreate and manage sensitive info types
    Identify sensitive information requirements for an organization's data; Translate sensitive information requirements into built-in or custom sensitive info types; Create and manage custom sensitive info types; Create and manage exact data match (EDM) classifiers; Implement document fingerprinting; Create and manage trainable classifiers; Identify when to use trainable classifiers; Design and create a trainable classifier; Test a trainable classifier; Retrain a trainable classifier
  • Implement and manage sensitivity labelsImplement and manage sensitivity labels
    Implement roles and permissions for administering sensitivity labels; Define and create sensitivity labels; Configure and manage sensitivity label policies; Configure auto-labeling policies for sensitivity labels; Monitor data classification and label usage by using Content explorer, Activity explorer, and audit search; Apply bulk classification to on-premises data by using the Microsoft Purview Information Protection scanner; Manage protection settings and marking for applied sensitivity labels
  • Design and implement encryption for email messagesDesign and implement encryption for email messages
    Design an email encryption solution based on methods available in Microsoft 365; Implement Microsoft Purview Message Encryption; Implement Microsoft Purview Advanced Message Encryption
Implement DLP Implement DLP 15%
  • Create and configure DLP policiesCreate and configure DLP policies
    Design DLP policies based on an organization’s requirements; Configure permissions for DLP; Create and manage DLP policies; Interpret policy and rule precedence in DLP; Configure a Microsoft Defender for Cloud Apps file policy to use DLP policies
  • Implement and monitor Endpoint DLPImplement and monitor Endpoint DLP
    Configure advanced DLP rules for devices in DLP policies; Configure Endpoint DLP settings; Recommend a deployment method for device onboarding; Identify endpoint requirements for device onboarding; Monitor endpoint activities; Implement the Microsoft Purview Extension; Monitor and manage DLP activities; Analyze DLP reports; Analyze DLP activities by using Activity explorer; Remediate DLP alerts in the Microsoft Purview compliance portal; Remediate DLP alerts generated by Defender for Cloud Apps
Implement data lifecycle and records management Implement data lifecycle and records management 10%
  • Retain and delete data by using retention labelsRetain and delete data by using retention labels
    Plan for information retention and disposition by using retention labels; Create retention labels for data lifecycle management; Configure and manage adaptive scopes; Configure a retention label policy to publish labels; Configure a retention label policy to auto-apply labels; Interpret the results of policy precedence, including using Policy lookup; Manage data retention in Microsoft 365 workloads; Create and apply retention policies for SharePoint and OneDrive; Create and apply retention policies for Microsoft 365 groups; Create and apply retention policies for Teams; Create and apply retention policies for Yammer; Create and apply retention policies for Exchange Online; Apply mailbox holds in Exchange Online; Implement Exchange Online archiving policies; Configure preservation locks for retention policies and retention label policies; Recover retained content in Microsoft 365; Implement Microsoft Purview records management; Create and configure retention labels for records management; Manage retention labels by using a file plan, including file plan descriptors; Classify records by using retention labels and retention label policies; Manage event-based retention; Manage the disposition of content in records management; Configure records management settings, including retention label settings and disposition settings
Monitor and investigate data and activities by using Microsoft Purview Monitor and investigate data and activities by using Microsoft Purview 15%
  • Plan and manage regulatory requirements by using Microsoft Purview Compliance ManagerPlan and manage regulatory requirements by using Microsoft Purview Compliance Manager
    Plan for regulatory compliance in Microsoft 365; Create and manage assessments; Create and modify custom templates; Interpret and manage improvement actions; Create and manage alert policies for assessments
  • Plan and manage eDiscovery and Content searchPlan and manage eDiscovery and Content search
    Choose between eDiscovery (Standard) and eDiscovery (Premium) based on an organization’s requirements; Plan and implement eDiscovery; Delegate permissions to use eDiscovery and Content search; Perform searches and respond to results from eDiscovery; Manage eDiscovery cases; Perform searches by using Content search
  • Manage and analyze audit logs and reports in Microsoft PurviewManage and analyze audit logs and reports in Microsoft Purview
    Choose between Audit (Standard) and Audit (Premium) based on an organization’s requirements; Plan for and configure auditing; Investigate activities by using the unified audit log; Review and interpret compliance reports and dashboards; Configure alert policies; Configure audit retention policies
Manage insider and privacy risk in Microsoft 365 Manage insider and privacy risk in Microsoft 365 15%
  • Implement and manage Microsoft Purview Communication ComplianceImplement and manage Microsoft Purview Communication Compliance
    Plan for communication compliance; Create and manage communication compliance policies; Investigate and remediate communication compliance alerts and reports
  • Implement and manage Microsoft Purview Insider Risk ManagementImplement and manage Microsoft Purview Insider Risk Management
    Plan for insider risk management; Create and manage insider risk management policies; Investigate and remediate insider risk activities, alerts, and reports; Manage insider risk cases; Manage forensic evidence settings; Manage notice templates
  • Implement and manage Microsoft Purview Information Barriers (IBs)Implement and manage Microsoft Purview Information Barriers (IBs)
    Plan for IBs; Create and manage IB segments and policies; Configure Teams, SharePoint, and OneDrive to enforce IBs, including setting barrier modes; Investigate issues with IB policies
  • Implement and manage privacy requirements by using Microsoft PrivaImplement and manage privacy requirements by using Microsoft Priva
    Configure and maintain privacy risk management; Create and manage Privacy Risk Management policies; Identify and monitor potential risks involving personal data; Evaluate and remediate alerts and issues; Implement and manage subject rights requests