
Join the SC-401 information security administrator associate course for hands-on demonstrations, browser-based simulations, and data loss prevention exercises aligned with official Microsoft exam objectives.
Build a solid foundation by exploring on-premise Active Directory and domain services, RAR, DMZ, virtualization, and Microsoft cloud offerings like 365 and azure, including IaaS, PaaS, and SaaS, with visuals.
Trace the evolution from mainframes to Active Directory domains, including domain controllers, replication, Kerberos, NTLM, LDAP, and DNS. Learn how GPOs centralize policy and the move toward cloud-oriented environments.
Trace the evolution from on-premise Active Directory Domain Services, LDAP, and Kerberos to Raas and VPN for remote access. Examine DMZ and perimeter networks, and virtualization with Hyper-V and VMware.
Explore cloud service models from IaaS to SaaS, and see how Azure and intro ID power Microsoft 365 apps, Intune, and the bridge between on premise domains and cloud services.
Discover how Microsoft renames key portals and services, such as Azure Active Directory to IntraID, and navigate updated links like admin.microsoft.com, defender.microsoft.com, purview.microsoft.com, and Intune.microsoft.com using the portals.examlabpractice.com resource.
Set up a lab with Microsoft 365 and Azure basics. Learn to obtain a free Office 365 trial, activate a Microsoft 365 E5 subscription, and explore a 30-day Teams trial.
Learn to create a free Microsoft 365 trial, verify by phone, assign an E5 license, and cancel after 30 days.
Explore course assignments and hands-on simulations, including creating a DLP policy for PII in Exchange, and learn that the certificate requires watching all videos, not completing assignments.
John Christopher invites questions for the SC-401 information security administrator course, demonstrates using docs.microsoft.com to find official answers, and explains updates, assignments, and Udemy exam guidance.
Explore why the course presents objectives in a logical learning order, balancing foundational and advanced concepts, and occasionally renaming or combining objectives for clarity.
Watch all videos to earn a certificate of completion. Assignments don't count toward certification, and a final video explains how to obtain your certificate.
Navigate the new Purview portal from admin.microsoft.com, compare it with the classic portal, and explore information protection, data lifecycle management, and data loss prevention.
Identify sensitive information types, including PII, financial data, PHI, IP, and confidential business data. Apply data sensitivity labels, governance, DLP, and encryption, with regulatory compliance like GDPR, HIPAA, and FISMA.
Translate sensitive information requirements into built-in or custom sensitive information types in Microsoft Purview, using manual, automated, or machine learning classification, built-in named entity types, and exact-match patterns.
Create and manage custom sensitive info types in Microsoft Purview by defining patterns (regex, keywords, dictionaries), primary elements such as credit card numbers, and supporting elements, then test.
Learn how document fingerprinting in Microsoft 365 creates a sensitive info type from document templates, enabling data loss prevention policies across Exchange, SharePoint, OneDrive, and Teams.
Create exact data match (edm) classifiers in purview by uploading a sample csv, selecting primary elements like credit card numbers, and configuring high-confidence detection rules.
Learn how trainable classifiers in Microsoft 365 classify and protect documents with retention, sensitivity, and communication compliance policies; seed with 50–500 samples and navigate licensing and admin roles.
Explore trainable classifiers in Microsoft Purview, using built-in or custom models to detect, classify, protect, or retain content across SharePoint sites, with 50–500 English documents and supported file types.
Explore how to monitor sensitive data with Data Explorer and Activity Explorer in Microsoft 365 compliance, labeling and ingesting data with connectors to reveal classified information and user activities.
activate OCR in microsoft purview to scan pdfs and images for sensitive information across exchange, sharepoint, onedrive, chats, and devices, with pay-as-you-go pricing managed by global admins.
Explore roles and permissions to administer sensitivity labels within Microsoft Purview and Microsoft 365, including information protection admins, analysts, investigators, and readers, and learn access for label policies and DLP.
Define sensitivity labels in Microsoft Purview to classify emails and documents with manual or automated labeling, metadata, watermarks, and encryption for data loss prevention across apps.
Learn how to define and manage sensitivity labels in Microsoft Purview by creating a label, setting protection and access control, and assigning scope, permissions, and priority for labeled items.
Configure protection settings and content marking for sensitivity labels in Microsoft Purview, applying access controls, watermarking, and optional double key encryption across emails, groups, and sites.
Publish and manage sensitivity label policies in Purview to deploy top secret labels across Word, Excel, PowerPoint, Outlook, SharePoint, Teams, and groups; configure admin units, default labels, and enforcement settings.
Configure auto labeling policies for sensitivity labels across Exchange, SharePoint, and OneDrive, including SSN detection and encryption. Requires E5 or eligible licenses and may take 24–48 hours to take effect.
Apply sensitivity labels to data assets and containers across emails, meetings, groups, sites, SharePoint, and Teams, with configurable privacy controls and auto labeling to enforce protection.
Apply sensitivity labels in Microsoft Word by signing into your Microsoft 365 account, selecting a label on the home tab, and viewing labels in both desktop and web Word.
Explore defender for cloud apps, a cloud access security broker that monitors user activity, prevents shadow IT, and enforces compliance across cloud and on-prem apps with discovery, connectors, and remediation.
Learn to automatically apply sensitivity labels with Microsoft Defender for Cloud Apps by creating a file policy that marks external sharing of top secret data and enforces SharePoint labeling.
Plan and deploy the Microsoft Purview Information Protection client to classify, label, encrypt, and protect sensitive data across Windows clients and servers, including on-premises scanning and File Explorer integration.
Install the Microsoft Purview Information Protection client on a machine or Azure virtual machine and verify installation. Download the exe, run the installer, and confirm it appears in control panel.
Learn to apply Microsoft Purview sensitivity labels to a file with the information protection client on Windows 11, including signing in, verifying identity, and selecting the top secret label.
Configure and run the Microsoft Purview Information Protection scanner on Windows servers to discover on-premises files, apply label and DLP policies, and log audits to the cloud.
Delete the vm's resource group in portal.azure.com using force delete to conserve azure credits, then move on once the group named 'VM Test Testing' is gone.
Analyze design options for securing Microsoft 365 email with Exchange, highlighting Microsoft Purview Message Encryption as the latest solution. Compare licensing needs and methods like Information Rights Management and S/MIME.
Learn to enable and enforce Microsoft Purview message encryption via the Exchange Admin Center by creating mail flow rules to encrypt all messages or scoped recipients, and verify with PowerShell.
Explore how to implement Microsoft Purview Advanced Message Encryption, understand license requirements, apply sensitivity labels for compliance, configure encryption rules in Exchange Admin Center, and set custom branding via PowerShell.
Design data loss prevention policies that monitor sensitive data across emails, SharePoint, OneDrive, Teams, and endpoints, covering regulatory use cases, policy tips, and controls to prevent data leakage.
Explore data loss prevention roles and permissions in Microsoft Purview, including built-in roles like compliance administrator and information protection admin, how to assign roles, and create custom roles.
Create and manage data loss prevention policies in Microsoft Purview using a financial data template to detect US financial information. Configure locations, policy tips, and simulation before activation.
Configure adaptive protection with data loss prevention policies in Microsoft Purview to auto adjust enforcement by user risk levels, guided by insider risk management and continuous monitoring.
Explore how data loss prevention policies and internal rule precedence work: lower numbers mean higher policy priority, with the most restrictive rule applying when conflicts arise.
Create a DLP policy in Microsoft Defender for Cloud Apps to monitor SharePoint documents exposed publicly and alert the owner when top secret data is detected.
Define endpoint data loss prevention requirements for on-premises Windows and Mac devices, including extensions and exclusions, to monitor and govern cloud egress, browser restrictions, and policy tips for overrides.
Configure endpoint DLP settings in Purview to apply classifications and access controls. Explore file path exclusions, advanced classification, network share groups, restricted apps, and VPN settings.
Configure advanced DLP rules for devices within your Microsoft Purview data loss prevention policies by creating low and high content rules with conditions, actions, and exceptions.
Enable just-in-time protection to dynamically evaluate files during share, copy, or move actions and enforce DLP in real time, with configurable fallback, copy restrictions, and exclusions.
Monitor endpoint activities using the Activity Explorer in Microsoft compliance to view device events, client IP addresses, locations, and users, with filters by date, sensitivity, and data loss prevention.
Explore how retention and disposition strategies use labels and policies to manage, preserve, or delete content across SharePoint, OneDrive, Exchange, and Teams in compliance.
Understand how retention policies apply broadly to locations automatically, how retention labels apply to individual items with optional user interaction, and how retention label policies publish these labels to users.
Use adaptive scopes to apply retention policies dynamically based on attributes like department or job title, ensuring the data lifecycle updates as staff move between roles.
Learn to create a seven-year retention label in Microsoft Purview, choose retention settings, define when a period starts, and configure post-retention actions such as automatic deletion and disposition reviews.
Publish a seven-year retention label in Microsoft Purview, choose adaptive or static scope, apply to Exchange mailboxes and OneDrive, and expect activation within about 24 hours.
Configure an auto apply seven year retention label for financial data in purview, using sensitive info or keywords, with adaptive scope to Exchange and OneDrive, activation takes seven days.
Interpret policy precedence by applying retention over deletion, explicit over implicit, and recognizing that the longest retention wins when conflicts remain.
Learn how to create and configure a static five-year retention policy in Microsoft Purview, selecting Exchange mailboxes, SharePoint and OneDrive, and decide whether to delete or retain items.
Learn to recover retained content in Microsoft 365 across Exchange, SharePoint, OneDrive, and Teams using retention policies, recovery items, recycle bins, and Purview content search.
Explore insider risk management roles and their permissions, including admins, analytics, investigators, auditors, and approvers, and learn how to assign roles in Purview.
Plan for insider risk management in Microsoft 365 helps you detect, investigate, and take action on insider threats using Purview policies, alerts, case workflows, and eDiscovery.
Configure insider risk management with third-party data connectors in Microsoft Purview, learn which connectors support insider risk, eDiscovery, and retention, and use the connector wizard to add them.
Enable insider risk management data sharing with Defender for Endpoint and other security solutions via Purview, then configure policy indicators and pay-as-you-go billing for integrated DLP alerts.
Configure insider risk management settings in Microsoft Purview, enabling analytics, data sharing, and intelligent detections. Tailor domains, exclusions, indicators, Power Automate, and team settings to optimize alerts and privacy.
Explore policy indicators in Microsoft Purview insider risk management to trigger events and activate indicators. Learn built-in and custom indicators and how risk scores rise with unusual activity.
Explore Microsoft insider risk policy templates for data theft, data leaks, and risky user behavior. Learn integration points like HR connector, DLP, Defender for Endpoint, and Purview.
Learn to create insider risk management policies in Microsoft Purview, using custom templates like data leaks, configure connectors, set user scopes, and tailor triggers, thresholds, and alerts.
Enable forensic evidence in insider risk management with Microsoft Purview to capture video clips of user activity, configure retention, capacity, and device resource policies.
Enable insider risk levels in Microsoft Purview Insider Risk Management with adaptive protection. Configure risk thresholds for elevated, moderate, and low alerts, plus history, timeframes, and expiration rules.
Explore insider risk management by using alerts to flag incidents and generating a case from an alert to drive investigations, with collaboration among admins in the compliance portal.
Learn how insider risk management uses notice templates to automatically email users when a case is created, outlining violations of the employee code of conduct.
Assign premium Purview audit licenses via Microsoft 365 E5 or E5 compliance, or the eDiscovery and Audit add-on, to enable extended retention, policies, and intelligent insights.
Learn how to audit in Microsoft Purview by navigating through admin portal, applying date and activity filters, viewing event details and JSON data, and exporting results.
Use Activity Explorer in Purview to monitor and analyze events by date, location, user, and sensitivity label, export results to a spreadsheet, with Copilot assistance.
Open the admin portal and access Microsoft Purview data loss prevention alerts to review incidents from DLP policies, then filter by user, status, and severity.
Inspect insider risk activity in Microsoft Purview by using the audit log to review policy changes, user actions, and timestamps, with category and date filters and export options.
Navigate to admin.microsoft.com, open security, and access Microsoft Defender XDR to view alerts generated by Microsoft Purview. Use the incidents and alerts blade to review and respond to these alerts.
Learn to find alert matches in defender for cloud apps, view all matches, and filter by apps, owner, access level, and file type; receive alert emails for continuous visibility.
Search Microsoft Purview content search to conduct eDiscovery investigations, create cases, and apply holds, then run queries across data sources to locate sensitive information.
Implement Microsoft Purview controls to protect content in AI environments by classifying data, applying retention labels, enforcing DLP policies, managing access, monitoring with audit logs, and integrating with Azure models.
Implement controls in Microsoft 365 AI workloads using data protection, data security posture management, insider risk management, and Defender for cloud apps to monitor and block risky AI apps.
Deploy a Windows 11 enterprise VM in Azure via portal.azure.com, configure the resource group and admin, enable RDP, and connect with the downloaded RDP file for the lab.
Master prerequisites for data security posture management for ai in microsoft purview, including analytics, device onboarding, the purview browser extension, and key roles for data discovery and risk assessments.
Configure and customize DSP for AI policies in Microsoft Purview by viewing, editing, and applying DLP and insider risk management policies for generative AI data.
Delete the Windows 11 virtual machine in Azure by removing its resource group in portal.azure.com using force deletion, completing within minutes.
Monitor DSPM for AI activities with Microsoft Purview using Activity Explorer, policy investigations, and DLP alerts, and review AI app interactions and insider risk reports.
We really hope you'll agree, this training is way more then the average course on Udemy!
Have access to the following:
Training from an instructor of over 20 years who has trained thousands of people and also a Microsoft Certified Trainer
Lecture that explains the concepts in an easy to learn method for someone that is just starting out with this material
Instructor led hands on and simulations to practice that can be followed even if you have little to no experience
TOPICS COVERED INCLUDING HANDS ON LECTURE AND PRACTICE TUTORIALS:
Introduction
Welcome to the course
Understanding the Microsoft Environment
A Solid Foundation of Active Directory Domains
A Solid Foundation of RAS, DMZ, and Virtualization
A Solid Foundation of the Microsoft Cloud Services
Creating a free Microsoft 365 Azure AD Account
Managing Microsoft 365 Services with PowerShell
Connecting to Security and Compliance using PowerShell
IMPORTANT Using Assignments in the course
Implement and manage data classification
Identify sensitive information requirements for an organization's data
Translate sensitive information requirements into built-in or custom
Create and manage custom sensitive info types
Implement document fingerprinting
Create and manage exact data match (EDM) classifiers
What are trainable classifiers?
Create and manage trainable classifiers
Monitor data classification & label by using data explorer & content explorer
Configure optical character recognition (OCR) support for sensitive info types
Implement and manage sensitivity labels in Microsoft Purview
Implement roles and permissions for administering sensitivity labels
Define the concepts of sensitivity labels in Microsoft Purview
Define and create sensitivity labels for items and containers
Configure protection settings and content marking for sensitivity labels
Configure and manage publishing policies for sensitivity labels
Configure and manage auto-labeling policies for sensitivity labels
Apply a sensitivity label to containers, such as Teams, SharePoint etc
Apply sensitivity labels manually using Microsoft Word
Understanding Microsoft Defender for Cloud Apps
Apply sensitivity labels by using Microsoft Defender for Cloud Apps
Implement information protection for Windows, file shares, and Exchange
Plan the Microsoft Purview Information Protection client
Implement the Microsoft Purview Information Protection client
Manage files by using the Microsoft Purview Information Protection client
Apply bulk classifications with Microsoft Purview Information Protection scanner
Removing the Azure virtual machine that is no longer needed
Design solutions for email Encryption in Microsoft 365
Implement Microsoft Purview Message Encryption
Implement Microsoft Purview Advanced Message Encryption
Create and configure data loss prevention policies
Design data loss prevention policies based on an organization’s requirements
Implement roles and permissions for data loss prevention
Create and manage data loss prevention policies
Configure data loss prevention policies for Adaptive Protection
Interpret policy and rule precedence in data loss prevention
Create file policies in Microsoft Defender for Cloud Apps by using a DLP policy
Implement and monitor Microsoft Purview Endpoint DLP
Specify device requirements for Endpoint DLP, including extensions
Configure Endpoint DLP settings
Configure advanced DLP rules for devices in DLP policies
Configure just-in-time protection
Monitor endpoint activities
Implement and manage retention
Plan for information retention and disposition by using retention labels
Concepts of Retention Policies vs Retention Labels vs Retention Label Policies
Create, configure, and manage adaptive scopes
Create retention labels for data lifecycle management
Configure a retention label policy to publish labels
Configure a retention label policy to auto-apply labels
Interpret the results of policy precedence, including using Policy lookup
Create and configure retention policies
Recover retained content in Microsoft 365
Implement and manage Microsoft Purview Insider Risk Management
Implement roles and permissions for Insider Risk Management
Plan for Insider Risk Management in Microsoft 365
Plan and implement Insider Risk Management connectors
Plan integration with Microsoft Defender for Endpoint
Configure and manage Insider Risk Management settings
Configure policy indicators
Select an appropriate policy template
Create and manage Insider Risk Management policies
Manage forensic evidence settings
Enable and configure insider risk levels for Adaptive Protection
Manage insider risk alerts and cases
Manage Insider Risk Management workflow, including notice templates
Manage information security alerts and activities
Assign Microsoft Purview Audit (Premium) user licenses
Investigate activities by using Microsoft Purview Audit
Configure audit retention policies
Analyze Purview activities by using activity explorer
Respond to data loss prevention alerts in the Microsoft Purview portal
Investigate insider risk activities by using the Microsoft Purview portal
Respond to Purview alerts in Microsoft Defender XDR
Respond to Defender for Cloud Apps file policy alerts
Perform searches by using Content search
Protect data used by AI services
Implement controls in Microsoft Purview in an environment that uses AI services
Implement controls in MS 365 productivity workloads in environments that use AI
Deploying a Windows 11 virtual machine for the lab
Implement pre-requisites for DSPM for AI along with roles and permissions
Configure DSPM for AI policies
Delete the Windows 11 virtual machine stored in Azure
Monitor activities in DSPM for AI