
An independent study guide for Microsoft Certified: Information Security Administrator Associate · by Tony Rough
Know which Purview label, policy or setting protects the data, and why.
Due on Amazon in December 2026, in Kindle and paperback editions.
This independent study guide for the Microsoft Certified: Information Security Administrator Associate exam distils what SC-401 really expects you to understand into the comparisons, configuration choices and traps that Microsoft Purview decisions turn on, with short Security & Compliance PowerShell and Exchange Online PowerShell examples throughout.
Fourteen chapters, each readable on its own and together covering all three SC-401 skill areas:
Microsoft Purview changes quickly. This edition reflects Microsoft's documentation as of October 2026 and the skills measured from 28 October 2026, including the Microsoft Purview portal, the new eDiscovery experience, label groups, Data Security Posture Management, Microsoft Purview Suite licensing and the retirement of Defender for Cloud Apps file policies.
This book contains no exam questions. It explains the knowledge the exam expects, so you can answer questions you have never seen and apply the same judgement to a real tenant.
Written by Tony Rough, a cloud architect with more than twenty years in IT infrastructure who holds the Azure Solutions Architect Expert, Azure Administrator and Azure Security Engineer certifications.
Part of the Ultra Transcenders series from Distilled Press. An independent publication, not affiliated with, sponsored by or endorsed by Microsoft Corporation.
Every skill area in Microsoft's SC-401 outline (as of October 28, 2026), and the chapters that cover it.
| Skill area | Weight | Chapters |
|---|---|---|
| Implement information protection | 30–35% | 2, 3, 4, 5, 6 |
| Implement data loss prevention and retention | 30–35% | 7, 8, 9, 10 |
| Manage risks, alerts, and activities | 30–35% | 4, 11, 12, 13, 14 |
Plus an appendix glossary of 300+ terms, each linked to Microsoft Learn, with the same terms explained free online for print readers.



Some sections of the book, free to read online:
How EDM SITs match your own records: schema, primary and supporting elements, new and classic experiences, and hashing and uploading data.
How to design sensitivity labels: the four label scopes, label priority and order, sublabels and label groups, and label limits.
How to roll out a DLP policy safely with simulation mode and policy tips, and the four policy states with their PowerShell Mode values.
Which Windows, Windows Server and macOS devices Endpoint DLP supports, the prerequisites, and how to onboard devices to Microsoft Purview.
Which setting wins when several retention policies and labels apply to one item, with worked examples, and how to use Policy lookup.
Which Insider Risk Management policy template fits each scenario, with its triggering event, prerequisites and user limit.
What Audit (Premium) adds over Audit (Standard): default retention periods, 10-year retention, intelligent insights and the licences each needs.
How to build Microsoft Purview eDiscovery searches with the condition builder and KeyQL, with example queries and the search limits to know.