The End of an Era for Microsoft Compliance Certifications
For years, the SC-400: Administering Information Protection and Compliance in Microsoft 365 exam was the go-to credential for professionals working across Microsoft Purview, data loss prevention, and compliance administration. That changed on May 31, 2025, when Microsoft officially retired both the exam and its associated certification, the Microsoft Certified: Information Protection and Compliance Administrator Associate.
This wasn’t a quiet sunset — it was a deliberate restructuring. Microsoft recognized that SC-400 had been trying to do two jobs at once: validating skills for information protection/data security professionals and for compliance professionals. Rather than continue bundling these into a single, sprawling exam, Microsoft split the role in two, giving each its own dedicated certification path.
Why Microsoft Made the Change
The core justification Microsoft gave was role clarity. As data security and compliance responsibilities grew more specialized within organizations, a single exam covering sensitivity labels, DLP, insider risk, retention policies, eDiscovery, and records management all at once no longer reflected how these jobs are actually structured in the field. Splitting the certification let Microsoft build a more focused, technically deep assessment for each specialization rather than a broad survey exam.
What Replaced SC-400
SC-401: Administering Information Security in Microsoft 365
This is the direct successor exam, launched in April 2025 and leading to the new Microsoft Certified: Information Security Administrator Associate credential. It’s worth being clear: SC-401 is not simply SC-400 renamed. It has a narrower scope focused specifically on information security and data security posture management (DSPM), and it introduces substantial new content that never appeared on SC-400 — most notably around DSPM for AI, reflecting the growing need to secure data used by AI services like Copilot.
SC-401 covers:
- Sensitivity labels, sensitive information types, and trainable classifiers
- Data Loss Prevention (DLP) policies, including Endpoint DLP
- Insider Risk Management configuration and investigation
- Data Security Posture Management, including for AI workloads
- Monitoring activities through Microsoft Purview and Microsoft Defender
Microsoft Purview Applied Skills Credentials
The compliance half of the old SC-400 — retention labels, records management, data lifecycle management, and eDiscovery — didn’t get folded into SC-401. Instead, Microsoft moved these into targeted Applied Skills credentials. These are narrower, scenario-based credentials rather than a single broad exam, letting professionals demonstrate specific compliance competencies (like retention or eDiscovery) without needing to pass one large test covering everything.
What This Means If You Already Hold SC-400
If you’re already SC-400 certified, there’s some reassurance here: your certification remains valid until its original expiration date and will still show up in your certification history. However, a few practical points matter:
- No renewal path exists anymore. Since the certification and its renewal assessment were retired together, you cannot renew SC-400 — even if your renewal window was approaching.
- Only renewals were ever free. If you want the new credential, you’ll need to register for and pay for SC-401 through Pearson VUE like any new exam — there’s no discounted or automatic transfer path from SC-400 to SC-401.
- Your knowledge still counts. Much of what you studied for SC-400 — sensitivity labels, DLP, classifiers — carries over directly into SC-401’s content. You’re not starting from zero, but you will need to study the new DSPM and AI-related material that wasn’t part of the old exam.
What This Means If You Were Planning to Take SC-400
You have two realistic options now:
- Move to SC-401 if your role centers on information/data security — this is the direct spiritual successor and the one most people transitioning from SC-400 will want.
- Look at Purview Applied Skills credentials if your work is primarily compliance-focused (retention, eDiscovery, records management) — these now live outside the SC-401 umbrella entirely.
The Bigger Picture
This split reflects a broader trend in Microsoft’s certification strategy: moving away from broad, do-everything exams toward more specialized, role-aligned credentials. As Microsoft Purview’s feature set has expanded — particularly with AI governance and DSPM for AI — a single exam covering the entire compliance and information protection surface area became increasingly impractical to test (and to study for) in one sitting.
For professionals, the practical takeaway is this: figure out which side of the old SC-400 role you actually work in day-to-day, and pursue the corresponding path — SC-401 for security-focused work, Applied Skills for compliance-focused work — rather than trying to replicate the old “do it all” credential.
