Microsoft SC-500
Microsoft SC-500 (Cloud and AI Security Engineer Associate) replaces the retired AZ-500 (Azure Security Engineer Associate, retired August 31, 2026). Four domains: manage identity, access, and governance; secure storage, databases, and networking; secure compute (now including an AI-security sub-domain covering Copilot, Microsoft Foundry agents, and Entra Agent ID); and manage and monitor security posture. Roughly 40-60 questions, 100 minutes, passing score 700 on a scaled 100-1000 scale.
Exam fee at last check: $165, per the vendor. The official objectives are at learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/sc-500. Verified 2026-09-26.
Free for a limited time. What I want from the site right now is to see what predicts passing, and that is worth more to me than a price.
- Manage Identity, Access, and Governance20-25%
- Secure Storage, Databases, and Networking25-30%
- Secure Compute20-25%
- Manage and Monitor Security Posture20-25%
Source: Vendor exam objectives. Checked 2026-09-26. Bar length is relative to the heaviest domain; the figure beside each name is the published weight.
What's on the exam
Manage Identity, Access, and Governance 20-25%
Entra ID identity security, Key Vault, and governance controls enforcing regulatory compliance.
- Privileged Identity Management (PIM) for just-in-time, approval-gated role activation
- Conditional Access for context-aware sign-in policy
- Managed identities for Azure resources (no embedded credentials)
- Access reviews to find and revoke stale, overprivileged role assignments
- Azure Policy with deny effects to block non-compliant deployments
- Azure Backup soft delete and multi-user authorization
Primary sources: Microsoft Entra ID Governance documentation
Secure Storage, Databases, and Networking 25-30%
The largest domain. Storage account and database security, plus the full range of Azure network security controls.
- Storage firewall rules + private endpoints to eliminate public network access
- Microsoft Defender for Databases threat detection
- Network Security Groups (NSGs) for subnet/NIC-level traffic filtering
- Azure Virtual Network Manager for centralized multi-VNet, multi-subscription policy
- Microsoft Entra Private Access for Zero Trust, identity-aware private application access
- Azure Firewall + Firewall Manager for hub-and-spoke traffic inspection
Primary sources: Azure Storage documentation, Azure Virtual Network documentation
Secure Compute 20-25%
VM, container, and application-platform security, plus an AI-security sub-domain with no AZ-500 equivalent.
- Just-in-time (JIT) VM access to lock down management ports by default
- Microsoft Defender for Servers via Azure Arc for hybrid/multicloud machines
- Microsoft Purview DSPM for AI: identifying data overexposure risk in Copilot-accessible content
- Microsoft Entra Agent ID for scoped AI agent identity + Defender XDR blast-radius analysis
- Microsoft Defender for Containers for AKS runtime threat detection
- Secure Boot, vTPM, and integrity monitoring for VM boot-chain attestation
Primary sources: Microsoft Defender for Cloud documentation, Microsoft Purview documentation, Microsoft Entra documentation
Manage and Monitor Security Posture 20-25%
Defender for Cloud posture scoring, multicloud connectors, Sentinel SIEM/SOAR, and AI-assisted investigation via Security Copilot.
- Secure Score via Defender CSPM
- Multicloud connectors (AWS, GCP) for unified posture management
- Sentinel data collection rules, including Windows Event Forwarding at scale
- Sentinel automation rules and playbooks for automated incident response
- Microsoft Security Copilot for natural-language incident investigation
- Microsoft Defender External Attack Surface Management (EASM) for unmanaged asset discovery
Primary sources: Microsoft Defender for Cloud documentation, Microsoft Sentinel documentation
Exam-day strategy
AZ-500 retired August 31, 2026; make sure any other study material you use targets SC-500's actual current blueprint, not legacy AZ-500 content.
The AI-security sub-domain under Secure Compute is new and has no AZ-500 equivalent: know Purview DSPM for AI, Entra Agent ID, and Security Copilot specifically.
Watch for distractors naming a real but wrong Azure service for the exact same general category (e.g., Defender for Servers vs Defender for Containers vs Defender for Databases).
On network questions, identify the exact scope: subnet/NIC-level (NSG) vs multi-VNet centralized (Virtual Network Manager) vs perimeter/hub (Azure Firewall).
Pace at roughly 2 minutes per question across the ~100-minute, 40-60 question exam.
Additional resources
Explore Related Cybersecurity Resources
DecipherU is independent of Microsoft. SC-500 (Cloud and AI Security Engineer Associate) is a trademark of Microsoft. DecipherU is not endorsed by, sponsored by, or affiliated with any certifying body.