Microsoft has retired AZ-500. The Azure Security Engineer Associate exam's last day was August 31, 2026. Its replacement is SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, which leads to a new credential, Microsoft Certified: Cloud and AI Security Engineer Associate.
Microsoft's Partner Center announcements for August 2026 put it plainly: "Azure Security Engineer Associate (AZ-500) retired on August 31, 2026. It was replaced by Cloud and AI Security Engineer Associate (SC-500), available as of July 21, 2026."
If you were halfway through AZ-500 prep, most of what you learned still applies. The new part is large, though: a whole skill area on securing AI, and a lot of it lives in Microsoft 365 and Purview rather than the Azure portal.
Everything below comes from the official SC-500 study guide and the certification page, checked on September 16, 2026.
The exam at a glance
- 120 minutes
- Passing score: 700 (scaled)
- US$165 in the United States (prices vary by country)
- English only. If English isn't your preferred language, you can request an additional 30 minutes.
- No official practice assessment yet
- Question count: not published. Microsoft doesn't give one, so be wary of any guide that quotes an exact number.
- Like other associate certifications, it renews every year with a free online assessment on Microsoft Learn.
Already hold AZ-500? Microsoft says earned certifications stay valid until they expire. Retirement doesn't revoke them, but a retired certification can no longer be renewed.
Microsoft expects practical experience administering Azure and hybrid environments, strong familiarity with Microsoft Entra ID, and familiarity with Microsoft 365 administration. The last part is new, and it matters.
One practical note: the old-style exam URL, /credentials/certifications/exams/sc-500/, returns a 404. Use the certification page to register.
How the domains changed
AZ-500 (skills as of January 22, 2026):
- Secure identity and access (15-20%)
- Secure networking (20-25%)
- Secure compute, storage, and databases (20-25%)
- Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel (30-35%)
SC-500:
- Manage identity, access, and governance (20-25%)
- Secure storage, databases, and networking (25-30%)
- Secure compute (20-25%)
- Manage and monitor security posture (20-25%)
The areas got reshuffled. Key Vault and Azure Policy moved in with identity, into a governance-heavy first domain. Storage and databases moved in with networking, which is now the heaviest domain. Compute stands alone, and it now includes "Implement security for AI." Defender for Cloud and Sentinel, now joined by Security Copilot, went from the biggest domain (30-35%) to one of three at 20-25%.
What's new
Securing AI
This is the headline change. The study guide lists these skills under Secure compute:
- Identify overexposure of data in SharePoint
- Identify risks related to Microsoft Copilot and AI apps by using Microsoft Purview Data Security Posture Management (DSPM)
- Enable and configure real-time protection for Microsoft Copilot Studio agents
- Implement Conditional Access for Microsoft Entra Agent ID, analyze its blast radius with Defender XDR, and manage Agent ID access
- Configure and deploy AI Gateway in Azure API Management for Microsoft Foundry
- Enable Defender for AI Services in Defender for Cloud
- Configure guardrails for agent security in Foundry
- Monitor AI security with the Data and AI security dashboard in Defender for Cloud
- Manage agents in the Microsoft 365 admin center
Notice how many of these aren't Azure resources. SharePoint, Purview, Copilot Studio and the Microsoft 365 admin center are all in scope. If you've only ever secured Azure subscriptions, budget real time for them.
Also new or expanded
- Passwordless authentication alongside MFA
- Defender CSPM secrets scanning, listed under Key Vault
- Security controls through infrastructure as code
- Microsoft Entra Private Access
- Azure Arc for hybrid and multicloud servers, and Azure Machine Configuration
- VM security features: secure boot, vTPM, integrity monitoring and security type
- Security controls for Azure Logic Apps, and authentication as well as network access for Azure Functions
- More Microsoft Sentinel data collection: content hub, syslog and CEF, Windows Security events with data collection rules and Windows Event Forwarding, custom log tables, retention, and querying Purview Audit in Defender XDR
- Microsoft Security Copilot: workspaces, roles, plugins, and Microsoft and Security Store agents
What was removed
Compared with the AZ-500 guide, these no longer appear as SC-500 skills:
- User-defined routes, and planning virtual network peering or VPN gateways
- Encryption over ExpressRoute
- Application Gateway and Front Door as their own topics (the Web Application Firewall is still in)
- DDoS Protection
- Bring your own key and double encryption for storage
- Transparent data encryption, Always Encrypted and dynamic data masking
- Defender for Cloud DevOps security
- Enabling Sentinel analytics rules
- Key Vault backup and recovery
Microsoft notes that listed skills illustrate what's assessed and that related topics may still come up, so don't treat the list as a guarantee. But it does tell you where to spend your hours.
How I'd study
If you studied for AZ-500, you already know PIM, Conditional Access, Key Vault, NSGs, private endpoints, Azure Firewall and Defender for Cloud. Review them against the new guide, then spend most of your time on:
- The AI security skills. Build a small Foundry agent, put API Management in front of it, turn on Defender for AI Services and configure guardrails. Then walk through Purview DSPM and SharePoint oversharing reports in a Microsoft 365 test tenant.
- Microsoft Entra Agent ID. Learn how Conditional Access targets agent identities and how agent access is managed.
- Arc and Machine Configuration. Onboard a non-Azure server and assign a baseline.
- Sentinel data collection. Build data collection rules by hand, including one for a custom table.
- Security Copilot roles and plugin settings.
If you're starting fresh, plan for eight to ten weeks and work through the four domains in order. Our SC-500 overview has a week-by-week study plan and topic notes.
Some of the AI features are new or still in preview. The study guide says most questions cover generally available features, but commonly used preview features can appear, so check the current docs before exam day.
Practice
The SC-500 practice exam has original scenario questions written from the new study guide, with a split across all four domains that follows Microsoft's weights and an explanation for every wrong answer. It includes the AI security skills: Agent ID Conditional Access, Purview DSPM, Copilot Studio real-time protection, the API Management AI gateway, Defender for AI Services and Foundry guardrails.
If you're also looking at the security operations side, SC-200 covers Sentinel and Defender XDR from the analyst's seat. The retired AZ-500 guide is still on the site for reference, but it describes an exam you can no longer book.