SC-500 Study Guide: Microsoft Cloud and AI Security Engineer Associate (2026)

Beehiiv art card-sc-500-study-guide

SC-500 is the exam for Microsoft Certified: Cloud and AI Security Engineer Associate, Microsoft’s security engineer certification for protecting identities, data, networks, compute and AI workloads across Azure, hybrid and AI-enabled environments. It replaced AZ-500 (Azure Security Engineer Associate), which Microsoft retired on August 31, 2026, and it costs $165 in the US for a 120-minute exam with a passing score of 700.

The big change from AZ-500 is AI: SC-500 adds a full group of tasks on securing AI, from Microsoft Purview Data Security Posture Management (DSPM) and Microsoft Entra Agent ID to guardrails in Microsoft Foundry. This guide covers the four skill areas and weights, exactly what the AI security tasks are, what AZ-500 holders should do, a 6-week study plan and the free official prep. One thing to know up front: Microsoft has no SC-500 Practice Assessment yet.

SC-500 at a glance

ExamSC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads
CertificationMicrosoft Certified: Cloud and AI Security Engineer Associate
LevelAssociate (Microsoft Learn lists it as Intermediate)
ReplacesAZ-500, Azure Security Engineer Associate (certification, exam and renewal assessment retired August 31, 2026)
Cost$165 in the US; the price depends on the country or region where you test, and tax is extra
Time120 minutes
QuestionsNot published (Microsoft says most of its exams have 40 to 60)
Passing score700 on a scaled score out of 1,000
PrerequisitesNone formal. Microsoft expects hands-on Azure and hybrid administration (compute, network, storage), strong Microsoft Entra ID skills and some Microsoft 365 administration
DeliveryProctored through Pearson VUE, online or at a test center; Microsoft Learn is available inside the exam
LanguagesEnglish, Chinese (Simplified), Chinese (Traditional), French, German, Italian, Japanese, Korean, Portuguese (Brazil), Spanish
StatusMicrosoft’s June 2026 roundup listed SC-500 in beta with general availability planned for July 2026; the Learn page showed no beta label on October 8, 2026
Validity1 year; renew for free with an online assessment on Microsoft Learn
RetakesWait 24 hours after a first fail, then 14 days between later attempts; up to 5 attempts in 12 months; each attempt is paid
Free official prepExam sandbox and course SC-500T00 (4 days instructor-led, or 12 self-paced learning paths). No Practice Assessment yet
Our practice questionsNone for SC-500 yet (see below for what to use instead)

Checked against Microsoft Learn’s Cloud and AI Security Engineer Associate certification page, SC-500 study guide and Azure Security Engineer Associate page on October 8, 2026.

Get an email when the Cloud and AI Security Engineer Associate (SC-500) exam changes

We check the official exam pages every day. If the price, version, format or retirement date changes, you’ll get a short email. At most one a week, plus the HOW TO // AI newsletter on Thursdays.

Unsubscribe anytime. Privacy policy.

Outside the US, Microsoft’s exam pricing data lists SC exams at £106 in the UK, €126 in Germany and France, ₹4,865 in India, ¥20,300 in Japan and US$140 in Australia and Canada, before tax. Listed prices don’t include promotional offers. For a cross-vendor view, see what AI certifications really cost.

SC-500 replaced AZ-500: what that means for you

Microsoft’s AZ-500 page now says the certification, its exam and its renewal assessments were retired on August 31, 2026, and that you can no longer earn or renew it. Microsoft’s retirement announcement names SC-500 as the replacement and describes the new certification as expanding the security role to cover cloud and AI model protection.

Your situationWhat to do
You hold AZ-500Microsoft says retired certifications stay valid until they expire, but AZ-500 can no longer be renewed. To keep a current Microsoft security engineer certification, plan to pass SC-500 before your AZ-500 expiry date.
You were studying for AZ-500Switch to SC-500. Identity, networking, storage, databases, compute and Defender for Cloud are still there; the AI security tasks are the main addition.
You are starting freshGo straight to SC-500, using the outline and plan below.

A rough mapping by area name (AZ-500 areas from its retired certification page, SC-500 weights from the current study guide):

AZ-500 (retired)SC-500 (current)
Secure identity and accessManage identity, access, and governance (20–25%)
Secure networkingSecure storage, databases, and networking (25–30%)
Secure compute, storage, and databasesSplit in two: storage and databases join networking in area 2, and compute is area 3, Secure compute (20–25%), which now includes implementing security for AI
Secure Azure using Microsoft Defender for Cloud and Microsoft SentinelManage and monitor security posture (20–25%), which also includes Microsoft Security Copilot

SC-500 skills measured and weights

Skill area (published outline)WeightMain tools
1. Manage identity, access, and governance20–25%Microsoft Entra ID, Privileged Identity Management, Azure Key Vault, Azure Policy, Defender for Cloud, Azure RBAC
2. Secure storage, databases, and networking25–30%Storage firewalls, Defender for Storage and Databases, Azure SQL auditing, NSGs, Virtual WAN, VPN, Entra Private Access, Private Link, Azure Firewall
3. Secure compute20–25%Security for AI, VMs and servers, Azure Arc, Defender for Servers and Containers, AKS, App Service, Functions, API Management
4. Manage and monitor security posture20–25%Defender CSPM, Defender External Attack Surface Management, Microsoft Sentinel, Purview Audit, Security Copilot

The study guide shows no “as of” date and was last updated May 13, 2026. Microsoft notes that the bullets under each skill illustrate how it is assessed, that related topics may be covered, and that most questions cover generally available features.

The AI security tasks on SC-500

This is the part that is new for anyone coming from AZ-500. It sits inside skill area 3 as the group “Implement security for AI.” Microsoft doesn’t publish a separate weight for it, but it is one of three groups in a 20–25% area. The published outline lists:

  • Identifying overexposure of data in SharePoint.
  • Identifying risks from Microsoft Copilot and AI apps with Microsoft Purview Data Security Posture Management (DSPM).
  • Enabling and configuring real-time protection for Microsoft Copilot Studio agents.
  • Implementing Conditional Access for Microsoft Entra Agent ID, managing Entra Agent ID access, and analyzing the blast radius of Entra Agent ID risks with Microsoft Defender XDR.
  • Configuring and deploying AI Gateway in Azure API Management for Microsoft Foundry.
  • Enabling Defender for AI Services in Defender for Cloud’s workload protection, and monitoring AI security with the Data and AI security dashboard in Defender for Cloud.
  • Configuring guardrails for agent security in Microsoft Foundry.
  • Managing agents in the Microsoft 365 admin center.

How to study it: Microsoft’s learning path Implement security for AI (9 modules, about 4 hours) covers the same ground: discover AI data risks with Purview DSPM, secure agent identities with Entra Agent ID and Conditional Access, analyze AI identity blast radius in Defender XDR, add runtime protection for Copilot Studio agents with Defender for Cloud Apps, secure model traffic with AI Gateway, configure Foundry guardrails, and protect AI workloads with Defender for Cloud. Work through it in order, and for each module write down the portal you’d open and the one setting that matters most. Our guides to fixing SharePoint oversharing, identity as your AI control plane and sensitivity labels and DLP before AI cover the same problems from the rollout side.

Skill area 1: Manage identity, access, and governance (20–25%)

  • Microsoft Entra ID: Privileged Identity Management (PIM), Conditional Access policies, authentication methods including MFA and passwordless, identity for enterprise applications and app registrations, OAuth permission grants and consent settings, and managed identities for Azure resources.
  • Azure Key Vault: deploying and configuring it, access and firewall settings, managing keys, secrets and certificates, scanning for secrets with Defender Cloud Security Posture Management (Defender CSPM), and Defender for Key Vault.
  • Governance and compliance: Azure Policy (built-in and custom definitions), regulatory compliance and security standards in Defender for Cloud, resource locks, built-in and custom roles (Azure and Entra), finding and fixing overprivileged access with Azure RBAC, Azure Backup security features, and security controls through infrastructure as code.

How to study it: build a small lab and apply each control once: a Conditional Access policy, a PIM role assignment, a Key Vault with firewall rules and RBAC, and an Azure Policy assignment. Microsoft’s learning path pages point to a free Azure trial of up to 30 days if you don’t have a subscription to practice in.

Skill area 2: Secure storage, databases, and networking (25–30%)

  • Storage: storage account security, firewall rules, Defender for Storage threat protection, and access policies.
  • Databases: platform-level security in Azure SQL, auditing for Azure SQL Database and Azure SQL Managed Instance, and Defender for Databases across Azure database services.
  • Networking: network security groups and application security groups, network access policies with Azure Virtual Network Manager, Azure Virtual WAN, VPN connections, Microsoft Entra Private Access, private endpoints and Private Link, Azure Firewall, and checking effective rules with Azure Network Watcher.

How to study it: this is the heaviest area, and networking is the widest part of it. Draw one reference network (hub, spoke, a PaaS service behind a private endpoint, Azure Firewall in the hub) and be able to explain how traffic flows and which control blocks what. Then use Network Watcher to prove it.

Skill area 3: Secure compute (20–25%)

  • Security for AI: the AI tasks listed above.
  • Servers and VMs: disk encryption, Azure Bastion, just-in-time VM access, Azure Arc for hybrid and multicloud servers, onboarding and configuring Defender for Servers (including vulnerability scanning, EDR and agentless scanning), VM security features such as secure boot and vTPM, and Azure Machine Configuration.
  • Application platform services: Defender for Containers, AKS, Azure Container Registry, Container Instances and Container Apps, Azure Functions, Logic Apps, App Service, Web Application Firewall, and API Management policies that protect back-end APIs.

Skill area 4: Manage and monitor security posture (20–25%)

  • Defender for Cloud: finding risks with Defender CSPM, compliance against security frameworks, workload protection plans, connecting AWS and Google Cloud, Defender Vulnerability Management for Azure VMs, and finding unprotected assets with Defender External Attack Surface Management.
  • Microsoft Sentinel: workspaces and roles, content hub solutions, data connectors, syslog and CEF collection, Windows Security events through data collection rules, custom log tables, automation rules and playbooks, data retention, and querying Microsoft Purview Audit in Defender XDR.
  • Microsoft Security Copilot: workspaces, permissions and roles, plugins, and Microsoft and Security Store agents.

How to study it: connect one data source to Sentinel end to end and write one automation rule. For Security Copilot, focus on the admin tasks in the outline (workspaces, roles, plugins and agents) rather than prompting. Our piece on logging what your AI assistants do is useful background for the monitoring mindset.

A 6-week SC-500 study plan

This plan assumes you already administer Azure and can give SC-500 about 6 to 8 hours a week, including lab time. If Entra ID or Azure networking is new to you, add two weeks.

WhenFocusWhat to do
Week 1Baseline and identityRead the study guide. Work through Secure access to resources by using Microsoft Entra and the Key Vault path. Build your lab.
Week 2GovernanceEnforce security governance and regulatory compliance. Apply Azure Policy, resource locks and custom roles in the lab.
Week 3Storage, databases, networkingThe storage, Azure SQL and network security paths. Draw and test your reference network.
Week 4AI securityImplement security for AI, all 9 modules, in order. Write the portal-and-setting notes for each task.
Week 5Compute and postureServers and VMs, application platform services, Defender for Cloud, Microsoft Sentinel and Security Copilot.
Week 6Review and bookReread every outline bullet and mark the ones you couldn’t do in a lab. Try the exam sandbox, practice finding answers fast on Microsoft Learn, then schedule.

Prefer a plan built around your own calendar? The free AI certification study plan generator makes one.

Free official SC-500 prep

  • SC-500 study guide: the full outline plus links to Azure, Entra, Defender for Cloud, Sentinel and networking documentation.
  • Course SC-500T00-A: Implement end-to-end security controls for cloud and AI workloads: 4 days, instructor-led with hands-on labs. The self-paced version is 12 learning paths on Microsoft Learn, from Entra and Key Vault through AI security, Sentinel and Security Copilot.
  • Exam sandbox: a demo of the Microsoft exam interface and question types.
  • Exam Readiness Zone: Microsoft’s exam-prep video series, linked from the study guide.
  • No Practice Assessment yet. The certification page says it isn’t available and that Practice Assessments usually arrive within 8 weeks of an exam leaving beta and becoming generally available. Check the page again before you book.

SC-500 practice questions

HOW TO // AI doesn’t have SC-500 practice questions yet, and neither does Microsoft at the moment, so your lab is your practice test: if you can perform every bullet in the outline, you’re ready. When Microsoft’s free Practice Assessment appears on the certification page, take it twice, once early and once before you book.

If you’re comparing SC-500 with vendor-neutral AI security credentials, our AI security certifications guide covers the options, including CompTIA SecAI+ and ISACA AAISM. For every exam we cover with free practice questions, see AI Exam Prep, and use the AI certification index for verified facts on other AI exams.

Skip any site selling “real” SC-500 questions. Those are dumps, and for an exam this new they are more likely to be guesswork than anything else.

What exam day looks like

  • 120 minutes, proctored by Pearson VUE, online or at a test center. The exam may include interactive components.
  • Microsoft Learn is open during the exam. On associate and expert exams you can open Learn in a split screen. No extra time is added, the clock keeps running, and Q&A, Practice Assessments and your profile are blocked.
  • Breaks: five minutes of break time are built in, the clock keeps running while you are away, and you can’t return to questions you saw before the break.
  • Register with a personal Microsoft account. Microsoft warns that exam records tied to a work or school account are lost if you leave that organization.
  • Retakes: 24 hours after a first fail, then 14 days between attempts, up to five attempts in 12 months, and each one is paid (Microsoft’s retake policy). Microsoft also sells Exam Replay, a voucher plus one retake used within 12 months.

Source for the timing, break and Learn-access rules: Microsoft’s exam duration and exam experience page.

Renewal: SC-500 is valid for one year

Microsoft’s credential expiration policy says associate certifications are valid for one year. To keep SC-500, pass the free, online, open-book renewal assessment on Microsoft Learn; the window opens six months before your expiry date and attempts are unlimited. Microsoft offers renewal once a certification has been available for more than six months. Our guide to which AI certifications expire compares renewal rules across vendors.

Is SC-500 worth it?

If you secure Azure for a living, yes: it is the certification Microsoft now recommends in place of AZ-500, and it its outline covers securing AI workloads and agents in Microsoft’s own tools. It is not an AI exam for beginners, though. Most of the outline is classic Azure security, and Microsoft expects real administration experience. If you want an AI security credential that isn’t tied to Microsoft’s products, compare the options in our AI security certifications guide, and for team planning see AI security readiness.

HOW TO // AI is not affiliated with or endorsed by Microsoft. SC-500, AZ-500, Microsoft Azure, Microsoft Entra, Microsoft Defender, Microsoft Sentinel, Microsoft Purview, Microsoft Security Copilot and Microsoft Foundry are trademarks of Microsoft Corporation; we reference them descriptively. All content is original and based on Microsoft’s published study guide; we do not reproduce or reveal real exam questions. Check the official certification page before you book.

Related guides

Frequently asked questions

What is the SC-500 exam?

SC-500 is the exam for Microsoft Certified: Cloud and AI Security Engineer Associate. It covers identity, access and governance (20–25%), storage, databases and networking (25–30%), compute including AI security (20–25%), and security posture management (20–25%) across Azure, hybrid and AI workloads.

Did SC-500 replace AZ-500?

Yes. Microsoft retired AZ-500 (Azure Security Engineer Associate), its exam and its renewal assessments on August 31, 2026, and names SC-500 (Cloud and AI Security Engineer Associate) as the replacement.

How much does the SC-500 exam cost?

SC-500 costs $165 in the United States. Microsoft sets the price by the country or region where you test, for example £106 in the UK and ₹4,865 in India, and tax is extra.

Is SC-500 still in beta?

Microsoft's June 2026 credentials roundup listed SC-500 in beta with general availability planned for July 2026. On October 8, 2026, the Microsoft Learn certification page showed no beta label.

Is there an SC-500 practice test?

Not from Microsoft yet. The certification page says the Practice Assessment isn't available and that they usually arrive within 8 weeks of an exam leaving beta. HOW TO // AI doesn't have SC-500 practice questions either, so use the exam sandbox and hands-on labs for now.

What AI security topics are on SC-500?

The 'Implement security for AI' group covers SharePoint data overexposure, Purview DSPM for Copilot and AI apps, real-time protection for Copilot Studio agents, Microsoft Entra Agent ID access and Conditional Access, AI Gateway for Microsoft Foundry, Defender for AI Services, Foundry guardrails, and managing agents in the Microsoft 365 admin center.

I already have AZ-500. Do I need SC-500?

Your AZ-500 stays valid until it expires, but Microsoft no longer lets you renew it. If you want a current Microsoft security engineer certification after that date, plan to pass SC-500.

How long is the SC-500 certification valid?

One year. You renew it for free by passing an online, open-book renewal assessment on Microsoft Learn, which opens six months before your certification expires and allows unlimited attempts.

How long should I study for SC-500?

About six weeks at 6 to 8 hours a week, including lab time, is a reasonable target if you already administer Azure. Add two weeks if Microsoft Entra ID or Azure networking is new to you.

Scroll to Top