Technology13 min read

AZ-500 Exam Guide 2026: Free Azure Security Prep Before Retirement

Free 2026 AZ-500 Azure Security Engineer prep: $165 fee, 100-minute format, January 2026 skills outline, 4 weighted domains, SC-500 successor decision, labs, and a 6-week study plan.

Ran Chen, EA, CFPMay 13, 2026

Key Facts

  • AZ-500 retires on August 31, 2026 at 11:59 PM Central Standard Time (Microsoft Learn study guide).
  • The current AZ-500 skills outline is dated January 22, 2026 on Microsoft Learn.
  • AZ-500 candidates have 100 minutes to complete the proctored Microsoft certification assessment (Microsoft Learn).
  • A scaled score of 700 or greater is required to pass AZ-500 (Microsoft Learn).
  • The AZ-500 exam fee is $165 USD in the United States, scheduled through Pearson VUE.
  • The Azure Security Engineer Associate credential is valid for 12 months and renews free on Microsoft Learn.
  • The January 2026 AZ-500 outline has four domains: identity 15-20%, networking 20-25%, compute/storage/databases 20-25%, and Defender for Cloud and Sentinel 30-35% (Microsoft Learn).
  • Microsoft named SC-500 (Cloud and AI Security Engineer Associate) as AZ-500's successor, with beta launching May 15, 2026.
  • AZ-500 typically delivers 40 to 60 questions across multiple-choice, multi-select, case study, and drag-and-drop formats (Microsoft Learn).
  • Microsoft's retake policy imposes a 24-hour wait after a first failed AZ-500 attempt, then 14-day waits for attempts 2-5.

📺 Watch the Video

AZ-500 in 2026: A Retirement-Aware Strategy

Exam AZ-500: Microsoft Azure Security Technologies is the single exam behind the Microsoft Certified: Azure Security Engineer Associate credential, but every 2026 candidate has to make one decision before opening a study guide: take AZ-500 before it disappears, or pivot to its already-announced successor.

Microsoft Learn states that AZ-500 retires on August 31, 2026 at 11:59 PM Central Standard Time. The certification and its renewal assessments retire the same day. Unlike a quiet retirement, Microsoft has already named the replacement: Exam SC-500 (Microsoft Certified: Cloud and AI Security Engineer Associate), which entered beta on May 15, 2026 and is expected to reach general availability in July 2026.

So the real question is not "will AZ-500 disappear" but "which exam matches my timeline and role." If you can sit AZ-500 before August 31, 2026, the credential you earn stays on your Microsoft transcript and remains a valid, recognized signal. If your realistic test date lands after retirement, start SC-500 instead, because it broadens the scope with AI workload security, Microsoft Security Copilot, and multicloud posture management that AZ-500 never covered.

/practice/azure-az-500Practice questions with detailed explanations

Official AZ-500 Facts (Verified July 2026)

Microsoft's source-of-truth pages are the AZ-500 exam page, the AZ-500 study guide, and the Azure Security Engineer Associate certification page.

Item2026 detail
ExamAZ-500: Microsoft Azure Security Technologies
CertificationMicrosoft Certified: Azure Security Engineer Associate
RetirementAugust 31, 2026 at 11:59 PM Central Standard Time
SuccessorSC-500 (Cloud and AI Security Engineer Associate), beta May 15, 2026
Current skills outlineJanuary 22, 2026
Questions40-60 (varies per session)
Exam time100 minutes to complete the assessment
Passing score700 or greater (scaled, not 70%)
Fee$165 USD in the United States; varies by region
DeliveryPearson VUE test center or online (OnVUE); proctored
Question typesMultiple choice, multi-select, case studies, drag-and-drop, hot-area, possible interactive labs
Validity12 months; free renewal assessment on Microsoft Learn
Renewal deadlineRenewal assessments also retire August 31, 2026
Retake policy24-hour wait after first fail; 14-day wait for attempts 2-5; max 5 per 12 months
PrerequisitesNone formal; Microsoft recommends AZ-104-level Azure admin experience
Candidate profileAzure security engineer implementing, managing, and monitoring security for Azure, multi-cloud, and hybrid environments

Microsoft says the AZ-500 candidate should have practical experience with Azure administration and hybrid environments plus strong familiarity with Microsoft Entra ID, compute, networking, and storage, and should align work to the Microsoft Cloud Security Benchmark (MCSB).

The 4 AZ-500 Domains in the January 22, 2026 Outline

Microsoft Learn's "Skills at a glance" lists four weighted domains. Memorize the weights, because they tell you where to spend your time.

DomainWeightWhat to master
Secure identity and access15-20%RBAC, custom roles, Microsoft Entra roles, Privileged Identity Management, MFA, Conditional Access, app registrations, service principals, managed identities
Secure networking20-25%NSGs, ASGs, Virtual Network Manager, UDRs, peering, VPN, Virtual WAN, Private Endpoints, Private Link, Azure Firewall, Application Gateway, Front Door, WAF, DDoS Protection
Secure compute, storage, and databases20-25%VM access, Bastion, JIT, AKS security, containers, ACR, disk encryption, Key Vault, API Management, storage security, database security
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel30-35%Security posture, Defender plans, vulnerability remediation, alerts, incidents, analytics rules, KQL, workbooks, playbooks, automation, regulatory compliance

The largest domain is Defender for Cloud and Microsoft Sentinel at 30-35%. That does not mean you can postpone identity or networking. Defender and Sentinel questions often assume you already know how a resource was secured before monitoring flagged a problem.

The January 22, 2026 update was minor: it renamed "Manage Microsoft Entra application access" to "Manage Microsoft Entra application access and managed identities" and made small wording edits to "Plan and implement advanced security for compute." The four domain weights and the four domain names above did not change.

AZ-500 vs SC-500 vs SC-200: Which Exam Should You Take

This is the decision every 2026 Azure security candidate is actually making, and most guides dodge it.

Take AZ-500 if you can test before August 31, 2026 and you want the Azure Security Engineer Associate credential now. The earned cert stays on your transcript after retirement, it is still recognized by employers and Microsoft partner competency requirements, and the study ecosystem (Microsoft Learn, John Savill, Tutorials Dojo, Pluralsight) is mature and deep. AZ-500 is the most efficient path if your timeline is under 8 weeks.

Take SC-500 if your test date lands after August 31, 2026, or if you specifically want the newer Cloud and AI Security Engineer Associate credential. SC-500 is not a renamed AZ-500. It expands the scope to include AI workload security, Microsoft Copilot risk, Microsoft Entra Agent ID, Defender for AI, Microsoft Purview Data Security Posture Management, and Microsoft Security Copilot. Beta exams are usually discounted and results arrive after the exam goes GA. Plan 6-10 weeks of study if you already know AZ-500 content, 10-14 weeks if you are new to Azure security.

Take SC-200 (Security Operations Analyst Associate) if your job is detection, incident response, and Microsoft Sentinel or Defender XDR operations rather than architecture and implementation. SC-200 covers Sentinel, Defender XDR, and threat hunting in depth but skips the identity, networking, and workload hardening scope that AZ-500 and SC-500 own. SC-200 has no announced retirement date, and many security engineers hold it alongside AZ-500 or SC-500.

Take SC-900 (Microsoft Security, Compliance, and Identity Fundamentals) first only if you are brand new to Microsoft security. SC-900 is a non-technical fundamentals exam; AZ-500 assumes you are well past it.

Article Thesis: AZ-500 Is a Security Implementation Exam, Not a Product Tour

Many AZ-500 summaries list Azure services in order. That is not enough. The exam asks you to decide how to implement security controls across an actual environment:

  • Which identity should access a resource, and should it be a managed identity, service principal, group assignment, or PIM-eligible role?
  • Should private access use Private Endpoint, Service Endpoint, or VNet integration?
  • Is an alert a Defender for Cloud recommendation, a Sentinel incident, a KQL analytics rule, or an Azure Monitor signal?
  • Should a workload use Azure Disk Encryption, encryption at host, customer-managed keys, confidential disk encryption, or storage account controls?
  • Does the scenario call for NSG, Azure Firewall, Application Gateway WAF, Front Door WAF, or DDoS Protection?

Study decisions, not menus.

What to Study First

1. Microsoft Entra ID and Azure RBAC

Start with the identity plane because every other domain depends on it. Be able to explain the difference between Microsoft Entra roles and Azure RBAC roles, when to use built-in versus custom roles, and how Privileged Identity Management changes standing access into eligible, just-in-time access.

High-yield tasks:

  • Assign built-in Azure roles at management group, subscription, resource group, and resource scope
  • Build a least-privilege custom role from actions and dataActions
  • Configure PIM activation settings, approval, MFA, justification, and access reviews
  • Configure Conditional Access for Azure management access
  • Use managed identities for Azure resources instead of secrets wherever possible

2. Network security decisions

Networking is 20-25% of the exam and shows up inside compute, storage, and database scenarios. Build a small lab with two VNets, NSGs, a private endpoint, Azure Firewall, and a web app behind an application delivery service.

NeedUsually tested answer
Control L3/L4 subnet or NIC trafficNSG, optionally ASG for grouping VMs
Central outbound/inbound inspectionAzure Firewall and firewall policy
Protect regional HTTP/S appApplication Gateway with WAF
Protect global HTTP/S appAzure Front Door with WAF
Keep PaaS resource off public internetPrivate Endpoint plus public access disabled
Extend subnet identity to public PaaS endpointService Endpoint
Protect from volumetric attacksAzure DDoS Protection Standard
Manage VNet security at scaleAzure Virtual Network Manager

3. Workload and data security

This domain is broad. Avoid memorizing one-off feature names until you can map each workload to its control surface.

  • VMs: Bastion, JIT access, disk encryption, update and security recommendations
  • AKS: network isolation, authentication, image and runtime monitoring
  • Containers: ACR access, Defender coverage, container monitoring
  • Storage: access keys, SAS, shared key disablement, private endpoints, encryption, lifecycle and immutability
  • Databases: Microsoft Entra authentication, firewall and private access, auditing, Defender, vulnerability assessment, TDE and key choices
  • Key Vault: secrets, keys, certificates, RBAC versus access policies, managed identity access
  • API Management: TLS, client certificates, managed identity, private networking, policy controls

4. Defender for Cloud and Microsoft Sentinel

This is the largest domain. Learn the workflow:

  1. Enable the right Defender plans.
  2. Review secure score and recommendations.
  3. Remediate vulnerabilities or exempt with justification.
  4. Investigate alerts and incidents.
  5. Use Sentinel analytics rules, KQL, workbooks, playbooks, and automation rules.
  6. Report regulatory compliance and security posture.

The exam expects you to understand the difference between posture management and security operations. Defender for Cloud identifies risk and recommends remediation. Sentinel is where you collect signals, correlate incidents, investigate, and automate response. Confusing a Defender recommendation with a Sentinel incident is a classic exam trap.

6-Week AZ-500 Study Plan Before the Retirement Date

WeekFocusHands-on output
1Exam scope and identityRBAC custom role, PIM workflow, Conditional Access policy, managed identity lab
2Network securityNSG/ASG rules, Private Endpoint, Azure Firewall, Application Gateway WAF, Front Door WAF comparison
3Compute and container securityBastion, JIT VM access, disk encryption options, AKS authentication and network controls, ACR permissions
4Storage, database, Key Vault, and API securityStorage public access lock-down, SAS comparison, SQL private access, database auditing, Key Vault RBAC, API Management security
5Defender for CloudDefender plans, secure score, recommendations, vulnerability management, regulatory compliance
6Sentinel and timed reviewAnalytics rule, incident workflow, KQL basics, workbook, playbook, full timed practice

If you cannot complete hands-on labs, delay the exam or pivot to SC-500. AZ-500 questions often hinge on portal and configuration details that are hard to learn from reading alone.

Common AZ-500 Mistakes

  1. Missing the retirement date and the SC-500 successor. AZ-500 retires August 31, 2026. If you cannot finish before then, switch to SC-500 instead of studying for an exam you can no longer sit.
  2. Studying Defender and Sentinel as one product. Defender for Cloud and Sentinel overlap in security operations, but they are tested as different workflows.
  3. Using Owner permissions in labs. Practice least privilege with scoped roles and managed identities.
  4. Confusing Private Endpoint and Service Endpoint. Private Endpoint gives the service a private IP in your VNet; Service Endpoint extends subnet identity to a public service endpoint.
  5. Skipping KQL. You do not need to be a full-time detection engineer, but you must read and reason about basic Sentinel queries.
  6. Treating WAF placement as interchangeable. Application Gateway WAF is regional; Front Door WAF is global edge-oriented.
  7. Ignoring Key Vault access models. Know when to use the RBAC permission model versus access policies, and how managed identities retrieve secrets.

Career Reality: What AZ-500 Is Worth

AZ-500 is a strong, recognized credential for Azure security engineers, but it is not a first certification and it does not by itself land a senior security role. Microsoft does not publish AZ-500 pass rates, and any specific pass-rate number cited elsewhere is fabricated.

For salary context, the closest official U.S. category is the Bureau of Labor Statistics Occupational Outlook Handbook for Information Security Analysts: a median annual wage of $124,910 (May 2024 BLS data) with projected job growth of 29% from 2024 to 2034, much faster than average. Azure security engineers typically sit above that median when they pair AZ-500 with hands-on experience and a second credential such as AZ-104, SC-200, or the new SC-500. Treat AZ-500 as proof you can implement Azure security controls, not as a standalone job ticket.

Official Resources

Start AZ-500 Practice Free

/practice/azure-az-500Practice questions with detailed explanations
Test Your Knowledge
Question 1 of 4

According to Microsoft Learn, when does AZ-500 retire?

Learn More with AI

10 free AI interactions per day

AZ-500Azure Security EngineerMicrosoft certificationMicrosoft Entra IDDefender for CloudMicrosoft SentinelSC-5002026

Related Articles

Stay Updated

Get free exam tips and study guides delivered to your inbox.

Free exam tips & study guides. Unsubscribe anytime.