AZ-500 in 2026: A Retirement-Aware Strategy
Exam AZ-500: Microsoft Azure Security Technologies is the single exam behind the Microsoft Certified: Azure Security Engineer Associate credential, but every 2026 candidate has to make one decision before opening a study guide: take AZ-500 before it disappears, or pivot to its already-announced successor.
Microsoft Learn states that AZ-500 retires on August 31, 2026 at 11:59 PM Central Standard Time. The certification and its renewal assessments retire the same day. Unlike a quiet retirement, Microsoft has already named the replacement: Exam SC-500 (Microsoft Certified: Cloud and AI Security Engineer Associate), which entered beta on May 15, 2026 and is expected to reach general availability in July 2026.
So the real question is not "will AZ-500 disappear" but "which exam matches my timeline and role." If you can sit AZ-500 before August 31, 2026, the credential you earn stays on your Microsoft transcript and remains a valid, recognized signal. If your realistic test date lands after retirement, start SC-500 instead, because it broadens the scope with AI workload security, Microsoft Security Copilot, and multicloud posture management that AZ-500 never covered.
Official AZ-500 Facts (Verified July 2026)
Microsoft's source-of-truth pages are the AZ-500 exam page, the AZ-500 study guide, and the Azure Security Engineer Associate certification page.
| Item | 2026 detail |
|---|---|
| Exam | AZ-500: Microsoft Azure Security Technologies |
| Certification | Microsoft Certified: Azure Security Engineer Associate |
| Retirement | August 31, 2026 at 11:59 PM Central Standard Time |
| Successor | SC-500 (Cloud and AI Security Engineer Associate), beta May 15, 2026 |
| Current skills outline | January 22, 2026 |
| Questions | 40-60 (varies per session) |
| Exam time | 100 minutes to complete the assessment |
| Passing score | 700 or greater (scaled, not 70%) |
| Fee | $165 USD in the United States; varies by region |
| Delivery | Pearson VUE test center or online (OnVUE); proctored |
| Question types | Multiple choice, multi-select, case studies, drag-and-drop, hot-area, possible interactive labs |
| Validity | 12 months; free renewal assessment on Microsoft Learn |
| Renewal deadline | Renewal assessments also retire August 31, 2026 |
| Retake policy | 24-hour wait after first fail; 14-day wait for attempts 2-5; max 5 per 12 months |
| Prerequisites | None formal; Microsoft recommends AZ-104-level Azure admin experience |
| Candidate profile | Azure security engineer implementing, managing, and monitoring security for Azure, multi-cloud, and hybrid environments |
Microsoft says the AZ-500 candidate should have practical experience with Azure administration and hybrid environments plus strong familiarity with Microsoft Entra ID, compute, networking, and storage, and should align work to the Microsoft Cloud Security Benchmark (MCSB).
The 4 AZ-500 Domains in the January 22, 2026 Outline
Microsoft Learn's "Skills at a glance" lists four weighted domains. Memorize the weights, because they tell you where to spend your time.
| Domain | Weight | What to master |
|---|---|---|
| Secure identity and access | 15-20% | RBAC, custom roles, Microsoft Entra roles, Privileged Identity Management, MFA, Conditional Access, app registrations, service principals, managed identities |
| Secure networking | 20-25% | NSGs, ASGs, Virtual Network Manager, UDRs, peering, VPN, Virtual WAN, Private Endpoints, Private Link, Azure Firewall, Application Gateway, Front Door, WAF, DDoS Protection |
| Secure compute, storage, and databases | 20-25% | VM access, Bastion, JIT, AKS security, containers, ACR, disk encryption, Key Vault, API Management, storage security, database security |
| Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel | 30-35% | Security posture, Defender plans, vulnerability remediation, alerts, incidents, analytics rules, KQL, workbooks, playbooks, automation, regulatory compliance |
The largest domain is Defender for Cloud and Microsoft Sentinel at 30-35%. That does not mean you can postpone identity or networking. Defender and Sentinel questions often assume you already know how a resource was secured before monitoring flagged a problem.
The January 22, 2026 update was minor: it renamed "Manage Microsoft Entra application access" to "Manage Microsoft Entra application access and managed identities" and made small wording edits to "Plan and implement advanced security for compute." The four domain weights and the four domain names above did not change.
AZ-500 vs SC-500 vs SC-200: Which Exam Should You Take
This is the decision every 2026 Azure security candidate is actually making, and most guides dodge it.
Take AZ-500 if you can test before August 31, 2026 and you want the Azure Security Engineer Associate credential now. The earned cert stays on your transcript after retirement, it is still recognized by employers and Microsoft partner competency requirements, and the study ecosystem (Microsoft Learn, John Savill, Tutorials Dojo, Pluralsight) is mature and deep. AZ-500 is the most efficient path if your timeline is under 8 weeks.
Take SC-500 if your test date lands after August 31, 2026, or if you specifically want the newer Cloud and AI Security Engineer Associate credential. SC-500 is not a renamed AZ-500. It expands the scope to include AI workload security, Microsoft Copilot risk, Microsoft Entra Agent ID, Defender for AI, Microsoft Purview Data Security Posture Management, and Microsoft Security Copilot. Beta exams are usually discounted and results arrive after the exam goes GA. Plan 6-10 weeks of study if you already know AZ-500 content, 10-14 weeks if you are new to Azure security.
Take SC-200 (Security Operations Analyst Associate) if your job is detection, incident response, and Microsoft Sentinel or Defender XDR operations rather than architecture and implementation. SC-200 covers Sentinel, Defender XDR, and threat hunting in depth but skips the identity, networking, and workload hardening scope that AZ-500 and SC-500 own. SC-200 has no announced retirement date, and many security engineers hold it alongside AZ-500 or SC-500.
Take SC-900 (Microsoft Security, Compliance, and Identity Fundamentals) first only if you are brand new to Microsoft security. SC-900 is a non-technical fundamentals exam; AZ-500 assumes you are well past it.
Article Thesis: AZ-500 Is a Security Implementation Exam, Not a Product Tour
Many AZ-500 summaries list Azure services in order. That is not enough. The exam asks you to decide how to implement security controls across an actual environment:
- Which identity should access a resource, and should it be a managed identity, service principal, group assignment, or PIM-eligible role?
- Should private access use Private Endpoint, Service Endpoint, or VNet integration?
- Is an alert a Defender for Cloud recommendation, a Sentinel incident, a KQL analytics rule, or an Azure Monitor signal?
- Should a workload use Azure Disk Encryption, encryption at host, customer-managed keys, confidential disk encryption, or storage account controls?
- Does the scenario call for NSG, Azure Firewall, Application Gateway WAF, Front Door WAF, or DDoS Protection?
Study decisions, not menus.
What to Study First
1. Microsoft Entra ID and Azure RBAC
Start with the identity plane because every other domain depends on it. Be able to explain the difference between Microsoft Entra roles and Azure RBAC roles, when to use built-in versus custom roles, and how Privileged Identity Management changes standing access into eligible, just-in-time access.
High-yield tasks:
- Assign built-in Azure roles at management group, subscription, resource group, and resource scope
- Build a least-privilege custom role from actions and dataActions
- Configure PIM activation settings, approval, MFA, justification, and access reviews
- Configure Conditional Access for Azure management access
- Use managed identities for Azure resources instead of secrets wherever possible
2. Network security decisions
Networking is 20-25% of the exam and shows up inside compute, storage, and database scenarios. Build a small lab with two VNets, NSGs, a private endpoint, Azure Firewall, and a web app behind an application delivery service.
| Need | Usually tested answer |
|---|---|
| Control L3/L4 subnet or NIC traffic | NSG, optionally ASG for grouping VMs |
| Central outbound/inbound inspection | Azure Firewall and firewall policy |
| Protect regional HTTP/S app | Application Gateway with WAF |
| Protect global HTTP/S app | Azure Front Door with WAF |
| Keep PaaS resource off public internet | Private Endpoint plus public access disabled |
| Extend subnet identity to public PaaS endpoint | Service Endpoint |
| Protect from volumetric attacks | Azure DDoS Protection Standard |
| Manage VNet security at scale | Azure Virtual Network Manager |
3. Workload and data security
This domain is broad. Avoid memorizing one-off feature names until you can map each workload to its control surface.
- VMs: Bastion, JIT access, disk encryption, update and security recommendations
- AKS: network isolation, authentication, image and runtime monitoring
- Containers: ACR access, Defender coverage, container monitoring
- Storage: access keys, SAS, shared key disablement, private endpoints, encryption, lifecycle and immutability
- Databases: Microsoft Entra authentication, firewall and private access, auditing, Defender, vulnerability assessment, TDE and key choices
- Key Vault: secrets, keys, certificates, RBAC versus access policies, managed identity access
- API Management: TLS, client certificates, managed identity, private networking, policy controls
4. Defender for Cloud and Microsoft Sentinel
This is the largest domain. Learn the workflow:
- Enable the right Defender plans.
- Review secure score and recommendations.
- Remediate vulnerabilities or exempt with justification.
- Investigate alerts and incidents.
- Use Sentinel analytics rules, KQL, workbooks, playbooks, and automation rules.
- Report regulatory compliance and security posture.
The exam expects you to understand the difference between posture management and security operations. Defender for Cloud identifies risk and recommends remediation. Sentinel is where you collect signals, correlate incidents, investigate, and automate response. Confusing a Defender recommendation with a Sentinel incident is a classic exam trap.
6-Week AZ-500 Study Plan Before the Retirement Date
| Week | Focus | Hands-on output |
|---|---|---|
| 1 | Exam scope and identity | RBAC custom role, PIM workflow, Conditional Access policy, managed identity lab |
| 2 | Network security | NSG/ASG rules, Private Endpoint, Azure Firewall, Application Gateway WAF, Front Door WAF comparison |
| 3 | Compute and container security | Bastion, JIT VM access, disk encryption options, AKS authentication and network controls, ACR permissions |
| 4 | Storage, database, Key Vault, and API security | Storage public access lock-down, SAS comparison, SQL private access, database auditing, Key Vault RBAC, API Management security |
| 5 | Defender for Cloud | Defender plans, secure score, recommendations, vulnerability management, regulatory compliance |
| 6 | Sentinel and timed review | Analytics rule, incident workflow, KQL basics, workbook, playbook, full timed practice |
If you cannot complete hands-on labs, delay the exam or pivot to SC-500. AZ-500 questions often hinge on portal and configuration details that are hard to learn from reading alone.
Common AZ-500 Mistakes
- Missing the retirement date and the SC-500 successor. AZ-500 retires August 31, 2026. If you cannot finish before then, switch to SC-500 instead of studying for an exam you can no longer sit.
- Studying Defender and Sentinel as one product. Defender for Cloud and Sentinel overlap in security operations, but they are tested as different workflows.
- Using Owner permissions in labs. Practice least privilege with scoped roles and managed identities.
- Confusing Private Endpoint and Service Endpoint. Private Endpoint gives the service a private IP in your VNet; Service Endpoint extends subnet identity to a public service endpoint.
- Skipping KQL. You do not need to be a full-time detection engineer, but you must read and reason about basic Sentinel queries.
- Treating WAF placement as interchangeable. Application Gateway WAF is regional; Front Door WAF is global edge-oriented.
- Ignoring Key Vault access models. Know when to use the RBAC permission model versus access policies, and how managed identities retrieve secrets.
Career Reality: What AZ-500 Is Worth
AZ-500 is a strong, recognized credential for Azure security engineers, but it is not a first certification and it does not by itself land a senior security role. Microsoft does not publish AZ-500 pass rates, and any specific pass-rate number cited elsewhere is fabricated.
For salary context, the closest official U.S. category is the Bureau of Labor Statistics Occupational Outlook Handbook for Information Security Analysts: a median annual wage of $124,910 (May 2024 BLS data) with projected job growth of 29% from 2024 to 2034, much faster than average. Azure security engineers typically sit above that median when they pair AZ-500 with hands-on experience and a second credential such as AZ-104, SC-200, or the new SC-500. Treat AZ-500 as proof you can implement Azure security controls, not as a standalone job ticket.
Official Resources
- AZ-500 exam page on Microsoft Learn
- AZ-500 study guide and January 22, 2026 skills outline
- Azure Security Engineer Associate certification page
- Microsoft exam scoring and score reports
- Microsoft certification renewal
- Microsoft exam and assessment lab retirement list
- Microsoft Defender for Cloud documentation
- Microsoft Sentinel documentation
- BLS Occupational Outlook Handbook: Information Security Analysts
