Identity, Access, Governance
20-25%of exam
Storage, Databases, Networking
25-30%of exam
Secure Compute and AI
20-25%of exam
Manage and Monitor Posture
20-25%of exam
Quick Facts
- Exam
- SC-500
- Credential
- Cloud and AI Security Engineer
- Level
- Associate
- Time
- 120 min
- Pass
- 700/1000
- Fee
- $165 USD
- Items
- Not published (40-60 typical)
- Delivery
- Pearson VUE, proctored
- Renewal
- 1 year, free online
- Replaces
- AZ-500
- Blueprint
- May 13 2026
Key Vault Retention
Soft delete 7-90 days | default 90
Policy vs Lock
Azure Policy
- Allow, deny, remediate
- Audits compliance
- Scales by scope
Resource lock
- CanNotDelete or ReadOnly
- Stops accidental change
- Inherited by children
Standard vs protection
Identity Control Picker
- Standing admin rights→PIM eligible role(Just-in-time)
- Risky sign-in→Conditional Access(Risk condition)
- App calls Azure→Managed identity(No stored secret)
- Identity shared by apps→User-assigned identity(Own lifecycle)
- App holds a secret→Key Vault(Use RBAC model)
- Stop accidental deletion→Resource lock(CanNotDelete)
- Enforce required tags→Azure Policy(deny effect)
- Too many role assignments→Azure RBAC review(Least privilege)
- Prove compliance state→Defender for Cloud(Regulatory compliance)
PIM Essentials
- Eligible
- Must activate before useJIT
- Active
- Rights already granted
- Activate
- MFA, justification, approval
- Time-bound
- Start and end dates
- Permanent eligible
- Always able to activate
- Approver
- Approves or denies request
- Access review
- Confirms access still needed
- Audit history
- Downloadable activation record
- PIM scope
- Entra roles, Azure roles, groups
Conditional Access Formula
Assignments + conditions -> grant or session
Eligible vs Active
Eligible
- Activation required
- MFA and justification
- Expires after activation
Active
- Rights already usable
- No activation step
- Can still be time-bound
Request it vs have it
Conditional Access
- Assignments
- Who, what, where
- Users and groups
- Include or exclude
- Target resources
- Apps, actions, auth context
- Network
- IP ranges and geographies
- Conditions
- Risk, platform, client app
- Grant
- Block or require controls
- Session
- Sign-in frequency, app restrictions
- Report-only
- Evaluate without enforcing
- Many policies
- All must be satisfied
- Block control
- Wins over every grant
Key Vault RBAC vs Access Policy
Azure RBAC
- Recommended and default
- Granting needs Owner
- Works with PIM
Access policy
- Legacy data-plane only
- Vault-wide permissions
- Contributor can self-grant
Central vs vault-local
App and Managed Identities
- App registration
- Tenant application object
- Enterprise app
- Service principal instance
- System-assigned
- Tied to resource lifecycle
- User-assigned
- Standalone, shareable identity
- OAuth grant
- Delegated permission consent
- Consent settings
- Limit what users approve
- Admin consent workflow
- Users request admin approval
Key Vault Protection
- Soft delete
- On by default, permanent
- Retention range
- 7 to 90 days
- Default retention
- 90 days
- Retention set once
- Fixed at vault creation
- Purge protection
- Optional, blocks early purge
- Key Vault Purge Operator
- Role allowed to purge
- RBAC model
- Recommended and now default
- Access policy
- Legacy data-plane model
- Vault firewall
- Deny public, allow trusted
- Defender for Key Vault
- Vault access threat alerts
Azure Policy Effects
- deny
- Blocks noncompliant creation
- audit
- Flags but allows
- auditIfNotExists
- Checks related resource
- deployIfNotExists
- Deploys missing configuration
- modify
- Changes properties or tags
- append
- Adds required fields
- denyAction
- Blocks a named action
- disabled
- Turns the rule off
- Order
- Append, modify, deny, audit
- Initiative
- Grouped policy definitions
RBAC and Locks
- Owner
- Full access plus granting
- Contributor
- Manages, cannot grant access
- User Access Administrator
- Assigns roles only
- Reader
- View only
- Custom role
- Actions plus notActions
- Deny assignment
- Blocks despite role grant
- CanNotDelete lock
- Read and edit allowed
- ReadOnly lock
- No edits or deletes
- Lock inheritance
- Child scopes inherit locks
Firewall Order
Threat intel -> DNAT -> Network -> Application
NSG vs ASG
NSG
- Allow or deny rules
- Subnet or NIC
- Priority 100-4096
ASG
- Named group of NICs
- Used inside NSG rules
- No rules of its own
Rule vs grouping
Network Control Picker
- Filter subnet traffic→NSG(Layer 3-4)
- Group VMs by role→ASG(Reusable source)
- Enforce rule tenant-wide→Security admin rule(Beats NSG)
- Filter outbound FQDN→Azure Firewall(Application rule)
- Inspect encrypted egress→Firewall Premium(TLS inspection)
- Block SQL injection→WAF(Prevention mode)
- Reach PaaS privately→Private endpoint(Private IP)
- Offer your own service→Private Link service
- Retire the VPN→Entra Private Access(Per-app access)
- Rule not applying→Network Watcher(Effective rules)
Storage Account Security
- User delegation SAS
- Signed by Entra credentialsBest
- Service SAS
- One service, account key
- Account SAS
- Many services, account key
- Stored access policy
- Revoke a service SAS
- Disable Shared Key
- Forces Entra authorization
- Storage firewall
- Default deny public networks
- Trusted services
- Exception for Azure platform
- Defender for Storage
- Malware and exfiltration alerts
- Sensitive data detection
- Prioritizes alerts by sensitivity
NSG Default Priorities
65000 VNet | 65001 edge | 65500 deny
Azure Firewall vs WAF
Azure Firewall
- Network and FQDN egress
- DNAT, network, application
- IDPS on Premium
WAF
- Inbound HTTP inspection
- SQL injection and XSS
- Gateway or Front Door
Egress vs web requests
Azure SQL Security
- TDE
- Encrypts at rest, default
- TDE with CMK
- Key Vault wraps key
- Always Encrypted
- Client-side column encryption
- Dynamic data masking
- Hides values in results
- Row-level security
- Filters rows per user
- Ledger
- Tamper-evident change proof
- Server firewall rule
- Applies to all databases
- SQL auditing
- Storage, Log Analytics, Event Hubs
- Entra-only auth
- Blocks SQL logins
- Defender for SQL
- Vulnerability assessment plus alerts
Private Endpoint vs Service Endpoint
Private endpoint
- Private IP in VNet
- Reachable from on-premises
- Needs private DNS
Service endpoint
- Source stays public IP
- Subnet scoped
- No cost, no DNS
Bring service in vs route out
NSG Default Rules
- Custom priority
- 100 to 4096
- Lower number
- Processed first, wins
- AllowVNetInBound
- Priority 65000
- AllowAzureLoadBalancerInBound
- Priority 65001
- DenyAllInbound
- Priority 65500
- AllowVnetOutBound
- Priority 65000
- AllowInternetOutBound
- Priority 65001
- DenyAllOutBound
- Priority 65500
- Stateful
- Return traffic auto-allowed
- ASG
- Groups NICs, not addresses
Firewall Rule Order
- Threat intelligence
- Runs before all rules
- DNAT rules
- Inbound translation, evaluated first
- Network rules
- Layer 3-4, after DNAT
- Application rules
- FQDN based, evaluated last
- Terminating
- First match stops processing
- Parent policy
- Beats child policy priority
- Premium SKU
- TLS inspection, IDPS, URL filtering
- IDPS Alert
- Runs parallel, logs only
- IDPS Alert and Deny
- Inline, drops matching flow
- Default action
- Deny anything unmatched
Private Access Options
- Private endpoint
- Private IP inside VNet
- Private Link service
- Publish your own service
- Service endpoint
- Subnet keeps public IP
- Private DNS zone
- Resolves FQDN to private
- Connection approval
- Automatic or manual request
- Entra Private Access
- Replaces VPN for apps
- Quick Access
- Primary FQDN and IP set
- Network Watcher
- Shows effective security rules
Security Admin Rules
- Owner
- Azure Virtual Network Manager
- Scope
- Applied at virtual network
- Order
- Evaluated before NSG rules
- Allow
- NSG rules still evaluated
- Always Allow
- Terminates, bypasses NSG
- Deny
- Terminates, drops traffic
- Priority
- 1 to 4096
- One config per region
- Use multiple rule collections
AI Security Stack
Discover -> Identity -> Guardrail -> Detect
Agent ID vs Managed Identity
Entra Agent ID
- Identity for AI agents
- Blueprints create agents
- Conditional Access applies
Managed identity
- Identity for Azure resources
- System or user assigned
- Gets RBAC roles
Agent vs resource
AI Control Picker
- Copilot sees too much→Purview DSPM for AI
- SharePoint oversharing→Data risk assessment
- Agent needs an identity→Entra Agent ID
- Limit agent access→Conditional Access(Target agents)
- Trace agent blast radius→Defender XDR
- Block jailbreak prompts→Prompt Shields(Foundry guardrail)
- Cap model token spend→APIM token limit
- Alert on AI attacks→Defender for AI Services
- Watch AI posture→Data and AI dashboard
Security for AI
- Purview DSPM for AI
- Copilot and AI data risk
- Data risk assessment
- Finds SharePoint oversharing
- Restricted Content Discovery
- Hides sites from Copilot
- Agent runtime protection
- Copilot Studio security status
- Entra Agent ID
- Identities for AI agents
- Agent identity blueprint
- Template creating agent identities
- Conditional Access for agents
- Blocks or limits agents
- Risky Agents report
- Agent risk from ID Protection
- Defender XDR
- Agent blast radius analysis
- Microsoft 365 admin center
- Where agents are managed
AI Guardrails
- Foundry guardrails
- Filters for models and agents
- Prompt Shields
- Detects prompt injection attacks
- User prompt attack
- Direct jailbreak attempt
- Document attack
- Indirect injection in content
- Spotlighting
- Marks untrusted document text
- Intervention points
- Input, tool call, output
- Guardrail action
- Annotate or block
- Harm categories
- Hate, Sexual, Violence, Self-Harm
- Trimmed severity
- 0, 2, 4, 6
- Groundedness detection
- Flags unsupported model claims
APIM AI Gateway
- llm-token-limit
- Caps tokens per consumer
- llm-emit-token-metric
- Token metrics to Monitor
- llm-semantic-cache-lookup
- Reuses similar prompt completions
- llm-content-safety
- Moderates prompts inline
- Backend load balancer
- Round-robin, weighted, priority
- Circuit breaker
- Stops calling failing backend
- Managed identity auth
- Removes stored API keys
VM and Server Hardening
- Trusted launch
- Default for new Gen2
- Secure boot
- Only signed components boot
- vTPM
- Measures the boot chain
- Integrity monitoring
- Remote boot attestation health
- Encryption at host
- Encrypts on the host
- Azure Disk Encryption
- In-guest BitLocker or DM-Crypt
- Bastion
- RDP/SSH without public IP
- AzureBastionSubnet
- /26 or larger
- JIT VM access
- Opens ports on request
- Azure Arc
- Extends controls to hybrid
- Machine Configuration
- Enforces guest OS baselines
Containers and App Platform
- Defender for Containers
- Misconfiguration and runtime risk
- Registry scanning
- Container image vulnerabilities
- AKS hardening
- Cluster security recommendations
- App Service auth
- Built-in identity provider
- Access restrictions
- IP allow list for apps
- Functions network access
- Private endpoints, inbound rules
- Logic Apps
- Secure inputs and outputs
- WAF modes
- Detection or Prevention
- APIM policies
- Protect back-end APIs
Sentinel Retention
30 default | 730 interactive | 12 years total
Sentinel vs Defender XDR
Sentinel
- Cloud-native SIEM
- Any connector or syslog
- KQL and playbooks
Defender XDR
- Microsoft-first XDR
- Correlates Microsoft alerts
- Agent blast radius
Any source vs Microsoft
Defender Plan Picker
- Need attack paths→Defender CSPM(Paid plan)
- Need EDR only→Servers Plan 1
- Need JIT and FIM→Servers Plan 2
- Scan blobs for malware→Defender for Storage
- Database threat alerts→Defender for Databases
- Find hardcoded secrets→Defender CSPM(Secrets scanning)
- Vault access threats→Defender for Key Vault
- Container runtime risk→Defender for Containers
- Unknown internet assets→Defender EASM
- Protect AWS and GCP→Multicloud connector
CSPM Plan Split
- Foundational CSPM
- Free posture plan
- MCSB
- Default free security standard
- Secure score
- Free, based on MCSB
- Asset inventory
- Free in both plans
- Defender CSPM
- Paid advanced posture
- Attack path analysis
- Defender CSPM only
- Cloud security explorer
- Defender CSPM only
- Agentless VM scanning
- Defender CSPM only
- AI security posture
- Defender CSPM only
- Defender EASM
- Finds unprotected internet assets
Foundational vs Defender CSPM
Foundational
- Free plan
- MCSB and secure score
- Recommendations and inventory
Defender CSPM
- Paid plan
- Attack paths and explorer
- Agentless and AI posture
Score vs risk context
Defender Workload Plans
- Servers Plan 1
- Defender for Endpoint integration
- Servers Plan 2
- Adds JIT, agentless, FIM
- File integrity monitoring
- Plan 2 only
- Data ingestion benefit
- Plan 2 free allowance
- Defender for Storage
- Priced per storage account
- Malware scanning
- Billed per GB scanned
- Defender for Databases
- Azure database threat alerts
- Defender for AI Services
- Generative AI threat alerts
- Multicloud connectors
- Onboard AWS and GCP
Sentinel Setup
- Workspace
- Log Analytics is required
- Content hub
- Installs solutions and connectors
- Sentinel Reader
- Views data and incidents
- Sentinel Responder
- Adds incident management
- Sentinel Contributor
- Creates rules, manages content
- Playbook Operator
- Runs playbooks manually
- Logic App Contributor
- Creates and edits playbooks
- Automation Contributor
- Service role, not people
- Automation rule
- Orchestrates incident response
- Playbook
- Logic App workflow
Sentinel Data Collection
- Data collection rule
- Defines what AMA collects
- Syslog via AMA
- Lands in Syslog table
- CEF via AMA
- Lands in CommonSecurityLog
- Log forwarder
- Linux VM running rsyslog
- Windows Security events
- Collected through a DCR
- Custom log table
- Stores ingested custom data
- Analytics default
- 30 days interactive
- Analytics maximum
- 730 days interactive
- Basic and Auxiliary
- Fixed 30-day interactive
- Total retention
- Up to 12 years
Security Copilot
- SCU
- Security compute unit
- Provisioned capacity
- Baseline, billed hourly
- Overage capacity
- Absorbs usage spikes
- Capacity calculator
- Estimates SCUs needed
- Owner role
- Changes capacity units
- Plugins
- Extend Copilot data sources
- Workspace
- Where capacity is associated
Common Traps
Sign in vs act
Entra ID authenticates ≠ Azure RBAC authorizes
Eligible vs active
Eligible needs activation ≠ Active works immediately
Soft delete vs purge protection
Soft delete always on ≠ Purge protection is optional
Allow vs Always Allow
Allow still hits NSG ≠ Always Allow skips NSG
Private vs service endpoint
Private endpoint gets private IP ≠ Service endpoint keeps public IP
Firewall vs WAF
Firewall filters network egress ≠ WAF inspects HTTP requests
Servers Plan 1 vs 2
Plan 1 is EDR ≠ Plan 2 adds JIT
Free vs paid posture
Foundational gives secure score ≠ Defender CSPM gives attack paths
Detection vs prevention
Detection only logs ≠ Prevention blocks the request
Masking vs encryption
Masking hides query output ≠ Always Encrypted protects stored data
Last Minute
- 1.Storage, database, network is heaviest: 25-30%
- 2.Other three areas: 20-25% each
- 3.Pass = 700 of 1000
- 4.Entra authenticates; Azure RBAC authorizes
- 5.PIM eligible means activate first
- 6.Key Vault soft delete: 7-90 days
- 7.Purge protection is not default
- 8.NSG deny-all inbound is 65500
- 9.Firewall: DNAT, network, then application
- 10.Always Allow bypasses NSG rules
- 11.Private endpoint = private VNet IP
- 12.WAF stops HTTP attacks, not egress
- 13.JIT needs Defender Servers Plan 2
- 14.Attack paths need paid Defender CSPM
- 15.DSPM for AI finds Copilot oversharing
- 16.Prompt Shields block jailbreak and injection
- 17.Entra Agent ID identifies AI agents
- 18.Sentinel default retention: 30 days
Explore More Microsoft Azure Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.
