1.1 Azure Security Engineer Role & Exam Logistics
Key Takeaways
- Exam AZ-500 and the Azure Security Engineer Associate certification retire on August 31, 2026 at 11:59 PM Central Standard Time.
- AZ-500 gives you 100 minutes of exam time within a 120-minute seat time, and requires a scaled score of 700 out of 1000 to pass.
- The current skills measured, dated January 22, 2026, weight Defender for Cloud and Sentinel highest at 30–35% and identity lowest at 15–20%.
- Most Microsoft certification exams contain 40–60 items, and case studies plus problem-solution sets cannot be revisited once you leave them.
- Data classification, identities, and client endpoints stay the customer’s responsibility in IaaS, PaaS, and SaaS alike.
1.1 Azure Security Engineer Role & Exam Logistics
The Microsoft Certified: Azure Security Engineer Associate (AZ-500) certification validates modern cybersecurity engineering capabilities within Microsoft Azure and hybrid cloud environments. An Azure Security Engineer is responsible for implementing security controls, maintaining security posture, managing identity and access, protecting data and applications, and executing threat management across cloud deployments.
Retirement Notice You Must Plan Around
Microsoft has announced that Exam AZ-500 and the Microsoft Certified: Azure Security Engineer Associate certification retire on August 31, 2026 at 11:59 PM Central Standard Time. After that date you can no longer earn the credential, and the annual renewal assessment also stops. If you already hold the certification, it stays on your transcript and remains valid until its existing expiration date. Two practical consequences:
- Schedule early. Pearson VUE seats for retiring exams get scarce in the final weeks, and a failed first attempt still costs you a 24-hour wait before a retake.
- Do not skip the current outline. Microsoft refreshed the skills measured on January 22, 2026, and the retiring exam is delivered against that refreshed outline — not against the older 2023-era objectives that most third-party courses still teach.
AZ-500 Exam Structure & Logistics
Understanding the exam mechanics, timing, scoring methodology, and structural parameters is critical for strategic preparation.
Key Exam Facts & Parameters
- Exam Code: AZ-500
- Title: Microsoft Azure Security Technologies
- Number of Questions: 40 to 60 questions (varies per exam seating)
- Exam Duration: 100 minutes of exam time. Microsoft’s exam duration table lists 120 minutes of seat time for associate role-based exams of this length, which adds the instructions, the Candidate Agreement, and the optional post-exam comment period. Five of the 100 minutes are built in as break time — the clock does not stop when you take a break.
- Passing Score: 700 out of 1000 (scaled score; not a simple raw percentage calculation). Microsoft does not publish per-domain minimums — the 700 is a single overall bar.
- Exam Cost: Priced by the country or region where the exam is proctored; the United States list price for associate role-based exams is US$165. Confirm the exact amount shown at Pearson VUE checkout, because Microsoft does not publish a global price table.
- Retake Policy: 24-hour wait for the second attempt; 14-day wait for each subsequent attempt, with a maximum of five attempts in any 12-month period.
- Open-book element: Associate role-based exams give you a split-screen window into
learn.microsoft.comduring the exam (Q&A, practice assessments, and your profile are blocked). No extra time is added, so treat it as a lookup of last resort — a candidate who searches every item will run out of clock by design.
Question Item Formats
The AZ-500 exam employs a range of item types designed to test both high-level design principles and granular implementation CLI/PowerShell syntax:
- Standard Multiple-Choice: Single-answer or multiple-select questions assessing concepts and tool capabilities.
- Drag-and-Drop / Matching: Pairing security controls, role assignments, or permission scopes with specific organizational requirements.
- Build-List / Sequence: Ordering step-by-step procedures, such as configuring Microsoft Entra Privileged Identity Management (PIM) or setting up Azure Key Vault customer-managed keys (CMK).
- Hotspot: Selecting active UI elements, drop-down configuration menus, or architectural topology nodes from captured portal interfaces.
- Case Studies: Comprehensive business scenarios detailing technical background, business requirements, security compliance goals, and current environment constraints. Critical Exam Fact: Case Study sections are self-contained. Once you submit a Case Study section and move to the next portion of the exam, you cannot return to review or edit answers in that Case Study.
- Scenario Yes/No Series: A consecutive series of independent questions presenting the same scenario but different candidate solutions. You cannot return to previous questions once answered in these series.
Official Blueprint Domain Weightings
The AZ-500 examination evaluates technical competency across four primary domain areas. Study effort should be allocated according to these domain weights:
These are the four functional groups published in the skills measured dated January 22, 2026. Use these exact names and ranges; older courseware still shows a four-domain split that begins "Manage identity and access (30–35%)" and ends "Manage security operations", and those weights no longer exist.
| Functional Group | Official Weighting | Primary Technical Focus Areas |
|---|---|---|
| 1. Secure identity and access | 15–20% | Azure built-in and custom role assignments, Entra custom roles, PIM for Azure resources, MFA, Conditional Access, enterprise applications and OAuth permission grants, app registrations and consent, service principals, managed identities |
| 2. Secure networking | 20–25% | NSGs and ASGs, Virtual Network Manager, UDRs, peering and VPN gateway, Virtual WAN and secured hub, ExpressRoute encryption, Network Watcher, Service Endpoints, Private Endpoints and Private Link, App Service/Functions/ASE/SQL MI network integration, TLS, Azure Firewall, Application Gateway, Front Door and CDN, WAF, DDoS Protection |
| 3. Secure compute, storage, and databases | 20–25% | Bastion and JIT VM access, AKS isolation/authentication/monitoring, ACI and Container Apps monitoring, ACR access, disk encryption (ADE, encryption at host, confidential), API Management recommendations, storage access control and keys, Azure Files and Blob access, soft delete/versioning/immutable storage, BYOK and infrastructure encryption, SQL Entra authentication, auditing, dynamic masking, TDE, Always Encrypted |
| 4. Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel | 30–35% | Azure Policy definitions and initiatives, Key Vault network and access configuration, certificate/secret/key lifecycle and rotation, backup protection, asset management, Secure Score and Inventory, compliance and custom standards, AWS/GCP connectors, Defender EASM, workload protection plans, agentless scanning, Defender Vulnerability Management, DevOps security, alerts and workflow automation, Azure Monitor data collection rules, Sentinel connectors, analytics rules, and automation |
Exam Tip: The Defender for Cloud and Sentinel group is the single largest at 30–35% — roughly one question in three. Candidates routinely over-invest in identity because it used to be the heaviest domain; on the current outline identity is the smallest group at 15–20%. Rebalance your study hours accordingly.
Exam Tip: Microsoft also states that most items cover generally available (GA) features, and that Preview features appear only when they are commonly used. When two answers are both technically possible, prefer the GA service over the preview capability.
Candidate Prerequisites & Core Responsibilities
Microsoft recommends candidate expertise in scripting languages (PowerShell, Azure CLI, Kusto Query Language - KQL), identity management, security architecture, and automation.
Practical Prerequisites
- Identity & Governance: Deep working knowledge of tenant administration, authentication protocols (OAuth 2.0, OpenID Connect, SAML), and Microsoft Entra ID governance.
- Networking Foundations: Experience with CIDR subnetting, routing tables (UDRs), virtual network peering, and perimeter inspection.
- Automation Skills: Ability to read and write Azure Resource Manager (ARM) templates, Bicep syntax, Azure CLI commands, and PowerShell modules (
Az.Security,Az.Resources). - Threat Hunting: Familiarity with Log Analytics workspaces and writing basic to intermediate KQL queries (
search,where,summarize,join).
Core Responsibilities of an Azure Security Engineer
- Enforcing Zero Trust identity boundary controls across human and non-human identities.
- Designing resilient network micro-segmentation to restrict lateral movement.
- Hardening host, container, and database workloads against zero-day threats and vulnerability exploitation.
- Monitoring centralized cloud log streams to detect, isolate, and remediate cybersecurity incidents.
The Cloud Shared Responsibility Model
Security in the cloud is a shared partnership between the cloud customer and Microsoft. The exact distribution of responsibilities depends directly on whether the service model is On-Premises, Infrastructure as a Service (IaaS), Platform as a Service (PaaS), or Software as a Service (SaaS).
Core Responsibility Division
- Always Owned by Customer (Across All Models):
- Data classification, tagging, and accountability
- Client endpoints (laptops, mobile devices, IoT)
- User accounts, identities, credentials, and access management (IAM)
- Always Owned by Microsoft (Across All Cloud Models):
- Physical datacenter facilities (building security, biometric gates, perimeter fencing)
- Physical hardware servers, racks, and power infrastructure
- Physical host network infrastructure (switches, cabling, routers)
- Variable Responsibility (Model-Dependent):
- Operating systems (OS patching, baseline configuration)
- Network controls (virtual firewalls, subnets, routing)
- Application runtimes, middleware, and database engines
Comparison of Responsibility across Cloud Deployment Models
| Architectural Layer | On-Premises | IaaS (e.g., Azure VMs) | PaaS (e.g., App Service, SQL) | SaaS (e.g., Microsoft 365) |
|---|---|---|---|---|
| Data & Information | Customer | Customer | Customer | Customer |
| Endpoints & Devices | Customer | Customer | Customer | Customer |
| Accounts & Identity | Customer | Customer | Customer | Customer |
| Application Security | Customer | Customer | Customer | Shared (Config / Microsoft) |
| Network Controls | Customer | Customer | Shared (Virtual Rules) | Microsoft |
| Operating System | Customer | Customer | Microsoft | Microsoft |
| Hypervisor / Host | Customer | Microsoft | Microsoft | Microsoft |
| Physical Datacenter | Customer | Microsoft | Microsoft | Microsoft |
In IaaS, you deploy Virtual Machines and have full OS administrator access. Consequently, you are responsible for applying OS security updates, managing antivirus/endpoint detection, and configuring host firewalls. In PaaS, Microsoft manages the underlying OS and runtime environment, allowing you to focus on application code and data security. In SaaS, Microsoft manages the host, OS, and software platform, while you retain ownership of data governance, identity, and endpoint access settings.
Which component of cloud security remains the sole responsibility of the customer across all cloud service models (IaaS, PaaS, and SaaS)?
What is the passing score requirement for the Microsoft AZ-500 certification exam?
In the AZ-500 exam structure, how are Case Study questions handled regarding navigation?
According to the AZ-500 skills measured dated January 22, 2026, which functional group carries the highest weighting, and what is its range?