
If you started AZ-500 prep this year, the first fact to absorb is that the AZ-500 and the Azure Security Engineer Associate certification retired on August 31, 2026, and Microsoft now routes security engineer candidates to a successor exam. Your preparation effort is not wasted: the underlying Azure security skills still carry over, but the exam that validates them has changed, and continuing to drill retired objectives wastes study hours. This guide explains what changed, what the replacement exam covers, and how to convert an AZ-500 study plan into an SC-500 plan in a single pass.
Why AZ-500 prep changed
Microsoft restructured its certification portfolio in 2026 to fold AI-era skills into role-based credentials. As part of that overhaul, Microsoft replaced it with the Cloud and AI Security Engineer Associate certification and its Exam SC-500, positioning the new credential as the direct successor for engineers who implement and monitor security controls across Azure, hybrid, and AI workloads. The official retirement notice on the Azure Security Engineer Associate certification page confirms that neither the exam nor the renewal assessments can be earned after the retirement date.
Three practical consequences follow. First, if you already earned the AZ-500 credential, it remains valid on your transcript until it expires; retirement does not revoke earned certifications. Second, if you were registered before the exam retired, you could still sit it while seats existed, but a failed attempt after retirement cannot be retaken. Third, if you had not yet registered, Microsoft’s guidance is explicit: prepare for the successor exam instead of the retired one.
What SC-500 covers
The SC-500 exam, Implementing End-to-End Security Controls for Cloud and AI Workloads, keeps the Azure security core you were already studying and adds explicit AI-workload security objectives. According to the official SC-500 study guide, Secure storage, databases, and networking carries the largest weight at 25–30%, ahead of three domains weighted 20–25% each:
| Domain | Weight | Representative skills |
|---|---|---|
| Manage identity, access, and governance | 20–25% | Entra ID, PIM, conditional access, Key Vault, Azure Policy, RBAC remediation |
| Secure storage, databases, and networking | 25–30% | Storage firewalls, Azure SQL auditing, NSGs, private endpoints, Azure Firewall |
| Secure compute | 20–25% | VM and App Service hardening, Defender plans, AI agent and Foundry guardrails |
| Manage and monitor security posture | 20–25% | Defender for Cloud, secure score, Microsoft Cloud Security Benchmark, Sentinel |
The structural story is simple: identity, platform, compute, and posture domains are evenly balanced, with data and network security slightly ahead. The genuinely new material sits inside the compute domain, where the guide lists securing Microsoft Copilot Studio agents, Microsoft Entra Agent ID conditional access, Defender for AI Service, and AI Gateway configuration in Azure API Management for Microsoft Foundry. An AZ-500 candidate who ignored AI security topics entirely will need roughly two extra weeks; a candidate who followed Defender for Cloud developments needs far less.
Scoring follows the standard Microsoft rule: a scaled score of 700 or greater is required to pass, on a scale that runs to 1000. If an attempt fails, Microsoft’s retake policy lets you schedule again 24 hours after the first attempt, with longer waits for subsequent retakes, so a failed first sitting does not derail a tight schedule.
Study plan for SC-500
Here is an eight-week conversion plan that reuses your AZ-500 prep materials and fills the AI-security gap. Follow it in order, because the later weeks assume hands-on tenant access set up in week one.
- Weeks 1–2, identity and Key Vault: rebuild your Entra ID lab, drill PIM assignments, conditional access policies, managed identities, and Key Vault firewall configuration. This is the domain AZ-500 veterans find most familiar.
- Weeks 3–4, data and network: configure storage firewalls and private endpoints, enable database auditing on Azure SQL, and practice evaluating effective security rules with Network Watcher. This is the highest-weighted domain, so protect two full weeks for it.
- Weeks 5–6, compute and the AI gap: harden VMs and App Service, then work through the new objectives: Copilot Studio agent protection, Entra Agent ID access management, Defender for AI Service enablement, and Foundry guardrails. Treat this block as net-new study time.
- Week 7, posture: map your environment against the Microsoft Cloud Security Benchmark, remediate secure score findings in Defender for Cloud, and review backup security controls.
- Week 8, exam simulation: do a full timed practice pass, revisit every missed objective in the study guide, and confirm your exam-day setup with Microsoft’s exam sandbox.
Track readiness with a simple checklist before booking: can you configure PIM end to end, deploy a private endpoint, explain Defender for AI Service enablement, remediate an overprivileged RBAC assignment, and interpret a secure score recommendation? When all five answers are yes without documentation open, schedule the exam.
Practice resources that transfer
Most of your existing materials remain useful. Microsoft Learn modules on Entra ID, Key Vault, Defender for Cloud, and network security map almost one to one onto SC-500 objectives, and hands-on labs transfer completely. Retire anything organized around the old AZ-500 skills outline percentages, since the domain weights changed. If you want a model for how structured certification practice pays off on Microsoft exams, the discipline shown in our PL-300 practice series part one applies directly to SC-500 preparation as well, and the rotation strategy in PL-300 practice part three shows how to recycle missed questions into targeted review. Microsoft’s Skills Hub announcement is the reference to monitor for go-live dates and any beta-to-GA changes to SC-500.