Skip to content

Microsoft Certified — Cloud and AI Security Engineer Associate (SC-500)

The exam that replaced AZ-500 in 2026 — Entra identity, Key Vault, storage and network security, Defender for Cloud and Sentinel, plus a new block on securing AI workloads, agents and Copilot.

Microsoft
Exam cost
Microsoft does not publish a fixed figure — the certification page states only that price is based on the country or region in which the exam is proctored. The standard United States price for an associate-level exam is $165 USD, confirmed at booking
src
Microsoft Learn — Cloud and AI Security Engineer Associate certification page (learn.microsoft.com/credentials/certifications/cloud-and-ai-security-engineer-associate)
chk
Duration
120 minutes
Passing score
700 out of 1,000
Valid for
12 months, renewable free of charge via an online assessment on Microsoft Learn

AZ-500 retired on 31 August 2026. If you were studying for it, that work is not wasted — but the certification is gone and this is the exam that replaced it.

SC-500 leads to the Cloud and AI Security Engineer Associate credential. There is no automatic conversion from AZ-500, no upgrade route and no discount. You sit the new exam or you have neither.

What actually changed

Most of AZ-500 survived. Entra identity, Key Vault, storage and database security, network controls, Defender for Cloud and Sentinel are all still examinable and largely unchanged.

The addition is AI workload security, and it is substantial: Copilot data exposure through Purview DSPM, Microsoft Entra Agent ID with conditional access and blast-radius analysis, Defender for AI Service, AI Gateway in API Management, guardrails in Foundry.

One quieter change worth noting: Microsoft now lists familiarity with Microsoft 365 administration as an expected prerequisite. AZ-500 did not. If your experience is purely Azure infrastructure, that is a real gap.

The trap in the domain list

The AI security material does not have its own domain. It sits inside Secure compute alongside VM and container security, which means someone budgeting study time from the four domain headings will not see it and will under-plan it.

It is also the reason the exam exists. Skipping it is the most likely way to fail.

Where the marks are

Secure storage, databases and networking is the heaviest at 25–30%. The other three domains are 20–25% each — a deliberately flat distribution.

Those are ranges, not fixed percentages, because that is how Microsoft publishes them. The figures shown above are the midpoints scaled to sum to 100, which keeps every one inside its official range. Microsoft's ranges are the authoritative source and this page does not pretend otherwise.

Who it is for

Cloud security engineers working in a Microsoft shop, which is the honest boundary. This is the first mainstream security certification to treat AI workload security as a serious block of examinable material rather than a paragraph, and that makes it genuinely interesting to anyone on the AI security path.

But it examines that material entirely through Microsoft's products. The underlying concepts — agent identity, blast radius, data exposure through an assistant — transfer anywhere. Entra Agent ID and Defender for AI Service do not.

Before you book

Renewal is free and annual. Microsoft associate certifications expire after twelve months and renew through a free online assessment on Microsoft Learn. Compared with the CNCF exams, which require paying for and sitting the full exam again every two years, this is the cheapest maintenance model of any certification on this site.

700 out of 1,000 to pass, on Microsoft's standard scaled model, in 120 minutes.

Microsoft does not publish a fixed price. The certification page says only that it depends on where the exam is proctored. The $165 figure quoted everywhere is the standard United States associate rate; confirm yours at booking.

Your progress0%

Exam domains

Secure storage, databases, and networking

29%
Security for storage accounts, firewall rules and access policiesDefender for Storage threat protectionPlatform-level security and auditing in Azure SQLNetwork security groups and application security groupsAzure Virtual Network Manager and Virtual WAN securityPrivate endpoints, Private Link and Microsoft Entra Private AccessAzure Firewall and effective rule evaluation with Network Watcher

Manage identity, access, and governance

24%
Privileged Identity Management and Conditional AccessMultifactor and passwordless authenticationEnterprise applications, app registrations and consentManaged identities for Azure resourcesKey Vault deployment, access and firewall settingsAzure Policy, resource locks and RBAC remediationSecurity controls delivered as infrastructure as code

Secure compute

24%
Security for AI — Copilot risk, Purview DSPM, Defender for AI ServiceMicrosoft Entra Agent ID, conditional access and blast-radius analysisAI Gateway in API Management and guardrails in FoundryDisk encryption, Azure Bastion and just-in-time VM accessDefender for Servers, including agentless scanning and EDRDefender for Containers, AKS and Container Registry controlsApp Service, Functions, Logic Apps and Web Application Firewall

Manage and monitor security posture

23%
Defender CSPM and compliance evaluationDefender for Cloud workload protection plansConnecting AWS and GCP to Defender for CloudExternal Attack Surface ManagementMicrosoft Sentinel workspaces, connectors and analytics rulesAutomation rules, playbooks and data retention in SentinelMicrosoft Security Copilot workspaces, plugins and agents

Preparation path

  1. 1

    Confirm you are studying for this exam and not AZ-500

    AZ-500 retired on 31 August 2026 and the Azure Security Engineer Associate certification can no longer be earned. There is no automatic conversion — SC-500 is a separate exam. Most Azure security material in circulation still targets AZ-500, and roughly a fifth of this syllabus did not exist there.

    ~2 hours
  2. 2

    Work the storage, database and networking block first

    At 25–30% it is the heaviest domain, and it is the one that carried over from AZ-500 almost unchanged. If you have AZ-500 study behind you this is where it still pays; if you do not, it is the largest single block of marks on the exam.

    ~25 hours
  3. 3

    Learn Entra identity properly, because everything else rests on it

    Identity, access and governance is 20–25%, and in Azure it is where security is actually won or lost. Privileged Identity Management, Conditional Access, managed identities and app consent are the recurring subjects, and they reappear inside the AI block as Agent ID.

    ~22 hours
  4. 4

    Study the AI security block, which has no AZ-500 equivalent

    Copilot data exposure, Purview DSPM, Entra Agent ID, Defender for AI Service, AI Gateway and Foundry guardrails. It sits inside Secure compute rather than standing alone, so it is easy to miss when planning study time — and it is the reason this exam exists.

    ~20 hours
  5. 5

    Get hands-on with Defender for Cloud and Sentinel

    Posture management is 20–25% and it is operational rather than conceptual. Connect a subscription, read the secure score, wire a Sentinel connector and write an analytics rule. Security Copilot is now examinable here too, which is new.

    ~20 hours

Frequently asked questions

Career Roadmaps