Microsoft Azure Security Engineer [AZ-500] Exam Guide (2026)
![Microsoft Azure Security Engineer [AZ-500] Exam Guide (2026)](/_next/image?url=https%3A%2F%2Fcdn.sanity.io%2Fimages%2F2oo9oqu3%2Fproduction%2F90bbd25585d94a6d8e1d1862481bac8376bae8b5-1600x813.png%3Frect%3D78%2C0%2C1445%2C813%26w%3D1200%26h%3D675&w=3840&q=75)
If you can say whether a privileged role should sit as eligible in Privileged Identity Management or as a permanent assignment, why an NSG does not stop a SQL injection, and whether a finding belongs on Secure Score or in a Microsoft Sentinel analytics rule, you are reading the right outline.
AZ-500 is the exam behind Microsoft Certified: Azure Security Engineer Associate. The credential page marks it intermediate, Azure, security engineer role, with a last updated date of 22 January 2026. The study guide publishes the matching skills outline under the heading Skills measured as of January 22, 2026. That outline is the whole scope of the last sitting.
The same study guide marks the exam retired on 31 August 2026 at 11:59 PM Central Standard Time. The credential page states that the certification, the exam, and the renewal assessments retired on that date, and that the credential can no longer be earned or renewed. This guide is for people who sat that January 2026 blueprint, who still hold the title, or who need the last published task list before moving to the current associate security sitting, Microsoft Certified: Cloud and AI Security Engineer Associate.
Who this exam is for
Take it as a map of the last Azure security-engineer job Microsoft scored under this code. The audience profile asks for subject matter expertise implementing, managing, and monitoring security for resources in Azure, multi-cloud, and hybrid environments as part of an end to end infrastructure. The engineer implements and manages security components with Microsoft Defender for Cloud and other tools, and keeps that infrastructure aligned with standards such as the Microsoft Cloud Security Benchmark.
The responsibility list is concrete. Managing the security posture. Implementing threat protection. Identifying and remediating vulnerabilities. The same person implements regulatory compliance controls across identity and access, network, compute, storage, data, applications, asset management, backup and recovery, and DevOps security. Microsoft is explicit that the role sits with architects, administrators, and developers, and that it may also work with security operations when an incident lands in Azure.
The prerequisite list is a gap check. Practical experience administering Microsoft Azure and hybrid environments. Strong familiarity with Microsoft Entra ID, and with compute, network, and storage in Azure. If those four platform areas are things you have only read about, the sitting will feel like a product catalog rather than a job test.
Skip it if the goal is the language of the cloud rather than the hardening of it. Service definitions, pricing models, and shared responsibility belong to AZ-900. Skip it if the work you actually want is running someone else's subscription day to day without owning the security controls, because that job is AZ-104. Governance appears here as Policy, Key Vault, backup protection, and Secure Score, not as a landing zone an architect invents.
The current associate security credential Microsoft publishes is SC-500. That sitting adds AI workload protection and Microsoft 365 familiarity on top of the same identity, network, compute, and posture core. Use this page for the AZ-500 task list. Use the SC-500 credential page and study guide when the next sitting is the one being scheduled.
Exam shape and how the score works
The January 2026 outline has four functional groups, and Microsoft publishes weight ranges rather than fixed percentages.
| Skill area | Weight | What gets tested |
|---|---|---|
| Secure identity and access | 15 to 20% | Built-in and custom roles, PIM settings and assignments, MFA, Conditional Access, app registrations, OAuth consent, service principals, managed identities |
| Secure networking | 20 to 25% | NSGs and ASGs, Virtual Network Manager, UDRs, peering and VPN, Virtual WAN, ExpressRoute encryption, service endpoints, private endpoints, Private Link, App Service and ASE and SQL Managed Instance network integration, TLS, Azure Firewall, Application Gateway, Front Door, WAF, DDoS Protection Standard, Network Watcher |
| Secure compute, storage, and databases | 20 to 25% | Bastion, JIT VM access, AKS isolation and authentication, container monitoring, ACR access, disk encryption, storage keys and identity, soft delete, versioning, immutable storage, BYOK, double encryption, Entra database authentication, auditing, dynamic masking, TDE, Always Encrypted |
| Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel | 30 to 35% | Azure Policy, Key Vault access and rotation, Secure Score, compliance standards, hybrid and AWS and GCP connectors, EASM, Defender workload plans, agentless scanning, vulnerability management, DevOps Security, Defender alerts and workflow automation, Monitor data collection rules, Sentinel connectors, analytics rules, automation |
Do the arithmetic on those ranges before building a plan. The lower bounds total 85%. The upper bounds total 105%. The midpoints total 95%. No exact split exists to memorize, and the bands are the only ordering Microsoft gives you. Defender for Cloud and Sentinel sit alone at the top. Networking ties with compute, storage, and databases in the middle. Identity sits alone at the bottom. Any study plan that gives four equal weeks overweights identity and underweights posture.
The logistics come off the credential page and the duration table. The sitting was proctored, scheduled through Pearson VUE while it was live, and the page warns that the exam may have interactive components. Price depended on the country or region where the exam was proctored, so no single global figure was published. Languages were English, Japanese, Chinese (Simplified), Korean, German, French, Spanish, Portuguese (Brazil), Chinese (Traditional), and Italian. A failed attempt could be retaken 24 hours later, and the wait varied for later retakes.
The credential page published 100 minutes for the assessment while the exam was live. After retirement the schedule block is gone from the live HTML. That 100 minute figure matches Microsoft's row for associate and expert role-based exams without labs, which lists 100 minutes of exam time and 120 minutes of seat time. Associate exams that may contain labs are listed at 120 minutes with 140 minutes of seat time. Microsoft states plainly that it does not publish a list of exams with labs, because labs can be pulled at any time for an outage or a bandwidth problem, and that the real exam time is confirmed at registration and on the launch screens. Plan for interactive components. Do not plan for a lab timer that Microsoft did not give you.
Scoring is the part most candidates get wrong. Technical exam scores are reported on a scale of 1 to 1,000 and 700 or greater passes. Microsoft says outright that the scaled score is not 70 percent of the points, because the passing standard reflects question difficulty. Multi-part questions usually award one point per correctly answered component, so all, some, or none of the points on a question are possible. There is no penalty for guessing. Some questions are unscored and used to collect data, and candidates are never told which, so every question deserves an answer.
The score report gives one overall number, a pass or fail status, and a bar chart per skill area. It does not give a numeric score per section, and Microsoft warns that the bars cannot be added up to reconstruct the result. A short bar in a small area can mean a handful of questions went wrong, and scoring zero in an area that carries only a few questions is documented as normal. Identity at 15 to 20% is the area where a short bar is easiest to misread as a catastrophe.
Two more details change how the last sittings were taken. Microsoft Learn is available in a split screen during role-based exams, covering everything on learn.microsoft.com except Q&A, practice assessments, and your profile, with no extra time added and no navigation outside the domain. Five minutes of break time are built into the clock, questions were removed to make room for it, and any question you have already seen is gone once the break starts.
The credential itself followed the associate renewal rule while the exam was live. Associate certifications expire annually. Renewal was free, unproctored, open book, and shorter than the original exam, inside a six month window before expiry. The credential page now states that those renewal assessments retired with the exam on 31 August 2026.
What changed on 22 January 2026
The study guide publishes a change log comparing the previous outline with the current one. The full table is short.
| Skill area prior to 22 January 2026 | Skill area as of 22 January 2026 | Change |
|---|---|---|
| Secure identity and access | Secure identity and access | No change |
| Manage Microsoft Entra application access | Manage Microsoft Entra application access and managed identities | Minor |
| Secure compute, storage, and databases | Secure compute, storage, and databases | No change |
| Plan and implement advanced security for compute | Plan and implement advanced security for compute | Minor |
| Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel | Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel | No change |
| Configure and manage threat protection by using Microsoft Defender for Cloud | Configure and manage threat protection by using Microsoft Defender for Cloud | Minor |
Three things are true of that table, and each one changes what you should do with older study material.
Every functional group listed is marked No change. Nothing on the table is marked Major. The exam code did not move, the four areas did not move, and the published weight ranges are the ones above. AZ-500 material written against the previous outline is still structurally correct.
Every sub-area listed is marked Minor. The touched sub-areas are Microsoft Entra application access, now titled with managed identities, advanced security for compute, and threat protection in Defender for Cloud. Those are exactly the places where Azure ships new capability fastest, so treat them as refresh work rather than relearning. Microsoft adds that most questions cover features that are generally available, and that preview features can appear when they are commonly used.
The table carries no row at all for Secure networking. Identity, compute, and Defender each appear. The joint-middle area is the one the change log leaves out entirely. NSGs, private endpoints, Azure Firewall, WAF, and Front Door behave on the last exam the way they behaved on the previous one, which makes that area the cheapest place to bank points and the least excusable place to lose them.
How an identity control actually lands
Identity is the lightest area at 15 to 20%, and most of its questions reduce to a single skill: naming whether the stem is about who may act, whether that person must activate first, or whether a signal after first-factor authentication still blocks them.

Azure RBAC still has four scope levels: management group, subscription, resource group, and resource. They form a parent and child hierarchy, each level down is more specific, and lower levels inherit role permissions from higher levels. A role assigned at a management group reaches every subscription inside it. A role assigned at a resource reaches nothing else. When a stem describes a security team that needs the same access across several subscriptions, the answer is almost always one assignment higher up the tree rather than several assignments lower down.
Privileged Identity Management sits on top of that assignment. An eligible assignment requires the user to activate before the role can be used. An active assignment does not. Microsoft states there is no difference in the access given to someone with a permanent assignment versus an eligible one. The only difference is that some people do not need that access all the time. Activation can require multifactor authentication, a business justification, and approval, and it lasts for a preconfigured period. The four duration shapes are permanent eligible, permanent active, time-bound eligible, and time-bound active. A stem that wants standing Owner on a production subscription is asking for a different answer than a stem that wants Owner for four hours after an approver signs off.
Who may manage those assignments depends on the plane of the role. For Microsoft Entra roles, only Privileged Role Administrator or Global Administrator can manage assignments for other administrators. For Azure resource roles, only a subscription administrator, a resource Owner, or a User Access Administrator can. Privileged Role Administrator does not, by default, see Azure resource role assignments in PIM. A stem that hands an Entra admin a subscription Owner request is testing that split.
Conditional Access is the third control and the one that traps people who stop at MFA. Policies are if-then statements, and they run after first-factor authentication is completed. Microsoft says outright that Conditional Access is not a frontline defense for denial-of-service. Signals include user or group, IP location, device state, the application being reached, and risk from Microsoft Entra ID Protection. The grant path can require MFA, a compliant device, a hybrid joined device, an approved client app, or a password change. The block path is the most restrictive decision. Requiring MFA for Azure management tasks is a documented common policy, and it is a different control from turning on MFA in PIM activation. One asks for a second factor to sign in to the Azure portal. The other asks for a second factor to activate a privileged role the user is already eligible for.
Managed identities finish the area. A system-assigned identity is created on the resource, shares that resource's life cycle, and cannot be shared. A user-assigned identity is a standalone resource, has its own life cycle, and can be attached to more than one compute resource. Microsoft names user-assigned as the recommended type for Microsoft services. A stem about a scale set that is recycled every night while the storage role assignment must stay put is a user-assigned stem. A stem about one virtual machine that should lose its identity when the machine is deleted is a system-assigned stem. Neither one is a service principal secret you store in a pipeline.
How a network control gets picked
Networking is 20 to 25%, the change log skipped it, and the private access question shows up in storage stems, App Service stems, and database stems as often as in networking ones.

| Control | Where it sits | What it stops |
|---|---|---|
| Network security group | Subnet or network interface | Five-tuple flows, stateful, first match wins |
| Azure Firewall | Hub virtual network or secured virtual hub | East-west and north-south traffic, FQDN and threat intelligence, IDPS on Premium |
| Web Application Firewall | Application Gateway or Front Door | SQL injection, cross-site scripting, and other HTTP exploits |
| Private endpoint | One private IP in your virtual network | Public access to one instance of a PaaS service |
| Service endpoint | Subnet toward a service tag | Public endpoint kept, source address becomes the private subnet |
| Azure DDoS Protection Standard | Public IP | Volumetric floods against a public endpoint |
Read the failure the stem describes before reading the options. An NSG evaluates source, source port, destination, destination port, and protocol. Priority runs from 100 to 4096, lower numbers process first, and processing stops at the first match. Default rules sit at the highest numbers so custom rules always run first. NSGs are stateful, so a reply to an allowed flow needs no second rule. An NSG does not inspect HTTP payloads. A stem about blocking SQL injection at the edge is not an NSG stem.
Azure Firewall is the centralized, fully stateful service that inspects east-west and north-south traffic. Standard adds threat intelligence feeds. Premium adds signature-based IDPS with more than 67,000 signatures. Azure Firewall Manager is how those policies land across subscriptions, including on a secured virtual hub in Virtual WAN. Microsoft lists Firewall, DDoS Protection, and Web Application Firewall as three services in the same Network Security category, each with its own job. Picking Firewall because the stem says "security" is how that question is lost.
A WAF is the HTTP answer. It deploys with Application Gateway, Application Gateway for Containers, Front Door, and Azure CDN. SQL injection and cross-site scripting are the attacks Microsoft names first. Application Gateway is the regional Layer 7 place. Front Door is the global place, and the outline pairs it with CDN. A stem about one region and a path-based listener is Application Gateway. A stem about anycast, global failover, and a WAF policy at the edge is Front Door.
Private access is the same discriminator AZ-104 uses, scored here as a security choice. A private endpoint is a network interface that takes a private IP from your virtual network and brings one instance of a service into that network over Azure Private Link. DNS has to resolve the service host name to that private IP. The public IP of the target can stay in place while the service firewall blocks it. A service endpoint extends the virtual network to the service over the Azure backbone while the service keeps its public endpoint, and DNS entries stay as they are. Microsoft's comparison table is the whole question. A service endpoint applies to all instances of the target service. A private endpoint targets one instance and is the control that stops data being written to some other tenant's storage account. Microsoft recommends Private Link.
Remote access to virtual machines sits on the same page even though the outline files it under compute. Azure Bastion gives RDP and SSH over TLS on port 443, from the portal or a native client, and it reaches every VM in the virtual network by private IP, so those VMs need no public IP, no agent, and no special client software. Just-in-time VM access is a Defender for Servers Plan 2 feature. It writes deny-all inbound rules for the selected management ports on the NSG and on Azure Firewall, then opens those ports from a requested IP for a limited time, then puts the rules back. Connections that are already established are not interrupted. JIT does not support Azure Firewalls that Azure Firewall Manager controls. A stem about standing administrative access with no public IP is Bastion. A stem about leaving RDP closed until an approved window opens is JIT. A stem that offers both is asking you to pick the one that matches the failure.
How Defender for Cloud and Sentinel split the work
This area is 30 to 35%, the heaviest band on the outline, and it is three products taught as one heading.

Azure Policy is the governance floor. It evaluates resource properties against business rules and enforces compliance without concern for who made the change. RBAC manages who may act. Even when a person holds the permission to create a resource, Policy still blocks the create or update when the result would be non-compliant. An initiative groups definitions. An assignment targets a management group, subscription, resource group, or resource. A stem about a property that resources must or must not have is a Policy question. A stem about a person who must or must not act is an RBAC question.
Key Vault is the secret floor, and the outline names both authorization systems on purpose. Azure RBAC operates on the control plane and the data plane. Access policies operate on the data plane alone. Microsoft warns to use RBAC. With the access policy model, a user who holds Contributor, Key Vault Contributor, or any role that includes Microsoft.KeyVault/vaults/write can grant themselves data plane access to keys, secrets, and certificates. RBAC restricts that grant to Owner and User Access Administrator, and it integrates with PIM so the grant can be eligible and time-bound. Starting with API version 2026-02-01, RBAC is the default for new vaults. A stem that lets a Contributor read a secret is testing the access-policy trap. The rest of the Key Vault tasks are network settings, rotation, and backup of certificates, secrets, and keys.
Microsoft Defender for Cloud is the Cloud Native Application Protection Platform on this outline. Foundational CSPM is free and includes centralized policy, Secure Score, and connectors for AWS and GCP. Turning Defender for Cloud on a subscription applies the Microsoft cloud security benchmark by default. Secure Score aggregates those MCSB recommendations into one number. Only built-in MCSB recommendations affect the score. Preview recommendations do not. A higher score means lower identified risk. Defender CSPM adds regulatory compliance, custom standards, cloud security explorer, governance, and attack path analysis. The outline also names External Attack Surface Management and DevOps Security for GitHub, Azure DevOps, and GitLab.
Cloud workload protection is the other half of Defender for Cloud. The skills list names Defender for Servers, Defender for Databases, and Defender for Storage, agentless scanning for virtual machines, and Microsoft Defender Vulnerability Management. Alerts fire when a workload is under threat. Workflow automation is how those alerts page a group or run a Logic App without a person watching the blade. A Secure Score recommendation is a configuration that is wrong. A Defender alert is an attack that is happening. Mixing those two up is how the heaviest area is lost.
Microsoft Sentinel is the SIEM. It collects data at scale through connectors, detects threats with analytics rules that group alerts into incidents, and responds with automation rules and playbooks built on Azure Logic Apps. The outline asks for three Sentinel tasks: configure data connectors, enable analytics rules, and configure automation. A stem about correlating Entra sign-in logs with Azure Activity and a firewall log is a Sentinel connector and analytics stem. A stem about a missing encryption-at-host recommendation on twenty virtual machines is a Secure Score stem. Both can page someone. They are not the same product.
The split that decides most questions in this band is the type of finding. Policy asks what a resource looks like. Secure Score asks how far the estate sits from the Microsoft cloud security benchmark. A Defender for Cloud alert asks whether a workload is being attacked. A Sentinel incident asks whether events from several sources add up to one attack. Read the stem twice and name the finding before you name the blade.
How to study the last blueprint
Order the weeks by the weight bands, not by the order the areas are printed in.
Week 1. Defender for Cloud and Sentinel, the 30 to 35% area. Turn Defender for Cloud on a subscription and watch the Microsoft cloud security benchmark apply. Read Secure Score, pick one unhealthy control, remediate it, and watch the number move. Add a custom standard. Connect a second cloud if you have one. Enable Defender for Servers, Defender for Storage, and Defender for Databases, and open one alert of each kind. Write one workflow automation that fires on a high-severity alert. Then stand up a Sentinel workspace. Attach the Azure Activity and Microsoft Entra ID connectors. Enable one analytics rule. Write one automation rule that opens a playbook. Finish the week in Key Vault: create a vault on Azure RBAC, assign a data-plane role at vault scope through PIM, rotate a key, and back up a secret. Repeat the same grant on a vault that still uses access policies and watch a Contributor add themselves.
Week 2. Networking, the 20 to 25% area the change log skipped. Build one hub and spoke. Put Azure Firewall in the hub, write a firewall policy in Firewall Manager, and send spoke traffic through it with a user-defined route. Attach an NSG to a spoke subnet and read the effective security rules on a network interface. Deploy Application Gateway with a WAF policy and Front Door with another, and be able to say which failure each one stops. Then reach one storage account through a service endpoint and one through a private endpoint, and watch what each does to DNS. Close the week on Bastion in AzureBastionSubnet and on JIT for a second VM, and write down which firewall SKUs JIT will not work with.
Week 3. Compute, storage, and databases, the other 20 to 25% area. Create a VM with encryption at host. Create another with ADE only if you need to see the guest-level control Microsoft is retiring on 15 September 2028. Push an image to Azure Container Registry and lock who can pull it. Turn on AKS network isolation and Microsoft Entra authentication. On storage, disable shared key access on one account, grant a user-assigned managed identity the data-plane role, turn on soft delete and versioning, then lock a container with a time-based immutability policy and try to delete a blob. On Azure SQL, enable Microsoft Entra authentication, turn on auditing, apply a dynamic mask to one column, confirm TDE is on, and encrypt a second column with Always Encrypted so the engine never sees the plaintext.
Week 4. Identity, the 15 to 20% area, and a full review. Build one eligible Owner assignment in PIM that requires MFA, justification, and approval, and one time-bound active assignment that does not. Write a Conditional Access policy that requires MFA for Azure management and a second that blocks legacy authentication. Register an application, set a permission scope, and grant admin consent. Attach a user-assigned managed identity to two compute resources and a system-assigned identity to one. Spend the rest of the week rereading the study guide task statements and naming, for each bullet, the portal blade and the CLI command that does it.
Take the free practice assessment linked from the study guide and run the exam sandbox at least once before using this outline against a clock. The sandbox exists so the question formats cost you nothing on the timer.
Traps that look like easy elimination
Associate items rarely give one plausible answer and three absurd ones. They give two controls that both sound correct and one detail that picks between them.
- An eligible PIM assignment is not standing access. The user must activate, and activation can require MFA, justification, and approval.
- Permanent and eligible grant the same permissions. The difference is whether those permissions are on all the time.
- Privileged Role Administrator manages Microsoft Entra roles in PIM. It does not, by default, manage Azure resource roles.
- Conditional Access runs after first-factor authentication. It is not a denial-of-service control.
- Requiring MFA to sign in to Azure and requiring MFA to activate a role are two different policies.
- A system-assigned managed identity dies with the resource. A user-assigned identity does not.
- A role assignment at a resource group does not reach a sibling resource group. Scope inheritance runs downward only.
- Policy governs what a resource looks like. RBAC governs who may act. A person with full permission still cannot create a non-compliant resource.
- An NSG is a five-tuple filter. It does not stop SQL injection. That is a WAF.
- Azure Firewall is the hub control for east-west and north-south traffic. A WAF is the HTTP control. DDoS Protection Standard is the volumetric control on a public IP.
- A service endpoint covers every instance of a service. A private endpoint covers one instance and needs a private DNS record to be useful.
- Bastion is standing private administrative access. JIT is a temporary hole in an NSG or Azure Firewall. JIT does not work with Firewall Manager policies.
- Server-side encryption is already on every managed disk. Encryption at host is the control that adds temp disks, caches, and the path to storage. ADE encrypts inside the guest and is scheduled to retire on 15 September 2028.
- TDE encrypts pages on disk. The engine sees plaintext in memory. Always Encrypted keeps plaintext out of the engine. Dynamic masking changes the result set and leaves the table alone.
- Soft delete and versioning recover a bad delete. Immutable storage with a locked time-based policy or a legal hold refuses the delete.
- A Key Vault access policy lets Contributor grant themselves data-plane rights. Azure RBAC does not.
- Secure Score is a posture number against the Microsoft cloud security benchmark. A Defender for Cloud alert is a threat against a workload. A Sentinel incident is a correlated investigation across connectors.
If deleting the scenario still lets you pick the answer from the service name, the question is easier than the live exam.
How this maps to CloudFluently
Start with the official material. The Microsoft Certified: Azure Security Engineer Associate credential page carries the retirement banner, the audience profile, and the assessed areas. The study guide for Exam AZ-500 carries the task statements, the weight ranges, and the change log quoted above. Exam duration and exam experience explains the associate timer, the built-in break, and the Microsoft Learn split screen. Exam scoring and score reports explains the 700 scaled pass mark and why the bar chart cannot be added up. Microsoft Certification renewal explains the annual free assessment that applied while the credential was renewable. The current associate security sitting is the Microsoft Certified: Cloud and AI Security Engineer Associate credential page and the study guide for Exam SC-500.
AZ-500 sits on top of Azure fundamentals and Azure administration, and that ground is already live here. Identity, subscriptions, resource groups, and shared responsibility are the AZ-900 Azure Fundamentals study notes and the AZ-900 Azure Fundamentals practice exam sets. The Azure Fundamentals roadmap sequences that ground, and the AZ-900 exam guide is the first companion page. Scope, NSGs, Bastion, Policy, storage, and private endpoints are the AZ-104 exam guide. Storage accounts and the relational services behind TDE, dynamic masking, and Always Encrypted are covered in the DP-900 Azure Data Fundamentals study notes and the DP-900 Azure Data Fundamentals practice exam sets.
Work those until the platform and the administrator controls are automatic, then use this page and the official study guide for the security-engineer-only skills: eligible against active in PIM, Conditional Access after first factor, NSG against Firewall against WAF, private endpoint against service endpoint, encryption at host against ADE, TDE against Always Encrypted, and Secure Score against a Sentinel incident.
Frequently Asked Questions
What is the passing score for AZ-500? 700 or greater on a scale of 1 to 1,000. Microsoft states that this is a scaled score and is not the same as 70 percent of the points, because the standard reflects the difficulty of the questions asked.
How long is the exam and how many questions are there? The credential page published 100 minutes while the exam was live. Microsoft does not publish a question count for any individual exam, and says most certification exams typically contain between 40 and 60 questions.
Is AZ-500 still available? No. The study guide marks the exam retired on 31 August 2026 at 11:59 PM Central Standard Time. The credential page states that the certification, the exam, and the renewal assessments retired on that date.
What replaced AZ-500? The current associate security credential Microsoft publishes is Microsoft Certified: Cloud and AI Security Engineer Associate, exam SC-500. That page publishes a 120 minute sitting.
Does AZ-500 have labs? Microsoft does not publish a list of exams with labs, because labs can be removed at any time for outages or bandwidth issues. The exam page says the exam may have interactive components. The published 100 minute duration matches Microsoft's row for associate role-based exams without labs, while exams that may contain labs are listed at 120 minutes. The exam time is confirmed at registration and on the launch screens.
What changed on 22 January 2026? Every functional group on the change log is marked No change, and every listed sub-area is marked Minor. The touched sub-areas are Microsoft Entra application access and managed identities, advanced security for compute, and threat protection in Defender for Cloud. The change log carries no row for Secure networking.
Which skill area is heaviest? Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel is the top band at 30 to 35%. Secure networking and Secure compute, storage, and databases share 20 to 25%. Secure identity and access is lowest at 15 to 20%.
Why do the percentages not add up to 100? Because Microsoft publishes ranges. The lower bounds total 85% and the upper bounds total 105%. Use the bands to order study time and stop looking for an exact split.
Can I use Microsoft Learn during the exam? Yes, on role-based exams. The split screen covers learn.microsoft.com, minus Q&A, practice assessments, and your profile. No extra time is added, the clock keeps running, and navigation to other domains is blocked.
How long does the certification last? Associate certifications expire annually. Renewal was free, online, unproctored, and open book, with a six month window before expiry. The AZ-500 renewal assessment retired with the exam on 31 August 2026.
Can I retake it if I fail? A failed attempt could be retaken 24 hours after the first attempt while the exam was live. Waiting periods for later retakes varied. After retirement there is no sitting to retake.
Where is the official outline? The study guide for Exam AZ-500. Use Microsoft for the task statements and the weight ranges. Use this page for what changed, what the discriminators are, and how to sequence the last blueprint.
