Retired exam
AZ-500 was retired on August 31, 2026
Microsoft will retire AZ-500 on 2026-08-31. The exam remains schedulable before the cutoff. Microsoft has not announced a successor; check the official Azure Security Engineer page for updates.
No direct replacement is named in the reviewed official sources.
Historical AZ-500 Scope
AZ-500, Microsoft Azure Security Technologies, remains available only until 2026-08-31. Its published domains cover Secure identity and access, Secure networking, Secure compute, storage, and databases, Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel. The final AZ-500 outline is unusually useful as a boundary map between resource-level Azure hardening and broader security operations. It shows where identity, network paths, workload configuration, posture management, and incident signals must be reasoned about together. Microsoft has not announced a successor; check the official Azure Security Engineer certification page for updates. This page keeps the dated blueprint useful while separating verified lifecycle facts from recommendations.
Who AZ-500 Was For
The original audience was Azure security engineers who implement controls across identity, networking, compute, storage, databases, Defender for Cloud, and Sentinel. Current candidates should choose AZ-500 only when preparation, scheduling, and any credential requirements can be completed before 2026-08-31; otherwise monitor Microsoft's official certification pages for post-retirement guidance.
Skills You Should Be Ready to Demonstrate
- Trace effective access across Azure roles, Microsoft Entra controls, and privileged workflows
- Design network and private-access controls around real workload dependencies
- Harden compute, storage, databases, and secrets without breaking operability
- Turn Defender for Cloud posture findings and Sentinel signals into corrective action
How to Reuse Your Preparation
Build one representative Azure environment and trace a control from identity assignment through network isolation, workload protection, policy evaluation, Defender findings, and Sentinel response. Candidates with enough time to test before the cutoff can finish AZ-500; longer plans should wait for Microsoft to publish a successor path before committing. Start with the dated Microsoft guide, map each objective to a task, decision, observable result, and failure mode, and use domain ranges to balance coverage rather than predict question counts. Keep notes labeled with the guide date so future product or blueprint changes do not silently contaminate the plan.
Migration checklist
- Confirm that a complete AZ-500 study and booking plan fits before 2026-08-31.
- If the plan extends past the cutoff, monitor Microsoft's official certification pages for any successor announcement.
- Keep dated AZ-500 notes clearly labeled so any future exam path gets its own current outline.
- Recheck the official retirement page before scheduling because Microsoft states that dates can change.
Historical Domain Guide
Secure identity and access: Historical Scope
Domain 1, Secure identity and access, organizes related decisions rather than isolated product facts. The current outline includes Manage security controls for identity and access; Manage Azure built-in role assignments; Manage custom roles, including Azure roles and Microsoft Entra roles. Practice by connecting the configuration or recommendation to prerequisites, downstream effects, evidence of success, and a safe correction when the expected result is not observed.
- Turn every Secure identity and access objective into a concrete task or decision you can explain
- Record the prerequisite, implementation choice, verification signal, and failure mode
- Mix this domain with adjacent domains so dependencies remain visible
Secure networking: Historical Scope
Domain 2, Secure networking, organizes related decisions rather than isolated product facts. The current outline includes Plan and implement security for virtual networks; Plan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs); Manage virtual networks by using Azure Virtual Network Manager. Practice by connecting the configuration or recommendation to prerequisites, downstream effects, evidence of success, and a safe correction when the expected result is not observed.
- Turn every Secure networking objective into a concrete task or decision you can explain
- Record the prerequisite, implementation choice, verification signal, and failure mode
- Mix this domain with adjacent domains so dependencies remain visible
Secure compute, storage, and databases: Historical Scope
Domain 3, Secure compute, storage, and databases, organizes related decisions rather than isolated product facts. The current outline includes Plan and implement advanced security for compute; Plan and implement remote access to virtual machines, including Azure Bastion and just-in-time (JIT) VM access; Configure network isolation for Azure Kubernetes Service (AKS). Practice by connecting the configuration or recommendation to prerequisites, downstream effects, evidence of success, and a safe correction when the expected result is not observed.
- Turn every Secure compute, storage, and databases objective into a concrete task or decision you can explain
- Record the prerequisite, implementation choice, verification signal, and failure mode
- Mix this domain with adjacent domains so dependencies remain visible
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel: Historical Scope
Domain 4, Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel, organizes related decisions rather than isolated product facts. The current outline includes Implement and manage enforcement of cloud governance policies; Create, assign, and interpret policies and initiatives in Azure Policy; Configure Azure Key Vault network settings. Practice by connecting the configuration or recommendation to prerequisites, downstream effects, evidence of success, and a safe correction when the expected result is not observed.
- Turn every Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel objective into a concrete task or decision you can explain
- Record the prerequisite, implementation choice, verification signal, and failure mode
- Mix this domain with adjacent domains so dependencies remain visible
Sources and Verification
Verified 2026-08-26
How this page was made
Cert Atlas reviewed Microsoft's dated AZ-500 study guide and official retirement list, then re-verified the retirement facts against the live Microsoft pages on the retirement date itself. The lifecycle, weights, and editorial claims were checked against the linked official pages; no exam questions, answers, choices, or explanations were used.
Historical AZ-500 Domains
1.0 Secure identity and access
15-20%
- 1.1Manage security controls for identity and access
- 1.2Manage Azure built-in role assignments
- 1.3Manage custom roles, including Azure roles and Microsoft Entra roles
- 1.4Plan and manage Azure resources in Microsoft Entra Privileged Identity Management, including settings and assignments
- 1.5Implement multi-factor authentication (MFA) for access to Azure resources
- 1.6Implement Conditional Access policies for cloud resources in Azure
- 1.7Manage Microsoft Entra application access and managed identities
- 1.8Manage access to enterprise applications in Microsoft Entra ID, including OAuth permission grants
- 1.9Manage Microsoft Entra app registrations
- 1.10Configure app registration permission scopes
- 1.11Manage app registration permission consent
- 1.12Manage and use service principals
- 1.13Manage managed identities
2.0 Secure networking
20-25%
- 2.1Plan and implement security for virtual networks
- 2.2Plan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs)
- 2.3Manage virtual networks by using Azure Virtual Network Manager
- 2.4Plan and implement user-defined routes (UDRs)
- 2.5Plan and implement Virtual Network peering or VPN gateway
- 2.6Plan and implement Virtual WAN, including secured virtual hub
- 2.7Secure VPN connectivity, including point-to-site and site-to-site
- 2.8Implement encryption over ExpressRoute
- 2.9Configure firewall settings on Azure resources
- 2.10Monitor network security by using Network Watcher
- 2.11Plan and implement security for private access to Azure resources
- 2.12Plan and implement virtual network Service Endpoints
- 2.13Plan and implement Private Endpoints
- 2.14Plan and implement Private Link services
- 2.15Plan and implement network integration for Azure App Service and Azure Functions
- 2.16Plan and implement network security configurations for an App Service Environment (ASE)
- 2.17Plan and implement network security configurations for an Azure SQL Managed Instance
- 2.18Plan and implement security for public access to Azure resources
- 2.19Plan and implement Transport Layer Security (TLS) to applications, including Azure App Service and API Management
- 2.20Plan, implement, and manage an Azure Firewall, including Azure Firewall Manager and firewall policies
- 2.21Plan and implement an Azure Application Gateway
- 2.22Plan and implement an Azure Front Door, including Content Delivery Network (CDN)
- 2.23Plan and implement a Web Application Firewall (WAF)
- 2.24Recommend when to use Azure DDoS Protection Standard
3.0 Secure compute, storage, and databases
20-25%
- 3.1Plan and implement advanced security for compute
- 3.2Plan and implement remote access to virtual machines, including Azure Bastion and just-in-time (JIT) VM access
- 3.3Configure network isolation for Azure Kubernetes Service (AKS)
- 3.4Secure and monitor AKS
- 3.5Configure authentication for AKS
- 3.6Configure security monitoring for Azure Container Instances (ACIs)
- 3.7Configure security monitoring for Azure Container Apps (ACAs)
- 3.8Manage access to Azure Container Registry (ACR)
- 3.9Configure disk encryption, including Azure Disk Encryption (ADE), encryption at host, and confidential disk encryption
- 3.10Recommend security configurations for Azure API Management
- 3.11Plan and implement security for storage
- 3.12Configure access control for storage accounts
- 3.13Manage storage account access keys
- 3.14Select and configure an appropriate method for access to Azure Files
- 3.15Select and configure an appropriate method for access to Azure Blob Storage
- 3.16Select and configure appropriate methods for protecting against data security threats, including soft delete, backups, versioning, and immutable storage
- 3.17Configure Bring your own key (BYOK)
- 3.18Enable double encryption at the Azure Storage infrastructure level
- 3.19Plan and implement security for Azure SQL Database and Azure SQL Managed Instance
- 3.20Enable Microsoft Entra database authentication
- 3.21Enable database auditing
- 3.22Plan and implement dynamic masking
- 3.23Implement Transparent Data Encryption (TDE)
- 3.24Recommend when to use Azure SQL Database Always Encrypted
4.0 Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
30-35%
- 4.1Implement and manage enforcement of cloud governance policies
- 4.2Create, assign, and interpret policies and initiatives in Azure Policy
- 4.3Configure Azure Key Vault network settings
- 4.4Configure access to Key Vault, including vault access policies and Azure Role Based Access Control
- 4.5Manage certificates, secrets, and keys
- 4.6Configure key rotation
- 4.7Perform backup and recovery of certificates, secrets, and keys
- 4.8Implement security controls to protect backups
- 4.9Implement security controls for asset management
- 4.10Manage security posture by using Microsoft Defender for Cloud
- 4.11Identify and remediate security risks by using the Microsoft Defender for Cloud Secure Score and Inventory
- 4.12Assess compliance against security frameworks by using Microsoft Defender for Cloud
- 4.13Manage compliance standards in Microsoft Defender for Cloud
- 4.14Add custom standards to Microsoft Defender for Cloud
- 4.15Connect hybrid cloud and multi-cloud environments to Microsoft Defender for Cloud, including Amazon Web Services (AWS) and Google Cloud Platform (GCP)
- 4.16Implement and use Microsoft Defender External Attack Surface Management (EASM)
- 4.17Configure and manage threat protection by using Microsoft Defender for Cloud
- 4.18Enable cloud workload protection plans in Microsoft Defender for Cloud
- 4.19Configure Microsoft Defender for Servers, Microsoft Defender for Databases, and Microsoft Defender for Storage
- 4.20Implement and manage agentless scanning for virtual machines in Microsoft Defender for Servers
- 4.21Implement and manage Microsoft Defender Vulnerability Management for Azure virtual machines
- 4.22Connect to and configure settings in Microsoft Defender for Cloud
- 4.23Devops Security, including GitHub, Azure DevOps, and GitLab
- 4.24Configure and manage security monitoring and automation solutions
- 4.25Manage and respond to security alerts in Microsoft Defender for Cloud
- 4.26Configure workflow automation by using Microsoft Defender for Cloud
- 4.27Monitor network security events and performance data by configuring data collection rules (DCRs) in Azure Monitor
- 4.28Configure data connectors in Microsoft Sentinel
- 4.29Enable analytics rules in Microsoft Sentinel
- 4.30Configure automation in Microsoft Sentinel