Don't take AZ-500. Take SC-500.

9 min read 93 views

Microsoft is retiring AZ-500 on August 31, 2026. That's under six weeks away.

If you're mid-study, about to book, or holding the credential already, the decision you make in the next few weeks determines whether you end up with a certification that's current or one with a hard expiry and no path forward. This post covers what's actually changing, what carries over, what's genuinely new, and what to do depending on where you're standing right now.


What's actually happening#

Microsoft is retiring the AZ-500 exam and the Azure Security Engineer Associate certification on August 31, 2026. Critically, that includes the renewal assessment. After that date you can't earn the credential and you can't renew it.

The replacement is SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, leading to a new credential: Microsoft Certified: Cloud and AI Security Engineer Associate.

A few things people keep getting wrong:

  • There's no automatic conversion. Holding AZ-500 does not grant you SC-500. There's no free transition exam either.
  • Retirement doesn't erase your transcript. If you passed AZ-500, it stays on your record. It just stops being renewable.
  • SC-500 isn't AZ-500 with a new number. Most of the Azure security content carries forward, but the scope genuinely widened.

The exam runs 120 minutes and needs 700 out of 1000 to pass — same bar as every other Microsoft role-based exam.


What SC-500 actually tests#

Four domains, and the weighting is unusually flat. There's no section you can safely skip:

DomainWeight
Manage identity, access, and governance20–25%
Secure storage, databases, and networking25–30%
Secure compute (includes AI security)20–25%
Manage and monitor security posture20–25%

Networking edges out the rest, and people who've sat the beta report it hitting hard — Azure Firewall policy, Virtual WAN secured hubs, NSGs and ASGs, Azure Virtual Network Manager, and cross-tenant VNet peering all showed up.


The good news: most of AZ-500 carries over#

If you've been studying AZ-500, you have not wasted your time. Roughly three quarters of the material transfers directly:

  • Identity — PIM, Conditional Access, MFA and passwordless, app registrations, enterprise applications, OAuth consent, managed identities
  • Key Vault — deployment, access, firewall rules, keys and secrets and certificates
  • Governance — Azure Policy including custom definitions, resource locks, built-in and custom roles, RBAC overprivilege remediation, infrastructure as code
  • Storage and databases — storage account security, Azure Storage firewalls, Azure SQL platform security and auditing, Defender for Storage and Databases
  • Networking — NSGs, ASGs, private endpoints, Private Link, VPN, Azure Firewall, Network Watcher
  • Compute — disk encryption, Bastion, just-in-time VM access, Azure Arc, Defender for Servers, secure boot and vTPM, containers and AKS, App Service, WAF
  • Posture — Defender CSPM, workload protection plans, multicloud connectors, Sentinel workspaces and data connectors

If you've done the AZ-500 grind, you're already most of the way there.


What's new — and it's more than just AI#

The headline change is AI security, folded into the Secure compute domain. This is the part that didn't exist on AZ-500 in any form, and it's more concrete than the marketing suggests:

  • Identifying data overexposure in SharePoint
  • Finding risks in Copilot and AI apps using Microsoft Purview DSPM
  • Real-time protection for Copilot Studio agents
  • Conditional Access for Microsoft Entra Agent ID
  • Blast radius analysis for Entra Agent ID risks in Defender XDR
  • Deploying AI Gateway in Azure API Management for Microsoft Foundry
  • Defender for AI Service in Cloud Workload Protection
  • Guardrails for agent security in Foundry
  • Managing agents from the Microsoft 365 admin center

But AI isn't the only addition. Also new or newly emphasized:

  • Microsoft Entra Private Access in the networking domain
  • Azure Virtual Network Manager and Virtual WAN security
  • Microsoft Security Copilot — an entire sub-domain covering workspaces, permissions, plugins, and agents
  • Defender EASM for discovering unprotected assets
  • Querying Purview Audit from Defender XDR
  • Azure Machine Configuration for enforcing server config

That last cluster matters. If you prepped strictly against the old AZ-500 blueprint, you'd walk in blind to a meaningful slice of the exam.


The honest case for taking AZ-500 anyway#

I don't want to strawman this. There are real reasons to sit AZ-500 before it goes:

Your employer needs the badge now. If a contract, a partner competency, or a promotion requires Azure Security Engineer Associate specifically, that requirement doesn't care about your five-year plan. Take it.

You're genuinely almost done. If you've been studying for two months and you're scoring well on practice exams, sitting it in the next few weeks is low marginal effort for a real credential.

The prep ecosystem is mature. AZ-500 has years of accumulated courses, practice tests, labs, and community write-ups. SC-500 has months. If you learn best with abundant structured material, that gap is real.

It's a known quantity. Question styles, common traps, and the difficulty curve are all well documented. New exams are noisier.


The case against — and why I'd still say SC-500#

The credential has a ceiling on its life. This is the decisive point. Even if you pass AZ-500 on August 30, you cannot renew it. It stays valid until its printed expiration and then it's gone permanently. You'd be spending 60–100 hours of study on something with a maximum twelve-month runway.

You'd study most of it twice. Since the majority of SC-500 is AZ-500 content, taking AZ-500 now means covering the same identity, networking, and Defender for Cloud material again next year — plus the new sections — to get the current credential.

The new material is the material that matters. AI workload security is not a fad bolted onto the blueprint. Agent identities, DSPM for Copilot, and AI gateways are showing up in real environments right now, and the number of people who can speak to them credibly is small. That's the part of SC-500 with actual career leverage.

Being early is an advantage, not a risk. The thin prep ecosystem cuts both ways. Fewer resources means fewer people holding the cert. Six months from now "SC-500 certified" is a differentiator; in two years it's table stakes.


So what should you do?#

Your situationWhat to do
Haven't started studyingSC-500. No contest. Don't start a race you can't finish before the track closes.
A few weeks in, not confident yetSwitch to SC-500. Your material mostly transfers. Add the AI and Security Copilot content.
Deep in study, scoring well, can book before Aug 31Judgment call. Take it if you need a credential in hand now. Otherwise redirect to SC-500 and keep the momentum.
Hold AZ-500, renewal due before Aug 31Renew immediately. Free, and buys you twelve more months. Then plan SC-500.
Hold AZ-500, renewal due after Aug 31SC-500 is your only path. There's no renewal window left for you.
Employer mandates AZ-500 specificallyTake AZ-500, then plan SC-500 for next year.

The renewal trap#

This is the detail that catches people, so it gets its own section.

If you currently hold Azure Security Engineer Associate, check your renewal date today.

Microsoft role-based certifications renew annually through a free unproctored assessment on Microsoft Learn, and the renewal window opens six months before expiry. Because the AZ-500 renewal assessment retires alongside the exam, this is your last chance to use it.

  • Renewal window opens before August 31? Renew now. You get another twelve months at zero cost, and you buy yourself breathing room to prepare SC-500 properly.
  • Renewal window opens after August 31? There's nothing to renew. Your credential will lapse on its printed date. Start on SC-500.

Setting a calendar reminder for this takes thirty seconds and is worth a year of credential validity.


Before you book: check the beta status#

SC-500's beta opened May 15, 2026, with general availability expected in July. Beta exams don't return a score immediately — Microsoft collects question performance data first, and results can take several weeks after the exam leaves beta.

That's not a reason to avoid it, but it changes your planning. If you need a pass on record by a specific date, confirm the exam's current status on the Microsoft Learn page before you schedule.


How I'd prepare#

Assuming you're going SC-500:

1. Use the official skills-measured document as your spine. Microsoft's outline defines exactly what's tested. Anything outside those bullets is unlikely to appear. Print it, work through it, tick items off.

2. Don't prep from the AZ-500 blueprint alone. It's a great foundation and a dangerous complete plan. You'd miss AI security, Security Copilot, Entra Private Access, and Virtual Network Manager entirely.

3. Overweight the AI section relative to its listed percentage. It reads as part of a 20–25% domain, but it's the newest content, the least documented, and the most likely to trip you up. Budget more time than the number suggests.

4. Get hands-on in Defender for Cloud. Spin up a test subscription and actually enable the workload protection plans, connect a multicloud connector, and click through CSPM and EASM. This domain rewards muscle memory over reading.

5. Drill managed identities until they're automatic. A useful heuristic from people who've sat it: if an answer option involves a connection string, it's probably wrong. Practice the managed identity flow against Key Vault, Storage, SQL, and Container Registry.

6. Take networking seriously. It's the heaviest domain and beta takers describe it as dense. Firewall policy, Virtual WAN, VNet Manager, and cross-tenant peering all deserve lab time rather than just reading.


Bottom line#

AZ-500 is a good certification that's about to stop being a current certification. Spending your next study cycle on a credential you can never renew is a poor trade when the successor covers most of the same ground plus the part of the field that's actually growing.

Take SC-500. If you're already partway through AZ-500 prep, you've lost nothing — most of it transfers, and you'll be adding the content that makes you useful in environments where AI workloads are showing up whether the security team is ready or not.

And if you hold AZ-500 right now: go check your renewal date before you close this tab.


Dates and exam details verified against Microsoft Learn as of July 2026. Microsoft changes exam schedules regularly — confirm on the official certification pages before booking.

Discussion 0

No comments yet. Ask a question or add something I missed.

Join the discussion

Comments are reviewed before appearing.