SC-500 Study Guide: Cloud and AI Security Engineer Associate
What is the SC-500 exam?
SC-500 is the exam for Microsoft Certified: Cloud and AI Security Engineer Associate. Microsoft describes the certification as validating "your ability to design, implement, and manage end-to-end security controls across Azure, hybrid, and AI-enabled environments to protect identities, data, applications, infrastructure, and maintain regulatory compliance."
The certification sits at Intermediate level. You'll have 120 minutes to complete the exam, and a score of 700 or greater is required to pass.
Microsoft's own description of the role: as a candidate, you're a security engineer who protects organisational systems and data across cloud and hybrid environments by implementing comprehensive security controls that proactively help prevent unauthorised access and mitigate risks. Your role spans identity, network, application, data, and compute security, and extends to ensuring the platforms, data, identities, and infrastructure used by AI workloads are securely implemented and monitored.
Who should take the SC-500?
Microsoft's audience profile for this exam names a security engineer who works closely with architects, administrators, engineers, analysts, and developers responsible for Azure, Microsoft 365, identity and access, information protection, security operations, DevOps, application development, database platforms, and networks.
Microsoft recommends that candidates have practical experience administering Azure and hybrid environments, including compute, network, and storage, along with strong familiarity with Microsoft Entra ID and familiarity with Microsoft 365 administration. Microsoft describes this as expected experience; it does not list a prerequisite certification for SC-500.
Exam domains and weighting
SC-500 covers four domains, weighted as follows:
| Domain | Weight |
|---|---|
| Manage identity, access, and governance | 20-25% |
| Secure storage, databases, and networking | 25-30% |
| Secure compute | 20-25% |
| Manage and monitor security posture | 20-25% |
Storage, databases, and networking carries the heaviest weight. The other three domains are weighted evenly against each other, which means no single area can be safely deprioritised. Put your first study hours here.
Domain 1: Manage identity, access, and governance (20-25%)
Secure access to resources by using Microsoft Entra ID
This section covers Privileged Identity Management (PIM) implementation and configuration, conditional access policies, authentication methods including multifactor authentication (MFA) and passwordless sign-in, identity for applications including enterprise applications and app registrations, OAuth permission grants and consent settings, and managed identities for Azure resources.
Secure secrets and keys by using Azure Key Vault
Candidates need to deploy Key Vault, configure Key Vault settings and access, configure firewall settings on Key Vault, manage keys, secrets, and certificates, scan for secrets using Defender Cloud Security Posture Management (Defender CSPM), and implement Defender for Key Vault.
Implement governance to enforce security and regulatory compliance
This covers Azure Policy (built-in and custom definitions), evaluating regulatory compliance through Microsoft Defender for Cloud, implementing security standards and recommendations in Defender for Cloud, resource locks, Azure built-in role assignments, custom roles across both Azure roles and Microsoft Entra roles, evaluating and remediating overprivileged access assignments using Azure RBAC, backup protection security controls using Azure Backup, and security controls implemented through infrastructure as code.
This domain mixes two kinds of knowledge: configuration steps you can practise directly in a subscription (Key Vault access policies, resource locks, Azure Policy assignment) and judgement calls that only come from working through scenarios (which built-in role fits a task with the least privilege, whether a custom role or a built-in one is the right answer). Practise both. Reading through the list of built-in Azure and Microsoft Entra roles is worthwhile time even though it feels like memorisation, because remediating overprivileged access means knowing the narrowest role that still satisfies a task.
Domain 2: Secure storage, databases, and networking (25-30%)
Implement security for storage accounts
Configure storage account security, Azure Storage firewall rules, Defender for Storage threat protection configurations, and access management including access policies.
Implement security for databases
This covers platform-level security configurations in Azure SQL, database auditing for Azure SQL Database and Azure SQL Managed Instance, and Defender for Databases protection across Azure database services.
Implement security for Azure network services
Network security groups (NSGs) and application security groups (ASGs), network access policies through Azure Virtual Network Manager, security for Azure Virtual WAN, VPN connection security, Microsoft Entra Private Access, private endpoints for Azure PaaS resources, Private Link services, Azure Firewall, and evaluating effective security rules using Azure Network Watcher diagnostics.
Network Watcher's effective security rules view deserves specific practice time. It resolves the combined effect of every NSG applied to a network interface, including rules inherited at the subnet level, into the single rule set that actually applies. When a scenario describes unexpected traffic behaviour, trace that resolved rule set rather than reading a single NSG in isolation.
Domain 3: Secure compute (20-25%)
Implement security for AI
This is the section that most clearly separates SC-500 from AZ-500. It covers identifying overexposure of data in SharePoint, identifying risks related to Microsoft Copilot and AI apps using Microsoft Purview Data Security Posture Management (DSPM), enabling real-time protection for Microsoft Copilot Studio agents, implementing conditional access for Microsoft Entra Agent ID, analysing blast radius for security risks related to Entra Agent ID using Defender XDR, managing Entra Agent ID access, configuring AI Gateway in Azure API Management for Microsoft Foundry, enabling Defender for AI Service in Cloud Workload Protection, configuring guardrails for agent security in Foundry, monitoring AI security through the Data and AI security dashboard in Defender for Cloud, and managing agents in the Microsoft 365 admin centre.
None of these skills appeared on AZ-500. Budget real study time for this section; it carries genuine exam weight on its own.
Implement security for servers and virtual machines
Disk encryption, Azure Bastion, just-in-time (JIT) VM access, extending security controls to hybrid and multicloud servers using Azure Arc, onboarding to Defender for Servers including hybrid and multicloud scenarios, Defender for Servers settings such as vulnerability scanning and endpoint detection and response, agentless scanning for VMs, VM security features including secure boot, virtual Trusted Platform Module (vTPM), integrity monitoring, and security type, and enforcing configuration through Azure Machine Configuration.
Implement security for application platform services
Detecting misconfigurations and runtime risks in container workloads through Defender for Containers, security controls for Azure Kubernetes Service (AKS), Azure Container Registry, Azure Container Instances, Azure Container Apps, Azure Functions authentication and network access, Azure Logic Apps, Azure App Service, Azure Web Application Firewall, and back-end API protection through API Management.
Domain 4: Manage and monitor security posture (20-25%)
Manage security posture by using Defender for Cloud
Identifying security risks through Defender CSPM, evaluating compliance against security frameworks, enabling workload protection plans, connecting hybrid and multicloud environments including Amazon Web Services (AWS) and Google Cloud Platform (GCP), configuring Microsoft Defender Vulnerability Management for Azure VMs, and discovering unprotected assets through Microsoft Defender External Attack Surface Management (EASM).
Implement activity and event collection in Microsoft Sentinel
Creating and connecting workspaces, assigning roles, using content hub solutions, configuring data connectors for Azure resources, syslog and Common Event Format (CEF) event collection, collecting Windows Security events through data collection rules including Windows Event Forwarding, creating custom log tables, implementing automation rules and playbooks, implementing data retention, and querying Microsoft Purview Audit in Defender XDR.
Implement Microsoft Security Copilot
Configuring workspaces, managing permissions and roles, enabling and configuring plugins, and enabling Microsoft agents and Security Store agents in Security Copilot.
What changed from AZ-500
AZ-500 assessed four domains: secure identity and access, secure networking, secure compute, storage, and databases, and secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel. SC-500 reorganises this into four different domains and adds an entire AI security section inside "Secure compute" covering Copilot, Copilot Studio, Microsoft Entra Agent ID, and Microsoft Foundry. It also adds Microsoft Security Copilot as its own skill area under posture management.
The core Azure security building blocks carry over: Key Vault, NSGs, Azure Firewall, Defender for Cloud, and Microsoft Sentinel all still appear. Candidates who studied for AZ-500 have a real head start on domains 1, 2, and part of domain 4. The AI security content in domain 3 and the Security Copilot content in domain 4 are new ground.
Study plan
Structure your preparation around the four domains, weighting your time to match the exam weights:
Weeks 1-2: Identity, access, and governance
Work through Entra ID PIM, conditional access policy design, and managed identities hands-on. Deploy a Key Vault, configure access policies, and practise Azure Policy assignment. Set up Defender CSPM secret scanning against a test vault.
Weeks 3-4: Storage, databases, and networking
This domain carries the highest weight, so give it the most time. Configure storage account firewalls and Defender for Storage, set up Azure SQL auditing, and build out NSGs, Azure Firewall, and private endpoints in a test environment. Practise reading effective security rules in Network Watcher.
Weeks 5-6: Secure compute, including AI security
Cover VM and container security first since it overlaps with prior Azure experience: disk encryption, JIT access, Defender for Servers, AKS and container security. Then move to the AI security sub-section specifically: Purview DSPM, Copilot Studio agent protection, Entra Agent ID, and Defender for AI Service. Treat this as new material even if you have an Azure security background.
Weeks 7-8: Security posture and monitoring
Build a Microsoft Sentinel workspace, connect a data source, and configure an automation rule. Review Defender for Cloud's regulatory compliance and workload protection features. Look at Microsoft Security Copilot's workspace and plugin configuration even if you don't have hands-on access, since it is an explicit skill area.
Weeks 9-10: Review and practice
Take full-length practice questions across all four domains, with extra weight on storage, databases, and networking. Revisit any domain where you are answering below your target pass rate.
Start practising
AzurePrep has practice questions across current Azure certifications, including SC-500. Start preparing for SC-500 with practice questions at azureprep.com/exam/sc-500.