← AZ-500: Azure security, historical path
AZ-500 and Azure Security Engineer Associate retired August31,2026. Independent historical content without Microsoft affiliation, accreditation, or certification award. SC-500 has its own syllabus. Editorial review without independent specialist verification. No live Azure changes, access policies, or real containment actions were executed. Fictional cases do not represent internal BNP Paribas policies. Trademarks belong to their respective owners.
03 / 6 · 40 MIN

Compute and operational access

Protect administration without confusing access, sessions, and encryption.

Concept and mechanism

Administering a VM without directly publishing SSH or RDP reduces an exposure surface. Azure Bastion supports VM access through its private IP but does not remove authentication, permissions, or network requirements. Features such as session recording depend on the chosen tier. JIT manages temporary port access subject to supported controls and existing rules. When the window ends, restoring rules does not guarantee termination of established connections. If operational policy requires no sessions after a given time, the runbook must include session management and verification in addition to controlling new connections.

Guided application

In private AKS, the API server is accessed through an internal network; the deployment agent needs resolution and a path to that control plane. More application replicas or a cluster-admin role do not repair a network timeout. Disk protection addresses another requirement. Disk Storage SSE alone does not cover caches and temporary disks in the same way as encryption at host. For new VMs, assess support and coverage for that mechanism. Current documentation announces ADE retirement on September15,2028, so design should account for migration and copies depending on that technology. Do not assume private or encrypted covers every service layer.

IN PRACTICE

JIT ends at21:00, but the maintenance session continues. Verify and apply authorized closure if required, preserving intervention evidence.

Common pitfalls

Bastion treated as no authentication; private API treated as isolation of every pod; SSE treated as cache coverage.

Related topics: Identity and temporary privilege · Network boundaries and private access · Data protection and use

Take this idea with you

Define the required effect at each layer and validate it with the correct consumer.

Create account

Reference: Defender for Servers JIT access and expiry · AZ-500 objectives2026-01-22; retired2026-08-31