← AZ-500: Azure security, historical path
AZ-500 and Azure Security Engineer Associate retired August31,2026. Independent historical content without Microsoft affiliation, accreditation, or certification award. SC-500 has its own syllabus. Editorial review without independent specialist verification. No live Azure changes, access policies, or real containment actions were executed. Fictional cases do not represent internal BNP Paribas policies. Trademarks belong to their respective owners.
06 / 6 · 40 MIN

Detection, collection, and verifiable response

Validate the complete path from event to action and recovery.

Concept and mechanism

An analytics rule cannot detect events that never arrived. With Azure Monitor Agent, verify the resource’s DCR association, selected sources, transformations, and destination. Installing an agent or creating a rule does not demonstrate complete collection. SentinelHealth requires feature enablement and supports selected connectors; it is not a universal automatic guarantee for every source. Also measure data freshness and continuity. A scheduled rule has distinct execution interval and lookback settings. If it runs every five minutes and observes ten, windows overlap and can include the same event in more than one run. Address event identity and alert configuration deliberately.

Guided application

Templates provide a starting point, but a template update requires comparison with the active rule and local customizations. For playbooks, manual success under an administrator account does not validate the automation rule’s identity or permissions for subsequent actions. Before allowing containment, define criteria, scope, proportionate approval, logs, failure handling, and recovery. For APS and SOC handover, use fixtures and controlled targets to demonstrate collection, detection, and response without affecting production. Inspected documentation schedules Sentinel’s removal from the Azure portal after March31,2027; in October2026, this is a future transition to plan rather than evidence that the portal already stopped working.

IN PRACTICE

The manual playbook test passes, but automatic execution fails authorization. Keep the acceptance criterion pending and test the path actually used.

Common pitfalls

Silence treated as absence of threat; template treated as an always-current rule; manual success treated as automatic validation.

Related topics: Identity and temporary privilege · Network boundaries and private access · Compute and operational access

Take this idea with you

Accept the solution when the observed chain matches agreed operations.

Create account

Reference: Sentinel scheduled analytics and lookback · AZ-500 objectives2026-01-22; retired2026-08-31