← AZ-500: Azure security, historical path
AZ-500 and Azure Security Engineer Associate retired August31,2026. Independent historical content without Microsoft affiliation, accreditation, or certification award. SC-500 has its own syllabus. Editorial review without independent specialist verification. No live Azure changes, access policies, or real containment actions were executed. Fictional cases do not represent internal BNP Paribas policies. Trademarks belong to their respective owners.
05 / 6 · 40 MIN

Vaults, policies, and control evidence

Distinguish visible resources, permitted operations, and demonstrated compliance.

Concept and mechanism

Key Vault has management and data planes. In an RBAC vault, Key Vault Reader reads metadata, while Secrets User allows reading secret values. Contributor manages the resource and should not be treated as a direct data grant in that model. Migrating from access policies to RBAC invalidates previous permissions; inventory consumers and prepare equivalent minimum roles before cutover. Current documentation uses RBAC by default in API2026-02-01, but that does not establish existing-vault configuration and should not be projected backward onto the entire historical syllabus. Always verify the resource’s effective model.

Guided application

Soft delete supports recovery of deleted objects; purge protection prevents permanent removal during retention but does not keep a deleted secret available to the application. In Azure Policy, remediating existing resources with modify or deployIfNotExists requires the appropriate task and an authorized managed identity. An assignment created through an SDK does not automatically guarantee all execution roles. When reporting Defender for Cloud, distinguish automated assessments, manual evidence, scope, and controls still unproven. A report can support auditors without itself certifying the organization. For example,18 passed assessments out of24 applicable ones represent75% of that population rather than incident-free probability or the secure-score formula.

IN PRACTICE

The administrator opens the vault, but the application receives403 after RBAC migration. Test the data action and consumer identity rather than only portal management.

Common pitfalls

Visible vault treated as readable secret; purge protection treated as availability; green dashboard treated as external certification.

Related topics: Identity and temporary privilege · Network boundaries and private access · Compute and operational access

Take this idea with you

Preserve the connection between evidence, scope, and acceptance decision.

Create account

Reference: Key Vault control and data planes and RBAC migration · AZ-500 objectives2026-01-22; retired2026-08-31