AZ-500: Azure security, historical path
Historical AZ-500: six lessons, 36 questions, and six cases on identity, networking, compute, data, Key Vault, policies, and Sentinel.
Objectives and progression
Independent historical path based on AZ-500 objectives dated January22,2026, with six lessons,36 questions,and six cases. The exam and certification retired August31,2026. Identity, networking, compute, and data connect to governance and operational response through original APS and infrastructure-project examples. Technical documentation was inspected in October2026, distinguishing service updates from the archived syllabus. The internal assessment reuses30 decisions in60 minutes without external certification. SC-500 is a progression with its own syllabus, whose coverage is not automatically established by this path.
Audience: Azure security engineers, APS and SOC teams, L3 support, and technical project managers.
Prerequisites: Azure, identity, TCP/IP, and application operations fundamentals. Fictional exercises require no tenant or real cloud resources.
300 estimated study minutes
- Connect principal, operation, scope, and activation.
- Separate routing, resolution, authorization, and enforcement.
- Protect administration without confusing access, sessions, and encryption.
- Choose controls according to threat and legitimate operation.
- Distinguish visible resources, permitted operations, and demonstrated compliance.
- Validate the complete path from event to action and recovery.
Modules
- Identity and temporary privilege
- Network boundaries and private access
- Compute and operational access
- Data protection and use
- Vaults, policies, and control evidence
- Detection, collection, and verifiable response
Continue learning
- AZ-104 — Azure Administrator
- SC-200 — Security Operations Analyst
- SC-300 — Identity and Access Administrator
- Production Support L3
References and version
AZ-500 objectives2026-01-22; retired2026-08-31
- AZ-500 retirement and certification · 2026-10-01
- AZ-500 archived objectives January22,2026 · 2026-10-01
- PIM eligible and active Azure resource roles · 2026-10-01
- Conditional Access report-only evaluation · 2026-10-01
- Azure roles versus Microsoft Entra roles · 2026-10-01
- Delegated and application access and consent · 2026-10-01
- Managed identity lifecycle and authorization · 2026-10-01
- NSG priority state and existing connections · 2026-10-01
- Storage private endpoints DNS and public access · 2026-10-01
- App Service outbound VNet integration · 2026-10-01
- Application Gateway WAF detection and prevention · 2026-10-01
- ExpressRoute encryption boundaries · 2026-10-01
- VNet service endpoints · 2026-10-01
- Defender for Servers JIT access and expiry · 2026-10-01
- Azure Bastion private VM access · 2026-10-01
- AKS private control-plane connectivity · 2026-10-01
- Disk encryption and ADE retirement · 2026-10-01
- Blob data access roles and scope · 2026-10-01
- Storage SAS scope and credentials · 2026-10-01
- SQL dynamic data masking and privileged users · 2026-10-01
- Always Encrypted and enclave boundaries · 2026-10-01
- SQL transparent data encryption · 2026-10-01
- Blob immutability retention and legal holds · 2026-10-01
- Key Vault control and data planes and RBAC migration · 2026-10-01
- Key Vault soft delete and purge protection · 2026-10-01
- Policy remediation tasks and managed identity permissions · 2026-10-01
- Defender for Cloud compliance evidence and manual assessments · 2026-10-01
- Sentinel playbooks permissions and response · 2026-10-01
- Sentinel scheduled analytics and lookback · 2026-10-01
- Sentinel connector health and coverage · 2026-10-01
- Azure Monitor data collection rule associations · 2026-10-01
What you will explore
0 / 6Identity and temporary privilege
Connect principal, operation, scope, and activation.
Network boundaries and private access
Separate routing, resolution, authorization, and enforcement.
Compute and operational access
Protect administration without confusing access, sessions, and encryption.
Data protection and use
Choose controls according to threat and legitimate operation.
Vaults, policies, and control evidence
Distinguish visible resources, permitted operations, and demonstrated compliance.
Detection, collection, and verifiable response
Validate the complete path from event to action and recovery.