SC-500: cloud and AI security
Six lessons, 42 questions, and six cases on identities, data, networks, AI agents, compute, and detection. Independent SC-500 preparation.
Objectives and progression
A guided course with fictional APS and project scenarios, explained decisions, and an internal assessment of 24 items in 60 minutes. Covers all four domains through access diagnosis, key availability, private networking, and security evidence. SC-500 guide updated 2026-05-13; objectives effective date is not explicitly stated. Official exam of 120 minutes and scaled score 700/1000, not equivalent to 70%, with no fixed question count inferred.. Preview agent capabilities are identified in lessons.
Audience: Cloud engineers, APS teams, and technical infrastructure managers.
Prerequisites: Azure administration, networking, identity, and security fundamentals.
300 estimated study minutes
- Distinguish authentication, authorization, and security-change execution.
- Connect delegation, private endpoints, auditing, and key availability.
- Interpret rules, DNS, and paths without confusing a partial check with complete success.
- Constrain data, identities, tools, and consumption around actual control coverage.
- Apply runtime protection and scoped changes while retaining recovery capability.
- Prioritize risk and establish collection, automation, and reporting limits.
Modules
- Identity, access, and governance
- Storage, SQL, and keys
- Private networks and diagnosis
- Agent and AI security
- Compute, platforms, and recovery
- Posture, Sentinel, and evidence
Continue learning
- Microsoft Certified: Azure Security Engineer Associate
- SC-200 — Security Operations Analyst
- SC-300 — Identity and Access Administrator
- Azure AI Cloud Developer Associate
References and version
SC-500 guide updated 2026-05-13; Microsoft security documentation accessed 2026-09-30
- SC-500 official objectives · 2026-09-30
- Cloud and AI Security Engineer Associate · 2026-09-30
- Eligible and active privileged access · 2026-09-30
- Conditional Access impact evaluation · 2026-09-30
- Policy remediation and assignment identity · 2026-09-30
- Resource locks and control-plane limits · 2026-09-30
- Key Vault authorization planes and migration · 2026-09-30
- Managed identities · 2026-09-30
- Delegated and application permissions · 2026-09-30
- Role Actions DataActions and NotActions · 2026-09-30
- Resource Guard separation of duties · 2026-09-30
- Scoped shared access signatures · 2026-09-30
- Storage private endpoints and subresources · 2026-09-30
- Azure SQL auditing and evidence · 2026-09-30
- TDE scope and key dependency · 2026-09-30
- NSG priority stateful flow behavior · 2026-09-30
- IP flow verification and rule evaluation · 2026-09-30
- Private endpoint DNS integration · 2026-09-30
- Azure Firewall rule evaluation · 2026-09-30
- DDoS network protection · 2026-09-30
- Agent identity targeting and preview conditions · 2026-09-30
- DSPM oversharing assessments · 2026-09-30
- AI gateway authentication and consumer limits · 2026-09-30
- Agent guardrail assignment and preview controls · 2026-09-30
- AI threat protection · 2026-09-30
- AI service protection onboarding · 2026-09-30
- JIT ports and existing connections · 2026-09-30
- Secure Boot vTPM and supported workloads · 2026-09-30
- Snapshot-based agentless scanning · 2026-09-30
- Scoped WAF exclusions · 2026-09-30
- AKS layered security · 2026-09-30
- Private VM administration · 2026-09-30
- Guest machine configuration · 2026-09-30
- API JWT claims and audience validation · 2026-09-30
- Contextual attack-path prioritization · 2026-09-30
- Automated and manual compliance evidence · 2026-09-30
- Sentinel automation permissions · 2026-09-30
- Connector health monitoring · 2026-09-30
- Interactive and total data retention · 2026-09-30
- AWS connector onboarding · 2026-09-30
- Security Copilot platform and plugin permissions · 2026-09-30
- CEF Syslog AMA and DCR diagnosis · 2026-09-30
- Microsoft scaled scores · 2026-09-30
- Custom table schema and DCR coordination · 2026-09-30
What you will explore
0 / 6Identity, access, and governance
Distinguish authentication, authorization, and security-change execution.
Storage, SQL, and keys
Connect delegation, private endpoints, auditing, and key availability.
Private networks and diagnosis
Interpret rules, DNS, and paths without confusing a partial check with complete success.
Agent and AI security
Constrain data, identities, tools, and consumption around actual control coverage.
Compute, platforms, and recovery
Apply runtime protection and scoped changes while retaining recovery capability.
Posture, Sentinel, and evidence
Prioritize risk and establish collection, automation, and reporting limits.