• Cohort starts Jan 16, 2027
Reserve seat
All posts
Azure

AZ-500 Retires August 31: Your SC-500 Transition Plan

PrimeSec Academy·8/22/2026
AZ-500 Retires August 31: Your SC-500 Transition Plan

AZ-500 retires August 31, 2026. SC-500 replaces it. What changed, what transfers, and which exam you should sit right now.

Microsoft is retiring the AZ-500 exam and the Azure Security Engineer Associate certification on August 31, 2026. The replacement is SC-500, which leads to the Microsoft Certified: Cloud and AI Security Engineer Associate credential and expands the old Azure security syllabus to include AI workload security, governance, and security posture management.

If you have been studying for AZ-500, you are not starting over. Most of what you learned still counts. But the target has moved, and the smart move now is to understand exactly what changed before you book anything.

What is actually retiring

Microsoft has published a retirement notice on the Azure Security Engineer Associate certification page. Three things go away at the same time:

  • The AZ-500 exam itself
  • The Azure Security Engineer Associate certification
  • The renewal assessment for that certification

The stated deadline is August 31, 2026 at 11:59 PM Central Standard Time. After that, Microsoft says you will no longer be able to earn or renew this certification.

That last point matters more than most people realize. If you already hold the credential, it stays on your Microsoft Learn transcript, but Microsoft role-based certifications expire unless renewed every 12 months. Once the renewal assessment is gone, there is no path to keep it current. Plan on transitioning to SC-500 at some point rather than treating your existing AZ-500 as permanent.

Why Microsoft made this change

The AZ-500 blueprint was built for a world where "cloud security engineer" meant identity, network, compute, storage, and a SIEM. That job description has changed.

Security engineers are now asked to secure AI agents, control what a Copilot-style assistant can read, review data exposure before an AI tool surfaces it, and monitor AI workloads for abuse. None of that existed in a meaningful way when AZ-500 was designed. Rather than bolt AI onto an aging blueprint, Microsoft rebuilt the credential around the role as it exists today.

The name change tells the story. "Azure Security Engineer" became "Cloud and AI Security Engineer." That is the direction the entire discipline is moving, and it is the same reason our own curriculum treats cloud security and AI security as one skill set rather than two.

AZ-500 vs SC-500: what changed

Here is how the two blueprints compare side by side.

AreaAZ-500 (retiring)SC-500 (current)
Certification earnedAzure Security Engineer AssociateCloud and AI Security Engineer Associate
Identity and accessSecure identity and access (15 to 20%)Manage identity, access, and governance (20 to 25%)
Networking, storage, databasesSplit across two domains (roughly 40 to 50% combined)Secure storage, databases, and networking (25 to 30%)
ComputeIncluded with storage and databasesSecure compute (20 to 25%), including AI security
Posture and monitoringDefender for Cloud and Sentinel (30 to 35%)Manage and monitor security posture (20 to 25%)
AI workload securityNot coveredCovered explicitly
Governance and complianceLight coverageExplicit objectives under identity and governance
Passing score700700

The headline takeaway: roughly 70 to 80 percent of your AZ-500 study time transfers directly. Entra ID, Key Vault, network security groups, Azure Firewall, private endpoints, storage account hardening, Defender for Cloud, and Sentinel all appear in both blueprints.

What SC-500 covers that AZ-500 did not

The genuinely new material sits inside the Secure compute domain, under an objective set called "Implement security for AI." According to the official SC-500 study guide, this includes:

  • Identifying overexposure of data in SharePoint, which is the classic failure mode when an organization turns on an AI assistant and it starts surfacing files people were never meant to see
  • Identifying risks related to Microsoft Copilot and AI apps using Microsoft Purview Data Security Posture Management
  • Configuring real-time protection for Microsoft Copilot Studio agents
  • Implementing conditional access for Microsoft Entra Agent ID
  • Analyzing blast radius for Entra Agent ID risks using Defender XDR
  • Configuring AI Gateway in Azure API Management for Microsoft Foundry
  • Enabling Defender for AI Service in Defender for Cloud
  • Configuring guardrails for agent security in Foundry
  • Monitoring AI security using the Data and AI security dashboard in Defender for Cloud

There is also a new Microsoft Security Copilot objective under posture management, covering workspace configuration, permissions and roles, and plugin enablement.

Notice the pattern in that AI list. It is not prompt engineering and it is not model training. It is identity, access control, data governance, and monitoring applied to a new class of workload. If you understand why an overprivileged service principal is dangerous, you already understand why an overprivileged AI agent is dangerous. The threat model rhymes with what you know from the OWASP LLM Top 10.

Which path should you take right now

Your answer depends on where you are today. Be honest about which of these describes you.

You are days away from being exam ready. If you have already done the labs and you are scoring well on practice assessments, sitting AZ-500 before August 31 is defensible. You get a credential you can put on a resume now. Understand the tradeoff: you will not be able to renew it, so treat it as a checkpoint rather than a destination and plan for SC-500 later.

You are mid-preparation with weeks of work left. Switch to SC-500 now. Rushing an exam you are not ready for to earn a credential that cannot be renewed is a poor use of both money and time. Your existing study on Entra ID, networking, and Defender carries over almost entirely.

You have not started yet. Go straight to SC-500. There is no scenario where beginning an AZ-500 study plan in late August makes sense.

You already hold the AZ-500 certification. Nothing happens to it on August 31. It stays valid until its renewal date. Start planning your SC-500 attempt before that renewal window closes, and use the time to build the AI security skills you will need regardless of which exam you sit.

If you are not sure which of these fits you, the eligibility quiz is a fast way to get a read on your current level.

A realistic study plan for SC-500

Microsoft expects candidates to have practical experience administering Azure and hybrid environments, strong familiarity with Microsoft Entra ID, and familiarity with Microsoft 365 administration. That last requirement is new relative to AZ-500 and it trips people up. The AI security objectives lean heavily on Purview, SharePoint permissions, and the Microsoft 365 admin center.

A workable sequence:

  1. Weeks 1 to 3: identity and governance. Entra ID, Privileged Identity Management, conditional access, managed identities, Key Vault, Azure Policy, and RBAC. This is the foundation everything else sits on.
  2. Weeks 4 to 6: storage, databases, networking. Storage account firewalls, Azure SQL auditing, network security groups, Azure Firewall, private endpoints, Private Link.
  3. Weeks 7 to 9: compute and AI. Disk encryption, Bastion, just-in-time VM access, Azure Arc, Defender for Servers, containers and AKS, then the AI security objectives.
  4. Weeks 10 to 12: posture and monitoring. Defender CSPM, multicloud connectors for AWS and GCP, Sentinel workspaces and data connectors, automation rules, and Security Copilot.

Do not read your way through this. Build each control in a lab, break it, and then fix it. Reading about conditional access and configuring a policy that locks you out of your own tenant are different educational experiences, and only one of them sticks. That is why every module in our projects track is built around doing the work rather than watching it.

If you want the wider context on how this credential fits a full career path, our guide on how to become a cloud security engineer covers the sequence from first job to senior role, and our Azure security fundamentals piece is a good warm-up before you touch the SC-500 blueprint.

The bigger signal for your career

Certification retirements are usually housekeeping. This one is not. Microsoft renamed its flagship Azure security credential to include AI, and rewrote the blueprint to match. Amazon and Google are moving in the same direction. The role that pays well in 2027 is the engineer who can secure a cloud environment and the AI workloads running inside it.

That is exactly the gap our 20-week program was built to close, combining AWS, Azure, GCP, and AI security into one hands-on track with 36 projects and a defended capstone.

Ready to build the skills SC-500 now measures? Explore the curriculum or enroll here to get started.

Frequently asked questions

When exactly does AZ-500 retire?

The AZ-500 exam, the Azure Security Engineer Associate certification, and its renewal assessment all retire on August 31, 2026 at 11:59 PM Central Standard Time. After that date you cannot earn or renew the certification.

What replaces AZ-500?

SC-500, titled Implementing End-to-End Security Controls for Cloud and AI Workloads, replaces it. Passing SC-500 earns the Microsoft Certified: Cloud and AI Security Engineer Associate credential.

Does my existing AZ-500 certification disappear on August 31?

No. If you already earned it, the certification remains on your Microsoft Learn transcript and stays valid until its renewal date. Because the renewal assessment retires as well, you will not be able to renew it after that point, so plan a transition to SC-500.

Is my AZ-500 study material wasted if I switch to SC-500?

Mostly no. Identity and access, Key Vault, storage security, database security, networking, Defender for Cloud, and Microsoft Sentinel all appear in both blueprints. The main additions are AI workload security, governance and compliance depth, and Microsoft Security Copilot.

What score do I need to pass SC-500?

A score of 700 or greater is required to pass, which is the standard passing score across Microsoft role-based certification exams.

Do I need Microsoft 365 experience for SC-500?

Yes, some. Microsoft lists familiarity with Microsoft 365 administration as an expectation, alongside practical Azure and hybrid administration experience and strong familiarity with Microsoft Entra ID. Several AI security objectives involve Purview, SharePoint data exposure, and the Microsoft 365 admin center.

Stay ahead in cybersecurity

Get the Latest Security Insights

Subscribe to our newsletter and get updates on new courses, labs, events, and career tips.

We respect your privacy. Unsubscribe at any time.