Microsoft • AZ-500
Validates expertise in implementing, managing, and monitoring security for Azure, multi-cloud, and hybrid environments, including identity and access, networking, compute, storage, and data security.
Questions
469
Duration
100 minutes
Passing Score
700/1000
Difficulty
AssociateLast Updated
Jan 2025
The Microsoft Certified: Azure Security Engineer Associate (AZ-500) validates expertise in implementing, managing, and monitoring security for resources across Azure, multi-cloud, and hybrid environments. Holders of this credential demonstrate the ability to maintain an organization's security posture, implement threat protection, and identify and remediate security vulnerabilities across the full Azure infrastructure stack—including identity and access, networking, compute, storage, data, applications, asset management, backup and recovery, and DevOps security.
The exam was last updated on January 22, 2026, and reflects current Azure security capabilities including Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Entra ID (formerly Azure AD), Azure Key Vault, Azure Firewall, and a broad range of network security services. Candidates are expected to ensure infrastructure aligns with standards and best practices such as the Microsoft Cloud Security Benchmark (MCSB), and to connect multi-cloud environments—including AWS and GCP—to Defender for Cloud. This is an intermediate-level, role-based Microsoft certification requiring annual renewal through a free online assessment on Microsoft Learn.
This certification is designed for security engineers and cloud security professionals who implement security controls as part of an end-to-end infrastructure. Relevant job titles include Azure Security Engineer, Cloud Security Engineer, Information Security Analyst, Security Operations Engineer, and Security Architect. Candidates typically work alongside cloud architects, administrators, and developers to plan and implement solutions that meet security and compliance requirements, and may also collaborate with security operations teams in responding to Azure security incidents.
The ideal candidate has hands-on experience administering Microsoft Azure and hybrid environments, and strong familiarity with Microsoft Entra ID as well as Azure compute, networking, and storage services. This certification is well-suited to professionals who already hold the AZ-104 (Azure Administrator Associate) or have equivalent practical experience and are looking to specialize in cloud security.
Microsoft does not impose formal prerequisites for AZ-500, but the exam assumes substantial practical experience. Candidates should have working knowledge of Microsoft Azure administration, including experience managing virtual machines, virtual networks, storage accounts, and identity services. Strong familiarity with Microsoft Entra ID—including role assignments, Conditional Access, and app registrations—is essential.
Recommended preparation includes experience with or knowledge of network security concepts (NSGs, firewalls, VPNs), identity and access management (IAM), and security monitoring tools. Holding or having studied for AZ-104: Microsoft Azure Administrator Associate is a commonly recommended stepping stone. Familiarity with regulatory compliance frameworks and the Microsoft Cloud Security Benchmark (MCSB) will also be beneficial, as these concepts appear throughout the exam domains.
AZ-500 is a proctored exam administered through Pearson VUE, available at authorized testing centers or via online proctoring. Candidates have 100 minutes to complete the assessment. The exam may include interactive lab components in addition to traditional question types such as multiple choice, case studies, drag-and-drop, and scenario-based items. Microsoft does not publish the exact number of questions, as this varies between exam versions.
A passing score of 700 out of 1000 is required. Scoring is scaled and not a simple percentage. The exam is available in English, Japanese, Chinese (Simplified and Traditional), Korean, German, French, Spanish, Portuguese (Brazil), and Italian. Candidates who fail may retake after 24 hours; subsequent retakes require a 14-day waiting period, with a maximum of five attempts within a 12-month period. The certification is valid for one year and can be renewed at no cost via a free online renewal assessment on Microsoft Learn.
The AZ-500 certification positions professionals for dedicated cloud security roles in organizations running Azure or hybrid infrastructures. Common job titles held by AZ-500 certified professionals include Azure Security Engineer, Cloud Security Engineer, Security Architect, and Information Security Manager. According to ZipRecruiter (February 2026), Azure Security Engineers in the United States earn average annual salaries of approximately $146,000–$165,000, with top earners in the 90th percentile exceeding $210,000. Salaries are highest in high-demand markets such as Washington D.C., California, Massachusetts, and Washington State.
The credential is well-positioned in the job market as organizations accelerate cloud adoption and face increasing regulatory pressure around data security and compliance. The AZ-500 is a natural complement to the AZ-104 (Azure Administrator Associate) and serves as a foundation for pursuing higher-level credentials such as the SC-100 (Microsoft Cybersecurity Architect Expert). Compared to vendor-neutral security certifications, the AZ-500 provides deep, platform-specific expertise that is directly applicable to Azure-heavy enterprise environments, making it particularly valuable for professionals targeting Microsoft ecosystem organizations.
1. A security auditor is reviewing a company's Key Vault configuration. They recommend following the best practice of separating duties for managing the Managed HSM. What does this practice entail?
2. CloudManufacturing Corp runs Linux virtual machines that process sensitive manufacturing data. They need to implement a security configuration that encrypts data at rest using dm-crypt, stores encryption keys in a hardware security module, and provides detailed audit logs of all key access operations. The solution must be cost-effective and fully managed by Azure. Which combination of Azure services should they deploy?
3. Where is a Virtual Network service endpoint policy object configured and applied?
4. An organization wants to assess its compliance with the NIST SP 800-53 framework. How can they use Microsoft Defender for Cloud to automate this assessment?
5. An e-commerce company, 'eShop', runs their website on Azure App Service with a custom domain. They want to centrally manage their SSL certificate. What is the correct sequence of steps to use a certificate from Key Vault?
All exams included • Cancel anytime