Training · Cloud and AI Security Engineer

SC-500, security engineering for the AI era.

AZ-500 retires August 31, 2026. SC-500 is its real successor, and it goes further: alongside identity, platform, and data security, it now covers securing AI agents and workloads directly.

What you'll walk away with

Built for administrators ready to specialize in security

If you’ve finished AZ-104

This is the natural security specialization path, hands-on configuration of real Microsoft security tooling.

If you’re exam-bound

Five domains, weighted close to evenly, with a genuinely new one, securing AI workloads, that older security exams never covered.

Curriculum

5 sections, exam-weighted

Module 1 is free to try before you enroll. Everything else unlocks after you enroll.

1. Identity and access

20–25% of exam
1.1 Hardening Entra ID authenticationFree preview
1.2 Conditional Access as a security controlLocked
1.3 Privileged Identity ManagementLocked

2. Platform protection

20–25% of exam
2.1 Defender for Cloud, configured properlyLocked
2.2 Network security controlsLocked
2.3 Securing platform resources at scaleLocked

3. Security operations

20–25% of exam
3.1 Microsoft Sentinel, hands-onLocked
3.2 Building detection rulesLocked
3.3 Incident response in practiceLocked

4. Data and application security

15–20% of exam
4.1 Information protection in practiceLocked
4.2 Securing applications and APIsLocked

5. Securing AI workloads

15–20% of exam
5.1 Why AI workloads need their own security modelLocked
5.2 Content safety and prompt injection defensesLocked
5.3 Governing agent permissions and identityLocked

Capstone

Practical build
Design a security posture covering identity, platform, and an AI agent deploymentLocked