AZ-500 retired on August 31, 2026. Microsoft’s direct replacement is SC-500, the Cloud and AI Security Engineer Associate exam that became available on July 21, 2026. For anyone preparing now, the practical conclusion is simple: AZ-500 is a legacy exam, while SC-500 is the current Microsoft cloud-security destination.
The transition does not make Azure security knowledge obsolete. Identity, networking, Key Vault, storage, databases, compute, governance, and Defender for Cloud remain highly relevant. What changed is the role boundary. SC-500 treats those controls as part of end-to-end cloud and AI workload security and places stronger emphasis on practical implementation and posture management.
AZ-500 now serves as historical architecture context
Older AZ-500 material can still teach durable Azure security concepts, especially when it explains how a control behaves rather than how an exam was weighted. Network segmentation, privileged access, Key Vault, Defender for Cloud, logging, and data security remain useful subjects for current practitioners.
What should not carry forward unchanged are retired exam logistics, legacy objective percentages, and the assumption that an Azure Security Engineer certification can still be earned through AZ-500. Microsoft’s retired-exam record is clear: the exam closed at the end of August 2026.
A practical transition plan begins by comparing the final AZ-500 skills with the current SC-500 guide. Mark concepts that transfer directly, topics that are now framed differently, and entirely new areas. This creates a personalized gap analysis. Someone with strong Azure security experience may need relatively little review of network or Key Vault concepts but more time on AI workload security and the newer posture-management model.
SC-500 broadens the role beyond classic Azure security
SC-500 describes a security engineer protecting systems and data across cloud and hybrid environments. The role spans identity, network, application, data, and compute controls and explicitly includes platforms, data, identities, and infrastructure used by AI workloads.
That wording matters. A candidate should think beyond “secure an Azure resource” toward “implement a coherent security boundary across the workload.” The same engineer may need to reason about Entra ID, Key Vault, private connectivity, storage permissions, compute hardening, AI resources, posture findings, and operational monitoring as connected parts of one design.
The credential change also affects how teams describe roles internally. ‘Azure Security Engineer’ suggested a platform-centered responsibility. ‘Cloud and AI Security Engineer’ signals a wider boundary that includes hybrid environments and AI workloads. Job titles do not have to change immediately, but training plans and ownership models should recognize that modern cloud security increasingly crosses product and workload categories.
Identity and access remain foundational
SC-500 retains strong emphasis on Microsoft Entra ID, including Privileged Identity Management, Conditional Access, authentication methods, application identities, consent, and managed identities. These are not side topics. Identity determines who can administer cloud controls and what workloads can reach.
Preparation should connect configuration to threat models. Understand why just-in-time privilege changes risk, how managed identity reduces stored credentials, and how excessive OAuth consent or role assignment can bypass a network boundary. Identity is the control plane through which many other security decisions are made.
Key Vault moves into an end-to-end access story
SC-500 explicitly includes deploying and securing Azure Key Vault, controlling access, configuring firewall settings, managing keys, secrets, and certificates, and using posture capabilities to find secret exposure. This is broader than memorizing vault features.
Study Key Vault as a system: managed identities, RBAC, private connectivity, logging, rotation, recovery, and ownership. The related Azure Key Vault certificate management can reinforce one part of that story, but current preparation should connect the vault to workload identity and cloud posture.
SC-500 preparation benefits from scenario thinking. Instead of memorizing which control exists, ask how an attacker could move from an exposed resource to a sensitive target and which identity, network, data, or compute control would break the path. That approach ties the domains together and reflects the way Microsoft now presents contextual posture and end-to-end security.
Network security remains central but is tied more tightly to workloads
Azure Firewall, application delivery security, private connectivity, DDoS protection, and network segmentation remain relevant. The stronger mental model is to follow a workload path from external entry point to internal service and identify where each control enforces trust.
Do not study network products as isolated feature lists. Connect routing, DNS, identity, private endpoints, firewall policy, and workload exposure. The current role expects engineers to understand how those pieces interact and how a control failure changes the attack surface.
Teams maintaining AZ-500 labs should update them selectively. A Key Vault lab can remain useful if it uses current RBAC and networking patterns. A Defender for Cloud lab should be refreshed to show current risk prioritization and attack paths. Add AI workload scenarios where the new exam expects them, and remove retired exam instructions that no longer map to a live objective.
Compute, storage, and databases receive explicit security treatment
SC-500 includes securing compute as well as storage and databases. This means hardening virtual machines and platform services, protecting data-plane access, applying encryption and network restrictions, and monitoring for risky configurations. Security is not complete when identity and perimeter controls are correct.
Think about the deployed resource itself: who can administer it, what data it contains, how it is patched, how secrets reach it, which endpoints are exposed, and which telemetry proves the intended state. This is where cloud security engineering becomes operational rather than architectural only.
AI workload security is a new explicit part of the path
The clearest signal in the replacement credential is AI. SC-500 responsibilities include securing AI solutions and the identities, infrastructure, and data they rely on. That does not mean every candidate becomes an AI engineer. It means cloud-security controls must extend to a new workload type.
Study AI security through familiar boundaries: identity and secrets, private connectivity, data access, content and service configuration, monitoring, and posture. The technology is newer, but the security questions are recognizable. Who can invoke the resource, what data can it reach, where is output stored, and what evidence shows the environment remains within policy?
Certification records also need clear language. Someone who earned the Azure Security Engineer Associate credential before retirement did not lose the achievement on August 31; Microsoft states that earned retiring certifications remain valid according to their normal validity period. The important distinction is that new candidates can no longer earn it through AZ-500 and should follow SC-500 instead.
Posture management is more explicitly operational
Microsoft Defender for Cloud, risk prioritization, attack paths, recommendations, and monitoring are central to current cloud-security work. SC-500 expects candidates to manage and monitor posture, not simply configure preventative controls once.
The Microsoft Defender cloud security provides useful adjacent context. For current preparation, connect findings to remediation ownership and architecture feedback. A secure design is one that can detect when deployed reality no longer matches the intended boundary.
Finally, update bookmarks, internal wiki pages, onboarding checklists, and certification reimbursement guidance. Small administrative references can keep a retired exam alive inside an organization long after the official transition. Repointing those materials to SC-500 reduces confusion for new hires and makes the change visible beyond the training team. A clean transition is partly technical curriculum work and partly information hygiene.
Current learners should translate legacy study into the new role
If you already studied AZ-500, do not restart from zero. Keep the Azure security foundations, then map them against SC-500’s current objectives. Identify the areas that are newly emphasized: AI workload security, broader end-to-end control implementation, and the current posture-management model.
Use the retired Azure Security Engineer credential page only as historical context and the Microsoft vendor path for broader navigation. The exam target for new cloud-security preparation is SC-500. The transition is best understood as continuity in core Azure security plus a wider, more modern workload boundary.
The transition is therefore best understood as evolution rather than replacement of knowledge. Core Azure security skills still matter, but the current role expects them to operate across a broader workload surface and within a more contextual security model. Treat legacy AZ-500 content as a foundation, then deliberately update the parts that Microsoft has expanded or reframed for SC-500.
For managers planning team development, the transition is also a chance to divide learning by responsibility. Network engineers can deepen private connectivity and perimeter controls, identity specialists can focus on Entra and privileged access, platform teams can own compute and data controls, and security engineers can integrate those domains through Defender for Cloud and posture management. Cross-training still matters, but shared scenarios are more effective than expecting every person to become equally deep in every control area.
For individuals, this also means resumes and learning plans should be precise about timing. List an earned AZ-500-based certification as an earned credential if it remains valid, but do not describe AZ-500 as the current exam. For future preparation, use SC-500 terminology so recruiters, managers, and learners are all discussing the same active path.
That precision keeps the transition clear for everyone involved.