Azure Security Engineer (AZ-500)
Microsoft
Complete guide to passing the Azure Security Engineer (AZ-500) exam on your first attempt.
$165
~50%
1 year (renewal required)
Global
Microsoft
$120k-$165k
Are you ready for Azure Security Engineer (AZ-500)?
Loading quiz...
Complete Overview
Exam AZ-500: Microsoft Azure Security Technologies is the single exam that earns the Microsoft Certified: Azure Security Engineer Associate credential, and it costs 165 USD in the United States. It is taken by security engineers who implement, manage and monitor security for Azure, hybrid and multi-cloud resources, and Microsoft expects candidates to arrive with practical experience administering Azure plus strong familiarity with Microsoft Entra ID, compute, network and storage.
One fact governs every decision about this exam right now: Microsoft is retiring AZ-500, the Azure Security Engineer Associate certification and its renewal assessment on August 31, 2026 at 11:59 PM Central Standard Time. After that date nobody can earn or renew the credential. The replacement is Exam SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, which earns Microsoft Certified: Cloud and AI Security Engineer Associate. If you already hold AZ-500, the certification stays on your Microsoft Learn transcript, and Microsoft Partners keep earning points or credit toward Partner requirements for one year after the retirement date.
Microsoft does not publish a fixed question count for AZ-500. Its official guidance is that most Microsoft certification exams contain between 40 and 60 questions, and the number varies by exam. Duration follows the exam-type table rather than a per-exam figure: associate and expert role-based exams without labs are allotted 100 minutes with a 120-minute seat time, while those that may contain labs get 120 minutes with a 140-minute seat time. Microsoft does not publish which exams contain labs, because labs can be pulled at short notice; you are told your exam time when you register. A score of 700 or greater on a 1,000-point scale is required to pass.
The blueprint, last updated January 22, 2026, has four skill areas and Microsoft publishes each as a band rather than a fixed percentage: Secure identity and access at 15 to 20 percent, Secure networking at 20 to 25 percent, Secure compute, storage, and databases at 20 to 25 percent, and Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel at 30 to 35 percent. That last area is the heaviest by a clear margin, so preparing as though this were an Entra ID and networking exam misallocates the largest block of study time.
The exam is proctored, may include interactive components, and is offered in English, Japanese, Chinese (Simplified), Korean, German, French, Spanish, Portuguese (Brazil), Chinese (Traditional) and Italian. Microsoft associate certifications expire after one year and are renewed free through an unproctored online assessment on Microsoft Learn, available in the six months before expiry. Microsoft publishes no pass rate for AZ-500 or any other exam.
Why Get Azure Security Engineer (AZ-500) Certified?
AZ-500 costs 165 USD in the United States, Microsoft's single price for role-based associate and expert exams, against 99 USD for fundamentals exams. The security track carries no premium over any other associate exam.
The heaviest skill area, Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel at 30 to 35 percent, covers the two products that most Azure security teams operate day to day.
Microsoft renewal is free and unproctored: passing an online assessment on Microsoft Learn in the six months before expiry extends the certification by a year at no cost, with unlimited attempts.
The exam allows access to learn.microsoft.com during the test itself, a facility Microsoft offers on role-based exams and not on fundamentals exams, which rewards candidates who know the documentation structure.
SC-500 rebuilds the same subject matter under four new headings: identity, access and governance; storage, databases and networking; compute; and security posture management. Microsoft Entra ID, Key Vault, network security groups, private endpoints, Azure Firewall, storage and Azure SQL security, disk encryption, Defender for Cloud and Microsoft Sentinel all appear in both blueprints, so AZ-500 study still counts even though the credential retires on August 31, 2026.
The credential covers multi-cloud work, not just Azure: the blueprint explicitly includes connecting Amazon Web Services and Google Cloud Platform environments to Microsoft Defender for Cloud.
Microsoft's retake policy allows a second attempt just 24 hours after a first failure, faster than the 14-day wait AWS imposes, so a narrow miss costs days rather than weeks.
Exam Format & Structure
Duration
Microsoft does not publish a per-exam duration for AZ-500. Its published table allots 100 minutes with a 120-minute seat time to associate and expert role-based exams without labs, and 120 minutes with a 140-minute seat time to those that may contain labs. You are given your exam time when you register.
Questions
Not published by Microsoft for AZ-500. Microsoft states that most of its certification exams contain between 40 and 60 questions and that the number varies by exam.
Passing Score
700 or greater on a 1,000-point scale
Question Types
- Multiple choice
- Active screen
- Build list
- Drag and drop
- Hot area
- Case studies
- Labs, which Microsoft may add or remove without notice
- Problem-solution question sets, where the same scenario is repeated with different proposed solutions
Delivery Method
Proctored through Pearson VUE, at a test centre or online. Microsoft states the exam may have interactive components.
Exam Domains & Topics
Covers managing security controls for identity and access, and managing Microsoft Entra application access and managed identities. Tasks include Azure built-in and custom role assignments, Entra roles, Privileged Identity Management settings and assignments, multifactor authentication for access to Azure resources, and Conditional Access policies scoped to cloud resources in Azure.
Key Topics to Master:
- Azure built-in role assignments and custom Azure and Microsoft Entra roles
- Microsoft Entra Privileged Identity Management settings, eligibility and approval workflows
- Multifactor authentication for access to Azure resources
- Conditional Access policies for cloud resources in Azure
- Enterprise application access and OAuth permission grants
- Microsoft Entra app registrations and permission scopes
- Admin consent and consent policies for app registrations
- Service principals compared with system-assigned and user-assigned managed identities
Covers security for virtual networks, for private access to Azure resources, and for public access to Azure resources. Expect to distinguish service endpoints from private endpoints, to place Azure Firewall against Application Gateway and Front Door correctly, and to reason about effective security rules when NSGs, ASGs and user-defined routes interact.
Key Topics to Master:
- Network security groups and application security groups
- Azure Virtual Network Manager for network group management
- User-defined routes, virtual network peering and VPN gateway
- Virtual WAN including secured virtual hub
- Point-to-site and site-to-site VPN security, and encryption over ExpressRoute
- Service endpoints compared with private endpoints and Private Link services
- Network integration for Azure App Service, Azure Functions and App Service Environments
- Azure Firewall, Firewall Manager and firewall policies
- Application Gateway, Azure Front Door, Web Application Firewall and DDoS Protection Standard
Covers advanced security for compute, security for storage, and security for Azure SQL Database and Azure SQL Managed Instance. Remote access via Azure Bastion and just-in-time VM access, container platform security across AKS, ACI, ACA and ACR, disk encryption options, and the several distinct methods of controlling access to Azure Files and Blob Storage all appear here.
Key Topics to Master:
- Azure Bastion and just-in-time VM access
- Network isolation, authentication and security monitoring for Azure Kubernetes Service
- Security monitoring for Azure Container Instances and Azure Container Apps
- Access management for Azure Container Registry
- Azure Disk Encryption, encryption at host and confidential disk encryption
- Storage account access control, access keys and shared access signatures
- Soft delete, versioning, backups and immutable storage for data protection
- Bring your own key and infrastructure-level double encryption for Azure Storage
- Microsoft Entra database authentication, auditing, dynamic data masking, Transparent Data Encryption and Always Encrypted
The largest skill area. Covers enforcing cloud governance policies, managing security posture with Microsoft Defender for Cloud, configuring threat protection, and running security monitoring and automation. Azure Key Vault sits inside this area rather than with data protection, which surprises candidates who study Key Vault alongside storage encryption.
Key Topics to Master:
- Azure Policy definitions and initiatives, and interpreting compliance results
- Azure Key Vault network settings, vault access policies compared with Azure RBAC, key rotation and backup
- Defender for Cloud Secure Score, Inventory and regulatory compliance standards
- Custom security standards and multi-cloud connectors for AWS and GCP
- Cloud workload protection plans including Defender for Servers, Databases and Storage
- Agentless scanning and Microsoft Defender Vulnerability Management for Azure VMs
- Defender for Cloud DevOps security connectors for GitHub, Azure DevOps and GitLab
- Microsoft Defender External Attack Surface Management
- Data collection rules in Azure Monitor, Microsoft Sentinel data connectors, analytics rules and automation
Recommended Study Plan
- 1Check the retirement date on the Microsoft Learn AZ-500 study guide page and on the exam and assessment lab retirement list before booking anything
- 2If the AZ-500 window has closed, download the SC-500 study guide instead and map its four skill areas against the AZ-500 areas you already know
- 3Take the free AZ-500 practice assessment on Microsoft Learn to get a domain-level baseline
- 4Set up an Azure free account or a pay-as-you-go subscription with a spending limit for lab work
- 5Copy the four skill area bands into a tracker and allocate hours in proportion, giving Defender for Cloud and Sentinel the largest share
- 1Work through the Microsoft Learn module set on managing identity and access in Azure
- 2Create a custom Azure role with a narrow actions list and assign it at resource group scope, then verify with the Check access blade
- 3Configure Privileged Identity Management for an Azure resource role with approval and justification requirements, then activate it as an eligible user
- 4Build a Conditional Access policy that requires MFA for access to the Azure management plane and test it in report-only mode first
- 5Register an application, grant a delegated Microsoft Graph scope, and observe the difference between user consent and admin consent
- 1Assign a system-assigned managed identity to a VM and use it to read a secret from Key Vault with no credentials in code
- 2Create a user-assigned managed identity, attach it to two resources, and compare the lifecycle with the system-assigned version
- 3Configure Key Vault access using Azure RBAC, then reconfigure the same vault using vault access policies and note which permissions differ
- 4Restrict Key Vault with firewall rules and a private endpoint, then confirm public access fails
- 5Configure automatic key rotation and take a backup and restore of a key, secret and certificate
- 1Build a hub and spoke topology with peering, then force spoke-to-spoke traffic through the hub using user-defined routes
- 2Create application security groups and write NSG rules that reference them instead of IP ranges
- 3Use Network Watcher effective security rules and the connection troubleshoot tool on a deliberately blocked path
- 4Deploy Azure Virtual Network Manager and apply a security admin rule, then observe how it overrides an NSG rule
- 5Configure a site-to-site VPN and review the IPsec and IKE policy settings
- 1Configure a service endpoint to a storage account, then replace it with a private endpoint and compare DNS resolution in each case
- 2Publish a service behind Private Link and connect to it from a peered virtual network
- 3Deploy Azure Firewall with a firewall policy containing application rules, network rules and DNAT rules
- 4Deploy Application Gateway with the Web Application Firewall in prevention mode and trigger an OWASP rule
- 5Compare Azure Front Door and Application Gateway feature by feature and write a one-line rule for choosing between them
- 1Deploy Azure Bastion and connect to a VM with no public IP address
- 2Enable just-in-time VM access in Defender for Cloud and request access, then inspect the NSG rule it creates
- 3Compare Azure Disk Encryption, encryption at host and confidential disk encryption in the Microsoft Learn documentation and record when each applies
- 4Create an AKS cluster with a private API server, Microsoft Entra integration and Azure RBAC for Kubernetes authorisation
- 5Restrict Azure Container Registry access with a private endpoint and disable admin user access
- 1Configure a storage account firewall with a virtual network rule and a resource instance exception, then test access from inside and outside
- 2Generate a user delegation shared access signature and compare it with an account key SAS in terms of revocation
- 3Enable soft delete, blob versioning and an immutable time-based retention policy, then attempt to delete a protected blob
- 4Configure customer-managed keys for a storage account and enable infrastructure encryption at creation time
- 5Enable Microsoft Entra authentication, auditing, dynamic data masking and Transparent Data Encryption on an Azure SQL Database, and read the audit log in the linked workspace
- 1Assign a built-in policy initiative such as the Microsoft cloud security benchmark and review the compliance results
- 2Write a custom policy definition with a deny effect and test it against a non-compliant deployment
- 3Apply a deployIfNotExists policy and watch the remediation task run
- 4Apply CanNotDelete and ReadOnly resource locks and confirm which operations each blocks
- 5Add a custom compliance standard to Defender for Cloud and map controls to policy assignments
- 1Review the Secure Score page, work three recommendations to completion, and record the score movement
- 2Enable Defender for Servers, Defender for Storage and Defender for Databases plans and note the per-plan pricing model
- 3Turn on agentless scanning for virtual machines and compare the findings with Defender Vulnerability Management output
- 4Connect a second cloud, either AWS or GCP, to Defender for Cloud through the multi-cloud connector
- 5Connect a GitHub or Azure DevOps organisation using the DevOps security connector and review the code scanning findings
- 1Create a Log Analytics workspace, enable Microsoft Sentinel and connect the Azure Activity and Microsoft Entra ID data connectors
- 2Write a data collection rule in Azure Monitor to collect Windows security events from a VM
- 3Enable a scheduled analytics rule from a template, then modify its KQL query and thresholds
- 4Build an automation rule that assigns an incident and triggers a Logic Apps playbook
- 5Set a workflow automation in Defender for Cloud that forwards a specific recommendation to a webhook
- 1Retake the Microsoft Learn practice assessment for AZ-500 under timed conditions and compare with your week one baseline
- 2Visit the Microsoft exam sandbox and interact with each question type, particularly build list, hot area and case studies
- 3Practise navigating learn.microsoft.com quickly for three specific facts, since the exam gives you access to that domain but adds no extra time
- 4Rehearse the break rule: decide in advance where in the exam you would take one, knowing you cannot return to any question you have already seen
- 5Re-read the change log at the bottom of the AZ-500 study guide to catch the January 22, 2026 updates to managed identities and Defender threat protection
- 1Rebuild every missed practice question into a single sentence stating the rule it tested
- 2Spend the largest remaining block on the Defender for Cloud and Sentinel skill area, which carries 30 to 35 percent of the exam
- 3Check the Microsoft Certification deals page for the exam replay or practice test offer before paying full price
- 4Book the exam and confirm your identification matches your Microsoft Learn profile name exactly
- 5Read Microsoft's exam duration and experience page so the seat time, break rules and Microsoft Learn access hold no surprises
Ready to pass Azure Security Engineer (AZ-500)?
Get 500+ practice questions, video walkthroughs, and a pass guarantee.
Best Study Resources
Study guide for Exam AZ-500
Official blueprintThe authoritative skills-measured document, last updated January 22, 2026, including the four skill area bands, the bullet-level task list and a change log comparing the current and previous versions.
Free
AZ-500 practice assessment on Microsoft Learn
Practice questionsMicrosoft-authored questions that mirror the style, wording and difficulty of the real exam, with a report showing which skill areas need work. Microsoft states it is not a replacement for training or product experience.
Free
Microsoft exam sandbox
Interface familiarisationA full run through the exam user interface including the introductory screens, the Candidate Agreement, every question type, mark for review, the review screen and the timer. The secure browser is not enabled in the sandbox.
Free
Course AZ-500T00: Secure cloud resources with Microsoft security technologies
Instructor-led trainingMicrosoft's official instructor-led course for the exam, aimed at Azure security engineers preparing for AZ-500 or performing these tasks in their day-to-day role.
Varies by training provider
Microsoft Learn training modules for Azure security
Self-paced learning pathsMicrosoft's own free learning paths covering identity and access, platform protection, security operations and data and application security, with embedded knowledge checks.
Free
Microsoft cloud security benchmark documentation
Official referenceThe standard Microsoft names in the AZ-500 audience profile as what the infrastructure should align to. It is also the default compliance standard shown in Microsoft Defender for Cloud.
Free
Microsoft Defender for Cloud documentation
Official documentationThe densest source for the 30 to 35 percent skill area, covering Secure Score, workload protection plans, multi-cloud connectors, agentless scanning and DevOps security.
Free
Microsoft Sentinel documentation
Official documentationCovers workspace design, data connectors, syslog and CEF collection, analytics rules, automation rules and playbooks, all of which appear in the monitoring and automation task list.
Free
Study guide for Exam SC-500
Successor exam blueprintThe blueprint for the replacement certification, Microsoft Certified: Cloud and AI Security Engineer Associate. Its four areas are Manage identity, access, and governance at 20 to 25 percent, Secure storage, databases, and networking at 25 to 30 percent, Secure compute at 20 to 25 percent, and Manage and monitor security posture at 20 to 25 percent.
Free
Microsoft Certification deals page
Discounts and offersWhere Microsoft publishes current exam offers, including bundles that pair an exam with a retake. Microsoft's terms require the exam and the retake to be scheduled and taken within 12 months of purchase, and the retake cannot be scheduled until you have taken the first attempt.
Free to browse
Common Mistakes to Avoid
Booking AZ-500 without checking the retirement date, then discovering no appointment slots exist before August 31, 2026.
Check the Microsoft exam and assessment lab retirement list first. AZ-500 retires August 31, 2026 at 11:59 PM Central Standard Time, and Microsoft is explicit that you cannot earn or renew the certification after that. If the window is closed, prepare for SC-500 instead: its blueprint reuses the Entra ID, Key Vault, networking, storage, database, compute and Defender for Cloud material and adds AI workload security on top.
Studying AZ-500 as an identity and networking exam, and treating Defender for Cloud and Sentinel as a final-week topic.
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel is 30 to 35 percent of the exam, larger than any other area and larger than identity and access at 15 to 20 percent. Give it the biggest single block of lab time, including Secure Score remediation, workload protection plans, data collection rules and analytics rules.
Studying Azure Key Vault alongside storage and disk encryption, and missing it in revision because it sits in a different skill area.
In the AZ-500 blueprint, Key Vault network settings, access configuration, certificate and secret management, key rotation and backup all sit under the Defender for Cloud and Sentinel skill area, inside the cloud governance task. Revise Key Vault as a governance topic, and practise both the vault access policy model and the Azure RBAC model, because questions test the difference.
Confusing service endpoints with private endpoints when a question asks how to reach a PaaS service privately.
Build both in a lab and compare what changes. A service endpoint keeps traffic on the Microsoft backbone but the service keeps its public IP and DNS name; a private endpoint gives the service a private IP in your subnet and changes DNS resolution. Questions that mention on-premises access over VPN or ExpressRoute almost always want a private endpoint.
Taking a break at a convenient moment and losing access to questions that were marked for review.
Microsoft builds five minutes of break time into the exam clock, but once a break starts you cannot return to any question you have already seen, even unanswered ones or those marked for review. Answer and review everything on screen before selecting Take a break, and note that the exam timer keeps running throughout.
Relying on the in-exam Microsoft Learn access as a substitute for knowing the material.
Microsoft gives role-based exam candidates access to everything on learn.microsoft.com except Q&A, practice assessments and your profile, but adds no extra time and lets the clock run while you browse. Microsoft states plainly that using it on every question means you will not finish. Practise looking up at most two or three specific facts quickly.
Preparing with material written before January 22, 2026 and missing the current managed identity and Defender threat protection content.
Read the change log at the end of the AZ-500 study guide. The January 22, 2026 revision renamed the Entra application access objective to include managed identities and made minor changes to advanced compute security and Defender for Cloud threat protection. Anything not covering agentless scanning, DevOps security connectors or External Attack Surface Management is out of date.
Assuming an expired Microsoft certification can be renewed later, the way a lapsed AWS certification can be regained by re-examination.
Microsoft certifications expire one year after they are earned, and the free renewal assessment only becomes available in the six months before expiry. If it lapses you must sit the full paid exam again, and after August 31, 2026 that option disappears for AZ-500 entirely. Set a reminder for the six-month renewal window as soon as you pass.
Treating Conditional Access on the Azure control plane and Azure RBAC as interchangeable access controls.
They answer different questions. Conditional Access decides whether the sign-in is permitted, based on signals such as device state, location and MFA. Azure RBAC decides what the authenticated principal may do once in. Exam scenarios that mention a compliant device or a trusted location want Conditional Access; scenarios about who can restart a VM want a role assignment or Privileged Identity Management.
Exam Day Tips
- 1
Confirm your appointment falls before August 31, 2026 at 11:59 PM Central Standard Time. Microsoft retires the AZ-500 exam at that moment, and no result after it earns the certification.
- 2
Allocate the full seat time, not the exam time. Microsoft gives associate role-based exams a 120-minute seat time for a 100-minute exam, and 140 minutes for a 120-minute exam that may contain labs, with the extra covering instructions, the Candidate Agreement and post-exam comments.
- 3
Five minutes of break time is built into the exam clock. You may take multiple breaks of any length, but the clock never stops and you cannot return to any question you have already viewed once a break begins.
- 4
You cannot start a break in the middle of a lab or inside a problem-solution question set, though you can take one before or after either. Breaks are allowed during case studies, with the same no-return rule.
- 5
Use the Microsoft Learn button in the left navigation pane to open documentation in a split screen. Everything on learn.microsoft.com is available except Q&A, practice assessments and your profile, and attempting to reach any other domain is blocked. No extra time is granted for using it.
- 6
Ctrl+F on Windows or Command+F on Mac searches the current Microsoft Learn page inside the exam window. It works only within the Learn pane, not on exam questions.
- 7
If the exam is not offered in your preferred language, request an additional 30 minutes when you register. Microsoft offers AZ-500 in ten languages, and localized versions are updated roughly eight weeks after the English version.
- 8
If a lab appears, it may require multi-factor authentication to reach an administrative portal. Microsoft provides a Contoso Authenticator app inside the lab; scan the QR code from the screen and paste the six-digit code, and if the code is not detected set display zoom to 120 percent.
- 9
Request accommodations before you register, not after. Assistive devices will be blocked by the secure browser during the exam unless an accommodation has been approved in advance.
- 10
If you use the exam sandbox to rehearse, remember that the secure browser is not enabled there, so the sandbox will not reveal whether your assistive setup will work in the real exam.
Career Paths & Salary Ranges
Azure security engineer
The role the certification is named for. Implements and manages security controls across Azure, hybrid and multi-cloud estates, maintains posture in Microsoft Defender for Cloud, and remediates vulnerabilities against the Microsoft cloud security benchmark.
$120k-$165k
Cloud security analyst
Operates Microsoft Sentinel day to day: manages data connectors and data collection rules, tunes analytics rules, triages incidents, and builds automation rules and Logic Apps playbooks to shorten response time.
$120k-$165k
Identity and access engineer
Owns Microsoft Entra ID configuration: Conditional Access policy design, Privileged Identity Management, MFA and passwordless rollout, app registrations and consent governance, and managed identity adoption to remove stored credentials.
$120k-$165k
Cloud security architect
Designs the landing zone and its guardrails: Azure Policy initiatives, management group structure, network segmentation across hub and spoke or Virtual WAN, key management strategy, and the standards that engineering teams build against.
$120k-$165k
Cloud compliance and governance specialist
Maps regulatory frameworks onto Azure Policy initiatives and Defender for Cloud compliance standards, adds custom standards where a framework has no built-in equivalent, and produces the evidence auditors ask for.
$120k-$165k
DevSecOps engineer
Connects GitHub, Azure DevOps or GitLab to Defender for Cloud DevOps security, enforces security controls through infrastructure as code, secures container pipelines through Azure Container Registry and AKS, and keeps secrets out of repositories using Key Vault and managed identities.
$120k-$165k
Prerequisites & Requirements
- There are no formal prerequisites. AZ-500 is a single exam and Microsoft does not require any other certification first.
- Microsoft states that candidates should have practical experience administering Microsoft Azure and hybrid environments.
- Microsoft also expects strong familiarity with Microsoft Entra ID, as well as compute, network and storage in Azure.
- A Microsoft Learn profile connected to your certification profile is needed to schedule the exam, take practice assessments, renew, and print certificates.
- Many candidates hold AZ-104 Azure Administrator Associate first because it covers the Azure administration experience the AZ-500 audience profile assumes, but Microsoft does not require it.
- For the successor exam SC-500, Microsoft adds familiarity with Microsoft 365 administration to the same Azure and Entra ID expectations.
Frequently Asked Questions
Is AZ-500 being retired?
Yes. Microsoft retires Exam AZ-500, the Microsoft Certified: Azure Security Engineer Associate certification, and its renewal assessment on August 31, 2026 at 11:59 PM Central Standard Time. After that date you can neither earn nor renew the certification. The certification remains on the transcript of anyone who already holds it, and Microsoft Partners continue earning points or credit toward Partner requirements for one year after the retirement date.
What replaces AZ-500?
Exam SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, which earns Microsoft Certified: Cloud and AI Security Engineer Associate. Its four skill areas are Manage identity, access, and governance at 20 to 25 percent, Secure storage, databases, and networking at 25 to 30 percent, Secure compute at 20 to 25 percent, and Manage and monitor security posture at 20 to 25 percent. SC-500 adds AI workload security, Microsoft Purview Data Security Posture Management, Microsoft Entra Agent ID and Microsoft Security Copilot, and expects familiarity with Microsoft 365 administration alongside Azure.
How much does the exam cost?
165 USD in the United States. Microsoft prices the exam by the country or region in which it is proctored, so the amount charged elsewhere differs. Microsoft uses two main price tiers in the United States: 99 USD for fundamentals exams and 165 USD for role-based associate and expert exams, of which AZ-500 is one.
What is the passing score?
700 or greater on a 1,000-point scale. Microsoft scales scores rather than reporting a raw percentage, so 700 does not mean 70 percent of questions answered correctly. Your score report shows performance by skill area, which tells you where to focus if you need a retake.
How long is the exam and how many questions are there?
Microsoft does not publish a per-exam question count for AZ-500, stating only that most of its certification exams contain between 40 and 60 questions and that the number varies. Duration follows exam type: associate and expert role-based exams without labs get 100 minutes of exam time and a 120-minute seat time, while those that may contain labs get 120 minutes and a 140-minute seat time. Microsoft will not say which exams have labs because labs can be withdrawn at short notice, so you learn your exam time at registration.
What happens if I fail?
You can retake it 24 hours after the first attempt. A 14-day waiting period applies between every subsequent attempt, and you may not take the same exam more than five times in a 12-month period counted from your first attempt; after a fifth failure you become eligible again 12 months from that first attempt date. You pay for each attempt. Microsoft waives the waiting period only for documented internet connectivity or equipment failures with an existing Pearson VUE case number.
How does renewal work and does it cost anything?
Renewal is free, online and unproctored. Microsoft associate, expert and specialty certifications expire one year after they are earned, and a Renew button appears on your Microsoft Learn profile when the certification is within six months of expiring. Passing the renewal assessment extends the certification by a year. There is no limit on renewal attempts, though after a second failed attempt you must wait 24 hours between tries. Microsoft does not use continuing education credits for certification renewal.
Can I still renew AZ-500 after the retirement date?
No. Microsoft states that renewal assessments retire alongside the certification, and it recommends renewing before the retirement date if you are eligible, because the option disappears afterwards. If your AZ-500 credential is within six months of expiring, renewing before August 31, 2026 buys you another year of active status; if it expires after that, there is no path to reactivate it.
What identification do I need?
Pearson VUE requires government-issued photo identification, and the name on it must match the name on your Microsoft Learn certification profile. If your profile name is wrong, correct it well before the appointment rather than on the day. ID requirements differ between test centre and online proctored appointments, so check the rules for the delivery method you booked when you receive your confirmation.
Can I take AZ-500 online?
Yes. The exam is proctored and Microsoft delivers it through Pearson VUE at a test centre or online. Microsoft notes that the exam may contain interactive components. For online delivery, the secure browser blocks all third-party applications, which is why assistive devices require an approved accommodation requested before registration.
Are calculators, notes or reference materials allowed?
No outside materials are permitted, and none are needed because AZ-500 requires no calculation. Microsoft does provide one reference inside the exam: on role-based exams you can open learn.microsoft.com in a split screen and browse everything except Q&A, practice assessments and your profile. No extra time is added for it, the exam clock keeps running, and Microsoft warns that leaning on it for every question will leave you unable to finish.
Can I take breaks during the exam?
Yes, without requesting them in advance. Microsoft builds five minutes of break time into the exam clock and removed questions to make room for it. You can take multiple breaks of any length, but the timer keeps running, and once a break starts you cannot return to any question you have already viewed, including unanswered ones and those marked for review. You must initiate the break through the exam interface or your exam is revoked, and you may not access any unauthorized material during it.
What accommodations are available?
Microsoft offers accommodations for candidates who use assistive devices, require extra time, or need modification to any part of the exam experience, and these must be requested before you register. Separately, if the exam is not offered in your preferred language you can request an additional 30 minutes; AZ-500 is offered in ten languages, so this applies mainly to candidates outside that list.
What question types should I expect?
Microsoft does not confirm the format of any specific exam, but its sandbox demonstrates the types used on role-based exams: multiple choice, active screen, build list, drag and drop, hot area, case studies, labs, plus problem-solution question sets where one scenario is repeated with different proposed solutions and each must be judged independently. The sandbox also shows the mark-for-review function, the review screen and the timer.
How does AZ-500 compare with SC-200?
AZ-500 is an engineering exam and SC-200, Microsoft Security Operations Analyst, is an operations exam. AZ-500 asks you to configure controls: NSGs, private endpoints, Key Vault access, disk encryption, Azure Policy. SC-200 asks you to hunt, triage and respond across Microsoft Defender XDR and Microsoft Sentinel. They overlap on Sentinel analytics rules and Defender for Cloud alerts, which is roughly the top third of the AZ-500 blueprint. Both are 165 USD associate-level exams with a 700 pass mark and annual renewal.
How does AZ-500 compare with AWS Certified Security - Specialty?
AWS Certified Security - Specialty costs 300 USD, runs 170 minutes with 65 questions, needs 750 on a 100 to 1,000 scale and stays valid for three years. AZ-500 costs 165 USD, needs 700 on a 1,000-point scale and expires after one year, renewed free online. AWS publishes exact domain percentages; Microsoft publishes bands. The AWS exam is entirely scenario-based multiple choice, while AZ-500 mixes in drag and drop, hot area, case studies and sometimes labs.
Is there a published pass rate?
No. Microsoft does not publish pass rates for its certification exams, so any percentage quoted for AZ-500 comes from third parties, not from Microsoft. Microsoft publishes the passing score of 700 and the score report structure, but not the proportion of candidates who reach it.
Should I take AZ-500 now or wait for SC-500?
That depends on whether an appointment is still available before August 31, 2026. If it is and you are ready, AZ-500 gives you a credential now, and Microsoft says nothing about revoking credentials already earned. If you are not ready in time, prepare for SC-500 directly: identity, Key Vault, networking, storage, database and Defender for Cloud content transfers, and the additional work is the AI security material, Microsoft Purview DSPM, Entra Agent ID and Microsoft Security Copilot. Note that SC-500 is currently offered in English only, unlike AZ-500's ten languages.
Pass Azure Security Engineer (AZ-500), Guaranteed
94% pass rate on first attempt
One-time • Lifetime access