Certification guide

AZ-500

Microsoft Azure Security Engineer: the honest guide

AZ-500 is the Azure security engineering exam. It is the one that asks you to configure the controls rather than respond to what gets past them, and it assumes you can already administer Azure competently.

It is an advanced certification and it behaves like one. The gap between AZ-104 and this exam is smaller than the gap between nothing and AZ-104, but it is real, and the identity material in particular goes considerably deeper than most people expect.

Who Azure Security Engineer is for

A good fit if

  • You administer Azure and are moving toward a security-focused role.
  • You hold AZ-104 and want the natural security specialisation on top of it.
  • Your organisation needs demonstrable Azure security competence for compliance or a customer requirement.
  • You work with Microsoft Entra ID conditional access and privileged access and want the credential that covers it.

Probably not, if

  • You are new to Azure. This exam assumes AZ-104 level administration and does not teach it, so sitting it first is an expensive detour.
  • You want security operations rather than engineering. SC-200 is the analyst exam; this one is about building controls.
  • You want vendor-neutral security knowledge. Security+ and CySA+ cover concepts that transfer; this is Azure specific throughout.

Is Azure Security Engineer worth it?

For an Azure administrator moving toward security, this is the right next exam and the material is directly applicable. Conditional access, privileged identity management and network security are things you will configure rather than merely describe.

For somebody without Azure administration experience, it is premature. The exam assumes fluency with resource groups, networking and identity, and candidates who arrive without it fail on operational detail rather than on security concepts.

The free annual renewal changes the long-term calculation. Unlike a certification with a recurring fee, holding AZ-500 costs the one exam plus an hour a year, which makes it cheap to keep current in a fast-moving area.

What the exam actually asks you to do

Multiple choice and multiple response, plus drag-and-drop ordering, hot area items where you click a region of a screenshot, and case studies that hold one scenario across several linked questions.

Item formats

  • Multiple choice
  • Multiple response
  • Drag and drop
  • Hot area
  • Case study

The highlighted formats are the ones you cannot answer from memory alone. Microsoft Learn, exam duration and question types

Domain breakdown and official weightings

From the official Microsoft Learn study guides. Manage identity and access is the heaviest domain at 28 percent, followed by Manage security operations at 28 percent.

  • Manage identity and access28%
  • Secure networking22%
  • Secure compute, storage, and databases22%
  • Manage security operations28%

Where to focus: Identity and security operations are 56 percent together. Build a lab tenant and configure conditional access and Defender for Cloud yourself; the exam asks what happens, not what the feature is called.

Microsoft Azure: Microsoft Learn study guides

Study plans by experience level

AZ-104 certified, working in Azure

5 to 6 weeksat 6 hours

  1. 1Week 1: read the skills outline and mark what you have not configured yourself. That list is the study plan.
  2. 2Weeks 2 to 3: identity and access, which is 28 percent of the exam and the deepest area. Conditional access, privileged identity management and identity protection all need Entra ID P2, so plan the trial around this block.
  3. 3Week 4: secure networking and the compute, storage and database protections.
  4. 4Week 5: security operations, meaning Defender for Cloud, secure score and Sentinel integration.
  5. 5Week 6: the Microsoft Learn path as a checklist, then a timed practice sitting.

Security background, new to Azure

12 to 14 weeksat 6 hours

  1. 1Work through AZ-104 material first, even if you do not sit the exam. This certification assumes it and does not teach it.
  2. 2Weeks 1 to 5: Azure fundamentals of identity and networking, mapping what you already know onto Azure names.
  3. 3Weeks 6 to 9: the identity area in depth, with a P2 trial started deliberately for one concentrated block rather than on day one.
  4. 4Weeks 10 to 12: platform protection and data security, built in a lab rather than read.
  5. 5Weeks 13 to 14: security operations and practice questions.

Coming from SC-200

6 to 8 weeksat 6 hours

  1. 1Start from what does not overlap. Defender for Cloud and Sentinel you already know; the identity, networking and data protection configuration you probably do not.
  2. 2Weeks 1 to 3: identity and access, which is the largest gap for an operations person and the largest domain on the exam.
  3. 3Weeks 4 to 5: networking controls, which is the second gap: network security groups, firewalls, private endpoints and application gateways.
  4. 4Weeks 6 to 7: compute, storage and database protection, especially Key Vault and encryption options.
  5. 5Week 8: timed practice, then book.

Common mistakes

Sitting it without AZ-104 level administration
The most common reason for failure. This exam expects you to already know how Azure is put together, and questions about securing a resource assume you can picture the resource. Security knowledge does not compensate for missing platform knowledge.
Starting the P2 trial on day one
Conditional access, privileged identity management and identity protection all need Entra ID P2, and the trial is time limited. Candidates who start it immediately find it expired before they reach the material it was for.
Confusing RBAC, Azure Policy and resource locks
They answer different questions: who may act, what may exist, and what may be changed. The exam tests the distinction directly and it is the single most reliable source of lost marks in the governance material.
Studying identity from documentation only
Conditional access is a policy engine and its behaviour is easier to understand by building a policy and watching it apply than by reading about signals and controls. A trial tenant makes this area substantially easier.
Neglecting the operations domain
Defender for Cloud, secure score and Sentinel integration are 28 percent of the exam, and engineers focused on configuration tend to under-prepare the monitoring side of it.

What comes after passing

SC-200 is the companion certification if you want the operations side to go with the engineering, and the overlap around Defender for Cloud makes the second exam noticeably cheaper in study time.

Set a renewal reminder immediately. Role-based Microsoft certifications last one year and renew free online, but a lapsed certification means sitting the full exam again.

This is a credible signal for an Azure security engineer role and it pairs well with a vendor-neutral security credential if you want the knowledge to travel.

Azure security moves faster than most of this catalog, so expect the annual renewal assessment to ask about services that did not exist when you passed.

Costs across the full renewal cycle are on the Azure Security Engineer cost page.

Frequently asked questions

Do I need AZ-104 before AZ-500?

There is no formal prerequisite, but it is the strongest recommendation in this guide. AZ-500 assumes you can already administer Azure, and the candidates who fail are usually the ones whose gap was platform knowledge rather than security knowledge. Skipping AZ-104 moves that material into your study plan.

What is the difference between AZ-500 and SC-200?

AZ-500 is engineering: configuring identity, network, compute and data protections in Azure. SC-200 is operations: detecting, investigating and responding to incidents across Defender and Sentinel. They overlap around Defender for Cloud and are otherwise different jobs.

Do I need a paid Entra ID licence to study?

Not to pass, but you do need trial access. Conditional access, privileged identity management and identity protection are examinable and all require Entra ID P2. The trial covers them, so the advice is to time it for the identity block rather than starting it on day one.

How long does AZ-500 last?

One year, and it renews free through an unproctored online assessment on Microsoft Learn that takes about an hour. The window opens six months before expiry; if it lapses you sit the full exam again at full price.

Is AZ-500 harder than SC-200?

For most people, yes. AZ-500 assumes deeper platform knowledge and its identity material goes further, while SC-200 is more contained because it lives inside a set of portals. Somebody who administers Azure daily may find the reverse, because SC-200 requires KQL that an engineer may not use.

Keep reading

Cheat sheets

Printable reference tables, free.

Every guide and cost breakdown, by vendor

Practise Azure Security Engineer for free while you decide

Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.

Start free Azure Security Engineer questions