SC-500 Certification
SC-500 is Microsoft's role-based certification exam for security engineers who implement security across the Microsoft cloud and AI stack. The credential validates subject matter expertise in implementing security controls and threat protection, managing identity and access, and protecting data, applications, and networks in cloud and hybrid environments as part of an end-to-end infrastructure[^c1]. It belongs to Microsoft's role-based certification portfolio, which replaced the legacy MCSA, MCSD, and MCSE tracks with credentials aligned to current job roles and continuously updated cloud services. SC-500 is the successor to the AZ-500 exam, which it replaces and which retires on August 31, 2026[^c6].
The certification's scope spans the core security domains of the Microsoft platform. Identity and access management is centered on Microsoft Entra ID, including conditional access policies, identity protection, and privileged identity management. Data protection relies on Microsoft Purview for classification, sensitivity labels, encryption, and data loss prevention across cloud and AI data. AI security has become a defining component of the credential: prompt injection is the number one vulnerability in OWASP's Top 10 for LLM Applications[^c2], and the syllabus covers the AI threat landscape, content safety controls, prompt injection defense, and AI governance. Threat detection and response build on Microsoft Defender for Cloud and Microsoft Sentinel, and compliance is managed through Azure Policy, Microsoft Secure Score, and Microsoft Purview Compliance Manager, which provides over 320 regulatory assessment templates[^c4].
Preparation for SC-500 combines official Microsoft Learn learning paths, instructor-led training, the Exam Ref study guide, official practice tests, and hands-on labs. Detection-lab builds in Azure can be run almost entirely free of charge using a trial subscription, Microsoft Sentinel's free trial, and Microsoft Defender for Cloud[^c5], giving candidates practical experience with the same tools used in production. The field itself is being reshaped by AI-driven security operations, with tools such as Microsoft Security Copilot delivering agentic automation and AI-driven insights to help security teams protect, detect, and respond at the speed and scale of AI[^c3].