- Implement and configure Privileged Identity Management (PIM).
- Implement conditional access policies.
- Implement authentication methods, including MFA and passwordless.
- Implement identity for applications, manage OAuth consent, and configure managed identities for Azure resources.
Microsoft Cloud and AI Security Engineer Certification Training Course SC-500
Prepare for Exam SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads — the associate credential that replaces AZ-500. Accumentum maps the course to Microsoft’s published skills measured.
Implement end-to-end security controls for cloud and AI workloads — not AZ-500-only Azure security.
Accumentum’s Microsoft Cloud and AI Security Engineer Certification Training Course (SC-500) prepares security engineers for Exam SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, which leads to Microsoft Certified: Cloud and AI Security Engineer Associate. Exam SC-500 replaces AZ-500. Microsoft has stated that AZ-500 reaches end of life on 31 August 2026; confirm current retirement details on Microsoft Learn.
Microsoft’s audience is a security engineer who protects organizational systems and data across cloud and hybrid environments and helps ensure that platforms, data, identities, and infrastructure used by AI workloads are securely implemented and monitored. Microsoft expects practical experience administering Azure and hybrid environments, strong familiarity with Microsoft Entra ID, and familiarity with Microsoft 365 administration.
This page uses Microsoft’s published skills measured. Accumentum does not invent exam prices or unofficial question counts.
What you will be able to secure, implement, and monitor.
Identity, secrets, and governance
Secure access with Microsoft Entra ID, protect secrets with Azure Key Vault, and enforce security and regulatory compliance.
Storage, databases, and networking
Implement security for storage accounts, Azure SQL and database services, and Azure network services including Firewall, Private Link, and Entra Private Access.
Secure compute including AI
Secure AI workloads with Purview DSPM, Entra Agent ID, Foundry guardrails, and Defender for AI, plus servers, VMs, and application platform services.
Posture, Sentinel, and Security Copilot
Manage posture with Defender for Cloud, collect activity in Microsoft Sentinel, and implement Microsoft Security Copilot.
Who Should Attend
- Security engineers who implement end-to-end security controls across cloud, hybrid, and AI workloads.
- Azure security professionals moving from AZ-500 to SC-500, including AI security topics that were not on AZ-500.
- People who work with architects, administrators, engineers, analysts, and developers across Azure, Microsoft 365, identity, information protection, security operations, DevOps, applications, databases, and networks.
- Learners still on AZ-500-only Azure security should use this SC-500 outline for current associate work.
Prerequisites
- Practical experience administering Azure and hybrid environments, including compute, network, and storage.
- Strong familiarity with Microsoft Entra ID.
- Familiarity with Microsoft 365 administration.
- No Accumentum-invented hour counts. Confirm any Microsoft-stated prerequisites on Microsoft Learn.
Twelve modules mapped to Microsoft SC-500 published skills.
Skills measured: manage identity, access, and governance 20–25%; secure storage, databases, and networking 25–30%; secure compute 20–25%; manage and monitor security posture 20–25%.
Secure access with Microsoft Entra ID
Secure secrets and keys with Azure Key Vault
Governance, compliance, and RBAC
Implement security for storage accounts
Implement security for databases
Implement security for Azure network services
Implement security for AI
Implement security for servers and VMs
Implement security for application platform services
Manage security posture with Defender for Cloud
Implement activity and event collection in Microsoft Sentinel
Implement Microsoft Security Copilot
- Deploy Key Vault and configure settings, access, and firewall.
- Manage keys, secrets, and certificates.
- Scan for secrets by using Defender CSPM.
- Implement Defender for Key Vault.
- Azure Policy, including built-in and custom definitions.
- Evaluate regulatory compliance and configure security controls in Microsoft Defender for Cloud.
- Resource locks; built-in and custom Azure and Entra roles; remediate overprivileged RBAC.
- Azure Backup security features and security controls by using infrastructure as code.
- Configure security for storage accounts and Azure Storage firewall rules.
- Implement Defender for Storage threat protection configurations.
- Manage access to storage, including access policies.
- Platform-level security configurations in Azure SQL.
- Database auditing for Azure SQL Database and Azure SQL Managed Instance.
- Configure Defender for Databases protection across Azure database services.
- NSGs, ASGs, and Azure Virtual Network Manager access policies.
- Virtual WAN, VPN, Microsoft Entra Private Access, private endpoints, and Private Link.
- Azure Firewall.
- Evaluate effective security rules with Azure Network Watcher diagnostics.
- Identify SharePoint data overexposure and Copilot / AI app risks with Microsoft Purview DSPM.
- Real-time protection for Microsoft Copilot Studio agents; Conditional Access and blast-radius analysis for Microsoft Entra Agent ID.
- AI Gateway in Azure API Management for Microsoft Foundry; Defender for AI Service; Foundry agent guardrails.
- Monitor AI security with the Data and AI security dashboard in Defender for Cloud; manage agents in Microsoft 365 admin center.
- Disk encryption, Azure Bastion, and just-in-time VM access.
- Extend controls to hybrid and multicloud servers with Azure Arc.
- Onboard servers to Defender for Servers, including vulnerability scanning, EDR, and agentless scanning.
- Secure boot, vTPM, integrity monitoring, and Azure Machine Configuration.
- Defender for Containers and security controls for AKS, Container Registry, Container Instances, and Container Apps.
- Security controls for Azure Functions, Logic Apps, and App Service.
- Azure Web Application Firewall.
- Security policies for back-end API protection by using API Management.
- Identify security risks with Defender CSPM and evaluate compliance frameworks.
- Enable Defender for Cloud workload protection plans.
- Connect hybrid, AWS, and GCP environments.
- Microsoft Defender Vulnerability Management and Microsoft Defender External Attack Surface Management (EASM).
- Create and connect workspaces and assign roles in Microsoft Sentinel.
- Content hub solutions and Microsoft data connectors for Azure resources.
- Syslog, CEF, Windows Security events with data collection rules, custom log tables, and data retention.
- Automation rules and playbooks; query Microsoft Purview Audit in Defender XDR.
- Configure workspaces for Security Copilot.
- Manage permissions and roles.
- Enable and configure plugins.
- Enable and configure Microsoft agents and Security Store agents.
Designed for SC-500 cloud and AI security engineering.
Skills-measured map
Twelve modules aligned to Microsoft SC-500 published skill domains.
AI security included
Secure compute includes AI workloads: Purview DSPM, Entra Agent ID, Foundry guardrails, and Defender for AI — topics that were not the AZ-500 center of gravity.
Public exam facts
Pearson VUE. Microsoft publishes a passing score of 700 or greater. Annual renewal on Microsoft Learn. No invented prices.
Prior exam context
AZ-500 is the prior Azure Security Engineer Associate exam. This course is SC-500.
Prepare for the official Microsoft SC-500 exam.
SC-500 Exam Readiness
Accumentum SC-500 training prepares security engineers to implement end-to-end security controls for cloud and AI workloads.

The Microsoft Certified: Cloud and AI Security Engineer Associate exam is SC-500 (Implementing End-to-End Security Controls for Cloud and AI Workloads). Public facts from Microsoft: delivered through Pearson VUE; a score of 700 or greater is required to pass; associate certifications expire annually and can be renewed on Microsoft Learn. Accumentum does not publish unofficial question counts or invented exam prices.
Skills measured: manage identity, access, and governance (20–25%); secure storage, databases, and networking (25–30%); secure compute (20–25%); manage and monitor security posture (20–25%).
Exam SC-500 replaces AZ-500. Microsoft has stated AZ-500 end of life on 31 August 2026; confirm current retirement, scheduling, and interactive-item details on Microsoft Learn and Pearson VUE.
SC-500 Cloud and AI Security Engineer training with Accumentum: scope, audience, skills measured, and public exam facts.
Enroll in Microsoft Cloud and AI Security Engineer Certification Training (SC-500) with Accumentum.
Enroll in Accumentum’s SC-500 training to prepare for Exam SC-500. For course dates and enrollment support, visit Accumentum’s registration page linked below.
Prepare for SC-500 cloud and AI security work.
End-to-end security controls for cloud and AI workloads. Not AZ-500.

